A solo occupational therapist with a caseload of post-stroke adults and a speech-language pathologist seeing three-year-olds on the autism spectrum are not worrying about the same AI question as a dental practice weighing a chatbot. Their question is narrower and harder: what happens when the patient in the room cannot fully understand what an AI tool is doing with their data, or cannot reliably tell you if something is wrong. That is a safeguarding question, not a productivity one, and almost nothing written about "AI in healthcare" this year has addressed it directly for OT and SLT caseloads specifically.
The psychology side of this site already covered the safeguarding gap in CQC's UK guidance (see CQC names five regulations for AI, safeguarding isn't one). Pediatric, post-stroke, and cognitively impaired caseloads raise a different set of questions, under US federal and state rules rather than UK ones. Below are the six questions OT and SLT practice owners are actually asking, answered with primary sources rather than assumption.
1. Do I have to tell patients or their guardians that I'm using AI in their sessions?
For occupational therapists, yes, and it's specific. AOTA's Policy E.19, "Ethical Use of Artificial Intelligence," effective April 2025, states that when AI tools are used during recorded sessions for transcription, documentation, or data analysis, individuals involved must be informed in advance of the recording, the intended use of AI, the nature and scope of data collection, and any potential storage or dissemination of information, with informed consent obtained (American Occupational Therapy Association, Policy E.19, effective April 2025). That's an association ethics policy, not a federal law, but it is the standard a licensing board or malpractice attorney would hold an OT to.
For speech-language pathologists, the obligation is broader but less specific. ASHA's Code of Ethics, Principle II, gives certified professionals an ethical responsibility to consider and evaluate any technology used in their work, and ASHA has confirmed there is limited legislative or regulatory oversight of generative AI in the profession so far (American Speech-Language-Hearing Association, "Generative Artificial Intelligence for Clinicians," 2026). ASHA has not published an AI-specific consent standard the way AOTA has.
So what for you: write a one-paragraph AI disclosure now and use it at every intake, even though no regulator is currently checking for one.
2. Does a patient's cognitive impairment, for example after a stroke, change how I get consent for AI tools?
Yes, procedurally. Research protocols involving cognitively impaired patients already require a formal capacity assessment before consent is accepted at face value, and where capacity is reduced, a surrogate or legally authorized representative provides consent instead (University of California San Francisco Human Research Protection Program, guidance on enrolling individuals with cognitive impairments, 2026). Clinical AI use isn't research, but the underlying logic transfers directly: if a patient cannot understand what an AI scribe or a progress-tracking tool does with their data, the disclosure has to reach whoever holds legal decision-making authority for them, not just be read aloud to the patient and checked off.
So what for you: build a capacity flag into intake for post-stroke, traumatic brain injury, and any other cognitively affected caseload, and route AI consent to a guardian or healthcare proxy when that flag is raised, before turning on any AI note-taking tool.
3. If I use an AI note-taking tool, does that change my legal duty to report suspected abuse or neglect?
No, and this is where a lot of practice owners overthink the AI angle. Mandated-reporter status comes from state statute and attaches to you as a licensed clinician, not to whatever software you use to write your notes. Occupational therapists and speech-language pathologists are named mandated reporters for child abuse and neglect, and separately for abuse of at-risk or vulnerable adults, in states including Connecticut, Arizona, Oregon, and Colorado (Connecticut Department of Public Health; Arizona Revised Statutes §46-454; Oregon Judicial Department; Colorado Department of Human Services, mandatory reporting guidance, 2026). That duty exists whether your notes are typed, dictated, or summarized by an AI scribe.
What does change: an AI-generated summary of a session becomes part of your clinical record. If the tool paraphrases something you said, or misses something a patient disclosed, that paraphrase is what a later reviewer sees, not your memory of the session.
So what for you: read every AI-generated note before signing it, and correct anything that could misrepresent a safeguarding-relevant detail. Treat the AI output as a draft you're accountable for, not a report you can point to as the source of a decision.
4. Is there a HIPAA rule specifically covering AI tools used with vulnerable patients?
Not yet, and not soon. HHS's Office for Civil Rights proposed updates to the HIPAA Security Rule on January 6, 2025, that would require covered entities to maintain an inventory of AI tools that interact with protected health information, fold AI vendor risk into Business Associate Agreement reviews, and run vulnerability scans at least every six months plus penetration testing at least annually (HHS.gov, HIPAA Security Rule NPRM factsheet, 2025). The public comment period closed March 7, 2025, and HHS received more than 4,000 comments. OCR had targeted a final rule for May 2026; that date passed with nothing published, and the federal government's own regulatory tracker (OMB Unified Agenda, RIN 0945-AA22) now lists July 2027 as the target, pushed back from an earlier spring 2026 estimate.
That delay does not mean AI tools are currently unregulated under HIPAA. The existing Security Rule risk-analysis requirement, in force since 2005, already obligates you to assess any technology, AI included, that touches patient data. The 2027 rule would make that obligation more specific and add AI-specific documentation requirements. It would not create the underlying duty from nothing.
So what for you: don't wait for 2027 to do a risk analysis on your AI vendor. The obligation to do one already exists, and a signed Business Associate Agreement with any AI vendor handling patient data should already be in your files.
5. Do pediatric patients need a different consent process from adults with cognitive impairment?
Yes, procedurally, even though the underlying principle is the same: whoever has legal authority to decide needs to actually understand what the AI tool does. For a pediatric caseload, that's a parent or legal guardian, and most state consent frameworks already expect a distinct signature for anything beyond standard treatment. For an adult with stroke-related cognitive impairment, capacity can be partial, fluctuating, or genuinely contested, which is a harder clinical judgment call, and one worth documenting with the same rigor a research protocol applies rather than treating as a formality.
So what for you: keep the pediatric and adult-cognitive-impairment consent pathways as two separate, clearly documented processes rather than one shared form covering both.
6. What should a solo OT or SLT practice actually do about AI and safeguarding this year, without a compliance budget?
Four steps cover most of the real exposure, and none of them need a lawyer on retainer. Write a one-page AI disclosure for intake and use it with every patient or guardian before any AI tool is switched on. Flag any patient without full decision-making capacity, pediatric or otherwise, and route their AI consent to whoever holds legal authority for them. Review every AI-generated note before signing it. And get a signed Business Associate Agreement from any AI vendor handling patient data now, since that's already a current HIPAA requirement, not something waiting on the 2027 rule.
So what for you: this is an afternoon of paperwork, not a compliance program. Doing it now costs a fraction of what an unaddressed safeguarding gap costs later.
If you want a second opinion on where your practice's AI safeguarding gaps actually are, before a licensing complaint or vendor contract forces the question, book a free 20-minute call. We'll work through your caseload mix and current AI tools against what AOTA, ASHA, and HHS actually require today, not what's still proposed.
The bottom line
No federal rule specifically governs AI use with vulnerable patients in OT or SLT practice as of July 2026, and the one that's coming is now targeted for 2027, two years after it was first proposed. That gap doesn't remove your existing obligations, it just means nobody is going to hand you a checklist. Mandated-reporter law, capacity assessment for consent, and the current HIPAA Security Rule all already apply to any AI tool touching a vulnerable patient's care, whether or not a regulator has written an AI-specific version of any of them yet. For the broader HIPAA questions solo clinicians ask about AI more generally, see 6 HIPAA questions solo clinicians ask about AI, answered, and for the billing side of AI adoption in these same specialties, the $2,480 threshold: what AI billing tools actually fix for solo OT and SLT practices.
The Clinical AI Briefing
One practical AI insight for healthcare practices every week. No hype. Evidence and outcomes only.
Related: 6 HIPAA questions solo clinicians ask about AI, answered · The $2,480 threshold: what AI billing tools actually fix for solo OT and SLT practices · CQC names 5 regulations for AI. Safeguarding isn't one.
This article is for informational purposes only and does not constitute legal, clinical, or safeguarding advice. Mandated-reporter obligations vary by state; confirm current requirements with your state licensing board and legal counsel before relying on anything above.