TwinEthos homeAPI access

Law

Illinois HB 2472 (P.A. 103-0656; Managed Care Reform and Patient Rights Act, 215 ILCS 134)

Illinois Department of Insurance · Illinois (US-IL) · 2 provisions encoded · verified against the official source as of 2026-10-03.

Informational data, not legal advice. Summaries and rules have not been reviewed by a lawyer: always verify official law text for decisions. A suggested guard is intended to address each rule; adding it is not a statement of compliance to that law.

Official text: www.ilga.gov.

Trust and provenance 4 official sources · last verified 3 Oct 2026 · not reviewed by a lawyer · 2 of 2 provisions audit-grade · release 2026.10.03.4

Where this instrument's data comes from, how current it is, and what has and has not been checked. Each provision below has its own panel.

Official sources
Lanes
Binding law — in force 2
Verification
Sources last verified 3 Oct 2026; each provision states how.
Data release
Data release 2026.10.03.4, data as of 3 Oct 2026, schema 0.3.9.
Legal review
None of the 2 provisions has been reviewed by a lawyer; no TwinEthos rule has been legally reviewed yet. Treat each as research to check against the official text; it is not legal advice. Open questions for counsel on them: 3.
Audit standard
2 of 2 provisions audit-grade. The audit standard is TwinEthos's own quality bar for provenance, dates, applicability, detectors, fixtures, remediation and licences; it is not a legal review.
Detectors
3 detectors, all experimental: written from the rule's text and not yet measured for precision on real code, so treat a hit as a lead to verify. Each provision lists its detectors' known limits.
Changes
  • 2026.10.03.4 (3 Oct 2026): 2 provisions added

Each data release records which provisions changed; the full list is on Changes.

Binding law — in force

Algorithmic review must use physician-set criteria, verified by board-certified physicians before changes and after errors (Illinois HB 2472)

215 ILCS 134/85(b-10) · official text · In force: applies since 1 Jan 2025 · Illinois (US-IL)

From 2025-01-01, utilization review programs that use algorithmic automated processes to decide whether to render adverse determinations based on medical necessity must use objective, evidence-based criteria compliant with URAC or NCQA accreditation requirements and prove compliance with each registration (215 ILCS 134/85(b-10), (a)); the registration must attach policies and procedures (1) ensuring that licensed physicians with relevant board certifications establish all criteria the process uses and (2) for a program integrity system that, before new or revised criteria are used and when implementation errors are found, requires such physicians to verify that the process and its corrections yield results consistent with the criteria for their certified field. A plan or program using an automated process must have that accreditation and those policies (45(i)). Detect the absence of physician criteria sign-off and pre-release integrity verification.

Trust and provenance not reviewed by a lawyer · audit-grade · source verified 3 Oct 2026 · release 2026.10.03.4
Lane
Binding law — in force In force: applies since 1 Jan 2025
Official source
215 ILCS 134/85(b-10) · captured 3 Oct 2026 · anchor hash (SHA-256) 9be9ea68cc49… · 12 more anchors in the data release
Verification
Quoted text found word for word in the captured official document (3 Oct 2026). Source last verified 3 Oct 2026: checked against the captured official document.
Data release
Data release 2026.10.03.4, data as of 3 Oct 2026, schema 0.3.9.
Legal review
Not reviewed by a lawyer. TwinEthos derived this rule from the official text it cites: treat it as research to check against that text; it is not legal advice. No TwinEthos rule has been legally reviewed yet. Open questions for counsel on this rule: 1.
Audit standard
Audit-grade: meets all 10 checks of the TwinEthos audit standard that apply to it. The audit standard is TwinEthos's own quality bar for provenance, dates, applicability, detectors, fixtures, remediation and licences; it is not a legal review.
Detectors

1 detector (missing artifact), experimental: written from the rule's text and not yet measured for precision on real code, so treat a hit as a lead to verify.

Known limits:

  • Verification run in a vendor's environment

Who it applies to

  • Duty falls on: insurer, organization
  • Sectors: insurance, healthcare
  • Health care plans (HMOs, managed care community networks and accountable care entities with a provider network) and any person conducting a utilization review program in Illinois (registered with the Department of Insurance) that uses an algorithmic automated process in utilization review for medical necessity. In force 2025-01-01.
  • Not covered:
    • Section 85 does not apply to persons providing utilization review program services only to the federal government (215 ILCS 134/85(c)(1))
    • Section 85 does not apply to self-insured ERISA health plans, though it applies to persons conducting utilization review on their behalf (85(c)(2))
    • Section 85 does not apply to hospitals and medical groups performing utilization review for internal purposes unless conducted for another person (85(c)(3))
    • 'Health care plan' (Section 45) excludes indemnity policies (including those with a contracted network), dental-only and vision-only plans, preferred provider administrators, self-insured ERISA plans, workers' compensation care and certain union-affiliated plans (134/10)
  • Whether it applies depends on facts outside the code; a person has to decide.

The guard to add

Pin dated model versions and run a blocking behavior and safety eval in CI whenever model ids, prompts, or inference settings change, then keep monitoring quality in production.

Reference models by dated snapshot ids in one config file instead of floating aliases (-latest, -preview, undated names), so the model changes only through a commit. A CI job triggered by changes to that file, the prompt files, and inference settings (sampling, quantization, routing, provider) runs the behavior and safety eval suite (promptfoo, deepeval, inspect_ai, or openai/evals) and blocks merge or release on regression. A scheduled online eval or canary, plus quality and refusal-rate alerts on production gen_ai spans, catches provider-side changes that no pre-release gate can see.

Where it goes: 3 config and feature flags, 8 model configuration, 11 CI/CD pipeline, 13 tests and evals.

What this provision adds:

  • Attach the criteria and program-integrity policies to the Department registration (every 2 years) and to each renewal.

Example (App model config), before:

llm:
  model: gpt-4o
  temperature: 0.7

After:

llm:
  model: gpt-4o-2024-08-06     # change only via PR; triggers the eval workflow
  temperature: 0.7

Control: Model, version, or serving change reaches users without re-running behavior and safety evaluations. The same guard addresses 3 items with binding law in 1 jurisdiction. Engineering guidance, not legal advice.

Standards that recommend the same control

Related incidents

  • Serving-stack changes silently degraded Claude output quality (2025-08; disclosed by the operator). Anthropic reports that three infrastructure bugs, including one introduced by a runtime performance optimization, intermittently degraded Claude's responses between early August and early September 2025, and that its benchmarks, safety evaluations, and canary deployments did not capture the degradation. It now runs quality evaluations continuously on production systems. Source: Anthropic (operator postmortem, 2025-09-17) · evidence grade: primary · cited by Re-run behavior and safety evaluations before any model, version, or serving change reaches users
  • GPT-4o update shipped with sycophantic behavior and was rolled back (2025-04-25; disclosed by the operator). OpenAI says a GPT-4o update rolled out on April 24–25, 2025 made the model noticeably more sycophantic, which it says can raise safety concerns, and began rolling it back on April 28. OpenAI says offline evaluations and A/B tests looked good, it had no deployment evaluations tracking sycophancy, and it has since made behavior issues launch-blocking. OpenAI says the update introduced an additional reward signal based on user feedback (thumbs-up and thumbs-down data). Source: OpenAI (operator disclosure, 2025-04-29) · evidence grade: primary · cited by Re-run behavior and safety evaluations before any model, version, or serving change reaches users

Rule id il-hb2472.automated-process-criteria-and-integrity · review status: primary source derived

Binding law — in force

Only a clinical peer makes adverse determinations; an algorithmic automated process may only certify or refer (Illinois HB 2472)

215 ILCS 134/45(i) and source note · official text · In force: applies since 1 Jan 2025 · Illinois (US-IL)

From 2025-01-01, even if a health care plan or other utilization review program uses an algorithmic automated process in utilization review for medical necessity, it must ensure that only a clinical peer (a health care professional in the same profession and the same or similar specialty as the provider who typically manages the condition) makes any adverse determination based on medical necessity, and that only a clinical peer reviews an appeal (215 ILCS 134/45(i)). Only a clinical peer may make adverse medical-necessity determinations; a health care professional or an accredited algorithmic automated process may certify medical necessity, and the process may refer a case to a clinical peer for a potential adverse determination (85(e)(2)). Detect automated output that sets a denial without a clinical peer, and prompts or schemas that ask the model to deny.

Trust and provenance not reviewed by a lawyer · audit-grade · source verified 3 Oct 2026 · release 2026.10.03.4
Lane
Binding law — in force In force: applies since 1 Jan 2025
Official source
215 ILCS 134/45(i) and source note · captured 3 Oct 2026 · anchor hash (SHA-256) b9219f4bdd38… · 11 more anchors in the data release
Verification
Quoted text found word for word in the captured official document (3 Oct 2026). Source last verified 3 Oct 2026: checked against the captured official document.
Data release
Data release 2026.10.03.4, data as of 3 Oct 2026, schema 0.3.9.
Legal review
Not reviewed by a lawyer. TwinEthos derived this rule from the official text it cites: treat it as research to check against that text; it is not legal advice. No TwinEthos rule has been legally reviewed yet. Open questions for counsel on this rule: 2.
Audit standard
Audit-grade: meets all 10 checks of the TwinEthos audit standard that apply to it. The audit standard is TwinEthos's own quality bar for provenance, dates, applicability, detectors, fixtures, remediation and licences; it is not a legal review.
Detectors

2 detectors (code pattern), experimental: written from the rule's text and not yet measured for precision on real code, so treat a hit as a lead to verify.

Known limits:

  • Review routing in a separate workflow service or BPM engine
  • Denials applied by a downstream claims system from an exported score
  • The clinical review may live in another module (a workflow engine or a separate review service); confirm the adverse status cannot be reached without it before reporting. Clinician tokens anywhere in the file suppress t…

2 more known limits in the data release.

Who it applies to

  • Duty falls on: insurer, organization
  • Sectors: insurance, healthcare
  • Health care plans (HMOs, managed care community networks and accountable care entities with a provider network) and any person conducting a utilization review program in Illinois (registered with the Department of Insurance) that uses an algorithmic automated process in utilization review for medical necessity. In force 2025-01-01.
  • Not covered:
    • Section 85 does not apply to persons providing utilization review program services only to the federal government (215 ILCS 134/85(c)(1))
    • Section 85 does not apply to self-insured ERISA health plans, though it applies to persons conducting utilization review on their behalf (85(c)(2))
    • Section 85 does not apply to hospitals and medical groups performing utilization review for internal purposes unless conducted for another person (85(c)(3))
    • 'Health care plan' (Section 45) excludes indemnity policies (including those with a contracted network), dental-only and vision-only plans, preferred provider administrators, self-insured ERISA plans, workers' compensation care and certain union-affiliated plans (134/10)
  • Whether it applies depends on facts outside the code; a person has to decide.

The guard to add

Route every adverse outcome an AI or algorithm proposes in utilization review to a qualified clinical reviewer, and issue a denial only from that reviewer's recorded decision.

At the point where a model, rules engine or scoring tool returns its result for a prior-authorization, concurrent or retrospective review, the code may auto-approve (where the law allows) or route the case, but any result that would deny, delay, modify or downgrade the request is written as a pending clinical review (status 'pending_clinical_review', a review_queue entry with the tool's output attached as a recommendation), never as the determination. Only a review action by an authenticated reviewer whose role is physician, clinical peer or qualified reviewer, in the same or a similar specialty where the law requires, can set an adverse status; that action records reviewer_id, licence and specialty, the clinical documents opened, the decision and its clinical rationale, and the timestamp, and the adverse-determination notice is generated from it (with the reviewer's signature or attestation where the law requires). Where a law forbids the automated system from making an adverse determination even in part (Texas), the tool's output may only approve, route or support administrative and fraud-detection work; it is not shown to the reviewer as a proposed denial.

Where it goes: 1 application source code, 2 data models, 9 AI output handling, 14 user-facing text.

What this provision adds:

  • The automated process may certify (approve) medical necessity or refer the case to a clinical peer; it may not produce the adverse determination, and appeals are reviewed only by a clinical peer.

Example (Python + OpenAI SDK (prior-authorization service)), before:

result = client.chat.completions.create(model=MODEL, messages=build_pa_prompt(request)).choices[0].message.content
if json.loads(result)['decision'] == 'deny':
    prior_auth.update(request.id, status='denied')
    send_denial_letter(request)

After:

result = json.loads(client.chat.completions.create(
    model=MODEL, messages=build_pa_prompt(request, record=member_clinical_record(request))).choices[0].message.content)
if result['decision'] == 'approve' and AUTO_APPROVE_ALLOWED:
    prior_auth.update(request.id, status='approved', ai_assisted=True)
else:                                   # any non-approval goes to a clinician
    review_queue.enqueue(request.id, queue='pending_clinical_review',
                         specialty=request.specialty, ai_recommendation=result)

@app.post('/reviews/{case_id}/decision')
def record_clinical_decision(case_id: str, body: Decision, reviewer=Depends(licensed_clinical_reviewer)):
    decision = clinical_decisions.create(case_id=case_id, reviewer_id=reviewer.id, licence=reviewer.licence,
                                         specialty=reviewer.specialty, documents_reviewed=body.documents,
                                         outcome=body.outcome, rationale=body.rationale)
    if body.outcome in ('denied', 'downgraded'):
        send_adverse_determination(case_id, decision=decision, signed_by=reviewer)

Control: AI or algorithm denies, delays or downgrades care in utilization review without a licensed clinical reviewer deciding. The same guard addresses 9 items with binding law in 8 jurisdictions. Engineering guidance, not legal advice.

Related incidents

No guardrail sits on this exact control; these incidents are cited by guardrails on related controls.

Rule id il-hb2472.clinical-peer-adverse-determination · review status: primary source derived

Informational data, not legal advice. Summaries are TwinEthos's own words and rules have not been reviewed by a lawyer: check the official text before relying on any of it. A guard addresses an item; adding it is not a statement that your code meets any law.