TwinEthos homeAPI access

Law

HHS Section 1557 rule, 45 CFR 92.210 (patient care decision support tools)

U.S. Department of Health and Human Services, Office for Civil Rights · United States (federal) (US) · 1 provision encoded · verified against the official source as of 2026-10-04.

Informational data, not legal advice. Summaries and rules have not been reviewed by a lawyer: always verify official law text for decisions. A suggested guard is intended to address each rule; adding it is not a statement of compliance to that law.

Official text: www.ecfr.gov, www.federalregister.gov.

Trust and provenance 6 official sources · last verified 4 Oct 2026 · not reviewed by a lawyer · 1 of 1 provision audit-grade · release 2026.10.05

Where this instrument's data comes from, how current it is, and what has and has not been checked. Each provision below has its own panel.

Official sources
Lanes
Binding law — in force 1
Verification
Sources last verified 4 Oct 2026; each provision states how.
Data release
Data release 2026.10.05, data as of 4 Oct 2026, schema 0.3.10.
Legal review
None of the 1 provision has been reviewed by a lawyer; no TwinEthos rule has been legally reviewed yet. Treat each as research to check against the official text; it is not legal advice. Open questions for counsel on them: 1.
Audit standard
1 of 1 provision audit-grade. The audit standard is TwinEthos's own quality bar for provenance, dates, applicability, detectors, fixtures, remediation and licences; it is not a legal review.
Detectors
1 detector, all experimental: written from the rule's text and not yet measured for precision on real code, so treat a hit as a lead to verify. Each provision lists its detectors' known limits.
Changes
  • 2026.10.05 (5 Oct 2026): 1 provision added

Each data release records which provisions changed; the full list is on Changes.

Binding law — in force

Identify patient care decision support tools that use race, color, national origin, sex, age or disability inputs and mitigate the risk (45 CFR 92.210)

45 CFR 92.210(b) · official text · In force: applies since 1 May 2025 · United States (federal) (US)

A covered entity must not discriminate on the basis of race, color, national origin, sex, age or disability through the use of patient care decision support tools (45 CFR 92.210(a)); it has an ongoing duty to make reasonable efforts to identify uses of such tools that employ input variables or factors measuring those characteristics (92.210(b)) and, for each tool identified, to make reasonable efforts to mitigate the risk of discrimination (92.210(c)). A 'patient care decision support tool' is any automated or non-automated tool used to support clinical decision-making (92.4); the Department states it includes automated decision systems and AI. Detect clinical model code that feeds protected characteristics to a model with no identification or mitigation record.

Trust and provenance not reviewed by a lawyer · audit-grade · source verified 4 Oct 2026 · release 2026.10.05
Lane
Binding law — in force In force: applies since 1 May 2025
Official source
45 CFR 92.210(b) · captured 4 Oct 2026 · anchor hash (SHA-256) 9fa7e776e9d9… · 11 more anchors in the data release
Verification
Quoted text found word for word in the captured official document (4 Oct 2026). Source last verified 4 Oct 2026: checked against the captured official document; not in the weekly watcher's list; checked against the captured document.
Data release
Data release 2026.10.05, data as of 4 Oct 2026, schema 0.3.10.
Legal review
Not reviewed by a lawyer. TwinEthos derived this rule from the official text it cites: treat it as research to check against that text; it is not legal advice. No TwinEthos rule has been legally reviewed yet. Open questions for counsel on this rule: 1.
Audit standard
Audit-grade: meets all 10 checks of the TwinEthos audit standard that apply to it. The audit standard is TwinEthos's own quality bar for provenance, dates, applicability, detectors, fixtures, remediation and licences; it is not a legal review.
Detectors

1 detector (code pattern), experimental: written from the rule's text and not yet measured for precision on real code, so treat a hit as a lead to verify.

Known limits:

  • Inventory and mitigation kept in a model registry or governance tool
  • Protected inputs assembled by a feature store outside the repository
  • Many clinical models legitimately use age or sex; 92.210 does not ban them but requires the use to be identified and the risk mitigated, so the finding asks for the record, not removal. The record may live in a model re…

Who it applies to

  • Duty falls on: organization
  • Sectors: healthcare, insurance
  • Covered entities under Section 1557 (45 CFR 92.4: recipients of HHS Federal financial assistance, HHS, and title I ACA entities, such as hospitals, clinics, health insurance issuers and state Medicaid programs) that use automated or non-automated patient care decision support tools, including AI and predictive models, to support clinical decision-making in their health programs or activities, for patients in the United States. 92.210(a) applies from 2024-07-05; the identification and mitigation duties of 92.210(b)-(c) from 2025-05-01 (300 days after 2024-07-05).
  • Not covered:
    • Employers and other plan sponsors of group health plans, with regard to their employment practices, including the provision of employee health benefits (45 CFR 92.2(b))
  • Whether it applies depends on facts outside the code; a person has to decide.

The guard to add

Build decision prompts and feature sets from an allowlist of decision-relevant fields, and redact protected attributes, known proxies, and free text before the model sees them.

At the prompt builder or feature-assembly step on the consequential-decision path, construct model inputs from an explicit allowlist (FEATURE_ALLOWLIST, APPROVED_FEATURES) instead of passing the whole person record or f-string interpolating its fields. Protected attributes (race, sex, religion, age, disability) and proxies (ZIP or postal code, surname, school, census tract) stay out unless a documented justification and a bias test exist, and free text (cover letters, notes, transcripts) goes through redaction (redact_pii, strip_protected_attributes) first. Log the features used and the model output per decision, and run disparity tests on outcomes; human review lowers the risk but does not replace the allowlist.

Where it goes: 1 application source code, 2 data models, 7 prompt construction, 13 tests and evals.

What this provision adds:

  • The duty is ongoing: keep identifying tools that use race, color, national origin, sex, age or disability as inputs, and record for each the reasonable efforts made to mitigate the risk of discrimination.
  • Identification and mitigation (92.210(b)-(c)) apply from 2025-05-01; the general prohibition (92.210(a)) from 2024-07-05.

Example (Python + OpenAI SDK), before:

prompt = f"Applicant {a.last_name}, age {a.age}, zip {a.zip_code}.\nNotes: {a.applicant_notes}\nApprove the loan?"
resp = client.chat.completions.create(model=MODEL, messages=[{'role': 'user', 'content': prompt}])

After:

FEATURE_ALLOWLIST = ['income', 'debt_to_income', 'requested_amount', 'payment_history_months']

features = {k: getattr(a, k) for k in FEATURE_ALLOWLIST}
notes = strip_protected_attributes(a.applicant_notes)   # drops names, ages, places, etc.
messages = [{'role': 'system', 'content': LENDING_RUBRIC},
            {'role': 'user', 'content': json.dumps({'features': features, 'notes': notes})}]
resp = client.chat.completions.create(model=MODEL, messages=messages)
decision_log.record(a.id, features, resp.choices[0].message.content)

Control: Protected or proxy attribute reaches AI decision. The same guard addresses 5 items with binding law in 4 jurisdictions. Engineering guidance, not legal advice.

Standards that recommend the same control

Related incidents

No guardrail sits on this exact control; these incidents are cited by guardrails on related controls.

Rule id us-hhs-1557-decision-support-tools.identify-and-mitigate-protected-attribute-inputs · review status: primary source derived

Informational data, not legal advice. Summaries are TwinEthos's own words and rules have not been reviewed by a lawyer: check the official text before relying on any of it. A guard addresses an item; adding it is not a statement that your code meets any law.