A telehealth support bot that answers "can I double my dose to catch up?" has just practised medicine without a licence, and the company owns the answer.
A customer support chatbot cannot give medical advice. In 2026, US law and professional rules reserve clinical judgement for licensed providers, and AI-specific statutes in California, Utah and Illinois now regulate what an automated system may say to a patient. A support agent may handle scheduling, billing, shipping and account tasks, and must route dosing, symptom and treatment questions to a clinician.
California AB 3030 (effective January 1, 2025) requires a disclaimer and a human contact path whenever generative AI communicates clinical information to a patient.
Illinois fines up to $10,000 per violation for AI delivering therapy, while permitting administrative and supplementary support.
The FTC has already extracted $1.5 million from GoodRx and $7.8 million from BetterHelp over health-data handling, before any chatbot-specific case.
32% of consumers used AI chatbots for health information in 2025 per Rock Health, so patients will ask your bot clinical questions whether you invite them or not.
Last updated: September 2026
Telehealth companies, and peptide and GLP-1 providers in particular, feel this problem more sharply than most. Their patients self-inject at home, titrate doses on a schedule, and message support at 11pm when a vial arrives warm or a dose is missed. Every one of those messages sits close to the clinical line. A generic chatbot trained on the help centre will try to be helpful, and "helpful" is exactly the failure mode regulators are now writing rules about.
The fix is not a disclaimer at the bottom of the chat window. It is an agent architecture that knows which questions it may resolve, which it must hand to a clinician, and how to make that handoff in a way that satisfies the law and the patient.
Can a Customer Support Chatbot Give Medical Advice?
A customer support chatbot cannot legally or safely give medical advice. Medical advice means interpreting a patient's symptoms, history or medication to recommend a course of action, and in the US that activity is reserved for licensed clinicians. A support chatbot may provide logistics, account and policy information, and may relay clinician-approved instructions verbatim.
The distinction matters because the same sentence can be either. "Store the vial between 2°C and 8°C" is product information. "Your vial was warm for 6 hours, so it is still fine to inject" is a clinical judgement.
Patients will ask anyway. According to Rock Health's 2025 consumer survey, 32% of US consumers used AI chatbots for health information, double the 16% in 2024, so patients arrive expecting the bot to answer. Gartner's July 2024 survey found 64% of customers would prefer companies did not use AI in customer service at all, which makes the trust cost of a wrong answer even higher.
Medical advice: a recommendation about diagnosis, treatment, dosing or symptom management that depends on an individual patient's circumstances and requires clinical judgement.
Administrative support: help with scheduling, orders, shipping, billing, subscriptions, account access and policy explanations that does not require clinical judgement.
Lorikeet is an AI customer support platform that resolves tickets end-to-end, processing refunds, updating subscriptions and completing multi-step workflows across chat, email and voice. In telehealth, Lorikeet is configured to resolve administrative tickets fully and to stop at the clinical line, handing dosing, symptom and treatment questions to a licensed provider with the full conversation attached.
Where Is the Line Between Support and Clinical Advice in Telehealth?
The line between support and clinical advice in telehealth sits at individual judgement: a support agent may state facts, policies and clinician-approved instructions, but the moment an answer depends on this patient's symptoms, history or dose, it becomes clinical. Most telehealth tickets are administrative, and a minority cross the line mid-conversation.
Clearly administrative
Order status, cold-chain replacement claims, refill ship dates, subscription pauses, refunds, payment retries, appointment booking, insurance receipts and "how do I upload my ID" questions. California AB 3030 explicitly exempts messages about appointments, billing and business matters from its clinical-AI rules. These tickets can be resolved end-to-end by an AI agent, and our telehealth use-case guide walks through each one.
Clearly clinical
Dose adjustments, missed-dose instructions, side-effect interpretation, drug interactions, whether to continue after a warm shipment, and any "is this normal?" question. These require a licensed clinician. The AI's job is intake and routing, not answering.
The grey zone that trips up bots
"When is my next dose?" is administrative if the answer is a date from the prescription record, and clinical if the patient adds that they skipped 2 weeks. Good agents detect that shift and change behaviour mid-conversation, which is where AI guardrails earn their keep.
"This is one of the most significant open questions in healthcare law right now, and the honest answer is that liability allocation is going to be highly fact-dependent and will likely take years of litigation to clarify."
- Meghan O'Connor, Health Law Partner and Co-chair of the AI team, Quarles & Brady, in MedCity News
What Laws Govern AI Chatbots in Patient Communication in 2026?
In 2026, AI chatbots in patient communication are governed by a patchwork: HIPAA for protected health information, the FTC Act and Health Breach Notification Rule for consumer health data, FDA guidance on clinical decision support, and state AI statutes in California, Utah, Illinois and others. No single law covers a telehealth support bot, so compliance means satisfying all of them at once.
California AB 3030 (January 1, 2025). Health facilities, clinics and practices using generative AI to communicate clinical information must include a disclaimer and instructions for reaching a human. In chat, the disclaimer must persist throughout the interaction. Messages reviewed by a licensed provider are exempt.
Utah AI Policy Act and SB 226 (2025). Disclosure is required for "high-risk" AI interactions, which Future of Privacy Forum notes include collecting health data and providing medical advice. HB 452 adds rules for mental health chatbots.
Illinois Wellness and Oversight for Psychological Resources Act (August 1, 2025). Prohibits AI from providing therapy, with fines up to $10,000 per violation per the Illinois IDFPR. Administrative and supplementary support for licensed professionals remains allowed.
FTC Health Breach Notification Rule (updated 2024). The FTC extended the rule to health apps, after fining GoodRx $1.5 million and settling with BetterHelp for $7.8 million over sharing health data with advertisers.
FDA Clinical Decision Support guidance (final, January 2026). Per Manatt Health's policy tracker, software that makes patient-specific recommendations a clinician does not independently review can be a regulated device. A support bot that interprets symptoms drifts toward that definition.
HIPAA. Any AI vendor that touches protected health information needs a signed Business Associate Agreement. Our BAA and HIPAA guide lists what to verify.
What Happens When a Support Bot Crosses the Line?
When a support bot gives medical advice, the company inherits the clinical, regulatory and product-liability exposure that the bot cannot carry itself. Enforcement to date has focused on data handling and therapy bots, but 2025 court rulings and state attorneys general have moved chatbots squarely into existing liability frameworks.
The cost signals are already visible. The FTC's GoodRx action, the first under the Health Breach Notification Rule, carried a $1.5 million penalty, and BetterHelp's settlement reached $7.8 million, according to the FTC. In May 2025 a federal court in Garcia v. Character Technologies treated a chatbot as a product for design-defect claims, and in December 2025 42 state attorneys general warned AI companies that chatbots face liability under existing state law, per the National Law Review.
Illinois adds fines of up to $10,000 per violation for AI therapy, and no state has yet carved out a safe harbour for support bots that drift into clinical territory.
The operational cost is quieter but larger: every wrong clinical answer that a patient later raises with a clinician becomes documentation work, a trust problem and, in the worst case, an adverse event. The upside of getting the line right is that the administrative majority of tickets, which LiveChatAI prices at $30 or more each in healthcare, can be automated with confidence.
The line is legal exposure on one side and $30-per-ticket savings on the other. See how Lorikeet keeps support agents on the right side of the clinical line.
How Do You Design a Support Agent That Knows When to Stop?
Designing a support agent that knows when to stop means 4 things: an explicit list of resolvable ticket types, guardrails that detect clinical content mid-conversation, a clinician handoff that carries the full transcript and patient context, and 100% conversation QA so misses are caught the same day. The agent should be measured on correct escalations as well as resolutions.
Start by writing the allow-list, not the block-list. Enumerate the administrative workflows the agent may complete end-to-end (refunds, ship dates, pauses, payment retries, ID uploads) and connect them to the systems that execute them.
Then define the clinical triggers: dose, missed, skipped, side effect, dizzy, nausea, rash, interaction, pregnant, and the dozens of phrasings patients actually use. When one fires, the agent stops resolving, discloses AI use where AB 3030 or Utah law requires it, and books or pages a clinician.
Finally, review everything. Sampling 5% of conversations means 95% of clinical near-misses go unseen. Lorikeet Coach reviews 100% of AI conversations against your policies, and our guide to preventing hallucinations in regulated support covers the testing discipline before launch.
Lorikeet's Take on Chatbots and Medical Advice
At Lorikeet, we've watched telehealth teams buy a chatbot to "reduce clinical load" and end up with a bot that answers dosing questions badly and refuses refunds it should have processed. Most vendors sell coverage: the percentage of questions the bot attempts. The reality is that in telehealth the valuable metric is the opposite, how reliably the agent resolves the administrative ticket completely and stops cold on the clinical one. Lorikeet is built around that split, with guardrails that change the agent's behaviour mid-conversation and escalations that arrive with the whole context. If your patients message at 11pm about a missed dose, see how Lorikeet's Resolution Loop handles the handoff.
Key Takeaways
Support chatbots cannot give medical advice; dosing, symptom and treatment questions belong to licensed clinicians in every US state.
California AB 3030 requires persistent AI disclaimers and a human contact path once clinical information enters a chat.
Illinois fines up to $10,000 per violation for AI therapy; the FTC has extracted $9.3 million combined from GoodRx and BetterHelp.
32% of consumers already ask AI for health information per Rock Health, so the bot will be asked clinical questions regardless.
Design an allow-list of administrative workflows, clinical triggers that stop the agent, and 100% QA of conversations.
The question is not whether a chatbot can give medical advice. It cannot, and in 2026 the law says so with increasing specificity. The useful question is whether your support automation is built to know the difference, sentence by sentence, and to act on it by resolving the administrative ticket fully and stopping at the clinical one.
Telehealth companies that get this right will automate most of their support volume without carrying clinical liability they cannot insure, and their clinicians will receive escalations that are complete, documented and worth their time.
If your team is drawing this line by hand today, talk to Lorikeet about a support agent that resolves everything it should and nothing it shouldn't.









