Generative AI did not create new legal obligations for local public health. It shortened the time it takes to breach the ones you already have — and three sets of rules apply at once.
.png)
An ethics conversation that assumes AI use has not started yet is a conversation about the wrong agency. Yours is already regulated, with or without an internal AI policy.
Nothing about generative AI created a new legal regime for local public health. It changed the speed at which you can cross the lines that already existed. Three sets of rules apply at the same time, and one set of working habits satisfies all three.

No BAA, no PHI. Entering protected health information into a tool your agency has no Business Associate Agreement with is an unauthorized disclosure, and it is reportable. Free and consumer AI accounts structurally cannot offer one: no signed agreement, no compliant audit trail, and inputs that may be retained or used to improve the service.
"De-identified" is a technical claim, not a description of effort. Removing names and Social Security numbers does not de-identify a record. Age, ZIP code, a specific condition, and an event date can combine to point at exactly one resident, and the smaller the jurisdiction the faster that happens. A working rule: if your county would fit inside a high school gymnasium, treat row-level data as identifiable and aggregate to counts before analysis.
Substance use records need their own lane. 42 CFR Part 2 protects substance use disorder treatment records above the standard HIPAA baseline, and the current rule text has been in force with a compliance date of February 16, 2026. SUD treatment records, syringe service records, and clinic notes do not belong in general-purpose AI tools at all, including tools you have otherwise approved.
Across jurisdictions, state archivists and counsel have reached the same conclusion. AI prompts and outputs created in the course of public business are records of that business.
Three consequences follow:
You cannot outsource liability to the tool. In Moffatt v. Air Canada, 2024 BCCRT 149, the airline argued that its chatbot was, in effect, a separate legal entity responsible for its own statements. The tribunal rejected that outright, finding the chatbot was simply part of the company's website and that the company was responsible for the information on it — including the inaccurate information that the customer had reasonably relied on. The organization operating the tool owns what the tool says.
Public-facing advice is where the exposure concentrates. A chatbot that gives residents confident, wrong guidance about a local ordinance or an eligibility rule creates both administrative liability and the kind of public failure that is difficult to walk back.
Proxy variables carry bias into resource decisions. The clearest documented case in health care is Obermeyer et al., published in Science in 2019. A widely used algorithm ranked patients for extra care using historical health care spending as a stand-in for health need. Because less money had historically been spent on Black patients at the same level of illness, the model read them as healthier. Correcting the proxy raised the share of Black patients flagged for additional help from 17.7% to 46.5%.
The lesson generalizes past that one model. If your prioritization logic uses spending, prior utilization, or service contact history as a proxy for need, it will reproduce whatever inequity is already in your service history — and present it as an objective score.
And there is now an explicit rule on this. Under Section 1557 of the Affordable Care Act, HHS finalized 45 CFR § 92.210, which prohibits discrimination through "patient care decision support tools" and requires covered entities to make reasonable efforts to identify such tools in use and mitigate the risk of discrimination from them. The definition is deliberately broad: automated or non-automated, from a flowchart to a machine learning model. If your agency receives federal financial assistance, this is a live obligation, not a future one. Confirm current applicability with your counsel, since enforcement guidance in this area continues to move.
Before any AI workflow goes live, five lines hold:
Notice what these have in common. None of them requires a new committee, a procurement cycle, or a technology decision. They are habits, and habits are cheaper than remediation.
Knowing the rules is not the same as running an agency inside them. You still need to decide which uses require review, who holds sign-off, and how you demonstrate any of it to a board of health that asks.
The next post lays out how to do that in 90 days, with the staff you already have.
Darwin's Policy Wizard is a free place to start: answer a few questions and generate an AI use policy tailored to your agency and the frameworks you follow.