Prior Authorization Is Where Health AI Gets Tested
The AI use cases in health insurance, function by function, and the evidence trail each one leaves in prior authorization, claims adjudication, and risk adjustment.
In this article
For Health plan compliance officers, chief medical officers, GCs, and operational leaders at insurers using AI in utilization management, claims, or risk adjustment.
Read if Prior auth, claims, and risk adjustment all use AI at your plan, and you need to know why each workflow requires a different evidence trail.
A denied prior authorization can leave a patient without a drug or procedure. A rejected claim can delay a provider’s payment. A risk-adjustment model that misclassifies a patient can move money between plans. These are the AI use cases in health insurance with the sharpest consequences, and each leaves a different record of timing, clinical support, payment, appeal, and correction. The health plan must connect that record to the system and people that shaped the result.
The health governance map explains plan types, jurisdictions, and the industry-wide adoption picture. This article begins one level lower, with three operating workflows that share data and vendors but produce different consequences.
The business-line map places those workflows in the wider sequence from understanding a decision to preserving its evidence.
The use cases, function by function
The NAIC’s health survey asked companies selling individual major medical coverage, function by function, whether they use or are exploring AI or machine learning. The answers: 71% for utilization management, 68% for prior authorization approvals, 61% for disease management programs, 51% for medical provider fraud detection, and 45% for sales and marketing 1. That list is the closest thing to an official menu of AI use cases in health insurance, and it is wider than the record-keeping problem this article works on.
The functions differ in what they can do to a member. Disease management programs recommend outreach rather than deny care, and sales and marketing models touch solicitation rules rather than medical necessity; both still owe an entry in the plan’s AI inventory, and fraud models have their own governance guide. This article stays with prior authorization, claims adjudication, and risk adjustment because those are the use cases where the output meets a patient, a provider payment, or a program dollar, and the file shows it.
Prior authorization and utilization management
Prior authorization creates one of the clearest records of AI-assisted health insurance decision-making. The plan asks a clinician to get approval before a service is covered, and an algorithm may support the review of medical necessity. Medicare Advantage insurers made nearly 53 million prior authorization determinations in 2024, fully or partially denying 4.1 million of them, about 7.7% of requests 2. The broader health AI governance framework covers the clinical-override and vendor-accountability requirements that apply here.
CMS has been trying to impose transparency on the process. The 2024 CMS Interoperability and Prior Authorization Final Rule (CMS-0057-F) requires impacted payers to implement prior authorization API standards 3. Certain provisions of the rule took effect January 1, 2026; the API requirements run primarily to January 1, 2027 3. The rule is designed to reduce the administrative burden on providers and give patients more visibility into the status of their requests. For plans, it also means the prior authorization workflow becomes more observable to regulators and to litigants.
The operational risk sits in the handoff between recommendation and decision. A model may flag a case for human review, yet the review has little value if the reviewer lacks the time, information, or authority to disagree. Litigation concerning UnitedHealth’s nH Predict tool illustrates why that seam needs a record. The allegations are disputed and have not been decided; the court let two contract-based counts proceed and dismissed the rest with prejudice.4 Our UnitedHealth case study owns the procedural history, the parties’ positions, and the relevant appeal data. The workflow lesson here is narrower: preserve the recommendation, the qualified reviewer’s reasoning, the determination, and what happened on appeal.
In Medicare Advantage the line sits in regulation rather than guidance. Before a plan issues a partially or fully adverse medical necessity decision, 42 CFR 422.566(d) requires the determination to be reviewed by a physician or other appropriate health care professional with expertise in the field at issue, including knowledge of Medicare coverage criteria 5. The denial notice must then state the specific reasons for the denial 5. A model can feed that review; it cannot be the reviewer, and the record has to show which person was. Those are exactly the records that a vendor-operated tool often obscures.
Claims adjudication and denial
Claims adjudication creates a separate health AI record. A model may apply an edit, route a claim, identify missing information, recommend a reduced payment, or support a denial. The distinction from prior authorization is the decision being made: coverage and clinical timing before care differ from contractual payment after a service.
The same post-acute-care dispute also shows how clinical review and claims administration can share one tool while producing different records. A plan should be able to identify which workflow made the action, which authority governed it, and where a later appeal was resolved. The case details remain in the linked case study rather than being repeated here.
The claims lifecycle guide follows the end-to-end intake, estimation, decision, notice, and appeal chain. A health plan adds the benefit, code, provider, plan document, edit, remittance or denial reason, reconsideration route, and program deadline. Those fields explain a health payment decision while this article stays with the health-specific record.
Health plans also need to monitor what the AI does to providers and patients over time. A model that reduces improper payments is valuable. A model that delays legitimate payments or drives a rising appeals rate is a problem that will show up in market conduct data. Read savings together with reversal, complaint, and provider-escalation rates.
Risk adjustment and HCC coding
Risk adjustment creates a different evidence problem. Medicare Advantage and ACA plans use hierarchical condition category (HCC) models to adjust payments based on the expected health cost of enrolled members. The more accurately a plan documents a member’s conditions, the more accurately it is paid. AI is increasingly used to identify undocumented conditions, suggest HCC codes, and prioritize chart review.
The benefit is real. Natural language processing can read encounter notes and identify diagnoses that a rules-based coder might miss. Predictive models can prioritize which members are most likely to have undocumented conditions, making retrospective chart review more efficient. The risk is that AI can also make the same error across thousands of members, or that the incentive to document every possible condition becomes an incentive to document conditions that are not properly supported.
CMS audits plans for unsupported HCC codes and recoups overpayments. The Department of Justice has pursued whistleblower cases alleging that plans inflated risk scores through aggressive coding practices. A code still needs clinical support when an AI system suggested it. Scale changes the control problem: one repeated error can affect thousands of members, so validation has to travel with the suggestion rather than arrive only after an audit.
For a sample of AI-suggested HCCs, keep the source encounter, supporting clinical text, suggestion version, coder or clinician validation, submitted status, and any later deletion. At program level, track the share of suggestions removed before submission, unsupported codes found in audit, recoupments, and repeated errors tied to one source or release. Those records show whether the tool improved documented accuracy or simply increased coding volume. Threshold setting and drift response remain with model monitoring.
Vendor delegation across the three workflows
A vendor platform may support utilization review, claims edits, and coding suggestions at the same plan. Record the function, release, criteria or model version, and delegated entity separately for each workflow. Each function needs its own proof: clinical support for an HCC suggestion, a claims accuracy measure for a payment edit, and evidence that a clinician could reconsider a medical-necessity recommendation.
The vendor risk assessment owns diligence, contract terms, audit rights, and continuing oversight. This article’s narrower requirement is that the vendor record can be joined to the patient, provider, claim, or coding transaction when a particular outcome is reviewed.
Keep the authority and outcome measures distinct
| Workflow | Authority record | Outcome measures that fit the decision |
|---|---|---|
| Prior authorization | Qualified reviewer, criteria, recommendation, determination, notice, appeal | Decision time, denial, peer review, reversal, delayed or abandoned care |
| Claims | Edit or model output, plan action, payment or denial reason, reconsideration | Payment time, corrected claim, reversal, provider escalation, complaint |
| Risk adjustment | Suggested diagnosis, encounter support, coder or clinician validation, submitted code | Unsupported-code rate, deletion, audit finding, recoupment, repeated source error |
Production thresholds and drift response belong in the model monitoring playbook. The decision evidence pack provides the common transaction spine. The table above supplies the health-specific fields and measures.
Why the record is unusually visible
The inventory mechanics behind such a program are in the AI inventory by line of business playbook.
Health decisions generate concrete measures: authorization time, payment, denial reason, appeal, reversal, unsupported code, and recoupment. That makes a weak control easier to find and challenge. The lesson for a health plan is practical: preserve the authority and outcome record for each workflow, then route inventory, vendor oversight, and portfolio monitoring to the articles that own those controls.
Footnotes
-
NAIC, “Health Insurance Artificial Intelligence/Machine Learning Survey Results,” May 2025, p.8 (individual major medical market, share of companies currently using or exploring AI/ML by function): https://content.naic.org/sites/default/files/inline-files/Health%20Survey%20Report%20-%20FINAL%205.9.25.pdf ↩
-
KFF, “Medicare Advantage Insurers Made Nearly 53 Million Prior Authorization Determinations in 2024,” January 2026: https://www.kff.org/medicare/medicare-advantage-insurers-made-nearly-53-million-prior-authorization-determinations-in-2024/ ↩
-
CMS, “CMS Interoperability and Prior Authorization Final Rule (CMS-0057-F),” January 2024: https://www.cms.gov/initiatives/burden-reduction/overview/interoperability/policies-regulations/cms-interoperability-prior-authorization-final-rule-cms-0057-f ↩ ↩2
-
Estate of Gene B. Lokken, et al. v. UnitedHealth Group, Inc., et al., No. 0:23-cv-03514-JRT-SGE (D. Minn.), Memorandum Opinion and Order on Motion to Dismiss, February 13, 2025 (Docket No. 91): the allegation that “over 90% of claim denials are reversed on appeal and over 80% of preauthorization denials are reversed” is recited at p.4 as the plaintiffs’ pleading; the order at p.24 lets Counts 1 and 2 proceed and dismisses Counts 3 through 7 with prejudice. https://storage.courtlistener.com/recap/gov.uscourts.mnd.211721/gov.uscourts.mnd.211721.91.0_2.pdf ↩
-
42 CFR 422.566(d) (review of adverse medical necessity organization determinations) and 42 CFR 422.568(e)(2) (denial notice must state the specific reasons for the denial): https://www.ecfr.gov/current/title-42/chapter-IV/subchapter-B/part-422/subpart-M/section-422.566 ↩ ↩2
The Bottom Line
- Health AI receives highly visible regulatory attention because denials, delays, appeals, and payment changes leave records that patients, providers, auditors, and regulators can examine.
- Prior authorization and claims adjudication are the flashpoints. Reviewers will ask whether a clinician could override the system and whether the plan documented that review.
- Risk adjustment is a financial and compliance exposure. AI that improves HCC coding accuracy can also magnify the consequences of an error if auditing is not parallel.
- The three workflows need different evidence: clinical review and timing for prior authorization, payment logic for claims, and diagnosis support for risk adjustment.
- These workflow differences are the article's job. General inventory, vendor, monitoring, and decision-record methods stay with their playbooks.
How to Build an AI Inventory by Line of Business for NAIC Exhibit A
Map your insurance AI systems by line of business for NAIC Exhibit A. Use this template to capture underwriting, pricing, claims, fraud, and customer service AI.
Continue →
Simon Li · Founding Editor
I write InsureAI Wire and maintain its 51-jurisdiction tracker. Most of the work is reading: NAIC working group papers, state bulletins, bills, court filings, and public comment letters. Every claim on the site carries the document it came from, so you never have to take my word for it.
Free · Weekly
Track these developments weekly
Get the InsureAI Wire dispatch in your inbox. Free, sourced, no spam.
Free weekly · No spam · Unsubscribe anytime
Related reading
AI in Insurance Claims
AI in insurance claims, step by step from intake to appeal: what each system decides, where it can go wrong, and what record makes the step reviewable.
What to Keep in an Insurance AI Decision Evidence Pack
Insurance AI decision documentation for reconstructing one underwriting or claims outcome, including human review, notice, appeal, and model version.
Will AI Replace Insurance Agents? The Work Is Splitting
Will AI replace insurance agents? What current employment projections can show, which tasks are changing, and where agency AI use creates compliance exposure.
Conversational AI in Insurance and Where the Rules Reach
What conversational AI and chatbots actually do across insurance, from quotes to claims, and the point where a customer-facing bot becomes a compliance question.
Information aggregation and analysis, not legal advice. See our disclaimer.