How does your AI governance program compare?

    See where your program has gaps in less than 2 minutes.

    Take the assessment
    Healthcare AI Compliance

    California SB 1120 AI Utilization Review Compliance Guide

    California SB 1120, the Physicians Make Decisions Act, requires California-regulated health plans and disability insurers using AI or algorithmic tools in utilization review to keep final adverse medical necessity determinations with a licensed physician or other appropriately licensed healthcare professional. AI may support review, but it cannot be the sole basis to deny, delay, or modify care. Compliance requires workflow controls, audit trails, credential verification, and runtime enforcement that prevent an AI-assisted recommendation from becoming an issued adverse determination without qualified human review.

    Direct answer

    California SB 1120, the Physicians Make Decisions Act, requires California-regulated health plans and disability insurers using AI or algorithmic tools in utilization review to keep final adverse medical necessity determinations with a licensed physician or other appropriately licensed healthcare professional. AI may support review, but it cannot be the sole basis to deny, delay, or modify care. Compliance requires workflow controls, audit trails, credential verification, and runtime enforcement that prevent an AI-assisted recommendation from becoming an issued adverse determination without qualified human review.

    What SB 1120 changes for AI-assisted utilization review

    SB 1120 changes the operating model for AI-assisted utilization review by making final adverse medical necessity determinations a licensed-reviewer responsibility. An AI or algorithmic tool may support review, surface information, or produce a recommendation, but it cannot become the sole basis to deny, delay, or modify care.

    For health plans and utilization review organizations, the practical implication is that compliance cannot depend only on policy language or training. The workflow itself needs to preserve the distinction between an AI-assisted recommendation and the final determination issued to a member, provider, or other party.

    SB 1120 compliance focus areas

    The supplied page identifies three focus areas that should shape how organizations review their AI-enabled utilization review workflows.

    • Physician final authority Adverse utilization review determinations must not be autonomously finalized by AI or algorithms.
    • Individualized assessment AI-assisted review must account for the patient's medical history and clinical circumstances, not only population-level data.
    • Auditable control path Enterprises need linked evidence of AI output, reviewer identity, credentials, review action, and final rationale.

    Where AI utilization review creates compliance exposure

    AI utilization review creates exposure when advisory outputs can influence or become adverse determinations without a documented licensed professional review. The highest-risk paths are those that allow an automated recommendation to flow directly into denial, delay, or modification notices without a mandatory review event.

    Exposure also increases when systems cannot show what patient-specific clinical information was available, which reviewer acted, whether the reviewer had the required licensure or professional qualification, and how the final rationale differed from or relied on the AI-assisted recommendation.

    Runtime controls needed to enforce physician-review requirements

    SB 1120 compliance should be designed into the runtime path of the utilization review system. The control objective is to make it technically impossible, or at minimum immediately detectable, for an AI-generated adverse recommendation to become an issued denial, delay, or modification without qualified review.

    1. 1

      Mandatory adverse-decision gate

      Any workflow path that results in denial, delay, or modification should require documented physician or qualified licensed professional sign-off before the determination is issued.

    2. 2

      Separation of recommendation and issuance

      AI recommendation services should be logically separated from systems that transmit determinations, so advisory outputs cannot bypass review controls.

    3. 3

      Credential-aware access control

      The system should verify and log that the reviewer has the required licensure or professional qualification for the determination type.

    4. 4

      Immutable audit logging

      Audit records should link the AI recommendation, patient-specific inputs considered, reviewer identity, review timestamp, final decision, and rationale.

    5. 5

      Runtime monitoring

      Monitoring should detect policy exceptions, such as adverse notices generated without a linked review event or repeated approvals with no documented rationale.

    6. 6

      Data lineage checks

      Controls should show that patient-specific clinical information was available and considered, rather than relying solely on population-level scoring.

    How to operationalize SB 1120 compliance

    Operationalizing SB 1120 compliance means turning the physician final authority requirement into enforceable control points. The organization should be able to trace the path from AI-assisted recommendation through qualified review and final determination.

    Control area Operational requirement Evidence to maintain
    Adverse determinations Require documented physician or qualified licensed professional sign-off before denial, delay, or modification is issued. Linked review event, reviewer identity, review timestamp, final decision, and rationale.
    AI recommendations Keep recommendation services logically separated from systems that transmit determinations. Records showing the AI output was advisory and did not bypass review controls.
    Reviewer qualification Verify that the reviewer has the required licensure or professional qualification for the determination type. Credential verification and access-control logs tied to the decision record.
    Individualized review Show that patient-specific clinical information was available and considered. Data lineage connecting clinical inputs, AI recommendation, and final rationale.
    Runtime exceptions Detect policy exceptions, including adverse notices without linked review events. Monitoring records and exception logs for workflow control failures.

    Compliance evidence to maintain

    Compliance teams should maintain evidence that connects the AI-assisted workflow to the human final determination. The evidence should make the control path reviewable after the fact.

    • AI recommendation associated with the utilization review decision.
    • Patient-specific inputs considered during review.
    • Reviewer identity and review timestamp.
    • Reviewer credentials or professional qualification for the determination type.
    • Final decision, including whether care was denied, delayed, modified, or approved.
    • Final rationale documenting the human review decision.
    • Runtime monitoring records showing policy exceptions and adverse notices without linked review events.
    • Data lineage showing that the review did not rely solely on population-level scoring.

    Governance implications for healthcare payer AI programs

    For healthcare payer AI programs, SB 1120 compliance is not limited to model review. It affects AI inventory management, vendor governance, workflow design, access control, monitoring, and audit readiness.

    Vendor tools should be included in the AI inventory and workflow map. Contracts and configurations should require human-in-the-loop finalization, audit logging, credential-aware review, and no autonomous adverse determination path.

    Frequently asked compliance questions

    Does SB 1120 ban AI in utilization review?

    No. Based on the provided evidence, the law targets autonomous adverse decision-making. AI may support utilization review, but it cannot be the sole basis to deny, delay, or modify care, and final authority must remain with the required licensed reviewer.

    Is a physician signature enough for compliance?

    Not by itself. The organization should be able to show substantive review, reviewer credentials, patient-specific clinical context, final rationale, and a clear distinction between the AI recommendation and the human final determination.

    What is the main technical control?

    The key control is a mandatory runtime gate that prevents an adverse UR determination from being issued unless a qualified reviewer has completed and documented the final decision.

    How should compliance teams treat vendor AI tools?

    Vendor tools should be included in the AI inventory and workflow map. Contracts and configurations should require human-in-the-loop finalization, audit logging, credential-aware review, and no autonomous adverse determination path.

    Strengthen runtime control for AI-assisted utilization review

    If AI recommendations influence utilization review, governance must be enforced in the workflow itself. Evaluate whether your systems can prove physician final authority, individualized review, and auditable non-autonomous decision-making.

    Explore Runtime Governance