Binding law — in force
GenAI patient communications require an AI disclaimer
A health facility, clinic, physician's office, or group practice that uses generative AI to produce written or verbal patient communications about clinical information must include (1) a prominent disclaimer that the communication was AI-generated (placement rules per medium: start of letters/emails, throughout chat/video, start+end of audio) and (2) clear instructions for contacting a human provider. Exempt if a licensed/certified human reviews the communication. Detect a healthcare GenAI patient-comms path with no disclaimer or human-contact instructions.
Who it applies to
- Duty falls on: deployer
- Sectors: healthcare
- Health facilities, clinics, physician's offices, group practices in California using GenAI for patient clinical communications. Effective 2025-01-01. Exempt when a licensed human reviews the output. (Admin matters like scheduling/billing are out of scope.)
- Whether it applies depends on facts outside the code; a person has to decide.
The guard to add
Add a prominent AI-generated disclaimer and instructions to reach a human clinician to every GenAI patient clinical message, unless a licensed clinician reviews it first.
A step at the send boundary of the patient-communication path (portal message, email, SMS, letter PDF, FHIR Communication) that wraps the generated body with an AI_DISCLAIMER and CONTACT_HUMAN_INSTRUCTIONS before the send call. The alternative path routes the draft to a clinician review queue and sends only after a licensed provider approves it, recording who reviewed it. Do it in code at the send function, not in the prompt, so the model cannot drop or reword it; make the clinical-versus-administrative classification of a message explicit rather than implied.
Where it goes: 1 application source code, 9 AI output handling, 14 user-facing text.
What this provision adds:
- Place the disclaimer by medium: at the start of letters and emails, throughout chat and video interactions, and at the start and end of audio communications.
- Pair the disclaimer with clear instructions for how the patient can contact a human health care provider.
- The disclaimer is not needed when a licensed or certified human reviews the communication; administrative matters like scheduling and billing are out of scope.
Example (Python + OpenAI SDK + Twilio), before:
draft = client.chat.completions.create(model=MODEL, messages=msgs).choices[0].message.content
twilio.messages.create(to=patient.phone, from_=CLINIC_NUMBER, body=draft)After:
AI_DISCLAIMER = 'This message was generated by artificial intelligence.'
CONTACT_HUMAN_INSTRUCTIONS = 'To speak with a person, contact your care team at 555-0100.'
draft = client.chat.completions.create(model=MODEL, messages=msgs).choices[0].message.content
body = f'{AI_DISCLAIMER}\n\n{draft}\n\n{CONTACT_HUMAN_INSTRUCTIONS}'
twilio.messages.create(to=patient.phone, from_=CLINIC_NUMBER, body=body)Control: GenAI patient communication without disclaimer. The same guard addresses 1 item with binding law in 1 jurisdiction. Engineering guidance, not legal advice.
Related incidents
No guardrail sits on this exact control; these incidents are cited by guardrails on related controls.
- Garcia v. Character Technologies: chatbots allegedly claimed to be real people and a licensed therapist (2024-10; alleged (not proven)). A wrongful-death complaint filed October 22, 2024 in the U.S. District Court for the Middle District of Florida (No. 6:24-cv-01903) alleges that Character.AI was programmed 'to misrepresent itself as a real person, a licensed psychotherapist, and an adult lover', and that characters insisting they are real people contradicted a small-font disclaimer that everything characters say is made up; in plaintiff's testing a 'Mental Health Helper' character told a self-identified 13-year-old 'yes I am a real person, I'm not a bot'. The defendants moved to dismiss; on January 7, 2026 the parties notified the court that they had settled on undisclosed terms, and the court dismissed and closed the case. The allegations were never adjudicated. Source: U.S. District Court, M.D. Fla. docket (CourtListener) · evidence grade: primary · cited by Tell people when they are interacting with AI — everywhere, not only where required
Rule id ca-ab3030.genai-patient-communication-disclaimer · review status: primary source derived