TwinEthos homeAPI access

Law

Rhode Island ch. 23-108 (AI by Healthcare Providers Notification Act)

State of Rhode Island · Rhode Island (US-RI) · 2 provisions encoded · verified against the official source as of 2026-10-04.

Informational data, not legal advice. Summaries and rules have not been reviewed by a lawyer: always verify official law text for decisions. A suggested guard is intended to address each rule; adding it is not a statement of compliance to that law.

Official text: webserver.rilegislature.gov.

Trust and provenance 2 official sources · last verified 4 Oct 2026 · not reviewed by a lawyer · 2 of 2 provisions audit-grade · release 2026.10.05

Where this instrument's data comes from, how current it is, and what has and has not been checked. Each provision below has its own panel.

Official sources
Lanes
Binding law — in force 2
Verification
Sources last verified 4 Oct 2026; each provision states how.
Data release
Data release 2026.10.05, data as of 4 Oct 2026, schema 0.3.10.
Legal review
None of the 2 provisions has been reviewed by a lawyer; no TwinEthos rule has been legally reviewed yet. Treat each as research to check against the official text; it is not legal advice. Open questions for counsel on them: 2.
Audit standard
2 of 2 provisions audit-grade. The audit standard is TwinEthos's own quality bar for provenance, dates, applicability, detectors, fixtures, remediation and licences; it is not a legal review.
Detectors
2 detectors, all experimental: written from the rule's text and not yet measured for precision on real code, so treat a hit as a lead to verify. Each provision lists its detectors' known limits.
Changes
  • 2026.10.05 (5 Oct 2026): 2 provisions added

Each data release records which provisions changed; the full list is on Changes.

Binding law — in force

Tell patients when AI documents their visit (Rhode Island AI by Healthcare Providers Notification Act)

R.I. Gen. Laws 23-108-3 · official text · In force: applies since 22 Jun 2026 · Rhode Island (US-RI)

Since 2026-06-22, every healthcare provider licensed by the Rhode Island director of health and every healthcare facility that employs artificial intelligence to document in-person or telehealth visits must notify patients that AI is used for that purpose (R.I. Gen. Laws 23-108-3, enacted by P.L. 2026, ch. 199 and ch. 372). Detect ambient-scribe and note-drafting code that sends visit audio or transcripts to an AI model with no patient notice on the path.

Trust and provenance not reviewed by a lawyer · audit-grade · source verified 4 Oct 2026 · release 2026.10.05
Lane
Binding law — in force In force: applies since 22 Jun 2026
Official source
R.I. Gen. Laws 23-108-3 · captured 4 Oct 2026 · anchor hash (SHA-256) d749cdce15b9… · 6 more anchors in the data release
Verification
Quoted text found word for word in the captured official document (4 Oct 2026). Source last verified 4 Oct 2026: checked against the captured official document.
Data release
Data release 2026.10.05, data as of 4 Oct 2026, schema 0.3.10.
Legal review
Not reviewed by a lawyer. TwinEthos derived this rule from the official text it cites: treat it as research to check against that text; it is not legal advice. No TwinEthos rule has been legally reviewed yet. Open questions for counsel on this rule: 1.
Audit standard
Audit-grade: meets all 10 checks of the TwinEthos audit standard that apply to it. The audit standard is TwinEthos's own quality bar for provenance, dates, applicability, detectors, fixtures, remediation and licences; it is not a legal review.
Detectors

1 detector (data flow), experimental: written from the rule's text and not yet measured for precision on real code, so treat a hit as a lead to verify.

Known limits:

  • Notice given at check-in, in the EHR's patient portal or on paper outside the integrating code
  • Scribe tools configured in a vendor console

Who it applies to

  • Duty falls on: individual professional, organization
  • Sectors: healthcare
  • Rhode Island-licensed healthcare providers (physicians, physician assistants, dentists, nurses, nursing assistants and other professionals licensed by the director of health) and healthcare facilities (23-17-2(9)) that employ AI to document in-person or telehealth visits, and the ambient-scribe and note tools they deploy. In force since 2026-06-22. When and how the notice is given (each visit, at intake, in writing) is not specified and is for counsel.
  • Whether it applies depends on facts outside the code; a person has to decide.

The guard to add

Send the person an AI-use notice on the decision path, before or when an AI system makes or substantially factors a consequential decision about them, and record its delivery.

A notice step in the decision workflow itself (application intake, underwriting, eligibility, applicant or employee scoring, diagnostic support) that runs before the model call, e.g. send_admt_notice(consumer) ahead of underwrite(), or a notice block rendered on the intake page the person submits from. The notice says that AI is used in the decision, for what, and how to get more information or ask for review, and its delivery is stored with the decision (notice id, channel, timestamp). The template lives in the repo so its content is reviewable; a privacy-policy paragraph alone is not on the decision path.

Where it goes: 1 application source code, 9 AI output handling, 14 user-facing text.

What this provision adds:

  • Notify the patient that AI documents the visit, for in-person and telehealth visits alike, and keep a record that the notice was given.

Example (FastAPI + OpenAI SDK), before:

@app.post('/applications')
def apply(app_in: Application):
    resp = client.chat.completions.create(model=MODEL, messages=underwriting_prompt(app_in))
    return {'decision': underwrite(resp.choices[0].message.content)}

After:

@app.post('/applications')
def apply(app_in: Application):
    notice = send_admt_notice(app_in.applicant_id, template='ai_decision_notice_v2')
    resp = client.chat.completions.create(model=MODEL, messages=underwriting_prompt(app_in))
    decision = underwrite(resp.choices[0].message.content)
    db.decisions.insert(app_in.id, decision, notice_id=notice.id)
    return {'decision': decision, 'ai_notice': notice.text}

Control: Consequential AI decision without consumer notice. The same guard addresses 9 items with binding law in 8 jurisdictions. Engineering guidance, not legal advice.

Standards that recommend the same control

Rule id ri-hb7538.ai-visit-documentation-patient-notice · review status: primary source derived

Binding law — in force

Review AI-generated visit documentation for accuracy after the visit (Rhode Island AI by Healthcare Providers Notification Act)

R.I. Gen. Laws 23-108-3 · official text · In force: applies since 22 Jun 2026 · Rhode Island (US-RI)

Since 2026-06-22, healthcare providers and healthcare facilities in Rhode Island that employ artificial intelligence to document in-person or telehealth visits must review the AI-generated documentation for accuracy after the visit (R.I. Gen. Laws 23-108-3). Detect note pipelines that commit an AI-drafted visit note as final, sign it or submit it with no clinician review step.

Trust and provenance not reviewed by a lawyer · audit-grade · source verified 4 Oct 2026 · release 2026.10.05
Lane
Binding law — in force In force: applies since 22 Jun 2026
Official source
R.I. Gen. Laws 23-108-3 · captured 4 Oct 2026 · anchor hash (SHA-256) d749cdce15b9… · 6 more anchors in the data release
Verification
Quoted text found word for word in the captured official document (4 Oct 2026). Source last verified 4 Oct 2026: checked against the captured official document.
Data release
Data release 2026.10.05, data as of 4 Oct 2026, schema 0.3.10.
Legal review
Not reviewed by a lawyer. TwinEthos derived this rule from the official text it cites: treat it as research to check against that text; it is not legal advice. No TwinEthos rule has been legally reviewed yet. Open questions for counsel on this rule: 1.
Audit standard
Audit-grade: meets all 10 checks of the TwinEthos audit standard that apply to it. The audit standard is TwinEthos's own quality bar for provenance, dates, applicability, detectors, fixtures, remediation and licences; it is not a legal review.
Detectors

1 detector (data flow), experimental: written from the rule's text and not yet measured for precision on real code, so treat a hit as a lead to verify.

Known limits:

  • Review workflows enforced inside a vendor EHR rather than in the integrating code

Who it applies to

  • Duty falls on: individual professional, organization
  • Sectors: healthcare
  • Rhode Island-licensed healthcare providers and healthcare facilities (23-17-2(9)) that employ AI to document in-person or telehealth visits, and the note and EHR tools they deploy: the AI-generated documentation is reviewed for accuracy after the visit. In force since 2026-06-22. Who must review (the treating provider or another) and when, are not specified and are for counsel.
  • Whether it applies depends on facts outside the code; a person has to decide.

The guard to add

Hold AI-generated clinical output as a draft until an accountable clinician reviews and signs it, and record who approved it before it reaches the chart or the patient.

A clinician sign-off step between the model call and every clinical sink: AI-drafted notes, summaries, diagnostic suggestions, triage levels, and treatment plans are stored as drafts (FHIR DocumentReference.docStatus 'preliminary', DiagnosticReport.status 'preliminary', CarePlan.status 'draft') and become final, active, or visible to the patient only through an action by an authorized clinician that records reviewed_by and reviewed_at. Configuration flags that auto-sign or auto-finalize AI-drafted records stay false, and provenance shows the AI as a contributing device and the clinician as verifier. The deployment also names who is accountable for AI-assisted decisions and gives patients a complaint or redress route.

Where it goes: 1 application source code, 2 data models, 9 AI output handling, 3 config and feature flags.

What this provision adds:

  • Hold AI-generated visit documentation as a draft until it has been reviewed for accuracy after the visit; record who reviewed it and when.

Example (Python + OpenAI SDK + FHIR REST), before:

note = client.chat.completions.create(model=MODEL, messages=msgs).choices[0].message.content
requests.post(f'{FHIR_BASE}/DocumentReference', json=doc_ref(patient_id, note, doc_status='final'))

After:

note = client.chat.completions.create(model=MODEL, messages=msgs).choices[0].message.content
requests.post(f'{FHIR_BASE}/DocumentReference',
              json=doc_ref(patient_id, note, doc_status='preliminary'))   # AI draft

def practitioner_review_and_sign(doc_id, practitioner):   # only path to 'final'
    doc = requests.get(f'{FHIR_BASE}/DocumentReference/{doc_id}').json()
    doc['docStatus'] = 'final'
    doc['authenticator'] = {'reference': f'Practitioner/{practitioner.id}'}
    requests.put(f'{FHIR_BASE}/DocumentReference/{doc_id}', json=doc)
    audit.record(doc_id, reviewed_by=practitioner.id, reviewed_at=utcnow())

Control: Health AI without clinician oversight/accountability + redress. The same guard addresses 11 items with binding law in 7 jurisdictions. Engineering guidance, not legal advice.

Standards that recommend the same control

Related incidents

No guardrail sits on this exact control; these incidents are cited by guardrails on related controls.

Rule id ri-hb7538.clinician-review-of-ai-visit-documentation · review status: primary source derived

Informational data, not legal advice. Summaries are TwinEthos's own words and rules have not been reviewed by a lawyer: check the official text before relying on any of it. A guard addresses an item; adding it is not a statement that your code meets any law.