Patient-led, evidence-informed insights on medical AI

Practical takeaways for clinicians, health leaders, and recruiters.

Stay current on AI in patient care

Join clinicians and recruiters receiving practical, evidence-informed updates.

Subscribe now About Dan

Developing A Patients' AI Bill of Rights - for hospitals & medical centers

Developing A Patients' AI Bill of Rights - for hospitals & medical centers
Developing a framework for a Patients' AI Bill of Rights for hospitals and medical centers

I originally formulated this concept in 2025 largely as an outgrowth of my own experience and training. You will find my original discussion of this topic elsewhere on this site, but as I spoke with healthcare leaders, the consensus was clear: we need a far more comprehensive framework that can be applied across the hospital system. My half-day, in-hospital workgroups grew in scope from talking about how patients use AI systems to what expectations patients have of healthcare systems that were deploying AI systems.

TL;DR

Healthcare AI is entering diagnosis, documentation, treatment, and care coordination faster than patients can see or challenge its role.

This proposed Patients’ AI Bill of Rights translates the Belmont Report’s principles of Respect for Persons, Beneficence, and Justice into ten practical protections: the rights to know, understand, access and control health information, make meaningful choices, receive human review, expect safety and equity, obtain accountability, and benefit from fair access.

The purpose is not to block useful AI. It is to ensure that innovation earns trust and remains answerable to the people it affects.

Why I Wrote This

A prescribing error nearly killed me.

It happened because a consequential decision was made about my body without the full clinical picture. A well-designed medication-safety system might have flagged the problem. A poorly governed AI system might have compounded it.

That tension is why I wrote this.

I believe AI can make healthcare safer. I also know what it feels like when a decision about your body is made through a process you cannot see, understand, or question.

AI is no longer experimental background technology. In the American Medical Association’s 2026 survey, 72% of physicians reported incorporating at least one of the identified AI use cases into their work. Physicians averaged 2.3 use cases, compared with 1.1 in 2023. The survey also found that privacy, validation, training, and the effect of AI on the patient-physician relationship remain major concerns.[2]

In December 2025, the FDA cleared UpDoc prescription software for protocol-based insulin management in adults with type 2 diabetes. The software calculates instructions within parameters established by the patient’s healthcare provider.[3]

That clearance matters. But it does not mean the safety question has been settled.

Regulatory clearance is one layer of evidence. It is not a substitute for responsible implementation, post-deployment monitoring, or an accountable human being. A cleared tool can still be applied to the wrong patient, used outside its intended purpose, or deployed without an effective escalation process.

Safety and accountability are inseparable.

The question is not simply whether healthcare AI can be safe. It is whether patients can know when it is involved, understand the role it played, request human review, make meaningful choices, and reach an accountable person when something goes wrong.

Why the Belmont Report?

I could have invented another ethical framework. Healthcare has no shortage of principles, pledges, and white papers.

What we need is not another moral compass. We need to apply an enduring one to a new technology.

Published in 1979, the Belmont Report established three foundational principles for research involving human participants:

  • Respect for Persons: Protect individual agency and people with diminished autonomy.
  • Beneficence: Maximize potential benefits while minimizing foreseeable harms.
  • Justice: Distribute the benefits and burdens of research fairly.[1]

The Belmont Report is an ethical framework for human-subject research. It is not itself a clinical AI law. Its principles influenced later human-subject protections and still provide a useful lens for asking three essential questions:

  1. Does the patient retain meaningful agency?
  2. Are benefits being maximized while harms are actively reduced?
  3. Are benefits, risks, and access distributed fairly?

These ten proposed rights are my attempt to answer those questions.

They are not a summary of rights currently guaranteed in every U.S. jurisdiction. They are a standard healthcare organizations, policymakers, developers, clinicians, and patients can work toward.

The Ten Rights

1. The Right to Know

Patients should be told when AI materially influences their diagnosis, treatment, triage, clinical documentation, or access to care.

Disclosure should happen before the interaction when practical, not after a patient discovers an algorithmic recommendation buried in the medical record.

This is not a demand to place a warning label on every piece of software. It is a demand for transparency when AI could meaningfully affect a patient’s health, choices, or relationship with a clinician.

In a nationally representative survey of 2,021 U.S. adults, 62.7% said it was very important to be notified when AI was used in their healthcare. Only 4.8% said notification was not important.[4]

Patients should not have to ask, “Was AI involved?” after something goes wrong.

2. The Right to a Meaningful Explanation

Patients deserve a plain-language explanation of:

  • What the AI is intended to do
  • What information it uses
  • Its known limitations
  • Whether it has been evaluated for people like them
  • How much weight the clinician gave its recommendation
  • What human being remains responsible

Meaningful explanation does not require exposing source code or asking clinicians to explain every mathematical operation inside a model.

It requires enough information for a patient to understand the AI’s role, its limits, the available alternatives, and who can answer questions.

This matters because public evidence remains incomplete. A 2025 analysis of 691 FDA-cleared AI-enabled devices found major gaps in publicly available information about study design, demographic representation, patient outcomes, and safety assessment.[6] Public summaries do not necessarily contain everything submitted to the FDA, but they are often what patients, clinicians, and purchasers can see.

Trust cannot depend on information nobody is allowed to examine.

3. The Right to Access, Correction, and Portability

Patients should be able to access their health information, request corrections, receive it in a usable format, and direct it to a clinician, caregiver, second-opinion provider, or trusted digital tool.

In the United States, saying that patients legally “own” all their health data is too broad. Record-ownership rules vary. HIPAA instead provides important rights to inspect and obtain copies of records, request amendments, and receive information about certain uses and disclosures.[7]

Federal information-blocking rules also seek to prevent practices that improperly interfere with the access, exchange, or use of electronic health information.[8]

But there is a dangerous gap: HIPAA protections may not follow health information when a patient voluntarily sends it to a consumer AI application that is not a HIPAA-covered entity or business associate.

Access without understandable privacy boundaries is not genuine control.

4. The Right to Meaningful Choice

Patients should be able to decline optional, patient-facing, or discretionary AI uses without retaliation or loss of medically necessary care.

When feasible, they should be offered a reasonable human-reviewed alternative. When an AI-free alternative is not practical, the limitations should be explained honestly and the patient should still be able to request human reconsideration.

This is a proposed standard, not a universal right under current U.S. law.

Meaningful choice requires more than a checkbox. In a 2025 study involving ambient AI documentation, willingness to consent fell from 81.6% to 55.3% when participants received more detailed information about AI involvement, data storage, and corporate relationships.[9] The study was small and should not be treated as nationally representative, but its message is important.

What we disclose changes what people choose.

Consent obtained through incomplete disclosure is not meaningful consent.

5. The Right to Meaningful Human Review

An accountable clinician or care team should have the training, time, information, and authority to question or override an AI recommendation.

A “human in the loop” is not enough if that human simply approves whatever the system produces.

Meaningful review requires:

  • A named responsible person or team
  • The authority to challenge the output
  • A documented escalation path
  • The ability to record overrides and concerns
  • Protection from organizational pressure to follow the algorithm

Cleveland Clinic’s ambient AI deployment shows that operational governance can be built at scale. Its 2026 report described more than 4,800 clinicians using the system across more than 3.5 million encounters, supported by governance, onboarding, clinician support, and continuous learning processes.[10]

That report is an operational case study, not proof of clinical safety. Its value is showing that governance can be embedded in daily work instead of left in a policy document.

Human oversight must be a functioning system, not a ceremonial signature.

6. The Right to Validated and Continuously Monitored AI

Healthcare AI should be supported by evidence proportionate to its risk before deployment. It should then be monitored for errors, performance drift, unintended consequences, and patient harm.

Validation should ask:

  • Does the tool work for its intended use?
  • Was it evaluated in the population where it will be deployed?
  • Does it improve a meaningful clinical or operational outcome?
  • What happens when the environment, data, or patient population changes?
  • How will adverse events be detected and reported?

The FDA’s dynamic, noncomprehensive list contained more than 1,500 AI-enabled medical-device entries by mid-2026. Approximately three-quarters were in radiology.[11]

Yet the 2025 examination of public device summaries found that demographic representation was absent from 95.5% of those summaries, while fewer than 1% reported patient outcomes.[6]

The number of cleared devices is growing faster than the transparency of the public evidence behind them.

Patients deserve to know whether a tool has been validated for people like them, not merely whether it performed well somewhere.

7. The Right to Equitable Performance

Healthcare AI should be evaluated across relevant patient populations. Meaningful performance disparities should be disclosed, investigated, mitigated, and continuously monitored.

No complex system can be promised to be completely “bias-free.” But healthcare organizations can be required to look for disparities before patients are harmed.

One of the clearest examples remains the 2019 study by Obermeyer and colleagues. A widely used population-health algorithm relied on healthcare spending as a proxy for medical need. Because unequal access had historically resulted in lower spending on Black patients, the algorithm systematically underestimated their needs.

Correcting the bias would have increased the proportion of Black patients identified for additional care from 17.7% to 46.5%.[12]

In dermatology, researchers evaluating AI on a diverse, curated clinical image set found substantially worse performance for darker skin tones and uncommon diseases. Adding more representative data helped reduce the disparity.[13]

Bias is not just a technical defect. When inequity is encoded into a system and deployed at scale, it becomes injustice at scale.

Justice must be designed, measured, and maintained.

8. The Right to Accountability, Appeal, and Remedy

When AI contributes to an error, patients deserve more than “the algorithm said so.”

They should be able to learn:

  • Who approved the system
  • Who was responsible for monitoring it
  • How the output influenced their care
  • Who had authority to override it
  • How to request reconsideration
  • How inaccurate information will be corrected
  • What remedy is available when harm occurs
  • How the organization will prevent recurrence

Accountability must follow the entire lifecycle: selection, validation, deployment, use, monitoring, incident response, and correction.

The FDA’s August 2026 discussion paper on generative AI-enabled medical devices explores a possible competency-inspired assessment model combining nonclinical benchmarking with clinical confirmation. It also asks important questions about postmarket monitoring for systems whose outputs may vary.[17]

The paper is a request for feedback, not adopted policy, and it does not resolve legal liability.

That is precisely why healthcare organizations need to name accountable people now.

9. The Right to Privacy and Control Over Secondary Use

Patients should have meaningful choices about using their health information to train, test, improve, commercialize, or market AI systems beyond the direct delivery of their care.

Those choices should be:

  • Specific
  • Understandable
  • Separate from routine care consent
  • Easy to revisit or withdraw when technically and legally possible
  • Free from manipulative interface design

This right is different from access and portability. The third right concerns a patient’s ability to obtain and use their information. This right concerns what other parties may do with it.

The FTC’s actions involving BetterHelp and GoodRx demonstrate why this distinction matters. BetterHelp agreed to pay $7.8 million after the FTC alleged that sensitive mental-health information was disclosed for advertising despite privacy promises.[14] GoodRx paid a $1.5 million civil penalty in the FTC’s first enforcement action under the Health Breach Notification Rule.[15]

The 2026 Health & AI Policy Index identified 240 policies in its January snapshot, revealing a fragmented mix of federal, state, international, sector-specific, and voluntary requirements.[18]

Patients should not need to understand a regulatory patchwork before they can protect their most intimate information.

10. The Right to Equitable Access and Accessibility

The benefits of healthcare AI should be available regardless of income, disability, language, geography, broadband access, digital literacy, or comfort with technology.

This requires more than putting an application online.

Accessible AI should include:

  • Plain-language communication
  • Translation and culturally relevant information
  • Disability accommodations
  • Non-digital alternatives
  • Support from trained people
  • Options that do not assume smartphone or broadband access
  • Affordable pathways to care

The 2003 National Assessment of Adult Literacy, still the only national direct assessment of its kind, found that only 12% of U.S. adults demonstrated proficient health literacy.[19]

A right that a patient cannot read, understand, or exercise is not a meaningful right. It is paperwork.

AI should narrow access gaps, not automate them.

The Path Forward

Rights become real only when they are connected to owners, workflows, resources, measurements, and escalation processes.

Policymakers should develop risk-based requirements for disclosure, validation, monitoring, appeal, and remedy. Rules should identify accountable organizations and people, not just accountable technologies.

Developers and healthcare institutions should build diverse datasets, publish clinically meaningful evidence, monitor performance after deployment, and include patients in system design and governance. A committee deciding how AI will affect patients, with no patients at the table, is not complete governance.

Healthcare professionals need training, time, protected override authority, and clear escalation paths. Clinicians cannot be held accountable for AI they were never taught to evaluate or permitted to challenge.

Patients and caregivers must be included where policies, procurement decisions, consent processes, and safety measures are created. Their participation should be treated as a design requirement, not a courtesy.

Why This Matters Now

On August 18, 2026, the FDA released its discussion paper on generative AI-enabled medical devices and opened docket FDA-2026-N-7874. Public comments are due October 19, 2026.[17]

The Digital Medicine Society has also launched an initiative to develop and openly release practical resources for operationalizing healthcare AI governance.[20]

The conversation is changing.

The question is no longer simply, “Does your organization have an AI framework?”

It is becoming, “Can you govern AI during an ordinary clinical day, when a patient is waiting, a model behaves unexpectedly, and someone must decide what happens next?”

A framework on a shelf does not protect a patient.

The Standard Healthcare AI Must Earn

Trust is not a communications problem to solve after deployment.

Trust grows when people know what is happening, understand their choices, can reach an accountable human, and have a meaningful path to challenge a decision.

The Patients’ AI Bill of Rights is not finished legal code. It is a practical starting point for turning familiar ethical principles into protections patients can see and use.

AI can help clinicians detect risks, reduce administrative burden, and make better information available at the right moment.

But the measure of progress cannot be how much AI we deploy.

It must be how well that AI protects the dignity, agency, safety, and humanity of every patient it touches.

I work with hospitals to translate questions like these into practical governance decisions through patient-centered workshops for clinicians and healthcare leaders. I explore the broader framework in The Healthcare AI Governance Playbook.

Which of these rights will be hardest for healthcare organizations to operationalize, and where should patients have a greater voice?

References

  1. National Commission for the Protection of Human Subjects of Biomedical and Behavioral Research. The Belmont Report. April 18, 1979.
  2. American Medical Association. Augmented Intelligence Research: Physician Sentiment Survey 2026. March 2026.
  3. U.S. Food and Drug Administration. 510(k) Premarket Notification: UpDoc, K253281. Decision December 23, 2025.
  4. Platt JE, et al. Public Attitudes Toward Notification of Use of Artificial Intelligence in Health Care. JAMA Network Open. 2024.
  5. Bracic A, et al. Factors for Patient Trust and Acceptance of Medical Artificial Intelligence. JAMA Network Open. 2026;9(3).
  6. Lin JC, et al. Benefit-Risk Reporting for FDA-Cleared Artificial Intelligence-Enabled Medical Devices. JAMA Health Forum. 2025;6(9).
  7. U.S. Department of Health and Human Services. Your Rights Under HIPAA.
  8. Assistant Secretary for Technology Policy and Office of the National Coordinator for Health Information Technology. Information Blocking.
  9. Lawrence K, et al. Informed Consent for Ambient Documentation Using Generative AI in Ambulatory Care. JAMA Network Open. 2025;8(7).
  10. Merlino A, et al. Accelerating Ambient AI Scribe Enterprise-Scale Deployment. npj Health Systems. 2026;3:74.
  11. U.S. Food and Drug Administration. Artificial Intelligence-Enabled Medical Devices.
  12. Obermeyer Z, et al. Dissecting Racial Bias in an Algorithm Used to Manage the Health of Populations. Science. 2019;366(6464):447-453.
  13. Daneshjou R, et al. Disparities in Dermatology AI Performance on a Diverse, Curated Clinical Image Set. Science Advances. 2022;8(32).
  14. Federal Trade Commission. BetterHelp Customers Will Begin Receiving Notices About Refunds Related to 2023 Privacy Settlement. May 6, 2024.
  15. Federal Trade Commission. FTC Enforcement Action to Bar GoodRx from Sharing Consumers’ Sensitive Health Information for Advertising. February 1, 2023.
  16. Washington State Office of the Attorney General. Protecting Washingtonians’ Personal Health Data and Privacy.
  17. U.S. Food and Drug Administration. Considerations for the Regulation of Generative AI-Enabled Medical Devices: Discussion Paper and Request for Feedback. August 18, 2026.
  18. Moss W, et al. Mapping AI Regulation in Health Care with the Health & AI Policy Index. npj Digital Medicine. 2026;9:413.
  19. National Center for Education Statistics. The Health Literacy of America’s Adults: Results From the 2003 National Assessment of Adult Literacy.
  20. Digital Medicine Society. Operationalizing AI Governance in Healthcare. July 2026.