The Number One Health Technology Hazard of 2026 Is a Chatbot.

Every January, the patient safety organization ECRI publishes its ranking of the most dangerous technology hazards in healthcare. It has done this since 2008, built on incident investigations, reporting databases, and independent device testing. The 2026 list includes unpreparedness for a sudden loss of electronic systems, syringe misconnections, falsified medical products, and cybersecurity risks from legacy devices.

None of them took the top spot. The number one health technology hazard of 2026 is the misuse of AI chatbots.

ECRI's testing found the tools have suggested incorrect diagnoses, recommended unnecessary testing, promoted subpar medical supplies, and invented body parts. Not misread body parts. Invented them. And these are not fringe tools: more than 40 million people ask ChatGPT health questions every day, by OpenAI's own count, and none of these chatbots are regulated as medical devices or validated for clinical use.

The data behind the ranking is blunt. An April 2026 audit published in BMJ Open tested five popular chatbots against 250 health questions: 49.6% of the responses were problematic, and 19.6% were highly problematic. Roughly a coin flip on accuracy, delivered in the confident tone of a thoughtful clinician.

The laws have already arrived.

While the safety data piled up, state legislatures moved. If your practice touches patients in California or Texas, these are already in force, and the pattern is spreading state by state.

California AB 3030, effective January 1, 2025, covers health facilities, clinics, and physician's offices. If generative AI produces a written or verbal communication containing a patient's clinical information, that communication must carry a disclaimer that it was AI-generated, plus instructions for reaching a human provider. For licensed facilities, violations can draw civil penalties of up to $25,000 per violation. For physicians, enforcement runs through the Medical Board.

California AB 489, signed in October 2025 and effective January 1, 2026, prohibits AI systems from using terms, credentials, or design elements that imply the AI holds a healthcare license. If the chatbot on your site sounds like a clinician, that is now a licensing-board matter.

Texas SB 1188, effective September 1, 2025, permits practitioners to use AI in diagnosis and treatment only if the practitioner discloses the AI use to patients and reviews all AI-generated records before a clinical decision is made. The Texas Attorney General can seek civil penalties of $5,000 to $250,000 per violation, and violations can also bring disciplinary action up to license suspension or revocation.

Texas HB 149, the state's broader AI act effective January 1, 2026, adds Attorney General enforcement with penalties of $10,000 to $200,000 per violation, and its AI disclosure requirement applies to private providers of healthcare services.

Illinois has banned AI from independently providing psychotherapy. Colorado's AI act arrives in 2027. The direction is uniform: disclose the AI, and put a licensed human in front of it.

Read the exemption. It is the whole story.

Buried in AB 3030 is the sentence that matters most to a small practice. The disclaimer requirements do not apply if the communication was read and reviewed by a human licensed or certified healthcare provider before it went out.

Texas says the same thing from the other direction: AI use is permitted when the practitioner reviews the output first.

Regulators in the two largest states independently arrived at the identical rule. AI that generates and ships in one automated step is a labeled hazard. AI whose output a licensed human approved before anyone saw it is compliant practice. The law does not care how good the model is. It cares whether a human stood between the generation and the patient.

Now look at what is actually on practice websites.

Medical, dental, and therapy practices are adding AI chat widgets for the same reason every other small business is: after-hours questions, missed calls, front-desk overload. Nearly all of these tools work the same way. When a visitor asks a question, the system retrieves some content and a language model generates a fresh answer on the spot, live, unsupervised, every time.

That means every answer is a new roll of the same dice ECRI just ranked above cyberattacks. Picture what patients type into a practice website at 11pm. Is this medication safe while breastfeeding? Do these symptoms mean I should go to the ER? Does my insurance cover this procedure? What should I do after my extraction?

A generative widget will answer all of those, fluently, whether or not the answer is true. And under the new laws, a wrong or undisclosed AI answer about clinical information is no longer just embarrassing. In California it is a disclosure violation with per-violation penalties. In Texas it can be a $250,000 problem. Everywhere, it is a plaintiff's exhibit and a board complaint waiting for a patient who relied on it.

No practice would let an unlicensed stranger answer patient questions at the front desk. A generative chatbot is exactly that, at scale, in writing.

What a practice actually needs.

The regulators already wrote the specification. Not a smarter model: a checkpoint. A system where a licensed human reviews and approves every answer before any patient can see it, where answers come only from the practice's own vetted materials, where the system declines instead of guessing when it has no approved answer, and where there is a record proving who approved what and when.

Truebe is a WordPress plugin built on Gated Truth Architecture. The gate comes before publication, not after. You upload your documents: post-op instructions, insurance and billing policies, service descriptions, patient FAQs, etc. Truebe drafts question-and-answer pairs from them, and you or your clinical staff review each one: edit it, approve it, or reject it. Nothing goes live without sign-off. When a patient asks a question, Truebe does not call an AI to compose an answer. It matches the question against your approved library and returns the answer you already vetted, word for word.

Nothing is generated at question time, so there is no moment at which the system can invent anything. If a question falls outside the library, Truebe suggests related approved answers and logs the question in a daily gap report, so the library grows around what your patients actually ask. Every answer traces to its source, and every approval is recorded with who approved it and when.

That approval log is the compliance artifact the new laws keep asking for. When the standard is human review before the patient sees it, the difference between claiming review and proving review is a record. Truebe produces the record automatically.

It runs on your server with your own API key. Your documents are processed at upload; Truebe is never in the data path and never stores your patient-facing content. For a practice living under HIPAA, your data never leaving your control is not a feature. It is the requirement.

It also works inward. The same system runs a private staff chat over the documents you upload: clinical protocols, office policies, payer rules, procedure checklists. Staff get answers drawn only from those documents, with the source cited and the exact passage shown. No open-web guessing reaching your front desk, and no invented answer reaching a patient through a staff member who trusted a chatbot.

The bottom line.

The country's leading patient-safety organization just ranked AI chatbots above cyberattacks as the top technology hazard in healthcare. Two of the largest states responded with the same rule: a licensed human must review AI output before it reaches a patient. Every generative chatbot on the market fails that rule by design, because generation and delivery happen in one automated step.

Truebe was built as that rule. No unapproved answer ever reaches a patient.

Try the demo

ECRI. "Misuse of AI chatbots tops annual list of health technology hazards." January 2026. home.ecri.org.

MedTech Dive. "ECRI names misuse of AI chatbots as top health tech hazard for 2026." January 22, 2026. medtechdive.com.

BMJ Group. "Substantial amount of medical information provided by popular chatbots inaccurate and incomplete." April 2026. On: "Generative artificial intelligence-driven chatbots and medical misinformation: an accuracy, referencing and readability audit." BMJ Open, doi 10.1136/bmjopen-2025-112695. bmjgroup.com.

Fenwick. "The New Regulatory Reality for AI in Healthcare: How Certain States Are Reshaping Compliance." fenwick.com.

Chambers Healthcare AI Practice Guide, California: AB 3030 enforcement and penalties. practiceguides.chambers.com.

Covington, Inside Privacy. "California Enacts Health AI Bill": AB 3030's human-review exemption. insideprivacy.com.

Texas Medical Association. "New Law Requires Texas Physicians to Disclose AI": SB 1188 requirements. October 2025. texmed.org.

Hendershot Cowart. "New Texas AI Healthcare Laws: SB 1188 & HB 149 Compliance Guide." February 2026. hchlawyers.com.

Akerman. "New Year, New AI Rules: Healthcare AI Laws Now in Effect." January 2026. akerman.com.