The Statutory Landscape for Clinical AI in Colorado
Colorado's regulatory posture on healthcare AI has shifted more than once in a compressed window, and ambulatory groups deserve a precise account rather than a marketing gloss. SB 24-205, the original "Consumer Protections for Artificial Intelligence," established duties for developers and deployers of high-risk AI systems used in consequential decisions, including decisions affecting access to or eligibility for healthcare. It was scheduled to take effect February 1, 2026, and it imposed a genuine documentation burden on practices that used algorithms in clinical or coverage workflows.
As originally drafted, the statute required deployers—that is, the ambulatory or specialty practices operating the AI—to maintain a risk-management program to prevent algorithmic discrimination, complete impact assessments before deployment and at least annually, and provide consumer notices when an AI system materially informed a consequential decision. The impact assessment had to describe the system's purpose, the categories of input and output data, performance metrics, known limitations, and post-deployment monitoring safeguards. Peer-reviewed analysis of EHR auditability frameworks reinforces why this provenance discipline matters clinically (see https://www.ncbi.nlm.nih.gov/pmc/).
Then the framework changed materially. Colorado repealed and reenacted the AI Act through SB 26-189, signed May 14, 2026, with an effective date of January 1, 2027. The replacement law drops the duty-of-care standard, eliminates mandatory risk-management programs, removes the annual impact-assessment requirement, and refocuses the surviving obligations on consumer notice and transparency. It also introduces a broad exemption for HIPAA-covered clinical AI use by providers operating from a Colorado location, with the notable carve-out that employment-related AI decisions remain in scope.
The Anchor Truth and the Current Reality
Any honest compliance page must acknowledge that the widely circulated summary of SB 24-205—annual algorithmic impact assessments, robust discrimination controls, three-year record retention—describes the original design rather than the controlling baseline you operate under today. The intellectual content of that framework has not become worthless; it has become voluntary for most HIPAA-covered clinical deployments. We treat it as a defensible best-practice template because it maps cleanly to what malpractice defense, payer audits, and future federal guidance will still expect of a prudent practice.
Healthcare-Specific Rules That Survive the Repeal
HB 26-1139, governing the use of artificial intelligence in health care, operates independently of the general AI Act and did not disappear with SB 24-205's repeal. It addresses AI in health benefit coverage determinations and requires that such determinations be based on the patient's medical and clinical history, individual circumstances, and specified clinical factors. Critically, any denial must be reviewed by a licensed clinician or other competent regulated professional before it is finalized.
For a specialty group that performs prior authorization, utilization review, or medical-necessity assessment with any algorithmic assistance, this statute creates an affirmative duty rather than an exemption. The documentation must support how AI factored into the determination, what patient-specific clinical data was considered, and which clinician attested to the review. This is where a documentation-assistant workflow and a coverage-review workflow diverge, and where practices most often misjudge their exposure by assuming the HIPAA exemption resolves everything.
Mapping Every Use Case Against Both Statutes
The operationally safe rule is straightforward: enumerate every AI use case in the practice and test each one against SB 26-189's surviving notice duties and HB 26-1139's coverage-review duties separately. A scribe drafting a progress note generally triggers neither the denial-review mechanics nor the employment carve-out. A tool that scores medical necessity, however, sits squarely inside HB 26-1139. Validate the prompt libraries and note templates driving each configuration against these clinical-factor requirements using the Scribing Template Directory before any deployment reaches a live patient encounter.
Documentation Workflows That Withstand Audit
Even with SB 26-189 narrowing the statutory surface, ambulatory and specialty practices still need structured documentation to satisfy HB 26-1139, general HIPAA and medical-record standards, and payer contract terms. The most durable approach borrows the SB 24-205 impact-assessment structure and applies it as internal governance, because that structure was engineered specifically to make algorithmic behavior traceable and defensible.
At the system level, each clinical AI tool should carry a registry entry recording its purpose, deployment context, and clinical rationale, followed by a data-lineage record describing the categories of PHI processed as inputs and the categories of output generated. Because Merry AI does not persist raw PHI, the registry stores model version identifiers, deployed prompt templates by use case, and active safety policies rather than patient content. That distinction satisfies the impact-assessment requirement to describe data categories without warehousing the data itself.
At the patient level, every encounter where AI contributes to documentation or decision support should carry a brief note annotation, the clinician's independent rationale, and a captured attestation. The attestation records clinician identity and credentials, a review timestamp, and confirmation language such as "I have reviewed this AI-assisted summary and it accurately reflects my clinical assessment." Stored as queryable metadata in the EHR, these records become the primary evidence of the human-in-the-loop oversight that HB 26-1139 demands.
Comparing the Three Charting Architectures
The practical difference between charting approaches is easiest to see when the compliance controls are placed side by side. Manual charting carries no algorithmic risk but also no efficiency gain and inconsistent provenance. Generic AI scribes deliver speed while frequently retaining transcripts and omitting structured attestation. The compliance-oriented architecture retains the speed while engineering the controls that Colorado's healthcare rules assume.
| Compliance Dimension | Manual Charting | Generic AI Scribe | Merry AI Compliance Architecture |
|---|---|---|---|
| PHI retention at AI layer | None | Frequently stored transcripts | Zero retention; RAM session shredding |
| Human attestation trail | Implicit in signature | Rarely enforced | Mandatory sign-off with credentials and timestamp |
| Configuration provenance | Not applicable | Opaque model versioning | Versioned registry linked by request ID |
| HB 26-1139 review evidence | Manual, unstructured | Absent | Queryable clinician-review metadata |
| Impact-assessment readiness | Labor-intensive | No supporting artifacts | Registry and metadata prepopulate assessment fields |
Reading across that table clarifies why the zero-retention plus local-provenance pattern is the design that reconciles SB 26-189's exemption with HB 26-1139's affirmative duty. You minimize breach exposure at the AI layer while preserving, inside your own controlled EHR environment, the metadata needed to reconstruct which configuration produced any given output.
Software Setup and the Annual Assessment as Policy
Configuring Merry AI for this environment turns on three technical commitments. First, enforce zero data retention so requests process transiently and only non-identifying metadata is logged, and confirm the business associate agreement reflects that behavior. Second, maintain a configuration registry that records model versions, deployed prompts, and safety settings, linked to encounter logs by request identifier so provenance survives even without stored PHI. Third, require mandatory clinician review before any output enters the record or drives a consequential decision.
Although SB 26-189 no longer compels an annual impact assessment for most HIPAA-covered clinical AI, we recommend retaining one as internal policy. Scope it to every tool influencing documentation, decision support, triage, scheduling, or coverage. Time it annually and after any substantial modification, mirroring the original SB 24-205 cadence. Populate its fields—purpose, discrimination risk, data categories, performance metrics, transparency measures, and governance decisions—directly from the audit trails and configuration registry, and align its complexity-capture documentation with CPT G2211 continuity requirements.
When you are ready to test this against your own service lines, the fastest path is a structured review of your current templates and attestation flows. Book a 15-Minute Workflow Audit and we will map each AI use case against SB 26-189, HB 26-1139, and the surviving best-practice elements of SB 24-205, then hand you a remediation checklist grounded in the statutory text rather than in speculation.


