Intelligence Terminal
Six converged feeds on the forces reshaping healthcare AI: threats, regulation, workforce, crisis, biosecurity, and the global movement to own the stack. Every data point is evidence, not marketing.
AI Governance & Frameworks
Nine frameworks define what “responsible AI in healthcare” legally means. The pattern across all of them: inventory, oversight, logging, and control. Sovereign architecture doesn't chase these requirements — it embodies them.
PHIPA
Personal Health Information Protection Act — governs collection, use, and disclosure of personal health information by health information custodians.
- Custodians remain accountable for PHI handled by agents and vendors — including AI tools
- Consent and purpose limits apply to AI processing of PHI
- Breach notification to the IPC and affected individuals
HIPAA
Privacy, Security, and Breach Notification Rules for Protected Health Information held by covered entities and business associates.
- Business Associate Agreements for every AI vendor touching ePHI
- Security Rule risk analysis must include AI systems
- Minimum-necessary standard applies to AI training and inference data
PIPEDA
Federal private-sector privacy law: consent, purpose limitation, safeguards, and openness for personal information in commercial activity.
- Meaningful consent for AI processing of personal information
- Accountability follows the data across borders — including to US cloud AI
- Safeguards proportional to data sensitivity (health data = highest)
Bill 194 / O. Reg. 51/26
Strengthening Cyber Security and Building Trust in the Public Sector Act — cyber-security programs and AI accountability for Ontario public-sector entities, with O. Reg. 51/26 obligations for prescribed hospitals in force July 2026.
- Documented cyber-security program with mandated maturity assessments
- AI use disclosure, risk management, and human oversight for public-sector AI
- Incident reporting on prescribed timelines
NIST AI RMF 1.0
Risk-management framework for trustworthy AI: GOVERN, MAP, MEASURE, MANAGE functions with a Generative AI profile (2024).
- AI inventory and risk mapping across the clinical portfolio
- Measurable trustworthiness characteristics (validity, privacy, transparency)
- Continuous monitoring and incident processes for deployed models
ISO/IEC 42001
The first certifiable AI Management System standard (2023) — the ISO 27001 of AI governance.
- AI policy, roles, and lifecycle controls under a managed system
- Impact assessments for high-consequence uses like clinical AI
- Continuous improvement with internal audit
EU AI Act
The world's first comprehensive AI law. Medical-device AI and safety-component AI are high-risk; GPAI obligations began August 2025, with high-risk obligations phasing in through 2026–2027.
- High-risk classification for most clinical AI: risk management, data governance, logging
- Human oversight and transparency for deployed systems
- Post-market monitoring and serious-incident reporting
Bill C-27 / AIDA
The Artificial Intelligence and Data Act died on the order paper when Parliament prorogued in January 2025. Federal AI regulation is expected to return; provinces are moving first.
- Would have imposed duties on 'high-impact' AI systems, including health
- Signals the direction of future federal obligations
- Interim: OSFI B-13, provincial laws, and the federal AI Strategy carry the weight
WHO Guidance: Ethics & Governance of AI for Health
WHO's guidance (2021, LMM addendum 2024) — six principles: autonomy, well-being, transparency, accountability, equity, and sustainable AI.
- Human autonomy: clinicians stay in control of decisions
- Transparency and explainability appropriate to clinical context
- Accountability mechanisms for AI-influenced care
Regulatory Timeline
- 1996HIPAA enacted
US health privacy baseline; Security Rule follows in 2003.
- 2000PIPEDA in force
Canada's federal private-sector privacy law.
- 2004PHIPA in force
Ontario's health-information custodian regime.
- 2021WHO AI-for-health guidance
Six ethical principles for health AI.
- 2023NIST AI RMF 1.0 + ISO/IEC 42001
The two dominant voluntary AI governance frameworks land.
- 2024EU AI Act adopted; Ontario Bill 194 passes
High-risk regime for clinical AI; Ontario mandates public-sector cyber programs.
- 2025AIDA dies with prorogation; EU GPAI duties begin
Canadian federal AI law resets while EU obligations start phasing in.
- 2026O. Reg. 51/26 in force (July)
Prescribed Ontario hospitals face binding cyber-security obligations. EU high-risk phase-in continues.
- 2027EU AI Act full application
High-risk medical AI must be fully compliant.
Latest Regulatory Signals
PRIORITYREGULATIONEU AI Act: August 2026 marks the high-risk general application milestone
The Act's main obligations for high-risk systems now apply, with embedded-in-regulated-products timelines running to 2027. Healthcare deployers in or serving the EU face logging, oversight, and monitoring duties.
ROUTINESTANDARDISO/IEC 42001 certification becomes a procurement checkbox
Health-system RFPs increasingly ask AI vendors for 42001 alignment or certification — the standard is doing to AI what 27001 did to security. Snapshot as of this refresh.
ROUTINEGUIDANCEOntario health sector guidance converges: IPC + Ontario Health AI positions
Ontario's IPC and provincial health bodies continue aligning guidance on AI scribes and clinical AI: custodian accountability, vendor due diligence, and no PHI to unvetted cloud tools. Snapshot as of this refresh.
FLASHREGULATIONO. Reg. 51/26 now in force: binding cyber obligations for prescribed Ontario hospitals
As of July 2026, prescribed hospitals must operate a documented cyber-security program, run maturity assessments, and report incidents on prescribed timelines. AI systems in clinical workflows fall squarely inside scope.
ROUTINEREGULATIONUS states fill the federal gap: Colorado AI Act takes effect June 2026
Colorado's algorithmic-discrimination law reaches deployers of high-risk AI, including healthcare decisions; a patchwork of state AI and privacy laws now governs US health AI in practice.
PRIORITYREGULATIONAIDA dies on the order paper as Parliament prorogues
Canada's federal AI law (Bill C-27) lapsed in January 2025, leaving a federal vacuum. Provinces — led by Ontario's Bill 194 — and sector regulators now set the pace for Canadian health AI.
PRIORITYREGULATIONHHS proposes first major HIPAA Security Rule overhaul in 20 years
The NPRM would make encryption, MFA, asset inventories, and network segmentation explicitly mandatory — removing 'addressable' outs. Driven directly by the healthcare ransomware epidemic.
ROUTINEGUIDANCEWHO issues governance guidance for large multimodal models in health
The LMM addendum sets out 40+ recommendations for governments and deployers, emphasizing that clinical LMMs need documented oversight, evaluation, and post-deployment monitoring.
ROUTINEREGULATIONOSFI B-13 sets the Canadian tone for technology-risk governance
Though aimed at federally regulated financial institutions, B-13's model-risk and third-party expectations are the template Canadian health regulators reference for AI oversight.
ROUTINEREGULATIONQuebec Law 25 fully in force: ADM transparency and privacy-by-default
Quebec's modernized privacy law requires disclosure of automated decision-making and data-portability rights — the strictest general privacy regime in North America and a preview of where health AI consent is heading.