AI Prior Authorization Denial Litigation: Governance Lessons for Payers
Recent litigation against major payers alleges that algorithmic tools functioned as the effective decision-maker in prior authorization denials, with minimal individualized clinical review and no auditable record of human oversight. CMS guidance, the NAIC Model Bulletin, and state laws like California's SB 1120 converge on the same requirement: AI can inform a denial but cannot be its sole basis, and payers must be able to prove that a documented clinician review occurred.
Litigation and Regulatory Signals at a Glance
Four developments define the current risk landscape for AI-assisted prior authorization: two active federal lawsuits and two regulatory frameworks converging on the same expectations.
Estate of Lokken v. UnitedHealth Group
Alleges algorithmic length-of-stay predictions were used to support Medicare Advantage denials without adequate individualized review (D. Minn., filed Nov. 2023).
Kisting-Leung v. Cigna
Alleges batch claim review averaging seconds per claim, raising questions about required individualized medical review (E.D. Cal., filed 2023).
CMS-0057-F
Requires specific denial reasons and public reporting of denial rates and decision timing, phased through 2026 to 2027.
NAIC Model Bulletin and State Laws
NAIC (Dec. 2023) and California SB 1120 (2024) require AI governance programs, clinician supervision, and prohibit AI as the sole basis for a denial.
What the Litigation Reveals
Two federal cases filed within the past two years illustrate a shared allegation: that an algorithmic tool functioned as the de facto decision-maker in prior authorization, without sufficient individualized clinical review. In Estate of Lokken v. UnitedHealth Group, filed in the District of Minnesota in November 2023, plaintiffs allege that UnitedHealthcare and NaviHealth used the nH Predict algorithm to project post-acute care lengths of stay for Medicare Advantage members, and that denials were supported by these predictions despite what the complaint characterizes as a high rate of internal reversal on appeal. These figures originate from the complaint, not an adjudicated finding, but they illustrate the evidentiary risk created when internal appeal-reversal data conflicts with the volume of AI-influenced denials.
A separate case, Kisting-Leung v. Cigna, filed in the Eastern District of California, centers on Cigna's PxDx claims review system. Reporting cited in the litigation found that physicians using the system spent an average of only a few seconds per claim during batch review sessions, raising the question of whether contemporaneous, individualized medical review occurred as required. Both cases share the same underlying dispute: not whether AI was used, but whether a documented, individualized clinical judgment was actually exercised before a denial was finalized.
The Regulatory Backdrop Payers Must Reconcile
CMS, the NAIC, and at least one state legislature have issued guidance that converges on similar expectations, though none specify a single technical standard. CMS has communicated to Medicare Advantage organizations, through sub-regulatory guidance, that an algorithm or software tool cannot serve as the sole basis for a coverage denial; determinations must reflect the individual patient's circumstances consistent with existing MA coverage criteria. Separately, CMS finalized the Interoperability and Prior Authorization Final Rule (CMS-0057-F) in January 2024, requiring affected payers, including Medicare Advantage, Medicaid, CHIP, and QHP issuers, to provide specific denial reasons and implement API-based data exchange, with compliance phased through 2026 and 2027. The rule also requires public reporting of approval and denial rates and average decision times, increasing the visibility of denial patterns that regulators or plaintiffs can use as evidence.
At the state level, California's SB 1120 (Physicians Make Decisions Act), enacted in 2024, requires that AI or algorithm-based tools used in utilization review be supervised by a licensed physician or qualified provider, and prohibits such tools from being the sole basis for a medical necessity denial. Colorado's algorithm governance framework under SB21-169, developed in a life insurance underwriting context rather than prior authorization specifically, reflects the same broader regulatory direction toward testing and accountability for algorithmic decision systems. The NAIC's December 2023 Model Bulletin directs insurers to establish AI governance programs covering accountability, documentation, risk management, and third-party vendor oversight, directly relevant given that both cases above name third-party or vendor-supplied models as central to the alleged failures. None of these sources prescribe a specific audit-log format or runtime architecture; they state outcomes rather than system design, leaving payers to determine how to produce defensible evidence.
The Common Failure Mode: Advisory Versus Determinative AI
One distinction recurs across the litigation and regulatory guidance reviewed: whether an AI-generated recommendation was advisory input to a human reviewer or functioned, in practice, as the final decision. Plaintiffs in both cases allege the latter, supported by evidence such as short per-claim review times and denial patterns that track algorithmic output regardless of individual clinical detail. Regulators have written this advisory-versus-determinative distinction directly into guidance and statute rather than leaving it as an internal policy matter.
This creates a specific evidentiary problem for payers. If a system cannot produce a record showing what the AI recommended, what clinical data a human reviewer considered, how long that review took, and whether the reviewer affirmed or overrode the recommendation, the payer has no way to demonstrate after the fact that the advisory label matched actual practice. In litigation, the absence of that record tends to function as evidence against the payer, even where no policy violation occurred, because there is nothing available to show otherwise.
Implementation Considerations for Compliance Teams
Addressing these failure modes is less about acquiring a new model and more about instrumenting existing prior authorization workflows. Payers should first inventory every point in the workflow where an algorithmic tool influences a denial decision, since litigation to date has targeted specific tools, such as length-of-stay prediction models, rather than AI use as a general category. Existing utilization management platforms may need workflow changes to enforce a mandatory clinician review step before any denial is finalized, a requirement made explicit under statutes like California's SB 1120 and implicit in CMS guidance for Medicare Advantage.
Vendor contracts covering third-party AI or algorithmic tools warrant separate review against the NAIC Model Bulletin's expectations for documentation, testing, and accountability. Both cases discussed here name payers, not vendors, as defendants for use of third-party models, so contractual allocation of liability does not eliminate the payer's own governance obligation. Compliance teams should also confirm readiness for CMS-0057-F's reporting and API requirements ahead of its phased timeline, since increased visibility into denial-rate data may itself draw scrutiny to AI-influenced outcomes that were previously less visible. Legal and compliance functions should coordinate on retention policies for AI decision logs, since discovery in the cases reviewed has focused specifically on internal override statistics and review-time data, information that only exists if it was captured and retained at the time the decision was made.
Where Runtime Governance Fits
Runtime governance is designed to enforce controls at the point of execution rather than solely at the policy or design stage. Capability areas such as runtime policy enforcement, audit logging, and tool approval workflows map directly to the failure modes identified in this litigation: preventing an AI agent's output from becoming a final action without a documented approval step, and retaining an auditable record of that decision path for later review. Trussed AI provides runtime governance and security controls for enterprise AI agents, including audit logging, agent permissions, and runtime policy enforcement, that address these categories of control. This does not mean any specific configuration satisfies a particular law or ruling; payers should evaluate governance tooling against their own regulatory obligations and legal counsel's guidance.
Runtime Controls That Address These Failure Modes
- Decision-stage logging: record whether each denial was algorithm-recommended or algorithm-determined, tied to a specific case record.
- Clinical data linkage: connect each denial to the specific patient clinical data reviewed, not only to the algorithm's output.
- Reviewer accountability: capture reviewer identity, review duration, and any override of an AI-generated recommendation.
- Enforcement of clinician sign-off: prevent a denial from being finalized without a documented clinician action.
- Unified reporting: generate CMS-0057-F metrics (denial rates, decision timing) from the same audit data used for internal governance, avoiding parallel record-keeping.
Frequently Asked Questions
Does CMS require human review of every AI-assisted prior authorization denial?
CMS sub-regulatory guidance to Medicare Advantage organizations states an algorithm cannot be the sole basis for a coverage denial and that determinations must reflect individual patient circumstances. CMS has not published a standalone AI-specific rule prescribing a particular review architecture.
What does CMS-0057-F require regarding AI-influenced denials specifically?
CMS-0057-F does not regulate AI directly. It requires affected payers to provide specific denial reasons and publicly report denial rates and decision timing via API-based data exchange, phased through 2026 to 2027, increasing visibility into denial patterns.
Is the human review requirement consistent across states?
No. California's SB 1120 requires licensed clinician supervision and prohibits AI as the sole basis for a medical necessity denial. Other states, such as Colorado, have algorithm governance rules developed outside the prior authorization context. There is no single federal standard, so requirements vary by jurisdiction.
Build Defensible AI Oversight Into Prior Authorization
Litigation and regulatory guidance both point to the same requirement: documented human review and an auditable decision trail for every AI-assisted denial. Runtime governance is one way to enforce and evidence that control.
Request a Demo