Generative AI in clinical documentation

A note-summarizing tool meets the law of the medical record, not the law of chatbots.

When a generative tool drafts the chart summary and the referral letter, the questions come from health information management, not from the AI press: who signs the entry, what happens when the summary is wrong, where the protected health information goes, and what the patient has to be told. This page shows the determination for one such tool.

The laws considered for the clinical notes example in LegisGate

The example

Clinical Notes Summarizer: an internal tool, used by clinicians.

It summarizes clinicians' visit notes into a short summary for the patient's chart and the referral letter. The clinician reads and edits every summary before it is saved; the tool makes no decision about a patient. It is used in the United States, California and Texas.

52
laws considered in those jurisdictions
7
returned obligations
25
obligations, 24 in force today
None
EU AI Act tier: no EU jurisdiction was declared

What the CMIO and the HIM director ask

The law of the record, answered from the determination.

Each obligation is quoted as the platform renders it for this tool, with its citation.

01

Who signs an AI-drafted entry in the chart?

The responsible clinician does, every time. The Conditions of Participation returned four obligations for this tool, and this is the one that changes a documentation workflow: it reaches AI-drafted entries by name. The vendor, meanwhile, is a contracted service the governing body answers for.

  • Have the responsible clinician authenticate every medical record entry, including AI-drafted entries42 C.F.R. § 482.24CMS Conditions of Participation
  • Treat the AI vendor as a contracted service the governing body answers for42 C.F.R. § 482.12CMS Conditions of Participation
02

What happens when a summary is wrong?

It is a quality event, and the tool belongs inside the hospital's quality program rather than outside it: the determination places AI-related errors and adverse events under QAPI tracking.

  • Bring Clinical Notes Summarizer into the hospital's QAPI program, including tracking AI-related errors and adverse events (42 C.F.R. § 482.21)42 C.F.R. § 482.21CMS Conditions of Participation
03

The notes are ePHI. What does HIPAA ask of the AI system itself?

HIPAA returned nine obligations, the most of any law here, and the first is the business associate agreement. After that, the administrative, physical and technical safeguards reach into the AI system, and the minimum-necessary standard limits what it is given.

  • Check the business associate agreement for Clinical Notes Summarizer against 45 C.F.R. § 164.504(e)45 C.F.R. § 164.502(e)HIPAA
  • Administrative safeguards - security management, workforce, access, training, and contingency covering ePHI in the AI system (45 CFR § 164.308)45 C.F.R. § 164.308HIPAA
  • Technical safeguards - access control, audit controls, integrity, authentication, and transmission security for ePHI in the AI system (45 CFR § 164.312)45 C.F.R. § 164.312HIPAA
  • Minimum necessary - limit ePHI uses, disclosures, and requests to the minimum needed (45 CFR § 164.502(b))45 C.F.R. § 164.502(b)HIPAA
04

Do we have to tell the patient?

In Texas, yes, by the first date of service: the Texas Responsible AI Governance Act returned two obligations, and the disclosure is one of them. The federal interoperability rules add that the tool must not interfere with access, exchange or use of electronic health information.

  • Disclose Clinical Notes Summarizer's AI use to the patient by the first date of serviceTex. Bus. & Com. Code § 552.051(f)Texas Responsible AI Governance Act
  • Do not let the AI system's deployment interfere with access, exchange or use of electronic health information45 C.F.R. § 171.103ONC Part 171
  • Strengthened right of access — electronic copies45 C.F.R. § 164.524HITECH
05

Does California add anything for a tool patients never see?

Yes. The CCPA returned six obligations for this tool, and they speak of sensitive personal information: limits on use and disclosure, a risk assessment before the processing, and a vendor agreement that carries the service-provider or contractor terms.

  • Limit use and disclosure of sensitive PICal. Civ. Code § 1798.121CCPA / CPRA
  • Confirm the Clinical Notes Summarizer vendor agreement meets the required service-provider or contractor termsCal. Civ. Code § 1798.100(d)CCPA / CPRA

Every law that returned obligations

Seven laws, twenty-five obligations.

Texas, the federal interoperability rules and the nondiscrimination provision of the Affordable Care Act each returned obligations of their own.

  • HIPAAUnited States · 9 obligations
  • CCPA / CPRACalifornia · 6 obligations
  • CMS Conditions of ParticipationUnited States · 4 obligations
  • Texas Responsible AI Governance ActTexas · 2 obligations
  • ONC Part 171United States · 2 obligations
  • ACA Section 1557United States · 1 obligation
  • HITECHUnited States · 1 obligation

Also in those jurisdictions, with no obligation attached to this tool: California AB 3030, California SB 942 and CMS WISeR. 40 of the 52 laws did not apply, each recorded with the reason (ECOA, for one, because the tool makes no credit decisions), and 2 could not be determined because a question was not answered: the False Claims Act and FedRAMP. A further 261 laws outside the declared jurisdictions were also evaluated. The figures are as recorded on October 7, 2026 and move when the law library or the answers change and the AI use case is checked again. Your result depends on your own answers.

Why there is no EU AI Act tier

No EU jurisdiction was declared for this tool.

The determination records the EU AI Act as not in scope for this tool, and the page shows no tier. The tier follows the use and the jurisdictions declared, not the kind of model.

Getting started

Your first five AI use cases are free.

Add your own AI use case, answer the intake form and read the determination.

Talk to usWe're here to help
Which Laws Reach a Generative AI Tool? | LegisGate™