Oregon just passed a chatbot law therapists can be sued under. Are you covered?
This week: Google fires up its first 2026 Core Update highest volatility score ever recorded; Oregon passes the nation's toughest AI chatbot law with a private right of action; State AI therapy regulation wave hits critical mass: Kentucky,
Google fires up its first 2026 Core Update highest volatility score ever recorded
On March 5, 2026, industry trackers confirmed Google launched its first broad Core Update of the year, and the shockwaves are already being felt. SEMrush's Sensor, which measures ranking turbulence on a scale of 0 to 10, hit 9.5, one of the highest readings ever recorded on the platform. This follows the February 2026 Discover Core Update that took 21 days to roll out and reshuffled traffic from Google's Discover feed, the first Discover-only update Google has ever run. Now, a full broad Core Update is layered on top of it, and both Search and Discover traffic are in motion simultaneously.
Core Updates are Google's biggest lever. They don't punish specific tactics. They fundamentally re-evaluate which websites deserve to rank at all. For therapists, the stakes are especially high: health and wellness content falls under Google's strictest scrutiny, requiring demonstrated expertise, real credentials, and evidence that a licensed professional wrote it. Practices with thin service pages, no therapist bios, or outdated content are at serious risk. The update is expected to take approximately two weeks to fully roll out.
👉 Action: Log into Google Search Console now and document your current rankings and traffic as a baseline before the update fully lands. Add or update detailed author bios on every page, include your license number, credentials, and specialties. Check that your service pages describe your actual approach, not just generic descriptions. Avoid making major structural changes to your website while the update is still rolling out; wait until volatility settles before assessing what shifted. Monitor only Google Search Console, not third-party tools, which can misread core update volatility as more severe than it is.
Oregon passes the nation's toughest AI chatbot law with a private right of action
On March 5, 2026, the Oregon House passed Senate Bill 1546 by a unanimous 52-0 vote. The bill now sits on Governor Tina Kotek's desk, with five business days to be signed into law. Oregon becomes the second state after California to pass a major AI chatbot safety bill. But SB 1546 goes further than California's SB 243 in one critical way: it includes a private right of action, meaning individuals can sue AI chatbot operators directly for statutory damages if the safety requirements are violated.
The law requires any AI chatbot operator to implement detection protocols for suicidal ideation or self-harm, and to refer users to the 988 Suicide and Crisis Lifeline at minimum. For users under 25, chatbots must redirect to a youth-specific crisis line accredited by the American Association for Suicidology. Additional protections for minors include bans on engagement tactics, like rewards, affirmations, and streaks, designed to keep young users on the platform. Any automated system that sustains a personalized ongoing dialogue with users about personal matters may be captured by the law. That means appointment chatbots, intake assistants, and website chat widgets used by therapy practices serving Oregon clients may be subject to these requirements.
👉 Action: Review every automated chat tool on your website and in your practice management system. If any of these tools interact personally with prospective or current clients and could potentially receive disclosures about mental health or self-harm, evaluate them for SB 1546 compliance before the Governor signs. Contact your practice management software and telehealth providers in writing and ask directly: does your product comply with Oregon SB 1546? If you serve clients in both Oregon and California, review both laws side by side, the requirements differ and both apply. The private right of action in Oregon is particularly significant: non-compliance is not just a regulatory risk, it creates direct legal exposure.
State AI therapy regulation wave hits critical mass: Kentucky, Washington, New York all move in one week
The past week saw a significant acceleration of state-level laws targeting AI use in therapy and mental health services. On March 2, 2026, Kentucky's House passed HB 455, a bill that directly regulates the use of AI in therapy and psychotherapy services, making Kentucky the latest state to act after Illinois, Nevada, Utah, and California. At the same time, Washington's chatbot safety bill passed the Senate by a 43-5 vote and is now awaiting a final House concurrence vote. In New York, a bill that would impose direct liability on chatbots that impersonate licensed professionals including therapists, that advanced to a third Senate floor reading. In Minnesota, lawmakers introduced companion bills specifically regulating the use of AI in psychotherapy sessions.
Each state is writing its own rules, and they do not align. Illinois prohibits AI from making independent therapy decisions. Nevada bans AI from claiming it can provide mental or behavioral healthcare. Florida's pending 2026 bill requires written, informed consent obtained at least 24 hours in advance before any AI system records or transcribes a therapy session. Oregon adds a private right of action. If you serve clients across multiple states, or if your practice management software or website chat tool reaches clients in any of these states, you may face multiple overlapping compliance obligations simultaneously. The window to get ahead of this patchwork is closing quickly.
👉 Action: Create a simple list of the states your clients are located in. For each state, check whether AI therapy legislation has passed or is advancing (the Troutman Privacy blog publishes a weekly update at troutmanprivacy.com that is free to read). Review every AI-assisted tool in your practice: transcription tools, intake chatbots, scheduling automation, and anything that generates AI-generated suggestions, against the requirements of the states you operate in. Pay particular attention to Florida's pending consent requirement if you serve Florida clients: written informed consent, 24 hours in advance, before any AI records a session. Start drafting that consent language now, before it becomes a legal deadline.
ChatGPT Health under-assessed half of medical emergencies
A peer-reviewed study published in Nature Medicine on March 3, 2026 found that ChatGPT Health, OpenAI's dedicated health chatbot that launched in January and now has hundreds of millions of users, under-assessed approximately half of all medical emergencies presented to it. Researchers at Mount Sinai Hospital fed 60 real-world medical scenarios to ChatGPT Health and compared the responses against three licensed physicians. The AI systematically misjudged severity, classifying emergency-level situations as non-urgent in roughly half of cases. The study also tested whether responses changed based on client race or gender, they did, raising additional bias concerns. OpenAI's own terms of service state ChatGPT Health is "not intended for diagnosis or treatment."
For therapy practices, this is a direct serious concern, not abstract technology news. Over 230 million people per week use ChatGPT for health and wellness questions. A significant portion involve mental health, and OpenAI reports that a majority of health-related ChatGPT messages occur outside of normal business hours, exactly when your clients are most likely to reach for it. If a client is in crisis at 11pm, describes their distress to ChatGPT Health, and the tool tells them things are fine, a referral to you or to 988 may never happen. The gap between AI availability and AI safety is not theoretical. It is currently wide open.
👉 Action: Add a brief, non-alarmist question to your intake and session check-in forms: "Between our sessions, have you been using any AI tools like ChatGPT to process your feelings or mental health?" Document any disclosed AI tool use in session notes. For clients with elevated risk histories, have a direct conversation about AI limitations: it cannot hear tone of voice, assess body language, or know your history. Remind clients that 988 is staffed by humans and available 24/7. This is also a practice positioning opportunity: the study reinforces that licensed human therapists with real client knowledge cannot be replicated by AI, a message worth sharing in your website content and client communications.
OCR's 12th enforcement: software vendor breached 15 million records and never told a single healthcare provider
On March 5, 2026, the U.S. Department of Health and Human Services' Office for Civil Rights announced a settlement with MMG Fusion, LLC, a Maryland-based dental software company, marking OCR's 12th enforcement action under its Risk Analysis Initiative. The case involves a 2020 hack in which an unauthorized actor infiltrated MMG's systems and accessed the protected health information of approximately 15 million individuals including names, phone numbers, addresses, email addresses, dates of birth, and appointment dates. The data was posted on the dark web. MMG failed to conduct a risk analysis. It failed to report the breach to OCR in a timely manner. And most critically, it never notified the healthcare provider clients whose clients' records were exposed.
OCR's Director stated plainly: "Covered entities and business associates cannot protect electronic protected health information if they haven't identified potential risks and vulnerabilities." For therapists, the lesson is urgent. Every third-party tool that touches your client data, including your EHR, practice management platform, scheduling software, telehealth system, intake chatbot, and billing service, is a HIPAA business associate. If one of those vendors is breached and doesn't tell you, your clients' most sensitive mental health information may already be on the dark web. OCR confirmed this year that the Risk Analysis Initiative is expanding beyond documenting risks to validating that you have actively managed them. Paper compliance is no longer enough.
👉 Action: Pull up every third-party vendor that handles client data in your practice. For each one, confirm you have a signed Business Associate Agreement on file. If you cannot locate one, contact the vendor in writing this week and request it, and document that request. Then conduct or update your Security Risk Analysis: a written assessment of where client electronic protected health information lives, who has access, and what safeguards exist. HHS provides a free Security Risk Assessment tool at HealthIT.gov. OCR has now filed 12 enforcement actions under this initiative in under two years. Solo practitioners and small therapy practices have already been named in settlements. The size of your practice does not exempt you.
Quick wins for the week
- Log into Google Search Console now to capture a ranking and traffic baseline before the March 2026 Core Update finishes rolling out
- Contact your website chatbot and practice management providers in writing asking whether they comply with Oregon SB 1546 before the Governor signs it into law
- Map which states your clients live in and flag any where AI therapy legislation is advancing, especially Florida if you serve clients there
- Add a brief AI chatbot screening question to your intake forms: "Have you been using any AI tools to talk through your mental health between sessions?"
- Pull your vendor list and confirm you have a signed Business Associate Agreement on file for every third-party tool that handles client data
Final thoughts
This week delivered five stories that belong in a single issue only because they all arrived in the same seven days. Google launched what tracking tools are calling one of the most volatile Core Updates ever recorded happening right now, while your rankings are live. Oregon passed the nation's first AI chatbot law with real private liability attached to it. A wave of state AI therapy legislation reached a tipping point, with Kentucky, Washington, New York, and Minnesota all advancing bills in a single week. A peer-reviewed study confirmed that the AI health tool hundreds of millions of your clients are already using misses roughly half of medical emergencies. And OCR announced its 12th enforcement action, this time involving 15 million records and a vendor that never told a single healthcare provider a breach had occurred.
Taken together, these are not isolated compliance headaches, they are a picture of an industry under fundamental transformation. The rules around AI in therapy are being written in real time, state by state, with no federal framework to simplify them. The tools your clients use between sessions are operating without safety guardrails. The vendors running your practice software may be handling client data in ways you have never reviewed. And Google, still the primary channel through which most new therapy clients find providers, is reshuffling its entire ranking system this week.
While you're providing therapy, we're monitoring policy changes, protecting your Google presence, and optimizing for AI search. You shouldn't need to become an SEO expert, compliance specialist, and tech strategist on top of being a therapist.
Get the next edition in your inbox
One email a week on Google, AI search, and running a visible therapy practice. No fluff, unsubscribe anytime.