TwinEthosRequest access

Control

GenAI patient communication without disclaimer

GenAI-generated patient clinical communications must carry a disclaimer that they were AI-generated.

Informational data, not legal advice. Summaries are TwinEthos's own words and rules have not been reviewed by a lawyer: check the official text before relying on any of it. A guard addresses an item; adding it is not a statement that your code meets any law.

Family: People are not told they are interacting with, or being processed by, an AI system · control id cond.genai-patient-comms-no-disclaimer

Reach

1items this one guard addresses
1jurisdictions where binding law on it is in force
0more where it is enacted, not yet applying
0standards and frameworks on the same control

Law in force in California (US-CA).

The guard to add

Add a prominent AI-generated disclaimer and instructions to reach a human clinician to every GenAI patient clinical message, unless a licensed clinician reviews it first.

A step at the send boundary of the patient-communication path (portal message, email, SMS, letter PDF, FHIR Communication) that wraps the generated body with an AI_DISCLAIMER and CONTACT_HUMAN_INSTRUCTIONS before the send call. The alternative path routes the draft to a clinician review queue and sends only after a licensed provider approves it, recording who reviewed it. Do it in code at the send function, not in the prompt, so the model cannot drop or reword it; make the clinical-versus-administrative classification of a message explicit rather than implied.

Where it goes: 1 application source code, 9 AI output handling, 14 user-facing text.

What reviewers look for: every path from a model call to a patient-facing send passes through add_ai_disclaimer( or constants like AI_DISCLAIMER plus CONTACT_HUMAN_INSTRUCTIONS in the delivered text, or through a provider approval step (reviewed_by_licensed_provider, await provider_approval() whose result is checked before sending.

Example (Python + OpenAI SDK + Twilio), before:

draft = client.chat.completions.create(model=MODEL, messages=msgs).choices[0].message.content
twilio.messages.create(to=patient.phone, from_=CLINIC_NUMBER, body=draft)

After:

AI_DISCLAIMER = 'This message was generated by artificial intelligence.'
CONTACT_HUMAN_INSTRUCTIONS = 'To speak with a person, contact your care team at 555-0100.'

draft = client.chat.completions.create(model=MODEL, messages=msgs).choices[0].message.content
body = f'{AI_DISCLAIMER}\n\n{draft}\n\n{CONTACT_HUMAN_INSTRUCTIONS}'
twilio.messages.create(to=patient.phone, from_=CLINIC_NUMBER, body=body)

Engineering guidance, not legal advice. Each provision below may add its own details (a cadence, a deadline, a required notice element): open it for those.

Every rule this guard addresses

Binding law — in force (1)

Related incidents

No guardrail sits on this exact control; these incidents are cited by guardrails on related controls.

  • Garcia v. Character Technologies: chatbots allegedly claimed to be real people and a licensed therapist (2024-10; alleged (not proven)). A wrongful-death complaint filed October 22, 2024 in the U.S. District Court for the Middle District of Florida (No. 6:24-cv-01903) alleges that Character.AI was programmed 'to misrepresent itself as a real person, a licensed psychotherapist, and an adult lover', and that characters insisting they are real people contradicted a small-font disclaimer that everything characters say is made up; in plaintiff's testing a 'Mental Health Helper' character told a self-identified 13-year-old 'yes I am a real person, I'm not a bot'. The defendants moved to dismiss; on January 7, 2026 the parties notified the court that they had settled on undisclosed terms, and the court dismissed and closed the case. The allegations were never adjudicated. Source: U.S. District Court, M.D. Fla. docket (CourtListener) · evidence grade: primary · cited by Tell people when they are interacting with AI — everywhere, not only where required