A rehabilitation hospital submits a routine continued-stay request for a 78-year-old post-stroke patient. Two hours later, a denial arrives. No phone call, no chart review request, no clarifying question about the patient’s gait training progress that week — just a letter citing an “estimated length of stay” that expired three days earlier. The treating physician, who has actually examined the patient, is left to accept the denial, absorb the cost, or file an appeal against a decision nobody at the plan appears to have made with a human mind.
The underlying issue is no longer hypothetical. Variations of this fact pattern sit at the center of several consequential health insurance lawsuits filed in the past three years, and it is the reason CMS and a growing number of state legislatures have spent 2024 through 2026 trying to answer a question that sounds almost naive: when a machine recommends “no,” whose signature is actually on that decision?
For providers, however, the question is not only who made the decision. It is also whether the practice has the documentation, coding, and claims evidence needed to challenge that decision.
When an automated or algorithm-assisted denial does not appear to reflect the patient’s actual clinical circumstances, the provider’s strongest response is not simply to argue that “the algorithm was wrong.” It is to build a well-supported record showing what the patient actually needed, what was documented, what was billed, and why the denial does not match the clinical or coverage criteria.
Not Every Automated Denial Is the Same Kind of Automated
Before getting into any of the specific cases, it’s worth being precise about what “AI denial” actually covers, because the term gets used loosely and the loose usage does real damage to both sides of the argument. Some systems are predictive models — trained on historical outcomes to forecast something about a given patient, the way naviHealth’s nH Predict tool forecasts post-acute-care length of stay. Others are rules-based logic that simply cross-references submitted diagnosis and procedure codes against a preset list, the way Cigna’s PxDx system does. Still others sit further back in the process as pure administrative automation — sorting, routing, or flagging claims for a human reviewer without generating a clinical recommendation at all.
The legal distinction between these matters less than it might seem, because the accountability question underneath all of them is the same one: did the technology assist a qualified reviewer in reaching an individualized judgment, or did it functionally replace that judgment? That question is exactly what the two most closely watched cases in this space were built to answer.
Two Systems, Two Lawsuits
The first involves naviHealth’s nH Predict tool, allegedly used by UnitedHealthcare to forecast how many days of skilled nursing or inpatient rehabilitation a Medicare Advantage patient should need, based on comparisons against a database of roughly six million prior patients. Plaintiffs in Estate of Gene B. Lokken v. UnitedHealth Group — led by the family of a 91-year-old Wisconsin man who fractured his leg and ankle in 2022, was flagged for discharge by the algorithm after 19 days of covered rehabilitation, and whose family paid out of pocket for nearly a year of continued care until his death — allege the tool’s predictions carried an error rate exceeding 90 percent when measured against actual outcomes on appeal. A Senate subcommittee investigation released in October 2024 found that UnitedHealth’s prior authorization denial rate for post-acute care more than doubled, from 10.9 percent in 2020 to 22.7 percent in 2022, during a period when the company was implementing multiple initiatives to automate the process. UnitedHealth’s Optum unit disputes that the tool drives coverage decisions at all, telling reporters that characterizations of nH Predict as a tool used to make adverse benefit determinations are false, and describing it instead as a care-support and discharge-planning resource shared with providers and families.
The second is Cigna’s PxDx (“procedure-to-diagnosis”) system, which flags discrepancies between a submitted diagnosis and a preset list of acceptable tests or procedures for that condition. A 2023 investigation by ProPublica and The Capitol Forum found that over a two-month span, Cigna medical directors denied more than 300,000 claims through the system while spending an average of 1.2 seconds per case. Cigna has consistently and directly disputed that framing. The company has said the system was built to “accelerate payment of claims for certain routine screenings” and to automatically approve — not deny — claims submitted with correct diagnosis codes, freeing medical directors’ time for genuinely complex reviews, and it maintains PxDx does not involve artificial intelligence or machine learning at all, calling the reporting a mischaracterization it welcomes the chance to correct with regulators. That dispute over characterization is not a side issue; it is close to the center of the legal case, because the plaintiffs’ theory in Kisting-Leung v. Cigna Corp. depends on showing that PxDx-generated denials were not, in fact, individually reviewed the way Cigna’s plan documents promised.
The Regulatory Floor CMS Built
CMS’s calendar year 2024 Medicare Advantage Final Rule, together with the FAQ guidance the agency issued in February 2024, is the clearest statement so far of where the federal line sits. The accurate description of that guidance is narrower than “algorithms can’t deny claims” — CMS did not ban the use of AI or algorithmic tools in coverage determinations. What it said is that Medicare Advantage organizations may use algorithms and software tools to assist with coverage determinations, but that those tools cannot substitute for the individualized clinical assessment required under 42 C.F.R. § 422.101(c): the decision has to be grounded in the specific enrollee’s medical history, the treating physician’s recommendations, and the clinical notes in that patient’s own record, not solely on a prediction drawn from a larger population dataset. CMS was equally direct on process — before a Medicare Advantage organization issues an adverse decision, a physician or another appropriately qualified clinician has to review whether the requested service is medically necessary.
The practical effect is a division of labor rather than a prohibition. An algorithm can narrow the file, flag a pattern, or draft the reasoning. It cannot, under this rule, be the reviewer of record.
For providers, that distinction creates a practical opportunity: a denial should be evaluated not only for its clinical merits, but also for whether the process used to reach it is consistent with the applicable requirements.
That makes documentation and appeal preparation increasingly important. If a denial appears to rely on a generalized rule or prediction rather than the patient’s individual circumstances, the medical record becomes the provider’s strongest evidence of what the reviewer may have missed.
The State Landscape: Real, but not Uniform
This is the part of the picture that gets flattened most often in commentary, and it’s worth separating out three genuinely different things that frequently get lumped together under “states are regulating AI in health insurance.”
The first is general AI governance for insurers, driven mainly by the NAIC’s Model Bulletin on the Use of Artificial Intelligence Systems by Insurers, adopted in December 2023. As of 2026, more than 20 states had adopted the bulletin in some form, while California, Colorado, New York, and Texas had issued separate insurance-specific AI regulations or guidance outside the bulletin structure. NAIC tracking and related 2026 analyses put the broader number of states with some form of insurance-related AI regulation at roughly the high twenties. This layer requires a written, auditable AI program, model-level documentation, and bias testing, and gives regulators a basis to demand records during an examination. It applies across underwriting, marketing, and claims broadly — it is not specific to medical necessity or utilization review.
The second, much narrower category is the set of statutes that specifically require a licensed human clinician to make the final medical-necessity call, regardless of what an algorithm recommends. This group is smaller and newer: California’s SB 1120 (the Physicians Make Decisions Act, effective January 1, 2025) and Illinois’s HB 2472 (effective the same day) were among the first; Texas’s SB 815 (effective September 1, 2025) prohibits utilization review agents from using an automated decision system, on its own, to generate an adverse determination; other states have enacted or developed additional measures with different requirements and effective dates. These laws are not uniform, and their scope depends on the type of plan and the state’s regulatory authority.
The third category is disclosure and reporting — Maryland’s HB 1563, for instance, requires insurers to report quarterly to the state Insurance Commissioner how many adverse decisions they issued, what services were involved, and whether AI played a role, with authority to investigate if denials spike, particularly for emergency department claims.
The practical upshot for a treating physician: the general AI-governance layer is now widespread, but the specific right to demand a human, individualized medical-necessity review is jurisdiction-dependent, and worth checking against your specific state and plan type before it’s cited in an appeal.
What the Courts Have Actually Decided
Legislation sets the rule going forward. Litigation is where the accountability question for past denials is being tested — and the most consequential recent development in either of the two flagship cases is a discovery order, not a verdict, which is worth understanding in its own right.
On March 9, 2026, Magistrate Judge Shannon Elkins ordered UnitedHealth to produce a broad set of internal records in Lokken, granting or partially granting discovery across most of the categories sought, including records concerning nH Predict’s development and use, employee training and incentives, government investigations, and UHC’s oversight of the technology. The order also addressed requests reaching back to 2017 and denied requests for the tool’s underlying source code and clinical guidelines. The judge held that UnitedHealth’s argument that nH Predict was never actually used to make coverage decisions was a merits question for trial, not a reason to block discovery into how the tool works. That followed a narrower but structurally important ruling in February 2025, when Judge John Tunheim dismissed five of the plaintiffs’ seven claims — including unjust enrichment, insurance bad faith, and negligence per se — as preempted by the Medicare Act, but allowed the breach-of-contract and breach-of-the-implied-covenant-of-good-faith-and-fair-dealing claims to proceed, because those claims turned on whether UnitedHealth’s own coverage documents promised that “clinical services staff” and “physicians” would make claim decisions, and whether that promise was kept. Class certification declarations are due in September 2026.
Kisting-Leung v. Cigna Corp. took a different legal route entirely: ERISA fiduciary breach. The plaintiffs argued that delegating medical-necessity review to PxDx violated the terms of the governing health plan, which required a medical director’s review. Cigna countered that it retained discretionary authority to interpret plan terms as it saw fit. In March 2025, Judge Dale Drozd found that, on the pleaded facts, Cigna’s interpretation of the plan provision requiring medical-necessity determinations by a medical director — as allowing an algorithm to make the decision so long as a medical director pushed the button — conflicted with the plain language of the plan and constituted an abuse of discretion. The court allowed certain ERISA fiduciary-breach claims to proceed while dismissing other claims or allowing amendment. The case remains in litigation. Read together with Lokken, the throughline is that neither court has had to decide, as a matter of law, whether AI-assisted review is permissible — both have instead focused on the narrower and more provable question of whether the insurer’s process matched what its own plan documents promised. That is the legal terrain a treating physician’s appeal should be built to occupy.
For providers, that means an appeal should do more than repeat the clinical argument. It should connect the patient’s documentation to the applicable coverage criteria and identify any gap between the plan’s stated review process and the reasoning reflected in the denial.
So, Who Is Actually on the Hook?
Accountability here is distributed across a chain, and each link carries a different kind of exposure — none of it, so far, fully settled by a final judgment.
The health plan or payer carries the primary regulatory and contractual exposure — the § 422.101(c) obligation, the state “licensed clinician must review” statutes where they exist, and the contract-law exposure that kept Lokken alive. This is where the bulk of current enforcement energy, from CMS audits to state insurance commissioner investigations, is aimed.
The reviewing physician or medical director, even when employed by the payer, may remain professionally accountable for the clinical judgment reflected in an adverse determination they sign, even when an algorithm helped generate the underlying recommendation. The exact scope of that responsibility depends on the applicable state licensing and utilization-review law, the plan type, and the clinician’s actual role in the review — this is not yet a settled legal principle with a single answer, but it is the reason the 1.2-second review time alleged in the Cigna litigation became a central fact in that case rather than a footnote.
The AI vendor — naviHealth, in the UnitedHealth structure — occupies a genuinely unsettled position. Vendors are rarely the direct focus of ERISA claims, although their potential liability and fiduciary status depend on the functions they perform. The March 2026 discovery order nevertheless shows how closely a vendor’s role can become tied to the insurer’s own legal obligations, particularly when the court is examining how the technology was developed and used.
The treating physician, meanwhile, is not a bystander even though none of the new laws impose direct obligations on them. The documentation a treating physician places in the chart, and in the appeal, can become important evidence for a plaintiff, a regulator, or an external reviewer seeking to show that an individualized clinical picture existed and was disregarded. That makes the quality of the provider’s own record especially important. A strong appeal starts before the appeal is written: it starts with documentation that clearly supports the service, accurate coding that reflects that documentation, and a claims record that can be reconciled with both.
What This Means at the Point of Care
For a provider, the goal is not to prove that an algorithm was used.
The goal is to determine whether the denial is supported by the patient’s record and the plan’s stated criteria — and to make the strongest possible case when it is not.
When a questionable denial arrives, the provider should ask:
- Who actually reviewed the case?
- Was the decision based on the patient’s individual clinical circumstances?
- What coverage criteria did the payer apply?
- What does the plan document or contract say?
- Were the patient’s medical history, physician recommendations, and clinical notes considered?
- Does the denial rationale actually correspond to the services that were provided?
- Is there a documentation, coding, authorization, or claims issue that may have contributed to the denial?
The answer to these questions can determine how an appeal should be structured.
For example, if a payer says that a patient did not meet medical necessity requirements, the provider should identify the specific clinical evidence supporting the service.
If the denial appears to rely on a generalized utilization rule, the provider can explain the patient-specific facts that distinguish the case.
If the denial is related to coding or claim information, the provider should correct the underlying issue rather than treating every denial as a clinical dispute.
Before submitting an appeal, practices should also verify that the supporting documentation, diagnosis and procedure codes, authorization history, and claim information are consistent.
A strong clinical argument can lose force if the underlying claim contains coding inconsistencies or if the documentation submitted with the appeal does not clearly support the service being challenged.
Where Providers Can Strengthen Their Position
Not every questionable denial is an AI issue, and not every denial requires a legal challenge. But every disputed claim benefits from a clear, well-supported record. Before escalating a denial, practices can strengthen their position by reviewing:
- Clinical documentation: Does the record clearly support the service and the patient’s condition?
- Coding: Do the diagnosis and procedure codes accurately reflect the documentation?
- Authorization history: Was authorization obtained when required, and is the denial rationale consistent with the authorization record?
- Claim information: Was the claim submitted accurately under the payer’s requirements?
- Appeal documentation: Does the appeal directly address the denial with patient-specific evidence?
This is also where the distinction between a clinical denial and a revenue-cycle problem becomes important. A denial may appear to be a medical necessity issue but actually involve coding, authorization, eligibility, documentation, or another payer requirement. Identifying that distinction early can prevent practices from spending time on the wrong appeal strategy.
| How WCH Can Help Practices Respond to Payer Denials For practices dealing with increasingly complex payer rules and automated claim processes, the challenge is not simply submitting more appeals. It is making sure that the underlying documentation, coding, billing, and claims record can support the provider’s position when a claim is challenged. WCH can support providers through coding audits, medical billing, claims review, and revenue-cycle support — helping practices identify documentation or coding gaps and build stronger, better-supported responses to payer denials. The objective is not simply to challenge more denials. It is to make sure that when a claim is challenged, the provider has the documentation, coding, and billing evidence needed to support its position. |
WISeR: Another Example of Technology Entering the Review Process
The same questions are becoming relevant beyond Medicare Advantage. CMS’s WISeR model, launched as a six-state Original Medicare model in 2026, uses technology contractors to support prior authorization and prepayment review for selected services. The model includes financial incentives tied to savings generated through review activity.
CMS describes the model as an effort to use technology to improve the accuracy and efficiency of Medicare review processes. Critics, however, have raised concerns about whether financial incentives tied to savings could create pressure toward more aggressive utilization management.
The broader issue is the same: As technology becomes more deeply integrated into claims and coverage review, providers need to understand not only what the payer’s system is doing, but also how to respond when the result does not accurately reflect the patient’s circumstances.
The Practical Takeaway for Providers
The debate over AI in healthcare will continue. So will the questions about transparency, accountability, regulation, and the role of human judgment. But providers do not have to wait for every legal question to be resolved before strengthening their own position. The most practical response is to make the record harder to dispute: Accurate documentation. Defensible coding. Complete claims records. Clear authorization history. And a well-supported appeal when a denial does not reflect the patient’s individual circumstances.
AI-assisted and automated denials make those fundamentals more important, not less. For providers, the issue is ultimately bigger than whether a machine made the wrong decision. It is whether the practice has the evidence, processes, and expertise needed to identify the problem and respond effectively.
That is where a strong billing, coding, and audit process becomes more than administrative support — it becomes part of the provider’s defense against preventable denials.
Sources
- CMS, Calendar Year 2024 Medicare Advantage Final Rule and February 2024 FAQ guidance on AI and algorithm use; 42 C.F.R. § 422.101(c)
- Estate of Gene B. Lokken, et al. v. UnitedHealth Group, Inc., et al., No. 0:23-cv-03514 (D. Minn.): opinion on motion to dismiss, Feb. 13, 2025, 766 F. Supp. 3d 835; order on motion to compel discovery, Mar. 9, 2026, 2026 WL 658883
- Kisting-Leung v. Cigna Corp., E.D. Cal., order on motion to dismiss, Mar. 31, 2025
- U.S. Senate Permanent Subcommittee on Investigations, report on Medicare Advantage denial practices, October 2024
- ProPublica and The Capitol Forum, “How Cigna Saves Millions by Having Its Doctors Reject Claims Without Reading Them,” March 2023
- California SB 1120 (Physicians Make Decisions Act), effective Jan. 1, 2025; Illinois HB 2472, effective Jan. 1, 2025; Texas SB 815, effective Sept. 1, 2025; Colorado HB 1139; Georgia SB 444; Maryland HB 820 and HB 1563; Washington SB 5395
- National Association of Insurance Commissioners, Model Bulletin on the Use of Artificial Intelligence Systems by Insurers, adopted Dec. 4, 2023, and related 2026 state-adoption tracking
- CMS, Wasteful and Inappropriate Service Reduction (WISeR) Model Fact Sheet and Provider and Supplier Operational Guide, 2025–2026
- Becker’s Payer Issues, reporting on the March 2026 discovery order in Lokken
- Forbes, “The Algorithm That Counted On No One Appealing,” June 2026
Discover more from Doctor Trusted
Subscribe to get the latest posts sent to your email.
