News
CMS finalizes AI transparency and appeals requirements for Medicare Advantage prior authorization
CMS on September 16 finalized new requirements that Medicare Advantage organizations disclose when AI or algorithmic tools are used to deny prior authorization requests, and that beneficiaries have expedited appeal rights when a denial rests on an AI recommendation. The final rule takes effect for the 2027 plan year and closes several loopholes that the proposed rule left open around vendor-provided decision engines and outsourced utilization management.
- CMS
- prior-authorization
- Medicare-Advantage
- AI-transparency
- regulatory
- appeals
The CMS final rule is the most consequential U.S. regulatory action of the year for AI in the payer space. Medicare Advantage plans have used algorithmic tools — some clearly AI, some rule-based systems marketed as AI — to accelerate prior authorization decisions for years, and the transparency of those tools has been the subject of both journalism and litigation. The final rule does not prohibit those tools. It creates a disclosure regime and an appeal-rights regime that changes their operational cost and reputational exposure.
The provisions that survived the proposed-to-final transition intact matter most. Beneficiaries who receive a denial that rests on an algorithmic recommendation now have to be told that fact in the denial notice, in plain language, along with the appeal path. Plans have to preserve the specific model version, input data, and output that produced the recommendation for a period long enough to support downstream review. And plans remain accountable for the decisions even when the algorithmic tool is provided by a third-party vendor or an outsourced utilization management partner — the vendor-liability loophole that the industry had lobbied to widen was closed rather than opened.
Operationally, plans and their vendors have roughly 15 months to build the disclosure, logging, and appeals infrastructure required to comply. That is a real engineering lift for organizations that treated the tools as opaque procurement rather than accountable clinical decision infrastructure. Expect a wave of vendor RFPs asking suppliers to demonstrate audit-trail capability, model-versioning discipline, and API-accessible decision records.
For the broader AI-in-healthcare policy conversation, the rule signals that the federal government is willing to regulate AI at the point of use — the payer decision workflow — even when the underlying model would fall outside FDA jurisdiction because it is not marketed as a medical device. That is the same regulatory posture that state attorneys general and the FTC have been taking on consumer-facing AI, and it is likely to spread to other CMS-regulated use cases (post-acute placement, home-health authorization) over the next several years.
Related coverage: prior authorization AI topic · health policy topic.
Primary source: Read the full original on Centers for Medicare & Medicaid Services ↗