AI in Health Insurance and Who Governs It
A map of AI in health insurance: plan and jurisdiction differences, high-stakes workflows, and the right guide for prior authorization, claims, and risk adjustment.
In this article
For Compliance officers, medical directors, operations leaders, and counsel at health insurers and health plans.
Read if You need to locate a health AI use in the correct plan, jurisdiction, and operating workflow before choosing controls.
The NAIC’s health insurer survey found that 84% of the 93 responding companies already used AI or machine learning somewhere in their operations.1 That figure belongs here because it describes the whole health-insurance landscape. It should not be repeated as the opening argument in every article about prior authorization or a single company.
Adoption is only the first fact. Within the business-line map, health insurance sits across insurance regulation, clinical decision rules, federal program requirements, privacy, vendor delegation, and plan-specific appeal rights. The same model output can have a different legal and human consequence depending on the plan, product, and decision it enters.
Begin with the plan and the decision
Before classifying a health AI system, identify four things:
- the legal entity and plan or product using it;
- the jurisdiction and program rules governing the decision;
- whether the system informs administration, clinical judgment, payment, coding, or communication;
- who has authority to make and reverse the final action.
Without that map, a team may test a model well and still apply the wrong notice, reviewer qualification, deadline, or appeal route.
| Context | Typical AI use | The health-specific question |
|---|---|---|
| Commercial health insurance | Utilization review, claims, service, fraud, forecasting | Which state insurance and clinical-decision rules govern the action? |
| Medicare Advantage | Prior authorization, post-acute review, risk adjustment, navigation | Which federal program requirements, coverage criteria, and appeal records control? |
| Medicaid managed care | Eligibility interfaces, utilization, care management, claims | How do state Medicaid rules, contract delegation, and due-process protections interact? |
| Pharmacy benefit or delegated service | Formulary, authorization, claims edits, outreach | Which entity owns the decision and can produce the vendor’s reasoning and version? |
| Internal administration | Coding support, summarization, staffing, forecasting | Can the use migrate into a member decision without a new review? |
This table is a routing device, not a legal scope opinion. The actual contract, license, program, and state determine the answer.
Why health decisions are different
Three features distinguish health AI from the same technology in other lines.
First, timing can be part of the harm. A delayed service, drug, or post-acute placement may matter even when the final appeal succeeds. Measure time to qualified review and access to care, not only final approval.
Second, some decisions require clinical judgment from a qualified professional. California’s Physicians Make Decisions Act, SB 1120, limits the use of AI and other software in medical-necessity determinations and reserves those determinations to appropriately licensed professionals.2 Other jurisdictions use different language and scope. A generic “human in the loop” field cannot substitute for the required qualification and authority.
Third, responsibility is distributed. The plan may delegate utilization management, pharmacy, analytics, or claims functions to an affiliate or vendor. The member still experiences one coverage process. The operating record should show which entity produced the recommendation, which entity acted, and which entity handles correction and appeal.
Route the operational problem
Use the health operations guide for the three workflows that most often get blended:
- prior authorization and utilization management;
- claims adjudication and denial;
- risk adjustment and HCC coding.
Those workflows share data and vendors but do not share one outcome. Prior authorization concerns access before or during care. Claims adjudication concerns payment and contractual processing. Risk adjustment concerns the accuracy and support of diagnostic coding and program payments. A control designed for one may miss the main risk in another.
The UnitedHealth case study is a separate kind of article. It uses public company statements, litigation records, and OIG data to test what evidence questions appear at scale. It does not define a standard for every plan.
Map the authorities without blending them
The NAIC Model Bulletin can apply where a state has adopted or otherwise used it for licensed insurers. It describes expectations for an AIS Program and for insurer responsibility when AI supports decisions affecting consumers.3 The NAIC Evaluation Tool provides optional supplemental exhibits a regulator may use to ask about counts, governance, selected high-risk models, and data.4
Colorado’s insurance regime and California’s clinical-decision rule are not interchangeable state add-ons. Federal health-program requirements add another layer for Medicare Advantage and Medicaid arrangements. Build a shared operating baseline where the control travels, then maintain a jurisdiction and program appendix for reviewer qualifications, notices, deadlines, filings, and appeal rights that do not.
Five health-specific questions for any AI use
The general controls have owner articles elsewhere. Health teams should add five questions that reflect the decision they are making.
- Access: Can the output delay, narrow, or end access to care, a benefit, or payment?
- Clinical authority: Does the action require a licensed or specially qualified reviewer, and can that reviewer change it?
- Delegation: Which plan, affiliate, contractor, or provider produced each part of the record?
- Recourse: What notice, reconsideration, appeal, or correction is available, on what clock?
- Program effect: Does the output also feed coding, risk adjustment, quality, payment, or future utilization decisions?
These questions modify the operating design. They do not replace the general controls, and a plan that answers all five still owes the same inventory entry and the same vendor assessment as any other carrier.
What health adds on top is transaction-level. Model monitoring will tell a plan that denial or reversal rates moved; the decision evidence pack is what tells it which authorization moved, who was qualified to sign it, and what the member was told.
The reading path from here
If the problem concerns prior authorization, claims, or risk adjustment, continue to the health operations guide. A system-wide control question belongs in the governance map; a question about the limits of public evidence belongs in the case study. The choice turns on the reader’s task, not on how many AI systems the plan uses.
The goal of this map is to prevent a false shortcut: treating “health AI” as one use case. Governance becomes workable only after the plan, program, decision, and appeal path are named.
Footnotes
-
National Association of Insurance Commissioners, Health Insurance Artificial Intelligence/Machine Learning Survey Results, May 2025. ↩
-
California Legislature, SB 1120, Physicians Make Decisions Act, effective January 1, 2025. ↩
-
National Association of Insurance Commissioners, Model Bulletin on the Use of Artificial Intelligence Systems by Insurers, adopted December 4, 2023. ↩
-
National Association of Insurance Commissioners, AI Systems Evaluation Tool 4.0, 2026. ↩
The Bottom Line
- The NAIC survey found AI or machine learning already in use at 84% of the responding health insurers. The open problem is where each use sits and who can defend its decisions.
- Commercial insurance, Medicare Advantage, Medicaid managed care, and other arrangements do not share one regulator or one appeal path.
- This page maps the health-specific differences. The operations guide owns prior authorization, claims, and risk adjustment.
- A vendor feature can be one technical product and several regulated workflows; governance should follow the decision in each workflow.
How to Build an AI Inventory by Line of Business for NAIC Exhibit A
Map your insurance AI systems by line of business for NAIC Exhibit A. Use this template to capture underwriting, pricing, claims, fraud, and customer service AI.
Continue →
Simon Li · Founding Editor
I write InsureAI Wire and maintain its 51-jurisdiction tracker. Most of the work is reading: NAIC working group papers, state bulletins, bills, court filings, and public comment letters. Every claim on the site carries the document it came from, so you never have to take my word for it.
Free · Weekly
Track these developments weekly
Get the InsureAI Wire dispatch in your inbox. Free, sourced, no spam.
Free weekly · No spam · Unsubscribe anytime
Related reading
What to Keep in an Insurance AI Decision Evidence Pack
Insurance AI decision documentation for reconstructing one underwriting or claims outcome, including human review, notice, appeal, and model version.
Will AI Replace Insurance Agents? The Work Is Splitting
Will AI replace insurance agents? What current employment projections can show, which tasks are changing, and where agency AI use creates compliance exposure.
Conversational AI in Insurance and Where the Rules Reach
What conversational AI and chatbots actually do across insurance, from quotes to claims, and the point where a customer-facing bot becomes a compliance question.
AI in Insurance Claims
AI in insurance claims, step by step from intake to appeal: what each system decides, where it can go wrong, and what record makes the step reviewable.
Information aggregation and analysis, not legal advice. See our disclaimer.