Healthcare AI Governance

    Who Is Liable When an AI Clinical Decision Support Tool Contributes to a Misdiagnosis or Adverse Patient Outcome?

    It is unsettled, and it is a legal question. CHAI's 2026 governance playbook says existing liability frameworks "were not designed with AI systems in mind," and that how they apply to AI-assisted decisions "is actively being litigated and debated." This page covers what published sources say is known and unknown, and the governance steps that help whichever way the law develops.

    Last updated: · By Teresa Younkin & Jim Younkin, Mosaic Life Tech

    Key Takeaways

    • ·Nobody can give a general answer today. CHAI's Third Party Management playbook lists the open questions, including whether liability rests with the user, the organization, the vendor, or is shared.
    • ·The same playbook says "prospective contractual risk allocation, not litigation, is currently the most practical tool for managing AI liability in healthcare," and recommends legal counsel review indemnification, limitation of liability and data ownership terms.
    • ·One federal rule already speaks to AI in patient care: 45 CFR 92.210 calls for reasonable efforts to identify and mitigate discrimination risk from patient care decision support tools.
    • ·We haven't found reliable public data on how many malpractice claims involve AI. An earlier version of this page repeated a figure we couldn't trace to a primary source, and we have removed it.
    • ·Governance doesn't decide who is liable. It lowers the chance of harm, and it produces the record your counsel will ask for first if something goes wrong.

    The short answer

    Ask your attorney, because the answer depends on the facts, your state's law, the tool's regulatory status and what your contracts say. What a leadership team can do without a law degree is make sure four things are true before that conversation happens: you know which AI tools touch clinical decisions, you have checked the important ones on your own patients, your clinicians are trained on their limits, and someone is watching how they perform. Those steps reduce the chance of harm, and they are the first things counsel will ask about.

    What Is Known and What Isn't

    The most useful published summary we have found is a short section of CHAI's Third Party Management playbook (May 2026) titled "Looking Ahead: AI Liability in Healthcare." It observes that malpractice, products liability and negligence frameworks "often assume there is an identifiable human decision-maker who made a call that could have gone differently," while AI spreads a decision across a system.

    What CHAI says is known

    • ·Contractual allocation of risk between health systems and AI vendors "is currently the primary tool available."
    • ·Agencies have issued guidance in specific contexts, "but comprehensive federal AI liability law does not yet exist."

    What CHAI says remains unsettled

    • ·"Whether liability for AI-assisted harm rests with the user, the organization, the vendor, or is shared, and how courts will weigh each party's role."
    • ·How the "learned intermediary" doctrine applies "when AI outputs influence (but do not replace) clinical judgment."
    • ·"Whether failure to adopt AI, or failure to override an AI recommendation, could itself constitute negligence in future cases."
    • ·How state AI laws interact with federal frameworks.

    For the legal analysis itself, two widely cited articles by legal scholars are listed under Sources. We haven't tried to summarize them, and they are no substitute for your own counsel.

    Where Exposure Can Come From

    These are different kinds of exposure, with different decision-makers. We list them so a leadership team knows which conversations to have, and with whom.

    Malpractice and negligence claims

    These are private lawsuits decided under state law. How a court would treat a clinician who followed, or overrode, an AI recommendation is one of the open questions above. The Federation of State Medical Boards adopted a policy in 2024 on physicians' use of AI, which its announcement says is focused on accountability for the use of AI tools. It is worth reading with your counsel and your medical staff leadership.

    The federal nondiscrimination rule

    Under 45 CFR 92.210, a covered entity "must not discriminate on the basis of race, color, national origin, sex, age, or disability in its health programs or activities through the use of patient care decision support tools," and has "an ongoing duty to make reasonable efforts to identify" tools that use those characteristics as inputs and to mitigate the risk. Those duties applied from May 1, 2025. Ask counsel how the rule applies to you and whether its enforcement has changed.

    State attorneys general and state AI laws

    In September 2024 the Texas Attorney General announced a settlement with an AI vendor, Pieces Technologies, resolving allegations that it made false and misleading statements about the accuracy and safety of a product used in Texas hospitals. The matter concerned the vendor's marketing. It was settled, and no court ruled on the allegations. Several states also have laws on telling patients when AI is used, which we summarize on our state laws page.

    Device reporting, when the tool is an FDA-regulated device

    The Joint Commission and CHAI guidance says organizations should treat AI-related safety events like other patient safety events and "use FDA pathways if the AI is a regulated device." Whether a tool is a device, and what reporting duties your organization has, are questions for counsel. Our FDA page explains the framework.

    The Joint Commission and CHAI guidance, and the voluntary certification built on it, are different in kind. They are voluntary, and they describe good practice. We haven't found a Joint Commission accreditation standard specific to AI.

    What Vendor Contracts Do

    Because the law is unsettled, the contract carries a lot of weight. CHAI's playbook recommends that "organizations should consult qualified legal counsel when reviewing AI vendor contracts, particularly provisions related to indemnification, limitation of liability, and data ownership." It also flags responsibility and timelines for incident reporting as "a consequential gap in many current vendor agreements."

    CHIME's Principles for Responsible AI makes a related point from the provider's side: when adopting third-party AI tools, especially ones built into clinical workflows, providers "can face additional uncertainty around liability, transparency and oversight." What your own agreements say is something only counsel can tell you. Our pages on evaluating vendor claims and vendor BAAs list the governance questions to settle first.

    What Governance Does

    Governance doesn't decide who is liable. It lowers the chance that an AI tool contributes to harm, and it produces the record your counsel, your carrier and your board will ask for if something goes wrong.

    01

    Check important tools on your own patients

    FDA clearance and vendor studies describe how a tool performed on the data the developer submitted. In the 2023 American Hospital Association IT survey, 61% of hospitals that used predictive models had evaluated them for accuracy on their own data, and 44% for bias (Nong and colleagues, Health Affairs, 2025). A federal brief on 2024 reports 82% and 74%, from a differently worded question. CHAI's playbook leaves it to each organization to decide, by risk tier, when local validation is needed.

    02

    Train clinicians on limits and on when to override

    FDA's Clinical Decision Support guidance defines the risk plainly: "Automation bias is the propensity of humans to over-rely on a suggestion from an automated system." Training on a tool's known failure modes, on when to be skeptical, and on how to record an override is the direct answer to it. The Joint Commission and CHAI guidance asks organizations to define and document role-specific training for the people who use AI tools.

    03

    Keep a documented intake and approval process

    An intake step, review criteria and approval records show who looked at a tool, what they found and what conditions were placed on its use. That record is what makes the rest of this list demonstrable.

    04

    Monitor after go-live, and report AI-related events

    The guidance notes that AI tools and their underlying algorithms "may be updated periodically," so performance can change. It says monitoring should be risk-based and scaled to your setting, and that organizations "should treat these events like patient safety events by capturing them in internal incident systems."

    05

    Have counsel read the AI provisions in your vendor contracts

    Liability caps, indemnification, warranties, insurance requirements, incident reporting duties and data use terms all belong in that review. Knowing what your contracts do and don't provide tells you how much of the risk you are carrying yourself.

    What This Means by Role

    General counsel

    You own the legal questions on this page. What helps most from the rest of the organization is a current inventory of AI tools, the contracts that govern each one, and the validation and monitoring records for the tools closest to clinical decisions.

    CMO and CMIO

    Clinician training and override practice sit with you. Ask whether clinicians know each tool's limits, and whether an override is easy to make and gets recorded.

    Risk management and quality

    Make sure AI-related near misses and harms can be captured in your existing incident system, and ask your malpractice carrier in writing how AI-assisted care is treated under your policy.

    Board members

    Ask whether management can show, with documents, which AI tools influence clinical decisions and who is accountable for each. Our page on board questions goes further.

    Frequently Asked Questions

    Common questions from healthcare leaders about AI and liability. For each one, the legal answer belongs to your counsel.

    Does FDA clearance shift liability to the vendor?

    Not by itself, as far as governance is concerned. FDA clearance or approval speaks to the device. It doesn't speak to whether your organization checked the tool on its own patients, trained staff or monitored it, and many AI tools in hospitals are never reviewed by FDA at all. How a tool's FDA status affects a legal claim is a question for counsel.

    Will our vendor contract protect us?

    It depends on what it says. CHAI's playbook calls contractual risk allocation the most practical tool currently available and recommends that legal counsel review indemnification, limitation of liability and data ownership terms. Ask counsel where your agreements leave you, tool by tool.

    Is a physician responsible for a decision made with an AI recommendation?

    Whether a clinician is liable in a given case is a legal question that turns on the facts and on state law. The Federation of State Medical Boards adopted a policy in 2024 on physicians' use of AI that focuses on accountability, and it is worth reading with your medical staff leadership and counsel. From a governance standpoint, the practical steps are training on each tool's limits and a clear, recorded way to override it.

    Are AI-related malpractice claims increasing?

    We haven't found reliable public data. Figures circulate online without a primary source, including one that an earlier version of this page repeated and that we have removed. Your malpractice carrier and broker are the best sources for what they are seeing.

    What about bias in AI tools?

    A 2019 study in Science found that a widely used commercial algorithm showed significant racial bias because it predicted health care costs in place of illness. The federal rule at 45 CFR 92.210, which has applied since May 1, 2025, calls for reasonable efforts to identify and mitigate discrimination risk from patient care decision support tools. Ask counsel how it applies to the tools you use.

    Does our malpractice insurance cover AI-assisted care?

    That depends on your policy. Ask your carrier and broker in writing how AI-assisted care is treated, and have counsel read the answer.

    Sources

    About the Authors

    Teresa Younkin

    Teresa Younkin, MSHI

    CEO & Co-Founder, Mosaic Life Tech

    20+ years leading AI, data governance, and interoperability initiatives across provider, payer, and federal health IT environments, including HL7 Da Vinci standards work and ONC programs.

    Jim Younkin

    Jim Younkin, MBA, FACHDM

    CTO & Co-Founder, Mosaic Life Tech

    30+ years across federal health IT programs, enterprise interoperability, and AI governance, including directing federal AI initiatives for ONC and co-founding Pennsylvania's first regional HIE serving 4M+ patients.

    Mosaic Life Tech helps healthcare executives build board-visible AI governance posture in alignment with Joint Commission and CHAI guidance. We don't sell AI tools or represent vendors. Our work is advisory, we aren't attorneys, and we refer legal questions to counsel.

    Want the governance record in order before counsel asks for it?

    We help healthcare leaders inventory the AI tools that influence clinical decisions, name an owner for each, and build the validation, training and monitoring record. Legal questions go to your attorney.

    Start a Conversation