Table of Contents
Summarize and analyze this article with
The denial decision now has rules of its own
What a defensible UM AI program needs
| Element | What it requires | Evidence |
|---|---|---|
| Human final decision | A licensed clinician makes the medical-necessity determination | Records showing the clinician, not the algorithm, decided |
| Individualized data | The decision reflects the enrollee’s own clinical circumstances | Case records tying the decision to individual data |
| Transparency and notice | Denial reasons and provider contact in written communications | Compliant denial notices |
| Governed policies | Written policies filed with oversight agencies; accountability for accuracy | Filed policies and review-and-revision records |
| Monitoring | Error rates, overturn rates, and outcomes reviewed for accuracy | Monitoring logs and remediation records |
| Audit trail | What was decided, on what basis, and by whom | Reconstructable decision records |
Why the cautionary cases matter
Where PiTech fits
The bottom line
Frequently Asked Questions (FAQs)
Can health plans use AI to deny coverage?
Plans can use AI to assist coverage and utilization-management decisions, but a growing body of law requires that the algorithm not be the final decision-maker for medical necessity. California’s Physicians Make Decisions Act, in force since 1 January 2025, requires a licensed physician or qualified health professional to make the medical-necessity determination when AI is used in utilization review, and CMS has clarified that Medicare Advantage plans may use an algorithm to assist but not as the sole basis for a determination. So AI can inform the decision and organize information, but a qualified human must make the call, on the individual’s circumstances. Using AI to auto-deny without genuine human judgment is where plans face legal exposure.
What does California's SB 1120 require?
SB 1120, the Physicians Make Decisions Act, took effect on 1 January 2025 and governs the use of AI and algorithmic tools in health-plan utilization review and management. It requires that a licensed physician or qualified health professional make the final medical-necessity determination rather than delegating it to an algorithm, that the decision be based on the enrollee’s own clinical circumstances and medical history rather than solely on a group dataset, and that plans maintain written policies, file them with state oversight agencies, and remain accountable for the accuracy and reliability of their tools. It does not ban AI; it bans AI making the final call on medical necessity. The law reflects a broader multi-state trend.
What did CMS say about algorithms in Medicare Advantage?
Do other states regulate AI in health insurance decisions?
Yes, and the number is growing. California’s SB 1120 is the most prominent example, but the pattern of regulating AI in utilization review and coverage decisions, requiring human oversight, individualized decision-making, and transparency, is spreading as states act in the absence of comprehensive federal legislation. Health plans operating in multiple states should expect a patchwork of requirements that share common themes: a qualified human must make the medical-necessity decision, the decision must reflect the individual, and the plan must be transparent and accountable. Building a governance approach to the strictest common denominator, rather than state by state, is the efficient way to stay compliant across a multi-state footprint.
What is the difference between governing the model and governing the decision?
Governing the model means validating that the algorithm performs accurately and monitoring it for drift. Governing the decision means ensuring that a qualified human makes the medical-necessity determination, that it rests on the individual’s circumstances, that the denial is transparent, and that the whole decision is reconstructable from records. The recent laws are about governing the decision: a model can perform well in testing and the plan can still be non-compliant if the human review is a formality or the decision is based on a group dataset. The evidence a plan must produce is not model accuracy alone but proof that a human decided, on individualized data, with a reviewable record.
How should plans document AI-assisted coverage decisions?
What are the risks of getting UM AI governance wrong?
How do we keep human review from becoming a rubber stamp?
Design the workflow so the reviewing clinician has the individual’s clinical information, the time, and the authority to overturn the algorithm, and measure whether that is happening. Track overturn rates, review times, and outcomes: a near-zero overturn rate or a median review time of seconds signals a rubber stamp. Give reviewers the individualized data the law requires rather than only a score, and record what they were shown and what they decided. Genuine human authority is demonstrated by evidence that reviewers actually change decisions on the merits, not by a policy statement. Monitoring the review path itself is what separates real oversight from a formality that fails under scrutiny.


