How does your AI governance program compare?

    See where your program has gaps in less than 2 minutes.

    Take the assessment
    Health Insurance | AI Governance

    Best Practices Guide  |  AI Governance in Regulated Industries

    Health Insurance AI Denial Lawsuits: Lessons for Claims Automation Governance

    Recent lawsuits against major health insurers allege that AI models were used to deny claims with minimal individualized human review, no accessible audit trail, and reviewer incentives that discouraged deviation from algorithmic output. These allegations, combined with new CMS and NAIC guidance, point to concrete governance controls that claims automation programs should implement: immutable decision logging, a genuine human-in-the-loop checkpoint, model version traceability, and documented oversight aligned to regulatory expectations.

    Why Claims Denial Litigation Is a Governance Signal

    Over the past 12 months, several lawsuits filed against health insurers have alleged that AI and algorithmic tools were used to deny claims or terminate coverage with little or no individualized clinical review. These are civil complaints, and the underlying allegations have not been adjudicated. But regardless of case outcomes, the complaints describe specific governance failures that any enterprise deploying claims automation should treat as a design checklist:

    • Absent or inaccessible audit trails for individual decisions
    • Unclear accountability between the AI vendor and the insurer deploying the system
    • Human review processes that existed on paper but not in practice

    For AI governance leaders, the value of this litigation is not legal precedent. It is a documented account of what regulators and courts consider evidence of inadequate oversight.


    What the Complaints Describe

    3 Major lawsuits filed against UnitedHealth, Humana, and Cigna
    1.2s Alleged average physician review time per claim in the Cigna PXDX litigation
    2 Regulatory actions now defining oversight expectations for AI in claims decisions

    Estate of Lokken v. UnitedHealth Group

    Filed in the District of Minnesota in November 2023, this suit alleges that UnitedHealth and NaviHealth used the nH Predict AI model to deny post-acute care to Medicare Advantage patients, overriding the determinations of treating physicians. The complaint further alleges that human clinical reviewers had limited practical ability to deviate from AI-generated recommendations, reportedly because performance metrics were tied to algorithm compliance.

    Barrows v. Humana

    A related suit makes similar allegations regarding the same algorithm's use in terminating skilled nursing and rehabilitation coverage. As with the UnitedHealth complaint, the central allegation is that a human reviewer was nominally in the loop but structurally unable or unincentivized to exercise independent judgment.

    Kisting-Leung v. Cigna Health and Life Insurance Co.

    Filed in the Eastern District of California in July 2023, this complaint alleges that Cigna's PXDX system allowed physicians to batch-deny claims at an average of 1.2 seconds per claim. The complaint asserts that formal physician sign-off did not reflect substantive individualized medical review.

    Common pattern across all three complaints

    A human reviewer nominally present in the workflow, but structurally unable or unincentivized to exercise independent clinical judgment. The AI output was treated as the effective decision, with human review serving as a procedural formality.


    Regulatory Expectations Now in Place

    Two regulatory developments give these governance gaps a direct compliance dimension.

    Regulatory Action Key Requirement Scope
    CMS-4201-F (Medicare Advantage final rule) Coverage determinations must be based on an individual enrollee's specific medical circumstances. Algorithms or software tools cannot serve as the sole basis for a denial. Algorithmic tools must be auditable with documentation retained to support individualized medical necessity decisions. Medicare Advantage plans
    NAIC Model Bulletin on AI Systems by Insurers (December 2023) Documented AI governance across the full lifecycle: development, acquisition and testing, deployment, and ongoing monitoring. Oversight requirements extend to third-party vendors supplying AI tools used in coverage decisions. State-level adoption varies; governance programs should track applicable state guidance

    State adoption of the NAIC bulletin is not uniform. Governance programs should verify applicable state guidance rather than assume a single national standard applies.


    Technical Controls to Close the Audit Trail Gap

    The complaints and regulatory guidance together point to a set of technical controls that claims automation architectures should address:

    • Immutable decision logging: Every AI-assisted claim decision should generate a tamper-evident log capturing model version, input data, model output, and the reviewer action taken.
    • Model version traceability: The specific model version and configuration active at the time of each decision must be identifiable in retrospect, including any updates or reconfigurations that occurred between deployment and the decision.
    • Human-in-the-loop enforcement: Workflows should technically enforce a genuine review checkpoint, not merely record that a reviewer was present. This includes structured fields requiring documented rationale when accepting or overriding an algorithmic recommendation.
    • Override rate monitoring: Anomalously low override rates can indicate that reviewers are not exercising independent judgment. Monitoring should flag denial spikes or override rate anomalies by claim type, model version, and reviewer cohort.
    • Vendor audit cooperation: Contracts with AI tool vendors should include data-retention commitments, audit-cooperation clauses, and access rights sufficient to respond to regulatory inquiry or discovery.

    Policy and Ownership Controls

    Technical controls require corresponding policy and accountability structures to be effective:

    • A named AI governance owner accountable for claims automation systems, distinct from the vendor relationship manager
    • Documented roles and responsibilities for human reviewers, including explicit authority to deviate from algorithmic recommendations without performance consequences
    • Periodic review of denial rates and override patterns as a governance metric, not only as an operational one
    • Third-party vendor onboarding criteria requiring disclosure of model training data, update cadence, and validation methodology for tools used in coverage decisions
    • Documented escalation paths when algorithmic output conflicts with treating physician determinations

    Evaluation Questions for Governance Leaders

    Use the following questions to assess your current claims automation governance posture against the gaps described in this litigation and the regulatory record:

    • Can the system produce an immutable audit trail showing model version, inputs, and reviewer action for any individual denial?
    • Does the workflow technically enforce a genuine human review checkpoint, or do design and incentives default to the algorithm's output?
    • Is documentation available to demonstrate individualized medical necessity review, consistent with CMS Medicare Advantage requirements?
    • Is model monitoring in place to detect abnormal override rates or denial spikes by claim type or model version?
    • Do vendor contracts include audit-cooperation and data-retention commitments in the event of regulatory inquiry or discovery?
    • Are reviewer performance metrics structured to avoid penalizing deviation from algorithmic recommendations?

    Where Runtime Governance Fits

    The gaps described across these lawsuits, missing audit trails, unclear model accountability, and human review that exists in name but not in substance, are runtime problems as much as policy problems. Runtime governance is designed to enforce oversight at the point of decision: logging model and agent actions as they occur, applying policy controls before an automated output reaches a downstream system, and maintaining an audit record that reflects what actually happened rather than what a policy document says should happen.

    For claims automation specifically, that means the ability to enforce and log human checkpoints, track model version at the moment of each decision, and produce records that hold up under regulatory or litigation scrutiny.

    Trussed AI provides runtime governance and security controls for enterprise AI systems, including audit logging, runtime policy enforcement, and oversight mechanisms relevant to the accountability gaps described in this litigation.


    Frequently Asked Questions

    Do these lawsuits establish legal precedent for AI governance requirements?

    Not yet. The complaints described here are civil actions in early litigation stages, and the allegations have not been adjudicated. Their governance value lies in the specific practices they document as problematic: absent audit trails, nominal human review, and performance incentives tied to algorithm compliance. These descriptions align with regulatory guidance that is already in effect.

    Does the NAIC Model Bulletin have the force of law?

    The NAIC Model Bulletin is not itself a binding federal rule. Its weight depends on adoption and implementation by individual state insurance regulators. Governance programs should track applicable state guidance for each jurisdiction where they operate rather than assuming uniform national applicability.

    Does the CMS Medicare Advantage rule apply to commercial health plans?

    CMS-4201-F applies to Medicare Advantage plans specifically. Commercial health plans are not directly subject to its requirements, though the NAIC Model Bulletin and applicable state regulations may impose parallel or overlapping obligations. Governance leaders should assess the regulatory frameworks applicable to each product line separately.

    What does a genuine human-in-the-loop checkpoint require technically?

    At minimum, a genuine checkpoint requires: a structured workflow step that cannot be bypassed automatically; a documented field requiring the reviewer to record a rationale when accepting or overriding a recommendation; logging of the reviewer identity, timestamp, action taken, and rationale; and performance metrics that do not penalize reviewers for exercising independent judgment. A human reviewer who can proceed without entering a rationale is not a functional governance checkpoint.

    What should vendor contracts include to address these governance gaps?

    Vendor contracts for AI tools used in coverage decisions should include: data-retention commitments sufficient to support regulatory or litigation discovery; audit-cooperation clauses granting the insurer access to model documentation on request; disclosure obligations for material model updates or reconfigurations; and warranty or representation provisions regarding model validation and performance on the insurer's use case. Legal review of these provisions against applicable state and federal requirements is advisable.

    Evaluate Your Claims Automation Governance Posture

    Recent litigation and regulatory guidance define concrete expectations for oversight, auditability, and human review in AI-driven claims decisions. Assess whether your current architecture can produce the audit trail and enforcement evidence these standards require.

    Talk to an Expert