How to read this
Regulation in this area does three distinct things, and they are easy to conflate:
- Constrains how a decision may be made — a licensed clinician must decide; the basis must be the individual's circumstances.
- Constrains how fast, and what must be told to whom — decision timeframes, specific denial reasons, appeal rights.
- Requires that all of the above be demonstrable on examination — records, documentation, governance.
APS produces evidence for the third category, about the first. It does not make a decision lawful; it makes a lawful decision provable, and an unlawful one detectable. The second category — timeliness, notice delivery, API transport — is largely outside the Profile, and Section 4 says so.
A qualified human must be accountable for an adverse determination
| Where it comes from | What it requires |
|---|---|
| CMS-4201-F (Medicare Advantage utilization management) | Medical-necessity determinations must rest on the individual's circumstances; an algorithm may not be the sole basis; coverage criteria must be reviewed by a qualified committee |
| CA SB 1120 (Physicians Make Decisions Act) | A licensed physician must make the medical-necessity determination; AI may not be the sole basis for a denial |
| TX SB 815 | Restricts AI as the sole basis for an adverse utilization-review determination |
| NAIC Model Bulletin on the Use of AI Systems by Insurers | Governance, documentation, and testing of AI systems, with records available to the regulator on examination |
- §5 — the accountable licensed reviewer is identified for every adverse determination, along with what they actually did: decided independently, confirmed the recommendation, or overrode it. An adverse determination with no accountable reviewer is non-conformant, which converts the obligation from a policy statement into a record that either exists or does not.
- §5 — reviewer credential and specialty recorded beside the clinical issue, so a competence mismatch is visible on inspection rather than requiring a separate investigation.
- §3.4 — the
deciderfield states whether a model or deterministic code issued the determination. This is the direct, single-field answer to "did AI deny this claim?" - §6 — the full routing chain for every non-approval, so the path from the AI's output to the final human determination is reconstructable end to end.
The determination must rest on the individual's clinical circumstances
| Where it comes from | What it requires |
|---|---|
| CMS-4201-F | Determinations based on the enrollee's medical condition and individual circumstances, not group or population data |
| CA SB 1120 | AI must base its output on the individual's clinical history and circumstances, not solely on a dataset of other patients |
| Colorado SB 21-169 | Insurers must be able to demonstrate that external consumer data and algorithms do not produce unfair discrimination |
| ACA §1557 patient care decision support provisions | Reasonable efforts to identify and mitigate discrimination risk arising from decision support tools |
- §8 — the record must show which of the member's own clinical facts were before the system.
- §3.1 — the evidence manifest, with a per-document
presented_to_modelflag. This is what makes §8 real: a fact on file that was never presented to the system was not before it, and no other part of the record distinguishes those two states. - §3.2 — the complete input surface, so any non-clinical content that entered the decision — a cost signal, a utilization target, a population statistic — is present in the record rather than inferred from the outcome.
- §4.2 — extraction output with each fact pointed at its location in the source packet; facts not traceable to the packet are marked ungrounded.
An adverse determination must state a specific reason, and the record behind it must be producible
| Where it comes from | What it requires |
|---|---|
| CMS-0057-F (Interoperability and Prior Authorization) | Impacted payers must provide a specific reason for denial, and publicly report prior-authorization metrics |
| ERISA claims procedure regulation, 29 CFR 2560.503-1 | The specific reason for an adverse benefit determination, reference to the plan provision relied on, and — on request — access to all documents relevant to the claim |
| State external-review and appeals statutes | The record considered must be producible to the reviewing body |
- §3.4 — the stated basis with principal reasons for any adverse outcome, and any generated reasoning retained in full and untruncated.
- §3.2 — the coverage rule's full text, hash-pinned to the version in force. A version identifier alone does not establish what the criterion said on the day; policies are revised, and an appeal turns on the wording that applied.
- §9.3 — every artifact retrievable under a declared custody arrangement. This is the direct answer to the ERISA "relevant documents" obligation: the record is not merely provable, it is producible.
- §3.1 — the manifest settles the recurring appeals dispute about whether a document was before the reviewer, arrived afterward, or was later amended.
AI systems must be governed, documented, and demonstrable on examination
| Where it comes from | What it requires |
|---|---|
| NAIC Model Bulletin (adopted by a growing number of states) | A written AI governance program; testing for validity and drift; oversight of third-party AI vendors; documentation available to the regulator |
| CMS-4201-F | Utilization-management committee oversight of the criteria applied |
| State AI utilization-review statutes | Disclosure of AI use in utilization review, and in several states, regulator access to the methodology |
- §7 — the assurance state carried on every decision: certificate and version, per-capability-line verdicts, applicable conditions and whether they were met, monitoring status, and the configuration fingerprint observed versus the one certified.
- §7 — lapsed monitoring forces affected capability lines to be recorded as lapsed rather than certified, which is the evidentiary form of "governance must be ongoing."
- §3.3 — the execution configuration, with every change to a routing threshold written as a dated, attributable ledger entry. This is the auditable form of vendor and configuration oversight.
- §11.1 — coverage measured against determination volume from the source system, so the governance claim is quantified rather than asserted.
- §4 — for a deployment using a third-party vendor, the pipeline chain records what that vendor's system did to the inputs, which is the substance of third-party oversight.
Records must be retained, protected, and their handling auditable
| Where it comes from | What it requires |
|---|---|
| HIPAA Security Rule, 45 CFR §164.312(b) | Audit controls: mechanisms recording and examining activity in systems containing ePHI |
| HIPAA Security Rule, 45 CFR §164.308 | Administrative safeguards, including information-system activity review |
| CMS record-retention requirements (Medicare Advantage and Medicaid managed care) | Retention of records for the applicable period |
| HIPAA Privacy Rule, 45 CFR §164.502(b) | Minimum necessary: disclose only what the purpose requires |
| HIPAA Privacy Rule, 45 CFR §164.528 | Accounting of disclosures: on request, tell an individual who received their information and why, going back six years |
| HIPAA Privacy Rule, 45 CFR §164.512 | Permitted disclosures without authorization — health oversight agencies, judicial and administrative proceedings, and disclosures required by law |
- §9.1 — signed, append-only, hash-chained ledger; corrections by appended linked record, never overwrite.
- §9.5 — every disclosure recorded as a ledger event: what, to whom, when, under what authority, scoped and expiring. This is the audit-control obligation made verifiable rather than merely logged.
- §9.6 — integrity verification operates on digests, so auditing AI involvement and human accountability does not require exposing protected health information.
- §9.4 — retention for the required period, with an express preference against retaining readable clinical content beyond it.
- §9.3 — the custody arrangement is declared, which is what makes a minimum-necessary posture auditable rather than asserted.
§164.528 gives an individual the right to ask who received their information and why, going back six years. Most plans satisfy this by hand, slowly, from incomplete sources.
§9.5 records every disclosure — what, to whom, when, under what authority — as a signed ledger event. That is the accounting, produced as a by-product of making disclosures properly.
The same record answers a second question no manual process can: because the disclosure is timestamped in the same chain as the determination, the plan can show a record existed in that exact form before anyone requested it.
Disclosing to regulators, courts, and members
| Where it comes from | What it requires |
|---|---|
| HIPAA §164.512(d) | Disclosure to health oversight agencies — state insurance departments, CMS, OIG — is permitted without authorization |
| HIPAA §164.512(e) | Disclosure in judicial and administrative proceedings, subject to specified assurances |
| HIPAA §164.502(b) | Minimum necessary: only what the purpose requires |
| HIPAA §164.524 | The individual's right of access to their own record |
| State external-review statutes | Production of the record considered, to the independent review entity |
These disclosures already happen daily. The question a regulator asks is not whether a plan may disclose but whether it can show what it disclosed, to whom, and that it disclosed no more than the purpose required.
- §9.5 — disclosure is scoped to the determinations at issue and expires, which is the minimum necessary rule expressed as a control rather than a policy.
- §9.5 — a standing export of the whole population is expressly not a disclosure. That distinction is the difference between a governed release and an unbounded copy.
- §9.1 — because the disclosure event is appended to the same chain, the record of what was released cannot later be revised.
Public reporting on how coverage decisions are made
| Where it comes from | What it requires |
|---|---|
| CMS-0057-F | Impacted payers must publicly report prior-authorization metrics on their website, annually |
| CMS-4201-F | Medicare Advantage internal coverage criteria must be publicly accessible |
| State AI utilization-review statutes | Disclosure that AI is used in utilization review |
The direction of travel is settled: plans are being required to say more, publicly, about how coverage decisions are made. What no instrument yet provides is a way for a plan to show that what it says is true.
- §11.3 — a public attestation with a defined content set: profile and version, reporting period, coverage rate, chain verification status with its as-of time, certification per capability line, and custody arrangement.
- §11.3 — the attestation must be independently verifiable against the ledger without access to clinical content, so the claim is checkable rather than asserted.
- §11.3 — it must carry no protected health information, no per-determination data, and no approval or denial statistics. It attests to provenance posture, never to the merits of determinations, which is what makes it publishable at all.
- §11.1 — the coverage rate is measured against determination volume from the source system, so a published figure cannot be inflated by counting only the records that were produced.
Configuration changes that shift outcomes must be detectable
No instrument names this obligation directly. It is included because it is where the others fail in practice, and because it is the first thing a plaintiff's expert or a market-conduct examiner will look for once they understand the architecture.
Where an approval threshold governs which cases reach a human, lowering it routes more cases to human review, where more can be denied — and the denial rate moves without any individual determination appearing to change.
- §5 — the routing logic must be recorded and held tamper-evident.
- §3.3 — threshold changes are written as dated, attributable ledger entries, so a retroactive or silent change is detectable.
- §9.1 — append-only commitment means the historical threshold cannot be revised to match a later account of it.
APS requirement → what it serves
A reverse index, for reading the Profile with the regulatory purpose of each section in view.
| APS section | Primary obligations served |
|---|---|
| §3.1 Evidence manifest | Individual circumstances (2.2); producible record on appeal (2.3) |
| §3.2 Input surface | Individual circumstances (2.2); specific reason and rule version (2.3) |
| §3.3 Execution configuration | AI governance (2.4); threshold detectability (2.8) |
| §3.4 Determination and decider | Human accountability (2.1); specific reason (2.3) |
| §3.5 Scoring model | Human accountability (2.1); AI governance (2.4) |
| §4 Pipeline chain | Individual circumstances (2.2); third-party vendor oversight (2.4) |
| §5 Human accountability | Qualified human decision-maker (2.1); threshold detectability (2.8) |
| §6 Routing chain | Qualified human decision-maker (2.1); appeals record (2.3) |
| §7 Assurance state | AI governance and ongoing oversight (2.4) |
| §8 Individual circumstances | Individual circumstances (2.2) |
| §9 Integrity, custody, disclosure | Audit controls and retention (2.5); producible record (2.3) |
| §9.5 Disclosure log | Accounting of disclosures and permitted disclosure (2.6) |
| §11 Conformance reporting | AI governance quantified (2.4); public reporting (2.7) |
What the Profile does not satisfy
The Profile records what happened. A fully conformant record of an unlawful denial is a complete, tamper-evident record of an unlawful denial. That is useful — it is how the denial becomes contestable — but it is not compliance with the underlying standard of care.
CMS-0057-F expedited and standard turnaround requirements are operational obligations. The Profile timestamps determinations, which makes timeliness measurable, but meeting the deadline is not a provenance property.
The FHIR Prior Authorization API, Patient Access, Provider Access, and Payer-to-Payer APIs are interface obligations. The Profile holds that the mode of transmission does not reduce what must be recorded (§6), but it does not implement or satisfy those interfaces.
Whether the member received a compliant adverse determination notice, with correct appeal-rights language, is outside the record.
The Profile makes the inputs to each determination inspectable, which is a precondition for disparate-impact analysis. It does not itself perform that analysis, and conformance is not evidence that a deployment produces equitable outcomes.
The Profile records the reviewer's credential and specialty beside the clinical issue so a mismatch is visible. It does not verify the credential, and does not adjudicate whether it was adequate for the case — that judgment belongs to the plan and its regulator.
Which instruments bind a given deployment depends on line of business, state of issue, and plan type. This document maps obligations to evidence; it does not determine which obligations apply.
Instruments referenced
| Short form | Instrument |
|---|---|
| CMS-0057-F | CMS Interoperability and Prior Authorization Final Rule |
| CMS-4201-F | CMS Medicare Advantage / Part D utilization-management final rule |
| CA SB 1120 | California, Physicians Make Decisions Act (AI in utilization review) |
| TX SB 815 | Texas, restrictions on AI-based utilization review |
| CO SB 21-169 | Colorado, protecting consumers from unfair discrimination in insurance practices |
| NAIC Model Bulletin | NAIC, Use of Artificial Intelligence Systems by Insurers |
| ERISA claims procedure | 29 CFR 2560.503-1 |
| HIPAA Security Rule | 45 CFR Part 164, Subpart C (notably §164.308, §164.312(b)) |
| HIPAA Privacy Rule | 45 CFR Part 164, Subpart E |
| ACA §1557 | Nondiscrimination, including provisions addressing patient care decision support tools |
Conformance does not make a determination lawful. It makes a lawful one provable.
If your reading of an instrument differs from ours, we want to hear it. This mapping is open for comment alongside the Profile itself.