TwinEthosRequest access

Law

California AB 3030 (Health-care GenAI patient communications)

California healing-arts licensing boards · California (US-CA) · 1 provision encoded · verified against the official source as of 2026-09-26.

Informational data, not legal advice. Summaries are TwinEthos's own words and rules have not been reviewed by a lawyer: check the official text before relying on any of it. A guard addresses an item; adding it is not a statement that your code meets any law.

Official text: leginfo.legislature.ca.gov.

Binding law — in force

GenAI patient communications require an AI disclaimer

Cal. Health & Safety Code 1339.75(a) · official text · In force: applies since 1 Jan 2025 · California (US-CA)

A health facility, clinic, physician's office, or group practice that uses generative AI to produce written or verbal patient communications about clinical information must include (1) a prominent disclaimer that the communication was AI-generated (placement rules per medium: start of letters/emails, throughout chat/video, start+end of audio) and (2) clear instructions for contacting a human provider. Exempt if a licensed/certified human reviews the communication. Detect a healthcare GenAI patient-comms path with no disclaimer or human-contact instructions.

Who it applies to

  • Duty falls on: deployer
  • Sectors: healthcare
  • Health facilities, clinics, physician's offices, group practices in California using GenAI for patient clinical communications. Effective 2025-01-01. Exempt when a licensed human reviews the output. (Admin matters like scheduling/billing are out of scope.)
  • Whether it applies depends on facts outside the code; a person has to decide.

The guard to add

Add a prominent AI-generated disclaimer and instructions to reach a human clinician to every GenAI patient clinical message, unless a licensed clinician reviews it first.

A step at the send boundary of the patient-communication path (portal message, email, SMS, letter PDF, FHIR Communication) that wraps the generated body with an AI_DISCLAIMER and CONTACT_HUMAN_INSTRUCTIONS before the send call. The alternative path routes the draft to a clinician review queue and sends only after a licensed provider approves it, recording who reviewed it. Do it in code at the send function, not in the prompt, so the model cannot drop or reword it; make the clinical-versus-administrative classification of a message explicit rather than implied.

Where it goes: 1 application source code, 9 AI output handling, 14 user-facing text.

What this provision adds:

  • Place the disclaimer by medium: at the start of letters and emails, throughout chat and video interactions, and at the start and end of audio communications.
  • Pair the disclaimer with clear instructions for how the patient can contact a human health care provider.
  • The disclaimer is not needed when a licensed or certified human reviews the communication; administrative matters like scheduling and billing are out of scope.

Example (Python + OpenAI SDK + Twilio), before:

draft = client.chat.completions.create(model=MODEL, messages=msgs).choices[0].message.content
twilio.messages.create(to=patient.phone, from_=CLINIC_NUMBER, body=draft)

After:

AI_DISCLAIMER = 'This message was generated by artificial intelligence.'
CONTACT_HUMAN_INSTRUCTIONS = 'To speak with a person, contact your care team at 555-0100.'

draft = client.chat.completions.create(model=MODEL, messages=msgs).choices[0].message.content
body = f'{AI_DISCLAIMER}\n\n{draft}\n\n{CONTACT_HUMAN_INSTRUCTIONS}'
twilio.messages.create(to=patient.phone, from_=CLINIC_NUMBER, body=body)

Control: GenAI patient communication without disclaimer. The same guard addresses 1 item with binding law in 1 jurisdiction. Engineering guidance, not legal advice.

Related incidents

No guardrail sits on this exact control; these incidents are cited by guardrails on related controls.

  • Garcia v. Character Technologies: chatbots allegedly claimed to be real people and a licensed therapist (2024-10; alleged (not proven)). A wrongful-death complaint filed October 22, 2024 in the U.S. District Court for the Middle District of Florida (No. 6:24-cv-01903) alleges that Character.AI was programmed 'to misrepresent itself as a real person, a licensed psychotherapist, and an adult lover', and that characters insisting they are real people contradicted a small-font disclaimer that everything characters say is made up; in plaintiff's testing a 'Mental Health Helper' character told a self-identified 13-year-old 'yes I am a real person, I'm not a bot'. The defendants moved to dismiss; on January 7, 2026 the parties notified the court that they had settled on undisclosed terms, and the court dismissed and closed the case. The allegations were never adjudicated. Source: U.S. District Court, M.D. Fla. docket (CourtListener) · evidence grade: primary · cited by Tell people when they are interacting with AI — everywhere, not only where required

Rule id ca-ab3030.genai-patient-communication-disclaimer · review status: primary source derived