Pennsylvania: AI health laws
4 entries on the map: 1 in force and 3 bills in the legislature.
Payer and utilization review AI
Insurers', benefit managers' and utilization reviewers' use of AI, including prior authorization and claim denials.
Insurance Notice 2024-04 (54 Pa.B. 1910), adopting the NAIC Model Bulletin: Use of Artificial Intelligence Systems by Insurers
Adopts the NAIC model bulletin, which expects insurers to ensure that decisions affecting consumers made or supported by AI systems comply with insurance laws, including unfair trade practices and unfair claims settlement practices laws, and to maintain a written AI systems program covering governance, risk management and internal controls, and third-party AI systems and data, about which the insurance department may ask in investigations and market conduct actions.
Physician read. It places no duty on physicians. Since April 6, 2024, according to the NAIC's map and model text, insurers in Pennsylvania are expected to keep a written program governing AI systems used in decisions affecting consumers, including claim administration and payment; Pennsylvania's own notice could not be opened.
Notes: The NAIC's Aug. 31, 2026 map lists Insurance Notice 2024-04, 54 Pa.B. 1910, as Pennsylvania's adoption of the model bulletin, adopted April 6, 2024. Pennsylvania's own text could not be opened: the Insurance Department's notices page does not list Notice 2024-04, and the Pennsylvania Bulletin's copy could not be reached. The content described is the NAIC model's (adopted by the NAIC Dec. 4, 2023), which is addressed to all insurers licensed in the adopting state, covers the insurance life cycle including claim administration and payment, and does not mention health insurance or utilization review by name. The notice's title as issued, its signing date, any Pennsylvania changes to the model and any stated effective date could not be checked; the NAIC map's April 6, 2024 date is used for both signed and effective.
HB 1925, Artificial Intelligence in Facilities, Use by Insurers and Use by MA or CHIP Managed Care Plans
Would require facilities that use AI in clinical decision-making to disclose that use to patients in plain language in related written communications and on their websites, label AI-generated patient communications about clinical information with a disclaimer and instructions for reaching a human provider, keep AI from superseding clinicians' decisions and file annual compliance statements with the Department of Health, and would require insurers and Medical Assistance or CHIP managed care plans that use AI in utilization review to disclose it, keep AI from basing determinations solely on a group data set or superseding the reviewing provider's decisions, and have a health care provider review the individual's clinical records and exercise independent judgment before a denial, reduction or termination of benefits is issued or upheld.
Physician read. It binds no one yet. As amended, it would, from one year after enactment, require a physician's office or clinic that uses AI in clinical decision-making to disclose that use to patients in plain language and on its website and to label AI-generated patient communications about clinical information, and would require a health care provider's review of the individual's clinical records and independent judgment before an insurer or Medicaid or CHIP plan using AI in utilization review issues or upholds a denial, reduction or termination of benefits.
Notes: Referred to the House Communications and Technology Committee Oct. 6, 2025; reported as amended (Printer's No. 3349) May 5, 2026, given first consideration and laid on the table; removed from the table June 25, 2026. The 2025-2026 session continues. The Senate companion, SB 1113, has not been reported from committee. The text does not say AI may not be the sole basis for a denial; it bars AI from basing a utilization review determination solely on a group data set or superseding the provider's decision-making and requires the provider review described above. As amended, a facility may not penalize a provider solely for exercising independent judgment that differs from an AI recommendation, and an insurer may not penalize a reviewing provider solely for refusing to issue or for overturning a decision. Communications only about administrative matters, such as scheduling or billing, and communications individually read, reviewed and approved by a human health care provider are exempt from the disclaimer. Insurers would also file annual AI compliance statements. Penalties would reach $10,000 per knowing or willful violation and $5,000 per negligent violation ($1,000 for a first negligent violation made in good faith), capped at $250,000 a year per entity; the Departments of Health, Insurance and Human Services enforce in their areas, and the Attorney General has exclusive authority to sue under the Unfair Trade Practices and Consumer Protection Law. The act would take effect in one year. Status and text are from LegiScan because palegis.us could not be reached.
Patient disclosure of AI use
Telling patients that AI is used in their care or in messages to them.
Also relevant here: HB 1925, Artificial Intelligence in Facilities, Use by Insurers and Use by MA or CHIP Managed Care Plans (under payer and utilization review AI); SB 1090, Safeguarding Adolescents from Exploitative Chatbots and Harmful AI Technology Act (under clinical decision and chatbot limits).
Clinical decision and chatbot limits
Limits on AI in clinical decisions and on health chatbots, including AI presenting itself as a licensed professional.
SB 1090, Safeguarding Adolescents from Exploitative Chatbots and Harmful AI Technology Act
Would require operators of AI companions to give a clear and conspicuous notice that the companion is artificially generated and not human when a reasonable person could be misled, to maintain and publish a protocol that prevents the companion from producing suicidal ideation, suicide or self-harm content or content directly encouraging violence and that refers users who express suicidal ideation or self-harm to crisis services, and, for users the operator knows or should have known are minors, to disclose that the companion is AI, remind them at least every three hours to take a break and that the companion is not human and take reasonable measures against sexually explicit material, enforced by the Attorney General with civil penalties of up to $10,000 per violation.
Physician read. It binds no one yet and would place no duty on physicians. If enacted, from 120 days after enactment, operators of AI companions would need a published protocol that blocks suicide and self-harm content and refers users to crisis services, and would have to remind users they know or should have known are minors at least every three hours to take a break and that the companion is not human.
Notes: Reported by the Senate Communications and Technology Committee Nov. 18, 2025 (11-0), amended on second consideration Feb. 3, 2026, re-referred to Appropriations, re-reported (22-0) and passed the Senate March 17, 2026 (49-1); referred to the House Communications and Technology Committee March 18, 2026, with no further action. The 2025-2026 session continues. An AI companion is a system that simulates a sustained human-like relationship by retaining information, asking unprompted emotion-based questions and sustaining personal dialogue. Operators must also disclose to users that AI companions may not be suitable for some minors. The amended text contains no bar on presenting the AI as a licensed professional and no private right of action. Status and text are from LegiScan because palegis.us could not be reached.
Also relevant here: HB 1925, Artificial Intelligence in Facilities, Use by Insurers and Use by MA or CHIP Managed Care Plans (under payer and utilization review AI).
Mental health AI
AI in therapy and mental health care.
Also relevant here: SB 1090, Safeguarding Adolescents from Exploitative Chatbots and Harmful AI Technology Act (under clinical decision and chatbot limits).
Data and privacy
Health and consumer data, biometrics, and data used to train AI.
HB 78, Consumer Data Privacy Act
Would require consumer consent before processing sensitive data, including data revealing a mental or physical health condition or diagnosis, genetic or biometric data and precise geolocation, give consumers rights to access, correct and delete personal data and to opt out of targeted advertising, sale and profiling in furtherance of solely automated decisions with legal or similarly significant effects, including on health care services, and require data protection assessments for high-risk processing, enforced by the Attorney General.
Physician read. It binds no one yet; as amended in the Senate it would exempt HIPAA covered entities, business associates and nonprofits, so it would place no duty on a HIPAA-covered practice. If enacted, from one year after enactment, for-profit businesses that meet its thresholds would need a consumer's consent to process data revealing a mental or physical health condition or diagnosis and would have to honor opt-outs from profiling in furtherance of solely automated decisions about health care services.
Notes: Passed the House Oct. 1, 2025 (127-76). In the Senate it was referred to Consumer Protection and Professional Licensure Oct. 3, 2025, reported as committed and re-referred to Communications and Technology Feb. 4, 2026, re-reported as amended (Printer's No. 3688) June 24, 2026 and given second consideration June 25, 2026. The 2025-2026 session continues; if the Senate passes it as amended, it returns to the House. The Senate amendments add Social Security, driver's license or state identification and financial account numbers to sensitive data. The Attorney General would enforce, with no private right of action; for an initial period set in the act the Attorney General must give notice and 60 days to cure before suing, and afterward may allow a cure at its discretion. The act would take effect in one year. Status and text are from LegiScan because palegis.us could not be reached.
Federal law also applies in every state: see federal law and policy.
Most recently checked Sept 29, 2026. General information, not legal advice. How the map works, and the data.