Use-case guide
AI in Insurance Claims & Adjudication
AI in claims adjudication is the live wire of insurance regulation right now — distinct from underwriting AI. Three things changed in 2023-2025: (1) CMS issued binding rules requiring human review for Medicare-Advantage AI denials, (2) class actions against UnitedHealthcare and Cigna over algorithmic denials moved through US federal court, (3) state insurance commissioners started subpoenaing claim-AI documentation in market-conduct exams. The risk profile is acute because every wrongful denial is a discrete plaintiff with a discrete cause of action.
For: Claims VPs, SIU teams, healthtech claims platforms, Medicare-Advantage operators, AI claims-adjudication vendors
What's at stake
Medicare Advantage AI denials must have human review
CMS Final Rule (April 2023, effective 1 Jan 2024) requires AI/algorithmic tools used to make coverage decisions to be applied only after considering the individual patient's circumstances — and human review is required before adverse coverage determinations.
Class-action exposure under ERISA + state law
Estate of Lokken v. UnitedHealthcare and Barrows v. Humana have established the template for ERISA-based AI-claim-denial class actions. Damages stack: ERISA equitable relief + state UDAP statutory damages + punitive in some jurisdictions.
Colorado AI Act + state AI insurance rules apply
Colorado AI Act treats insurance claims as a consequential decision. Annual impact assessment + adverse-decision notice + human appeal route are statutory.
EU AI Act treats claims AI as high-risk (Annex III §5)
Risk-assessment and pricing AI in EU insurance includes claims-adjudication algorithms. Annex III §5(c) coverage; full risk-management + transparency + human oversight duties.
Regulations that apply
CMS Medicare Advantage Final Rule (2023)
RegulationMandates human review for AI/algorithmic coverage denials. Provider-side appeal rights expanded. CMS audit and revocation powers are active.
Where in the text: 42 C.F.R. § 422.101(c)(1); CMS-4201-F (2023).
Colorado AI Act
LawInsurance claims are 'consequential decisions' — annual impact assessment, deployer registration, consumer notice + human-appeal route.
Where in the text: Sec. 6-1-1701(3)(g); 6-1-1703.
EU AI Act
LawClaims adjudication AI in life/health is high-risk. Article 14 human oversight, Article 13 transparency to deployer, Article 26 deployer-specific duties.
Where in the text: Annex III §5(c); Articles 13, 14, 26.
Arizona HB 2175 + parallel state laws
LawAZ HB 2175 restricts AI use in health insurance claim denials. Comparable bills in CT, NJ, OR, TX, WA — patchwork compliance.
Where in the text: Ariz. Rev. Stat. § 20-3252.
Do
- ✓Document human-in-the-loop for every adverse decision — sample-based audits won't satisfy CMS or plaintiff lawyers. Per-decision human review record is the floor.
- ✓Train your claims AI on data that includes the medical necessity criteria — not just claims-paid history. Otherwise you're reproducing historical denials.
- ✓Build an audit log per AI decision: model version, input features, score, reviewing human, timestamp. ERISA discovery will demand it.
- ✓Publish an algorithmic-decision policy at the member-facing level — Colorado AI Act requires consumer notice; CMS expects readable disclosure.
- ✓Maintain a clinical-reviewer-override rate metric. If your AI is overridden <2% of the time, regulators question whether the review is real.
Don't
- ✗Don't auto-deny based on length-of-stay benchmarks (Naviheath-style) without per-patient medical-necessity assessment — that's the exact pattern in Lokken v. UHC.
- ✗Don't reuse a Medicare-Advantage claims model for commercial plans without revalidating — coverage criteria differ and disparate-impact analysis must be plan-specific.
- ✗Don't take the claims-AI vendor's word for HIPAA-equivalent EU/UK GDPR-compliance — verify SCCs + DPA + processor obligations directly.
- ✗Don't deploy a generative-AI summarisation tool that's used in denial decisions without Article 50 disclosure to members in EU markets.
- ✗Don't disregard prior-authorization clinical guidelines because the model says no — the model is a tool; the clinical guideline is the legal floor.
Also worth knowing
If you operate in PPO/HMO commercial markets: ERISA's 'arbitrary and capricious' standard for benefits denials interacts with AI — courts increasingly hold that systematic AI denial patterns ARE arbitrary. If you're a third-party administrator (TPA): the TPA-as-fiduciary doctrine flows AI risk to you even if the underlying employer-plan bears nominal cost. If you operate in Medicaid managed-care: state Medicaid agency AI bulletins are emerging — California DMHC has been first-mover.
Want a tailored answer?
The wizard takes your jurisdiction, AI use case, and data types and gives you the top-3 regulations to focus on — in 60 seconds.
Start the wizard →Educational guide. Not legal advice. For specific compliance decisions, consult qualified counsel in the relevant jurisdiction.
Note: this guide was drafted with AI assistance — Anthropic Claude.