Skip to content

California AB 3030: AI Disclaimers in Patient Communications

9 min read · updated August 11, 2026

AB 3030 asks for two things, not one, and implementations routinely ship the first and forget the second. It also contains an exemption that a well-designed workflow can sit inside permanently.

Who is bound, and by what

AB 3030 was signed in September 2024 and took effect on 1 January 2025. It added a new article beginning at section 1339.75 to Chapter 2 of Division 2 of the California Health and Safety Code. The duty falls on health facilities, clinics, physician’s offices and group practices — the provider organisations, not the software vendors. A company selling a message-drafting product into a California clinic is not the regulated party; its customer is, which changes what belongs in the contract rather than in the product.

Where such a provider uses generative artificial intelligence to generate written or verbal patient communications pertaining to patient clinical information, the communication must include two things:

  • A disclaimer stating that the communication was generated by generative AI.
  • Clear instructions describing how the patient may contact a human health care provider, employee of the facility, or other appropriate person.

The second is the one that gets dropped. A banner saying “this message was drafted with AI” satisfies half the section. Without a route back to a human it does not satisfy the section at all.

Nothing here is legal advice, and the scope of “clinic” and “group practice” under the Health and Safety Code is narrower than everyday usage. Take advice on whether your organisation is a covered entity for this article specifically.

The line: patient clinical information

The article reaches communications pertaining to patient clinical information, which the statute frames in terms of information relating to the health status of a patient. That boundary is the whole compliance question for most products, because a portal sends both kinds of message from the same queue.

An AI-drafted reply explaining what a lab value means, whether a symptom warrants a visit, or how to take a medication is clinical. An appointment reminder, a bill, a parking instruction, a form request or a “your results are ready, log in to view them” notice is administrative and outside the article — even though it is sent by the same system to the same patient. Building one blanket disclaimer onto every outbound message is a defensible over-compliance choice, but it trains patients to ignore the banner, which is the opposite of what the section is for.

The harder cases are the mixed ones. A message that confirms an appointment and adds AI-generated preparation instructions (“nothing to eat after midnight because of the procedure”) carries clinical content inside an administrative wrapper. There is no California case law drawing that line, and the safe reading is that the clinical sentence pulls the whole message in.

Where the disclaimer has to appear

The statute does not leave placement to taste. It specifies it by medium, and the differences matter for anyone building the UI:

  • Written communications — the disclaimer appears at the beginning, not in a footer.
  • Continuous online interactions, such as a chat interface — prominently displayed throughout the interaction, not once at the top of a scrolling transcript.
  • Audio communications — verbally at the start and at the end of the interaction.
  • Video communications — prominently displayed throughout.

“Throughout” is the requirement that a typical chat build fails. A one-time system message at the top of the thread scrolls out of view within a few turns; a persistent header or a per-message label does not. The primary text is at California Legislative Information.

The licensed-review exemption

The article does not apply where the AI-generated communication is read and reviewed by a licensed or certified human health care provider. This is the most consequential sentence in the statute and it points directly at a product design: a draft-and-approve workflow, where the clinician sees the generated text and sends it deliberately, is outside the disclaimer requirement altogether. A fully automated send is inside it.

Two cautions on relying on that. First, review has to be real. A one-click bulk approve across forty drafts is a workflow a regulator could characterise as not reading, and no California authority has yet tested where the floor is — so treat “how do we evidence review” as an open question and log it. Second, the exemption is about the disclaimer, not about the underlying professional duty: a clinician who approves a wrong AI-drafted answer owns that answer.

“Read and reviewed” has no implementing regulation and no reported California decision construing it as at the date on this page. Whether a given review step qualifies is unresolved, and it is exactly the kind of question to put to counsel with your actual screen recordings rather than a description.

Enforcement, and how this sits with HIPAA

Enforcement follows the existing licensing structure rather than creating a new one. Violations by physicians and surgeons are enforceable by the Medical Board of California and the Osteopathic Medical Board of California; violations by facilities and clinics are enforceable by the California Department of Public Health under its normal licensing powers. There is no private right of action in the article, which means the realistic exposure is a licensing action or a survey finding, not a class action — a different shape of risk from statutes with private enforcement.

AB 3030 is a disclosure statute and does nothing about the data. Using a third-party model to draft a message that contains protected health information is a HIPAA question in its own right: the vendor is a business associate, the agreement has to exist before the first request, and the amount of record you paste into the prompt is a minimum-necessary question. Those are covered separately in the BAA clauses page and the minimum-necessary page. Satisfying AB 3030 tells you nothing about either.

Nor does AB 3030 turn a drafting tool into a medical device. Device status is a federal question under the Food, Drug, and Cosmetic Act and turns on the intended use and on whether a clinician can independently review the basis for the output; see the medical device regulation page. A product can comfortably be outside device regulation and squarely inside this disclaimer duty, and the two analyses have to be done separately.