Clinical AI governance software built for hospitals and health systems
Risk Meridian helps healthcare providers meet TRAIGA's one affirmative duty — disclosing to patients when AI is used in their care (§ 552.051(f)) — and build the defensible governance record that preserves your reasonable-care presumption if the Texas Attorney General ever asks. Inventorying your clinical AI and running patient-harm risk assessments are recommended for safe-harbor readiness — not required by TRAIGA. All in one HIPAA-aware platform that needs no PHI.
Jan 1, 2026
TRAIGA in effect across Texas
Texas HB 149, as enacted
Sept 1, 2025
SB 1188 healthcare AI rules in effect
Texas SB 1188 (89th Legislature)
$10K–$200K
TRAIGA civil penalty range
Enforced by the Texas Attorney General
60-day
cure period before AG enforcement; no private right of action
TRAIGA enforcement provisions
Which clinical AI systems carry the most governance risk?
Some clinical AI carries more legal and patient-safety risk than others. Here are the categories Texas healthcare providers should govern most closely — and why each matters under TRAIGA, SB 1188, and FDA guidance.
Clinical decision support systems
AI that assists physicians with diagnosis, treatment selection, medication dosing, or discharge planning sits at the center of patient safety. When AI is used in a patient's treatment, TRAIGA's § 552.051(f) healthcare provision requires the provider to disclose that use, and SB 1188 (§ 183.005) requires the treating practitioner to review AI-created records consistent with Texas Medical Board standards and to disclose diagnostic AI use to patients. Documented risk reviews and human oversight are how you show that use is responsible and defensible.
Prior authorization and utilization management
Health plans using AI to approve or deny care face real exposure — including TRAIGA's prohibition on using AI to intentionally and unlawfully discriminate against a protected class. Documenting the system, testing for bias across demographic groups, and keeping clear member communications are how you reduce that risk.
Patient scheduling and triage algorithms
AI that prioritizes which patients receive care — ED triage support, appointment scheduling, call-routing — directly affects patient access. Where it informs treatment or healthcare-service decisions, provider disclosure duties can apply, and a documented governance record helps you show the system is used fairly.
Revenue cycle and billing AI
AI-driven coding, billing optimization, and fraud detection can carry regulatory risk when they influence patients' financial outcomes. TRAIGA doesn't require you to inventory back-office AI, but keeping these systems in your governance record helps you spot bias and demonstrate responsible use.
Vendor-supplied AI embedded in EHR platforms
AI embedded in Epic, Cerner, Oracle Health, and other EHR platforms is easy for compliance teams to overlook. Because your providers are the ones using these tools with patients, the disclosure and record-review duties under TRAIGA and SB 1188 fall on your organization — not the vendor.
Predictive analytics and population health tools
Population health platforms that stratify patient risk, identify care gaps, or predict readmissions can shape who gets outreach and resources. Tracking these systems, checking them for bias, and documenting oversight keeps your use of them defensible.
Not sure if a specific AI system is covered? Read the TRAIGA compliance guide →
Everything a health system needs to govern clinical AI
Eight integrated capabilities purpose-built for the healthcare AI governance workflow — from initial inventory to ongoing board reporting.
Clinical AI System Inventory
Centralized registry for every AI system across your health system — from EHR-embedded tools to third-party clinical decision support. Capture the vendor, model, clinical context, patient population, and deployment setting. Recommended for defensibility and safe-harbor readiness — TRAIGA doesn't mandate an AI inventory.
Patient-Harm Risk Scoring
Healthcare-specific risk weighting that accounts for patient harm potential, clinical AI context, affected patient populations, and human-in-the-loop oversight mechanisms. Produces a calibrated Risk Meridian risk class (low, moderate, or high) to help you prioritize oversight and align with FDA guidance. A best practice for prioritizing oversight, not a TRAIGA mandate.
Patient Disclosure Generator
One-click drafts of the patient-facing AI-use notices that Texas healthcare providers must give under TRAIGA's § 552.051(f) healthcare disclosure duty and SB 1188 — the one affirmative duty TRAIGA puts on providers. Auto-populated from your AI system inventory, saving weeks of manual drafting.
Clinical Control Framework
Auto-generated control recommendations for each clinical AI system based on its risk class. Covers human oversight checkpoints, explainability requirements, model monitoring, and bias testing — all trackable within the platform.
Board Governance Report Pack
Board-ready AI governance report packs generated in seconds. Includes executive summary, system inventory summary, risk heat map, control status, and open incident log — designed to support hospital boards' growing oversight role in AI governance.
Clinical AI Incident Management
Structured workflow for logging, triaging, investigating, and resolving AI-related clinical incidents. Links incidents to AI system records, controls, and risk reviews for full traceability across the patient safety chain.
Multi-Framework Mapping
Organize clinical AI controls once and reuse that documentation across frameworks — TRAIGA and NIST AI RMF mapping today, with the EU AI Act, ISO 42001, and FDA AI/ML guidance on the roadmap.
Continuous Monitoring
Schedule periodic risk re-assessments, track model performance drift, and maintain a living governance record as clinical AI systems are updated, replaced, or decommissioned. AI governance isn't a one-time exercise — your governance record should stay current as systems change.
The clinical AI governance workflow
Risk Meridian guides your clinical informatics, compliance, and legal teams through a structured workflow that produces documentation supporting a defensible TRAIGA governance record.
Disclose AI use to patients (§ 552.051(f))
TRAIGA's one affirmative duty for a healthcare provider is telling a patient — or their representative — when AI is used in their care, no later than the date service or treatment is first provided (in an emergency, as soon as reasonably possible). Risk Meridian drafts these patient AI-use notices in one click.
Tip: SB 1188 adds related patient-notice and record-review rules where applicable — Risk Meridian tracks both.
Inventory your clinical AI — recommended, not required
TRAIGA doesn't mandate an AI inventory, but cataloging the tools deployed across your organization — including EHR-embedded AI from Epic, Cerner, and Oracle Health — is the fastest way to be safe-harbor ready. Capture clinical context, patient population, vendor details, and deployment setting.
Tip: Risk Meridian provides a vendor questionnaire template to collect governance documentation from your AI suppliers.
Run patient-harm risk assessments — recommended for defensibility
Risk Meridian's healthcare-specific risk engine scores each clinical AI system on patient harm likelihood, clinical impact severity, affected population vulnerability (pediatric, elderly, underserved), reversibility, and human oversight adequacy. This is best practice for prioritizing oversight, not a TRAIGA requirement.
Tip: Risk Meridian automatically generates a risk class — low, moderate, high, or critical — to help you prioritize oversight and align with FDA guidance.
Keep the record that preserves your reasonable-care presumption
TRAIGA presumes you used reasonable care (§ 552.105(c)). If the Attorney General issues a civil investigative demand (§ 552.103), a maintained governance record answers it and helps you qualify for the affirmative defense (§ 552.105(e)). Risk Meridian generates the board AI governance report packs and audit trail that make up that file — you don't have to inventory, but you'll want the file if the AG calls.
Tip: Board reports include the executive summary, risk heat map, and control status that help hospital governing boards carry out their oversight role.
The regulatory landscape for healthcare AI
Healthcare AI governance sits at the intersection of multiple regulatory frameworks. Risk Meridian helps you organize your controls with these frameworks in mind.
Texas Responsible AI Governance Act (TRAIGA)
Supported todayScope
Texas healthcare providers and organizations using clinical AI
Key Requirements
- § 552.051(f): providers must disclose AI use in a patient's care — the one affirmative duty
- Prohibits specific harmful uses (e.g. intentional, unlawful discrimination); no inventory mandate
- Rebuttable presumption of reasonable care (§ 552.105(c)); affirmative defense (§ 552.105(e))
- Enforced solely by the Texas Attorney General — 60-day cure, no private right of action
- SB 1188 (H&S Code ch. 183, § 183.005): diagnostic-AI patient disclosure + practitioner review of AI-created records per Texas Medical Board standards; U.S. EHR storage (§ 183.002)
- Documentation is optional best practice that answers an AG demand (§ 552.103)
FDA AI/ML-Based SaMD Action Plan
MonitoringScope
AI/ML software that meets the definition of a medical device
Key Requirements
- Predetermined change control plan (PCCP)
- Real-world performance monitoring
- Transparency and labeling requirements
- Algorithm change protocols
EU AI Act
On roadmapScope
High-risk AI in healthcare — diagnostic, treatment, monitoring
Key Requirements
- Conformity assessment
- Technical documentation
- Human oversight mechanisms
- Post-market surveillance
- EU database registration
NIST AI RMF
Supported todayScope
Voluntary framework broadly adopted in healthcare
Key Requirements
- Govern, Map, Measure, Manage functions
- Trustworthy AI characteristics
- Organizational accountability
- AI risk measurement
Healthcare AI governance — frequently asked questions
Common questions from compliance officers, clinical informatics teams, and hospital legal counsel evaluating AI governance software.
- Does TRAIGA apply to hospitals and health systems?
- Yes — TRAIGA applies to organizations operating in Texas (effective January 1, 2026). But for a healthcare provider the one affirmative duty it adds is the § 552.051(f) patient disclosure: telling a patient (or their representative) when AI is used in their care, no later than the date service or treatment is first provided (in an emergency, as soon as reasonably possible). Beyond that, TRAIGA is intent-based — it prohibits specific harmful uses, including intentional, unlawful discrimination against a protected class — and it is enforced solely by the Texas Attorney General, after a 60-day cure period, with no private right of action. There is no AI-inventory or registration requirement for private deployers; inventorying and risk-scoring your systems are best practices for defensibility, not TRAIGA mandates. Texas SB 1188 adds related provider duties (see below).
- Which clinical AI systems should we govern most closely?
- TRAIGA doesn't require you to document or register your AI systems, but the systems closest to patient care carry the most risk: clinical decision support, prior authorization AI, triage and scheduling tools, predictive readmission models, and population health stratification. When a provider uses AI in a patient's treatment, TRAIGA's § 552.051(f) disclosure duty and SB 1188's § 183.005 record-review and patient-disclosure rules apply — and because your providers are the ones using EHR-embedded tools from Epic or Cerner with patients, those duties fall on your organization, not the vendor. A governance record is the practical way to meet them and stay defensible.
- What patient disclosures does TRAIGA require for healthcare AI?
- This is a real duty. TRAIGA's § 552.051(f) healthcare provision requires healthcare providers to disclose to a patient (or their representative) when AI is used in the patient's treatment or healthcare services — no later than the date service or treatment is first provided and, in an emergency, as soon as reasonably possible. Texas SB 1188 (Health & Safety Code ch. 183, effective September 1, 2025) adds a separate AI duty under § 183.005: a practitioner who uses AI for diagnostic purposes must act within their license scope regardless of the AI, review all AI-created records consistent with medical-records standards set by the Texas Medical Board, and disclose that AI use to patients (§ 183.005(b)). It also requires patient-information EHRs to be stored in the U.S. or a U.S. territory (§ 183.002), and is enforced by the Attorney General with civil penalties up to $5,000 (negligent), $25,000 (knowing or intentional), or $250,000 (PHI used for financial gain), plus possible license suspension or revocation after repeat violations (§§ 183.010–183.011). Risk Meridian helps you draft the patient AI-use notices and keep the review and oversight records these duties call for.
- If we don't have to inventory our AI, why keep a governance record?
- Because TRAIGA starts on your side, and documentation is how you keep it there. The law presumes you used reasonable care (§ 552.105(c)). If the Attorney General opens an investigation, a civil investigative demand can require a description of your AI system's purpose, the data it uses, its outputs, its known limitations, and your oversight process (§ 552.103). A maintained governance record preserves that reasonable-care presumption, answers the demand directly, and helps you qualify for the affirmative defense (§ 552.105(e)) — which recognizes substantial compliance with the NIST AI RMF and discovery of issues through red-team testing. You don't have to inventory — but you'll want the file if the AG calls.
- Is a hospital district treated as a TRAIGA governmental entity?
- No. TRAIGA expressly excludes a hospital district from its definition of governmental entity (Bus. & Com. Code § 552.001(3)), so TRAIGA's governmental-entity-only prohibitions — such as social scoring (§ 552.053) and biometric identification (§ 552.054) — do not bind a hospital district under TRAIGA. A hospital district is still a healthcare provider, so the § 552.051(f) patient disclosure duty and SB 1188's record-review and patient-notice rules apply to it, and SB 1964 may reach it on its own terms — confirm that with counsel. A private practice faces the same § 552.051(f) disclosure duty and the general prohibitions, plus the optional best-practice safe-harbor work, with SB 1188 where relevant.
- How does Risk Meridian handle vendor-supplied AI in EHR systems?
- Risk Meridian's position is that the organization deploying AI — not the vendor — is closest to the patient and carries the disclosure and oversight duties, whether the AI was built in-house or procured from Epic, Oracle Health, or a third-party clinical AI company. Risk Meridian gives you a vendor questionnaire and procurement checklist to collect governance documentation (model cards, validation, bias testing) from your suppliers, so you can document oversight and generate the patient disclosures the law requires.
- What does a hospital board AI governance report include?
- Risk Meridian's board AI governance report pack includes an executive summary of your AI governance program, a complete inventory of clinical AI systems with their Risk Meridian risk class, a control implementation status summary, an open incident log, and a governance maturity score. It is designed to give hospital boards the evidence to support their oversight discussions as AI-governance expectations continue to develop.
- How long does it take to complete a hospital's initial AI inventory?
- Most hospitals complete their initial AI system inventory within one to three weeks, depending on the number of systems and the responsiveness of internal stakeholders. Risk Meridian provides a structured intake form, a vendor questionnaire template, and automated reminders to keep the process moving. Many organizations inventory their first ten systems on day one.
- How does Risk Meridian handle HIPAA and PHI?
- Risk Meridian stores governance metadata about your AI systems — vendors, use-cases, risk scores, controls — not patient records, so no PHI is required to use the platform; that keeps it HIPAA-aware by design. Where a workflow could involve PHI, we can offer a Business Associate Agreement (BAA). Risk Meridian's infrastructure runs on AWS with encryption at rest and in transit, role-based access controls, and audit logging.
- Can Risk Meridian handle multi-site health systems with dozens of AI systems?
- Yes. Risk Meridian is a fully multi-tenant SaaS platform designed to scale from a single-hospital operator to a large integrated delivery network. Role-based access allows compliance officers, clinical informatics teams, legal counsel, and board members to have appropriately scoped access. You can organize AI systems by facility, service line, or business unit and generate consolidated governance reports across your entire system.
Start governing your clinical AI systems today
Hospitals and health systems using Risk Meridian get their first AI system inventoried in under 10 minutes. Start now — no implementation project, no waiting.
HIPAA-aware — no patient data required
TRAIGA disclosures generated in one click
Board governance reports ready in minutes