USA – CALIFORNIA Trends and Developments Contributed by: Lowell Brown and Douglas Grimm, ArentFox Schiff LLP
Enforcement Mechanisms and Penalties Non-compliance with California’s healthcare AI regu - lations carries enforcement risks and potential penal - ties, including administrative fines, civil litigation, and criminal charges, as applicable under state law. State agencies and the Attorney General’s office possess broad authority to enforce AI-related laws in health - care. Violations of AB 3030’s generative AI communica - tion disclosure requirements are subject to specific enforcement mechanisms, as outlined below. • For licensed health facilities, violations fall under the enforcement mechanisms described in Article 3 of Chapter 2 of the Health and Safety Code (Sec - tions 1425-1429), which may include civil penalties of up to USD25,000 per violation. • For licensed clinics, violations are subject to enforcement under Article 3 of Chapter 1 of the Health and Safety Code. • For physicians, violations fall under the jurisdiction of the Medical Board of California or the Osteo - pathic Medical Board of California. The DMHC and the California Department of Insur - ance (CDI) have the authority to assess administrative penalties for health plans and insurers that fail to meet the requirements of SB 1120, including timeframes for authorisation decisions or improper use of AI. The California Privacy Protection Agency (CPPA) and the California Attorney General enforce the CCPA and CPRA. Penalties for non-compliance can be sub - stantial, ranging from USD2,500 per non-intentional violation to USD7,500 per intentional violation or for offences involving the personal information of minors under the age of 16. Individuals can bring private rights of action against entities that negligently release confidential medical information under CMIA, seeking actual damages, nominal statutory damages of USD1,000, and/or punitive damages upon proof of willful misconduct. Healthcare providers who knowingly and willfully obtain, disclose, or use medical information in viola - tion of CMIA may be liable for an administrative fine of up to USD2,500 per violation. The Department of Pub -
lic Health can also assess administrative penalties, including USD25,000 per patient whose medical infor - mation was unlawfully accessed, used, or disclosed, with subsequent occurrences incurring USD17,500 per incident, and daily penalties for failure to report. Practical Compliance Strategies for Healthcare Organisations Navigating California’s healthcare AI regulatory land - scape requires a proactive and multi-faceted com - pliance strategy. Organisations must integrate legal requirements into every stage of AI development, deployment, and ongoing operation. Risk Assessment Frameworks for Healthcare Organisations Healthcare organisations are obliged to take specific actions in order to assess risks related to the use of AI, such as: • conduct algorithmic impact assessments (AIAs) to evaluate potential risks, including bias, discrimi - nation, and privacy harms, before deploying AI systems, particularly high-risk ones; • assess liability exposure for AI-assisted diagnoses and treatments, considering the evolving standard of care, corporate practice of medicine doctrines, and maintain appropriate professional liability insurance coverage that specifically addresses AI- related risks; • develop detailed incident response plans for AI failures, data breaches, or adverse events, ensur - ing timely reporting and mitigation; and • establish clear human oversight protocols for all AI- driven clinical and administrative decisions, ensur - ing that AI does not replace, but rather augments, human judgment. Compliance Checklists for Healthcare AI Developers Below, you can find compliance checklists for the developers of AI used within the healthcare sector. • Implement mechanisms for prominent disclaimers and clear human contact instructions for genera - tive AI patient communications, as required by AB 3030.
155 CHAMBERS.COM
Powered by FlippingBook