Skip to content
← Insights

September 16, 2026

AI governance in healthcare, September 2026: coverage is now decided feature by feature

Earlier this summer the notable shift was that the paperwork was getting easier: providers were making it quicker for a practice to put the right agreement in place before using AI with client information. This month the story moved to what sits on the other side of that agreement. The short version is encouraging. AI is becoming easier to supervise, and the providers are being more explicit about exactly where their coverage starts and stops.

What improved

First, the range of everyday AI work that providers will stand behind under a formal agreement has widened. Chat, documents, spreadsheets, presentations, recordings and longer multi-step tasks increasingly sit inside the covered lane rather than outside it – though newer features can still sit outside the agreement.

Second, the tooling that watches how staff use AI has caught up with the tools themselves. Audit trails, retention rules, legal hold and risky-usage detection now extend beyond a practice’s built-in assistant to competing assistants too, with many of the same core monitoring and retention capabilities. The choice of tool no longer decides whether basic supervision is possible – though the controls are not equivalent, and the built-in assistant still has the fuller set.

What didn’t change: the rules

The proposed federal update that would tighten HIPAA security requirements – removing the distinction between required and addressable safeguards and expressly requiring measures like encryption and multifactor authentication – remains a proposal, now on a longer timeline. There is no new deadline. The requirements in effect today are the ones that have been in effect for years, and the standing question is the same: did you look honestly at your risks, and did you act on what you found? A signed agreement doesn’t answer that, and never has.

Coverage now has three states, not two

The most useful change this month is that providers are publishing both sides of the line. One major provider now lists the features its healthcare agreement does not cover, alongside the ones it does – and warns, in its own words, that recently added features may not appear on the page yet. Another restructured its agreement page so that, inside a covered plan, features sit in three states:

  • Covered – usable with client information once the rest of the setup is right.
  • Available but not covered – it works, it’s there, and it sits outside the agreement. An administrator who turns it on is responsible for how it’s used.
  • Not available – some newer features simply aren’t offered in the covered configuration at all, so they can’t be turned on by accident.

The middle state is the one that needs a decision. It’s also worth knowing that the same word can sit on both sides: one provider now covers a basic, shared form of AI memory but not the more capable form that draws on past conversations, and ships that second kind switched off on its healthcare plans. A policy that simply says “memory is fine” is no longer specific enough.

The labels move

Two smaller changes make the same point. A provider renamed its workplace assistant, and the new name has now reached its official list of services covered by its healthcare agreement. Coverage didn’t change – but the new name is also the name of its free consumer app, which isn’t covered. “Use the approved assistant” now needs a second clause: signed in with your work account.

Separately, a provider announced it will retire a widely used way of building custom assistants and move teams to a newer format that can also bundle connections to outside apps. Both are on its covered list today, but its own guidance says a feature being available doesn’t settle whether a connected outside service is covered. A migration is a new approval decision, not a rename.

Assistants are reaching further in

Standalone assistants – the kind you sign up for separately from your main platform – can increasingly connect into the systems where client information lives: email, document storage, and in one healthcare offering an electronic health record system, under the organization’s own permissions. One provider’s documentation states plainly that its document-and-email connector can’t be limited to specific file-sharing sites; it searches everything the signed-in user can already reach.

The old mental model said a built-in assistant inherits your existing access while a standalone tool only sees what staff paste into it. That distinction is eroding. Reviewing who can reach what now comes first for every tool on the list, not just the one built into your email. And connecting an assistant to your email or files raises a separate coverage question: a covered workspace doesn’t automatically make every connected path covered.

Eligibility fine print for ABA practices

The free, agreement-capable AI offering aimed at individual clinicians verifies physicians, nurse practitioners, physician assistants and pharmacists. Behavior analysts are still not on those eligibility lists. For an ABA practice, careful AI use with client information continues to run through a properly configured organizational plan, not an individual sign-up.

Why this is good news

Almost every improvement above comes with a decision somebody at your practice makes. Some providers ship uncovered features switched off; others leave them available and put the decision on an administrator. Either way, a published boundary is far more useful than a vague one. The work becomes more concrete: decide what’s on, write it down, review access, and look again when the list changes. That’s governance working as it should – not a barrier to adoption, but the thing that lets you say yes to the everyday AI work that never touches client information, while knowing exactly where the line sits for the rest.

What we’d actually do

  • Start with everyday work that has no client information in it – drafting, summarizing, first-pass research.
  • Write your AI policy around configurations, not product names: which plan, signed in how, with which features on, and who is allowed to change that. One page is enough.
  • Where client information is involved, confirm the specific feature – not just the plan – is covered, and get the agreement in place where one is needed.
  • Review access before connecting any assistant to email, files or records. Many connectors inherit everything a user can already reach – confirm the scope of the one you deploy.
  • Treat a vendor rename, retirement or migration as a prompt to re-approve, not housekeeping.
  • Re-read your provider’s coverage page on a schedule – quarterly is a practical starting point – plus a check before enabling anything new.

None of this makes any tool “HIPAA compliant” – no tool is, on its own. An agreement is one prerequisite among several; configuration, access, policy and training do the rest. The providers are making that work easier to do honestly. That’s the same HIPAA-minded discipline we bring to ABA IT every day.

Vendor and regulatory information in this article was checked against official sources through September 16, 2026. It is educational material, not legal or compliance advice.

Common questions

Is there a new HIPAA deadline we need to meet for AI?+

No. The proposed federal security update remains a proposal on a longer timeline. The requirements in effect are unchanged, and they ask what they always have: analyze your risks and act on what you find.

If our plan is covered, is every feature in it covered?+

No. Providers increasingly separate covered features from ones that are available but outside the agreement, and some newer features aren’t offered in the covered configuration at all. Uncovered features often arrive switched off, and either way turning them on is a decision your practice owns.

How often should we re-check what our AI provider covers?+

On a schedule, not once at purchase. At least one provider says plainly that recently added features may not yet appear on its coverage page. For most practices quarterly is a reasonable rhythm, plus a check before enabling anything new.

Does connecting an AI assistant to our email and files stay covered?+

Not necessarily. A covered workspace doesn’t automatically make every connected path covered, and some connections fall outside the agreement entirely. Confirm it specifically before any client information moves through that path – and review who can reach what first.

Our approved AI assistant was renamed or is being replaced. Do we need to do anything?+

Yes, briefly. Update staff guidance so it describes the configuration – the work account and approved setup – rather than just the product name, and treat any replacement feature as a new approval: confirm it’s covered, check what it connects to, and review who it’s shared with.

Not sure where to start?

In a short, no-commitment conversation we’ll help you find the safest first step for your practice.

AI governance in healthcare, September 2026: coverage is now decided feature by feature | Anchor Networks