Utah: AI health laws
8 entries on the map: 7 in force and 1 enacted and not yet in force (main duties begin Jan 1, 2027).
Dates ahead
- Jan 1, 2027SB 319, Health Insurance Preauthorization AmendmentsPayer and utilization review AI
Payer and utilization review AI
Insurers', benefit managers' and utilization reviewers' use of AI, including prior authorization and claim denials.
SB 319, Health Insurance Preauthorization Amendments
Requires an insurer that uses AI in its processes for reviewing authorization requests to post a notice on its website and to disclose that use to the Insurance Department, each health care provider in its network and each enrollee, requires that an adverse preauthorization determination on clinical or medical necessity be made by an individual who knows the enrollee's condition or consults a specialist who does, exercises independent medical judgment and does not rely solely on recommendations from any other source, and sets maximum decision times and a minimum 12-month authorization period for drugs, devices or services for chronic or long-term conditions.
Physician read. From Jan. 1, 2027, an insurer that uses AI to review authorization requests must say so to in-network providers, enrollees and the Insurance Department and on its website, and a preauthorization denial on clinical or medical necessity must come from a reviewer who knows the patient's condition or consults a specialist who does, exercises independent medical judgment and does not rely solely on any other source's recommendation. Insurers must also decide standard requests within seven calendar days and urgent requests within 72 hours after receiving all necessary information, and authorizations for chronic or long-term conditions must last at least 12 months.
Notes: Passed the Senate March 3, 2026 and the House March 4, 2026, with Senate concurrence March 5, 2026; signed March 19, 2026; takes effect Jan. 1, 2027. Amends Section 31A-22-650: the website notice is in Subsection (2)(d), the disclosure to the department, network providers and enrollees in Subsection (3), and the reviewer requirement, new in this bill, in Subsection (6)(e). 'Artificial intelligence' has the meaning in Section 53-25-901 and includes generative AI. The disclosure section does not specify timing or form beyond the website notice. 'Insurer' has the meaning in Section 31A-22-634; whether the section reaches Medicaid managed care or the Public Employees' Health Program was not determined. Utah's 2026 HB 60, which a tracker listed as the payer AI disclosure law, is Water Rights Amendments.
Patient disclosure of AI use
Telling patients that AI is used in their care or in messages to them.
SB 149, Artificial Intelligence Amendments (Artificial Intelligence Policy Act)
Required anyone providing the services of a regulated occupation, such as a licensed health profession, to prominently disclose when a person is interacting with generative AI in the provision of regulated services, required a person using generative AI in connection with an activity the Division of Consumer Protection administers to disclose it when asked, and created the Office of Artificial Intelligence Policy and an AI learning laboratory that can enter regulatory mitigation agreements relaxing enforcement for AI pilots.
Physician read. From May 1, 2024, a Utah physician or other licensee whose patients interacted with generative AI in licensed services had to disclose it prominently at the start of the exchange; SB 226 narrowed that duty to high-risk interactions from May 7, 2025 (separate entry). The Office of Artificial Intelligence Policy created by this act can sign regulatory mitigation agreements that let AI systems perform tasks in health care, such as prescription renewals, under set safeguards.
Notes: Passed the Senate Feb. 13, 2024 and the House Feb. 28, 2024; signed March 13, 2024; effective May 1, 2024. The original disclosure rules were in Section 13-2-12, which SB 226 (2025) repealed and replaced with narrower duties (separate entry). The enrolled bill numbered the Office, learning laboratory and regulatory mitigation provisions Title 13, Chapter 70; later bills cite them as Title 13, Chapter 72, the Artificial Intelligence Policy Act. As enacted, an initial regulatory mitigation agreement could last no longer than 12 months, with a single 12-month extension. The act originally set the chapter to repeal May 1, 2025; SB 332 (signed March 25, 2025) moved the repeal date to July 1, 2027, and neither HB 320 nor SB 12 (2026), Sunset and Repeal Date Amendments, amends that repeal provision. HB 320 (signed March 18, 2026, effective May 6, 2026) keeps the 12-month limit on an initial agreement, lets the Office grant up to two 12-month extensions, requires agreements to specify any required disclosures to consumers and reporting to comply with the Office's audits, requires the Office to consult relevant agencies on agreement terms, and requires an annual report that includes the agreements executed. SB 149 also amended the Consumer Privacy Act's definitions to include synthetic data in deidentified data.
SB 226, Artificial Intelligence Consumer Protection Amendments
Requires an individual providing the services of a regulated occupation to prominently disclose that a person is interacting with generative AI when the use is a high-risk AI interaction, defined to include an interaction that collects sensitive personal information such as health, financial or biometric data, or that gives personalized recommendations, advice or information, including medical or mental health advice, that could reasonably be relied on for significant personal decisions, and requires suppliers to disclose AI use when an individual clearly and unambiguously asks.
Physician read. Since May 7, 2025, a Utah physician or other licensee must prominently disclose generative AI use in providing licensed services when the AI collects health data or gives personalized medical or mental health advice, verbally at the start of a verbal interaction and in writing before a written one. A licensee who provides services through generative AI must also meet all requirements of the profession.
Notes: Signed March 27, 2025 (LegiScan); effective May 7, 2025. It repealed Section 13-2-12, the 2024 disclosure rule from SB 149, which had required licensees to disclose any generative AI interaction. The enrolled bill numbers the new provisions Title 13, Chapter 75; SB 38 (2026) refers to them as Title 13, Chapter 77, Generative Artificial Intelligence - Consumer Disclosures and Enforcement, and the Doctronic agreement cites the disclosure duty as Section 13-77-103. SB 38 (2026), effective May 6, 2026, amends Sections 13-77-101 and 13-77-102 and adds Chapter 77 to the chapters the Division of Consumer Protection enforces; its amended text could not be read in full, so whether it changed the disclosure duty itself was not determined. A high-risk interaction also includes other applications defined by Division rule. A licensee providing services through generative AI must also comply with all requirements of the regulated occupation. Safe harbor: a person is not subject to enforcement if its generative AI clearly and conspicuously discloses, at the outset of any interaction in a consumer transaction or the provision of regulated services and throughout the interaction, that it is generative AI, is not human, or is an AI assistant. The Division of Consumer Protection enforces, with administrative fines up to $2,500 per violation, court fines up to $2,500 per violation and civil penalties up to $5,000 for each violation of an order.
Also relevant here: Guidance Letter: Best Practices for the Use of Artificial Intelligence by Mental Health Therapists, Office of Artificial Intelligence Policy and Division of Professional Licensing (under mental health AI); HB 452, Artificial Intelligence Amendments (under mental health AI); Office of Artificial Intelligence Policy, AI Learning Laboratory regulatory mitigation agreement with Doctronic, LLC (AI prescription renewals) (under clinical decision and chatbot limits); SB 319, Health Insurance Preauthorization Amendments (under payer and utilization review AI).
Clinical decision and chatbot limits
Limits on AI in clinical decisions and on health chatbots, including AI presenting itself as a licensed professional.
Office of Artificial Intelligence Policy, AI Learning Laboratory regulatory mitigation agreement with Doctronic, LLC (AI prescription renewals)
Lets Doctronic's AI system authorize 30-, 60- or 90-day renewals of previously prescribed, non-controlled medications on an approved formulary for Utah patients, with the Division of Professional Licensing forgoing enforcement of specified unlawful-conduct, telehealth and unprofessional-conduct provisions for that use, subject to physician review of every renewal for the first 250 patients, retrospective physician review for the next 1,000, monthly review of 5% to 10% of renewals after that, AI disclosure to users, and monthly reporting.
Physician read. Physicians and other licensees named as prescribers in the pilot are protected from Division of Professional Licensing unprofessional-conduct enforcement for AI-authorized renewals while the agreement's terms are met; the AI may not issue new prescriptions, change treatment plans or renew controlled substances. The Utah Medical Licensing Board asked on April 20, 2026 that the pilot be suspended; the Department of Commerce declined on April 21, 2026, citing physician review of every renewal in the first phase.
Notes: Signed by the Office of Artificial Intelligence Policy and Doctronic on Oct. 23, 2025 and by the Division of Professional Licensing on Oct. 24, 2025, for 12 months from execution, with a single extension of up to 12 months if Doctronic requests it at least 30 days before the term ends; the Office's page describes the term as October 2025 to October 2026 with an option to renew for a year, and no renewal or extension appeared on the Office's pages on Sept. 29, 2026. The response to the board was signed by the directors of the Division of Professional Licensing and the Office. The Office's first public report, dated May 19, 2026, covers January through April 2026 and says the pilot was still in Phase One. The Office's page (modified June 18, 2026) reports amendments removing butalbital and flecainide from the formulary and letting each medication group move to Phase 2 after 250 fills in that group, subject to Office approval. Users must acknowledge disclosures, including that they are interacting with generative AI, before using the service. The agreement does not limit remedies available to users, third parties or the state other than the Division. It rests on the AI Policy Act (Title 13, Chapter 72), set to repeal July 1, 2027.
Also relevant here: Office of Artificial Intelligence Policy, AI Learning Laboratory regulatory mitigation agreement with Legion Health (AI psychiatric medication refills) (under mental health AI); SB 149, Artificial Intelligence Amendments (Artificial Intelligence Policy Act) (under patient disclosure of AI use).
Mental health AI
AI in therapy and mental health care.
Guidance Letter: Best Practices for the Use of Artificial Intelligence by Mental Health Therapists, Office of Artificial Intelligence Policy and Division of Professional Licensing
Advises licensed mental health therapists who use AI to obtain informed consent, disclosing benefits, risks and data practices, before using AI to record or transcribe sessions or to let patients interact with a conversational bot beyond intake, to maintain competence with AI tools, to verify data handling and business associate agreements with AI vendors, to review AI-generated content before it enters the record and keep independent judgment on AI-suggested diagnoses or treatments, to disclose when AI contributed to documentation or communications, and to set protocols for crises that AI tools cannot handle.
Physician read. The guidance letter, which does not say it is binding, is addressed to mental health therapists, a term it defines to include physicians engaged in the practice of mental health therapy. Since April 2025 it has asked them to obtain informed consent before using AI to record or transcribe a session or to let a patient interact with a conversational bot beyond intake, to accommodate or refer patients who decline, and to review AI-generated content before it enters the record.
Notes: Issued in April 2025 by the Office of Artificial Intelligence Policy and the Division of Professional Licensing; neither the letter nor its executive summary gives a day, so the date fields are empty. The letter takes its definition of mental health therapist from Utah Code Section 58-60-102, listing 14 licensed professions, including a physician and surgeon or osteopathic physician engaged in the practice of mental health therapy and an advanced practice registered nurse specializing in psychiatric mental health nursing. It does not state that it is binding or how the Division will use it; it asks therapists to align AI use with their profession's ethics code.
Office of Artificial Intelligence Policy, AI Learning Laboratory regulatory mitigation agreement with Legion Health (AI psychiatric medication refills)
Lets Legion Health's AI system handle routine refills of existing, non-controlled psychiatric medications, such as common treatments for anxiety and depression, for stable Utah patients under relaxed rules, with clinician review of the first 250 requests before completion, retrospective review of the next 1,000, monthly randomized audits, immediate clinician review when risks such as suicidality, severe side effects, signs of mania or pregnancy appear, and human review on the patient's request.
Physician read. It places no duty on physicians outside the pilot. The AI does not diagnose, prescribe new medications or adjust doses, and handles refills only for stable patients on existing prescriptions.
Notes: The Office's page (modified May 15, 2026) describes a 12-month pilot, says certain rules are relaxed while all standard patient protections and legal responsibilities still apply, and says patients are told that AI is part of the process. It links the signed agreement, posted under a March 2026 upload path; the agreement is posted as a scanned image, so its terms could not be checked. The signing date, term dates and the provisions for which enforcement is forgone could not be confirmed, so the date fields are empty.
HB 452, Artificial Intelligence Amendments
Requires a mental health chatbot to clearly disclose that it is AI and not a human before a user accesses it, at the start of any interaction after seven days without use and whenever the user asks, bars the supplier from selling or sharing a Utah user's individually identifiable health information or user input with third parties except in limited cases, bars using user input to decide whether or what to advertise or to customize ads and requires ads to be labeled, and gives a supplier an affirmative defense if it creates, files with the Division of Consumer Protection and complies with a written policy meeting the act's safety requirements.
Physician read. It places no duty on physicians. Since May 7, 2025, a generative AI chatbot that its supplier represents, or a reasonable person would believe, can provide mental health therapy to a Utah patient must identify itself as AI, may not sell or share the patient's identifiable health information or chat input except in limited cases, and may not use that input to target advertising.
Notes: Passed the House Feb. 27, 2025 and the Senate March 5, 2025; signed March 25, 2025; effective May 7, 2025. Codified as Title 13, Chapter 72a, Artificial Intelligence Applications Relating to Mental Health; the data-sharing ban is Section 13-72a-201 and the advertising rules are Section 13-72a-202. A mental health chatbot is AI technology that uses generative AI to engage in interactive conversations similar to confidential communications with a licensed mental health therapist and that the supplier represents, or a reasonable person would believe, can or will provide mental health therapy or help a user manage or treat mental health conditions; scripted output such as guided meditations, and tools that analyze input to connect a person with a human therapist, are excluded. Exceptions to the data-sharing ban cover information requested by a health care provider with the user's consent, information provided to the user's health plan on request, and sharing needed for the chatbot's functionality under a contract with HIPAA-equivalent protections. The affirmative defense requires a supplier to show it created, maintained and implemented a policy meeting the act's requirements, kept documentation, filed the policy with the Division and complied with it; the policy must cover, among other things, involvement of licensed mental health therapists in development, testing so the chatbot poses no greater risk than therapy with a licensed therapist, protocols to respond in real time to risk of harm, and regular safety audits. The Division of Consumer Protection may impose administrative fines up to $2,500 per violation; a court may impose fines up to $2,500 per violation and civil penalties up to $5,000 for each violation of an administrative or court order.
Data and privacy
Health and consumer data, biometrics, and data used to train AI.
SB 227, Consumer Privacy Act
As enacted, gives consumers rights to access, delete and port personal data and to opt out of targeted advertising and sale, and bars processing sensitive data, including information on an individual's medical history, mental or physical health condition, or medical treatment or diagnosis and biometric data used to identify a person, without first giving clear notice and an opportunity to opt out.
Physician read. The act exempts HIPAA covered entities, business associates and protected health information, so it places no duty on a physician practice acting as a covered entity. Large businesses outside HIPAA, such as some health and wellness apps, have since Dec. 31, 2023 had to give notice and an opt-out before processing a consumer's health or biometric data.
Notes: Signed March 24, 2022; effective Dec. 31, 2023. Codified at Title 13, Chapter 61; Section 13-61-102(2) exempts covered entities and business associates as entities, as well as protected health information. It uses notice and an opportunity to opt out, not consent, for sensitive data, and as enacted it has no right to correct, no right to opt out of profiling and no data protection assessment requirement. The Division of Consumer Protection receives and investigates complaints and refers matters to the attorney general, who has exclusive enforcement authority after a 30-day cure period. SB 149 (2024) amended the definitions in Section 13-61-101 to define synthetic data and include it in deidentified data. SB 38 (2026), effective May 6, 2026, amends Section 13-61-101; its amended text could not be read in full. No later amendment adding health, biometric, neural, geolocation, minors' or profiling provisions was identified, though the 2023 to 2026 sessions were not reviewed bill by bill.
Also relevant here: HB 452, Artificial Intelligence Amendments (under mental health AI).
Federal law also applies in every state: see federal law and policy.
Most recently checked Sept 29, 2026. General information, not legal advice. How the map works, and the data.