TwinEthos homeAPI access

Law

Iowa HF 2635 (2026 Iowa Acts ch. 1087; Iowa Code 514F.8(2A), 514F.8A)

Iowa Insurance Division (Commissioner of Insurance) · Iowa (US-IA) · 2 provisions encoded · verified against the official source as of 2026-10-03.

Informational data, not legal advice. Summaries and rules have not been reviewed by a lawyer: always verify official law text for decisions. A suggested guard is intended to address each rule; adding it is not a statement of compliance to that law.

Official text: www.legis.iowa.gov.

Trust and provenance 3 official sources · last verified 3 Oct 2026 · not reviewed by a lawyer · 2 of 2 provisions audit-grade · release 2026.10.03.4

Where this instrument's data comes from, how current it is, and what has and has not been checked. Each provision below has its own panel.

Official sources
Lanes
Binding law — in force 1 Binding law — not yet in force or stayed 1
Verification
Sources last verified 3 Oct 2026; each provision states how.
Data release
Data release 2026.10.03.4, data as of 3 Oct 2026, schema 0.3.9.
Legal review
None of the 2 provisions has been reviewed by a lawyer; no TwinEthos rule has been legally reviewed yet. Treat each as research to check against the official text; it is not legal advice. Open questions for counsel on them: 2.
Audit standard
2 of 2 provisions audit-grade. The audit standard is TwinEthos's own quality bar for provenance, dates, applicability, detectors, fixtures, remediation and licences; it is not a legal review.
Detectors
3 detectors, all experimental: written from the rule's text and not yet measured for precision on real code, so treat a hit as a lead to verify. Each provision lists its detectors' known limits.
Changes
  • 2026.10.03.4 (3 Oct 2026): 2 provisions added

Each data release records which provisions changed; the full list is on Changes.

Binding law — in force

AI may give an initial prior-authorization review but may not be the sole basis to deny, delay or downgrade (Iowa HF 2635)

2026 Iowa Acts ch. 1087, sec. 2 (Iowa Code 514F.8(2A)) · official text · In force: applies since 1 Jul 2026 · Iowa (US-IA)

From 2026-07-01, a utilization review organization may use an artificial intelligence-based algorithm or system to provide an initial review of a request for prior authorization, but for a prior-authorization request for a health care service based on medical necessity it shall not use such an algorithm or system as the sole basis for its decision to deny, delay or downgrade the request (Iowa Code 514F.8(2A), added by 2026 Iowa Acts ch. 1087, sec. 2; a downgrade changes an expedited or urgent request to a standard determination or modifies the service to a lower level). Detect automated output that sets a denial, delay or downgrade without a clinical reviewer's decision.

Trust and provenance not reviewed by a lawyer · audit-grade · source verified 3 Oct 2026 · release 2026.10.03.4
Lane
Binding law — in force In force: applies since 1 Jul 2026
Official source
2026 Iowa Acts ch. 1087, sec. 2 (Iowa Code 514F.8(2A)) · captured 3 Oct 2026 · anchor hash (SHA-256) ebde828bcb0e… · 7 more anchors in the data release
Verification
Quoted text found word for word in the captured official document (3 Oct 2026). Source last verified 3 Oct 2026: checked against the captured official document.
Data release
Data release 2026.10.03.4, data as of 3 Oct 2026, schema 0.3.9.
Legal review
Not reviewed by a lawyer. TwinEthos derived this rule from the official text it cites: treat it as research to check against that text; it is not legal advice. No TwinEthos rule has been legally reviewed yet. Open questions for counsel on this rule: 1.
Audit standard
Audit-grade: meets all 10 checks of the TwinEthos audit standard that apply to it. The audit standard is TwinEthos's own quality bar for provenance, dates, applicability, detectors, fixtures, remediation and licences; it is not a legal review.
Detectors

1 detector (code pattern), experimental: written from the rule's text and not yet measured for precision on real code, so treat a hit as a lead to verify.

Known limits:

  • Review routing in a separate workflow service or BPM engine
  • Denials applied by a downstream claims system from an exported score
  • The clinical review may live in another module (a workflow engine or a separate review service); confirm the adverse status cannot be reached without it before reporting. Clinician tokens anywhere in the file suppress t…

Who it applies to

  • Duty falls on: insurer, organization
  • Sectors: insurance, healthcare
  • Utilization review organizations (entities performing utilization review, including health carriers accredited by URAC or NCQA performing it for their own plans) reviewing prior-authorization requests for Iowa covered persons. In force 2026-07-01 (2026 Iowa Acts ch. 1087, sec. 2, with Iowa Code 3.7(1)).
  • Whether it applies depends on facts outside the code; a person has to decide.

The guard to add

Route every adverse outcome an AI or algorithm proposes in utilization review to a qualified clinical reviewer, and issue a denial only from that reviewer's recorded decision.

At the point where a model, rules engine or scoring tool returns its result for a prior-authorization, concurrent or retrospective review, the code may auto-approve (where the law allows) or route the case, but any result that would deny, delay, modify or downgrade the request is written as a pending clinical review (status 'pending_clinical_review', a review_queue entry with the tool's output attached as a recommendation), never as the determination. Only a review action by an authenticated reviewer whose role is physician, clinical peer or qualified reviewer, in the same or a similar specialty where the law requires, can set an adverse status; that action records reviewer_id, licence and specialty, the clinical documents opened, the decision and its clinical rationale, and the timestamp, and the adverse-determination notice is generated from it (with the reviewer's signature or attestation where the law requires). Where a law forbids the automated system from making an adverse determination even in part (Texas), the tool's output may only approve, route or support administrative and fraud-detection work; it is not shown to the reviewer as a proposed denial.

Where it goes: 1 application source code, 2 data models, 9 AI output handling, 14 user-facing text.

Example (Python + OpenAI SDK (prior-authorization service)), before:

result = client.chat.completions.create(model=MODEL, messages=build_pa_prompt(request)).choices[0].message.content
if json.loads(result)['decision'] == 'deny':
    prior_auth.update(request.id, status='denied')
    send_denial_letter(request)

After:

result = json.loads(client.chat.completions.create(
    model=MODEL, messages=build_pa_prompt(request, record=member_clinical_record(request))).choices[0].message.content)
if result['decision'] == 'approve' and AUTO_APPROVE_ALLOWED:
    prior_auth.update(request.id, status='approved', ai_assisted=True)
else:                                   # any non-approval goes to a clinician
    review_queue.enqueue(request.id, queue='pending_clinical_review',
                         specialty=request.specialty, ai_recommendation=result)

@app.post('/reviews/{case_id}/decision')
def record_clinical_decision(case_id: str, body: Decision, reviewer=Depends(licensed_clinical_reviewer)):
    decision = clinical_decisions.create(case_id=case_id, reviewer_id=reviewer.id, licence=reviewer.licence,
                                         specialty=reviewer.specialty, documents_reviewed=body.documents,
                                         outcome=body.outcome, rationale=body.rationale)
    if body.outcome in ('denied', 'downgraded'):
        send_adverse_determination(case_id, decision=decision, signed_by=reviewer)

Control: AI or algorithm denies, delays or downgrades care in utilization review without a licensed clinical reviewer deciding. The same guard addresses 9 items with binding law in 8 jurisdictions. Engineering guidance, not legal advice.

Related incidents

No guardrail sits on this exact control; these incidents are cited by guardrails on related controls.

Rule id ia-hf2635.ai-not-sole-basis-for-denial · review status: primary source derived

Binding law — not yet in force or stayed

Denials and downgrades are made and signed by a qualified reviewer or clinical peer, with an attestation of qualifications (Iowa HF 2635)

2026 Iowa Acts ch. 1087, sec. 6 (Iowa Code 514F.8A(2)) · official text · Enacted, not yet applying: applies from 1 Jan 2027 · Iowa (US-IA)

For prior-authorization requests made on or after 2027-01-01 under plans delivered, issued, continued or renewed in Iowa on or after that date (Iowa Code 514F.8A(5)-(6)), a utilization review organization shall not deny or downgrade a request unless the decision is made by a qualified reviewer (a physician in the same or a similar specialty with the training and expertise to treat the condition) where the requester is a physician, or a clinical peer where not, and it gives the provider a written statement citing the specific reasons and criteria, signed by that reviewer, a written explanation of the appeals process (also to the covered person) and a written attestation of the reviewer's specialty, training, board certifications and education (514F.8A(2)). Detect automated denials without a reviewer decision and denial statements generated without the reviewer's signature or attestation.

Trust and provenance not reviewed by a lawyer · audit-grade · source verified 3 Oct 2026 · release 2026.10.03.4
Lane
Binding law — not yet in force or stayed Enacted, not yet applying: applies from 1 Jan 2027
Official source
2026 Iowa Acts ch. 1087, sec. 6 (Iowa Code 514F.8A(2)) · captured 3 Oct 2026 · anchor hash (SHA-256) c58bcbe201cf… · 10 more anchors in the data release
Verification
Quoted text found word for word in the captured official document (3 Oct 2026). Source last verified 3 Oct 2026: checked against the captured official document.
Data release
Data release 2026.10.03.4, data as of 3 Oct 2026, schema 0.3.9.
Legal review
Not reviewed by a lawyer. TwinEthos derived this rule from the official text it cites: treat it as research to check against that text; it is not legal advice. No TwinEthos rule has been legally reviewed yet. Open questions for counsel on this rule: 1.
Audit standard
Audit-grade: meets all 10 checks of the TwinEthos audit standard that apply to it. The audit standard is TwinEthos's own quality bar for provenance, dates, applicability, detectors, fixtures, remediation and licences; it is not a legal review.
Detectors

2 detectors (code pattern), experimental: written from the rule's text and not yet measured for precision on real code, so treat a hit as a lead to verify.

Known limits:

  • Review routing in a separate workflow service or BPM engine
  • Denials applied by a downstream claims system from an exported score
  • The clinical review may live in another module (a workflow engine or a separate review service); confirm the adverse status cannot be reached without it before reporting. Clinician tokens anywhere in the file suppress t…

2 more known limits in the data release.

Who it applies to

  • Duty falls on: insurer, organization
  • Sectors: insurance, healthcare
  • Utilization review organizations deciding prior-authorization requests made on or after 2027-01-01 under individual or group accident and sickness insurance (expense-incurred), hospital or medical service contracts (chapters 509, 514, 514A), HMO contracts (chapter 514B) and public-employee plans (chapter 509A) delivered, issued for delivery, continued or renewed in Iowa on or after 2027-01-01.
  • Not covered:
    • Accident-only, specified disease, short-term hospital or medical, hospital confinement indemnity, credit, dental, vision, Medicare supplement, long-term care, basic hospital and medical-surgical expense, disability income, supplemental-to-liability, workers' compensation or similar, and automobile medical payment coverage (Iowa Code 514F.8A(6)(b))
  • Whether it applies depends on facts outside the code; a person has to decide.

The guard to add

Route every adverse outcome an AI or algorithm proposes in utilization review to a qualified clinical reviewer, and issue a denial only from that reviewer's recorded decision.

At the point where a model, rules engine or scoring tool returns its result for a prior-authorization, concurrent or retrospective review, the code may auto-approve (where the law allows) or route the case, but any result that would deny, delay, modify or downgrade the request is written as a pending clinical review (status 'pending_clinical_review', a review_queue entry with the tool's output attached as a recommendation), never as the determination. Only a review action by an authenticated reviewer whose role is physician, clinical peer or qualified reviewer, in the same or a similar specialty where the law requires, can set an adverse status; that action records reviewer_id, licence and specialty, the clinical documents opened, the decision and its clinical rationale, and the timestamp, and the adverse-determination notice is generated from it (with the reviewer's signature or attestation where the law requires). Where a law forbids the automated system from making an adverse determination even in part (Texas), the tool's output may only approve, route or support administrative and fraud-detection work; it is not shown to the reviewer as a proposed denial.

Where it goes: 1 application source code, 2 data models, 9 AI output handling, 14 user-facing text.

What this provision adds:

  • The deciding reviewer signs a statement of the specific reasons and criteria; send an appeals explanation to the provider and the covered person and an attestation of the reviewer's specialty, board certifications and education.

Example (Python + OpenAI SDK (prior-authorization service)), before:

result = client.chat.completions.create(model=MODEL, messages=build_pa_prompt(request)).choices[0].message.content
if json.loads(result)['decision'] == 'deny':
    prior_auth.update(request.id, status='denied')
    send_denial_letter(request)

After:

result = json.loads(client.chat.completions.create(
    model=MODEL, messages=build_pa_prompt(request, record=member_clinical_record(request))).choices[0].message.content)
if result['decision'] == 'approve' and AUTO_APPROVE_ALLOWED:
    prior_auth.update(request.id, status='approved', ai_assisted=True)
else:                                   # any non-approval goes to a clinician
    review_queue.enqueue(request.id, queue='pending_clinical_review',
                         specialty=request.specialty, ai_recommendation=result)

@app.post('/reviews/{case_id}/decision')
def record_clinical_decision(case_id: str, body: Decision, reviewer=Depends(licensed_clinical_reviewer)):
    decision = clinical_decisions.create(case_id=case_id, reviewer_id=reviewer.id, licence=reviewer.licence,
                                         specialty=reviewer.specialty, documents_reviewed=body.documents,
                                         outcome=body.outcome, rationale=body.rationale)
    if body.outcome in ('denied', 'downgraded'):
        send_adverse_determination(case_id, decision=decision, signed_by=reviewer)

Control: AI or algorithm denies, delays or downgrades care in utilization review without a licensed clinical reviewer deciding. The same guard addresses 9 items with binding law in 8 jurisdictions. Engineering guidance, not legal advice.

Related incidents

No guardrail sits on this exact control; these incidents are cited by guardrails on related controls.

Rule id ia-hf2635.qualified-reviewer-signed-denial · review status: primary source derived

Informational data, not legal advice. Summaries are TwinEthos's own words and rules have not been reviewed by a lawyer: check the official text before relying on any of it. A guard addresses an item; adding it is not a statement that your code meets any law.