Practice Academy: Practice Management Track - Register Now
Commentary|Videos|October 1, 2026

How AI vendor contracts can leave medical practices holding the liability

Fact checked by: Keith A. Reynolds

An artificial intelligence vendor contract may cap what the company owes the practice, but health care attorney Tatiana Melnik, J.D., says the people using the tools are the bigger risk.


Health care attorney Tatiana Melnik, J.D., gives practice administrators the same first assignment whether they are buying a new artificial intelligence (AI) tool or already running one: pull the vendor contracts and find out what the practice has consented to.

Melnik, of Melnik Legal PLLC in Tampa, Florida, represents physician practices. She presented "Privacy and Security Legal Issues in the Age of Artificial Intelligence" on Sept. 28 at the Medical Group Management Association (MGMA) 2026 Annual Conference in San Antonio and sat down with Physicians Practice at the conference. When an AI tool used for scheduling, prior authorizations or visit notes can access protected health information, the Health Insurance Portability and Accountability Act (HIPAA) applies to it as it would to any other technology, she said.

Contract terms to reread

Allowing a vendor to de-identify patient data may have been a low-risk choice before AI. Today, Melnik said, a practice might decide it's high risk "because re-identification is so easy."

She advised administrators to look closely at how a contract defines "usage data," normally the clicks a vendor tracks to troubleshoot its product, and to ask whether AI prompts now fall under it. The same goes for "confidential information," any right to keep data after termination and the vendor's obligation, and ability, to delete it.

If a vendor can't delete the data, Melnik said, the next stop is the indemnity and damages cap language. Many contracts limit the vendor's liability to 12 months of fees paid before an incident. "Well, if the incident arises three years after the contract because you've allowed them to keep your data post termination, then the damages cap is zero," she said. That leaves the practice, as the HIPAA covered entity, holding the liability.

A weekly training habit

Asked for one step an administrator could take right away, Melnik said, "Train your team. Spend the money necessary to actually train your staff." She suggested weekly five-minute sessions on best practices, weekly reminders on existing policies and ongoing training beyond that.

"The biggest risk in a lot of these technologies is the people using them," she said. "It's uncomfortable. It takes time. No one wants to do it. People don't remember, and that's why you've got to do it anyway."

A consent process for AI scribes

Patients in California have brought consumer class actions against practices and hospital systems over AI scribes they say they never agreed to, according to Melnik. She expects malpractice carriers to start denying coverage in some AI-related cases, such as one in which a physician didn't review notes an AI scribe drafted.

Her advice is to get patients' affirmative consent and decide ahead of time what happens when a patient refuses. The practice can turn the tool off for that patient, or it can make the technology a condition of care, as some practices did with electronic records. Either way, she would put the AI disclosures in the existing notice of privacy practices, a document HIPAA already requires.


Physicians Practice was in San Antonio at the MGMA Annual Conference, Sept. 27-30, celebrating 100 years of MGMA, attending sessions and speaking with industry leaders. Follow our coverage on our MGMA conference page.


Related to this article