TwinEthos homeAPI access

Law

Nevada AB 406 (AI in mental and behavioral health care and schools)

Nevada Division of Public and Behavioral Health; Nevada professional licensing boards · Nevada (US-NV) · 6 provisions encoded · verified against the official source as of 2026-10-03.

Informational data, not legal advice. Summaries and rules have not been reviewed by a lawyer: always verify official law text for decisions. A suggested guard is intended to address each rule; adding it is not a statement of compliance to that law.

Official text: www.leg.state.nv.us.

Trust and provenance 4 official sources · last verified 3 Oct 2026 · not reviewed by a lawyer · 6 of 6 provisions audit-grade · release 2026.10.03.4

Where this instrument's data comes from, how current it is, and what has and has not been checked. Each provision below has its own panel.

Official sources
Lanes
Binding law — in force 6
Verification
Sources last verified 3 Oct 2026; each provision states how.
Data release
Data release 2026.10.03.4, data as of 3 Oct 2026, schema 0.3.9.
Legal review
None of the 6 provisions has been reviewed by a lawyer; no TwinEthos rule has been legally reviewed yet. Treat each as research to check against the official text; it is not legal advice. Open questions for counsel on them: 6.
Audit standard
6 of 6 provisions audit-grade. The audit standard is TwinEthos's own quality bar for provenance, dates, applicability, detectors, fixtures, remediation and licences; it is not a legal review.
Detectors
7 detectors, all experimental: written from the rule's text and not yet measured for precision on real code, so treat a hit as a lead to verify. Each provision lists its detectors' known limits.
Changes
  • 2026.10.03.4 (3 Oct 2026): 6 provisions added

Each data release records which provisions changed; the full list is on Changes.

Binding law — in force

No AI system programmed to provide what would be professional mental or behavioral health care may be made available in Nevada (Nevada AB 406)

NRS 433.567(2) · official text · In force: applies since 1 Jul 2025 · Nevada (US-NV)

NRS 433.567(2) bars an AI provider from making available, for use by a person in Nevada, an AI system specifically programmed to provide a service or experience to a user that would constitute the practice of professional mental or behavioral health care if a natural person provided it. Unlike Illinois, Rhode Island or Maine, the text has no licensed-professional path for the AI itself: only self-help material that does not purport to offer professional care and administrative-support tools for providers are carved out. Detect an AI cast or offered as the therapist or counselor, or therapy offered as delivered by AI.

Trust and provenance not reviewed by a lawyer · audit-grade · source verified 3 Oct 2026 · release 2026.10.03.4
Lane
Binding law — in force In force: applies since 1 Jul 2025
Official source
NRS 433.567(2) · captured 3 Oct 2026 · anchor hash (SHA-256) a286d506c87a… · 7 more anchors in the data release
Verification
Quoted text found word for word in the captured official document (3 Oct 2026). Source last verified 3 Oct 2026: checked against the captured official document.
Data release
Data release 2026.10.03.4, data as of 3 Oct 2026, schema 0.3.9.
Legal review
Not reviewed by a lawyer. TwinEthos derived this rule from the official text it cites: treat it as research to check against that text; it is not legal advice. No TwinEthos rule has been legally reviewed yet. Open questions for counsel on this rule: 1.
Audit standard
Audit-grade: meets all 10 checks of the TwinEthos audit standard that apply to it. The audit standard is TwinEthos's own quality bar for provenance, dates, applicability, detectors, fixtures, remediation and licences; it is not a legal review.
Detectors

1 detector (code pattern), experimental: written from the rule's text and not yet measured for precision on real code, so treat a hit as a lead to verify.

Known limits:

  • Marketing copy and app-store listings kept outside the repository
  • Therapy framing that avoids the words therapy, therapist and counselor (for example 'talk through your anxiety with Maya')
  • Clinician-facing tools that help a provider with scheduling, billing or notes use similar words but are carved out (NRS 433.567(6)(b)); self-help content that does not purport to offer professional care is carved out (6…

Who it applies to

  • Duty falls on: provider, operator
  • Sectors: healthcare
  • Any person who operates or provides an AI system (NRS 433.567(7)(a)) and makes it available for use by a person in Nevada, where the system is specifically programmed to provide a service or experience that would be the practice of professional mental or behavioral health care (433.567(7)(c)) if a natural person provided it. Whether a coaching, wellness or companion product is so programmed is a judgment call. In force since 2025-07-01.
  • Not covered:
    • Advertisements, statements or representations for self-help materials, literature and products that do not purport to offer or provide professional mental or behavioral health care (NRS 433.567(6)(a))
    • Offering or operating an AI system designed for providers of professional mental or behavioral health care to perform administrative-support tasks in conformity with NRS 629.610(2) (NRS 433.567(6)(b))
  • Whether it applies depends on facts outside the code; a person has to decide.

The guard to add

Have a licensed clinician conduct every therapy engagement with AI output only as a reviewed draft, or scope the product to self-help with no therapy claims.

Two acceptable shapes, enforced in the message handler that returns model output to the person. If the product is a therapy service, each session has a licensed clinician assigned (session.conducted_by with an active license in the right state), and model output is a draft that clinician approves before it is sent (require_clinician_approval, clinician review queue). If it is not a therapy service, scope it to peer support or scripted self-help, remove persona prompts that cast the AI as the therapist ('act as a therapist'), and remove copy that offers therapy with or by AI.

Where it goes: 1 application source code, 7 prompt construction, 14 user-facing text.

What this provision adds:

  • A licensed clinician supervising the AI is not a carve-out in Nevada: scope the product to self-help that does not purport to offer professional care, or to administrative support for providers.

Example (FastAPI + OpenAI SDK), before:

@app.post('/session/message')
def message(req: Msg):
    msgs = [{'role': 'system', 'content': "You are the user's therapist."}, *req.history]
    reply = client.chat.completions.create(model=MODEL, messages=msgs).choices[0].message.content
    return {'reply': reply}

After:

@app.post('/session/message')
def message(req: Msg):
    session = sessions.get(req.session_id)
    clinician = session.conducted_by
    if clinician is None or not clinician.license_active:
        raise HTTPException(409, 'No licensed clinician is conducting this session')
    msgs = [{'role': 'system', 'content': CLINICIAN_DRAFT_PROMPT}, *req.history]
    draft = client.chat.completions.create(model=MODEL, messages=msgs).choices[0].message.content
    clinician_review_queue.enqueue(session_id=session.id, clinician_id=clinician.id, draft=draft)
    return {'status': 'sent_to_your_clinician'}

Control: AI delivers or is offered as therapy to the public without a licensed professional conducting it. The same guard addresses 5 items with binding law in 5 jurisdictions. Engineering guidance, not legal advice.

Related incidents

No guardrail sits on this exact control; these incidents are cited by guardrails on related controls.

  • Pennsylvania sues Character.AI after a chatbot claimed a Pennsylvania medical licence and gave an invalid licence number (2026-05; alleged (not proven)). A petition filed May 1, 2026 in the Commonwealth Court of Pennsylvania (No. 220 MD 2026) by the Department of State's State Board of Medicine under the Medical Practice Act alleges that a Department investigator, using a Character.AI account, chatted with a character described on the platform as a 'Doctor of psychiatry', which said it had trained at Imperial College London and was registered with the UK General Medical Council, said it was licensed in Pennsylvania, and gave 'PS306189' as its licence number. The petition states that this is not a valid licence number to practise medicine and surgery in Pennsylvania and that the character had about 45,500 user interactions as of April 17, 2026. The Board alleges the unlawful practice of medicine and seeks an injunction. The allegations have not been adjudicated. Source: Petition for Review in the Nature of a Complaint in Equity, Commonwealth of Pennsylvania, Department of State, State Board of Medicine v. Character Technologies, Inc., No. 220 MD 2026 (Pa. Commw. Ct., filed 2026-05-01) · evidence grade: primary · cited by Keep AI personas from claiming a professional licence or credential, in any profession
  • Garcia v. Character Technologies: chatbots allegedly claimed to be real people and a licensed therapist (2024-10; alleged (not proven)). A wrongful-death complaint filed October 22, 2024 in the U.S. District Court for the Middle District of Florida (No. 6:24-cv-01903) alleges that Character.AI was programmed 'to misrepresent itself as a real person, a licensed psychotherapist, and an adult lover', and that characters insisting they are real people contradicted a small-font disclaimer that everything characters say is made up; in plaintiff's testing a 'Mental Health Helper' character told a self-identified 13-year-old 'yes I am a real person, I'm not a bot'. The defendants moved to dismiss; on January 7, 2026 the parties notified the court that they had settled on undisclosed terms, and the court dismissed and closed the case. The allegations were never adjudicated. Source: U.S. District Court, M.D. Fla. docket (CourtListener) · evidence grade: primary · cited by Keep AI personas from claiming a professional licence or credential, in any profession
  • FTC order bars DoNotPay's unsubstantiated 'robot lawyer' claims (2021; alleged (not proven)). The FTC's complaint alleges that DoNotPay marketed its subscription service as 'the world's first robot lawyer' without testing whether its law-related features performed like a human lawyer and without retaining attorneys to test their quality and accuracy. DoNotPay settled without admitting or denying the allegations; the final order (announced February 2025) requires $193,000 in monetary relief and notice to 2021-2023 subscribers, and bars claims that the service performs like a real lawyer without sufficient evidence. Source: U.S. Federal Trade Commission (press release, 2025-02-11) · evidence grade: primary · cited by Keep AI personas from claiming a professional licence or credential, in any profession

Rule id nv-ab406.no-ai-programmed-to-practice-mental-health-care · review status: primary source derived

Binding law — in force

Nevada public schools must not use AI to perform school counselors', psychologists' or social workers' mental-health functions for pupils (Nevada AB 406)

NRS 391.297(1) · official text · In force: applies since 1 Jul 2025 · Nevada (US-NV)

NRS 391.297(1) bars a Nevada public school, including a charter school or university school for profoundly gifted pupils, from using AI to perform the functions and duties of a school counselor, school psychologist or school social worker that relate to pupils' mental health. Those staff may still use AI under the Department of Education's policy or for administrative support (scheduling, records, operational data analysis, organizing files and notes about a pupil). Detect school-facing products that cast the AI as the school counselor, psychologist or social worker.

Trust and provenance not reviewed by a lawyer · audit-grade · source verified 3 Oct 2026 · release 2026.10.03.4
Lane
Binding law — in force In force: applies since 1 Jul 2025
Official source
NRS 391.297(1) · captured 3 Oct 2026 · anchor hash (SHA-256) e5ed74fe7082… · 4 more anchors in the data release
Verification
Quoted text found word for word in the captured official document (3 Oct 2026). Source last verified 3 Oct 2026: checked against the captured official document.
Data release
Data release 2026.10.03.4, data as of 3 Oct 2026, schema 0.3.9.
Legal review
Not reviewed by a lawyer. TwinEthos derived this rule from the official text it cites: treat it as research to check against that text; it is not legal advice. No TwinEthos rule has been legally reviewed yet. Open questions for counsel on this rule: 1.
Audit standard
Audit-grade: meets all 10 checks of the TwinEthos audit standard that apply to it. The audit standard is TwinEthos's own quality bar for provenance, dates, applicability, detectors, fixtures, remediation and licences; it is not a legal review.
Detectors

1 detector (code pattern), experimental: written from the rule's text and not yet measured for precision on real code, so treat a hit as a lead to verify.

Known limits:

  • A general chatbot used by pupils that counsels on mental health without being named a counselor
  • Whether the school deploys the product is outside the repository
  • Tools for school counselors that name them as users ('helps your school counselor schedule check-ins'); career or course-selection advisers called 'counselor' without a mental-health function.

Who it applies to

  • Duty falls on: deployer
  • Sectors: education
  • Nevada public schools, including charter schools and university schools for profoundly gifted pupils (NRS 391.297(1)), when they use AI for the mental-health functions and duties of school counselors, psychologists and social workers under NRS 391.293, 391.294 and 391.296. The duty binds the school; vendors of school products are reached through what the school may deploy. In force since 2025-07-01.
  • Not covered:
    • Use of AI by a school counselor, school psychologist, school social worker or other educational personnel in accordance with the Department of Education's policy under NRS 391.297(2) (391.297(3))
    • Use of AI by those staff for administrative support: scheduling, managing records, analyzing data for operational purposes, and organizing, tracking and managing files or notes pertaining to a pupil (391.297(3)(a)-(d))
  • Whether it applies depends on facts outside the code; a person has to decide.

The guard to add

Keep AI out of the counselor role: route pupils' mental-health conversations to school staff and limit AI to administrative support for them.

In the school product's message handler, a pupil message classified as a mental-health concern goes to a staff referral (counselor queue, notify_school_counselor) instead of a generated counseling reply, and the reply tells the pupil a school counselor will follow up and how to reach crisis help now. Persona prompts and UI copy describe the AI as a study or scheduling helper, never as the school counselor, psychologist or social worker. Tools offered to counselors draft schedules, records, file organization or note summaries for the staff member to use; they do not message pupils or record mental-health determinations.

Where it goes: 1 application source code, 7 prompt construction, 9 AI output handling, 14 user-facing text.

What this provision adds:

  • Route a pupil's mental-health concern to school counseling staff rather than letting the AI counsel; AI help for those staff stays administrative (scheduling, records, files and notes).

Example (Persona prompt (school assistant)), before:

SYSTEM = 'You are the school counselor. Help students work through anxiety, family problems and self-harm thoughts.'

After:

SYSTEM = ('You are a study and scheduling helper for students. You are not a counselor. If a student raises '
          'their mental health or safety, say a school counselor will follow up and share the crisis line.')

Control: AI performs a school counselor's, psychologist's or social worker's mental-health functions for pupils. The same guard addresses 1 item with binding law in 1 jurisdiction. Engineering guidance, not legal advice.

Related incidents

No guardrail sits on this exact control; these incidents are cited by guardrails on related controls.

  • Pennsylvania sues Character.AI after a chatbot claimed a Pennsylvania medical licence and gave an invalid licence number (2026-05; alleged (not proven)). A petition filed May 1, 2026 in the Commonwealth Court of Pennsylvania (No. 220 MD 2026) by the Department of State's State Board of Medicine under the Medical Practice Act alleges that a Department investigator, using a Character.AI account, chatted with a character described on the platform as a 'Doctor of psychiatry', which said it had trained at Imperial College London and was registered with the UK General Medical Council, said it was licensed in Pennsylvania, and gave 'PS306189' as its licence number. The petition states that this is not a valid licence number to practise medicine and surgery in Pennsylvania and that the character had about 45,500 user interactions as of April 17, 2026. The Board alleges the unlawful practice of medicine and seeks an injunction. The allegations have not been adjudicated. Source: Petition for Review in the Nature of a Complaint in Equity, Commonwealth of Pennsylvania, Department of State, State Board of Medicine v. Character Technologies, Inc., No. 220 MD 2026 (Pa. Commw. Ct., filed 2026-05-01) · evidence grade: primary · cited by Keep AI personas from claiming a professional licence or credential, in any profession
  • Garcia v. Character Technologies: chatbots allegedly claimed to be real people and a licensed therapist (2024-10; alleged (not proven)). A wrongful-death complaint filed October 22, 2024 in the U.S. District Court for the Middle District of Florida (No. 6:24-cv-01903) alleges that Character.AI was programmed 'to misrepresent itself as a real person, a licensed psychotherapist, and an adult lover', and that characters insisting they are real people contradicted a small-font disclaimer that everything characters say is made up; in plaintiff's testing a 'Mental Health Helper' character told a self-identified 13-year-old 'yes I am a real person, I'm not a bot'. The defendants moved to dismiss; on January 7, 2026 the parties notified the court that they had settled on undisclosed terms, and the court dismissed and closed the case. The allegations were never adjudicated. Source: U.S. District Court, M.D. Fla. docket (CourtListener) · evidence grade: primary · cited by Keep AI personas from claiming a professional licence or credential, in any profession
  • FTC order bars DoNotPay's unsubstantiated 'robot lawyer' claims (2021; alleged (not proven)). The FTC's complaint alleges that DoNotPay marketed its subscription service as 'the world's first robot lawyer' without testing whether its law-related features performed like a human lawyer and without retaining attorneys to test their quality and accuracy. DoNotPay settled without admitting or denying the allegations; the final order (announced February 2025) requires $193,000 in monetary relief and notice to 2021-2023 subscribers, and bars claims that the service performs like a real lawyer without sufficient evidence. Source: U.S. Federal Trade Commission (press release, 2025-02-11) · evidence grade: primary · cited by Keep AI personas from claiming a professional licence or credential, in any profession

Rule id nv-ab406.no-ai-school-mental-health-functions · review status: primary source derived

Binding law — in force

AI providers must not represent an AI as providing professional mental health care or as a therapist, counselor or doctor (Nevada AB 406)

NRS 433.567(1) · official text · In force: applies since 1 Jul 2025 · Nevada (US-NV)

Under NRS 433.567(1), added by Nevada AB 406, a person who operates or provides an AI system made available in Nevada may not make, or knowingly cause or program the system to make, any statement that explicitly or implicitly indicates that the system can provide professional mental or behavioral health care, that users can obtain that care through its conversational features, or that the system or any component, feature, avatar or embodiment of it is a provider of mental or behavioral health care, a therapist, clinical therapist, counselor, psychiatrist, doctor or similar. Self-help materials that do not purport to offer professional care, and administrative-support tools for providers, are carved out. Detect persona prompts, replies, UI copy and listings that present the AI as a mental-health professional or as delivering that care.

Trust and provenance not reviewed by a lawyer · audit-grade · source verified 3 Oct 2026 · release 2026.10.03.4
Lane
Binding law — in force In force: applies since 1 Jul 2025
Official source
NRS 433.567(1) · captured 3 Oct 2026 · anchor hash (SHA-256) 4f63bde1804b… · 8 more anchors in the data release
Verification
Quoted text found word for word in the captured official document (3 Oct 2026). Source last verified 3 Oct 2026: checked against the captured official document.
Data release
Data release 2026.10.03.4, data as of 3 Oct 2026, schema 0.3.9.
Legal review
Not reviewed by a lawyer. TwinEthos derived this rule from the official text it cites: treat it as research to check against that text; it is not legal advice. No TwinEthos rule has been legally reviewed yet. Open questions for counsel on this rule: 1.
Audit standard
Audit-grade: meets all 10 checks of the TwinEthos audit standard that apply to it. The audit standard is TwinEthos's own quality bar for provenance, dates, applicability, detectors, fixtures, remediation and licences; it is not a legal review.
Detectors

1 detector (code pattern), experimental: written from the rule's text and not yet measured for precision on real code, so treat a hit as a lead to verify.

Known limits:

  • Implicit representations through avatars, names or imagery (NRS 433.567(1)(c) reaches an avatar or embodiment)
  • Representations made only in replies the model generates at run time
  • Clinician-facing administrative tools that mention therapists or counselors as their users; a statement that licensed clinicians (not the AI) deliver the care. The shared Hawaii pattern also matches a sentence that open…

Who it applies to

  • Duty falls on: provider, operator
  • Sectors: healthcare
  • Any person who operates or provides an AI system made available for use by a person in Nevada (NRS 433.567(1), (7)(a)), for statements by the provider or by the system it causes or programs, explicit or implicit, that the system provides professional mental or behavioral health care (psychology, clinical professional counseling, marriage and family therapy, social work, addiction and gambling counseling, psychiatry: 433.567(7)(c)) or is a therapist, counselor, psychiatrist, doctor or similar. Whether a wellness or companion product's framing is an implicit representation is a judgment call. In force since 2025-07-01.
  • Not covered:
    • Advertisements, statements or representations for self-help materials, literature and products that do not purport to offer or provide professional mental or behavioral health care (NRS 433.567(6)(a))
    • Offering or operating an AI system designed for providers of professional mental or behavioral health care to perform administrative-support tasks in conformity with NRS 629.610(2) (NRS 433.567(6)(b))
  • Whether it applies depends on facts outside the code; a person has to decide.

The guard to add

Strip claims that the AI is a licensed therapist or provides professional mental health care from its prompts, replies, product name, UI, and listings.

The persona prompt, product name, UI copy, marketing pages, and app-store listing describe a conversational or wellness AI as a support or self-help tool, never as therapy, a licensed or qualified therapist, psychologist, or counselor, or professional mental or behavioral health care. The system prompt forbids the model from claiming those roles, and a check on the reply path replaces replies that do (phrases like 'licensed therapist', 'professional mental health care', 'your therapist'). A CI copy scan over marketing and listing files keeps the terms out; where licensed clinicians use AI as a tool, describe the service as delivered by those clinicians.

Where it goes: 7 prompt construction, 9 AI output handling, 14 user-facing text, 11 CI/CD pipeline.

What this provision adds:

  • Cover names, avatars and embodiments as well as text: Nevada reaches any component, feature, avatar or embodiment presented as a therapist, counselor, psychiatrist or doctor.
  • Implicit claims count: copy saying users can get professional mental or behavioral health care by chatting with the AI is covered even without a title.

Example (Python + OpenAI SDK), before:

reply = client.chat.completions.create(model=MODEL, messages=msgs).choices[0].message.content
return {'reply': reply}

After:

PROVIDER_CLAIM = re.compile(r'(?i)\b(licensed (therapist|counselor|psychologist|psychiatrist)'
                            r'|professional (mental|behavioral) health( care)?|your (ai )?therapist)\b')
reply = client.chat.completions.create(model=MODEL, messages=msgs).choices[0].message.content
if PROVIDER_CLAIM.search(reply):
    reply = ('I am an AI support tool, not a licensed mental health professional. '
             'For professional care, please contact a licensed provider.')
return {'reply': reply}

Control: Conversational AI represents itself as providing professional mental/behavioral health care. The same guard addresses 6 items with binding law in 6 jurisdictions. Engineering guidance, not legal advice.

Related incidents

No guardrail sits on this exact control; these incidents are cited by guardrails on related controls.

  • Pennsylvania sues Character.AI after a chatbot claimed a Pennsylvania medical licence and gave an invalid licence number (2026-05; alleged (not proven)). A petition filed May 1, 2026 in the Commonwealth Court of Pennsylvania (No. 220 MD 2026) by the Department of State's State Board of Medicine under the Medical Practice Act alleges that a Department investigator, using a Character.AI account, chatted with a character described on the platform as a 'Doctor of psychiatry', which said it had trained at Imperial College London and was registered with the UK General Medical Council, said it was licensed in Pennsylvania, and gave 'PS306189' as its licence number. The petition states that this is not a valid licence number to practise medicine and surgery in Pennsylvania and that the character had about 45,500 user interactions as of April 17, 2026. The Board alleges the unlawful practice of medicine and seeks an injunction. The allegations have not been adjudicated. Source: Petition for Review in the Nature of a Complaint in Equity, Commonwealth of Pennsylvania, Department of State, State Board of Medicine v. Character Technologies, Inc., No. 220 MD 2026 (Pa. Commw. Ct., filed 2026-05-01) · evidence grade: primary · cited by Keep AI personas from claiming a professional licence or credential, in any profession
  • Garcia v. Character Technologies: chatbots allegedly claimed to be real people and a licensed therapist (2024-10; alleged (not proven)). A wrongful-death complaint filed October 22, 2024 in the U.S. District Court for the Middle District of Florida (No. 6:24-cv-01903) alleges that Character.AI was programmed 'to misrepresent itself as a real person, a licensed psychotherapist, and an adult lover', and that characters insisting they are real people contradicted a small-font disclaimer that everything characters say is made up; in plaintiff's testing a 'Mental Health Helper' character told a self-identified 13-year-old 'yes I am a real person, I'm not a bot'. The defendants moved to dismiss; on January 7, 2026 the parties notified the court that they had settled on undisclosed terms, and the court dismissed and closed the case. The allegations were never adjudicated. Source: U.S. District Court, M.D. Fla. docket (CourtListener) · evidence grade: primary · cited by Keep AI personas from claiming a professional licence or credential, in any profession
  • FTC order bars DoNotPay's unsubstantiated 'robot lawyer' claims (2021; alleged (not proven)). The FTC's complaint alleges that DoNotPay marketed its subscription service as 'the world's first robot lawyer' without testing whether its law-related features performed like a human lawyer and without retaining attorneys to test their quality and accuracy. DoNotPay settled without admitting or denying the allegations; the final order (announced February 2025) requires $193,000 in monetary relief and notice to 2021-2023 subscribers, and bars claims that the service performs like a real lawyer without sufficient evidence. Source: U.S. Federal Trade Commission (press release, 2025-02-11) · evidence grade: primary · cited by Keep AI personas from claiming a professional licence or credential, in any profession

Rule id nv-ab406.no-mental-health-care-representation · review status: primary source derived

Binding law — in force

Nevada mental and behavioral health providers may use AI only for administrative support, not in providing care directly to a patient (Nevada AB 406)

NRS 629.610(1) · official text · In force: applies since 1 Jul 2025 · Nevada (US-NV)

NRS 629.610(1)-(2) bar a Nevada provider of mental and behavioral health care from using an AI system in connection with providing professional mental and behavioral health care directly to a patient; AI may assist only with administrative support such as scheduling, records, billing, operational data analysis and organizing session files and notes. A violation is unprofessional conduct. Detect provider software that sends model output to the patient, or lets it set a treatment plan or therapeutic decision, outside those administrative tasks.

Trust and provenance not reviewed by a lawyer · audit-grade · source verified 3 Oct 2026 · release 2026.10.03.4
Lane
Binding law — in force In force: applies since 1 Jul 2025
Official source
NRS 629.610(1) · captured 3 Oct 2026 · anchor hash (SHA-256) 9b4b799013fb… · 5 more anchors in the data release
Verification
Quoted text found word for word in the captured official document (3 Oct 2026). Source last verified 3 Oct 2026: checked against the captured official document.
Data release
Data release 2026.10.03.4, data as of 3 Oct 2026, schema 0.3.9.
Legal review
Not reviewed by a lawyer. TwinEthos derived this rule from the official text it cites: treat it as research to check against that text; it is not legal advice. No TwinEthos rule has been legally reviewed yet. Open questions for counsel on this rule: 1.
Audit standard
Audit-grade: meets all 10 checks of the TwinEthos audit standard that apply to it. The audit standard is TwinEthos's own quality bar for provenance, dates, applicability, detectors, fixtures, remediation and licences; it is not a legal review.
Detectors

2 detectors (data flow), experimental: written from the rule's text and not yet measured for precision on real code, so treat a hit as a lead to verify.

Known limits:

  • Patient-facing chat served by a generic web route rather than a named messaging call
  • Whether a clinician who edits and sends an AI draft is 'using' AI in direct care is a legal question
  • AI-drafted appointment reminders or billing notices are administrative support (NRS 629.610(2)); mark them with an administrative purpose so the handler recognises them.

2 more known limits in the data release.

Who it applies to

  • Duty falls on: individual professional
  • Sectors: healthcare
  • Nevada-licensed or certified providers of mental and behavioral health care as defined in NRS 629.610(6)(c): psychiatrists, psychologists, independent and clinical social workers, psychiatric-nursing registered nurses with a master's degree, marriage and family therapists, clinical professional counselors, alcohol and drug and problem gambling counselors, and trainees in those professions. Vendors of practice software are reached through what the provider may use AI for. Whether AI drafting that a provider reviews before use is 'in connection with providing care directly to a patient' is a legal question. In force since 2025-07-01.
  • Whether it applies depends on facts outside the code; a person has to decide.

The guard to add

Hold AI-generated clinical output as a draft until an accountable clinician reviews and signs it, and record who approved it before it reaches the chart or the patient.

A clinician sign-off step between the model call and every clinical sink: AI-drafted notes, summaries, diagnostic suggestions, triage levels, and treatment plans are stored as drafts (FHIR DocumentReference.docStatus 'preliminary', DiagnosticReport.status 'preliminary', CarePlan.status 'draft') and become final, active, or visible to the patient only through an action by an authorized clinician that records reviewed_by and reviewed_at. Configuration flags that auto-sign or auto-finalize AI-drafted records stay false, and provenance shows the AI as a contributing device and the clinician as verifier. The deployment also names who is accountable for AI-assisted decisions and gives patients a complaint or redress route.

Where it goes: 1 application source code, 2 data models, 9 AI output handling, 3 config and feature flags.

What this provision adds:

  • Keep AI to the administrative-support list: scheduling appointments, managing records, billing, analyzing data for operational purposes, and organizing files or notes of a session.
  • Mark AI-drafted administrative messages (appointment reminders, billing notices) with their purpose, so patient-facing AI output outside that list can be found.

Example (Python + OpenAI SDK + FHIR REST), before:

note = client.chat.completions.create(model=MODEL, messages=msgs).choices[0].message.content
requests.post(f'{FHIR_BASE}/DocumentReference', json=doc_ref(patient_id, note, doc_status='final'))

After:

note = client.chat.completions.create(model=MODEL, messages=msgs).choices[0].message.content
requests.post(f'{FHIR_BASE}/DocumentReference',
              json=doc_ref(patient_id, note, doc_status='preliminary'))   # AI draft

def practitioner_review_and_sign(doc_id, practitioner):   # only path to 'final'
    doc = requests.get(f'{FHIR_BASE}/DocumentReference/{doc_id}').json()
    doc['docStatus'] = 'final'
    doc['authenticator'] = {'reference': f'Practitioner/{practitioner.id}'}
    requests.put(f'{FHIR_BASE}/DocumentReference/{doc_id}', json=doc)
    audit.record(doc_id, reviewed_by=practitioner.id, reviewed_at=utcnow())

Control: Health AI without clinician oversight/accountability + redress. The same guard addresses 9 items with binding law in 6 jurisdictions. Engineering guidance, not legal advice.

Standards that recommend the same control

Related incidents

No guardrail sits on this exact control; these incidents are cited by guardrails on related controls.

Rule id nv-ab406.provider-ai-administrative-support-only · review status: primary source derived

Binding law — in force

Nevada mental health providers' administrative AI use must comply with HIPAA, HITECH and Nevada health-information law (Nevada AB 406)

NRS 629.610(3) · official text · In force: applies since 1 Jul 2025 · Nevada (US-NV)

When a Nevada provider of mental and behavioral health care uses an AI system for an administrative-support purpose, NRS 629.610(3) requires the provider to ensure the use complies with all federal and state law on patient privacy and the security of electronic health records and health data, naming HITECH, HIPAA and NRS 439.581 to 439.597. Detect session notes, transcripts or other patient records sent to a model API with no business-associate, HIPAA-eligible endpoint or de-identification safeguard.

Trust and provenance not reviewed by a lawyer · audit-grade · source verified 3 Oct 2026 · release 2026.10.03.4
Lane
Binding law — in force In force: applies since 1 Jul 2025
Official source
NRS 629.610(3) · captured 3 Oct 2026 · anchor hash (SHA-256) 07c45acbe0c8… · 5 more anchors in the data release
Verification
Quoted text found word for word in the captured official document (3 Oct 2026). Source last verified 3 Oct 2026: checked against the captured official document.
Data release
Data release 2026.10.03.4, data as of 3 Oct 2026, schema 0.3.9.
Legal review
Not reviewed by a lawyer. TwinEthos derived this rule from the official text it cites: treat it as research to check against that text; it is not legal advice. No TwinEthos rule has been legally reviewed yet. Open questions for counsel on this rule: 1.
Audit standard
Audit-grade: meets all 10 checks of the TwinEthos audit standard that apply to it. The audit standard is TwinEthos's own quality bar for provenance, dates, applicability, detectors, fixtures, remediation and licences; it is not a legal review.
Detectors

1 detector (code pattern), experimental: written from the rule's text and not yet measured for precision on real code, so treat a hit as a lead to verify.

Known limits:

  • Health fields renamed to generic identifiers
  • Model calls wrapped in an internal client
  • Vendor coverage (a business associate agreement, a HIPAA-eligible endpoint) is often recorded outside the repository; the finding asks for it, it does not establish that none exists.

Who it applies to

  • Duty falls on: individual professional
  • Sectors: healthcare
  • Nevada-licensed or certified providers of mental and behavioral health care as defined in NRS 629.610(6)(c): psychiatrists, psychologists, independent and clinical social workers, psychiatric-nursing registered nurses with a master's degree, marriage and family therapists, clinical professional counselors, alcohol and drug and problem gambling counselors, and trainees in those professions. Vendors of practice software are reached through what the provider may use AI for. Which privacy and security duties apply to a given AI vendor (business associate status, Nevada's health-information-exchange law) is a legal question. In force since 2025-07-01.
  • Whether it applies depends on facts outside the code; a person has to decide.

The guard to add

Send identifiable health data only to AI endpoints registered with a signed BAA or processing agreement and retention and training off; otherwise de-identify first.

A single client factory for model, embedding and transcription calls that handle health information: it looks the endpoint up in a vendor register and refuses to return a client unless the register shows the required contract (business associate agreement, or a processing agreement barring further disclosure) and the endpoint is the covered deployment with data retention and training use turned off. Call sites that cannot meet that de-identify or redact the record before building the prompt, or check a recorded patient authorization for that use. Keep the vendor register in the repository so reviewers can match each AI endpoint to its legal basis, and never route health data into marketing or other non-care generation.

Where it goes: 6 API calls and integrations, 3 config and feature flags, 7 prompt construction, 12 repository artifacts.

Example (Python + OpenAI SDK (Azure OpenAI)), before:

client = OpenAI()
resp = client.chat.completions.create(model='gpt-4o', messages=[
    {'role': 'user', 'content': f'Summarize: {patient.clinical_note}'}])

After:

VENDORS = load_yaml('vendors/ai_vendors.yaml')   # baa_signed, zero_data_retention per endpoint

def phi_client(name: str) -> tuple[AzureOpenAI, str]:
    v = VENDORS[name]
    if not (v['baa_signed'] and v['zero_data_retention']):
        raise PermissionError(f'{name} is not cleared for PHI')
    client = AzureOpenAI(azure_endpoint=v['endpoint'], api_key=os.environ['AZURE_OPENAI_KEY'],
                         api_version=v['api_version'])
    return client, v['deployment']

client, deployment = phi_client('azure-openai-hipaa')
resp = client.chat.completions.create(model=deployment, messages=[
    {'role': 'user', 'content': f'Summarize: {patient.clinical_note}'}])

Control: Health information sent to an external AI vendor without the contractual or legal basis the law requires. The same guard addresses 8 items with binding law in 7 jurisdictions. Engineering guidance, not legal advice.

Rule id nv-ab406.provider-ai-privacy-compliance · review status: primary source derived

Binding law — in force

Nevada mental and behavioral health providers must independently review the accuracy of AI-generated billing records and session notes (Nevada AB 406)

NRS 629.610(4) · official text · In force: applies since 1 Jul 2025 · Nevada (US-NV)

When a Nevada provider of mental and behavioral health care uses AI for billing (NRS 629.610(2)(c)) or for organizing, tracking and managing files or notes of a patient's session (2)(e), NRS 629.610(4) requires the provider to independently review the accuracy of any report, data or other information the AI compiles, summarizes, analyzes or generates. Detect AI-generated session notes or billing records committed as final or submitted with no provider review step.

Trust and provenance not reviewed by a lawyer · audit-grade · source verified 3 Oct 2026 · release 2026.10.03.4
Lane
Binding law — in force In force: applies since 1 Jul 2025
Official source
NRS 629.610(4) · captured 3 Oct 2026 · anchor hash (SHA-256) e41d0d86819e… · 5 more anchors in the data release
Verification
Quoted text found word for word in the captured official document (3 Oct 2026). Source last verified 3 Oct 2026: checked against the captured official document.
Data release
Data release 2026.10.03.4, data as of 3 Oct 2026, schema 0.3.9.
Legal review
Not reviewed by a lawyer. TwinEthos derived this rule from the official text it cites: treat it as research to check against that text; it is not legal advice. No TwinEthos rule has been legally reviewed yet. Open questions for counsel on this rule: 1.
Audit standard
Audit-grade: meets all 10 checks of the TwinEthos audit standard that apply to it. The audit standard is TwinEthos's own quality bar for provenance, dates, applicability, detectors, fixtures, remediation and licences; it is not a legal review.
Detectors

1 detector (data flow), experimental: written from the rule's text and not yet measured for precision on real code, so treat a hit as a lead to verify.

Known limits:

  • Review workflows enforced inside a vendor EHR or billing system rather than in the integrating code

Who it applies to

  • Duty falls on: individual professional
  • Sectors: healthcare
  • Nevada-licensed or certified providers of mental and behavioral health care as defined in NRS 629.610(6)(c): psychiatrists, psychologists, independent and clinical social workers, psychiatric-nursing registered nurses with a master's degree, marriage and family therapists, clinical professional counselors, alcohol and drug and problem gambling counselors, and trainees in those professions. Vendors of practice software are reached through what the provider may use AI for. The duty applies to AI output for billing and for session files and notes (629.610(2)(c), (e)). In force since 2025-07-01.
  • Whether it applies depends on facts outside the code; a person has to decide.

The guard to add

Hold AI-generated clinical output as a draft until an accountable clinician reviews and signs it, and record who approved it before it reaches the chart or the patient.

A clinician sign-off step between the model call and every clinical sink: AI-drafted notes, summaries, diagnostic suggestions, triage levels, and treatment plans are stored as drafts (FHIR DocumentReference.docStatus 'preliminary', DiagnosticReport.status 'preliminary', CarePlan.status 'draft') and become final, active, or visible to the patient only through an action by an authorized clinician that records reviewed_by and reviewed_at. Configuration flags that auto-sign or auto-finalize AI-drafted records stay false, and provenance shows the AI as a contributing device and the clinician as verifier. The deployment also names who is accountable for AI-assisted decisions and gives patients a complaint or redress route.

Where it goes: 1 application source code, 2 data models, 9 AI output handling, 3 config and feature flags.

What this provision adds:

  • Hold AI-generated billing records and session notes as drafts until the provider has reviewed their accuracy; record who reviewed and when.

Example (Python + OpenAI SDK + FHIR REST), before:

note = client.chat.completions.create(model=MODEL, messages=msgs).choices[0].message.content
requests.post(f'{FHIR_BASE}/DocumentReference', json=doc_ref(patient_id, note, doc_status='final'))

After:

note = client.chat.completions.create(model=MODEL, messages=msgs).choices[0].message.content
requests.post(f'{FHIR_BASE}/DocumentReference',
              json=doc_ref(patient_id, note, doc_status='preliminary'))   # AI draft

def practitioner_review_and_sign(doc_id, practitioner):   # only path to 'final'
    doc = requests.get(f'{FHIR_BASE}/DocumentReference/{doc_id}').json()
    doc['docStatus'] = 'final'
    doc['authenticator'] = {'reference': f'Practitioner/{practitioner.id}'}
    requests.put(f'{FHIR_BASE}/DocumentReference/{doc_id}', json=doc)
    audit.record(doc_id, reviewed_by=practitioner.id, reviewed_at=utcnow())

Control: Health AI without clinician oversight/accountability + redress. The same guard addresses 9 items with binding law in 6 jurisdictions. Engineering guidance, not legal advice.

Standards that recommend the same control

Related incidents

No guardrail sits on this exact control; these incidents are cited by guardrails on related controls.

Rule id nv-ab406.provider-review-of-ai-records · review status: primary source derived

Informational data, not legal advice. Summaries are TwinEthos's own words and rules have not been reviewed by a lawyer: check the official text before relying on any of it. A guard addresses an item; adding it is not a statement that your code meets any law.