🎓 FREE Webinar You Can't Miss + 7 ChatGPT Lawsuits Therapists Must Know

This week: Seven families sue OpenAI as ChatGPT redirects mental health questions to therapists; Massive HIPAA Security Rule overhaul confirmed still moving forward to May 2026; Google shuts down Business Profile Q&A API

Seven families sue OpenAI as ChatGPT redirects mental health questions to therapists

On November 7, seven lawsuits were filed in California alleging ChatGPT contributed to suicides and psychological harm. Families claim OpenAI rushed GPT-4o's release without adequate safety protocols, and that ChatGPT reinforced delusions, helped write suicide notes, and increased isolation all without the legal duty to report danger that licensed therapists have. One case involves a 56-year-old who killed his mother and himself after ChatGPT allegedly reinforced paranoid delusions.

Just days before these lawsuits, on November 1, ChatGPT implemented a major policy change: it now redirects mental health inquiries to licensed professionals instead of providing direct advice. Users asking for therapy or mental health guidance now receive messages like "I'm not a substitute for professional help" with prompts to consult licensed therapists. This creates an unprecedented referral channel, as ChatGPT actively sends people seeking mental health support to human professionals.

👉 Action: Update intake forms immediately to ask: "Have you been using AI chatbots like ChatGPT to discuss your mental health?" Revise informed consent to address risks of AI self-diagnosis without professional oversight. Screen new patients for AI-driven misinformation during assessments and document any reported AI chatbot usage in clinical notes. In marketing materials, emphasize human clinical judgment, legal duty of care, and mandatory reporting obligations that AI cannot provide. Add FAQ content to your website: "Can AI chatbots replace therapy?" to capture search traffic.

Seven families sue OpenAI as ChatGPT redirects mental health questions to therapists

Massive HIPAA Security Rule overhaul confirmed still moving forward to May 2026

On November 4, despite significant industry pushback and hopes the rule might be shelved, the Department of Health and Human Services confirmed the proposed HIPAA Security Rule overhaul remains on the official regulatory agenda for finalization in May 2026. The 393-page proposed rule, published in January 2025, represents the most significant change to HIPAA security requirements since 2013, moving from flexible, risk-based standards to prescriptive, mandatory cybersecurity requirements.

Key changes include mandatory technology asset inventories updated annually, network maps showing how patient data moves through systems, elimination of the distinction between "required" and "addressable" implementation specifications (making all requirements mandatory), and specific technical controls that many small practices don't currently have. The public comment period closed in March 2025, and OCR received sharp criticism from healthcare providers. Despite this pushback, the rule is proceeding to finalization, giving practices just 6 months from now until implementation begins.

👉 Action: Begin compliance preparation immediately, you have 6 months until May 2026. Create a technology asset inventory listing every device and system that stores patient information (EHR, email, telehealth, billing, cloud storage, computers, phones). Document how patient data flows between systems. Review current HIPAA compliance and identify gaps between "addressable" specs you skipped and the new "all mandatory" requirement. Budget now for encryption software, multi-factor authentication, security audits, and technical assistance. Monitor the HHS website for final rule publication.

Massive HIPAA Security Rule overhaul confirmed still moving forward to May 2026

Google shuts down Business Profile Q&A API

On November 3, Google discontinued the My Business Q&A API, preventing businesses from programmatically managing Questions and Answers through third-party tools. The API shutdown was announced September 17, giving businesses 47 days notice. While the Q&A feature itself remains visible on Google Search and Maps, businesses can no longer use automation tools or marketing platforms to manage these responses.

This change primarily affects multi-location businesses, marketing agencies, and franchises that relied on automated Q&A management at scale. Individual therapists managing their own single Google Business Profile through the GBP dashboard are minimally impacted. Google is transitioning toward AI-powered "Ask Maps" using Gemini, which may eventually replace traditional Q&A functionality with AI-generated responses based on business information.

👉 Action: Solo/small practices: no urgent action required, Q&A still works through your GBP dashboard. If you use third-party tools (Yext, Birdeye, SOCi) for Q&A management, switch to manual dashboard management and export existing Q&A data now. Create FAQ content on your website to supplement Q&A functionality. Monitor Google's AI-powered "Ask Maps" rollout and ensure your GBP information is comprehensive since AI will pull from it.

Google shuts down Business Profile Q&A API

FDA holds first advisory meeting on regulating AI mental health chatbots

On November 6, the FDA convened its Digital Health Advisory Committee for the first time to specifically address "Generative Artificial Intelligence-Enabled Digital Mental Health Medical Devices." This nine-hour meeting discussed whether AI chatbots that provide therapy-like conversations should require FDA clearance as medical devices, what evidence should be required before approval, and whether these tools need healthcare provider supervision.

The meeting addressed scenarios ranging from prescription AI therapy tools to over-the-counter mental health apps. Final recommendations will inform FDA guidance expected in 2026, creating the first federal regulatory framework for AI tools that compete with or complement traditional therapy. The public comment period closes December 8, 2025, giving therapists one month to submit feedback on how these regulations should work.

👉 Action: Monitor FDA guidance releases by checking the FDA Digital Health Center monthly. Audit any AI tools in your practice (scheduling chatbots, intake assistants, symptom screeners) for potential medical device classification. Prepare documentation showing human therapist oversight of AI-generated content. Update informed consent forms to address AI tool limitations and clarify that AI cannot replace licensed clinical judgment. Submit public comments to FDA Docket FDA-2025-N-2338 before December 8 if regulations concern you.

FDA holds first advisory meeting on regulating AI mental health chatbots

Quick wins for the week

  • Add AI chatbot screening question to intake forms: "Have you used AI chatbots to discuss your mental health?"
  • Update informed consent to address AI tool limitations and patient data privacy
  • Begin creating technology asset inventory for HIPAA Security Rule changes coming May 2026
  • Submit public comments to FDA Docket FDA-2025-N-2338 before December 8 regarding AI chatbot regulations
  • Review third-party tools to identify which use the discontinued Google Q&A API
  • Add FAQ to your website: "Can AI chatbots replace therapy?" to capture search traffic

Final thoughts

This week brought the first federal moves toward regulating AI mental health tools, lawsuits highlighting the dangers of unregulated chatbots, confirmation that massive HIPAA changes are still coming in 2026, and the quiet removal of automated Google features therapists barely used. Each story points to the same reality: the infrastructure supporting therapy practices is being fundamentally rebuilt, and regulatory agencies are just starting to catch up.

The FDA meeting signals that AI therapy tools won't stay in the regulatory gray zone forever. The OpenAI lawsuits demonstrate what happens when AI companies deploy mental health features without the legal obligations therapists carry. The HIPAA overhaul shows that small practices will soon face the same rigid cybersecurity requirements as hospitals. And Google's API shutdown reminds us that platforms can remove features overnight without consulting the businesses that depend on them.

What makes this week different from others is the shift from reactive compliance to proactive preparation. You have four months to comment on HIPAA changes before they're finalized. You have one month to influence FDA regulations on AI chatbots. You can update your intake forms today to screen for AI usage that might affect treatment. The practices that start preparing now while regulations are still in draft form, will adapt far more smoothly than those who wait until enforcement begins.

While you're providing therapy, we're monitoring policy changes, protecting your Google presence, and optimizing for AI search. You shouldn't need to become an SEO expert, compliance specialist, and tech strategist on top of being a therapist.