Binding law — in force
AI may not be the sole basis to deny, delay or modify care; a physician or clinical peer makes adverse determinations (Nebraska LB 77)
From 2026-01-01, an artificial intelligence-based algorithm shall not be the sole basis of a utilization review agent's decision to deny, delay or modify health care services based in whole or in part on medical necessity (LB 77 sec. 12(1)), and the agent must ensure that all adverse determinations for prior authorization are made by a physician (or, where the requesting provider is not a physician, a clinical peer of that provider) holding a current nonrestricted U.S. licence, with appropriate training, knowledge or expertise, under the clinical direction of a medical director responsible for Nebraska enrollees (sec. 4(1)). Detect automated output that sets a denial, delay or modification without a physician's decision.
Trust and provenance not reviewed by a lawyer · audit-grade · source verified 3 Oct 2026 · release 2026.10.03.4
- Lane
- Binding law — in force In force: applies since 1 Jan 2026
- Official source
- Nebraska LB 77, Sec. 12(1) · captured 3 Oct 2026 · anchor hash (SHA-256)
40875d7f8a8a…· 11 more anchors in the data release - Verification
- Quoted text found word for word in the captured official document (3 Oct 2026). Source last verified 3 Oct 2026: checked against the captured official document.
- Data release
- Data release 2026.10.03.4, data as of 3 Oct 2026, schema 0.3.9.
- Legal review
- Not reviewed by a lawyer. TwinEthos derived this rule from the official text it cites: treat it as research to check against that text; it is not legal advice. No TwinEthos rule has been legally reviewed yet. Open questions for counsel on this rule: 1.
- Audit standard
- Audit-grade: meets all 10 checks of the TwinEthos audit standard that apply to it. The audit standard is TwinEthos's own quality bar for provenance, dates, applicability, detectors, fixtures, remediation and licences; it is not a legal review.
- Detectors
1 detector (code pattern), experimental: written from the rule's text and not yet measured for precision on real code, so treat a hit as a lead to verify.
Known limits:
- Review routing in a separate workflow service or BPM engine
- Denials applied by a downstream claims system from an exported score
- The clinical review may live in another module (a workflow engine or a separate review service); confirm the adverse status cannot be reached without it before reporting. Clinician tokens anywhere in the file suppress t…
Who it applies to
- Duty falls on: insurer, organization
- Sectors: insurance, healthcare
- Utilization review agents (any person, company, health carrier or other entity performing utilization review, with the 44-5418(31) exclusions) making prior-authorization and other medical-necessity decisions for Nebraska enrollees. Operative 2026-01-01 (LB 77 sec. 17).
- Not covered:
- Not utilization review agents (Neb. Rev. Stat. 44-5418(31)): federal agencies and agents acting for the federal government or the State (to that extent), agencies of the State, internal quality assurance programs not used to allow or deny claims, licensed pharmacists and pharmacies in the practice of pharmacy, workers' compensation utilization review, individuals employed by a certified agent, and ERISA-exempt employee benefit plans
- Whether it applies depends on facts outside the code; a person has to decide.
The guard to add
Route every adverse outcome an AI or algorithm proposes in utilization review to a qualified clinical reviewer, and issue a denial only from that reviewer's recorded decision.
At the point where a model, rules engine or scoring tool returns its result for a prior-authorization, concurrent or retrospective review, the code may auto-approve (where the law allows) or route the case, but any result that would deny, delay, modify or downgrade the request is written as a pending clinical review (status 'pending_clinical_review', a review_queue entry with the tool's output attached as a recommendation), never as the determination. Only a review action by an authenticated reviewer whose role is physician, clinical peer or qualified reviewer, in the same or a similar specialty where the law requires, can set an adverse status; that action records reviewer_id, licence and specialty, the clinical documents opened, the decision and its clinical rationale, and the timestamp, and the adverse-determination notice is generated from it (with the reviewer's signature or attestation where the law requires). Where a law forbids the automated system from making an adverse determination even in part (Texas), the tool's output may only approve, route or support administrative and fraud-detection work; it is not shown to the reviewer as a proposed denial.
Where it goes: 1 application source code, 2 data models, 9 AI output handling, 14 user-facing text.
What this provision adds:
- The physician or clinical peer holds a current nonrestricted U.S. licence, has the training or expertise to apply the clinical guidelines, and decides under the clinical direction of a medical director responsible for Nebraska enrollees.
Example (Python + OpenAI SDK (prior-authorization service)), before:
result = client.chat.completions.create(model=MODEL, messages=build_pa_prompt(request)).choices[0].message.content
if json.loads(result)['decision'] == 'deny':
prior_auth.update(request.id, status='denied')
send_denial_letter(request)After:
result = json.loads(client.chat.completions.create(
model=MODEL, messages=build_pa_prompt(request, record=member_clinical_record(request))).choices[0].message.content)
if result['decision'] == 'approve' and AUTO_APPROVE_ALLOWED:
prior_auth.update(request.id, status='approved', ai_assisted=True)
else: # any non-approval goes to a clinician
review_queue.enqueue(request.id, queue='pending_clinical_review',
specialty=request.specialty, ai_recommendation=result)
@app.post('/reviews/{case_id}/decision')
def record_clinical_decision(case_id: str, body: Decision, reviewer=Depends(licensed_clinical_reviewer)):
decision = clinical_decisions.create(case_id=case_id, reviewer_id=reviewer.id, licence=reviewer.licence,
specialty=reviewer.specialty, documents_reviewed=body.documents,
outcome=body.outcome, rationale=body.rationale)
if body.outcome in ('denied', 'downgraded'):
send_adverse_determination(case_id, decision=decision, signed_by=reviewer)Control: AI or algorithm denies, delays or downgrades care in utilization review without a licensed clinical reviewer deciding. The same guard addresses 9 items with binding law in 8 jurisdictions. Engineering guidance, not legal advice.
Related incidents
No guardrail sits on this exact control; these incidents are cited by guardrails on related controls.
- UnitedHealth nH Predict claim-denial litigation (2023-11; alleged (not proven)). A class action filed in November 2023 alleges that UnitedHealth's nH Predict model had a 90% error rate, measured by denials reversed on appeal, while only about 0.2% of members appealed. UnitedHealth disputes the allegations; the litigation is ongoing. Source: STAT News · evidence grade: primary · cited by Monitor how often adverse AI decisions are reversed, and suspend models that are usually wrong
- Cigna PXDX batch claim denials (reported) (2022; alleged (not proven)). ProPublica, citing internal Cigna records, reported that Cigna's PXDX system was used to reject more than 300,000 claims over two months in 2022, with physicians spending an average of 1.2 seconds on each. Cigna disputes the reporting; related lawsuits are ongoing. Source: ProPublica / The Capitol Forum · evidence grade: press of record · cited by Make human review of adverse AI decisions substantive, not nominal
Rule id ne-lb77.ai-not-sole-basis-physician-decides · review status: primary source derived