Commentary|Videos|October 1, 2026

The HIPAA and malpractice risks physicians take on with AI tools

Fact checked by: Keith A. Reynolds

An artificial intelligence vendor that keeps patient data after a contract ends can leave the practice holding the liability once the vendor's damages cap runs to zero, according to health care attorney Tatiana Melnik, J.D.


Medical practices are using artificial intelligence (AI) tools to draft visit notes, schedule appointments and work through prior authorizations. Once a tool can reach protected health information, the Health Insurance Portability and Accountability Act (HIPAA) applies "same as it does to every other technology," said Tatiana Melnik, J.D., a Tampa, Florida, health care attorney with Melnik Legal PLLC who represents physician practices.

Melnik led the session "Privacy and Security Legal Issues in the Age of Artificial Intelligence" on Sept. 28 at the Medical Group Management Association (MGMA) 2026 Annual Conference in San Antonio. She sat down with Medical Economics at the conference. Her first advice was to review vendor contracts, existing and new, and understand what consents the practice has granted.

What to look for in an AI vendor contract

Before AI, letting a vendor de-identify patient data may have been a low-risk decision. "Now, in the age of AI, you might decide it's high risk because re-identification is so easy," Melnik said.

She flagged "usage data" clauses, which usually cover the clicks a vendor tracks to troubleshoot its software, and questioned whether an AI prompt now counts. Practices should pin down what a vendor means by that phrase and by "confidential information," whether the vendor may keep data after the contract ends and whether it can actually delete it, she said.

Many of these contracts cap the vendor's liability at 12 months of fees paid before an incident, according to Melnik. "Well, if the incident arises three years after the contract because you've allowed them to keep your data post termination, then the damages cap is zero," she said. Under HIPAA, she added, the covered entity bears most of the risk.

AI scribes, consent and malpractice coverage

Patients in California have filed consumer class actions against medical practices and hospital systems using AI scribes, saying they did not consent, Melnik said. She expects malpractice carriers to begin denying coverage in some cases where AI was involved, for example when a physician didn't review notes an AI scribe produced, with the carrier arguing, in her words, "that's a technology issue. That's not a malpractice issue." She likened it to electronic health records, whose audit trails let plaintiffs' attorneys question notes edited months after a visit.

Her recommendation is to ask patients and get their affirmative consent, with a process ready for those who decline. A practice may be able to turn the tool off, or it may decide, as some did with electronic records, that patients who object can't be seen there. Melnik said the notice of privacy practices, which HIPAA already requires, is the best place for AI disclosures. "There is no reason why they can't add AI terminology to their existing notice of privacy practices," she said.

Patients who arrive having asked a chatbot about their symptoms should be handled with the same processes practices already use for patients who consulted "Doctor Google," she said.

Melnik also urged practices to prepare their staff. "This technology is coming. It's not going away," she said, pointing out that practices have adapted to new technology before.


Medical Economics was in San Antonio at the MGMA Annual Conference, Sept. 27-30, celebrating 100 years of MGMA, attending sessions and speaking with industry leaders. Follow our coverage on our MGMA conference page.


Related to this article