HandInLoop

Guide

Does California require a human to review AI claim denials? (SB 1120)

The short answer: yes, within a specific domain. California's SB 1120, the Physicians Make Decisions Act (effective January 1, 2025), says that when a health plan or disability insurer uses AI or an algorithm in utilization review or utilization management, a determination of medical necessity can be made only by a licensed physician or qualified health care professional — the AI tool cannot make that call on its own. It does not ban AI in claims, and it does not reach every AI decision an insurer makes. It ensures a qualified human, not a model, is accountable for denying, delaying, or modifying care.

What SB 1120 actually says

SB 1120 amended California's Knox-Keene Act (Health and Safety Code § 1367.01) and the parallel Insurance Code provision, which govern health care service plans and disability insurers. When such a payer uses "artificial intelligence, algorithm, or other software tool" for utilization review or utilization management, the law requires, among other things, that:

The through-line is accountability: AI may assist, but a licensed human owns the medical-necessity decision and the payer must be able to show it.

What the law does not do

It is easy to overstate SB 1120. To stay accurate:

Treat this page as a plain-language explainer, not legal advice. For how the statute applies to a specific program, consult qualified counsel.

Why this is hard to prove after the fact

A payer can have a compliant policy and still struggle to demonstrate compliance. When a denial is challenged — by a regulator, an appeal, or in litigation — the question becomes: who reviewed this specific decision, were they qualified, and what did they see? If the answer lives in scattered logs, screenshots, and email, it is slow and contestable to reconstruct. The mandate is really a recordkeeping problem: every AI-assisted denial needs a durable, tamper-evident record that a named, credentialed human stood behind it.

How a human-in-the-loop record demonstrates compliance

HandInLoop is a verification layer, not an adjudicator: it does not decide medical necessity. What it provides is the human-in-the-loop workflow and the audit record the mandate implies:

  1. A denial can never auto-issue. When an AI-assisted decision proposes to deny or pend care, the job is always routed to human review — it cannot be finalized by the model alone.
  2. A credentialed human attests. To complete a denial, the reviewer records who they are and their qualification — name, credential type, license number, and jurisdiction — captured as a required attestation on the decision.
  3. The attestation is cryptographically bound. That "reviewed by licensed [X]" record is embedded in an Ed25519-signed Proof Object, so the signature binds the decision to the human who made it. Anyone can verify it offline against a public key — no trust in HandInLoop required.
  4. Everything is on the audit trail. The result shows what the AI proposed, that a licensed human reviewed it, and who that was — the exact chain SB 1120 asks a payer to be able to produce.

Note that this attestation is currently self-declared by the reviewer rather than checked against a licensing board — it records and signs the credential the reviewer supplies. That is enough to establish an auditable, tamper-evident chain of accountability; board-level verification is a separate control.

Doing this with HandInLoop

HandInLoop runs the loop as a service: AI extracts and scores the claim, any proposed denial or pend is forced to a human, the reviewer attests with their credential, and a signed, verifiable decision record comes back — showing that a licensed human, not a model, owned the call. It's a clean fit for the accountability SB 1120 requires, demoed today on synthetic and de-identified claims.

See the human-in-the-loop record — free