There is a lot of uncertainty surrounding AI in health care, but waiting for clearer regulations is not a strategy practice owners can rely on. In this episode, hosts Brad Adatto and Michael Byrd explore how physicians and practice owners can navigate a rapidly evolving AI landscape when the rules are still taking shape. If you are wondering where to start, the answer may lie in the regulations already governing your practice. Tune in to learn how existing health care laws can help guide AI use today, why “Shadow AI” may already be present in your practice, and how to protect patient privacy, manage employee use of AI, and reduce cybersecurity risk while embracing innovation.
Listen to the full episode using the player below, or by visiting one of the links below. Contact ByrdAdatto if you have any questions or would like to learn more.
Transcript
*The below transcript has been edited for readability.
Intro: [00:01] Welcome to Legal 123s with ByrdAdatto. Legal issues simplified through real client stories and real-world experiences. Creating simplicity in three, two, one.
Brad: [00:13] Welcome to the launch of season 25. That’s right, season 25 of Legal 123s with ByrdAdatto, I’m your host, Brad Adatto, with my co-host, Michael Byrd.
Michael: [00:23] Brad, I’m excited for this season. We are going to be cutting edge this season.
Brad: [00:28] Oh, cutting edge, like, are we going to talk about movies from the 2000s? I mean, I don’t know if I’m ready for such modern discussions. Tell us what the theme for this season is.
Michael: [00:38] I know you’re not ready for 2000 movie talks-
Brad: [00:41] Yeah
Michael: [00:41] So we will not do that.
Brad: [00:42] Okay, thanks.
Michael: [00:42] Here it is. As business attorneys for health care practices, we meet a lot of interesting people and learn their amazing stories. This season’s theme is AI in health care. We’re bringing in people a lot smarter than the two of us to help decipher the business risk of using AI in a medical practice.
Brad: [01:01] Well, Michael, first off, finding smarter people than us, I think that’s pretty easy. That’s, I don’t think that’s a big challenge. The audience probably has been listening to us for a while and probably agrees with that. But audience members, we will be using this term AI a lot this season, and of course we just want to make sure we’re all on the same page at the beginning of the season. That means artificial intelligence, also known as AI. And that generally means computer systems that can think and learn and solve problems like people. That’s the whole idea behind AI. And because AI is so new, we don’t really have that many client stories that we would normally use to illustrate lessons learned. So instead, we’re actually going to have a series of interactive conversations where we work through many of these issues that will arise, because this is really, audience members, like a lifetime shift in the world and business right now.
Michael: [01:49] Before we get anywhere near the law, Brad, I have a question for you. We’ve known each other for a long time. Over 20 years, and there is something controversial that I still don’t know about you. I’m trying to figure out if you’re a normal human or if you’re disgusting.
Brad: [02:06] Wow, okay. We’re about 90 seconds or so into season 25, and you’re already coming in pretty hot there, Michael. No welcome back to the season, so glad we have another season. You’re just kicking off the whole season accusing me of being disgusting. I respect that, actually. Okay, hit me.
Michael: [02:22] Yeah, we got work to do, man.
Brad: [02:24] Yeah.
Michael: [02:24] Okay. Do you toss food once the date on the label has passed?
Brad: [02:30] Toss foods, I’m assuming throw that food away. But I guess the answer to your question is, I don’t really pay attention to those labels. But someone in my house is always looking at the expiration dates and making sure that the pantry and refrigerator is cleared out. So no, I don’t. But I guess I’ve never really needed to develop that strong skill set that maybe some people have. How about yourself?
Michael: [02:54] If it’s expired, it goes. It’s just not worth the risk. And I think I’m influenced by my grandparents. My grandparents were notorious for the stuff I would find in their pantry. It was like a museum for food. I mean, literally something that expired in the ’70s you might find. And so I would secretly trash the expired items to save them from themselves, not that they would eat something that they’d clearly been storing for 20-something years. But they would get mad at me if they caught me doing it.
Brad: [03:27] Yeah, actually, that’s a more common story. Our grandparents who were part of the greatest generation were also part of the Great Depression, and they saved everything. So that does make sense that they would not want to ever trash food, expired or otherwise.
Michael: [03:44] Well, one thing we have in common is my wife Stephanie. She’s even stricter than I am about this, so leftovers are not safe in our fridge.
Brad: [03:53] That sounds terrible. I mean, we have something called “dinner nights” where we call it “Must Go’s.” Everything in the fridge must go. So yeah, we’re not against that idea, but I know people who are. But I guess maybe the next question is, what does this brand-new AI season have to do with food expiration dates? I’m not really understanding how this coincides.
Michael: [04:15] Yeah. Well, first, we have “Must Go’s,” too. They just go into the trash. But no, I read an article that said that experts, I put that in quotes-
Brad: [04:27] Okay
Michael: [04:27] I’m still suspicious. But they believe throwing out expired food is often a waste. And here is what caught my attention. There are no federal regulations requiring standardized date labels. I think they have one for baby formula, but otherwise no regulations. And so you end up with all these confusing terms floating around on packages that might say “Best Before” or “Best By” or “Best If Used By” and even “Sell By.”
Brad: [05:02] You know what? That sounds like lawyers involved with all these colorful terms, “Best If Used By.” But that doesn’t sound like much scientific data there, Michael.
Michael: [05:11] Yeah. No, I think it’s a free-for-all. There’s more than 50 different date labels that are used across the US. And the whole point of the article was that these labels are really about how fresh something is and not how safe the food is to eat.
Brad: [05:27] Kind of like the concept that Twinkies could last forever, but then we discovered on another show even Twinkies have a shelf life, apparently.
Michael: [05:35] Yeah. Yeah. Well, and then in shocking news, I’ll use that in quotes, California’s the first state that’s trying to get their arms around this and regulate it. So starting July 1st of 2026, anyone selling food in California has to use one of two standardized labels. Yes. They have “Best If Used By” or “Use By.”
Brad: [06:02] No shocker, California, for better or for worse, tends to push all the national legal standards. I’d be very curious to see what those labels really look like, though.
Michael: [06:14] Right. Well, let’s get started with our conversation. Enough label talk for now-
Brad: [06:20] Okay. Okay.
Michael: [06:20] Today we’re going to talk about how AI is regulated in a medical practice.
Brad: [06:27] Perfect. Well, I love that, and so let’s really dig into the subject matter. AI feels like it’s a foreign language for almost everyone in the workforce right now, and as you know, I can barely speak English, so the AI world is a challenge for almost anyone. And it’s changing so fast, Michael, that it almost compounds the confusion. So how does even a practice start to think about compliance or any use in the context of AI?
Michael: [06:57] It’s a great question, and something we’ve had to wrestle with as we’ve been asked to speak on it. And I think the starting point is that we have to recognize a few uneasy truths. The first one, Brad, is that AI’s already in your practice if you’re a health care practitioner in the audience. And Brad, have you heard the term shadow AI?
Brad: [07:28] That makes me nervous. Is that like AI that comes out around Halloween, and it’s part of the dark web? Actually, just kidding, Michael. I actually think I do know this answer. But those who don’t, why don’t you let them know what does shadow AI mean?
Michael: [07:42] Yeah, and I’ll give a brief overview because we’ll talk an entire episode on this next episode. Shadow AI is this idea that even if you are a physician-owned practice and you’re super conservative and super scared of AI and think, “I’m not going to touch this”, that AI’s happening in your practice, and it can show up in different forms. It can show up in the third-party software that you’re using. It can show up in your employees and what they’re doing that you’re not seeing and using AI, and it can show up with the patients and how they’re bringing AI into your practice. And so you have to recognize this truth that you have got to deal with AI. It’s in your practice.
Brad: [08:31] Yeah, and I feel like I have a lot to say on that, but you have to stay tuned for next week for me to really go into giving all my in-depth knowledge on this. But Michael, you said that was a truth. What’s the next truth?
Michael: [08:42] Yeah, we have a couple more. So the second uneasy truth is that it’s the Wild West out there right now with AI. The risk is super hard to define because the ground is moving under all of us. And then the third uneasy truth is that there really aren’t any experts yet. Anyone who tells you they have this completely figured out should make you a little nervous.
Brad: [09:07] Yeah, I think you’re exactly right. Oh wait, hold on. You know what? You’re right in that there’s a lot happening with those three uneasy truths, and I started thinking about that. I feel like there’s actually a fourth uneasy truth, which is waiting for certainty is really not really an option for anyone anymore. Every business owner, whether you’re a physician or a professional leader, has been talking to us about and wrestling with these types of challenges. Heck, at lunch today we were talking about it with a financial group, and they know AI is going to impact their business, but the rules, the risk, the technology around it continues to evolve actually in real time. So I agree that when someone says they have AI completely figured out, I’m a little bit skeptical as to truly what that means. But when someone says they’relearning, testing, implementing controls and continually trying to improve their knowledge, I’m much more likely to think they’re credible and trust the answer they’ll give after that.
Michael: [10:07] Right. So let’s talk about the laws that are actually out there, and then on the other side of the break, we’ll get into some practical steps that practices can start taking. So Brad, walk us through the state of AI-specific laws that are being passed right now.
Brad: [10:28] There are none. Oh, sorry, just kidding. Let’s go to the break. One of the most interesting things I think that’s happening right now is actually Congress or the federal government has really not made a pass at a comprehensive AI, at least health care, law. Instead, these regulations are adopting existing laws around medical devices, privacy, civil rights, Medicare, consumer protection. They’re all coming into it, and they’re addressing AI to some level. The real action really though is happening at the state level. For example, in 2025, I know we’re a few years past that, 38 states enacted or adopted AI-related measures. By mid-2026, 27 states have already enacted a new AI law just this year. So further as we’re seeking clarification or trying to figure out really where accountability falls, is it human accountability or is this the AI? It’s still kind of unknown, meaning that AI can assist, right? But a licensed professional really must still remain responsible for any decisions. So again, it doesn’t matter if you’re a lawyer, a doctor, engineer, whatever. That’s where it seems to be falling. So while there’s no one big AI law yet, there’s definitely more regulations coming. It’s becoming more specialized each year.
Michael: [11:53] And there’s perhaps a false sense of hope that there’s going to be some laws that specifically deal with AI, so I’m going to get that clarity. And we should pause a moment and talk about what it actually means to a business or a practice when a new law’s passed. The only thing a new law gives you at the beginning is the actual language of the new law, and the problem is that laws are often negotiated on both sides of the political aisle, and then there’s a rush to get them finalized once an agreement’s reached. And so they look more like a Frankenstein creation than a beautiful, clear law that tells you what’s going to happen. And then it takes years of interpretation and enforcement to really gain clarity about how that law works, how it’s going to be enforced, and to be able to gauge risk to your practice.
Brad: [12:54] Yeah, and I think the problem that a lot of people are having is as you laid out so clearly, not only does the law happen, but the time it takes to give the clarity, while AI is evolving faster than the law can actually get there. It becomes very challenging for anyone to understand week to week what should they be thinking about from an AI perspective, what are the practical considerations, what are the regulations, should they even be using AI? I mean, there’s a lot that’s happening right now.
Michael: [13:25] Yeah. And so let’s talk about, well, what do I do with that? I mean, we’ve said nothing really helpful other than just that it’s chaos so far.
Brad: [13:36] Well, I think hopefully it’s helpful that those who don’t know better, if they think this is chaotic, they’re right in the majority.
Michael: [13:43] Yes. Everybody’s in the same boat. And I do think it is relevant to try to stay up to date with the laws that are getting passed so that we can make our best effort to be in compliance and make sure that the way things are running in our practice are in line with how we believe they’ll be interpreted. But even more importantly is recognizing that health care is heavily regulated already.
Brad: [14:12] Yep.
Michael: [14:12] There’s a massive framework that applies to compliance in a medical practice, and so we can use those laws foundationally to understand there’s basic principles to running a compliant medical practice that you can extend into how you’re using AI in your practice. And so we know that a medical practice is going to be regulated by the medical board.
Brad: [14:40] Yep.
Michael: [14:41] We know there’s going to be state and federal laws that regulate patient privacy.
Brad: [14:46] Sure.
Michael: [14:46] We know that there’s a bunch of different laws that regulate things like medical advertising, and so we take this body of traditional laws that apply to a medical practice and then apply the AI tool you’re using to that to make sure that we’re staying in line.
Brad: [15:05] Yeah, and I think the good news, audience members, is I know we’re being very general here, but this is our opening episode on AI. We will go further into this analysis. But again, a really good point Michael is making to the audience to really think through here is if you don’t know what the AI law is in your home state right now, the easiest thing to fall back on is what’s required of you in general, and that’s what Michael’s kind of talked about. There are already a lot of rules on the books as it relates to these issues. Again, how does the medical board view using AI to practice medicine, or the privacy concerns, or even, as you said, using AI for marketing purposes. All those, there are rules in place right now. So don’t think that because AI is so unique, even if there are no direct laws in your state, that it doesn’t apply in some capacity.
Michael: [15:58] Yeah, and I think we can be helpful. So let’s go to break, and on the other side, let’s talk about some practical steps that practices can start taking today.
Access+: [16:09] Many business owners use legal counsel as a last resort, rather than as a proactive tool that can further their success. Why? For most, it’s the fear of unknown legal costs. ByrdAdatto’s Access+ program makes it possible for you to get the ongoing legal assistance you need, for one predictable monthly fee. That gives you unlimited phone and email access to the legal team, so you can receive feedback on legal concerns as they arise. Access+, a smarter, simpler way to access legal services. Find out more. Visit byrdadatto.com today.
Brad: [16:43] Welcome back to Legal 123s with ByrdAdatto. I’m your host, Brad Adatto, my co-host, Michael Byrd. Now, Michael, for those who don’t know, this season we’re really focusing on AI in health care. And before we went to break, you actually laid out three uneasy truths. I added a fourth uneasy truth. But we really started trying to talk about the laws that are already on the books and application to AI. So before we get too practical, maybe give the audience a little recap of anything you thought of that we left off on.
Michael: [17:13] Yeah. So we recognize that AI is in your practice, that it’s the Wild West right now, and that there’s few experts, and you can’t wait to get certainty. And so we then talked about the laws and that there are emerging AI laws that are out there, but really our focus as we started toward the break is that we need to ground ourselves in the existing laws that govern a practice and make decisions on how we’re going to implement AI in our practice based on those regulations.
Brad: [17:56] Yeah, so probably audience members who’ve been listening at this point, you’re like, “Okay, you guys have been unhelpful. All you’ve done is make it real scary with these uneasy truths.”
Michael: [18:05] Mostly Brad.
Brad: [18:06] Mostly Brad. I agree with that.
Michael: [18:07] Yeah.
Brad: [18:07] I like Halloween, so why not scare everybody? Why don’t we help them out here a little bit, Michael? And I know this is our opening episode, so we’re going to cover a lot of things at a high level. But give the audience something to think about. How do they protect their practice? What is the most important compliance step a practice can take right now?
Michael: [18:23] Well, as a starting point, the medical license of a physician is what gives a practice authority to practice medicine.
Brad: [18:34] What is it?
Michael: [18:36] Say that again.
Brad: [18:37] What is it?
Michael: [18:37] What is what?
Brad: [18:38] What gives them the authority?
Michael: [18:39] The medical license.
Brad: [18:40] That’s it?
Michael: [18:41] Yes.
Brad: [18:41] That’s all they need?
Michael: [18:42] Yes.
Brad: [18:42] Oh, wow.
Michael: [18:43] Yeah. And so people sometimes ask, “What do I need?” Your medical license is what allows it to happen. In every state-
Brad: [18:51] Is that AI medical license or-
Michael: [18:52] No, Brad.
Brad: [18:53] Okay.
Michael: [18:53] Your actual medical license that physicians went to medical school for. And so we apply that to AI, and you have to come back to this. Your license, and it’s your risk if you’re the physician. And so if you have an AI tool that you want to use and that AI is influencing patient care, for example, and you as the physician are not ultimately making the decisions on what has to happen with that patient or someone who you are supervising, then you’re at risk. So a lot of times the way that’ll show up is the doctor will be like, “Well, what happens if this AI tool that I’m using is giving a wrong answer, and that leads to a wrong diagnosis? Is that AI company going to be liable?” And I’m like, “Probably not.” That patient came to hire you. That license is what gives you the authority to practice. And so that’s your malpractice risk. And so you can make your decisions about how to integrate AI with that fundamental principle in mind.
Brad: [20:07] Yeah, see, I mean, obviously we’re going to keep going through this and understanding the different aspects of how AI is in it, but you’re right. I mean, if you worked as hard as a physician or a nurse practitioner, a PA, or an RN, wherever you fall in the care line, you want to protect your license, and that’s a big risk whether or not you know AI is there or not, the impact it’s going to have on your medical practice as it relates to the day-to-day use of that. But yeah, you’re right. Your license is probably the biggest, but there are other risks out there, Michael.
Michael: [20:42] Yeah. We always say that the two biggest risks to a practice are the two most important things to a successful practice: your employees and your patients. And so let’s take them one at a time. Brad, talk about the practical application to manage the risk with employees.
Brad: [21:01] Yeah. I think a lot of people think the biggest AI risk is the technology. It’s not. It’s the employees using these powerful tools without clear rules. A good AI policy creates guardrails around privacy, accuracy, accountability, human oversight, so you don’t turn some innovative idea into some new liability. And I know that we have, again, an entire show dedicated to this topic, so I won’t go too crazy on this. But if you don’t know where to start, think about three simple steps. Start with an approved use of AI policy. Employees should know which AI tools are approved by the practice and which ones are off-limits. Again, not every AI platform is appropriate for health care. If there’s an AI assistant, the human needs to still be a part of that decision-making, making it clear that the AI can support decision-making, but employees cannot blindly rely on the AI output, especially, again, as you said earlier. A licensed professional still is going to remain accountable no matter what the AI says, and you need to ultimately decide whether or not that’s the correct course of action. And then obviously document accountability, so that’s the third one. Every AI policy should answer one simple question: Who is responsible when the AI gets it wrong? Again, this goes back to the human element because I think regulators are definitely going to be increasing enforcement around AI, and they’re going to be looking for that human accountability, not machine accountability, so making sure it’s very clear who has that role.
Michael: [22:34] We can’t blame the machines. That keeps coming up.
Brad: [22:36] Yes.
Michael: [22:37] Another thing that I’ve noticed recently, I’ve had more and more clients call and say they’re sitting down to have a performance improvement plan with an employee or some other type of sit-down with an employee, and employees are showing up and they’re recording conversations. And so this is confusing. Like, what do I do with this? This is a new element to my business, and it’s tricky because you first have to think about, in the context of how you’re going to do AI, do you want recording in your practice? And this extends beyond just this one circumstance. And then how do you feel about having employees record? And then there are employment laws, so you have to get counsel in your state to make sure that you’re allowed to prevent that from happening. The sister concept is you’re trying to prevent an employee from talking about their compensation. And so there are laws that regulate that. And so first, you have to recognize that this might be happening and then figure out what you can and can’t do in your state and then what fits with your practice and develop a policy around it.
Brad: [24:07] Yeah. And audience members, again, we’re actually going to have a deep dive on this subject on another date. So we’re just, again, highlighting the different aspects that you just need to be thinking about. And stay tuned, shameless plug for the show when we do go deeper into the employment side. But you said the other risk. Let’s talk about how do you manage it with patients, Michael?
Michael: [24:28] Yeah. So patients are showing up with AI in play. And so one may be that they’re showing up to record their consults. And so, again, how do you feel about that? Are you recording your patient interactions? And then, if you are, there’s all sorts of questions. Is that part of the medical record if they become a patient? And then if you have an EMR that’s going to be integrated, or you have EMR with an AI note-taker, what’s your policy on that? How does it work? How does it fit with the medical record? And again, to your point, Brad, we’re going to really dive deeper as we progress in the season into a lot of these points. But the first step is awareness that there’s all these different applications out there that we need to be thinking about.
Brad: [25:27] I feel like we’ll be saying this a lot this season, and it’s not meant to be campy. It just goes back to there being so many different elements that AI is going to impact in a given business, especially in a medical practice. And so going back to the initial discussion here on patients, we’re definitely seeing states starting to increase regulations. Going back to the laws that are coming from the states and regulators, if you are using AI, the question becomes when and how are you using AI in your practice? Is AI drafting these messages or interacting directly with patients or helping curate the medical records? What we’re seeing is regulators really want transparency here about the use of AI in your medical practice. And that then means if you are using it already in your medical practice, most of our recommendations would be to notify the patient. So typically, a good patient consent would include that information so that they can review it and realize that you are using it.
Brad: [26:26] So if you’re using AI and you don’t have the right patient consents, this is a great opportunity to stop and pause and go back and start reviewing them and updating them based on how the practice is using AI. No matter, again, if you know you’re using it. So that goes back to making sure you understand what you’re using it for and what the AI tools are, and again, allowing that to be presented to the patients.
Michael: [26:57] I just saw a law yesterday, I can’t remember which state, that says, it may be a bill, but I think it was a new law that requires a verbal conversation with a patient prior to using AI in a patient interaction.
Brad: [27:12] Yes.
Michael: [27:12] And so there’s a lot of laws out there around, to your point, consent. But there’s, again, so much that goes into it there. So as we’re kind of trying to lay the groundwork for the season, let’s wrap up with some final thoughts and give things for our audience to think about as we really start unpacking this throughout the season.
Brad: [27:37] Yeah, I think for those who are trying to figure out what to do, AI is not the future. It is here. It is already here. The winners, if you think about it, won’t be the businesses and medical practices that use AI the most. They’ll actually be the ones that use it most responsibly. Put policies in place, train your team, protect your data, keep humans in charge. View AI as just another tool that’s going to support and hopefully help make your practice run smoother with better decision-making, but you’re still the one making the decisions. So as organizations head this way, I do believe that the organizations that ignore AI will likely start falling behind compared to the organizations that use it. But the organizations that use it recklessly will create unnecessary legal, compliance, and other reputational risks. So it’s a balancing act, audience members. And again, that’s why I’m so excited about this season. We have timeto go further in depth. And so we’re almost out of time, Michael, so what are your final thoughts?
Michael: [28:42] Yeah, the final point is that with AI in a practice, it’s going to increase your cyber risk. And I mean, we see stories in the news about AI models infiltrating other businesses. And so a great starting point is to make sure if you do not have cybersecurity insurance, that you go and secure that and get it priced out for your practice and have that first layer of coverage to protect against this new level of risk that will affect a practice.
Brad: [29:18] Absolutely. Well, audience members, that is all the time we have for this show. But as promised, next Wednesday we’ll be back with series regular and our partner, Jay Reyero, who will join us to take a deeper dive into what is Shadow AI.
Brad: [29:30] Thanks again for joining us today. And remember, if you liked this episode, please subscribe. Make sure to give us a five-star rating and share with your friends.
Michael: [29:40] You can also sign up for the ByrdAdatto newsletter by going to our website at byrdadatto.com.
Outro: [29:47] ByrdAdatto is providing this podcast as a public service. This podcast is for educational purposes only. This podcast does not constitute legal advice, nor does it establish an attorney-client relationship. Reference to any specific product or entity does not constitute an endorsement or recommendation by ByrdAdatto. The views expressed by guests are their own, and their appearance on the program does not imply an endorsement of them or any entity they represent. Please consult with an attorney on your legal issues.

