Texas TRAIGA & SB 1188: What the New AI Disclosure Rules Mean for Ambient Scribes in Healthcare
Published September 07, 2026
- TRAIGA (HB 149) took effect January 1, 2026 and requires Texas healthcare providers to disclose AI use in care, in plain language, no later than the date of service.
- SB 1188 (effective September 1, 2025) adds physician-review duties for AI diagnostic records and bars offshoring of AI-touched electronic medical records.
- Ambient AI scribes almost certainly trigger disclosure duties — a checkbox buried in an intake bundle is not a substitute for real notice.
- The Sutter Health / MemorialCare / Sharp lawsuits show that a HIPAA BAA does not immunize providers from state wiretap, CMIA, or false-consent-attestation claims.
- On-device AI transcription eliminates the external-transmission element on which most cloud-scribe theories of liability depend.
Quick answer: Yes. Under Texas HB 149 (TRAIGA), effective January 1, 2026, healthcare providers must clearly and conspicuously disclose to patients — in plain language and by the date of service — that an AI system is being used in their care. Companion law SB 1188, effective September 1, 2025, adds physician-review duties and requires that AI-touched electronic medical records be stored inside the United States.
If you run a clinic, hospital, or health system that touches a Texas patient, two new state laws now govern how you deploy artificial intelligence in care — and both apply squarely to the ambient AI scribes drafting your progress notes. House Bill 149, the Texas Responsible Artificial Intelligence Governance Act (TRAIGA), took effect on January 1, 2026 and requires providers to inform patients when AI systems are being used in their treatment, in plain language, no later than the date of service. The companion law, Senate Bill 1188, became effective September 1, 2025 and adds physician-review duties for AI-generated diagnostic records plus a prohibition on offshoring AI-touched electronic medical records.
The stakes are not abstract. The pending Washington v. Sutter Health class action in the Northern District of California — filed April 8, 2026 against Sutter Health and Memorial Healthcare Services — alleges that ambient scribing by Abridge AI recorded patient-provider conversations and transmitted them to external servers without patient consent. That case is a preview of what happens when disclosure is treated as a checkbox rather than a workflow. Texas providers now have a statute that pre-empts the same argument at the front door.
What TRAIGA Actually Requires of Healthcare Providers
TRAIGA is a broad AI governance law — it regulates biometrics, government agencies, prohibited practices like social scoring, and more — but for clinicians the operative section is the healthcare disclosure duty. Covington's Inside Privacy summary explains that TRAIGA requires healthcare providers that use an AI system "in relation to health care service or treatment" to disclose that use to the patient no later than the date of service, or as soon as reasonably possible in an emergency.
The phrase "in relation to" is doing enormous work. It is deliberately wider than diagnosis alone. Ambient scribes that listen to the visit, transcribe it, and draft the note that becomes part of treatment documentation are unambiguously "in relation to" the service. Providers who assume TRAIGA only bites on radiology CAD or predictive-triage tools are reading the statute too narrowly.
The plain-language standard
The disclosure has to be "clear, conspicuous, and in plain language." The Texas Attorney General's consumer AI rights page mirrors that standard for governmental-agency AI interactions and signals how the office will read the same words in the healthcare context. Buried Terms-of-Use language, an easy-to-miss line in a paper intake packet, or an auto-populated consent field in an EHR are all bad answers to "was the disclosure conspicuous?"
SB 1188: The Overlooked Companion Statute
Everyone talks about TRAIGA, but Senate Bill 1188 is arguably the tighter constraint for ambient scribes. It imposes physician-review requirements on AI-generated diagnostic records and prohibits the physical offshoring of electronic medical records. In practical terms, that US-storage rule means an EHR (or the audio and transcripts feeding an EHR) cannot live in a data center outside the United States.
For any vendor pipeline that touches an EU or Asia region for latency, model training, or disaster recovery, SB 1188 is a real problem. And it lands on top of, not instead of, HIPAA — the covered entity is still on the hook for a valid Business Associate Agreement, a Security Risk Analysis that includes the scribe, and breach notification if audio escapes.
Why a HIPAA BAA Is Not Enough
Clinicians and administrators often assume that a signed BAA with an ambient scribe vendor is the end of the analysis. It is not. HIPAA Journal's coverage of the Sutter/MemorialCare complaint spells out the parallel legal exposure: the plaintiffs allege violations of the California Invasion of Privacy Act, the California Confidentiality of Medical Information Act, California Unfair Competition Law, the Federal Wiretap Act, and common-law invasion of privacy — none of which a BAA touches.
The theory of liability is the interception, not the storage. As Alston & Bird's privacy team put it, the focus of the Abridge complaint is on the recording itself, not only on downstream data use. HIPAA authorizes disclosures for treatment, payment, and health care operations; state wiretap statutes and TRAIGA impose separate, additive consent and disclosure obligations that a BAA does not satisfy. If you are new to how these bodies of law layer, our explainer on whether ambient AI scribes are HIPAA compliant walks through the stack in detail.
The Consent-Checkbox Problem
The single most dangerous artifact of a rushed AI scribe rollout is the auto-populated consent line in the EHR. In a July 2026 essay on KevinMD, a physician-reviewer summarized the November 2025 Sharp HealthCare complaint bluntly: a proposed class action accused a hospital system of using an ambient AI scribe across more than 100,000 patient encounters in an all-party-consent state, with notes carrying boilerplate language stating patients had been advised of and had consented to the recording — when they had not.
The consent field returned "yes." The problem was that nobody had actually asked. Under TRAIGA's plain-language standard, an auto-populated attestation with no supporting conversation is almost certainly not "clear and conspicuous" disclosure — and it hands a plaintiff's lawyer written evidence that the concealment was systematic.
Where TRAIGA and SB 1188 Fit in the Broader Compliance Map
Texas is not alone. WilmerHale notes that Texas is the second state to pass comprehensive AI regulation, one month before Colorado's AI Act. But the healthcare-specific disclosure duty is a Texas differentiator. Providers with patients across state lines now have to build a workflow that is defensible under the strictest applicable regime — and TRAIGA plus SB 1188 sets a very concrete floor.
Cross-state HIPAA obligations under the HHS Privacy Rule still apply as background law, and Texas providers with California patients pick up CIPA's all-party consent requirement on top. The compliance question is no longer "is this HIPAA compliant" but "does this survive the highest-friction combination of statutes any patient in the schedule can invoke."
Cloud Ambient Scribes vs. On-Device Transcription Under Texas Law
Here is the architectural picture, mapped against the actual statutory hooks:
| Dimension | Cloud ambient scribe (Abridge / Nuance DAX / Suki / Nabla) | On-device transcription (Basil AI on iPhone / iPad / Mac) |
|---|---|---|
| Audio transmitted outside the exam room | Yes — sent to vendor cloud for ASR and LLM drafting | No — processed on the Apple Neural Engine locally |
| Business Associate Agreement required | Yes — vendor is a BA under 45 CFR 160.103 | No BA relationship; no third-party PHI recipient |
| SB 1188 US-storage rule | Must be verified vendor-by-vendor for every region and subprocessor | Satisfied by architecture — data never leaves the device |
| TRAIGA disclosure duty | Applies — plus explain external processing | Applies — but disclosure is simpler ("used on my device") |
| CIPA / Federal Wiretap Act exposure | High — third-party interception is the core theory | No third-party interception; no factual hook |
| Model-training risk | Depends on vendor ToS and opt-outs | None — no data leaves for training |
| Data deletion | Subject to vendor retention schedule | Deleted immediately by the clinician |
Choosing a cloud scribe does not eliminate any of these obligations — it multiplies them, because each row becomes a due-diligence item, a BAA clause, and a subprocessor to inspect. Choosing an on-device architecture collapses several rows to "not applicable."
How Basil AI Solves This
Basil AI is a fully on-device meeting and encounter transcription app for iPhone, iPad, and Mac. Audio is captured, transcribed, diarized, and summarized locally, using Apple's on-device Speech framework and the Apple Neural Engine. Nothing is transmitted to Basil's servers because Basil does not run servers that receive your audio. That architecture maps directly onto Apple's own privacy commitments around keeping personal information on the device.
For a Texas provider evaluating the January 1, 2026 TRAIGA disclosure duty, three things change:
- SB 1188's US-storage rule is satisfied by architecture. Data that never leaves an iPhone in Dallas cannot be stored outside the United States.
- The interception element in Sutter-style cases has no factual hook. There is no third-party server capturing the audio, so CIPA, CMIA, and Federal Wiretap Act theories have nothing to attach to.
- TRAIGA disclosure becomes a simpler conversation. "I'm going to use an AI transcription tool on my device to help me take notes. It stays on this device." That is a plain-language, clear, conspicuous disclosure that a patient can consent to or decline in the moment.
Basil is not "HIPAA certified" — HIPAA has no certification. What Basil does is remove the architectural conditions that create HIPAA, CMIA, wiretap, and TRAIGA-storage exposure in the first place. Compliance judgments remain the covered entity's responsibility; the deployment choice determines how hard those judgments are. For deeper background, our analysis of the Sharp, Sutter, and MemorialCare ambient scribe lawsuits and the Abridge follow-up walk through why an on-device architecture removes the interception element entirely.
A Practitioner's Checklist for TRAIGA and SB 1188
- Inventory every AI system that touches a patient encounter — ambient scribes, coding assistants, decision-support tools, patient-portal chatbots.
- Verify each vendor's data-residency posture against SB 1188's US-storage rule. Ask specifically about disaster-recovery regions and subprocessor locations, not just primary production.
- Rewrite your patient intake script so the AI-use disclosure is spoken in plain language before or at the date of service — not buried in a Terms-of-Use bundle.
- Audit any auto-populated "patient was advised" language in your EHR templates. If it fires without a corresponding scripted conversation, remove it.
- Update your Security Risk Analysis under the HIPAA Security Rule to include each ambient-scribe data flow, from microphone to EHR to backup.
- Review the applicable BAA against consumer-grade vendor terms like Otter's to spot broad content-use grants that would be unacceptable in a healthcare deployment.
- Document a fallback for patients who decline AI use — a non-AI workflow that produces the same clinical documentation, so consent is meaningful.
- Train front-desk and clinical staff on how to deliver and document the TRAIGA disclosure, and log training completion as part of your evidence package.
- For multi-state operations, map your Texas TRAIGA workflow against California CIPA/CMIA and Illinois BIPA to ensure the tightest regime is your default.
What to Watch Next
The Texas Attorney General has exclusive TRAIGA enforcement authority, so the first enforcement action — whenever it comes — will be a strong signal. Watch for it in a healthcare context, because AI scribes are the highest-volume, most patient-facing AI deployment in the state. Watch also for a healthcare-specific class action modeled on the Washington v. Sutter Health pattern but pled under Texas invasion-of-privacy tort theories, since TRAIGA itself does not provide a private right of action.
Providers who assume that the current, quiet enforcement environment will hold are making the same bet the defendants in the Otter, Sharp, and Sutter cases made. The pattern in those complaints is clear: the plaintiffs' bar reads the vendor's own marketing copy back to the jury. Anything a scribe vendor says in a sales deck about "invisible," "passive," or "automatic" is a future exhibit. Choose an architecture that makes those exhibits unnecessary.
Try Basil AI — Private, On-Device Transcription
100% on-device transcription for iPhone, iPad, and Mac. Nothing leaves the device. Nothing trains a model. Nothing to breach.
Frequently Asked Questions
When does Texas TRAIGA's healthcare AI disclosure requirement take effect?
TRAIGA (House Bill 149) took effect on January 1, 2026. It requires healthcare providers that use an AI system in relation to a health care service or treatment to disclose that use to patients or their personal representatives no later than the date of service, or as soon as reasonably possible in an emergency. The companion Senate Bill 1188 took effect earlier, on September 1, 2025.
Does an ambient AI scribe count as an 'AI system' under TRAIGA?
Almost certainly yes. TRAIGA's disclosure trigger reaches AI used 'in relation to' a health care service or treatment, which is broader than diagnosis alone. Ambient scribes like Abridge, Nuance DAX, Suki, and Nabla listen to the visit, transcribe it, and draft clinical notes that feed the EHR — direct participation in the treatment workflow. Providers should assume the disclosure duty applies and document it patient-by-patient.
Is a consent checkbox in the patient portal enough to satisfy TRAIGA?
Probably not, and it may create additional exposure. TRAIGA requires disclosures to be clear, conspicuous, and in plain language, and the pending Sutter/MemorialCare ambient-scribe litigation alleges that auto-inserted 'patient was advised and consented' language in charts — with no actual conversation — is itself deceptive. A generic checkbox buried in an intake bundle is unlikely to satisfy either the statute or California's parallel wiretap regime.
How does SB 1188 differ from TRAIGA, and do both apply to AI scribes?
SB 1188 (effective September 1, 2025) imposes physician-review requirements on AI-generated diagnostic records, adds disclosure duties for diagnostic AI, and prohibits storing AI-touched electronic medical records outside the United States. TRAIGA (effective January 1, 2026) is broader — covering treatment as well as diagnosis and reaching non-diagnostic AI. Ambient scribes typically implicate both statutes because they touch treatment documentation and produce records that live in the EHR.
Who enforces TRAIGA and what are the penalties?
Enforcement authority sits exclusively with the Texas Attorney General; TRAIGA does not create a private right of action. That said, penalties are steep and layered: TRAIGA carries civil penalties per violation, and the AG can seek injunctive relief. The absence of a private right of action does not immunize providers from parallel claims under CIPA-style wiretap statutes in other states, invasion-of-privacy tort theories, or HIPAA enforcement by HHS OCR.
How does on-device AI transcription change the TRAIGA and SB 1188 analysis?
On-device processing eliminates the external transmission that most cloud-scribe risk theories depend on. SB 1188's US-storage rule becomes trivially satisfied when audio and transcripts never leave the clinician's iPhone, iPad, or Mac. TRAIGA's disclosure duty still applies — you must still tell the patient — but you remove the business-associate chain, the vendor training-data exposure, and the third-party wiretap element that made Washington v. Sutter Health possible.