Pew surveyed 3,488 US adults in late June, at a point when 85% of Epic's health system customers were already running AI tools that draft replies to patient messages.

 

What happened

About 72% of US adults say it is extremely or very important that a doctor or other provider tells them when AI is being used in their healthcare, according to Pew Research Center, which surveyed 3,488 adults between June 22 and June 28, 2026. Support held across age, gender, education, and racial and ethnic groups. Eight in ten or more wanted disclosure specifically where AI touches care decisions, covering analysis of medical scans, diagnosis, and explanation of lab results. Demand extended to administrative uses as well, with 72% wanting to know when AI takes notes during an appointment, 64% when it orders prescription refills, and 56% when it schedules visits, Healthcare Dive reported. Adoption is already widespread in patient communication specifically, with Epic reporting that 85% of its health system customers use generative AI tools that include AI-drafted replies to patient portal messages, according to research published in JAMA Network Open examining how patients perceive those messages.

 

Going deeper

Nearly half of respondents were unsure whether AI had already been used in their own care. On control, 53% said they have not too much or no say over whether a provider uses AI, against 33% who felt they had at least some say. White adults were more likely than Hispanic, Black, or Asian adults to report having little to no say. Americans were three times as likely to want more input on AI use in their healthcare as to say they were comfortable with the amount of input they currently have. Message volume has risen sharply enough to become a recognized driver of clinician burnout, and health systems have turned to language models to draft replies that a clinician then reviews before sending, according to the same research. Interviews with 40 patients found nearly all wanted disclosure in plain language, with preferences differing on when and how it should appear. The gap between adoption and awareness is wide, since 71% of non-federal acute care hospitals reported using predictive AI in 2024, and an American Medical Association survey this year found 72% of responding physicians had incorporated at least one AI application into practice.

 

What was said

"Knowing what tools providers are deploying, especially new tools like AI, is really important. And then patients can make sure that they're comfortable with those choices," said Andrew Crawford, senior counsel of data and privacy at the Center for Democracy and Technology, speaking to GovInfoSecurity. Crawford noted that patient information entered into systems such as an AI scribe or a diagnostic tool falls under the HIPAA Privacy Rule, while adding that patients need to understand those protections and trust that their data will not be used for advertising or sold to data brokers.

 

In the know

Research from the Coalition for Health AI found that concerns centre less on whether AI is present and more on who is accountable when it is used, how decisions are monitored, and what protections exist, in a patient survey report examining transparency specifically. Respondents expressed greater alarm about commercialization and sale of health data than about algorithmic bias, with 12% saying they had never considered AI bias at all. Insurance applications remained substantially less trusted than clinical ones even when clinician review was introduced, holding at around 28%. The report concluded that transparency about AI use is broadly expected while disclosure by itself falls short of building trust.

 

The big picture

Researchers synthesizing patient concerns about AI in healthcare identified privacy, data security, and the opacity of automated decision-making as recurring themes across the qualitative literature, in work published in the Journal of Medical Internet Research. For compliance teams, the practical consequence sits in the notice of privacy practices and in what patients are told at the point of care. Nothing in HIPAA currently requires a provider to disclose that an AI tool processed a patient's information, though state legislation is moving on this and several bills would impose disclosure duties directly. Organizations deploying ambient documentation, diagnostic support, or message drafting should establish now what they would tell a patient who asks, who inside the organization knows which tools are running, and whether the business associate agreements covering those vendors address secondary use of the data. Patient messages carry protected health information into whatever system drafts the reply, which makes the vendor holding that tool a business associate and the contract governing it a data security question rather than a clinical one.

 

FAQs

Does HIPAA cover data entered into an AI scribe?

Yes, where the vendor is acting as a business associate of the covered entity. The agreement governs what the vendor may do with the information, and secondary uses such as model training generally require explicit contractual permission rather than being assumed.

 

Are providers legally required to disclose AI use to patients?

No federal requirement exists at present. Several states have moved or are moving on disclosure and opt-out provisions, and professional bodies have issued ethical guidance, which means obligations vary by jurisdiction and by the specific application.

 

What is predictive AI in a hospital setting?

Software that estimates the likelihood of an outcome from patient data, covering sepsis risk scoring, readmission prediction, deterioration alerts, and no-show forecasting for scheduling. It differs from generative tools that produce text or summaries, and the two often sit under the same internal governance process.

 

How would a patient find out which AI tools their provider uses?

There is usually no straightforward route. Notices of privacy practices rarely name specific technologies, and front-line staff may not know which systems incorporate AI. Asking the practice directly is the available option, and the answer depends on whether anyone internally has compiled that list.

 

What should a covered entity document about AI deployments?

Which tools are in use, what data each processes, whether the vendor is a business associate, what the agreement permits regarding retention and secondary use, and how the tool is monitored after deployment. That record is what makes a patient question answerable and what a regulator would ask for.