Patient Rights11 min read

Can AI Deny Your Health Insurance Claim? State Rules for 2026

Thirteen states regulate AI in health-plan utilization review. Eleven require a human to make the denial; Indiana and Utah let AI drive it and require the insurer to say so. We read every statute, checked which Nebraska insurers actually disclose AI use, and found the gap where Medicare's own AI prior authorization pilot sits outside all of it.

Health Bill Central Team·

13 states now regulate artificial intelligence in health-plan utilization review, and they do not all answer it the same way. 11 require a qualified human to make the denial. Two others — Indiana and Utah — let AI drive it and instead require the insurer to disclose that it did. In the other 37 states, no law addresses AI in that decision at all.

The laws do not cover the plans many patients are actually on. A self-funded employer plan sits outside state insurance regulation entirely, and Medicare Advantage answers to federal standards rather than state ones: a Nebraskan on a commercial plan gets the protection of the state's new law, and the same Nebraskan on Medicare Advantage does not. Only five of the 14 laws require an insurer to disclose that it uses AI at all, and the disclosure does not always reach the patient — in Maryland it goes to the state regulator alone. The largest AI-assisted prior authorization program now running is Medicare's own: a pilot in traditional fee-for-service Medicare, launched on 1 January 2026, that no state law reaches, and in which the companies doing the reviewing are paid a share of the spending they avert.

Which states have a law

13 states have passed 14 of these laws; Illinois enacted two. As of August 30, 2026, 8 are in force — California and Illinois came first, on 1 January 2025, followed by Texas, Maryland, Nebraska, Washington, Indiana and Iowa. The other 6 are signed and waiting: Alabama's takes effect this October, Colorado's, Georgia's, Minnesota's and Utah's on 1 January 2027, and Illinois's second law a year after that.

The colour on the map is what the law does to the denial decision, not how recently it passed. Texas is the only state where an automated system may not issue an adverse determination at all. Ten states require a named clinician to make it — including Nebraska and Minnesota, whose AI clauses are often reported as mere “sole basis” rules but sit inside statutes that already require a physician. Indiana and Utah let AI make the call and require the insurer to say so. Faded states have passed a law that has not taken effect yet; click any state to jump to its row.

What each state's law does to an AI denial

5 states are drawn faded: their law has passed but has not taken effect yet. The colour still shows what it will require. Verified against enrolled bill text, August 2026.

AI denial banned outright (1)Only a clinician may deny (10)AI may deny, if disclosed (2)No law (37)
Table 1. Every enacted state law on AI in health-plan utilization review, as of August 30, 2026. Each row was read against the enrolled or chaptered text on the state's own legislature site; bill numbers link to that text.
StateLawIn forceWhat it requires
AI denial banned outright
TexasSB 815Sep 1, 2025The flattest prohibition of the set: an automated system may not make an adverse determination at all, in whole or in part. Applies to plans issued or renewed on or after 1 January 2026.
Only a clinician may deny
CaliforniaSB 1120Chapter 879, Statutes of 2024Jan 1, 2025A licensed physician or comparable professional must make the medical-necessity call, and the tool may not decide from a group dataset alone.
IllinoisHB 2472Public Act 103-0656Jan 1, 2025Where an algorithmic automated process is used, only a clinical peer may issue the adverse determination.
MarylandHB 820Chapter 747, Laws of Maryland 2025Oct 1, 2025Bars the tool from denying, delaying or modifying care, and adds an AI-use flag to the quarterly adverse-decision report carriers already file with the Commissioner. Chapter 165 (2026) later made that reporting zip-code-level.
NebraskaLB 77Jan 1, 2026Stacks four requirements: a physician or specialty-matched clinical peer must make the denial, AI may not be its sole basis, the plan must say on its own public website whether it uses AI, and §13 bars paying a review agent — or its reviewers — based on denial volume.
WashingtonE2SSB 5395Chapter 157, Laws of 2026Jun 11, 2026Algorithms may approve a request, but may not deny one without human review of the patient's own record.
IowaHF 2635Acts Chapter 1087Jul 1, 2026Requires human review before an AI-assisted adverse determination stands.
AlabamaSB 63Act 2026-589Oct 1, 2026not yetAdds an annual certification that the tool does not rely on a group dataset or discriminate, backed by fines and licence revocation.
ColoradoHB26-1139Chapter 325, Session Laws of Colorado 2026Jan 1, 2027not yetAI may not be the sole basis for an adverse determination, and a human must make the final call.
GeorgiaSB 444Act 411, Georgia Laws 2026Jan 1, 2027not yetNo adverse determination may issue until a human review involving a clinical peer has happened, and the tool may never override that peer.
MinnesotaHF 4188Chapter 124, Article 3 §6 (Minn. Stat. §62M.09 subd. 3(f))Jan 1, 2027not yetNarrower than it is usually reported: it bars automated processing alone without clinician review, and never defines “artificial intelligence.”
AI may deny, if disclosed
IndianaHB 1271Public Law 88-2026Jul 1, 2026The only one aimed at downcoding rather than denial — and it requires the insurer to say when AI drove either.
UtahSB 319Chapter 240, Laws of Utah 2026Jan 1, 2027not yetNebraska's four-way disclosure duty, plus something Nebraska lacks: the notice must sit in a conspicuous place the general public can reach.
IllinoisSB 3114Public Act 104-0568Jan 1, 2028not yetAimed at downcoding rather than denial: AI may not be the sole basis for reducing the code a claim was billed under, and the enrollee must be told when it was.

What changes next

Laws that have passed but have not taken effect yet — the faded states on the map.

October 1, 2026Alabama (SB 63)

January 1, 2027Colorado (HB26-1139), Georgia (SB 444), Minnesota (HF 4188), Utah (SB 319)

January 1, 2028Illinois (SB 3114)

What complying everywhere would require

A national insurer wanting one policy good in all 13 states would have to meet the strictest version of each rule, and the strictest version comes from a different state each time.

  • Keep AI out of the denial. Nine laws bar an algorithm as the sole basis; Texas bars it “wholly or partly.”
  • Put a named clinician behind it. Eight laws require one — Illinois a clinical peer, California a professional “competent to evaluate the specific clinical issues involved.”
  • Judge the patient, not the dataset. California, Maryland, Washington and Alabama require the decision to rest on the individual's own circumstances.
  • Tell everyone. Five laws require disclosure that AI is in use; Nebraska and Utah set the widest audience — the regulator, providers, enrollees and a public website.
  • Submit the tool for review. Seven laws require periodic accuracy or bias checks, or let the regulator audit the system.

The rule most of them converge on

Washington states it most plainly. Under E2SSB 5395, in force since June 2026:

Artificial intelligence shall not be the sole means used to deny, delay, or modify health care services. Algorithms may be used to process and approve prior authorization requests, but may not be used without human review to deny care based on a determination of medical necessity.

Approve by machine, deny by human. Texas goes further and bars an automated system from making an adverse determination “wholly or partly”. California and Alabama require the determination come from a licensed clinician who can actually evaluate the tool's conclusion. Illinois requires a clinical peer. Georgia says the software may never “supersede the judgment of such clinical peer.”

Nebraska adds something none of the others do, and it is the most interesting provision in the whole set. Section 13 of LB 77 bars a “utilization review agent” from being “compensated based on its volume of denials,” and bars it from tying any incentive or penalty for an individual reviewer to how many denials that reviewer issues or upholds. The term is not about software: a utilization review agent is the company that performs the review, and the individual reviewers are its staff. Software cannot be paid. The firm that deploys it can, and that is the money the section is aimed at — the financial structure around the decision, rather than the tool used to reach it.

What your insurer says about it

Nebraska is, as of August 30, 2026, the only state whose law in force makes a health plan say on its own public website if it uses AI to review your care — Utah's equivalent duty starts in January 2027. LB 77 §12(2) requires disclosure “to the department, to each health care provider in its network, to each enrollee, and on its public website.” That duty switched on 1 January 2026, which means there is now something checkable.

We checked the 7 carriers writing Nebraska commercial or marketplace business, where the duty plainly applies, in August 2026. 4 publish a statement. 3 say nothing either way.

Table 2. The 10 carriers writing Nebraska commercial or marketplace business, checked in August 2026 by reading each carrier's site as rendered in a browser — several disclosures sit behind state selectors and accordions that never appear in the page source. “No statement found” means its legal, compliance, state-notice, prior-authorization and provider pages plus a site-restricted search turned up nothing; that negative is weaker for carriers with no internal site search. It is not a finding of non-compliance: LB 77 §12(2) requires a disclosure only from a carrier that actually uses AI in utilization review.
CarrierNebraska businessAI use disclosed?What we found
AetnaCommercial / groupYesBehind a state selector; the notice renders for Nebraska and not for California, Texas, Washington, Massachusetts or Arkansas.
UnitedHealthcareCommercial / marketplaceYesPublished on a page titled “Nebraska required state notices”.
Cigna HealthcareCommercial / groupYesBehind a Nebraska accordion. Cigna's site-wide precertification page carries a differently scoped statement describing the tool as assisting clinical reviewers in the utilization review process.
Ambetter Health (Centene)MarketplaceYesDated 18 December 2025 — two weeks before LB 77 took effect — and it borrows the statute's own words, “sole basis to deny, delay, or modify”.
Blue Cross and Blue Shield of NebraskaCommercial / marketplaceNo statement foundHas a page titled “AI Use Disclosure”, but it covers only its chatbot and says nothing about utilization review. Its site map shows no other AI-labelled page.
MedicaMarketplace / groupNo statement foundPublishes an AI addendum imposed on its vendors, which does not state whether Medica itself uses AI in utilization review.
OscarMarketplaceNo statement foundMaintains a state-mandated utilization-review statistics page, so it does operate a compliance-posting process; no AI notice found. Oscar exposes no drivable internal search, so this negative rests on targeted checks and site: queries.
Nebraska Total Care (Centene)Heritage Health (Medicaid)n/aNot covered by the lawWhether LB 77 §12 reaches a Heritage Health plan is unsettled: §44-5418 exempts “an agent acting on behalf of … the State of Nebraska” from the definition of utilization review agent, and these plans review care under a state Medicaid contract. No notice was found on this site, but we do not list that as a gap against an unsettled duty.
Molina Healthcare of NebraskaHeritage Health (Medicaid)n/aNot covered by the lawIts 2026 provider manual forbids providers — not itself — from using AI to deny or delay covered services without clinician review — the mirror of the duty the statute puts on the plan — while saying nothing about Molina's own use.
HumanaMedicare Advantagen/aNot covered by the lawHumana's Nebraska presence is Medicare Advantage, which 42 CFR 422.402 places outside state insurance standards, so LB 77 does not reach it. Humana does publish an AI use notice — on its Ohio Medicaid pages, where a state requires one.

The disclosures that do exist describe the same architecture the statutes draw. Aetna: “AI may be used to auto-approve claims that meet required criteria… Aetna never uses AI to deny care for medical reasons.” UnitedHealthcare: “AI does not make clinical decisions to deny coverage. Every clinical denial is reviewed by a qualified medical professional.” Ambetter: “AI-based algorithms may be used to assist in approving certain health care service requests. These tools are not used to make denial decisions and are not the only factor considered in any review.”

These disclosures exist because a law required them

Aetna publishes its notice on a page that serves 23 states through a dropdown. Select Nebraska and a heading appears: “Notice about the use of artificial intelligence (AI) in utilization management.” Select California, Texas, Washington, Massachusetts or Arkansas and it is not there — including three states that regulate AI in utilization review but do not require a website posting. Aetna's own Washington section explains the logic for a different rule: “Washington law requires us to post info on our website that identifies each HCBM we contract with.” The page carries what each state compels, and nothing else.

And Ambetter dated its Nebraska notice 18 December 2025 — two weeks before LB 77 took effect — using the statute's own words back to it: it does not use AI “as the sole basis to deny, delay, or modify health care service requests.”

The same companies disclosed in the state that asked and not in the states that did not. What their practices are elsewhere, these pages do not say — which is the argument for disclosure mandates, and unusually clean evidence for a policy question.

Why silence tells you nothing

Here is the flaw in how these laws are built. LB 77 is conditional: a review agent must disclose if AI-based algorithms are used. A plan that does not use AI has nothing to post. So when 3 of 7 Nebraska carriers say nothing, you cannot tell whether they use no AI or simply published no notice — and neither can the Department of Insurance, without asking.

Blue Cross and Blue Shield of Nebraska illustrates the gap precisely. It has a page titled “AI Use Disclosure.” It covers the company's chatbot, and says nothing about utilization review. That may be entirely accurate and entirely compliant. It also tells a patient nothing about whether an algorithm touched their prior authorization.

Utah fixed this on paper. Its SB 319, effective January 2027, requires the notice be posted “in a conspicuous location accessible by the general public” — the word “conspicuous” doing work that Nebraska's statute leaves undone. Today, finding these notices means knowing that Aetna's sits behind a state dropdown, Cigna's behind an accordion on a compliance page, and UnitedHealthcare's on a page called “required state notices.”

The federal rules are thinner than you would guess

Most national coverage of this topic implies a federal backstop. There is much less than that.

For Medicare Advantage, CMS has said an algorithm that decides coverage from a population data set rather than the individual patient does not comply with 42 CFR 422.101(c), and that a predicted length of stay cannot itself terminate coverage. Those are real constraints. But CMS proposed broader AI guardrails in the CY2026 Medicare Advantage rule and did not finalize them. What exists is narrower than the state laws above.

And the direction of preemption is the opposite of what most people assume. Under 42 CFR 422.402, federal standards supersede state ones for Medicare Advantage plans. So a Nebraskan on a commercial plan is covered by LB 77; the same person on Medicare Advantage is not. Self-funded employer plans sit outside state insurance regulation too.

Congress has passed no statute on AI in utilization review. The one federal attempt at broader guardrails, proposed in the CY2026 Medicare Advantage rule, was never finalized. That absence is what produced the patchwork: a Texan on a commercial plan cannot have an algorithm deny her claim even in part, a patient in 37 states has no rule at all, and a Nebraskan is covered on a commercial plan but not on Medicare Advantage. Whether a human being has to stand behind your denial depends on your zip code and on which plan you happen to have.

Medicare is running the largest AI prior authorization program in the country

CMS launched the WISeR Model — Wasteful and Inappropriate Service Reduction — on 1 January 2026 in New Jersey, Ohio, Oklahoma, Texas, Arizona and Washington, with prior authorization applying to services delivered from 15 January. It brings prior authorization to traditional Medicare for a set of services including skin and tissue substitutes, electrical nerve stimulators and epidural steroid injections for pain, and CMS contracts with vendors using AI and machine learning to run the reviews.

Two of those six states — Texas and Washington — have their own laws about AI in utilization review, and neither applies here. (Arizona requires a medical director to review a medical-necessity denial personally, but its law says nothing about AI at all.) WISeR is traditional Medicare, and state insurance codes do not reach it.

Now recall Nebraska's §13, which bars paying a review agent based on denial volume. WISeR pays its participants a cut of what they stop Medicare spending. CMS's own model page says they “receive a percentage of the expenditures associated with averted wasteful, inappropriate care as a result of their reviews.” The percentage is 25. Under the WISeR Participant Guide, a company earns 25% of the average Medicare spending for that service in that region, less a discount for the denials Medicare's own contractors would have made anyway, multiplied by a quality score that never falls below 90%. There is no cap. Payments, in CMS's words, “are calculated from requests that did not result in a paid claim.”

Nebraska bars pay tied to the volume of denials; WISeR pays a share of averted spending. Not identical, but the same idea — the reviewer earns more the less care is approved. A state legislature prohibited it for the plans it regulates. The federal pilot is built on it, and a Nebraskan on traditional Medicare gets the federal version, because their state's law stops at the Medicare line.

WISeR also skipped a step. CMS published it as a notice rather than a rule, with no comment period. In May 2026, at the request of four senators, the Government Accountability Office concluded that the notice is a rule for purposes of the Congressional Review Act, and therefore had to be submitted to Congress before it could take effect. It had not been. CMS submitted it on 9 June 2026, conceding the procedure, which opened a window for Congress to strike the rule down by simple majority. The Senate tried on 16 July 2026 and the motion failed 46 to 50. The White House had argued that day that WISeR is a “limited test program” aimed at services where up to two-thirds of what Medicare spent on them “may have been fraudulent, wasteful, or abused” — an estimate published with no methodology, though even taken at face value it does not conflict with anything here. A program can target real fraud and still sit outside the rules that protect the patient it denies. The model is scheduled to run to the end of 2031.

CMS says determinations come within three calendar days, two where delay could jeopardize the patient, and that “non-affirmations will require the review of a human clinician and cannot be performed solely by technology.” What that looks like on the ground is contested. In an April 2026 letter to the Secretary of Health and Human Services, Senator Maria Cantwell of Washington — whose state is one of the six, and who opposes the model — wrote that providers there report waiting 15 to 20 days for determinations, “most often denials issued without any clear justification.” Those are providers' accounts relayed by a senator, not measured data, and there is no published CMS figure to set against them.

Whether WISeR denies care wrongly is unknown and will take years of data to establish. What is knowable now is that a program placing an algorithm between a patient and a procedure sits outside every protection this page has described.

What to actually do about it

The useful question is not whether AI touched your claim. By every disclosure now on the record, and by law in 11 states, a human is supposed to make the denial. The useful questions are whether one actually did, and who.

  • Ask who made the decision, by name. If your coverage is through an employer or the marketplace, federal law entitles you — on written request tied to your denial — to the name of the medical expert whose advice the plan obtained, whether or not it relied on that advice: 29 CFR 2560.503-1(h)(3)(iv). The Labor Department has said handing over the review company's name, or the expert's qualifications, does not satisfy it. This is also the one handle that reaches a self-funded employer plan, which no state law above can touch. Ask for the specialty as well, but know that the name is the part you are owed. Medicare Advantage and Medicaid managed-care plans must use a licensed, expertise-matched reviewer and are required to tell you nothing about who that was.
  • Ask for the criteria. Several of these statutes require the determination rest on your own clinical history rather than a group dataset. Ask what specifically in your record supported the denial.
  • Check your state's row above, then look for your carrier's AI notice — start at its legal, compliance or “state notices” page and look for a state selector.
  • Appeal. Whatever produced the denial, the appeal path is the same, and appeals succeed often enough to be worth the effort. Our guide to appealing a medical bill and our prior authorization guide walk through it.

If you are looking at a bill rather than a denial, our analysis of insurer prior authorization denial rates shows how much the numbers vary between plans in the same state.

Sources

Every law above was read against the enrolled or chaptered text on the state's own legislature or revisor site; each bill number links to it. We did this because the secondary lists disagree with each other and with the statutes — most often because AI language was written into a bill and struck by amendment before passage, which a bill's title and status never show.

3 bills commonly listed as AI utilization-review laws are not, and we left them out:

  • Arizona HB 2175: Enacted (Chapter 165, effective 1 July 2026) but contains no AI language at all — a full-text search for “artificial”, “algorithm” and “automat” returns nothing. It requires a medical director to individually review a medical-necessity denial without relying solely on any other source.
  • Florida SB 794: Never enacted — it died in committee on 16 June 2025. Its text also addressed insurance claims generally rather than health-plan utilization review.
  • Illinois HB 35: Passed the House and stalled in Senate Executive Committee. Illinois does have two AI utilization-review laws, but they are HB 2472 and SB 3114 — not this one.

Content is for informational purposes only and does not constitute financial, legal, or medical advice. Consult a qualified professional for advice specific to your situation.

Frequently Asked Questions

Can AI deny your health insurance claim?

In eleven of the thirteen states that have legislated on it, no — a qualified human must make the adverse medical-necessity determination. Indiana and Utah are the exceptions: their laws let AI drive the decision and instead require the insurer to disclose that it did. Washington's law puts the split plainly: algorithms may process and approve prior authorization requests, but may not be used without human review to deny care based on medical necessity. Texas goes furthest, barring an automated decision system from making an adverse determination "wholly or partly." In the remaining states no such rule exists, and federal protections are narrower than most coverage suggests.

How do I find out whether my insurer uses AI to review my care?

Start at your carrier's legal, compliance or "state notices" page and look for a state selector — these disclosures are routinely hidden behind dropdowns and accordions rather than published plainly. Nebraska is currently the only state whose in-force law requires a plan to post on its own public website if it uses AI; Utah's equivalent duty begins 1 January 2027 and adds that the notice must be conspicuous. If your carrier posts nothing, that is not proof it uses no AI: the disclosure duty is triggered only when AI is actually used, so silence is ambiguous.

Do these state laws protect me if I have Medicare Advantage?

Generally no. Under 42 CFR 422.402, federal standards supersede state ones for Medicare Advantage plans, so a state law on AI in utilization review does not reach your MA coverage. Self-funded employer plans also sit outside state insurance regulation. CMS has said an algorithm that decides coverage from a population data set rather than your own circumstances does not comply with 42 CFR 422.101(c), but broader AI guardrails proposed in the CY2026 Medicare Advantage rule were not finalized.

What is the WISeR model?

WISeR — Wasteful and Inappropriate Service Reduction — is a CMS pilot that began 1 January 2026 in New Jersey, Ohio, Oklahoma, Texas, Arizona and Washington, with prior authorization applying to services delivered from 15 January. It applies prior authorization to traditional Medicare for services including skin and tissue substitutes, electrical nerve stimulators and epidural steroid injections, with CMS contracting vendors that use AI and machine learning to run reviews. Participating companies receive an incentive payment tied to a share of the resulting savings. Because it is traditional Medicare, state laws on AI in utilization review do not apply to it, including in Texas and Washington, the two participating states that have such laws.

What should I ask if my prior authorization is denied?

Ask who made the decision, by name, specialty and licensure, in writing — every one of these state laws turns on a qualified human making the determination. Then ask what in your own clinical record supported it, since several statutes require the decision rest on your individual circumstances rather than a group dataset. Then appeal. The appeal path is the same regardless of what produced the denial, and overturn rates are high enough to make it worth the effort.

Was this article helpful?

Ready to Take Action?

Upload your medical bill and we'll help you identify errors, check charity care eligibility, and generate professional appeal letters.

Analyze Your Bill