Healthcare AI 2025

USA – CALIFORNIA Trends and Developments Contributed by: Lowell Brown and Douglas Grimm, ArentFox Schiff LLP

Strategies for Navigating Conflicting State Requirements Adopt the “most stringent” standard When state laws impose different requirements, organisations should generally adhere to the more stringent standard to ensure comprehensive compli - ance. Develop a layered compliance approach Organisations need to implement a compliance pro - gram that addresses all state requirements distinctly, recognising where California laws add specific obliga - tions (eg, AB 3030’s disclaimers, SB 1120’s human oversight for utilisation review). Conclusion California’s healthcare AI regulatory landscape is rapidly taking shape amid ongoing innovation and debate. That evolutionary process occurs through a legislative and enforcement approach that prioritises patient safety, data privacy, algorithmic fairness, and informed consent. The state’s framework introduces unique and often more stringent requirements, includ - ing transparency in AI-generated patient communica - tions, human oversight in health insurance utilisation review, and robust data privacy rights for health infor - mation.

• Ensure AI used in utilisation management complies with SB 1120, mandating human oversight for medical necessity decisions and prohibiting sole AI-based denials. • Adhere to AB 2885’s requirements for high-risk automated decision systems, including inventory, bias audits, and transparency. • Integrate privacy-by-design and security-by-design principles into AI system architecture. • Implement robust data minimisation and de-iden - tification techniques for training and operational data, consistent with CMIA. • Establish secure data handling protocols, including encryption, access controls, and regular vulnerabil - ity assessments. • Conduct regular audits of data inputs, outputs, and model performance to detect and mitigate bias and ensure accuracy. • Develop comprehensive vendor management pro - grams for third-party AI solutions, ensuring busi - ness associate agreements (BAAs) are in place, that vendors meet all regulatory requirements, and that regular compliance audits are conducted to verify ongoing adherence to applicable laws and regulations.

156 CHAMBERS.COM

Powered by