Table of Contents
Ready to See Results?
From strategy through execution, Atlantic Health Strategies integrates compliance, operations, and growth into durable, measurable results. Let’s put our expertise to work for your organization.
The Short Answer
Behavioral health operators must treat every AI tool that touches PHI as a regulated system. That means a written risk analysis, a signed Business Associate Agreement, human clinician sign-off on adverse decisions, 42 CFR Part 2 consent handling, and documented monitoring for bias and error. That is the floor.
The DOJ Criminal Division, HHS Office for Civil Rights (OCR), SAMHSA, and CMS have all moved on this in the last 24 months, and federal prosecutors are now specifically instructed to ask about it. On September 23, 2024, the DOJ Criminal Division updated its Evaluation of Corporate Compliance Programs (ECCP). The revisions now require prosecutors to evaluate whether a company’s compliance program includes safeguards against the “deliberate or reckless misuse” of new technologies, including AI, that would violate criminal laws or the company’s Code of Conduct. Then-Deputy Attorney General Lisa Monaco put it plainly at the ABA in March 2024: “Fraud using AI is still fraud.”
If you run a treatment center in Florida, Texas, New Jersey, or Arizona and you cannot hand a surveyor or a prosecutor the risk assessment, the BAA, and the human-in-the-loop protocol for every AI tool touching a chart, a claim, or a coverage decision, you are exposed.
The Regulators Moved. Most Operators Did Not.
Three federal actions matter more than any LinkedIn discourse about AI.
DOJ ECCP (September 2024). Going forward, DOJ expects companies to stress-test AI applications to identify vulnerabilities, continuously monitor high-risk AI use cases, and document risk mitigation efforts. Prosecutors reference this document when they decide whether to charge, whether to impose a monitor, and how large the penalty will be.
HHS OCR on Section 1557. OCR issued the Section 1557 final rule on May 6, 2024, effective July 5, 2024. Under 45 C.F.R. § 92.210, covered entities are expressly prohibited from discriminating on the basis of race, color, national origin, sex, age, or disability in health programs or activities through the use of patient care decision support tools. Compliance with the decision-support-tool provisions was required by May 1, 2025. In her January 10, 2025 “Dear Colleague” letter, then-OCR Director Melanie Fontes Rainer wrote that “discrimination in AI-driven health care tools – whether intentional or unintentional – can lead to uneven care, diminished trust, and financial risks, such as lawsuits and regulatory interventions.”
SAMHSA / OCR 42 CFR Part 2 Final Rule. Persons subject to the regulation must comply with the applicable requirements of the final rule by February 16, 2026. OCR confirmed that from February 16, 2026, it will accept complaints alleging violations of the regulation that protects the confidentiality of SUD patient records and alleged breach notification violations, and has made noncompliance with Part 2 an enforcement priority.
Now look at the enforcement picture. In total, OCR imposed 22 financial penalties to resolve HIPAA violations in calendar year 2024 and collected $9,944,612 in settlements and penalties. OCR’s most frequently cited violation was an inadequate risk analysis, which appeared in 13 matters. Across 663 large breaches reported in 2024, the protected health information of 242,908,056 individuals was exposed or impermissibly disclosed. If your team has not documented an AI-specific risk analysis, that is the finding waiting for you.
What Actually Fails in a Behavioral Health Setting
Picture the fact pattern. An ambient AI scribe drafts a group therapy note. The clinician clicks accept. The note gets pushed to Kipu or Sunwave. Ninety days later a payer SIU audit lands and pulls 30 charts.
Here is what breaks.
- No signed BAA with the scribe vendor. The vendor is a subcontractor to your EHR, or worse, a Chrome extension a clinician installed. Under HIPAA, only a signed Business Associate Agreement legally binds the vendor to protect PHI. No BAA, no PHI touching the tool.
- Part 2 consent is missing or expired. Piping session audio through a third-party AI vendor without valid consent is a Part 2 violation. Under the 2024 amendments, HIPAA penalties now apply to Part 2 violations, including civil penalties ranging from $141 to $2.1 million per violation (adjusted annually for inflation), criminal fines, and possible imprisonment for the most serious violations.
- SUD counseling notes get swept in. The Final Rule creates a new definition for an SUD clinician’s notes analyzing the conversation in an SUD counseling session that the clinician voluntarily maintains separately from the rest of the patient’s SUD treatment and medical record and that require specific consent from an individual. If your scribe drops raw therapist analysis into the general record, you have collapsed a protection the regulation just built.
- The AI hallucinates a Level of Care justification. We have tested several AI chart audit tools. They skip obvious errors and invent findings. If a UR reviewer reads an ASAM Criteria 4th Edition rationale that the clinician never wrote, that is a False Claims Act exposure, not a documentation quirk.
None of these fail in isolation. They fail together, on the same chart, in the same audit. Prosecutors have been told to look for exactly this pattern.
Coverage Decisions, Prior Auth, and the CMS WISeR Model
AI on the operator side is one problem. AI on the payer side is a different one, and it will hit your census.
On February 6, 2024, CMS issued an FAQ memo on Medicare Advantage. CMS clarified that Medicare Advantage organizations may use algorithms and AI to assist with coverage determinations, but those technologies may not override standards related to medical necessity. Under 42 C.F.R. § 422.566(d), an adverse medical necessity decision must be reviewed by a physician or other appropriate clinician with expertise in the field of medicine appropriate for the service at issue.
Then came WISeR. The Wasteful and Inappropriate Service Reduction (WISeR) Model runs for six performance years from January 1, 2026 to December 31, 2031 in six states: New Jersey, Ohio, Oklahoma, Texas, Arizona, and Washington. A human clinician must review every denial decision. A recent survey by the National Association of Insurance Commissioners found that in 2025 70% of health insurers are implementing artificial intelligence to conduct prior authorization or plan to do so within three years.
If your treatment center sits in any of those six states, expect algorithmic scrutiny on documentation quality, medical necessity language, and continued-stay justifications. Weak notes will not survive. Your utilization management team should read every denial rationale for signs of pattern-matching that ignored patient-specific facts, because that is the exact scenario CMS said would be non-compliant.
What Operators Should Do This Quarter
Not a maturity model. A punch list.
- Inventory every AI tool that touches PHI. Scribes, chart auditors, intake bots, verification-of-benefits tools, revenue cycle predictors, marketing chatbots. If your leadership team does not know where the tool sits, they cannot analyze the risk.
- Get the BAA or turn the tool off. No BAA, no PHI. This is not negotiable and it is the single fastest way to shrink your surface area.
- Write the AI-specific risk analysis. Document what data flows where, how the vendor trains on it (or does not), what the deletion policy is, and what your human override looks like. The September 2024 ECCP advises companies to conduct risk assessments of their use of new and emerging technologies and cites the January 2023 National Institute of Standards and Technology (NIST) AI Risk Management Framework as a resource. This is the artifact a prosecutor or an OCR investigator will ask for.
- Add Part 2 consent language for AI processing of SUD records. Your consent forms probably do not name AI vendors as recipients. Fix that before your next state licensure survey.
- Human-in-the-loop, on paper. Write the policy. Log the overrides. Show the audit trail.
- Train the clinical team. Not a one-time deck. A recurring competency, tied to documented performance auditing.
Behavioral health has always been the sector where the regulator shows up first and the technology matures second. AI has not changed that. Operators who write it down, test it, and can hand a surveyor a binder will be fine. The ones treating AI as an IT decision instead of a compliance decision will not.
Frequently asked questions
Does an AI scribe vendor need a Business Associate Agreement in behavioral health?
Yes. Any vendor that creates, receives, maintains, or transmits PHI on your behalf is a business associate under HIPAA and requires a signed BAA. For SUD programs, you also need to confirm the vendor will honor 42 CFR Part 2 restrictions on use and re-disclosure, which most generic medical scribes do not address by default. Post-February 16, 2026, Part 2 violations carry HIPAA-tier civil penalties ranging from $141 to $2.1 million per violation. No BAA, no PHI touches the tool.
What did the DOJ change in September 2024 that affects behavioral health operators?
On September 23, 2024, the Criminal Division updated its Evaluation of Corporate Compliance Programs and now instructs prosecutors to evaluate whether a company’s compliance program includes safeguards against the deliberate or reckless misuse of AI. DOJ expects companies to stress-test AI applications, continuously monitor high-risk use cases, and document risk mitigation. For a behavioral health operator, an AI tool without a documented risk assessment and controls is a specific prosecutorial checkpoint at the time of any corporate criminal investigation.
Which states are affected by CMS’s WISeR AI prior authorization model?
The WISeR Model launched January 1, 2026 and operates in six states through December 31, 2031: New Jersey, Ohio, Oklahoma, Texas, Arizona, and Washington. Providers in those states will see AI-assisted prior authorization or pre-payment medical review on selected Original Medicare items and services, with a human clinician required to review every denial decision.
When did 42 CFR Part 2 compliance for the 2024 Final Rule become mandatory?
HHS finalized the rule with a compliance date of February 16, 2026. On that date, OCR began accepting Part 2 complaints and breach notifications and made noncompliance an enforcement priority. Operators running SUD programs should confirm consent forms, breach notification workflows, and any AI vendor handling of SUD records reflect the new rule.
References
- HHS Fact Sheet: 42 CFR Part 2 Final Rule
- CMS Innovation Center: WISeR (Wasteful and Inappropriate Service Reduction) Model
- Holland & Knight: New DOJ Compliance Program Guidance Addresses AI Risks (September 2024 ECCP)
- Mintz: ACA Section 1557 Final Rule. OCR Prohibits Discrimination Related to Use of AI in Health Care
- HIPAA Journal: OCR Reports to Congress on HIPAA Compliance and Data Breaches in 2024
- HIPAA Journal: February 16, 2026 Compliance Deadline for Part 2 Final Rule
- Woods Rogers: Compliance Deadline Approaches for 42 CFR Part 2 Amendments. Enhanced Penalties
- Congressional Research Service: Overview of the Medicare WISeR Model
- Shook, Hardy & Bacon: OCR Enforcement Activity. Trends and Insights
- McDermott: Section 1557 Patient Care Decision Support Tools. 12 Things to Consider