Control
AI or algorithm denies, delays or downgrades care in utilization review without a licensed clinical reviewer deciding
In health-insurance utilization review, an AI, algorithm or other automated tool never issues an adverse determination (a denial, delay, modification or downgrade based on medical necessity) by itself: it may approve, gather information or route the case, and every adverse outcome is decided, and where the law requires signed, by a licensed physician, clinical peer or other qualified health care professional who reviews the individual's clinical information and the requesting provider's recommendation.
Informational data, not legal advice. Summaries and rules have not been reviewed by a lawyer: always verify official law text for decisions. A suggested guard is intended to address each rule; adding it is not a statement of compliance to that law.
Reach
Law in force in Alabama (US-AL), California (US-CA), Iowa (US-IA), Illinois (US-IL), Maryland (US-MD), Nebraska (US-NE), Texas (US-TX); enacted, not yet applying in Georgia (US-GA); next date 2027-01-01.
Trust and provenance
How far the rules this guard addresses have been checked. Each rule links to its provision, with its citation, official text and its own panel.
- This control
- Audit-grade: meets all 3 checks of the TwinEthos audit standard that apply to it.
- Lanes
- Binding law — in force 7 Binding law — not yet in force or stayed 2
- Verification
- Sources last verified 3 Oct 2026; each provision states how.
- Data release
- Data release 2026.10.03.4, data as of 3 Oct 2026, schema 0.3.9.
- Legal review
- None of the 9 rules has been reviewed by a lawyer; no TwinEthos rule has been legally reviewed yet. Treat each as research to check against the official text; it is not legal advice. Open questions for counsel on them: 12.
- Audit standard
- 9 of 9 rules audit-grade. The audit standard is TwinEthos's own quality bar for provenance, dates, applicability, detectors, fixtures, remediation and licences; it is not a legal review.
- Detectors
- 12 detectors, all experimental: written from the rule's text and not yet measured for precision on real code, so treat a hit as a lead to verify. Each provision lists its detectors' known limits.
The guard to add
Route every adverse outcome an AI or algorithm proposes in utilization review to a qualified clinical reviewer, and issue a denial only from that reviewer's recorded decision.
At the point where a model, rules engine or scoring tool returns its result for a prior-authorization, concurrent or retrospective review, the code may auto-approve (where the law allows) or route the case, but any result that would deny, delay, modify or downgrade the request is written as a pending clinical review (status 'pending_clinical_review', a review_queue entry with the tool's output attached as a recommendation), never as the determination. Only a review action by an authenticated reviewer whose role is physician, clinical peer or qualified reviewer, in the same or a similar specialty where the law requires, can set an adverse status; that action records reviewer_id, licence and specialty, the clinical documents opened, the decision and its clinical rationale, and the timestamp, and the adverse-determination notice is generated from it (with the reviewer's signature or attestation where the law requires). Where a law forbids the automated system from making an adverse determination even in part (Texas), the tool's output may only approve, route or support administrative and fraud-detection work; it is not shown to the reviewer as a proposed denial.
Where it goes: 1 application source code, 2 data models, 9 AI output handling, 14 user-facing text.
What reviewers look for: no code path that sets a denied, declined or downgraded status, or sends a denial letter, directly from model or scoring output; a pending_clinical_review or review_queue step on every adverse path; a reviewer decision record (reviewer_id, role, specialty, documents reviewed, rationale) required by the endpoint that issues the adverse determination; notices built from that record and signed where required; and, for Texas, no model prompt or output schema that asks the tool to return a denial.
Example (Python + OpenAI SDK (prior-authorization service)), before:
result = client.chat.completions.create(model=MODEL, messages=build_pa_prompt(request)).choices[0].message.content
if json.loads(result)['decision'] == 'deny':
prior_auth.update(request.id, status='denied')
send_denial_letter(request)After:
result = json.loads(client.chat.completions.create(
model=MODEL, messages=build_pa_prompt(request, record=member_clinical_record(request))).choices[0].message.content)
if result['decision'] == 'approve' and AUTO_APPROVE_ALLOWED:
prior_auth.update(request.id, status='approved', ai_assisted=True)
else: # any non-approval goes to a clinician
review_queue.enqueue(request.id, queue='pending_clinical_review',
specialty=request.specialty, ai_recommendation=result)
@app.post('/reviews/{case_id}/decision')
def record_clinical_decision(case_id: str, body: Decision, reviewer=Depends(licensed_clinical_reviewer)):
decision = clinical_decisions.create(case_id=case_id, reviewer_id=reviewer.id, licence=reviewer.licence,
specialty=reviewer.specialty, documents_reviewed=body.documents,
outcome=body.outcome, rationale=body.rationale)
if body.outcome in ('denied', 'downgraded'):
send_adverse_determination(case_id, decision=decision, signed_by=reviewer)Engineering guidance, not legal advice. Each provision below may add its own details (a cadence, a deadline, a required notice element): open it for those.
Upcoming dates
- : AI may not issue an adverse determination before a review with a clinical peer, nor supersede the peer's judgment (Georgia SB 444) (Georgia (US-GA); first application)
- : Denials and downgrades are made and signed by a qualified reviewer or clinical peer, with an attestation of qualifications (Iowa HF 2635) (Iowa (US-IA); first application)
Every rule this guard addresses
Binding law — in force (7)
- Alabama (US-AL)
- Only a licensed physician or competent health care professional may deny, delay or modify prior authorization (Alabama SB 63) Ala. SB 63 (2026), sec. 1(b)(3)
- California (US-CA)
- AI may not deny, delay or modify care; only a licensed physician or competent professional decides medical necessity (California SB 1120) Cal. Health & Safety Code 1367.01(k)(2)
- Illinois (US-IL)
- Only a clinical peer makes adverse determinations; an algorithmic automated process may only certify or refer (Illinois HB 2472) 215 ILCS 134/45(i) and source note
- Iowa (US-IA)
- AI may give an initial prior-authorization review but may not be the sole basis to deny, delay or downgrade (Iowa HF 2635) 2026 Iowa Acts ch. 1087, sec. 2 (Iowa Code 514F.8(2A))
- Maryland (US-MD)
- Nebraska (US-NE)
- Texas (US-TX)
Binding law — not yet in force or stayed (2)
- Georgia (US-GA)
- AI may not issue an adverse determination before a review with a clinical peer, nor supersede the peer's judgment (Georgia SB 444) Ga. SB 444, sec. 1 (O.C.G.A. 33-46-7.1(c)) · applies from 2027-01-01
- Iowa (US-IA)
- Denials and downgrades are made and signed by a qualified reviewer or clinical peer, with an attestation of qualifications (Iowa HF 2635) 2026 Iowa Acts ch. 1087, sec. 6 (Iowa Code 514F.8A(2)) · applies from 2027-01-01
Related incidents
No guardrail sits on this exact control; these incidents are cited by guardrails on related controls.
- UnitedHealth nH Predict claim-denial litigation (2023-11; alleged (not proven)). A class action filed in November 2023 alleges that UnitedHealth's nH Predict model had a 90% error rate, measured by denials reversed on appeal, while only about 0.2% of members appealed. UnitedHealth disputes the allegations; the litigation is ongoing. Source: STAT News · evidence grade: primary · cited by Monitor how often adverse AI decisions are reversed, and suspend models that are usually wrong
- Cigna PXDX batch claim denials (reported) (2022; alleged (not proven)). ProPublica, citing internal Cigna records, reported that Cigna's PXDX system was used to reject more than 300,000 claims over two months in 2022, with physicians spending an average of 1.2 seconds on each. Cigna disputes the reporting; related lawsuits are ongoing. Source: ProPublica / The Capitol Forum · evidence grade: press of record · cited by Make human review of adverse AI decisions substantive, not nominal
Informational data, not legal advice. Summaries are TwinEthos's own words and rules have not been reviewed by a lawyer: check the official text before relying on any of it. A guard addresses an item; adding it is not a statement that your code meets any law.