An artificial intelligence vendor that retains patient data after a contract concludes can leave the medical practice holding significant liability, especially once the vendor's damages cap runs to zero. Health care attorney Tatiana Melnik, J.D., highlights the critical need for physicians to understand the HIPAA implications and malpractice risks associated with integrating AI tools into their practice workflows.
Medical practices are increasingly adopting artificial intelligence (AI) tools for various tasks such as drafting visit notes, scheduling appointments, and managing prior authorizations. Tatiana Melnik, J.D., a health care attorney, emphasized at the Medical Group Management Association (MGMA) 2026 Annual Conference that the Health Insurance Portability and Accountability Act (HIPAA) applies to these AI tools just as it would to any other technology. This legal framework immediately becomes relevant once an AI tool accesses protected health information. Melnik's primary recommendation for medical practices is to thoroughly review both existing and new AI vendor contracts to fully comprehend the consents they are granting to these technology providers and to actively mitigate potential legal exposures.
The landscape for patient data privacy has shifted significantly with the advent of AI. Previously, allowing a vendor to de-identify patient data might have been considered a low-risk decision. However, in the current AI era, this has become a high-risk activity due to AI's advanced capabilities for re-identification, as noted by Melnik. Physicians and practices must meticulously examine 'usage data' clauses in vendor contracts, clarifying whether the use of AI prompts is included under this definition. It is also crucial to precisely define 'confidential information' and to understand if vendors are permitted to retain patient data after a contract terminates, and if they possess the actual capability to permanently delete it. A critical concern highlighted by Melnik is that many AI vendor contracts cap liability at 12 months of fees paid prior to an incident. If a data breach or other issue emerges three years post-contract termination, especially if the vendor was allowed to retain data, the damages cap effectively becomes zero. This scenario leaves the covered entity—the medical practice—to bear the majority of the financial and legal risk under HIPAA regulations, underscoring the urgent need for careful contract negotiation and robust data management policies.
The use of AI scribes has already led to consumer class action lawsuits in California against medical practices and hospital systems, with patients alleging a lack of informed consent for the AI's involvement in their care. Attorney Melnik anticipates a significant trend where malpractice insurance carriers may begin denying coverage in cases involving AI, particularly if a physician failed to adequately review AI-generated notes. Carriers might argue that such incidents represent a 'technology issue' rather than a traditional 'malpractice issue,' drawing parallels to how electronic health records' audit trails can be used by plaintiffs' attorneys to scrutinize notes edited long after patient visits. Melnik strongly advises practices to obtain explicit, affirmative consent from patients before deploying AI scribes and to establish a clear, documented protocol for patients who decline. Practices might need to disable the AI tool for non-consenting patients or, akin to the early adoption challenges with electronic records, consider policies for patients who object to AI use. She further recommends integrating comprehensive AI disclosures into the existing HIPAA-mandated notice of privacy practices, ensuring full transparency with patients. Additionally, practices should equip their staff to effectively handle patients who arrive having already consulted AI chatbots about their symptoms, applying similar established processes used for patients who self-diagnose using general internet search engines. Melnik concluded by emphasizing the inevitability and pervasive nature of AI in healthcare, urging practices to proactively adapt and prepare their staff for these technological advancements to mitigate future risks and ensure patient trust.