An audit will require a record, not a reconstruction.

In Brief:  Arizona did not ban AI from claims or prior authorization. It made the denial decision individually reviewable, personally accountable, and capable of being proved later.
HB 2175, effective on July 01, 2026, is widely described as a law that bans artificial intelligence from denying health insurance claims. The enacted text does not use the words artificial intelligence, algorithm, or automation. It adds two provisions: A.R.S. 20-3103 for claims and A.R.S. 20-3407 for prior authorization, which require that before a health plan may deny a claim or a prior authorization on medical-necessity grounds, a medical director must individually review that denial, exercise independent medical judgment, and may not rely solely on a recommendation from any other source.
By regulating the decision rather than the tool, the practical consequence is evidentiary: a plan must be able to show, months later, what information, rules, and recommendations informed that specific determination

Read the Statute, Not the Coverage

Anyone building a compliance plan from headlines should slow down and read the enacted text.

Public discussion around HB 2175 largely treated it as an AI-ban statute, tracking the debate around the bill, rather than the law that finally passed. Because most of the existing media coverage was written before enactment, it discussed AI-focused language that did not make it into the final statute ?. Those stories have been recycled ever since, often by tools that summarize secondary sources without checking the law itself, resulting in new stories that repeat the superseded language. This AI content glitch illustrates, in its own sphere, the problem the statute addresses: a confident answer, widely repeated, that no longer matches the current state of the record.

Arizona HB 2175 was signed in May 2025 and is codified in two surviving provisions:

  • R.S. § 20-3103: “Before a health care insurer may deny a claim that was submitted by a provider on the basis of medical necessity, the medical director shall individually review the denial. During each individual review, the medical director shall exercise independent medical judgment and may not rely solely on recommendations from any other source.”
  • R.S. § 20-3407 applies the same standard to certain direct denials of prior authorization involving medical necessity.

The words that carry the operational weight are not “AI.” They are individually, each, independent medical judgment, and may not rely solely.

The duty attaches to the specific determination, not to the existence of a utilization-management program in general. That means the compliance burden scales with the number of medical-necessity denials that require this kind of review.

The real operational relief sits upstream. Resolve the clean cases correctly the first time, and fewer of them ever reach a medical director.

The Word That Isn’t There

Arizona regulated the decision and left the tools alone. The statute does not mention artificial intelligence, algorithms, models, or automation. It does not ban any technology. It does not even distinguish a machine recommendation from a human one.

It would be easy to treat that absence as the legislature having pulled its punch, but a ban on a named technology would have started a years-long fight over definitions. Is a rules engine AI? Is a scoring model? Is a clinical criteria set with automated pathing? Vendors would eternally debate which side of a moving line their product sits on, and the line would need redrawing with every release.

There is a more useful reading. The law does not ban automation. It makes the final covered denial rest on a human decision, which has to be demonstrable. Data can still be gathered, rules applied, conflicts flagged, and recommendations generated. What cannot happen is a denial that rests solely on a recommendation the medical director did not independently evaluate.

This does not make AI irrelevant. It makes AI part of the evidence problem. If a model, rules engine, criteria platform, or vendor workflow influenced a denial, the plan needs to know what it produced, what data it used, what version was in effect, and how the medical director evaluated it.

The statute does not ask plans to litigate whether a tool is “AI.” It asks them to prove that the human decision was not merely derivative of the tool. CureIS CEO Chris Sawotin puts it this way:

HB 2175 is better understood as a floor for trustworthy automation than as a ceiling on technology. The regulation draws a line in the sand. It says a system whose output cannot be explained should not be trusted to drive a consequential decision.

On the enacted text, that reading is close to literal. The statute sets no ceiling on technology. It sets an evidentiary floor under the decision.

Everything Turns on “Solely”

The statute does not say the medical director must ignore recommendations. It says the denial may not rely solely on them.

A director may see information from many sources: medical policy, clinical criteria, claim data, benefit terms, prior authorization records, vendor recommendations, internal notes, or system-generated flags. The question is whether the final denial reflects independent medical judgment or if it’s a recommendation wearing a human signature.

A signature only proves presence. It does not, by itself, prove judgment.

The proof lives in the record: what recommendation was generated, what supported it, what the director saw and concluded, what action was taken, and why, for that determination, on that date.

Most claims executives can explain why a claim would be denied today. Ask them to prove why it was denied three months ago and the ground gets soft. A claim denied on July 10 may have been evaluated against one eligibility record, one provider contract version, one medical policy version, and one configuration state. By October, each of these may have changed. If the system can only show October, the plan is no longer producing the original basis for the denial. It is reconstructing one.

Managed care data doesn’t sit still. Under Arizona’s law, that’s an audit problem.

A queue entry, a timestamp, a checkbox, and a denial notice may show workflow activity, but they do not typically show independent judgment. That is why this is an architecture question, not a staffing question.

The ability to show what a medical director saw months later either exists in how the data, rules, recommendations, and reviewer actions were captured at the time – or it does not.

Proving that a Human Decided

We took this up in an earlier post. In a lot of healthcare workflows, “human in the loop” has come to mean a person at the end of a high-volume queue. The system generates a recommendation, routes it to someone, and records that a person touched the case. When thousands of transactions move through in a day, real scrutiny is often unrealistic. The signature starts functioning less as assurance and more as an autopen.

That is not the posture this statute rewards.

A human-in-command model works the other way around. People set the policy. People define the rules. People decide the exceptions. People make the clinical calls that require judgment. Automation executes the rules it has been given and escalates the cases it cannot resolve cleanly.

One model asks a person to bless a conclusion. The other asks people to govern the process.

Under a statute that requires independent medical judgment and prohibits sole reliance on another recommendation, that distinction is not philosophical. It is the thing you have to be able to show.

Sawotin explains:

It’s not what people sometimes imagine, where everything becomes fully automated and agentic, operating without knowledge or participation. That is not how accountable healthcare operations should work.

At CureIS, human-first is a design principle, not a slogan. Our technology is built to put people in command of the definitions and the exceptions, not to replace the judgment that has to remain accountable. UniSync executes according to the rules people have set and escalates the cases that still require a human decision.

Why Testable Beats Probable

Many tools sold as AI for claims are probabilistic. These produce a likely answer from patterns or model behavior, then manage the leftover uncertainty with confidence scores and review queues. This can surface useful signals, but it’s a weak foundation for a determination you have to explain later, with precision.

A deterministic path works differently. The applicable rules and data determine the outcome. The same inputs produce the same result. When the system hits a combination it has not been configured to handle, it doesn’t invent an answer. It escalates.

Determinism does not mean the system is always right. It means that when the result is wrong, you can find out whether the defect sat in the source data, the rule logic, the configuration, or the policy interpretation – and fix it once, instead of rediscovering it across dozens of cases.

Arizona’s Broader Pattern: Delegate the Work, Not the Judgment

Although HB 2175 is often framed as a Luddite reaction to an unfamiliar technology, Arizona’s recent sessions suggest a broader instinct: keep the clinical judgment with the accountable licensed professional and let the administrative or ancillary work be delegated.

Arizona’s SB 1713, enacted in the same period, gives pharmacists authority to test and treat certain conditions while restricting delegation of clinical judgment. The context is different, but the shape is familiar: delegate the work, not the judgment that must remain with someone.

HB 2175 applies similar logic to claims and prior-authorization denials. Automation, vendors, criteria sets, and workflows may support the process. The covered medical-necessity denial still has to be individually reviewed, and the accountable judgment still has to be the medical director’s own.

For health plans deciding how much to invest in audit-ready architecture, that consistency is meaningful. The regulatory direction is not “less AI,” it’s more accountable decision-making.

Sidebar: Could an AI Ever be the Medical Director?

The statute names a role – medical director – and then attaches the duty to each individual review. It does not define who can occupy that role, which begs the question: if an AI were ever appointed as “medical director,” would the enacted text, read in isolation, stop it?

In practice, surrounding Arizona law closes that door more tightly than the statute suggests. In Murphy v. Board of Medical Examiners, 190 Ariz. 441, 949 P.2d 530 (App. 1997), review denied, the Court of Appeals held that a Blue Cross medical director’s medical-necessity pre-certification denial was a medical decision, not merely an insurance decision, and that the Board of Medical Examiners had jurisdiction over that judgment. The Arizona Supreme Court left the ruling in place.

If a medical-necessity denial is the practice of medicine, the person making it has to be capable of holding a license and of being disciplined by a medical board. An AI cannot do either. It also cannot “exercise independent medical judgment” in the sense the courts mean.

Plans should take their counsel’s view; the statute’s neutrality about tools should not be read as creating an empty title.

Questions to Ask any Automation Vendor

Plans don’t need to ask only whether a vendor uses AI. They need to ask whether the system can support proof.

  • Can it reproduce the data, rules, and policy versions that were in effect on the date of a determination?
  • Does it preserve overwritten, corrected, or retroactively changed data?
  • Can it show what recommendation was generated, what supported it, and what action the reviewer took?
  • Can it distinguish a denial that requires individual medical-director review from one that does not?
  • What happens when it encounters a combination of facts it has not been configured to resolve?
  • Are the business rules readable and changeable by the people accountable for them, or only by technical staff?
  • Who, other than the vendor, has verified that identical inputs produce identical outputs?
  • Does the audit trail preserve a record or rebuild history from current-state data?

A plan that cannot answer these before an audit, an appeal, or a regulatory inquiry may be relying on confidence its own systems cannot support.

The Choice

A plan can satisfy HB 2175 procedurally: routing medical-necessity denials to the medical director, capturing the review, and treating the requirement as met. That approach holds until an audit or dispute asks for the complete record behind a specific determination made months earlier.

The more durable response treats the statute as a standard of proof and works backward from it. If the plan will eventually have to show what was known, what rule applied, what was recommended, who decided, and why, then those elements have to be captured as the work happens, not assembled later from whatever the systems still hold.

Because the duty attaches to each individual medical-necessity denial, the volume of cases that reach that review is the real operational variable. The only lasting relief is resolving the clean cases correctly the first time so fewer of them ever require a medical director’s independent judgment.

Answer an audit or dispute with a record and the statute becomes manageable. Answer it with a reconstruction and the statute is only the start of the exposure.

Arizona did not ban a technology. It made a person answerable for a decision and required that the answer be their own.

———

Want to know whether your claims and prior authorization processes can produce a record rather than a reconstruction? CureIS works with health plans to answer that question against their own operations.

About CureIS

CureIS has spent two decades inside managed care data and claims operations. We build on that foundation, challenge how things have always been done, and modernize health plan operations without a rip-and-replace. Audit-ready operations follow from that approach. They are not bolted onto it.

Frequently Asked Questions

Does Arizona’s HB 2175 ban health plans from using AI to deny claims?
The enacted statute does not mention artificial intelligence. It regulates the decision rather than the technology used to support it.
For covered medical-necessity denials of claims and prior authorizations, the statute requires individual review by the medical director, independent medical judgment, and no reliance solely on a recommendation from another source.
Automation may still gather data, apply administrative rules, flag conflicts, generate recommendations, and route work. The key issue is whether the denial rests on independent medical judgment rather than solely on an automated or third-party recommendation. Health plans should consult their own counsel regarding how the provisions apply to specific workflows.

What does “any other source” cover?
The act does not define or limit “any other source.” It reaches any recommendation the medical director receives, whether generated by software, a clinical criteria set, a vendor guideline, another clinician, or a delegated utilization management entity.

What is the practical compliance burden?
The practical burden is proving that the decision did not rely solely on a recommendation.
That means the plan must be able to show what else informed the decision for a specific determination on a specific date. This depends on what the plan’s systems captured and retained at the time, not merely what they can report today.

Why does point-in-time data matter for auditability?
Because audits, appeals, and regulatory inquiries often ask why a specific determination was made on a specific date.
Managed care inputs change constantly through rate updates, retroactive contracts, corrected eligibility, retroactive terminations, authorization changes, and policy revisions. If the data layer stores only current state, historical explanations must be reconstructed from today’s values. Preserving prior state is what turns an audit trail into a record.

What is the difference between deterministic and probabilistic automation?
Probabilistic automation produces a likely answer based on patterns or model behavior and typically manages uncertainty with confidence thresholds and review queues.
Deterministic automation resolves to the same answer every time for the same inputs because the applicable rules and data determine the outcome. When it encounters an unrecognized combination, it escalates rather than inventing certainty.
Deterministic systems are not automatically correct. They are testable, which is what matters when a determination has to be explained later.

How should a plan evaluate a vendor’s claim that its automation is deterministic?
Ask who evaluated the behavior besides the vendor. Determinism is testable: identical inputs should produce identical outcomes, and unrecognized combinations should escalate rather than produce invented certainty. A data sheet asserting determinism is not verification.

Our denial rates are already defensible. Why does this matter?
Because the statute creates exposure at the level of the individual determination rather than the aggregate rate.
A reasonable denial rate and an unprovable process can coexist. Under HB 2175, the process behind the individual decision is what has to be shown.

Sources & References

Arizona House Bill 2175 – original language.

Arizona House Bill 2175, Chapter 165, Fifty-seventh Legislature, First Regular Session (2025). Approved by the Governor May 12, 2025; effective from and after June 30, 2026.

Arizona Revised Statutes §§ 20-3103 and 20-3407. Codified effective July 1, 2026.

Arizona State Legislature, Senate Bill 1713 (Fifty-seventh Legislature, Second Regular Session). Non-delegable clinical judgment provision at A.R.S. § 32-1979.04.

Arizona Medical Association. “Keeping Healthcare Human: How a New Arizona Law Will Protect Patient Care From AI.”

Holland & Knight. “States Continue Efforts to Regulate AI in Healthcare: A Review of Legislation Passed in 2026.” May 2026.

KFF. “Regulation of AI in Prior Authorization and Claims Review: A Look at Federal and State Consumer Protections.” 2026.

Upcoming Webinar

Connect With a CureIS Data Expert