If you run security or compliance for a healthcare organization, CMS has been writing AI rules for three years — just never in a document titled "AI rules." The obligations are scattered across a Medicare Advantage final rule, a prior-authorization interoperability rule, FAQs, and the HHS nondiscrimination framework that travels with them. This briefing pulls the AI-relevant threads into one place: what each rule actually says about algorithms, when it bites, and who in your organization owns the response.
The one-sentence version: CMS's position is that algorithms may inform care and coverage decisions but may not make them alone — and the enforcement mechanics arriving through 2026 and 2027 assume you can prove which decisions your AI touched. That proof requirement is where security and compliance teams come in.
Last verified: August 7, 2026. This is a security-practitioner's briefing, not legal advice — verify obligations against the rule text and your counsel before relying on them.
The map: four instruments, one direction
| Instrument | What it says about AI | Key dates | Who owns it |
|---|---|---|---|
| CMS Medicare Advantage rule + 2024 FAQs | Algorithms and AI may support coverage decisions but cannot be the sole basis for denying or terminating care; decisions must reflect the individual patient's circumstances, and coverage criteria cannot shift by algorithmic ingestion | In force — plan years since 2024 | Compliance / medical management, with IT evidence support |
| CMS-0057-F (Interoperability & Prior Authorization) | Doesn't regulate AI directly — but its prior-auth decision timelines and API mandates are exactly where payers are deploying AI, under the MA rule's constraints | Operational provisions from Jan 2026; API requirements Jan 2027 | CIO / interoperability program |
| HHS Section 1557 final rule (§92.210) | Covered entities must not discriminate through patient care decision support tools — including AI — and must make reasonable efforts to identify such tools and mitigate discrimination risk | Decision-support provisions in force since 2025 | Chief compliance officer / civil-rights coordinator |
| ONC HTI-1 (decision-support transparency) | Certified health IT must expose "source attribute" transparency for predictive decision-support interventions — what the algorithm considers, its limits, its provenance | In force since 2025 for certified health IT | CMIO / EHR program |
What "algorithms cannot terminate care" actually requires of you
The MA rule's headline principle — an algorithm cannot on its own end or deny services — sounds like a policy for utilization-management teams. Operationally, it is an evidence requirement, and it lands on three teams at once:
- You must know where algorithms sit in the decision path. That means an inventory: which tools touch coverage and care decisions, including the AI features your vendors switched on inside existing products. Shadow AI is not just a data-leak problem in healthcare — it is a regulatory-exposure problem, because a tool nobody inventoried is a tool nobody assessed under §92.210.
- You must be able to show human involvement. If a determination gets challenged, "the reviewer considered the individual circumstances" needs an audit trail, not a recollection. Logs of what the algorithm recommended versus what the human decided are the artifact regulators and plaintiffs' counsel will ask for.
- You must monitor for drift toward algorithmic dependence. A tool deployed as decision support becomes a de facto decision maker the day reviewers stop overriding it. Usage analytics — override rates, review times — are the early-warning system.
Section 1557: the "reasonable efforts" clock is running
The nondiscrimination rule's decision-support provision is the sleeper obligation. "Reasonable efforts to identify" discriminatory risk in patient care decision support tools presumes you can enumerate those tools — which most organizations cannot, because clinicians adopt AI the way everyone else does: a browser tab at a time. An inventory that covers sanctioned clinical systems but misses the ambient AI layer (scribes, summarizers, chatbots handling patient context) is a §92.210 gap wearing a completed-checklist costume. The practical program: discover everything in use, classify what touches patient care decisions, document the mitigation review for each, and re-run the cycle on a schedule — because the tool list changes monthly.
What to do this quarter
- Build the AI inventory with discovery, not surveys — including browser and endpoint usage where the unsanctioned layer lives. This single artifact feeds the MA-rule evidence trail, the §92.210 identification duty, and your HIPAA risk analysis simultaneously.
- Map each care- or coverage-adjacent tool to a named human checkpoint and log both the recommendation and the decision.
- Put PHI guardrails at the AI boundary — the same inventory will surface tools receiving PHI without a BAA, which is a separate and immediate problem.
- Assign the §92.210 mitigation file to an owner with a review cadence, so "reasonable efforts" has a paper trail with dates on it.
FAQ
Does CMS prohibit using AI in coverage decisions?
No — it prohibits AI being the sole basis for adverse decisions and requires individual-circumstance review. AI-assisted workflows are permitted; unattended ones are the violation.
We're a provider, not a payer. Does any of this apply?
Section 1557 and HTI-1 apply to covered providers directly; the CMS payer rules reach you through the prior-auth workflows and payer tools you interact with. And every one of them presumes the inventory-and-evidence layer this briefing describes.
Which team should own this?
The pattern that works: compliance owns the obligations, clinical informatics owns the tool assessments, and security owns discovery and the audit trail — because security is the only function with the telemetry to see what is actually in use.
Where does AccuroAI fit?
The inventory and evidence layer: discovering every AI tool in use across browsers and endpoints, PHI redaction at the boundary, and interaction logs attributable to users — the artifacts each of these rules quietly assumes you have. The fuller architecture is in our Healthcare AI Security Playbook.
Sources: CMS Medicare Advantage program rules and 2024 utilization-management FAQs; CMS-0057-F Interoperability and Prior Authorization final rule; HHS Section 1557 final rule (45 CFR §92.210); ONC HTI-1 final rule. Verify current obligations against the rule text — agency guidance in this area updates frequently.
Related: Healthcare AI Security in 2026: What CMS, HHS, and Section 1557 Mean · Is ChatGPT HIPAA Compliant in 2026? · AccuroAI for Healthcare.