HandInLoop

Guide

AI utilization-review compliance: the human-in-the-loop mandate

The short answer: AI can speed up utilization review, but the emerging rule across regulators and courts is that a qualified human — not a model alone — must own the decision to deny, delay, or modify care. California's SB 1120 makes this explicit for health plans; federal prior-authorization rules and a wave of litigation over algorithmic denials push the same way. The practical requirement is not "don't use AI" — it's being able to prove, for any given denial, that a competent human reviewed it. That is a recordkeeping problem, and it's solved with a verified, signed decision record.

What "human-in-the-loop" means in utilization review

Utilization review (UR) and utilization management (UM) are how payers decide whether a requested service is covered and medically necessary. AI is attractive here because it can read charts and flag routine cases fast. The risk is that a model's suggested denial becomes the actual denial with no meaningful human judgment in between. "Human-in-the-loop" means the reverse: AI assists and prioritizes, but a qualified person makes and stands behind the medical-necessity call — and there is a record proving it.

Why the pressure is building

None of this bans AI. All of it raises the bar on being able to demonstrate qualified human review — which is where most programs are weakest.

Why policy alone isn't enough

Plenty of payers already require physician sign-off on denials as policy. The gap is evidentiary. When a decision is questioned months later, the payer has to answer concrete questions: which named, credentialed person reviewed this claim, what did they see, and can that be shown without relying on the payer's own uncorroborated word? If the trail is scattered across systems and editable logs, "we had a human review it" is an assertion, not proof. Defensible compliance means a per-decision record that is specific, durable, and tamper-evident.

What a verified, signed decision record provides

The reusable pattern that satisfies the mandate has four properties:

  1. No automated denial. A proposed deny or pend can never finalize on the model's say-so; it is always routed to a human before the decision issues.
  2. Named, credentialed attestation. The reviewer who clears a denial is recorded with their qualification — name, credential type, license number, jurisdiction — attached to that specific decision.
  3. Cryptographic integrity. The decision and its attestation are sealed in an Ed25519-signed Proof Object, so the record can't be silently altered and can be verified offline by anyone holding the public key — no need to trust the vendor or the payer.
  4. A complete audit trail. The record shows what the AI proposed, that a qualified human reviewed it, and who that was — reproducible on demand for a regulator, an appeal, or a court.

Where HandInLoop fits

HandInLoop supplies exactly this layer, and is careful about its boundary: it verifies decisions; it does not make medical-necessity determinations. It forces every proposed denial to a human, captures the reviewer's credential as a required attestation, and returns a signed, independently verifiable record that a licensed human owned the call. The credential is currently self-declared by the reviewer rather than checked against a licensing board, but it produces a durable, tamper-evident chain of accountability — the artifact these rules effectively demand. It's demonstrated today on synthetic and de-identified claims, so teams can evaluate the mechanism before any protected data is involved.

See the verified decision record — free