A clear pattern is emerging across state AI legislation: When technology is used to help make healthcare coverage or prior-authorization decisions, states are generally holding users accountable or requiring human review.
Alabama, Arizona, Georgia, Iowa, Maryland, Nebraska, and Washington have all passed laws that place limits on automated decision-making in healthcare or health insurance. The details vary, but the direction is similar. AI can support review processes, but it should not independently determine whether medically necessary care is denied, delayed or changed.
Alabama
Alabama’s SB 63, effective October 1, 2026, applies to health insurers using AI in coverage decisions. Insurers cannot rely exclusively on AI to deny or reduce coverage, and a qualified healthcare professional must make the adverse decision. The law also introduces requirements around disclosure and oversight of how the technology is used.
For insurers, this means being able to show where AI sits in the process, when a person takes over, and who is responsible for the final decision.
Arizona
Arizona has taken a similar approach, with HB 2175, but places the responsibility specifically on the medical director. From July 1, 2026, a medical director must individually review certain claim and prior-authorization denials based on medical necessity, and exercise independent medical judgment. The reviewer cannot simply accept an automated or other recommendation as the answer.
The practical issue for insurers is the handoff between an automated recommendation and the person making the decision. Records should make that distinction clear.
Georgia
Georgia’s SB 444 takes effect on January 1, 2027. AI can still be used in utilization review, including to automate tasks and support decision-making, but it cannot issue an adverse determination until the required human review has taken place. Where a clinical peer is involved, the technology cannot override that person’s judgment.
That puts the emphasis on workflow design. An organization should be able to demonstrate that the system cannot bypass the clinical review required before an adverse decision is released.
Iowa
Iowa HF 2635 also allows AI to assist with the initial review of prior-authorization requests. However, an AI-based system cannot be the sole basis for denying, delaying, or downgrading a request involving medical necessity.
Organizations using automated screening therefore need a clear route for cases to move from the system to the appropriate human reviewer.
Maryland
Maryland’s requirements go further than simply requiring human involvement. HB 820 applies to carriers, pharmacy benefit managers, and private review agents using AI, algorithms or other software in utilization review.
The technology must take the individual patient’s clinical circumstances into account rather than relying solely on group data, and it cannot replace the role of the healthcare professional in the determination process. The law also addresses discrimination and the accuracy and reliability of the tools being used.
For businesses, that makes ongoing oversight just as important as the original implementation. It is not enough to put a human at the end of the process if the system feeding that decision is not being appropriately monitored.
Nebraska
Nebraska LB 77 prevents an AI-based algorithm from being the sole basis for denying, delaying, or modifying healthcare services because of medical necessity. It also requires organizations to disclose when AI is being used in utilization review and gives regulators the ability to audit automated utilization-management systems.
That creates a stronger documentation requirement. Health carriers need to be prepared not only to explain a particular decision, but also to show regulators how the underlying system is being used.
Washington
Washington SB 5395 follows much the same principle. AI cannot be the sole means of denying, delaying, or modifying care, and a licensed professional must consider the patient’s individual clinical circumstances when making a medical-necessity decision. The law also sets expectations around how AI systems use clinical information and how they are assessed for discrimination.
Across these states, the common business question is therefore straightforward: Can the organization show where automated analysis ends and accountable human judgment begins?
For organizations already using management systems, ISO 42001 can provide a framework for defining AI roles, risks, controls, and oversight. ISO 27001 and ISO 9001 may also support related information-security, documented-information, and quality processes.