# AI in Health Insurance and Who Governs It

> A map of AI in health insurance: plan and jurisdiction differences, high-stakes workflows, and the right guide for prior authorization, claims, and risk adjustment.

- Source: https://insureaiwire.com/ai-in-health-insurance/
- Publication: InsureAI Wire
- Author: Simon Li
- Updated: 2026-07-31

---
The NAIC's health insurer survey found that 84% of the 93 responding companies already used AI or machine learning somewhere in their operations.[^1] That figure belongs here because it describes the whole health-insurance landscape. It should not be repeated as the opening argument in every article about [prior authorization](/glossary/prior-authorization/) or a single company.

Adoption is only the first fact. Within the [business-line map](/ai-by-business-line/), health insurance sits across insurance regulation, clinical decision rules, federal program requirements, privacy, vendor delegation, and plan-specific appeal rights. The same model output can have a different legal and human consequence depending on the plan, product, and decision it enters.

## Begin with the plan and the decision

Before classifying a health AI system, identify four things:

1. the legal entity and plan or product using it;
2. the jurisdiction and program rules governing the decision;
3. whether the system informs administration, clinical judgment, payment, coding, or communication;
4. who has authority to make and reverse the final action.

Without that map, a team may test a model well and still apply the wrong notice, reviewer qualification, deadline, or appeal route.

**Table [row-headers]:** Health-insurance contexts, typical AI uses, and the governing question for each

| Context | Typical AI use | The health-specific question |
|---|---|---|
| Commercial health insurance | Utilization review, claims, service, fraud, forecasting | Which state insurance and clinical-decision rules govern the action? |
| [Medicare Advantage](/glossary/medicare-advantage/) | Prior authorization, post-acute review, risk adjustment, navigation | Which federal program requirements, coverage criteria, and appeal records control? |
| Medicaid managed care | Eligibility interfaces, utilization, care management, claims | How do state Medicaid rules, contract delegation, and due-process protections interact? |
| Pharmacy benefit or delegated service | Formulary, authorization, claims edits, outreach | Which entity owns the decision and can produce the vendor's reasoning and version? |
| Internal administration | Coding support, summarization, staffing, forecasting | Can the use migrate into a member decision without a new review? |

This table is a routing device, not a legal scope opinion. The actual contract, license, program, and state determine the answer.

## Why health decisions are different

Three features distinguish health AI from the same technology in other lines.

First, timing can be part of the harm. A delayed service, drug, or post-acute placement may matter even when the final appeal succeeds. Measure time to qualified review and access to care, not only final approval.

Second, some decisions require clinical judgment from a qualified professional. California's Physicians Make Decisions Act, SB 1120, limits the use of AI and other software in medical-necessity determinations and reserves those determinations to appropriately licensed professionals.[^2] Other jurisdictions use different language and scope. A generic “human in the loop” field cannot substitute for the required qualification and authority.

Third, responsibility is distributed. The plan may delegate utilization management, pharmacy, analytics, or claims functions to an affiliate or vendor. The member still experiences one coverage process. The operating record should show which entity produced the recommendation, which entity acted, and which entity handles correction and appeal.

## Route the operational problem

Use the [health operations guide](/ai-in-health-insurance-claims-prior-auth-risk-adjustment/) for the three workflows that most often get blended:

- prior authorization and utilization management;
- claims adjudication and denial;
- [risk adjustment](/glossary/risk-adjustment/) and HCC coding.

Those workflows share data and vendors but do not share one outcome. Prior authorization concerns access before or during care. Claims adjudication concerns payment and contractual processing. Risk adjustment concerns the accuracy and support of diagnostic coding and program payments. A control designed for one may miss the main risk in another.

The [UnitedHealth case study](/unitedhealth-ai-governance/) is a separate kind of article. It uses public company statements, litigation records, and OIG data to test what evidence questions appear at scale. It does not define a standard for every plan.

## Map the authorities without blending them

The [NAIC Model Bulletin](/naic-model-bulletin/) can apply where a state has adopted or otherwise used it for licensed insurers. It describes expectations for an AIS Program and for insurer responsibility when AI supports decisions affecting consumers.[^3] The [NAIC Evaluation Tool](/naic-ai-evaluation-tool/) provides optional supplemental exhibits a regulator may use to ask about counts, governance, selected high-risk models, and data.[^4]

Colorado's insurance regime and California's clinical-decision rule are not interchangeable state add-ons. Federal health-program requirements add another layer for Medicare Advantage and Medicaid arrangements. Build a shared operating baseline where the control travels, then maintain a jurisdiction and program appendix for reviewer qualifications, notices, deadlines, filings, and appeal rights that do not.

## Five health-specific questions for any AI use

The general controls have owner articles elsewhere. Health teams should add five questions that reflect the decision they are making.

1. **Access:** Can the output delay, narrow, or end access to care, a benefit, or payment?
2. **Clinical authority:** Does the action require a licensed or specially qualified reviewer, and can that reviewer change it?
3. **Delegation:** Which plan, affiliate, contractor, or provider produced each part of the record?
4. **Recourse:** What notice, reconsideration, appeal, or correction is available, on what clock?
5. **Program effect:** Does the output also feed coding, risk adjustment, quality, payment, or future utilization decisions?

These questions modify the operating design. They do not replace the general controls, and a plan that answers all five still owes the same [inventory](/ai-inventory-by-line-of-business/) entry and the same [vendor assessment](/ai-vendor-risk-assessment/) as any other carrier.

What health adds on top is transaction-level. [Model monitoring](/ai-model-monitoring-insurance/) will tell a plan that denial or reversal rates moved; the [decision evidence pack](/insurance-ai-decision-evidence-pack/) is what tells it which authorization moved, who was qualified to sign it, and what the member was told.

## The reading path from here

If the problem concerns prior authorization, claims, or risk adjustment, continue to the health operations guide. A system-wide control question belongs in the governance map; a question about the limits of public evidence belongs in the case study. The choice turns on the reader's task, not on how many AI systems the plan uses.

The goal of this map is to prevent a false shortcut: treating “health AI” as one use case. Governance becomes workable only after the plan, program, decision, and appeal path are named.

[^1]: National Association of Insurance Commissioners, [Health Insurance Artificial Intelligence/Machine Learning Survey Results](https://content.naic.org/sites/default/files/inline-files/Health%20Survey%20Report%20-%20FINAL%205.9.25.pdf), May 2025.
[^2]: California Legislature, [SB 1120, Physicians Make Decisions Act](https://leginfo.legislature.ca.gov/faces/billNavClient.xhtml?bill_id=202320240SB1120), effective January 1, 2025.
[^3]: National Association of Insurance Commissioners, [Model Bulletin on the Use of Artificial Intelligence Systems by Insurers](https://content.naic.org/sites/default/files/inline-files/2023-12-4%20Model%20Bulletin_Adopted_0.pdf), adopted December 4, 2023.
[^4]: National Association of Insurance Commissioners, [AI Systems Evaluation Tool 4.0](https://content.naic.org/sites/default/files/inline-files/AI%20Systems%20Evaluation%20Tool%204.0%20%28Clean%29.pdf), 2026.