Guide

AI in Healthcare under Texas Law

What Texas requires when AI touches patients: the Attorney General's enforcement record on accuracy claims, TRAIGA's disclosure duties, and the consumer protection rules that were already in place.

Law checked through

Short Answer

Texas has no AI-specific licensing or approval regime for clinical AI tools. The rules that matter are general ones applied to an AI use. Marketing claims about an AI product's accuracy answer to the Deceptive Trade Practices-Consumer Protection Act (DTPA). Where AI is used in relation to health care services or treatment, the Texas Responsible Artificial Intelligence Governance Act (TRAIGA) requires a disclosure to the patient (or the patient's personal representative). Protected health information brings in the Health Insurance Portability and Accountability Act (HIPAA), and tools minors may use bring in the Securing Children Online through Parental Empowerment Act (SCOPE Act) and the Texas Data Privacy and Security Act (TDPSA). The clearest map of the Attorney General's enforcement posture is the 2024 settlement with Pieces Technologies, which treated marketed AI accuracy metrics as a consumer protection matter and resolved it with five years of disclosure and substantiation duties, no admission, and no money changing hands.

Which Laws Apply

  • Texas AI-specific: Business and Commerce Code § 552.051 (TRAIGA disclosure to consumers; health care provider duty).
  • Generally applicable Texas law: DTPA, Business and Commerce Code §§ 17.41 to 17.63 (accuracy marketing, enforcement); SCOPE Act, Business and Commerce Code chapter 509, and the Texas Data Privacy and Security Act, Business and Commerce Code chapter 541, where minors use the tool.
  • Federal: Federal Trade Commission (FTC) Act § 5 (15 U.S.C. § 45) for deceptive acts or practices in commerce; HIPAA where the tool handles protected health information.

The Pieces Settlement: What the Attorney General Actually Required

On September 18, 2024, Attorney General Ken Paxton announced a settlement with Pieces Technologies, a Dallas-based company whose generative AI products summarize patient charts and draft clinical notes inside hospital electronic health records. The case was filed as State of Texas v. Pieces Technologies, Inc., Cause No. DC-24-13476 in the 191st Judicial District Court of Dallas County, and resolved by an Assurance of Voluntary Compliance under DTPA § 17.58.

The State alleged that Pieces developed a series of metrics and benchmarks purporting to show its generative AI outputs were "highly accurate," including a "severe hallucination rate" of less than 1 per 100,000 and a "critical hallucination rate" below 0.001 percent. The Attorney General's investigation found those metrics were likely inaccurate and may have deceived hospitals about the accuracy and safety of the products. At least four major Texas hospitals had been providing their patients' health care data to Pieces in real time to generate the summaries. Pieces denied any wrongdoing or liability and contended it had accurately represented its hallucination rate.

The Assurance runs for five years after its effective date and then automatically terminates. Its operative duties, as written:

  • Marketing and advertising disclosures. If Pieces includes any metric, benchmark, or similar measurement describing the outputs of its generative AI products in marketing or advertising, it must clearly and conspicuously disclose (1) the meaning or definition of the metric and (2) the method, procedure, or other process used to calculate it. Alternatively, Pieces may retain an independent third-party auditor to assess, measure, or substantiate the product's performance, in which case all marketing statements must be consistent with and substantiated by the auditor's findings.
  • No unsubstantiated representations. A prohibition on false, misleading, or unsubstantiated representations (express or implied) about accuracy, reliability, efficacy, testing or monitoring methodologies, the meaning of metrics, or the data used to train the products.
  • Customer documentation. Clear and conspicuous disclosure to current and future customers of any known or reasonably knowable harmful or potentially harmful uses or misuses, including: the type of data and models used to train the products; the intended purpose and use plus any training or documentation needed for proper use; known or reasonably knowable limitations, including risks to patients and health care providers such as physical or financial injury from inaccurate output; known or reasonably knowable misuses that increase the risk of inaccurate outputs or harm; and documentation sufficient for a user to understand the nature and purpose of an output, monitor for patterns of inaccuracy, and avoid misuse.
  • Compliance monitoring. Within 30 business days of a written State request, Pieces must submit sworn compliance information, appear for depositions, or produce records for inspection and copying.

Three things the settlement did not include: any admission of liability, any civil penalty or monetary payment (the Assurance contains no penalty provision; it is a complete settlement and release of the State's claims based on the alleged facts), and any private right of action. The existing site Guide "Before a Business Adopts an AI Tool" already flags the practical lesson: a business adopting a health or high-stakes AI tool should ask the vendor how its own metrics were calculated.

TRAIGA's Health Care Disclosure Duty

Business and Commerce Code § 552.051 sets two disclosure rules. The one most businesses read first is subsection (b): a governmental agency that makes available an AI system intended to interact with consumers must disclose, before or at the time of the interaction, that the consumer is interacting with an AI system. That duty applies regardless of whether the AI interaction would be obvious to a reasonable consumer.

The health care duty is subsection (f): if an AI system is used in relation to health care service or treatment, the provider of the service or treatment must provide the disclosure under subsection (b) to the recipient of the service or treatment (or the recipient's personal representative) no later than the date the service or treatment is first provided. In an emergency, the disclosure is due as soon as reasonably possible. "Health care services" means services related to human health or to the diagnosis, prevention, or treatment of a human disease or impairment, provided by an individual licensed, registered, or certified under applicable state or federal law to provide those services.

Form matters. The disclosure must be clear and conspicuous, written in plain language, and free of any dark pattern (the term TRAIGA borrows from TDPSA § 541.001). It may be provided by hyperlink to a separate web page. Note what the duty is not: a duty to disclose accuracy metrics, to substantiate performance, or to limit clinical use. It is a duty to tell the patient that AI is involved.

The DTPA and AI Accuracy Marketing

The DTPA was the statute the Attorney General reached for in Pieces, and its structure explains why AI accuracy claims are a consumer protection matter in Texas without any AI-specific provision.

§ 17.46(a) declares false, misleading, or deceptive acts or practices in the conduct of any trade or commerce unlawful and subjects them to action by the Consumer Protection Division under §§ 17.47, 17.58, 17.60, and 17.61. § 17.46(b) then gives a non-exhaustive "laundry list" of covered acts. Two items do the work for AI marketing. Item (b)(5) covers representing that goods or services have sponsorship, approval, characteristics, ingredients, uses, benefits, or quantities which they do not have. Item (b)(7) covers representing that goods or services are of a particular standard, quality, or grade, or that goods are of a particular style or model, if they are of another. A marketed hallucination rate or accuracy benchmark is a representation about the product's characteristics and quality; a rate the company cannot substantiate falls within both items.

Enforcement posture is structural. Under § 17.47, the Consumer Protection Division may bring an action in the name of the State whenever it has reason to believe a person is engaging in, has engaged in, or is about to engage in an unlawful act or practice, and proceedings would be in the public interest. The trier of fact may award a civil penalty to the State of up to $10,000 per violation, plus up to $250,000 more where the act or practice was calculated to acquire or deprive money or other property from a consumer who was 65 or older when it occurred. Health care marketing that reaches older patients should be read with that second tier in mind. § 17.58, the assurance vehicle used in Pieces, lets the Division resolve an investigation through negotiated commitments rather than penalties.

At the federal layer, FTC Act § 5 (15 U.S.C. § 45) independently prohibits unfair or deceptive acts or practices in commerce, and the FTC ran its own AI enforcement sweep (Operation AI Comply) in September 2024. A Texas health AI company answers to both sovereigns on its marketing claims.

The Attorney General's Broader Health AI Posture: Chatbots and Minors

The Pieces settlement is not the office's only AI health move. In August 2025, the Attorney General opened an investigation into Meta AI Studio and Character.AI for potentially engaging in deceptive trade practices by misleadingly marketing AI chatbots as mental health tools. The office alleged the platforms may present themselves as professional therapeutic tools despite lacking proper medical credentials or oversight, impersonate licensed mental health professionals, fabricate qualifications, and claim to provide private counseling, while their terms reveal that interactions are logged, tracked, and used for targeted advertising and algorithmic development. civil investigative demands (CIDs) were issued to determine violations of Texas consumer protection laws, including prohibitions on fraudulent claims, privacy misrepresentations, and concealment of material data use. No filed action or public outcome has been announced.

Separately, in December 2024 the office launched investigations into Character.AI and fourteen other companies, including Reddit, Instagram, and Discord, regarding their privacy and safety practices for minors under the SCOPE Act and the TDPSA. The SCOPE Act prohibits digital service providers from sharing, disclosing, or selling a minor's personal identifying information without a parent's or legal guardian's permission and requires parental tools to manage a child's account privacy settings. The TDPSA imposes strict notice and consent requirements on the collection and use of minors' personal data. The office has stated these protections extend to how minors interact with AI products. A research note with the full timeline and sources is kept in the site's hidden files for the future Insight draft.

Illustrative Example (Hypothetical)

A Dallas health system licenses an AI tool that drafts discharge summaries inside its EHR. The vendor's sales deck advertises a "critical error rate below 0.002 percent." Before deployment, the system should: ask the vendor to define the metric and show the calculation method (the Pieces standard), and if the vendor cannot, treat the claim as unsubstantiated under DTPA § 17.46(b)(5) and (7); confirm the vendor's customer documentation discloses training data, intended purpose, known limitations, and reasonably knowable misuses clearly and conspicuously; determine whether the AI use is "in relation to health care service or treatment" triggering TRAIGA § 552.051(f) disclosure to patients or their representatives no later than first service; confirm HIPAA safeguards for the PHI the tool will process; and, because discharge summaries may go to adolescent patients, check SCOPE and TDPSA duties for any minor-facing use.

What Is Unsettled

How far § 552.051(f)'s "in relation to health care service or treatment" reaches (back-office coding tools versus clinical documentation); whether existing hospital consent forms already satisfy the disclosure duty; and how malpractice and products liability doctrines will treat injuries from AI-assisted clinical decisions.

Questions to Ask

  • If the business markets an AI product's accuracy, can it define each metric and show the calculation method, or point to an independent auditor whose findings substantiate the claim?
  • Do customer materials clearly and conspicuously disclose training data, intended purpose, known limitations, and reasonably knowable misuses?
  • Where AI is used in relation to health care service or treatment, has the AI use been disclosed to the patient or personal representative no later than the first date of service (or as soon as reasonably possible in an emergency)?
  • Is that disclosure clear, conspicuous, plain language, and free of dark patterns?
  • For any tool minors may use: do SCOPE parental-consent and privacy-tool duties and TDPSA minors' notice and consent duties hold?
  • Where the tool processes patient data: do HIPAA administrative, physical, and technical safeguards hold?
  • Are testing and internal review records kept, since they can matter under TRAIGA's defenses?

Sources