Kentucky: AI health laws
2 entries on the map: 2 in force.
Payer and utilization review AI
Insurers', benefit managers' and utilization reviewers' use of AI, including prior authorization and claim denials.
Bulletin 2024-02, The Use of Artificial Intelligence Systems in the Business of Insurance
Adopts the NAIC Model Bulletin, which expects insurers to maintain a written program for the responsible use of AI systems in decisions affecting consumers, with governance, risk management and controls, oversight of third-party systems and documentation available to the department.
Physician read. It places no duty on physicians. Since April 16, 2024, an insurer doing business in Kentucky, including a health insurer, is expected to govern the AI systems it uses in decisions affecting consumers under a written program.
Notes: The department's bulletins and advisories page lists Bulletin 2024-02, 'The Use of Artificial Intelligence Systems in the Business of Insurance,' dated April 16, 2024, and links to the bulletin, which is posted as a scanned image, so its addressees and wording could not be checked. The NAIC's adoption map lists Bulletin No. 2024-02, adopted April 16, 2024, as Kentucky's adoption of the NAIC Model Bulletin, and the summary, applies_to and physician_read follow the model's terms. No separate effective date could be read, so the issue date is used. The department's list shows no other AI bulletin.
Patient disclosure of AI use
Telling patients that AI is used in their care or in messages to them.
Nothing in this category was found in the review of Sept 29, 2026.
Clinical decision and chatbot limits
Limits on AI in clinical decisions and on health chatbots, including AI presenting itself as a licensed professional.
Nothing in this category was found in the review of Sept 29, 2026.
Mental health AI
AI in therapy and mental health care.
Nothing in this category was found in the review of Sept 29, 2026.
Data and privacy
Health and consumer data, biometrics, and data used to train AI.
HB 15 (2024 Acts Ch. 72), Kentucky Consumer Data Protection Act
Gives consumers rights to confirm, access, correct, delete and obtain a copy of their personal data and to opt out of targeted advertising, sale and profiling in furtherance of decisions with legal or similarly significant effects, requires consent before processing sensitive data, including a mental or physical health diagnosis, identifying genetic or biometric data and precise geolocation, and requires data protection assessments for processing created or generated on or after June 1, 2026.
Physician read. Since Jan. 1, 2026, a business covered by the act needs a consumer's consent before processing data revealing a mental or physical health diagnosis, identifying genetic or biometric data, or precise geolocation. HIPAA covered entities, business associates and protected health information are exempt, so it places no new duty on a practice covered by HIPAA.
Notes: The Attorney General has exclusive authority to enforce it; a controller gets 30 days to cure after written notice, after which the Attorney General may seek damages of up to $7,500 for each continued violation, and the act creates no private right of action. HB 692 (2026 Acts Ch. 118, signed April 13, 2026, effective July 1, 2027) amends the act to bar collecting automatic content recognition data from smart monitors without consent; it does not change the health, biometric or profiling provisions.
Federal law also applies in every state: see federal law and policy.
Most recently checked Sept 29, 2026. General information, not legal advice. How the map works, and the data.