Skip to main content
Healthcare AI Governance

Clinical AI governance software built for hospitals and health systems

Risk Meridian helps healthcare providers meet TRAIGA's one affirmative duty — disclosing to patients when AI is used in their care (§ 552.051(f)) — and build the defensible governance record that preserves your reasonable-care presumption if the Texas Attorney General ever asks. Inventorying your clinical AI and running patient-harm risk assessments are recommended for safe-harbor readiness — not required by TRAIGA. All in one HIPAA-aware platform that needs no PHI.

TRAIGA ReadyHIPAA-aware (no PHI)Encrypted · SSO · TOTP MFA · RBAC · Tamper-evident audit logEU AI Act (roadmap)NIST AI RMF Safe Harbor

Jan 1, 2026

TRAIGA in effect across Texas

Texas HB 149, as enacted

Sept 1, 2025

SB 1188 healthcare AI rules in effect

Texas SB 1188 (89th Legislature)

$10K–$200K

TRAIGA civil penalty range

Enforced by the Texas Attorney General

60-day

cure period before AG enforcement; no private right of action

TRAIGA enforcement provisions

Which clinical AI systems carry the most governance risk?

Some clinical AI carries more legal and patient-safety risk than others. Here are the categories Texas healthcare providers should govern most closely — and why each matters under TRAIGA, SB 1188, and FDA guidance.

Critical Risk

Clinical decision support systems

AI that assists physicians with diagnosis, treatment selection, medication dosing, or discharge planning sits at the center of patient safety. When AI is used in a patient's treatment, TRAIGA's § 552.051(f) healthcare provision requires the provider to disclose that use, and SB 1188 (§ 183.005) requires the treating practitioner to review AI-created records consistent with Texas Medical Board standards and to disclose diagnostic AI use to patients. Documented risk reviews and human oversight are how you show that use is responsible and defensible.

Critical Risk

Prior authorization and utilization management

Health plans using AI to approve or deny care face real exposure — including TRAIGA's prohibition on using AI to intentionally and unlawfully discriminate against a protected class. Documenting the system, testing for bias across demographic groups, and keeping clear member communications are how you reduce that risk.

High Risk

Patient scheduling and triage algorithms

AI that prioritizes which patients receive care — ED triage support, appointment scheduling, call-routing — directly affects patient access. Where it informs treatment or healthcare-service decisions, provider disclosure duties can apply, and a documented governance record helps you show the system is used fairly.

High Risk

Revenue cycle and billing AI

AI-driven coding, billing optimization, and fraud detection can carry regulatory risk when they influence patients' financial outcomes. TRAIGA doesn't require you to inventory back-office AI, but keeping these systems in your governance record helps you spot bias and demonstrate responsible use.

High Risk

Vendor-supplied AI embedded in EHR platforms

AI embedded in Epic, Cerner, Oracle Health, and other EHR platforms is easy for compliance teams to overlook. Because your providers are the ones using these tools with patients, the disclosure and record-review duties under TRAIGA and SB 1188 fall on your organization — not the vendor.

Moderate Risk

Predictive analytics and population health tools

Population health platforms that stratify patient risk, identify care gaps, or predict readmissions can shape who gets outreach and resources. Tracking these systems, checking them for bias, and documenting oversight keeps your use of them defensible.

Not sure if a specific AI system is covered? Read the TRAIGA compliance guide →

Everything a health system needs to govern clinical AI

Eight integrated capabilities purpose-built for the healthcare AI governance workflow — from initial inventory to ongoing board reporting.

Recommended

Clinical AI System Inventory

Centralized registry for every AI system across your health system — from EHR-embedded tools to third-party clinical decision support. Capture the vendor, model, clinical context, patient population, and deployment setting. Recommended for defensibility and safe-harbor readiness — TRAIGA doesn't mandate an AI inventory.

Recommended

Patient-Harm Risk Scoring

Healthcare-specific risk weighting that accounts for patient harm potential, clinical AI context, affected patient populations, and human-in-the-loop oversight mechanisms. Produces a calibrated Risk Meridian risk class (low, moderate, or high) to help you prioritize oversight and align with FDA guidance. A best practice for prioritizing oversight, not a TRAIGA mandate.

Core

Patient Disclosure Generator

One-click drafts of the patient-facing AI-use notices that Texas healthcare providers must give under TRAIGA's § 552.051(f) healthcare disclosure duty and SB 1188 — the one affirmative duty TRAIGA puts on providers. Auto-populated from your AI system inventory, saving weeks of manual drafting.

Clinical Control Framework

Auto-generated control recommendations for each clinical AI system based on its risk class. Covers human oversight checkpoints, explainability requirements, model monitoring, and bias testing — all trackable within the platform.

Core

Board Governance Report Pack

Board-ready AI governance report packs generated in seconds. Includes executive summary, system inventory summary, risk heat map, control status, and open incident log — designed to support hospital boards' growing oversight role in AI governance.

Clinical AI Incident Management

Structured workflow for logging, triaging, investigating, and resolving AI-related clinical incidents. Links incidents to AI system records, controls, and risk reviews for full traceability across the patient safety chain.

Multi-Framework Mapping

Organize clinical AI controls once and reuse that documentation across frameworks — TRAIGA and NIST AI RMF mapping today, with the EU AI Act, ISO 42001, and FDA AI/ML guidance on the roadmap.

Continuous Monitoring

Schedule periodic risk re-assessments, track model performance drift, and maintain a living governance record as clinical AI systems are updated, replaced, or decommissioned. AI governance isn't a one-time exercise — your governance record should stay current as systems change.

The clinical AI governance workflow

Risk Meridian guides your clinical informatics, compliance, and legal teams through a structured workflow that produces documentation supporting a defensible TRAIGA governance record.

1

Disclose AI use to patients (§ 552.051(f))

TRAIGA's one affirmative duty for a healthcare provider is telling a patient — or their representative — when AI is used in their care, no later than the date service or treatment is first provided (in an emergency, as soon as reasonably possible). Risk Meridian drafts these patient AI-use notices in one click.

Tip: SB 1188 adds related patient-notice and record-review rules where applicable — Risk Meridian tracks both.

2

Inventory your clinical AI — recommended, not required

TRAIGA doesn't mandate an AI inventory, but cataloging the tools deployed across your organization — including EHR-embedded AI from Epic, Cerner, and Oracle Health — is the fastest way to be safe-harbor ready. Capture clinical context, patient population, vendor details, and deployment setting.

Tip: Risk Meridian provides a vendor questionnaire template to collect governance documentation from your AI suppliers.

3

Run patient-harm risk assessments — recommended for defensibility

Risk Meridian's healthcare-specific risk engine scores each clinical AI system on patient harm likelihood, clinical impact severity, affected population vulnerability (pediatric, elderly, underserved), reversibility, and human oversight adequacy. This is best practice for prioritizing oversight, not a TRAIGA requirement.

Tip: Risk Meridian automatically generates a risk class — low, moderate, high, or critical — to help you prioritize oversight and align with FDA guidance.

4

Keep the record that preserves your reasonable-care presumption

TRAIGA presumes you used reasonable care (§ 552.105(c)). If the Attorney General issues a civil investigative demand (§ 552.103), a maintained governance record answers it and helps you qualify for the affirmative defense (§ 552.105(e)). Risk Meridian generates the board AI governance report packs and audit trail that make up that file — you don't have to inventory, but you'll want the file if the AG calls.

Tip: Board reports include the executive summary, risk heat map, and control status that help hospital governing boards carry out their oversight role.

The regulatory landscape for healthcare AI

Healthcare AI governance sits at the intersection of multiple regulatory frameworks. Risk Meridian helps you organize your controls with these frameworks in mind.

Texas Responsible AI Governance Act (TRAIGA)

Supported today

Scope

Texas healthcare providers and organizations using clinical AI

Key Requirements

  • § 552.051(f): providers must disclose AI use in a patient's care — the one affirmative duty
  • Prohibits specific harmful uses (e.g. intentional, unlawful discrimination); no inventory mandate
  • Rebuttable presumption of reasonable care (§ 552.105(c)); affirmative defense (§ 552.105(e))
  • Enforced solely by the Texas Attorney General — 60-day cure, no private right of action
  • SB 1188 (H&S Code ch. 183, § 183.005): diagnostic-AI patient disclosure + practitioner review of AI-created records per Texas Medical Board standards; U.S. EHR storage (§ 183.002)
  • Documentation is optional best practice that answers an AG demand (§ 552.103)

FDA AI/ML-Based SaMD Action Plan

Monitoring

Scope

AI/ML software that meets the definition of a medical device

Key Requirements

  • Predetermined change control plan (PCCP)
  • Real-world performance monitoring
  • Transparency and labeling requirements
  • Algorithm change protocols

EU AI Act

On roadmap

Scope

High-risk AI in healthcare — diagnostic, treatment, monitoring

Key Requirements

  • Conformity assessment
  • Technical documentation
  • Human oversight mechanisms
  • Post-market surveillance
  • EU database registration

NIST AI RMF

Supported today

Scope

Voluntary framework broadly adopted in healthcare

Key Requirements

  • Govern, Map, Measure, Manage functions
  • Trustworthy AI characteristics
  • Organizational accountability
  • AI risk measurement

Healthcare AI governance — frequently asked questions

Common questions from compliance officers, clinical informatics teams, and hospital legal counsel evaluating AI governance software.

Does TRAIGA apply to hospitals and health systems?
Yes — TRAIGA applies to organizations operating in Texas (effective January 1, 2026). But for a healthcare provider the one affirmative duty it adds is the § 552.051(f) patient disclosure: telling a patient (or their representative) when AI is used in their care, no later than the date service or treatment is first provided (in an emergency, as soon as reasonably possible). Beyond that, TRAIGA is intent-based — it prohibits specific harmful uses, including intentional, unlawful discrimination against a protected class — and it is enforced solely by the Texas Attorney General, after a 60-day cure period, with no private right of action. There is no AI-inventory or registration requirement for private deployers; inventorying and risk-scoring your systems are best practices for defensibility, not TRAIGA mandates. Texas SB 1188 adds related provider duties (see below).
Which clinical AI systems should we govern most closely?
TRAIGA doesn't require you to document or register your AI systems, but the systems closest to patient care carry the most risk: clinical decision support, prior authorization AI, triage and scheduling tools, predictive readmission models, and population health stratification. When a provider uses AI in a patient's treatment, TRAIGA's § 552.051(f) disclosure duty and SB 1188's § 183.005 record-review and patient-disclosure rules apply — and because your providers are the ones using EHR-embedded tools from Epic or Cerner with patients, those duties fall on your organization, not the vendor. A governance record is the practical way to meet them and stay defensible.
What patient disclosures does TRAIGA require for healthcare AI?
This is a real duty. TRAIGA's § 552.051(f) healthcare provision requires healthcare providers to disclose to a patient (or their representative) when AI is used in the patient's treatment or healthcare services — no later than the date service or treatment is first provided and, in an emergency, as soon as reasonably possible. Texas SB 1188 (Health & Safety Code ch. 183, effective September 1, 2025) adds a separate AI duty under § 183.005: a practitioner who uses AI for diagnostic purposes must act within their license scope regardless of the AI, review all AI-created records consistent with medical-records standards set by the Texas Medical Board, and disclose that AI use to patients (§ 183.005(b)). It also requires patient-information EHRs to be stored in the U.S. or a U.S. territory (§ 183.002), and is enforced by the Attorney General with civil penalties up to $5,000 (negligent), $25,000 (knowing or intentional), or $250,000 (PHI used for financial gain), plus possible license suspension or revocation after repeat violations (§§ 183.010–183.011). Risk Meridian helps you draft the patient AI-use notices and keep the review and oversight records these duties call for.
If we don't have to inventory our AI, why keep a governance record?
Because TRAIGA starts on your side, and documentation is how you keep it there. The law presumes you used reasonable care (§ 552.105(c)). If the Attorney General opens an investigation, a civil investigative demand can require a description of your AI system's purpose, the data it uses, its outputs, its known limitations, and your oversight process (§ 552.103). A maintained governance record preserves that reasonable-care presumption, answers the demand directly, and helps you qualify for the affirmative defense (§ 552.105(e)) — which recognizes substantial compliance with the NIST AI RMF and discovery of issues through red-team testing. You don't have to inventory — but you'll want the file if the AG calls.
Is a hospital district treated as a TRAIGA governmental entity?
No. TRAIGA expressly excludes a hospital district from its definition of governmental entity (Bus. & Com. Code § 552.001(3)), so TRAIGA's governmental-entity-only prohibitions — such as social scoring (§ 552.053) and biometric identification (§ 552.054) — do not bind a hospital district under TRAIGA. A hospital district is still a healthcare provider, so the § 552.051(f) patient disclosure duty and SB 1188's record-review and patient-notice rules apply to it, and SB 1964 may reach it on its own terms — confirm that with counsel. A private practice faces the same § 552.051(f) disclosure duty and the general prohibitions, plus the optional best-practice safe-harbor work, with SB 1188 where relevant.
How does Risk Meridian handle vendor-supplied AI in EHR systems?
Risk Meridian's position is that the organization deploying AI — not the vendor — is closest to the patient and carries the disclosure and oversight duties, whether the AI was built in-house or procured from Epic, Oracle Health, or a third-party clinical AI company. Risk Meridian gives you a vendor questionnaire and procurement checklist to collect governance documentation (model cards, validation, bias testing) from your suppliers, so you can document oversight and generate the patient disclosures the law requires.
What does a hospital board AI governance report include?
Risk Meridian's board AI governance report pack includes an executive summary of your AI governance program, a complete inventory of clinical AI systems with their Risk Meridian risk class, a control implementation status summary, an open incident log, and a governance maturity score. It is designed to give hospital boards the evidence to support their oversight discussions as AI-governance expectations continue to develop.
How long does it take to complete a hospital's initial AI inventory?
Most hospitals complete their initial AI system inventory within one to three weeks, depending on the number of systems and the responsiveness of internal stakeholders. Risk Meridian provides a structured intake form, a vendor questionnaire template, and automated reminders to keep the process moving. Many organizations inventory their first ten systems on day one.
How does Risk Meridian handle HIPAA and PHI?
Risk Meridian stores governance metadata about your AI systems — vendors, use-cases, risk scores, controls — not patient records, so no PHI is required to use the platform; that keeps it HIPAA-aware by design. Where a workflow could involve PHI, we can offer a Business Associate Agreement (BAA). Risk Meridian's infrastructure runs on AWS with encryption at rest and in transit, role-based access controls, and audit logging.
Can Risk Meridian handle multi-site health systems with dozens of AI systems?
Yes. Risk Meridian is a fully multi-tenant SaaS platform designed to scale from a single-hospital operator to a large integrated delivery network. Role-based access allows compliance officers, clinical informatics teams, legal counsel, and board members to have appropriately scoped access. You can organize AI systems by facility, service line, or business unit and generate consolidated governance reports across your entire system.

Start governing your clinical AI systems today

Hospitals and health systems using Risk Meridian get their first AI system inventoried in under 10 minutes. Start now — no implementation project, no waiting.

HIPAA-aware — no patient data required

TRAIGA disclosures generated in one click

Board governance reports ready in minutes