Montana: AI health laws

3 entries on the map: 3 in force.

Payer and utilization review AI

Insurers', benefit managers' and utilization reviewers' use of AI, including prior authorization and claim denials.

Nothing in this category was found in the review of Sept 29, 2026.

Patient disclosure of AI use

Telling patients that AI is used in their care or in messages to them.

Nothing in this category was found in the review of Sept 29, 2026.

Clinical decision and chatbot limits

Limits on AI in clinical decisions and on health chatbots, including AI presenting itself as a licensed professional.

Nothing in this category was found in the review of Sept 29, 2026.

Mental health AI

AI in therapy and mental health care.

Nothing in this category was found in the review of Sept 29, 2026.

Data and privacy

Health and consumer data, biometrics, and data used to train AI.

In forceLaw

SB 384, Consumer Data Privacy Act

In force since Oct 1, 2024 (signed May 19, 2023)

Gives consumers rights over their personal data, including opting out of targeted advertising, sale and certain profiling, and requires consent before processing sensitive data, including data revealing a mental or physical health condition or diagnosis and genetic or biometric data processed to identify an individual.

Physician read. It exempts HIPAA covered entities and business associates as entities, so it places no duty on physician practices that are covered entities. Since Oct. 1, 2024, other businesses that meet the thresholds have needed consumers' consent to process data revealing a health condition or diagnosis, or biometric data used to identify them.

Applies to: Businesses that control or process personal data of at least 25,000 Montana consumers, or 15,000 while deriving more than 25 percent of gross revenue from selling personal data (thresholds as lowered in 2025)

Notes: Chapter 681, Laws of 2023, codified at Title 30, chapter 14, part 28, MCA. The history comes from LegiScan; the enrolled text states the act is effective Oct. 1, 2024. The original thresholds were 50,000 consumers, or 25,000 with more than 25 percent of revenue from selling data; SB 297 (2025) lowered them and added protections for minors, including limits on collecting minors' precise geolocation (separate entry).

Checked against its sources
In forceLaw

SB 163, Generally Revise Privacy Laws Related to Biometric, Genetic, and Neural Data (Genetic Information Privacy Act amendments)

In force since Oct 1, 2025 (signed May 1, 2025)

Adds neurotechnology data to the Genetic Information Privacy Act, so that an entity covered by that act must give privacy notices, obtain initial express consent to collect, use or disclose neurotechnology data and separate express consent to transfer it to third parties or use it beyond its primary purpose, keep a comprehensive security program and let consumers access and delete the data and revoke consent, and limits governmental agencies' collection and use of genetic or neurotechnology data to what a specific state law, search warrant or investigative subpoena allows.

Physician read. Since Oct. 1, 2025, an entity that offers consumer genetic testing or collects, uses or analyzes genetic data needs a consumer's express consent to collect, use or disclose neurotechnology data and separate consent to share it or use it beyond its primary purpose; the act's definition of entity, which SB 163 left unchanged, does not mention neurotechnology. Protected health information that a HIPAA covered entity or business associate collects is exempt only if the entity obtains separate informed consent for the genetic or neurotechnology data and gives consumers a way to access and delete it, revoke consent and have biological samples destroyed.

Applies to: Entities that offer consumer genetic testing directly to consumers or that collect, use or analyze genetic data, for the genetic and neurotechnology data they handle; governmental agencies that collect or use such data

Notes: Chapter 345, Laws of 2025 (per the MCA history notes). The short title mentions biometric data, but the enrolled act amends only the Genetic Information Privacy Act (MCA 30-23-101 to 30-23-105) and MCA 44-6-104, on government access to consumer DNA databases, adding neurotechnology data and neurotechnology databases; it does not change biometric data rules or the Consumer Data Privacy Act, whose definition of sensitive data does not list neural data. It did not amend the definition of entity in MCA 30-23-102, which still covers only an organization that offers consumer genetic testing products or services directly to a consumer or collects, uses or analyzes genetic data. Neurotechnology data means information captured by neurotechnologies, generated by measuring the activity of the central or peripheral nervous system, or associated with neural activity, excluding nonneural information about downstream physical effects such as pupil dilation, motor activity and breathing rate. It also requires any governmental agency's collection, storage, use or dissemination of genetic or neurotechnology data to follow a specific state law or a search warrant or investigative subpoena, and adds legislative findings on neurotechnology privacy. The enrolled text has no effective-date section, so it took effect Oct. 1, 2025 under MCA 1-2-201. The history comes from LegiScan.

Checked against its sources
In forceLaw

SB 297, Generally Revise Privacy Laws (Consumer Data Privacy Act amendments)

In force since Oct 1, 2025 (signed May 8, 2025)

Lowers the act's thresholds to 25,000 consumers (15,000 for businesses deriving more than 25 percent of revenue from selling data) and requires controllers offering online services, products or features to minors under 18 to use reasonable care to avoid a heightened risk of harm, bars targeted advertising, sale and certain profiling of minors' data without consent, and limits collection of minors' precise geolocation.

Physician read. HIPAA covered entities and business associates remain exempt, so it places no duty on physician practices that are covered entities. Since Oct. 1, 2025, the act reaches smaller businesses, and online services offered to minors must avoid a heightened risk of harm and obtain consent before using minors' data for targeted advertising, sale or certain profiling.

Applies to: Controllers subject to the Consumer Data Privacy Act, including those offering online services, products or features to minors

Notes: Chapter 567, Laws of 2025 (per the MCA history notes). The enrolled text has no effective-date section, so it took effect Oct. 1, 2025 under MCA 1-2-201; its data protection assessment duties apply to processing activities created or generated after Oct. 1, 2025. The attorney general must give notice and 60 days to cure before bringing an action. The history comes from LegiScan.

Checked against its sources

Federal law also applies in every state: see federal law and policy.

Most recently checked Sept 29, 2026. General information, not legal advice. How the map works, and the data.