Est.
AI in ClaimsLong read

CMS and OIG Regulatory Guidance on AI Use in Claims Submission

Medicare regulators now require AI billing tools to account for individual patient circumstances.

Reporter · · 10 min read
Cover illustration for “CMS and OIG Regulatory Guidance on AI Use in Claims Submission”
AI in Claims · October 1, 2026 · 10 min read · 2,145 words

Two major federal actions in early 2026 have made AI in claims submission a compliance priority for any practice that bills Medicare Advantage or uses an AI-assisted billing operation. Together, they mean that any practice billing Medicare Advantage, or relying on an AI-assisted billing vendor to do so, is now operating inside a regulatory framework that specifically names AI as a source of risk, not just a tool of convenience.

Why Federal Regulators Are Focused on AI in Claims Submission and Utilization Management

On February 3, 2026, HHS-OIG released new industry-specific voluntary compliance guidance for the Medicare Advantage program, the first comprehensive update to that guidance since 1999. The update reaches well past Medicare Advantage organizations themselves. It applies to first tier, downstream, and related entities (FDRs) and other individuals and entities that participate in or engage with the MA program, collectively referred to as MA Parties, which may include healthcare providers in those roles.

On February 25, 2026, CMS announced the CRUSH initiative, short for Comprehensive Regulations to Uncover Suspicious Healthcare. CRUSH marks a deliberate break from the "pay and chase" enforcement model that has defined Medicare oversight for decades, in which the government paid claims first and investigated fraud after the fact. CMS now describes a "detect and deploy" approach that uses AI tools to catch fraud and stop improper payments before money moves.

These two announcements did not happen in isolation. These two actions cite ongoing DOJ and CMS work to identify potentially abusive practices, and in July 2025 DOJ and HHS formed a renewed False Claims Act Working Group with fraud as its first priority. AI is now embedded in the enforcement infrastructure scrutinizing claims, and regulators have made explicit that AI used on the provider side to submit or support claims must meet specific behavioral standards. What follows in this piece breaks down what those standards actually are, and what a practice running or relying on AI billing tools needs to do about them.

The OIG's MA Compliance Guidance on AI and Claims Submission

The guidance identifies accurate claims submission as a key risk area and, for the first time in a major federal compliance document, singles out algorithm-based and AI tools as a source of compliance risk that organizations and their downstream entities must actively manage. The seven key risk areas include the Submission of Accurate Claims, and the guidance specifically identifies the use of algorithms based on artificial intelligence technology as an emerging area that presents compliance risks.

The substantive rule buried inside that warning is straightforward. Medicare Advantage organizations cannot rely solely on an algorithm or software that fails to account for an individual member's circumstances when making medical necessity determinations. Every utilization management decision has to be grounded in that member's actual medical history, the treating physician's recommendations, and the medical record in front of them, rather than a generalized pattern extracted from claims data. OIG backs this up with concrete recommendations: MAOs should review trends in claims and prior authorization denials to confirm they aren't inappropriately restricting coverage, track how often denials get overturned on appeal, and audit their algorithm-based tools directly to confirm the outputs reflect individualized clinical circumstances rather than blanket criteria.

The reach of this guidance matters as much as its content. Unlike existing CMS regulations, which apply narrowly to MAOs, the ICPG explicitly covers healthcare providers and first-tier, downstream, and related entities. A physician practice that uses an AI billing tool, or contracts with a vendor that provides AI-assisted billing services, carries its own compliance exposure under this framework, independent of whatever obligations sit with the health plan.

OIG notes it may update the ICPG periodically to address newly identified risk areas and respond to stakeholder feedback, an indication that AI-specific compliance expectations will tighten over time.

CMS prior authorization rule and proposed FHIR standard requirements for AI-assisted workflows

Where OIG's guidance sets compliance expectations, the CMS Prior Authorization Rule, formally CMS-0057-F, imposes hard structural requirements on the systems that generate prior authorization decisions, including AI-driven ones. Its operational provisions took effect January 1, 2026, with its technical FHIR API requirements following on January 1, 2027. A related proposal would extend similar interoperability requirements well beyond the payers this rule currently covers.

CMS-0057-F applies to Medicare Advantage, Medicaid, CHIP, and Qualified Health Plans (QHPs) on Federally Facilitated Exchanges (FFEs) and requires impacted payers to adopt FHIR APIs, due January 1, 2027, and electronic prior authorization processes enabling standardized interoperability between payer platforms and providers. In plain terms, this is an interoperability mandate: it forces payer systems and provider systems to speak a common electronic language for prior authorization requests and decisions, rather than relying on faxes, portals, and one-off data formats that make timely follow-up difficult.

The rule also sets hard clocks on decision timing. Payers must issue decisions on expedited, urgent requests within 72 hours, and on standard, nonurgent requests within seven calendar days. Those windows matter operationally: an AI-generated denial that arrives within 72 hours is still a denial, and a practice needs a workflow built to catch it, evaluate it, and respond inside the same window rather than discovering it weeks later buried in a billing report.

CMS's broader 2026 rulemaking goes further than timing and format. It proposed amending 42 CFR § 422.112(a)(8) to state clearly that equitable access has to be maintained regardless of whether a decision is made by a human reviewer or an automated system, and that AI or automated tools cannot discriminate based on any factor tied to an enrollee's health status. The same rulemaking proposed formal regulatory definitions for terms like "automated system" and "patient care decision support tool," which would give those phrases legal weight in enforcement proceedings for the first time.

A further expansion, CMS-0062-P, proposed in April 2026, would apply HL7 FHIR standards for prior authorization transactions to every HIPAA-covered entity, not just payers. That means health care providers and clearinghouses, alongside health plans, would be swept into the same interoperability mandate. Public comment on that proposal closed June 15, 2026, and it remains a proposed rule.

There's a nearer-term compliance point practices should already be addressing. USCDI v3 data classes became a requirement for certified health IT as of January 2026, and practices may need to enable additional FHIR resources or update their SMART on FHIR application settings to stay current. A practice that hasn't made those updates risks submitting claims through systems that are already out of step with the data standards CMS now requires, independent of anything CMS-0062-P eventually decides.

The CMS CRUSH Initiative and Enforcement Risk for AI-Assisted Billing

Diagram: From 'Pay and Chase' to 'Detect and Deploy': The CRUSH Enforcement Shift. Visualizes: Show the contrast between two enforcement eras in Medicare fraud detection.

CRUSH doesn't change what counts as fraud. CMS announced CRUSH on February 25, 2026 as an initiative that employs AI tools to detect fraud and prevent improper payments in real time, replacing the prior "pay and chase" model in which payments were made and then clawed back after investigation, and it changes how fast irregular billing gets noticed and acted on. Billing patterns that once took months to surface in a retrospective claims review can now trigger scrutiny while the pattern is still live.

The RFI published February 27, 2026 specifically solicits feedback on "Artificial Intelligence in Medicare Advantage Coding Oversight and Hospital Billing," a signal that AI-generated or AI-assisted claims are being treated as a distinct area of scrutiny rather than a subcategory of general fraud.

The scale of the detection infrastructure already running gives a sense of what CRUSH is building on top of. In 2025 alone, CMS's automated edits denied millions of Medicare claims, the agency imposed hundreds of administrative payment suspensions, it took thousands of provider and supplier revocation actions, and it placed more than $5.7 billion in Medicare payments on hold. For a physician practice, CRUSH translates into faster detection of irregular billing patterns, faster audit initiation, less patience for gaps in documentation, and closer examination of ownership structures and business relationships, including ties to third-party billing vendors.

Part of that infrastructure is the Health Care Fraud Data Fusion Center, which uses cloud computing, AI, and advanced analytics to spot emerging fraud schemes. It can trace patterns across state lines and map relationships between providers, suppliers, and billing entities that investigators previously had no practical way to see. None of this means legitimate AI-assisted billing operations are under threat simply for using automation. It means a practice whose AI billing tool is generating a pattern of aggressive upcoding, modifier stacking, or claim volumes that don't match plausible clinical activity is now exposed to enforcement attention that arrives faster and carries more evidentiary weight than it would have under the old audit model.

What payer AI denial practices mean for practices navigating these guardrails

The individualization standard that OIG has now written into its guidance doesn't just constrain how practices use AI. It sets an explicit bar that payer-side AI denial systems have to clear as well, and practices that understand that bar are in a stronger position to identify which denials are indefensible and worth fighting.

OIG's Medicare Advantage guidance addresses prior authorization denials directly, pointing back to earlier OIG reports from April 2022 and July 2023 that documented serious problems with improper denials and delays in patient care. Recent litigation gives that standard concrete shape. A federal judge in Minnesota ordered UnitedHealth to turn over internal documents related to its nH Predict system on March 9, 2026, granting plaintiffs access across all seven categories of records they requested, with some individual requests narrowed. Among the questions those documents are meant to answer is whether the system was built to override physician judgment, which is the same individualized-review standard OIG has now put into its guidance. Cigna's PxDx algorithm has drawn similar scrutiny for denying a large volume of claims with an average review time of 1.2 seconds per claim, a pattern that, measured against OIG's standard, looks like exactly the kind of algorithm-only determination that ignores a member's individual circumstances. Humana is also being sued in Kentucky over the nH Predict technology, with patients arguing that rigid AI criteria ignored their specific circumstances, and the legal theory mirrors OIG's stated compliance standard.

None of this is offered as legal advice to practices considering litigation. It's offered as operational intelligence. When a prior authorization denial arrives from a Medicare Advantage plan with no individualized clinical rationale attached, that denial isn't just questionable on the medical merits. It may fail the compliance standard OIG has now put in writing. A payer's ratio of denials to appeal overturns is exactly the kind of data OIG recommends MAOs track internally, and it's data practices can request directly under the transparency provisions built into CMS-0057-F.

A financial pattern underneath a lot of unchallenged denials is now drawing regulators' attention. Many practices absorb a denial rather than spend more money contesting it than the original claim was worth, and payers have built that math into their own denial strategy. Practices that consistently document and appeal AI-generated denials lacking individualized clinical rationale protect their own revenue. They're building exactly the kind of evidentiary record the current enforcement environment is set up to reward.

What these guardrails require of an AI billing operation

None of this regulatory framework is satisfied by the simple fact of using AI in billing. Compliance requires that AI-assisted decisions be traceable to individualized clinical circumstances, checked by qualified human reviewers when exceptions arise, and monitored on an ongoing basis for patterns that might signal systematic over-denial or improper claims submission.

The individualization requirement is the clearest operational demand in the entire framework. Any AI tool used in utilization management or prior authorization support has to produce decisions that trace back to a specific patient's medical history and the treating physician's recommendations, rather than a procedure code or a diagnosis pattern matched against a population-level dataset. Practices evaluating any AI billing vendor, whether built in-house or contracted out, should ask a direct question: how does the system document the clinical basis for each determination it makes?

Human review of exceptions isn't a nice-to-have layered on top of the AI system. OIG's guidance is explicit that MAOs may not rely solely on an algorithm or software for medical necessity decisions, and the same principle applies to the billing and prior authorization tools practices use. Downstream entities, including physician practices, share compliance exposure alongside the MAOs they work with. A vendor's AI system failing this standard becomes the practice's problem too.

Denial trend monitoring rounds out the picture. A practice that tracks its own denial rates, its appeal outcomes, and the patterns in how its AI billing tools generate claims is doing more than protecting revenue. It's building the same kind of internal record OIG has told MAOs to keep, and it's the record that will matter most if a regulator or auditor ever asks how a given claim, or a given denial, actually got made.

Sources

  1. OIG Releases Long-Awaited Medicare Advantage Compliance Program Guidance | Insights | Sidley Austin LLP
  2. OIG Issues New Industry Compliance Program Guidance for Medicare Advantage in First Major Update Since 1999
  3. CMS Rule for CY 2026 Highlights AI, Behavioral Health, Anti-Obesity Drug Coverage, and More | Epstein Becker Green
  4. CMS CRUSH Update: Providers Must Prepare for AI Driven Audits in 2026- Liles Parker PLLC
Filed underAI in Claims

More in AI in Claims