Artificial Intelligence in Healthcare: Legal Concerns for Southeast Michigan Medical Practices

Szura & Delonis, PLC

By Szura & Delonis, PLC

Artificial intelligence is finding its way into the everyday work of medical practices—from drafting visit notes and answering patient messages to suggesting billing codes and supporting clinical decisions. For physicians, practice administrators, and other healthcare professionals in Southeast Michigan, the question is not simply whether an AI tool saves time. It is whether the practice can use that tool without compromising patient privacy, clinical judgment, or compliance.

Existing legal obligations do not disappear when a practice introduces AI. HIPAA requirements, Michigan’s medical malpractice standards, and rules governing accurate claims submissions remain relevant to how these tools are selected, configured, and supervised.

Before your practice adopts an AI scribe, chatbot, or decision-support platform, consider the following legal concerns.

Patient Privacy and Vendor Access

An AI tool may receive much more patient information than a practice initially realizes. An ambient documentation system, for example, may process an entire conversation rather than just the final note. A patient-facing chatbot may collect symptoms, medication information, and appointment details.

When a vendor creates, receives, maintains, or transmits protected health information on behalf of a HIPAA-covered practice, it generally acts as a business associate. HHS specifically identifies certain third-party AI chatbots on patient portals as examples of business associates. A HIPAA-compliant business associate agreement, or BAA, is therefore an essential starting point—not an optional vendor add-on.

However, signing a BAA does not complete the practice’s compliance work. HHS also requires covered entities to assess risks associated with their cloud environment and implement appropriate safeguards for electronic protected health information.

Before allowing an AI vendor access to patient information, practices should examine:

  • What information the system collects, including recordings, transcripts, prompts, and generated responses.
  • Whether patient information is retained or used to train or improve models.
  • Which subcontractors receive or store the information.
  • How access, security incidents, data deletion, and contract termination are handled.
  • Whether the vendor’s service agreement and privacy terms are consistent with the BAA.

A vendor’s use of patient information must remain within the permissions established by applicable law and the contractual relationship. Do not assume that a general promise of “HIPAA compliance” authorizes every secondary use of patient data.

As a practical safeguard, practices should prohibit staff from entering identifiable patient information into unapproved AI tools. They should also review recording, patient-notice, consent, and any applicable heightened confidentiality requirements before deploying tools that listen to clinical encounters. Those questions require a workflow-specific analysis rather than a blanket assumption that a BAA resolves them.

Clinical Judgment and Patient Safety

AI should support professional judgment—not become a substitute for it.

Michigan’s medical malpractice statute establishes standards applicable to general practitioners and specialists and requires proof of causation and injury. Adopting an AI system does not replace that statutory framework or establish that following the system’s recommendation meets the applicable standard of care.

Consider a hypothetical AI-generated visit note that omits a medication allergy mentioned during the appointment. If the clinician signs the note without checking it, the omission becomes part of the record that other professionals may rely on. A faster documentation process is not necessarily a safer one.

A sensible implementation policy should require clinicians to verify material facts, correct unsupported statements, and review recommendations against the patient’s actual condition. CMS’s responsible-use principles likewise emphasize human oversight and ongoing monitoring for accuracy and safety.

Regulatory status also matters. Some clinical decision-support software falls outside FDA’s medical-device definition, while other software functions remain subject to FDA oversight. One important consideration is whether the healthcare professional can independently review the basis for a recommendation rather than rely primarily on the software’s output.

Before adopting a clinical AI product, ask the vendor to explain its intended use, regulatory status, limitations, and validation. A tool appropriate for drafting administrative text may not be appropriate for diagnosis or treatment decisions.

Documentation, Billing, and Contracts

AI-generated documentation can create financial exposure when it supports claims that do not accurately reflect the care provided.

Practices remain responsible for ensuring that submitted claims are accurate and adequately supported, regardless of whether a person or an AI system generated the underlying note or code. Unsupported documentation can create overpayment concerns and, depending on the facts and the applicable knowledge requirements, potential False Claims Act exposure.

Before submitting claims based on AI-assisted work, practices should establish controls to verify:

  • That the documented services were actually performed.
  • That diagnoses and codes are supported by the medical record.
  • That generated notes do not invent findings, counseling, or procedures.
  • That recurring errors trigger investigation and correction rather than repeated submission.

The vendor contract deserves equal attention. A BAA addresses important privacy obligations, but practices should also negotiate commercial terms governing performance, support, responsibility, and remedies.

Useful contract-review questions include:

  • Who bears responsibility for security incidents and third-party claims?
  • Do liability caps leave the practice with substantial unrecoverable exposure?
  • Can the vendor change data-use terms or model functionality unilaterally?
  • Must the vendor disclose material updates and known safety limitations?
  • Can the practice export its records and obtain appropriate data deletion when the relationship ends?
  • Does the practice’s insurance cover the proposed AI-assisted activities?

These are negotiation and risk-allocation issues, not protections that should be assumed from a product demonstration or marketing statement.

Steps Before Launching AI

A practice does not need to reject AI to manage its legal risks. It needs a documented process for deciding which tools are appropriate and how they will be used.

A practical pre-launch review should include:

  1. Inventory the proposed tools and identify their clinical, administrative, and billing functions.
  2. Map where patient information travels and which organizations can access it.
  3. Complete the appropriate privacy and security assessment and obtain required BAAs.
  4. Review vendor contracts, intended uses, and relevant regulatory status.
  5. Establish patient-notice and consent procedures appropriate to the workflow.
  6. Train staff on approved uses, prohibited inputs, and required human review.
  7. Test the system before broad deployment and monitor errors after implementation.
  8. Assign responsibility for incident response, complaints, and decisions to suspend a tool.

These steps put privacy safeguards and meaningful human oversight into the implementation process rather than treating them as afterthoughts. HHS’s cloud guidance and CMS’s AI principles both emphasize those responsibilities.

Planning to introduce AI into your medical practice? Before signing a vendor agreement or allowing access to patient information, seek a legal review of the proposed arrangement.

Contact Szura & Delonis, PLC at (248) 716-3600 to discuss your practice’s AI-related privacy, contracting, and compliance concerns. The firm is located in Southfield and serves clients throughout Michigan, including Oakland, Wayne, and Macomb counties.

Please do not include patient information or other confidential details in an initial contact form, text message, or voicemail. Contacting the firm does not create an attorney-client relationship.

This post is intended for general informational purposes and does not constitute legal advice. The requirements applicable to a particular AI tool depend on its functions, data flows, contractual terms, and the circumstances of its use.

Client Reviews

Rick Delonis was outstanding for me in a business matter. Only providing professional information and execution. He was always there to answer anything I needed.

Brian Klanow

This firm has been handling my legal work for nearly 10 years. They have excelled when it comes to reviewing my business contracts, handling articles of incorporation for my entities and, most importantly...

Dan

These guys are the best. They really took care of me when I needed them the most. Very honest and truly care about their clients. I would highly recommend Rick Delonis and the other partners at this law firm to...

John

Being a landlord sometimes is not all it's cracked up to be. Being new to the game mistakes will be made and can be very costly if not handled correctly. After initial negotiations failed our case went to trial...

Francis

Address

Southfield Office
29777 Telegraph Rd
#2401

Southfield, MI 48034

Office

Contact Us

Fill out the form or call us at (248) 716-3600 to reach us.

We Accept the Following Payment Solutions

Payment Methods