About
Health Care

Health Care

Tracking Health Care legal and regulatory developments.

14 entries in Legal Intelligence Tracker

LawSnap Briefing Updated May 11, 2026

State of play.

  • Enforcement has moved from policy to litigation. A state AG has filed the first major enforcement action targeting a chatbot that impersonated a physician in a clinical setting, treating deceptive AI conduct as consumer fraud . Class actions against Sutter Health and MemorialCare over ambient AI scribe deployments follow a November 2025 case against Sharp HealthCare, establishing a pattern of wiretapping and consent-based claims against health systems — not vendors .
  • The federal preemption play is live but unresolved. The White House's March 2026 National Policy Framework proposes legislation to preempt state AI laws imposing "undue burdens," distributing oversight across FDA, CMS, HHS, OCR, FTC, and DOJ — but no preemptive statute has passed, and over 177 state bills remain active across 31 states .
  • Genetic data from M&A is the next class action frontier. Tempus AI faces multi-state class actions alleging it transferred genetic data from over one million Ambry Genetics patients — without consent — to train AI models and license to more than 70 pharma and biotech partners under agreements valued above $1.1 billion .
  • The Second Circuit has narrowed insurer fraud defenses in no-fault reimbursement. The panel held that anti-kickback violations do not automatically disqualify providers from no-fault eligibility under New York law, certifying the core question to the New York Court of Appeals — affecting hundreds of pending cases and more than $1 billion in annual reimbursements .
  • For counsel advising health systems, digital health platforms, or life sciences companies, the practical baseline is simultaneous exposure across three vectors: AI deployment consent failures generating wiretapping and HIPAA-adjacent liability, acquisition-triggered genetic data claims, and a federal preemption framework that may or may not arrive before state enforcement accelerates further.

Where things stand.

  • AI scribe consent litigation is a pattern, not an isolated case. The Sutter Health/MemorialCare class action alleges CMIA, CIPA, and Federal Wiretap Act violations, with plaintiffs pointing to false chart documentation of consent — and Abridge, the vendor, is not named as a defendant, placing institutional liability squarely on the health system . The Sharp HealthCare case filed November 2025 established the template.
  • State AG enforcement is treating deceptive AI conduct as consumer fraud. The first enforcement action against a chatbot impersonating a physician signals that regulators will not wait for AI-specific statutes — existing consumer protection authority is the vehicle .
  • Federal AI governance is distributed, not centralized. The March 2026 National Policy Framework routes oversight through existing agencies rather than a new body; the Department of Commerce would evaluate conflicting state laws; compliance sandboxes are proposed but not yet operative .
  • Genetic data de-identification is contested doctrine. Tempus AI's defense that transferred Ambry data was de-identified faces the plaintiffs' argument that genetic information is inherently identifiable — a question courts have not yet resolved under state genetic privacy statutes .
  • AI drug discovery is compressing timelines and creating IP gaps. A Nature Reviews Drug Discovery review by Pun et al. documents AI embedding patentability and competitor analysis into target selection; the FDA fast-tracked 12 AI-identified oncology drugs in 2024; premature patents on unvalidated candidates and inventorship gaps under EPC Article 81 and U.S. law remain unresolved .
  • Consumer-facing AI health platforms are proliferating without a settled regulatory framework. Microsoft Copilot Health, launched March 2026, aggregates EHR, lab, and wearable data for roughly 50,000 U.S. hospital-connected organizations; Microsoft's commitment not to use Copilot Health data for model training is positioned as a voluntary benchmark, not a legal requirement .
  • The FTC under reconstituted Republican leadership has signaled enforcement focus on hidden fees, dark patterns, and subscription traps across healthcare and digital platforms. Following the 2025 dismissals of Democratic commissioners, Chairman Ferguson has outlined a shift toward fraud redress over structural antitrust .
  • No-fault reimbursement enforcement authority has shifted toward state regulators. The Second Circuit's March 2026 decision constrains insurers' unilateral denial of claims based on provider misconduct, leaving GEICO's fraud and RICO theories for further proceedings pending New York Court of Appeals resolution .

Latest developments.

  • State AG files first enforcement action against AI chatbot impersonating a physician in a clinical setting, framing the conduct as consumer fraud .
  • Class action against Sutter Health and MemorialCare alleges CIPA, CMIA, and Federal Wiretap Act violations over Abridge ambient scribe deployment without patient consent; false chart documentation of consent alleged .
  • Tempus AI faces multi-state class actions alleging unconsented transfer of genetic data from over one million Ambry Genetics patients for AI model training and pharma licensing .
  • White House National Policy Framework for AI proposes federal preemption of state AI laws; no preemptive statute has passed; 177 state bills remain active .
  • Second Circuit vacates GEICO summary judgment in no-fault kickback case, holding anti-kickback violations do not automatically disqualify providers from reimbursement eligibility; question certified to New York Court of Appeals .
  • Microsoft launches Copilot Health, aggregating EHR, lab, and wearable data; commits not to use data for model training; competes directly with OpenAI ChatGPT Health and Anthropic Claude for Healthcare .
  • Senate Commerce Committee holds first FTC oversight hearing in nearly six years; Chairman Ferguson outlines enforcement priorities including healthcare dark patterns and subscription traps .
  • Nature Reviews Drug Discovery review documents AI embedding patentability analysis into drug target selection; USPTO extends AI Search Automated Pilot through June 2026 .
  • McKinsey 2025 survey finds 50 percent of healthcare organizations have implemented generative AI; agentic AI emerging as next deployment wave .

Active questions and open splits.

  • Whether health systems or vendors bear liability for AI scribe consent failures. The Sutter/MemorialCare complaint names only the health systems, not Abridge — but vendor agreements, indemnification provisions, and BAA structures will determine ultimate allocation; courts have not yet resolved the institutional-vs.-vendor responsibility split .
  • Whether genetic data can be meaningfully de-identified under state genetic privacy statutes. Tempus AI's de-identification defense is untested at the class action level; the outcome will govern how every healthcare platform structures post-acquisition data integration and downstream licensing .
  • Whether the federal AI preemption framework displaces state enforcement before state litigation matures. With 177 state bills active and no federal statute enacted, the window for state-law claims is open; if preemption legislation advances, retroactive effect on pending suits is unsettled .
  • What consent standard satisfies CIPA and the Federal Wiretap Act for ambient AI documentation. Boilerplate chart language stating patients "were advised" has been directly challenged as fabricated; whether any disclosure-at-intake mechanism satisfies all-party consent in California remains unresolved .
  • Whether AI chatbot impersonation of clinicians triggers consumer fraud liability independent of harm. The state AG enforcement action frames deception as the violation — not a specific patient injury — which, if sustained, sets a low threshold for future enforcement across clinical AI deployments .
  • Inventorship and patentability gaps in AI-generated drug candidates. With AI now embedding patentability analysis into target selection, premature filing on unvalidated candidates and inventorship attribution under EPC Article 81 and U.S. law remain open — and the USPTO's AI Search Automated Pilot does not resolve the underlying inventorship question .
  • Whether the Second Circuit's no-fault ruling shifts enforcement leverage from insurers to state regulators. The New York Court of Appeals certification will determine whether anti-kickback violations can ever serve as a reimbursement-eligibility defense — with hundreds of pending cases in the balance .

What to watch.

  • New York Court of Appeals resolution of the certified no-fault eligibility question — outcome reshapes insurer fraud-defense strategy across the $1 billion-plus annual no-fault market .
  • Early motions practice in the Sutter Health/MemorialCare AI scribe case — particularly whether courts treat vendor-deployed ambient recording as categorically different from provider-initiated recording under CIPA .
  • Whether additional state AGs file consumer fraud actions against AI health tools following the chatbot-impersonation enforcement template .
  • Congressional movement on the White House AI preemption framework — any committee action will signal whether federal standards will arrive before state litigation produces binding precedent .
  • Tempus AI's de-identification defense in the Northern District of Illinois — the court's treatment of genetic data anonymization will set the M&A data-integration standard for life sciences transactions .
  • USPTO expiration of the AI Search Automated Pilot on June 1, 2026 — whether it is extended or replaced will affect prosecution strategy for AI-identified drug candidates .

14 Contributing Entries

UN releases 2026 International AI Safety Report warning of enormous benefits and existential risks

The United Nations released the International AI Safety Report 2026, a comprehensive assessment concluding that advanced artificial intelligence presents both transformative opportunities and escalating dangers. The report, led by the UN agency for digital technology, finds that AI can accelerate development in health, education, and financial services in developing nations while simultaneously enabling cyberattacks, deepfake fraud, non-consensual intimate imagery, and biological weapon design. The core finding: AI capabilities in critical fields like biological research are advancing faster than governance frameworks, creating a dangerous gap between what is technologically possible and what remains safe.

American Healthcare Systems Files Amended Complaint Against Former Counsel Over Takeover Scheme

American Healthcare Systems Corp. and its founder Mike Sarian filed an amended complaint in California state court on Tuesday, July 7, 2026, accusing their former in-house counsel Faisal Gill of orchestrating an extortion and takeover scheme. The complaint also names Dr. Aramais Paronyan, a minority shareholder and director, as a participant in efforts to remove Sarian from control and restrict his access to company finances. AHS operates five Florida hospitals, including Palmetto General and Coral Gables Hospital.

Former Mayo Clinic AI Director Sues System Over Alleged Retaliation and AI Safety Cover-Up

Traci Tamiko Eto, former research director at Mayo Clinic, filed a federal lawsuit on July 6, 2026, alleging retaliation and wrongful termination after she raised concerns about AI safety failures and patient privacy violations. According to the complaint, Eto was demoted in July 2025, placed on involuntary medical leave, and fired in December 2025 when her position was eliminated in a reduction in force that reportedly affected only her role. The suit was filed in U.S. District Court for the District of Minnesota under the False Claims Act's retaliation provision, the Americans with Disabilities Act, and the Family and Medical Leave Act.

FTC, Utah, and California Sue Hims & Hers Over Health Data and Billing Practices

The FTC, joined by Utah and California, sued telehealth company Hims & Hers Health, Inc. on July 29, 2026, in U.S. District Court for the Northern District of California. The complaint alleges that Hims shared consumers' sensitive health information with third-party ad platforms including Meta and Snap despite privacy commitments, and that it charged customers for prescriptions immediately after intake forms were completed—before any provider consultation occurred. The agencies also claim Hims misled customers about billing, subscriptions, and cancellation procedures. The FTC alleges violations of the FTC Act and the Restore Online Shoppers' Confidence Act (ROSCA), while Utah and California assert violations of state consumer protection and false-advertising statutes.

California expands PFAS fraud case against DuPont spinoffs over asset transfers

California Attorney General Rob Bonta filed a Second Amended Complaint in the state's PFAS litigation, alleging that DuPont-related companies executed fraudulent asset transfers designed to shield themselves from environmental liability. The complaint targets E. I. du Pont de Nemours and Company, DuPont de Nemours, Inc., Corteva, Inc., The Chemours Company, and newly created Qnity Electronics. Bonta contends that corporate restructuring and amended agreements shifted the bulk of PFAS-related liabilities onto Chemours while reducing exposure for New DuPont, Corteva, and Qnity Electronics. The filing invokes the Uniform Fraudulent Transfer Act and the Uniform Voidable Transactions Act, and seeks relief in U.S. District Court for the District of South Carolina.

States tighten rules on AI therapy chatbots amid rising mental health use

Seven states have now enacted laws restricting AI-powered therapy chatbots, with five new restrictions taking effect in 2026. Colorado, Maine, Rhode Island, Tennessee, and Vermont joined Illinois and Nevada in prohibiting or severely limiting how artificial intelligence can deliver mental health services. Colorado's law, effective June 3, bars AI therapy chatbots entirely and restricts how licensed professionals can deploy AI tools. Maine treats unauthorized AI therapy as an unfair trade practice. Rhode Island requires that all therapy services be delivered by licensed professionals and prohibits AI from making independent treatment decisions. Tennessee bars AI systems from advertising themselves as qualified mental health professionals. Vermont prohibits AI from independently delivering mental health services. Illinois and Nevada adopted similar restrictions in 2025.

Over 23,000 Kaiser Nurses Join Therapists in One-Day Strike Over AI Concerns

On March 2026, more than 23,000 Kaiser Permanente nurses and approximately 2,400 mental health professionals in Northern California staged a coordinated six-hour strike across five facilities—Fresno, Oakland, Sacramento, Santa Clara, and Santa Rosa Medical Centers. The work stoppage, which ran from 8 a.m. to 2 p.m., was organized by the National Nurses United and the National Union of Healthcare Professionals to protest Kaiser's expanding use of artificial intelligence in patient care and clinical roles.

FTC, California, and Utah Sue Hims & Hers Over Health Data and Billing Practices

The Federal Trade Commission, joined by California and Utah, has sued telehealth company Hims & Hers Health, Inc. in U.S. District Court for the Northern District of California, alleging that the company shared sensitive health data with advertising platforms including Meta and Snap while marketing itself as private and discreet. The complaint also charges Hims with deceptive subscription practices, including charging customers immediately after intake forms were submitted—before any medical consultation occurred—and making cancellation unreasonably difficult. The FTC alleges violations of the FTC Act and the Restore Online Shoppers' Confidence Act, while California invokes its False Advertising and Unfair Competition Laws and Utah cites its Consumer Sales Practices Act.

FTC, Utah, and California Sue Hims & Hers Over Health Data Sharing

The FTC, joined by Utah and California, filed a federal complaint in the U.S. District Court for the Northern District of California against Hims & Hers Health, Inc., alleging the telehealth company shared consumers' sensitive health information with third-party advertising platforms including Meta and Snap while publicly promising privacy protection. The complaint also charges that Hims & Hers misled users about billing and cancellation practices. According to the filing, the company disclosed health-related data and customer lists through tracking technologies embedded on its website, charged consumers for prescriptions immediately after intake forms were submitted—before any provider consultation occurred—and deliberately made subscriptions difficult to cancel. The FTC alleges violations of the FTC Act and the Restore Online Shoppers' Confidence Act (ROSCA), while Utah invokes the Utah Consumer Sales Practices Act and California cites its False Advertising and Unfair Competition laws.

House Appropriations Committee Votes to Defund WISeR AI Prior Authorization Pilot

The House Appropriations Committee voted unanimously Tuesday to strip funding for WISeR, a CMS pilot program that uses artificial intelligence to impose prior authorization requirements on traditional Medicare beneficiaries. The committee adopted an amendment to the FY 2027 HHS appropriations bill that prohibits the Centers for Medicare & Medicaid Services from spending federal dollars on WISeR or any similar prior authorization model targeting traditional Medicare. The vote represents the first formal legislative action against the program, which CMS launched last year as a six-year Innovation Model beginning January 1, 2026.

Judge Approves $46.75M Bankruptcy Settlement for 23andMe 2023 Data Breach Victims

A U.S. bankruptcy judge has approved a $46.75 million settlement to compensate victims of 23andMe's 2023 data breach, resolving claims after the genetic testing firm exposed the genetic data of nearly 6.9 million people worldwide. U.S. Bankruptcy Judge Brian Walsh in St. Louis ordered Chrome Holding—the entity that acquired 23andMe following its bankruptcy filing—to disburse the funds through Kroll Restructuring within five days.

UN independent panel warns unchecked AI progress poses catastrophic risks

On July 1, 2026, the UN's Independent International Scientific Panel on Artificial Intelligence released a preliminary report warning that unregulated AI development is outpacing both scientific understanding and government policy, with no guarantee against catastrophic harm. Led by UN Secretary-General António Guterres and computer scientist Yoshua Bengio, the panel identified specific risks: loss of control over autonomous systems, deceptive AI behaviors, and exploitation for fraud, cyberattacks, and biological threats. The report notes that AI already demonstrates expert-level reasoning in mathematics and science, with task complexity doubling every four to seven months, while current models trained on only a fraction of the world's 7,000 languages produce dangerous errors in health diagnoses for many populations.

Patients are using AI to read lab results before doctors do

Patients are increasingly pasting lab results and medical test data into consumer AI chatbots like Claude and Gemini to interpret findings before or instead of consulting their physicians. The trend has prompted pushback from doctors, who warn that these tools frequently produce incorrect medical explanations and may inadvertently expose protected health information. The behavior shift reflects a broader adoption pattern: roughly one-third of U.S. adults now consult AI for health advice, creating real-time pressure on clinicians to correct AI-generated misreadings during patient encounters.

Federal Judge Denies Meta's Summary Judgment, Allowing NJ Youth Mental Health Trial to Proceed

A federal judge in California has denied Meta Platforms' motion for summary judgment, clearing the way for a multistate lawsuit over youth mental health to proceed to trial in August 2026. The ruling, issued June 29 by the U.S. District Court for the Northern District of California, rejects Meta's attempt to have the case dismissed and confirms that the attorneys general's claims have sufficient legal merit to survive pretrial scrutiny.

mail Subscribe to Health Care email updates

Primary sources. No fluff. Straight to your inbox.

Also on LawSnap