In a single legislative session, states began writing the human back into AI-influenced healthcare determinations by statute — a licensed reviewer, a clinical peer, an annual certification. Every one of those laws creates a requirement. None of them creates the artifact that proves it was met. Clinica produces that record at the moment the review happens.
These are not guidance documents or model bulletins. They are enacted laws with effective dates, and they share a structure: an automated system may participate in a determination, and a qualified human must be part of it.
"Artificial intelligence shall not be the sole means used to deny, delay, or modify health care services." Carrier AI policies are open to audit by the insurance commissioner.
AI is permitted for initial prior-authorization review only. The determination itself does not belong to the system.
Licensed human review of AI-influenced coverage determinations — plus an annual certification filed with the Department of Insurance. Not a policy on a shelf: a filing, every year.
AI may not issue an adverse determination until a qualified human review agent conducts a review with a clinical peer participating. The reviewer's qualification is itself specified.
Others have moved in the same session, and the NAIC model bulletin on insurer AI use has been adopted in roughly two dozen states. The direction is not in question. What varies is only how fast each state gets there.
Read those four statutes together and the same shape appears in each: a human must review, the reviewer must be qualified, and in one case the organisation must certify annually that this happened. What none of them specify is what a firm produces when someone asks it to demonstrate that the review occurred.
Most organisations will answer with a policy. A policy is a statement of intent. It doesn't establish that a specific determination, on a specific date, was reviewed by a specific person who held the required qualification and had the relevant information in front of them.
A large national insurer's annual filing tells investors that its use of AI and machine learning could produce compliance costs, regulatory investigations, fines, penalties, and consumer lawsuits. Separately, it remains a defendant in a putative class action alleging improper use of an AI model in denials of post-acute care to Medicare Advantage members — allegations it disputes, which have not been proven, and on which a court has allowed several claims to proceed. Disclosure is not control. Control is what you can attest to when someone asks.
Clinica does not make clinical determinations and does not build the model that produces a recommendation. It governs the moment a recommendation reaches a person — capturing who reviewed it, what qualification they held, what was in front of them, how long they had it, and what they decided.
Not a checkbox and not a username. The record establishes who the reviewer was and that they held the credential the statute requires — because "a licensed human reviewed it" is a claim, and the licence is the part that gets checked.
The recommendation, the inputs it reasoned over, and the source material retrieved — sealed together, so what the reviewer had in front of them is part of the record rather than a matter of recollection.
Not only that a review happened, but how long it took. An adverse determination released in eleven seconds is a different fact than one held for twenty minutes, and both are worth knowing before someone else establishes them.
When a human disagreed with the system, that is captured — the disagreement, the basis, and the outcome. Override rate is the single most diagnostic number in any human-in-the-loop system and almost nobody keeps it.
Name, version, and weights hash. A determination from March can be reconciled against exactly what was running in March — which matters, because models are updated and behaviour moves with them.
Where a statute requires an annual attestation, the evidence accumulates through the year rather than being assembled at the deadline from whatever survived.
| Determination | SHA-256 of the released output |
| Inputs | Digest of each record the system reasoned over |
| Model | Name, version, weights hash |
| Reviewer | Named individual and credential held at time of review |
| Clinical peer | Where the statute requires one, recorded separately |
| Timing | Released at, and duration held under review |
| Disposition | Concurred, modified, or overridden — with basis |
| PHI | Whether identified data entered, and where it was exposed |
| Seal | 7b14c8e0a3f19d6248fbb7e05c1a9d3f8827ee40b6a5d213c94f07e8a1b2c6d5 |
Sealed under SHA-256 through LedgerGuard — verifiable by a regulator, an auditor, or opposing counsel using standard tools, with no cooperation required from us.
The exposure that worries us most in clinical settings is not a breach. It's capture that nobody decided to enable — an ambient tool authorised months earlier by one participant, a transcription service fired by a calendar integration, an assistant embedded in software the practice never chose. We call it consent drift: the distance between consent given once to a tool and the capture it now performs in rooms nobody anticipated.
In healthcare that drift carries PHI. And the failure has a specific shape worth naming: the party that granted access is rarely the party whose information is exposed. A patient did not authorise the tool. A referring physician did not authorise the tool. The person who clicked accept was somebody else entirely.
Whether identified information entered a decision, whether it was de-identified, and where identified data was exposed — a standing record rather than a point-in-time statement.
Deployed on the node, the system runs on hardware the organisation owns with no outbound path at all. There is no vendor to trust with PHI because there is nowhere for it to go.
Credentials, records, claims, referrals and authorisations screened for whether they are what they claim to be — including instructions hidden in a document and addressed to whatever system reads it.
The AI already operating inside the organisation that nobody selected — embedded in the EHR, the scheduling tool, the service desk. You cannot govern what you have not found.
Credentials, records, claims, referrals, authorisations — checked against the authority that holds the record, before anything reasons over them.
The system answers from the organisation's own material, with the sources shown alongside the output.
Nothing reaches a determination until a human with the required credential has it in front of them. Nothing clears itself.
At release — reviewer, credential, timing, disposition, model, PHI handling. Tamper-evident from that moment forward.
Clinica does not practise medicine and does not make coverage determinations. It produces evidence and structure. Clinical judgment belongs to a licensed clinician; coverage determinations belong to the parties licensed to make them. Nothing on this page is legal advice or a statement about the merits of any pending litigation.
Ask what you could produce today about who reviewed it, what qualification they held, what they had in front of them, and how long they spent. That single question is the fastest way to find out whether this is worth a conversation.
Start the conversation