TwinEthos homeAPI access

Law

CMS Medicare Advantage rules, 42 CFR 422.101(c)(1)(i) and 422.566(d)

Centers for Medicare & Medicaid Services · United States (federal) (US) · 2 provisions encoded · verified against the official source as of 2026-10-04.

Informational data, not legal advice. Summaries and rules have not been reviewed by a lawyer: always verify official law text for decisions. A suggested guard is intended to address each rule; adding it is not a statement of compliance to that law.

AI-adjacent law General privacy or biometric law, included only where AI data flows trigger it; reported apart from AI-specific law.

Official text: www.ecfr.gov, www.federalregister.gov.

Trust and provenance 4 official sources · last verified 4 Oct 2026 · not reviewed by a lawyer · 2 of 2 provisions audit-grade · release 2026.10.05

Where this instrument's data comes from, how current it is, and what has and has not been checked. Each provision below has its own panel.

Official sources
Lanes
Binding law — in force 2
Verification
Sources last verified 4 Oct 2026; each provision states how.
Data release
Data release 2026.10.05, data as of 4 Oct 2026, schema 0.3.10.
Legal review
None of the 2 provisions has been reviewed by a lawyer; no TwinEthos rule has been legally reviewed yet. Treat each as research to check against the official text; it is not legal advice. Open questions for counsel on them: 2.
Audit standard
2 of 2 provisions audit-grade. The audit standard is TwinEthos's own quality bar for provenance, dates, applicability, detectors, fixtures, remediation and licences; it is not a legal review.
Detectors
2 detectors, all experimental: written from the rule's text and not yet measured for precision on real code, so treat a hit as a lead to verify. Each provision lists its detectors' known limits.
Changes
  • 2026.10.05 (5 Oct 2026): 2 provisions added

Each data release records which provisions changed; the full list is on Changes.

Binding law — in force AI-adjacent law

Base Medicare Advantage medical necessity determinations on the enrollee's own history, physician recommendations and notes (42 CFR 422.101(c)(1)(i))

42 CFR 422.101(c)(1)(i) · official text · In force: applies since 1 Jan 2024 · United States (federal) (US)

MA organizations must make medical necessity determinations based on all of: Medicare coverage and benefit criteria (and may not deny basic benefits on criteria not specified in 422.101(b) or (c)), whether the item or service is reasonable and necessary under section 1862(a)(1) of the Act, the enrollee's medical history (for example diagnoses, conditions, functional status), physician recommendations and clinical notes, and, where appropriate, the medical director's involvement (42 CFR 422.101(c)(1)(i)(A)-(D)). The rule never mentions AI; it is encoded as AI-adjacent (owner decision D-19, D-11 pattern 1) because algorithmic and AI review tools that predict outcomes from group data are where determinations without the individual record arise. Detect a utilization-review model or scoring call whose inputs never include the enrollee's own clinical record.

Trust and provenance not reviewed by a lawyer · audit-grade · source verified 4 Oct 2026 · release 2026.10.05
Lane
Binding law — in force In force: applies since 1 Jan 2024
Official source
42 CFR 422.101(c)(1)(i) · captured 4 Oct 2026 · anchor hash (SHA-256) 19716f0548d6… · 3 more anchors in the data release
Verification
Quoted text found word for word in the captured official document (4 Oct 2026). Source last verified 4 Oct 2026: checked against the captured official document; not in the weekly watcher's list; checked against the captured document.
Data release
Data release 2026.10.05, data as of 4 Oct 2026, schema 0.3.10.
Legal review
Not reviewed by a lawyer. TwinEthos derived this rule from the official text it cites: treat it as research to check against that text; it is not legal advice. No TwinEthos rule has been legally reviewed yet. Open questions for counsel on this rule: 1.
Audit standard
Audit-grade: meets all 10 checks of the TwinEthos audit standard that apply to it. The audit standard is TwinEthos's own quality bar for provenance, dates, applicability, detectors, fixtures, remediation and licences; it is not a legal review.
Detectors

1 detector (code pattern), experimental: written from the rule's text and not yet measured for precision on real code, so treat a hit as a lead to verify.

Known limits:

  • Prompt builders imported from another module
  • Feature stores whose columns are not named in the code
  • The clinical record may be assembled in a helper module and passed in under a generic name; trace the prompt or feature builder before reporting.

Who it applies to

  • Duty falls on: insurer
  • Sectors: insurance, healthcare
  • Medicare Advantage organizations (42 CFR 422.2) making medical necessity determinations for MA enrollees in the United States, whatever tool, AI, algorithm or otherwise, supports the determination. The revised 422.101(c) is in force from 2023-06-05 and applies to coverage beginning 2024-01-01.
  • Whether it applies depends on facts outside the code; a person has to decide.

The guard to add

Build each automated medical-necessity determination from the enrollee's own clinical record and the provider's submission, and refuse to decide on group statistics alone.

In the prompt builder or feature pipeline for each medical-necessity or coverage determination, load the enrollee's clinical history and the requesting provider's clinical documentation for this request (the attached notes, the FHIR Condition, Observation and DocumentReference resources for the member, the provider's letter of medical necessity) and pass the fields the decision needs; group or population data (a diagnosis code's typical length of stay, a cohort's approval rate, a regional benchmark) may be context but never the only input. A guard before the model or rules call raises an error, or routes the case to clinical review, when the individual clinical inputs are empty, and the inputs used are saved with the result so a reviewer or regulator can see what the determination rested on.

Where it goes: 1 application source code, 2 data models, 7 prompt construction, 9 AI output handling.

What this provision adds:

  • Medicare coverage and benefit criteria and the reasonable-and-necessary test also bind each determination; basic benefits may not be denied on criteria not specified in 422.101(b) or (c).

Example (Python + Anthropic SDK), before:

features = {'cpt': req.cpt, 'icd10': req.icd10, 'cohort_approval_rate': cohort_stats(req.icd10)}
reply = client.messages.create(model=MODEL, max_tokens=400,
    messages=[{'role': 'user', 'content': f'Prior authorization request: {features}'}])

After:

record = member_clinical_record(req.member_id, fields=PA_CLINICAL_FIELDS)   # history, conditions, meds
submission = provider_clinical_submission(req.id)                            # notes, letter of medical necessity
if not record or not submission:
    return review_queue.enqueue(req.id, reason='individual clinical information missing')
reply = client.messages.create(model=MODEL, max_tokens=400, messages=[{'role': 'user', 'content':
    render('pa_review.txt', request=req, clinical_history=record, provider_submission=submission)}])
determinations.save(req.id, inputs={'clinical_history': record.ids, 'submission': submission.ids})

Control: AI coverage or medical-necessity determination not based on the individual's own clinical information. The same guard addresses 5 items with binding law in 5 jurisdictions. Engineering guidance, not legal advice.

Related incidents

No guardrail sits on this exact control; these incidents are cited by guardrails on related controls.

Rule id us-cms-ma-medical-necessity.determination-on-individual-medical-history · review status: primary source derived

Binding law — in force AI-adjacent law

A physician or other appropriate professional reviews every expected adverse Medicare Advantage medical necessity decision first (42 CFR 422.566(d))

42 CFR 422.566(d) · official text · In force: applies since 1 Jan 2024 · United States (federal) (US)

If an MA organization expects to issue a partially or fully adverse medical necessity decision based on the initial review of a request, the organization determination must be reviewed, before it issues, by a physician or other appropriate health care professional with expertise in the field of medicine or health care appropriate for the services at issue, including knowledge of Medicare coverage criteria, holding a current and unrestricted license (42 CFR 422.566(d)). The rule never mentions AI; it is encoded as AI-adjacent (owner decision D-19, D-11 pattern 1) because AI and algorithmic review tools are where denials without that review arise. Detect utilization-review code where model output reaches a denial with no physician or clinical review step.

Trust and provenance not reviewed by a lawyer · audit-grade · source verified 4 Oct 2026 · release 2026.10.05
Lane
Binding law — in force In force: applies since 1 Jan 2024
Official source
42 CFR 422.566(d) · captured 4 Oct 2026 · anchor hash (SHA-256) 822fe12a5d11… · 4 more anchors in the data release
Verification
Quoted text found word for word in the captured official document (4 Oct 2026). Source last verified 4 Oct 2026: checked against the captured official document; not in the weekly watcher's list; checked against the captured document.
Data release
Data release 2026.10.05, data as of 4 Oct 2026, schema 0.3.10.
Legal review
Not reviewed by a lawyer. TwinEthos derived this rule from the official text it cites: treat it as research to check against that text; it is not legal advice. No TwinEthos rule has been legally reviewed yet. Open questions for counsel on this rule: 1.
Audit standard
Audit-grade: meets all 10 checks of the TwinEthos audit standard that apply to it. The audit standard is TwinEthos's own quality bar for provenance, dates, applicability, detectors, fixtures, remediation and licences; it is not a legal review.
Detectors

1 detector (code pattern), experimental: written from the rule's text and not yet measured for precision on real code, so treat a hit as a lead to verify.

Known limits:

  • Review routing in a separate workflow service or BPM engine
  • Denials applied by a downstream claims system from an exported score
  • The clinical review may live in another module (a workflow engine or a separate review service); confirm the adverse status cannot be reached without it before reporting. Clinician tokens anywhere in the file suppress t…

Who it applies to

  • Duty falls on: insurer
  • Sectors: insurance, healthcare
  • Medicare Advantage organizations (42 CFR 422.2) that expect to issue a partially or fully adverse medical necessity organization determination for an MA enrollee in the United States, whatever tool, AI, algorithm or otherwise, proposed it. The revised 422.566(d) is in force from 2023-06-05 and applies to coverage beginning 2024-01-01.
  • Not covered:
    • An applicable integrated plan follows 42 CFR 422.629 through 422.634 instead of 422.566(c) and (d), beginning 2021-01-01 (422.566(a)); those sections are not captured
  • Whether it applies depends on facts outside the code; a person has to decide.

The guard to add

Route every adverse outcome an AI or algorithm proposes in utilization review to a qualified clinical reviewer, and issue a denial only from that reviewer's recorded decision.

At the point where a model, rules engine or scoring tool returns its result for a prior-authorization, concurrent or retrospective review, the code may auto-approve (where the law allows) or route the case, but any result that would deny, delay, modify or downgrade the request is written as a pending clinical review (status 'pending_clinical_review', a review_queue entry with the tool's output attached as a recommendation), never as the determination. Only a review action by an authenticated reviewer whose role is physician, clinical peer or qualified reviewer, in the same or a similar specialty where the law requires, can set an adverse status; that action records reviewer_id, licence and specialty, the clinical documents opened, the decision and its clinical rationale, and the timestamp, and the adverse-determination notice is generated from it (with the reviewer's signature or attestation where the law requires). Where a law forbids the automated system from making an adverse determination even in part (Texas), the tool's output may only approve, route or support administrative and fraud-detection work; it is not shown to the reviewer as a proposed denial.

Where it goes: 1 application source code, 2 data models, 9 AI output handling, 14 user-facing text.

What this provision adds:

  • The reviewer needs expertise appropriate for the services at issue, knowledge of Medicare coverage criteria and a current, unrestricted license; the same specialty as the treating physician is not always required.

Example (Python + OpenAI SDK (prior-authorization service)), before:

result = client.chat.completions.create(model=MODEL, messages=build_pa_prompt(request)).choices[0].message.content
if json.loads(result)['decision'] == 'deny':
    prior_auth.update(request.id, status='denied')
    send_denial_letter(request)

After:

result = json.loads(client.chat.completions.create(
    model=MODEL, messages=build_pa_prompt(request, record=member_clinical_record(request))).choices[0].message.content)
if result['decision'] == 'approve' and AUTO_APPROVE_ALLOWED:
    prior_auth.update(request.id, status='approved', ai_assisted=True)
else:                                   # any non-approval goes to a clinician
    review_queue.enqueue(request.id, queue='pending_clinical_review',
                         specialty=request.specialty, ai_recommendation=result)

@app.post('/reviews/{case_id}/decision')
def record_clinical_decision(case_id: str, body: Decision, reviewer=Depends(licensed_clinical_reviewer)):
    decision = clinical_decisions.create(case_id=case_id, reviewer_id=reviewer.id, licence=reviewer.licence,
                                         specialty=reviewer.specialty, documents_reviewed=body.documents,
                                         outcome=body.outcome, rationale=body.rationale)
    if body.outcome in ('denied', 'downgraded'):
        send_adverse_determination(case_id, decision=decision, signed_by=reviewer)

Control: AI or algorithm denies, delays or downgrades care in utilization review without a licensed clinical reviewer deciding. The same guard addresses 13 items with binding law in 12 jurisdictions. Engineering guidance, not legal advice.

Related incidents

No guardrail sits on this exact control; these incidents are cited by guardrails on related controls.

Rule id us-cms-ma-medical-necessity.physician-reviews-adverse-medical-necessity-decision · review status: primary source derived

Informational data, not legal advice. Summaries are TwinEthos's own words and rules have not been reviewed by a lawyer: check the official text before relying on any of it. A guard addresses an item; adding it is not a statement that your code meets any law.