See what Trussed catches that your current tool misses, live in your stack

    No migration, no commitment, just a direct comparison in your environment.

    Set up a technical evaluation
    A growing number of states have introduced or enacted laws imposing disclosure, human review, audit trail, and appeal-rights obligations on health plans using AI or algorithmic tools in prior authorization decisions. Which specific states apply, and under what statutory language, changes frequently and should be confirmed with legal counsel rather than treated as fixed. What is consistent across enacted and proposed laws is a shift toward mandatory disclosure of AI involvement, documented clinical review of adverse determinations, and auditable decision records that can be produced on request.
    Compliance Guide

    AI Prior Authorization Transparency Requirements by State

    A growing number of states have introduced or enacted laws imposing disclosure, human review, audit trail, and appeal-rights obligations on health plans using AI or algorithmic tools in prior authorization decisions. Which specific states apply, and under what statutory language, changes frequently and should be confirmed with legal counsel rather than treated as fixed. What is consistent across enacted and proposed laws is a shift toward mandatory disclosure of AI involvement, documented clinical review of adverse determinations, and auditable decision records that can be produced on request.

    Obligation Categories at a Glance

    Four themes recur across enacted and proposed state AI transparency laws for prior authorization. Each is described in more detail below.

    Disclosure of AI Use

    Notice that an automated tool contributed to a coverage determination.

    Human Clinical Review

    A licensed clinician documented as decision-maker of record for denials.

    Audit Trail

    Reconstructable records of the AI recommendation and human action.

    Appeal Rights

    Denial rationale a provider or patient can act on to file an appeal.

    Four Recurring Obligation Categories in State AI Transparency Laws

    • Disclosure of AI use: requires health plans to disclose to patients or providers that an automated or AI-assisted tool contributed to a coverage determination, rather than leaving the AI's role unstated.
    • Human clinical review of adverse determinations: requires a qualified clinical reviewer to be documented as the decision-maker of record for denials, distinct from any automated recommendation that informed the decision.
    • Audit trail and decision logging: requires health plans to reconstruct how and why a determination was reached, including the AI recommendation, the human reviewer's action, and any override.
    • Patient and provider appeal rights: requires denial notices to include a rationale a treating provider or patient can act on to file an appeal, rather than raw model output or a generic denial code.

    The Structure Behind State AI Prior Authorization Laws

    Prior authorization has become the primary point of contact between health plan AI systems and patient care decisions. As health plans, third-party administrators, and vendors have expanded use of algorithmic tools to score, route, or recommend coverage determinations, state legislatures have responded with an expanding set of transparency requirements. Rather than converging on a single national model, states have moved independently, producing enacted laws, pending bills, and regulatory guidance that differ in scope, applicability, and enforcement mechanism.

    Because this guide is intended to remain accurate as the legislative landscape changes, it does not list which specific states have enacted which specific statute, since that detail changes frequently and must be confirmed against current, dated legislative text. Instead, it describes the obligation categories that recur across enacted and proposed state AI prior authorization laws, and the technical controls a health plan needs to operationalize compliance regardless of which specific states apply to its operations.

    Compliance leaders should treat the categories above as a framework for building a jurisdiction tracking process, not as a final answer for any single state. Legal counsel or a dedicated regulatory tracking function should confirm the current statutory text, effective dates, and applicability thresholds, such as plan size or line of business, for each state in which the organization operates.

    Technical Architecture Implications

    Translating these obligation categories into system requirements has direct architectural consequences for any AI system used in prior authorization workflows.

    Governance Practices for an Evolving Legal Landscape

    • Establish clear accountability for approving changes to AI models or scoring logic used in coverage determinations, since model changes may trigger new disclosure obligations.
    • Maintain a cross-functional process involving legal, compliance, clinical, and technical stakeholders to track new and amended state requirements as they emerge.
    • Document the distinction between AI-assisted recommendations and final human decisions in policy, to support both regulatory defense and patient appeals.
    • Build a defined process to reassess technical controls whenever a new state law or amendment affecting AI use in prior authorization is identified.

    Frequently Asked Questions

    Which states currently require AI disclosure for prior authorization decisions?

    The list of states with enacted requirements changes frequently and depends on statutory language, applicability thresholds, and effective dates. Compliance teams should maintain an ongoing legislative tracking process and confirm current statutory text with legal counsel for each state where the plan operates.

    How should a multi-state health plan set one national compliance standard?

    Compare the obligation category requirements, disclosure, human review, audit retention, and appeal rights, across all applicable states, then adopt the most stringent requirement in each category as the operating baseline rather than maintaining separate state configurations.

    Who is responsible for maintaining audit logs when a vendor provides the AI scoring tool?

    Responsibility should be defined contractually between the health plan, TPA, and vendor. Regardless of which party technically stores the logs, the health plan generally remains accountable for producing them on regulator or patient request.

    Does a human reviewing an AI recommendation satisfy human-in-the-loop requirements?

    Generally the reviewer must be a qualified clinician documented as the decision-maker of record for adverse determinations, with their action recorded as distinct from the AI's recommendation, not simply a passive sign-off.

    Enforce Multi-State Prior Authorization Compliance at Runtime

    As state AI transparency requirements continue to differ and evolve, health plans need policy enforcement and decision logging that operate at the point of AI decision-making, not after the fact.

    See How Runtime Enforcement Works