Colorado Division of Insurance (carriers); Department of Human Services and Department of Health Care Policy and Financing (behavioral health administrative services organizations and managed care entities) · Colorado (US-CO) · 6 provisions encoded · verified against the official source as of 2026-10-04.
Informational data, not legal advice. Summaries and rules have not been reviewed by a lawyer: always verify official law text for decisions. A suggested guard is intended to address each rule; adding it is not a statement of compliance to that law.
Sources last verified 4 Oct 2026; each provision states how.
Data release
Data release 2026.10.05, data as of 4 Oct 2026, schema 0.3.10.
Legal review
None of the 6 provisions has been reviewed by a lawyer; no TwinEthos rule has been legally reviewed yet. Treat each as research to check against the official text; it is not legal advice. Open questions for counsel on them: 6.
Audit standard
6 of 6 provisions audit-grade. The audit standard is TwinEthos's own quality bar for provenance, dates, applicability, detectors, fixtures, remediation and licences; it is not a legal review.
Detectors
7 detectors, all experimental: written from the rule's text and not yet measured for precision on real code, so treat a hit as a lead to verify. Each provision lists its detectors' known limits.
Changes
2026.10.05 (5 Oct 2026): 6 provisions added
Each data release records which provisions changed; the full list is on Changes.
Binding law — not yet in force or stayed
Disclose in writing to the regulator where AI is used in utilization review, its human oversight and audit process (Colorado HB 26-1139)
C.R.S. 10-16-112.7(4) · official text · Enacted, not yet applying: applies from 1 Jan 2027 · Colorado (US-CO)
From 2027-01-01, a carrier, pharmacy benefit manager, private utilization review organization, behavioral health administrative services organization or managed care entity that uses an artificial intelligence system for utilization review must provide written disclosures to the Division, the Department of Human Services or the Department of Health Care Policy and Financing, as applicable, that identify the utilization-review functions for which the system will be used, the points in the process when it is used, the human oversight process (including the qualifications of the reviewer and whether a human must approve an adverse determination) and the process for maintaining audit information sufficient to demonstrate compliance with subsection (3) (C.R.S. 10-16-112.7(4)); the system's or algorithm's criteria and guidelines must comply with other applicable state or federal law on utilization review and coverage ((3)(h)). Detect the absence of the written disclosure record.
Trust and provenancenot reviewed by a lawyer · audit-grade · source verified 4 Oct 2026 · release 2026.10.05
Lane
Binding law — not yet in force or stayed Enacted, not yet applying: applies from 1 Jan 2027
Official source
C.R.S. 10-16-112.7(4) · captured 4 Oct 2026 · anchor hash (SHA-256) 315e6323ccc0… · 6 more anchors in the data release
Verification
Quoted text found word for word in the captured official document (4 Oct 2026). Source last verified 4 Oct 2026: checked against the captured official document; not in the weekly watcher's list; checked against the captured document.
Data release
Data release 2026.10.05, data as of 4 Oct 2026, schema 0.3.10.
Legal review
Not reviewed by a lawyer. TwinEthos derived this rule from the official text it cites: treat it as research to check against that text; it is not legal advice. No TwinEthos rule has been legally reviewed yet. Open questions for counsel on this rule: 1.
Audit standard
Audit-grade: meets all 10 checks of the TwinEthos audit standard that apply to it. The audit standard is TwinEthos's own quality bar for provenance, dates, applicability, detectors, fixtures, remediation and licences; it is not a legal review.
Detectors
1 detector (missing artifact), experimental: written from the rule's text and not yet measured for precision on real code, so treat a hit as a lead to verify.
Known limits:
Regulatory filings kept in a compliance system outside the repository
Who it applies to
Duty falls on: insurer, organization
Sectors: insurance, healthcare
Carriers that use an artificial intelligence system for utilization review, or contract with or otherwise work through a person that does; pharmacy benefit managers and private utilization review organizations that contract with a carrier to provide utilization review on its behalf and use such a system; and behavioral health administrative services organizations and managed care entities that use such a system for utilization review of mental or behavioral health services (C.R.S. 10-16-112.7(2)), in Colorado. 'Artificial intelligence system' has the meaning in 6-1-1701(2). Applies from 2027-01-01 to actions taken on or after that date (HB 26-1139 sec. 4).
Whether it applies depends on facts outside the code; a person has to decide.
The guard to add
Notify consumers when AI makes or supports their underwriting, rating, or claims decision, and list that model in the insurer's written AIS Program.
In the code path that calls a model for underwriting, rating, premium quoting, or claims decisions, send or render a consumer notice that AI systems are used (in the quote flow, claim acknowledgement, or decision letter) and record that it was delivered. The model is an entry in the insurer's written AIS Program, covering governance, risk-management controls, internal audit, lifecycle management, third-party systems, and an accountable leader, with an owner; keep the inventory entry or a pointer to it in the repository so each decision path is traceable to its program record.
Where it goes: 9 AI output handling, 14 user-facing text, 12 repository artifacts.
What this provision adds:
The disclosure names the utilization-review functions, the process points where the system is used, the human oversight process (reviewer qualifications; whether a human must approve an adverse determination) and the audit-information process.
AI_USE_NOTICE = ('An AI system helped evaluate your claim. '
'You can ask us how it was used and request review by a claims adjuster.')
resp = client.chat.completions.create(model=MODEL, messages=claim_msgs)
claim_decision = parse_decision(resp.choices[0].message.content)
claims.update(claim_id, status=claim_decision, ais_program_ref='AIS-012')
send_ai_notice(claimant, text=AI_USE_NOTICE)
Rule id co-hb26-1139.ai-use-disclosure-to-regulator · review status: primary source derived
Binding law — not yet in force or stayed
AI utilization review must produce and retain documentation, audit logs and model-governance records (Colorado HB 26-1139)
C.R.S. 10-16-112.7(3)(e) · official text · Enacted, not yet applying: applies from 1 Jan 2027 · Colorado (US-CO)
From 2027-01-01, a person that uses an artificial intelligence system to conduct utilization review must ensure that the system produces and retains documentation, audit logs and model-governance records in order to demonstrate compliance with 10-16-112.7 and 10-3-1104.9 (C.R.S. 10-16-112.7(3)(e)), and must disclose to the regulator its process for maintaining audit information sufficient to demonstrate compliance with subsection (3) ((4)(d)). Detect AI determinations stored without an audit record, and the absence of model-governance records.
Trust and provenancenot reviewed by a lawyer · audit-grade · source verified 4 Oct 2026 · release 2026.10.05
Lane
Binding law — not yet in force or stayed Enacted, not yet applying: applies from 1 Jan 2027
Official source
C.R.S. 10-16-112.7(3)(e) · captured 4 Oct 2026 · anchor hash (SHA-256) 7bdf304bed84… · 6 more anchors in the data release
Verification
Quoted text found word for word in the captured official document (4 Oct 2026). Source last verified 4 Oct 2026: checked against the captured official document; not in the weekly watcher's list; checked against the captured document.
Data release
Data release 2026.10.05, data as of 4 Oct 2026, schema 0.3.10.
Legal review
Not reviewed by a lawyer. TwinEthos derived this rule from the official text it cites: treat it as research to check against that text; it is not legal advice. No TwinEthos rule has been legally reviewed yet. Open questions for counsel on this rule: 1.
Audit standard
Audit-grade: meets all 10 checks of the TwinEthos audit standard that apply to it. The audit standard is TwinEthos's own quality bar for provenance, dates, applicability, detectors, fixtures, remediation and licences; it is not a legal review.
Detectors
2 detectors (code pattern, missing artifact), experimental: written from the rule's text and not yet measured for precision on real code, so treat a hit as a lead to verify.
Known limits:
Audit logging in a separate workflow service or data pipeline
Model-governance records (model cards, validation reports) kept outside the repository
The audit record may be written by middleware, a decorator or a persistence layer defined elsewhere; check that the determination path emits one before reporting. Audit tokens anywhere in the file suppress the finding,…
1 more known limit in the data release.
Who it applies to
Duty falls on: insurer, organization
Sectors: insurance, healthcare
Carriers that use an artificial intelligence system for utilization review, or contract with or otherwise work through a person that does; pharmacy benefit managers and private utilization review organizations that contract with a carrier to provide utilization review on its behalf and use such a system; and behavioral health administrative services organizations and managed care entities that use such a system for utilization review of mental or behavioral health services (C.R.S. 10-16-112.7(2)), in Colorado. 'Artificial intelligence system' has the meaning in 6-1-1701(2). Applies from 2027-01-01 to actions taken on or after that date (HB 26-1139 sec. 4).
Whether it applies depends on facts outside the code; a person has to decide.
The guard to add
Write a structured event record for every inference and decision of the high-risk system (when, model version, input reference, output, operator) to a log store with explicit retention.
An audit event emitted automatically by the service at the decision boundary, where model output becomes a status change, score, or response, rather than left to callers: decision_id, timestamp, model and resolved model_version, an input reference (a pointer rather than raw personal data where possible), the output, the operator or user identity, and any human verification. Events go to a central store (CloudWatch Logs, Log Analytics, Cloud Logging, Loki) whose retention is set explicitly in IaC, not left to a console default, and monitoring queries over those events flag risk situations and drift.
Where it goes: 1 application source code, 4 infrastructure-as-code, 10 logs and telemetry.
What this provision adds:
Keep the documentation, audit logs and model-governance records so that they show compliance with both 10-16-112.7 and 10-3-1104.9, and describe how audit information is maintained in the written disclosure to the regulator.
Example (Python + OpenAI SDK + structlog), before:
No guardrail sits on this exact control; these incidents are cited by guardrails on related controls.
Court compelled discovery on how nH Predict works (2026-03-09; confirmed). A federal magistrate judge in the District of Minnesota ordered UnitedHealth to produce documents on how nH Predict works, including whether it was designed to supplant physician decision-making. Plaintiffs needed litigation discovery to learn how the model was designed and used. Source: U.S. District Court, D. Minn. (Order, Doc. 162) · evidence grade: primary · cited by Record enough at decision time to reproduce and explain every consequential AI decision
Rule id co-hb26-1139.audit-logs-and-model-governance-records · review status: primary source derived
Binding law — not yet in force or stayed
No medical-necessity denial solely on AI output without review and approval by a competent licensed clinician (Colorado HB 26-1139)
C.R.S. 10-16-112.7(5)(b) · official text · Enacted, not yet applying: applies from 1 Jan 2027 · Colorado (US-CO)
From 2027-01-01, a carrier's denial of coverage based in whole or in part on medical necessity shall not be issued solely on the output of an artificial intelligence system without human review and approval of the denial by a licensed clinician, licensed physician or other regulated professional competent to evaluate the specific clinical issues involved in the services the provider requested, and a review of the health benefit plan's terms of coverage for the service (C.R.S. 10-16-112.7(5)(b)). An AI system may still be used to assist with utilization review, including expedited approvals ((5)(a)). Detect model or scoring output that sets a denial without a clinical reviewer's decision.
Trust and provenancenot reviewed by a lawyer · audit-grade · source verified 4 Oct 2026 · release 2026.10.05
Lane
Binding law — not yet in force or stayed Enacted, not yet applying: applies from 1 Jan 2027
Official source
C.R.S. 10-16-112.7(5)(b) · captured 4 Oct 2026 · anchor hash (SHA-256) 772d096f18cc… · 5 more anchors in the data release
Verification
Quoted text found word for word in the captured official document (4 Oct 2026). Source last verified 4 Oct 2026: checked against the captured official document; not in the weekly watcher's list; checked against the captured document.
Data release
Data release 2026.10.05, data as of 4 Oct 2026, schema 0.3.10.
Legal review
Not reviewed by a lawyer. TwinEthos derived this rule from the official text it cites: treat it as research to check against that text; it is not legal advice. No TwinEthos rule has been legally reviewed yet. Open questions for counsel on this rule: 1.
Audit standard
Audit-grade: meets all 10 checks of the TwinEthos audit standard that apply to it. The audit standard is TwinEthos's own quality bar for provenance, dates, applicability, detectors, fixtures, remediation and licences; it is not a legal review.
Detectors
1 detector (code pattern), experimental: written from the rule's text and not yet measured for precision on real code, so treat a hit as a lead to verify.
Known limits:
Review routing in a separate workflow service or BPM engine
Denials applied by a downstream claims system from an exported score
The clinical review may live in another module (a workflow engine or a separate review service); confirm the adverse status cannot be reached without it before reporting. Clinician tokens anywhere in the file suppress t…
Who it applies to
Duty falls on: insurer
Sectors: insurance, healthcare
Carriers (and the pharmacy benefit managers and private utilization review organizations that conduct utilization review on their behalf, C.R.S. 10-16-112.7(2)) issuing a denial of coverage based in whole or in part on medical necessity where an artificial intelligence system's output is used, in Colorado. Approvals, including expedited approvals, may be assisted by the system ((5)(a)). Applies from 2027-01-01 to actions taken on or after that date (HB 26-1139 sec. 4).
Not covered:
Approvals, including expedited approvals: an artificial intelligence system may be used to assist with utilization review (C.R.S. 10-16-112.7(5)(a)); only a denial based in whole or in part on medical necessity needs the clinician's review and approval ((5)(b))
Whether it applies depends on facts outside the code; a person has to decide.
The guard to add
Route every adverse outcome an AI or algorithm proposes in utilization review to a qualified clinical reviewer, and issue a denial only from that reviewer's recorded decision.
At the point where a model, rules engine or scoring tool returns its result for a prior-authorization, concurrent or retrospective review, the code may auto-approve (where the law allows) or route the case, but any result that would deny, delay, modify or downgrade the request is written as a pending clinical review (status 'pending_clinical_review', a review_queue entry with the tool's output attached as a recommendation), never as the determination. Only a review action by an authenticated reviewer whose role is physician, clinical peer or qualified reviewer, in the same or a similar specialty where the law requires, can set an adverse status; that action records reviewer_id, licence and specialty, the clinical documents opened, the decision and its clinical rationale, and the timestamp, and the adverse-determination notice is generated from it (with the reviewer's signature or attestation where the law requires). Where a law forbids the automated system from making an adverse determination even in part (Texas), the tool's output may only approve, route or support administrative and fraud-detection work; it is not shown to the reviewer as a proposed denial.
Where it goes: 1 application source code, 2 data models, 9 AI output handling, 14 user-facing text.
What this provision adds:
The approving reviewer is a licensed clinician, licensed physician or other regulated professional competent to evaluate the specific clinical issues of the requested services, and the review also covers the health benefit plan's terms of coverage for the service.
Example (Python + OpenAI SDK (prior-authorization service)), before:
result = client.chat.completions.create(model=MODEL, messages=build_pa_prompt(request)).choices[0].message.content
if json.loads(result)['decision'] == 'deny':
prior_auth.update(request.id, status='denied')
send_denial_letter(request)
After:
result = json.loads(client.chat.completions.create(
model=MODEL, messages=build_pa_prompt(request, record=member_clinical_record(request))).choices[0].message.content)
if result['decision'] == 'approve' and AUTO_APPROVE_ALLOWED:
prior_auth.update(request.id, status='approved', ai_assisted=True)
else: # any non-approval goes to a clinician
review_queue.enqueue(request.id, queue='pending_clinical_review',
specialty=request.specialty, ai_recommendation=result)
@app.post('/reviews/{case_id}/decision')
def record_clinical_decision(case_id: str, body: Decision, reviewer=Depends(licensed_clinical_reviewer)):
decision = clinical_decisions.create(case_id=case_id, reviewer_id=reviewer.id, licence=reviewer.licence,
specialty=reviewer.specialty, documents_reviewed=body.documents,
outcome=body.outcome, rationale=body.rationale)
if body.outcome in ('denied', 'downgraded'):
send_adverse_determination(case_id, decision=decision, signed_by=reviewer)
No guardrail sits on this exact control; these incidents are cited by guardrails on related controls.
UnitedHealth nH Predict claim-denial litigation (2023-11; alleged (not proven)). A class action filed in November 2023 alleges that UnitedHealth's nH Predict model had a 90% error rate, measured by denials reversed on appeal, while only about 0.2% of members appealed. UnitedHealth disputes the allegations; the litigation is ongoing. Source: STAT News · evidence grade: primary · cited by Monitor how often adverse AI decisions are reversed, and suspend models that are usually wrong
Cigna PXDX batch claim denials (reported) (2022; alleged (not proven)). ProPublica, citing internal Cigna records, reported that Cigna's PXDX system was used to reject more than 300,000 claims over two months in 2022, with physicians spending an average of 1.2 seconds on each. Cigna disputes the reporting; related lawsuits are ongoing. Source: ProPublica / The Capitol Forum · evidence grade: press of record · cited by Make human review of adverse AI decisions substantive, not nominal
Rule id co-hb26-1139.clinician-approves-medical-necessity-denial · review status: primary source derived
Binding law — not yet in force or stayed
AI utilization review must not discriminate unlawfully, must be fairly applied and must be periodically reviewed (Colorado HB 26-1139)
C.R.S. 10-16-112.7(3)(c) · official text · Enacted, not yet applying: applies from 1 Jan 2027 · Colorado (US-CO)
From 2027-01-01, a person that uses an artificial intelligence system to conduct utilization review must ensure that the system is not used in any way that discriminates against individuals in violation of other state or federal laws (C.R.S. 10-16-112.7(3)(c)), that it is fairly and equitably applied, including in accordance with applicable regulations and guidance of the federal Department of Health and Human Services ((3)(d)), and that its performance, use and outcomes are periodically reviewed to maximize accuracy and reliability ((3)(f)). Detect the absence of a periodic accuracy, outcome and disparity review.
Trust and provenancenot reviewed by a lawyer · audit-grade · source verified 4 Oct 2026 · release 2026.10.05
Lane
Binding law — not yet in force or stayed Enacted, not yet applying: applies from 1 Jan 2027
Official source
C.R.S. 10-16-112.7(3)(c) · captured 4 Oct 2026 · anchor hash (SHA-256) 98a5e8423341… · 7 more anchors in the data release
Verification
Quoted text found word for word in the captured official document (4 Oct 2026). Source last verified 4 Oct 2026: checked against the captured official document; not in the weekly watcher's list; checked against the captured document.
Data release
Data release 2026.10.05, data as of 4 Oct 2026, schema 0.3.10.
Legal review
Not reviewed by a lawyer. TwinEthos derived this rule from the official text it cites: treat it as research to check against that text; it is not legal advice. No TwinEthos rule has been legally reviewed yet. Open questions for counsel on this rule: 1.
Audit standard
Audit-grade: meets all 10 checks of the TwinEthos audit standard that apply to it. The audit standard is TwinEthos's own quality bar for provenance, dates, applicability, detectors, fixtures, remediation and licences; it is not a legal review.
Detectors
1 detector (missing artifact), experimental: written from the rule's text and not yet measured for precision on real code, so treat a hit as a lead to verify.
Known limits:
Reviews kept in a governance system outside the repository
Who it applies to
Duty falls on: insurer, organization
Sectors: insurance, healthcare
Carriers that use an artificial intelligence system for utilization review, or contract with or otherwise work through a person that does; pharmacy benefit managers and private utilization review organizations that contract with a carrier to provide utilization review on its behalf and use such a system; and behavioral health administrative services organizations and managed care entities that use such a system for utilization review of mental or behavioral health services (C.R.S. 10-16-112.7(2)), in Colorado. 'Artificial intelligence system' has the meaning in 6-1-1701(2). Applies from 2027-01-01 to actions taken on or after that date (HB 26-1139 sec. 4).
Whether it applies depends on facts outside the code; a person has to decide.
The guard to add
Compute per-group accuracy and bias metrics in the training pipeline of every consequential-decision model, keep the results per version, and rerun them on a schedule.
A validation stage that runs whenever a decision model is trained, fine-tuned, or retrained (the same module or pipeline step as fit(), Trainer, xgb.train, or fine_tuning.jobs.create) and again on a recurring schedule against recent decisions: accuracy and error rates per group, selection rates and disparity metrics (fairlearn MetricFrame, demographic_parity_difference, AIF360 disparate impact), and drift. Results go to a versioned validation report alongside a datasheet or data card for the training data, and a threshold gate blocks promotion of a model version whose metrics regress until a named owner reviews and records a decision. The validation cadence and owner are written in the model's validation record.
Where it goes: 1 application source code, 11 CI/CD pipeline, 12 repository artifacts, 13 tests and evals.
What this provision adds:
Review the system's performance, use and outcomes periodically (the act sets no cadence) and check application against applicable HHS regulations and guidance.
No guardrail sits on this exact control; these incidents are cited by guardrails on related controls.
Meta's automated moderation over-enforced Arabic and under-enforced Hebrew content (BSR due diligence) (2021-05; disclosed by the operator). An independent human rights due diligence by BSR, commissioned and published by Meta on September 22, 2022, found that during the May 2021 Israel-Palestine escalation Arabic content saw greater over-enforcement per user than Hebrew content and Hebrew content greater under-enforcement. BSR attributes this in part to Meta having an Arabic hostile-speech classifier but no Hebrew one, and to Arabic classifiers likely being less accurate for Palestinian Arabic. BSR found no intentional bias but 'various instances of unintentional bias' with different impacts on Palestinian and Arabic-speaking users. Meta committed to implement 10 of BSR's 21 recommendations and said it had since launched a Hebrew hostile-speech classifier. Source: Meta (operator response, 2022-09-22) · evidence grade: primary · cited by Check AI ranking, pricing, moderation, and ad targeting for disparities when features can stand in for protected traits, and screen every served language
Google ads suggesting arrest records served more often for Black-identifying names (2012; confirmed). Harvard researcher Latanya Sweeney searched 2,184 racially associated full names on google.com and reuters.com (a Google AdSense host) from September 24 to October 23, 2012 and found ads suggestive of an arrest record appeared more often for Black-identifying first names; on reuters.com a Black-identifying name was 25% more likely to get such an ad (statistically significant). Ads appeared regardless of whether the name had an arrest record in the advertiser's database. The paper does not determine whether the advertiser's templates or Google's click-based ad optimization caused the pattern; the advertiser, Instant Checkmate, told the author it gave Google the same ad text for groups of last names. Source: Sweeney, 'Discrimination in Online Ad Delivery' (original researcher, 2013-01-28) · evidence grade: primary · cited by Check AI ranking, pricing, moderation, and ad targeting for disparities when features can stand in for protected traits, and screen every served language
Rule id co-hb26-1139.fair-application-and-periodic-review · review status: primary source derived
Binding law — not yet in force or stayed
AI utilization review must rest on the individual's clinical history and record, not solely on group data (Colorado HB 26-1139)
C.R.S. 10-16-112.7(3)(a) · official text · Enacted, not yet applying: applies from 1 Jan 2027 · Colorado (US-CO)
From 2027-01-01, a carrier, pharmacy benefit manager, private utilization review organization, behavioral health administrative services organization or managed care entity that uses an artificial intelligence system to conduct utilization review must ensure that the system bases its determination, as applicable, on the individual's medical or other clinical history, the individual clinical circumstances as presented by the requesting provider, and other relevant clinical information in the individual's medical or other clinical record (C.R.S. 10-16-112.7(3)(a)), and does not base its determinations solely on group data, without reference to the individual's data ((3)(b)). Detect utilization-review model calls built without the member's clinical record or the provider's submission.
Trust and provenancenot reviewed by a lawyer · audit-grade · source verified 4 Oct 2026 · release 2026.10.05
Lane
Binding law — not yet in force or stayed Enacted, not yet applying: applies from 1 Jan 2027
Official source
C.R.S. 10-16-112.7(3)(a) · captured 4 Oct 2026 · anchor hash (SHA-256) 266f2935eaa2… · 6 more anchors in the data release
Verification
Quoted text found word for word in the captured official document (4 Oct 2026). Source last verified 4 Oct 2026: checked against the captured official document; not in the weekly watcher's list; checked against the captured document.
Data release
Data release 2026.10.05, data as of 4 Oct 2026, schema 0.3.10.
Legal review
Not reviewed by a lawyer. TwinEthos derived this rule from the official text it cites: treat it as research to check against that text; it is not legal advice. No TwinEthos rule has been legally reviewed yet. Open questions for counsel on this rule: 1.
Audit standard
Audit-grade: meets all 10 checks of the TwinEthos audit standard that apply to it. The audit standard is TwinEthos's own quality bar for provenance, dates, applicability, detectors, fixtures, remediation and licences; it is not a legal review.
Detectors
1 detector (code pattern), experimental: written from the rule's text and not yet measured for precision on real code, so treat a hit as a lead to verify.
Known limits:
Prompt builders imported from another module
Feature stores whose columns are not named in the code
The clinical record may be assembled in a helper module and passed in under a generic name; trace the prompt or feature builder before reporting.
Who it applies to
Duty falls on: insurer, organization
Sectors: insurance, healthcare
Carriers that use an artificial intelligence system for utilization review, or contract with or otherwise work through a person that does; pharmacy benefit managers and private utilization review organizations that contract with a carrier to provide utilization review on its behalf and use such a system; and behavioral health administrative services organizations and managed care entities that use such a system for utilization review of mental or behavioral health services (C.R.S. 10-16-112.7(2)), in Colorado. 'Artificial intelligence system' has the meaning in 6-1-1701(2). Applies from 2027-01-01 to actions taken on or after that date (HB 26-1139 sec. 4).
Whether it applies depends on facts outside the code; a person has to decide.
The guard to add
Build each automated medical-necessity determination from the enrollee's own clinical record and the provider's submission, and refuse to decide on group statistics alone.
In the prompt builder or feature pipeline for each medical-necessity or coverage determination, load the enrollee's clinical history and the requesting provider's clinical documentation for this request (the attached notes, the FHIR Condition, Observation and DocumentReference resources for the member, the provider's letter of medical necessity) and pass the fields the decision needs; group or population data (a diagnosis code's typical length of stay, a cohort's approval rate, a regional benchmark) may be context but never the only input. A guard before the model or rules call raises an error, or routes the case to clinical review, when the individual clinical inputs are empty, and the inputs used are saved with the result so a reviewer or regulator can see what the determination rested on.
Where it goes: 1 application source code, 2 data models, 7 prompt construction, 9 AI output handling.
What this provision adds:
Build the determination from the individual's medical or other clinical history, the clinical circumstances the requesting provider presents and other relevant information in the individual's record, as applicable; group data may inform it but never stand alone.
record = member_clinical_record(req.member_id, fields=PA_CLINICAL_FIELDS) # history, conditions, meds
submission = provider_clinical_submission(req.id) # notes, letter of medical necessity
if not record or not submission:
return review_queue.enqueue(req.id, reason='individual clinical information missing')
reply = client.messages.create(model=MODEL, max_tokens=400, messages=[{'role': 'user', 'content':
render('pa_review.txt', request=req, clinical_history=record, provider_submission=submission)}])
determinations.save(req.id, inputs={'clinical_history': record.ids, 'submission': submission.ids})
No guardrail sits on this exact control; these incidents are cited by guardrails on related controls.
Meta's automated moderation over-enforced Arabic and under-enforced Hebrew content (BSR due diligence) (2021-05; disclosed by the operator). An independent human rights due diligence by BSR, commissioned and published by Meta on September 22, 2022, found that during the May 2021 Israel-Palestine escalation Arabic content saw greater over-enforcement per user than Hebrew content and Hebrew content greater under-enforcement. BSR attributes this in part to Meta having an Arabic hostile-speech classifier but no Hebrew one, and to Arabic classifiers likely being less accurate for Palestinian Arabic. BSR found no intentional bias but 'various instances of unintentional bias' with different impacts on Palestinian and Arabic-speaking users. Meta committed to implement 10 of BSR's 21 recommendations and said it had since launched a Hebrew hostile-speech classifier. Source: Meta (operator response, 2022-09-22) · evidence grade: primary · cited by Check AI ranking, pricing, moderation, and ad targeting for disparities when features can stand in for protected traits, and screen every served language
Google ads suggesting arrest records served more often for Black-identifying names (2012; confirmed). Harvard researcher Latanya Sweeney searched 2,184 racially associated full names on google.com and reuters.com (a Google AdSense host) from September 24 to October 23, 2012 and found ads suggestive of an arrest record appeared more often for Black-identifying first names; on reuters.com a Black-identifying name was 25% more likely to get such an ad (statistically significant). Ads appeared regardless of whether the name had an arrest record in the advertiser's database. The paper does not determine whether the advertiser's templates or Google's click-based ad optimization caused the pattern; the advertiser, Instant Checkmate, told the author it gave Google the same ad text for groups of last names. Source: Sweeney, 'Discrimination in Online Ad Delivery' (original researcher, 2013-01-28) · evidence grade: primary · cited by Check AI ranking, pricing, moderation, and ad targeting for disparities when features can stand in for protected traits, and screen every served language
Rule id co-hb26-1139.individual-clinical-data-basis · review status: primary source derived
Binding law — not yet in force or stayed
Health data used in AI utilization review must not be used beyond its intended or stated purpose (Colorado HB 26-1139)
C.R.S. 10-16-112.7(3)(g) · official text · Enacted, not yet applying: applies from 1 Jan 2027 · Colorado (US-CO)
From 2027-01-01, a person that uses an artificial intelligence system to conduct utilization review must ensure that an individual's health data is not used beyond its intended or stated purpose, consistent with applicable state and federal laws (C.R.S. 10-16-112.7(3)(g)). Detect utilization-review patient data exported to model training or fine-tuning, marketing lists or product analytics.
Trust and provenancenot reviewed by a lawyer · audit-grade · source verified 4 Oct 2026 · release 2026.10.05
Lane
Binding law — not yet in force or stayed Enacted, not yet applying: applies from 1 Jan 2027
Official source
C.R.S. 10-16-112.7(3)(g) · captured 4 Oct 2026 · anchor hash (SHA-256) 5406d85fc74e… · 5 more anchors in the data release
Verification
Quoted text found word for word in the captured official document (4 Oct 2026). Source last verified 4 Oct 2026: checked against the captured official document; not in the weekly watcher's list; checked against the captured document.
Data release
Data release 2026.10.05, data as of 4 Oct 2026, schema 0.3.10.
Legal review
Not reviewed by a lawyer. TwinEthos derived this rule from the official text it cites: treat it as research to check against that text; it is not legal advice. No TwinEthos rule has been legally reviewed yet. Open questions for counsel on this rule: 1.
Audit standard
Audit-grade: meets all 10 checks of the TwinEthos audit standard that apply to it. The audit standard is TwinEthos's own quality bar for provenance, dates, applicability, detectors, fixtures, remediation and licences; it is not a legal review.
Detectors
1 detector (code pattern), experimental: written from the rule's text and not yet measured for precision on real code, so treat a hit as a lead to verify.
Known limits:
Exports run from notebooks or warehouse jobs outside the repository
A training export may be lawful where the stated purpose and HIPAA permit it (for example quality improvement under a business associate agreement); check the documented purpose before reporting.
Who it applies to
Duty falls on: insurer, organization
Sectors: insurance, healthcare
Carriers that use an artificial intelligence system for utilization review, or contract with or otherwise work through a person that does; pharmacy benefit managers and private utilization review organizations that contract with a carrier to provide utilization review on its behalf and use such a system; and behavioral health administrative services organizations and managed care entities that use such a system for utilization review of mental or behavioral health services (C.R.S. 10-16-112.7(2)), in Colorado. 'Artificial intelligence system' has the meaning in 6-1-1701(2). Applies from 2027-01-01 to actions taken on or after that date (HB 26-1139 sec. 4).
Whether it applies depends on facts outside the code; a person has to decide.
The guard to add
Send identifiable health data only to AI endpoints registered with a signed BAA or processing agreement and retention and training off; otherwise de-identify first.
A single client factory for model, embedding and transcription calls that handle health information: it looks the endpoint up in a vendor register and refuses to return a client unless the register shows the required contract (business associate agreement, or a processing agreement barring further disclosure) and the endpoint is the covered deployment with data retention and training use turned off. Call sites that cannot meet that de-identify or redact the record before building the prompt, or check a recorded patient authorization for that use. Keep the vendor register in the repository so reviewers can match each AI endpoint to its legal basis, and never route health data into marketing or other non-care generation.
Where it goes: 6 API calls and integrations, 3 config and feature flags, 7 prompt construction, 12 repository artifacts.
Example (Python + OpenAI SDK (Azure OpenAI)), before:
Rule id co-hb26-1139.patient-data-purpose-limit · review status: primary source derived
Informational data, not legal advice. Summaries are TwinEthos's own words and rules have not been reviewed by a lawyer: check the official text before relying on any of it. A guard addresses an item; adding it is not a statement that your code meets any law.