AI in Med-Mal: The 3 Worst Mistakes That Get Attorneys Sanctioned (2026)

Verify it yourself — free, no login

See how AI medical-record review links every fact to the exact Bates page that proves it — click any citation and jump straight to the record.

See the 60-second demo →

By John Mahoney · Founder, MedLegal AI · May 19, 2026

Mata v. Avianca (S.D.N.Y. 2023) — the case that launched a thousand law-review articles — was the first major AI-sanctions case in U.S. legal practice. Two attorneys submitted a brief citing six fabricated case decisions that ChatGPT had invented wholesale. They were fined $5,000 each and the case became required reading. Since then, the sanctions docket has grown. By 2026, sanctions orders related to fabricated AI citations are reported approximately monthly across federal and state courts.

For plaintiff medical malpractice attorneys, AI is now indispensable for record review, chronology building, and expert workup. But the AI-sanctions risk is real, and the patterns that drive it are specific. This is the catalog of the three mistakes that drive the sanctions docket — and the workflow safeguards that make AI safe to use in court.

Mistake #1: Submitting AI-Generated Case Citations Without Verification

This is the Mata v. Avianca mistake — and it has not gone away. In every AI-sanctions case we've tracked through 2026, fabricated case citations are the proximate cause. ChatGPT, Claude, Gemini, and other general-purpose LLMs can produce realistic-looking case citations — court name, parties, reporter, page number, parenthetical — that are entirely fabricated. The citations don't exist. The opinions don't exist. The reasoning attributed to them is invented.

How it happens: Attorney asks ChatGPT (or similar) to "find me a Third Circuit case on Daubert reliability of differential diagnosis." ChatGPT produces a citation that looks correct. Attorney copies it into the brief. Attorney never opens the cited case. Defense (or the court) tries to look it up. The case doesn't exist.

Why it still happens: Plaintiff attorneys are busy, deadlines are tight, the AI output looks polished, the attorney's confirmation bias does the rest. The sanctions cases all share this pattern: the attorney didn't check the citation.

The safeguard: Use only AI tools that ground every cited authority against an actual source. For medical literature, that means PubMed PMID resolution — the tool fetches the actual abstract from PubMed and verifies the citation before including it in output. For case law, that means Westlaw / Lexis / CourtListener integration. If your AI tool can produce a citation and you can't click through to the source from the tool itself, do not use that citation without manually verifying.

Mistake #2: Letting AI Draft Expert Reports Without Independent Expert Review

This is the next-generation sanctions risk, and we expect it to drive the bulk of 2026-2027 cases. AI tools can produce expert-report-quality output — methodology articulation, alternative-cause analysis, peer-reviewed citations, even draft opinions. The temptation is to use the AI output as the report itself and have the expert sign it after a cursory read.

How it happens: Attorney runs the case through a Daubert workup tool. The tool produces a draft expert report including draft opinions. Attorney shares the draft with the retained expert. Expert reviews quickly, signs. Report is filed. Defense moves to exclude under FRE 702 amendment, arguing the expert is not actually the author of the methodology articulation.

What courts are doing: The 2023 FRE 702 amendment requires the expert to have actually applied the methodology. If the AI did the application and the expert merely signed off, the expert can be cross-examined into admitting the methodology articulation wasn't theirs. Result: exclusion on application-to-facts grounds, possible Rule 26 sanctions if the AI authorship wasn't disclosed.

The safeguard: The AI workflow is: AI produces the draft → expert performs the actual methodology application using the AI's structure as a starting point → expert can testify at deposition that they personally applied the methodology to the facts. The AI is a force multiplier on the expert's preparation; it is not the expert. Document the expert's actual review and revision time. Many firms now require experts to sign a declaration stating they personally performed the methodology application; this is becoming best practice.

Mistake #3: Uploading PHI to a Public LLM Without HIPAA-Compliant Architecture

This isn't a sanctions risk per se — it's a HIPAA violation risk and a potential bar discipline risk for protecting client confidences. But it's the most common AI mistake we see plaintiff attorneys make, and the consequences can be severe.

How it happens: Attorney has a 1,500-page medical record production. Attorney pastes it into ChatGPT (consumer version) and asks for a chronology. The records contain the client's name, DOB, diagnoses, treatments, and provider information. The consumer ChatGPT terms of service permit OpenAI to use that input for training. The PHI has now been transmitted to a non-BAA vendor and is potentially being used to train a future model.

Why it still happens: The attorney didn't realize the consumer ChatGPT vs the enterprise ChatGPT have different data-handling terms. The attorney thought "AI is AI." The attorney was solving a real problem (1,500 pages is a lot) and reached for the most convenient tool.

The safeguard: Use only AI tools with: (a) a signed BAA (Business Associate Agreement) with the vendor; (b) zero-retention data handling on inputs; (c) clear documentation that PHI inputs are not used for model training. MedLegal AI's processing happens under BAA with Anthropic; inputs are not retained for training; the medical record files themselves are stored under your account in an S3 bucket scoped to your tenant. Verify these properties of any AI tool before uploading PHI.

The Disclosure Question

A growing number of federal and state courts now require attorneys to disclose AI use in filings — local rules in the Northern District of Texas, multiple judges in the Southern District of New York, and Sixth Circuit standing orders. The disclosure usually requires:

This is not yet uniform. Check your jurisdiction's specific rules and the standing orders of each judge before each filing. Some judges go further and require disclosure of the specific tool used.

The Defense Tactic to Anticipate

Defense firms in 2026 are increasingly using AI disclosure as a discovery tactic. Interrogatory requests like "Identify every AI tool used to prepare any document produced in this litigation" are common. The aim is to either (a) catch fabricated citations through deposition, (b) attack expert reports as AI-authored, or (c) pressure plaintiff firms into not using AI at all.

The protective practice is the same as the safeguards above: use only HIPAA-compliant, citation-grounded tools; document expert review independently; verify every citation manually. Done right, AI use is fully defensible.

What Makes a Tool Defensible

Four properties to look for in any legal AI tool you use in active litigation:

  1. Citation grounding. Every cited authority has a verifiable source (PMID for medical literature, Westlaw/Lexis/CourtListener URL for case law). The tool produces citations only when it can ground them.
  2. BAA / HIPAA architecture. Signed BAA, zero-retention input handling, clear no-training-on-input policy.
  3. Expert-augmenting workflow. The tool produces a draft for the expert to apply and revise, not a finished report for the expert to sign.
  4. Audit trail. Every output can be reproduced from inputs. If defense asks "how did the AI arrive at this opinion," you can show the source documents that informed it.

Bottom Line

AI sanctions in 2026 are real but predictable. They happen when attorneys (a) cite AI-generated authority without verification, (b) treat AI output as the expert's own work, or (c) upload PHI to non-HIPAA-compliant tools. The defensible AI workflow is the inverse: PubMed-grounded citations, expert-augmenting drafts, BAA-protected processing. Done right, AI is a force multiplier that survives any defense Daubert motion or sanctions inquiry.

Try MedLegal AI's free Daubert workup — PubMed-grounded, BAA-compliant, expert-augmenting by design.


MedLegal AI is software, not a law firm. We do not provide legal advice. All AI-generated outputs require independent review by a licensed attorney.

Run a free Daubert workup on your expert

PubMed-grounded, no hallucinations, 90 seconds.

Try the free Daubert workup →
MedLegal AI is software, not a law firm. We do not provide legal advice and no attorney-client relationship is created by use of this service. All outputs are AI-generated and must be independently reviewed by a licensed attorney before use in any legal proceeding, expert report, or client communication.
See the AI cite its source — no login
Most legal AI is wrong 17–33% of the time. Watch MedLegal AI pin every finding to the exact record page — click any citation and it jumps to the line that proves it.
Watch the 30-second demo →