AccuroAI
Products
What We Do
Solutions
Company
Resources
Book demo
← Blog·AI Compliance7 read

CMS AI Guidance for Healthcare: The 2026 Compliance Briefing

CMS's position in one sentence: algorithms may inform care and coverage decisions but may not make them alone — and the enforcement mechanics assume you can prove which decisions your AI touched. The four instruments, mapped.

S
Sofia Reyes
Head of Compliance
2026-08-07

If you run security or compliance for a healthcare organization, CMS has been writing AI rules for three years — just never in a document titled "AI rules." The obligations are scattered across a Medicare Advantage final rule, a prior-authorization interoperability rule, FAQs, and the HHS nondiscrimination framework that travels with them. This briefing pulls the AI-relevant threads into one place: what each rule actually says about algorithms, when it bites, and who in your organization owns the response.

The one-sentence version: CMS's position is that algorithms may inform care and coverage decisions but may not make them alone — and the enforcement mechanics arriving through 2026 and 2027 assume you can prove which decisions your AI touched. That proof requirement is where security and compliance teams come in.

Last verified: August 7, 2026. This is a security-practitioner's briefing, not legal advice — verify obligations against the rule text and your counsel before relying on them.

The map: four instruments, one direction

InstrumentWhat it says about AIKey datesWho owns it
CMS Medicare Advantage rule + 2024 FAQsAlgorithms and AI may support coverage decisions but cannot be the sole basis for denying or terminating care; decisions must reflect the individual patient's circumstances, and coverage criteria cannot shift by algorithmic ingestionIn force — plan years since 2024Compliance / medical management, with IT evidence support
CMS-0057-F (Interoperability & Prior Authorization)Doesn't regulate AI directly — but its prior-auth decision timelines and API mandates are exactly where payers are deploying AI, under the MA rule's constraintsOperational provisions from Jan 2026; API requirements Jan 2027CIO / interoperability program
HHS Section 1557 final rule (§92.210)Covered entities must not discriminate through patient care decision support tools — including AI — and must make reasonable efforts to identify such tools and mitigate discrimination riskDecision-support provisions in force since 2025Chief compliance officer / civil-rights coordinator
ONC HTI-1 (decision-support transparency)Certified health IT must expose "source attribute" transparency for predictive decision-support interventions — what the algorithm considers, its limits, its provenanceIn force since 2025 for certified health ITCMIO / EHR program

What "algorithms cannot terminate care" actually requires of you

The MA rule's headline principle — an algorithm cannot on its own end or deny services — sounds like a policy for utilization-management teams. Operationally, it is an evidence requirement, and it lands on three teams at once:

  1. You must know where algorithms sit in the decision path. That means an inventory: which tools touch coverage and care decisions, including the AI features your vendors switched on inside existing products. Shadow AI is not just a data-leak problem in healthcare — it is a regulatory-exposure problem, because a tool nobody inventoried is a tool nobody assessed under §92.210.
  2. You must be able to show human involvement. If a determination gets challenged, "the reviewer considered the individual circumstances" needs an audit trail, not a recollection. Logs of what the algorithm recommended versus what the human decided are the artifact regulators and plaintiffs' counsel will ask for.
  3. You must monitor for drift toward algorithmic dependence. A tool deployed as decision support becomes a de facto decision maker the day reviewers stop overriding it. Usage analytics — override rates, review times — are the early-warning system.

Section 1557: the "reasonable efforts" clock is running

The nondiscrimination rule's decision-support provision is the sleeper obligation. "Reasonable efforts to identify" discriminatory risk in patient care decision support tools presumes you can enumerate those tools — which most organizations cannot, because clinicians adopt AI the way everyone else does: a browser tab at a time. An inventory that covers sanctioned clinical systems but misses the ambient AI layer (scribes, summarizers, chatbots handling patient context) is a §92.210 gap wearing a completed-checklist costume. The practical program: discover everything in use, classify what touches patient care decisions, document the mitigation review for each, and re-run the cycle on a schedule — because the tool list changes monthly.

What to do this quarter

  1. Build the AI inventory with discovery, not surveys — including browser and endpoint usage where the unsanctioned layer lives. This single artifact feeds the MA-rule evidence trail, the §92.210 identification duty, and your HIPAA risk analysis simultaneously.
  2. Map each care- or coverage-adjacent tool to a named human checkpoint and log both the recommendation and the decision.
  3. Put PHI guardrails at the AI boundary — the same inventory will surface tools receiving PHI without a BAA, which is a separate and immediate problem.
  4. Assign the §92.210 mitigation file to an owner with a review cadence, so "reasonable efforts" has a paper trail with dates on it.

FAQ

Does CMS prohibit using AI in coverage decisions?

No — it prohibits AI being the sole basis for adverse decisions and requires individual-circumstance review. AI-assisted workflows are permitted; unattended ones are the violation.

We're a provider, not a payer. Does any of this apply?

Section 1557 and HTI-1 apply to covered providers directly; the CMS payer rules reach you through the prior-auth workflows and payer tools you interact with. And every one of them presumes the inventory-and-evidence layer this briefing describes.

Which team should own this?

The pattern that works: compliance owns the obligations, clinical informatics owns the tool assessments, and security owns discovery and the audit trail — because security is the only function with the telemetry to see what is actually in use.

Where does AccuroAI fit?

The inventory and evidence layer: discovering every AI tool in use across browsers and endpoints, PHI redaction at the boundary, and interaction logs attributable to users — the artifacts each of these rules quietly assumes you have. The fuller architecture is in our Healthcare AI Security Playbook.

Sources: CMS Medicare Advantage program rules and 2024 utilization-management FAQs; CMS-0057-F Interoperability and Prior Authorization final rule; HHS Section 1557 final rule (45 CFR §92.210); ONC HTI-1 final rule. Verify current obligations against the rule text — agency guidance in this area updates frequently.

Related: Healthcare AI Security in 2026: What CMS, HHS, and Section 1557 Mean · Is ChatGPT HIPAA Compliant in 2026? · AccuroAI for Healthcare.

See AccuroAI in action.
30-minute demo tailored to your top AI risk.
Book a demo
More from the blog
See AccuroAI in action.

Book a 30-minute demo and see how security teams use AccuroAI to discover, govern, and protect every AI asset across their organization.

Book a demoTalk to security