What This Is About
Health plans and healthcare providers are deploying AI to accelerate prior authorization decisions, flag claims for review and guide utilization management. These systems process protected health information, make or influence coverage determinations and generate records that patients, regulators and litigants will scrutinize. The business case is clear: faster decisions, lower administrative cost and more consistent application of coverage policy. The compliance challenge is equally clear: no single federal law governs AI in healthcare administration, yet multiple regulators expect organizations to demonstrate that these systems are fair, explainable, secure and subject to meaningful human oversight.
The problem is not a lack of rules. It is the absence of a unifying standard and the practical difficulty of assigning clear executive ownership across compliance, medical policy, IT and legal functions. Leadership is accountable for outcomes—defensible decisions, regulatory compliance, appeal processes that withstand scrutiny—without a template for organizing the work or measuring progress.
Why This Matters Now
Regulatory attention is increasing. CMS issued final rules in 2024 requiring health plans to provide specific reasons for prior authorization denials and to meet response time standards. State legislatures are enacting laws that require disclosure when AI is used in coverage decisions, impose explainability obligations and in some cases require human review before denials. The FTC enforces data security obligations under Section 5 of the FTC Act, which applies to health apps and services not covered by HIPAA, and has published guidance making clear that companies must honor privacy promises and maintain security appropriate to the data they hold.
At the same time, AI systems are evolving faster than regulatory frameworks. A model that performs well in testing may behave unpredictably in production. A vendor's assurance of fairness does not discharge the organization's legal obligation to verify that claim and monitor performance over time. The risk is not hypothetical. Denied claims generate appeals. Appeals that reveal unexplained or inconsistent AI behavior generate regulatory inquiries, litigation risk and reputational harm.
Organizations that move quickly to establish governance, assign accountability and document their risk decisions gain a defendable position. Those that treat AI deployment as an IT implementation without compliance architecture are building exposure.
What Regulations and Guidance Apply
CMS Requirements for Prior Authorization
CMS rules apply to Medicare Advantage plans, Medicaid managed care organizations and qualified health plans on the federally facilitated exchanges. Organizations must provide specific reasons for prior authorization denials, not boilerplate language. When AI informs or generates a denial, the explanation must be specific enough that a provider or patient understands what clinical information was missing or what policy criterion was not met. Response time standards also apply: CMS expects standard requests to be processed within specified timeframes, and expedited requests more quickly.
The practical implication: AI systems must be able to produce decision rationales that satisfy these standards. A model that outputs a denial code without supporting detail does not meet CMS expectations. Organizations must validate that AI-generated explanations are accurate, consistent with policy and sufficient for appeal purposes.
State Laws on AI in Coverage Decisions
Several states have enacted or are considering laws that require health plans to disclose the use of AI in prior authorization or claims decisions, impose explainability or fairness requirements, or mandate human review before certain adverse determinations. These laws vary in scope and definition. Some apply only to fully automated decisions; others apply when AI substantially influences a human decision. Organizations operating in multiple states must map their obligations state by state and configure systems to satisfy the most stringent requirements or implement jurisdiction-specific workflows.
Data Security and Privacy Obligations
HIPAA applies to covered entities and business associates. AI systems that process protected health information must comply with the Security Rule's requirements for administrative, physical and technical safeguards. Organizations must conduct risk assessments, implement access controls, encrypt data in transit and at rest where appropriate, and maintain audit logs. When a vendor provides the AI model, the business associate agreement must address the vendor's security obligations and breach notification procedures.
For health apps and services not covered by HIPAA, the FTC enforces data security obligations under Section 5 of the FTC Act. The FTC has stated that companies must honor privacy promises made in policies or marketing and must maintain security appropriate to the sensitivity of the data they hold. A failure to implement reasonable security measures, or a misrepresentation about data practices, can result in FTC enforcement. The [Health Breach Notification Rule](https://www.ftc.gov/business-guidance/privacy-security) may also apply, requiring vendors of personal health records and related entities to notify consumers and the FTC following a breach.
The NIST Privacy Framework provides a voluntary structure for identifying and managing privacy risks. It is not a regulation, but it offers a common language for discussing data minimization, transparency, individual participation and accountability—principles that align with regulatory expectations and that courts and regulators may reference when evaluating an organization's practices.
Bias, Fairness and Explainability
No federal law explicitly defines algorithmic fairness for healthcare AI, but multiple regulatory frameworks create implicit obligations. The Civil Rights Act prohibits discrimination on the basis of race, color, national origin, sex, disability and age. If an AI system produces disparate outcomes along these dimensions—for example, higher denial rates for certain demographic groups—the organization may face claims of disparate impact even if no discriminatory intent exists. Section 1557 of the Affordable Care Act reinforces these protections in the healthcare context.
Explainability is a practical necessity even where not explicitly required. A decision that cannot be explained cannot be defended in an appeal, an audit or litigation. Organizations must be able to articulate what inputs the model considered, how those inputs were weighted, and why a particular output was generated. This does not mean exposing proprietary algorithms; it means being able to provide a clinically and procedurally meaningful explanation to the patient, the provider and the regulator.
Appeals Processes
Existing appeal rights do not disappear when AI is involved. Patients and providers retain the right to challenge adverse determinations through internal appeals and, where applicable, external review. Organizations must ensure that the appeals process can accommodate challenges to AI decisions. This means providing sufficient information about how the decision was made, preserving audit trails and ensuring that human reviewers have access to the data and logic the AI system used.
If the AI system cannot produce a defensible record of its decision-making, the appeal process is compromised. If human reviewers lack the training or tools to evaluate AI recommendations, the appeal becomes procedural theater rather than meaningful review.
Who Owns This and What Adequate Ownership Looks Like
AI governance in healthcare administration typically falls between functions. Compliance teams understand regulatory obligations but may lack technical depth to evaluate model behavior. IT teams deploy systems but do not own medical policy or legal risk. Medical directors own clinical standards but may not have visibility into how AI systems operationalize those standards. Legal counsel advises on risk but does not typically lead implementation.
Adequate ownership means appointing an executive—often the chief information security officer, chief compliance officer or chief risk officer—who is accountable for the entire governance program and who has explicit authority to convene stakeholders, make risk decisions and escalate issues to the CEO or board. This individual does not need to be a data scientist or a clinician, but they must have the mandate and the resources to establish and enforce governance processes.
For many mid-sized health plans and provider organizations, this level of expertise and authority does not exist in-house or cannot be fully dedicated to AI governance. [Virtual CISO (vCISO) leadership](/vciso/) provides the executive accountability, cross-functional coordination and regulatory positioning that this work requires, without the overhead of a permanent C-suite hire. A vCISO defines the governance framework, assigns responsibilities across compliance, IT, legal and clinical teams, establishes risk tolerances and reporting cadences, and ensures that the organization can demonstrate due diligence to regulators and auditors.
What Leadership Must Do Next
Assign explicit accountability for AI governance. Identify a single executive owner responsible for the governance program, including policy development, risk assessment, vendor oversight and regulatory reporting. This cannot be a committee responsibility or a shared mandate.
Inventory AI systems already in use or under consideration. Document what each system does, what data it uses, whether it makes decisions or supports human decisions, what vendors are involved and what jurisdiction-specific obligations apply. Many organizations discover systems in production that were approved as IT projects without compliance review.
Establish a risk assessment process for AI deployments. Before any AI system influences a coverage determination, assess bias and fairness risks, explainability requirements, data security controls, appeals implications and regulatory obligations. Document the assessment and the decision to proceed, including what residual risks leadership has accepted.
Validate vendor claims. Do not rely on vendor assertions about fairness, explainability or compliance. Require evidence, conduct testing on your own data, and include governance obligations in contracts. If a vendor cannot explain how a model makes decisions, or cannot provide audit logs sufficient for appeals, find a different vendor or delay deployment.
Implement ongoing monitoring. AI systems do not remain static. Models drift as data changes; edge cases emerge in production that were not anticipated in testing. Establish monitoring processes that track denial rates by demographic group, measure explanation quality and flag anomalies for human review. Assign responsibility for investigating outliers and escalating issues.
Train staff who interact with AI outputs. Medical directors, nurses and call center staff who rely on AI recommendations must understand what the system can and cannot do, when to override recommendations and how to document decisions. Training must be specific to the tools in use, not generic AI literacy.
Prepare for regulatory questions. Regulators expect organizations to articulate their governance approach, demonstrate that they have assessed risks and show that monitoring is ongoing. Create a governance record that can be produced in response to an audit or inquiry: policies, risk assessments, vendor due diligence, monitoring reports and escalation logs.
How This Relates to AI and Emerging Technology Governance
AI in prior authorization and claims processing is a specific application of a broader governance challenge. Organizations deploying AI in any business function—underwriting, fraud detection, customer service, clinical decision support—face similar questions: How do we assess risk? Who owns compliance? How do we monitor performance? What do we tell regulators?
The NIST Cybersecurity Framework and the NIST Privacy Framework provide voluntary structures that help organizations organize this work. The [Cybersecurity Framework](https://www.nist.gov/cyberframework) offers a risk-based approach to identifying, protecting, detecting, responding to and recovering from cybersecurity threats. The [Privacy Framework](https://www.nist.gov/privacy-framework) provides a parallel structure for managing privacy risks, emphasizing data minimization, transparency and accountability. Neither framework is specific to AI, but both can be adapted to address AI-specific risks.
Organizations that establish a general AI governance program—defining roles, setting risk tolerances, standardizing assessment processes, implementing monitoring—can deploy AI in prior authorization and other use cases more quickly and with greater confidence. Those that treat each AI project as a standalone initiative accumulate technical debt, inconsistent practices and ungoverned risk.
Taking the Next Step
If your organization is deploying or considering AI in prior authorization, claims processing or utilization management, and you do not have clear executive ownership of the governance program, you are building exposure. The regulatory environment will continue to evolve, but the expectation that organizations demonstrate due diligence, document decisions and maintain ongoing oversight is already established.
A confidential consultation can clarify what governance obligations apply to your specific systems and operating context, who should own this work internally, what a defensible governance program looks like and how to measure progress. If this resonates, reply directly to discuss your situation.
Sources
- Cybersecurity Framework | NIST , www.nist.gov
- Privacy and Security | Federal Trade Commission , www.ftc.gov
- Privacy Framework | NIST , www.nist.gov
Related service: AI and Emerging Technology Governance
Governance for how your organization adopts artificial intelligence: approved uses, data handling boundaries, review before deployment, and accountability for the output.