News From Our Perspective

Navigate the Healthcare System with Ease

06
Apr 2026

What Hospitals Can Learn from the UnitedHealth AI Lawsuit – A Legal and Compliance Framework for Responsible AI Governance

Editor’s note (August 18, 2026): This post was originally published April 6, 2026. It has been updated to reflect developments through August 2026, to correct a citation to STAT News, and to add UnitedHealth’s public response and a fuller account of what the February 2025 ruling actually held.

A federal court in Minnesota is forcing UnitedHealth Group to open its internal files on one of the most consequential questions in modern medicine: when an artificial intelligence algorithm and a treating physician disagree about what a patient needs, who wins?

The lawsuit, Estate of Lokken v. UnitedHealth Group, alleges the answer at UnitedHealth was the algorithm.

UnitedHealth denies it. Optum’s position, stated on the record, is that claims the tool was used to make adverse benefit or coverage decisions are false, and that medical necessity determinations are made by qualified physicians following CMS guidance rather than by AI. The company describes nH Predict as a care-support tool that considers a patient’s cognition, mobility, and ability to perform daily activities, and that is shared with providers and caregivers to help guide recovery planning. In litigation, UnitedHealth has argued that the tool is a guide rather than a coverage decision, and that the Medicare Act preempts the plaintiffs’ state-law claims.

That disagreement, guide versus decision, is the whole case. It is also the exact line every hospital deploying AI in clinical or utilization workflows now has to be able to document on its own side of the ledger.

The March 2026 discovery order is what makes this worth your attention. It requires UnitedHealth to produce internal records reaching back to January 2017, and what is produced over the coming months may reshape how healthcare organizations across the country think about where AI belongs in clinical and coverage decision-making. The compliance expectations and litigation theories being tested in Minneapolis are directly relevant to provider operations.

What the Algorithm Could Not See

To understand why this case matters, it helps to understand what the plaintiffs say was happening to patients.

According to the complaint, the nH Predict algorithm, built on a database of roughly six million patient records, generated a predicted length of stay for elderly Medicare Advantage members receiving post-acute rehabilitation care. Plaintiffs allege that rather than treating that prediction as one input among many, UnitedHealth set internal targets requiring clinical staff to discharge patients when the algorithm said they should no longer need care, regardless of what the treating physician determined was medically necessary.

An algorithm can see patterns across a population. It cannot see that this particular patient is recovering more slowly because of a comorbidity the population data does not weight appropriately, or that the patient’s home environment makes early discharge dangerous. It cannot see what the physician saw when she examined the patient that morning, or what the family reported about function the day before. It cannot see trajectory, meaning where this patient has been and where this patient is actually going.

Plaintiffs allege that UnitedHealth knew the algorithm’s outputs were reversed on appeal roughly 90 percent of the time when patients challenged them, and that fewer than 0.2 percent of patients ever appealed. Patients in post-acute rehabilitation are, by definition, among the most vulnerable: elderly, often cognitively impaired, physically declining, and without the resources or knowledge to navigate a multi-level federal appeals process while fighting for their lives.

The scheme plaintiffs allege is straightforward. Deny claims at scale, retain Medicare Advantage premiums for care not delivered, and rely on patients being too sick or too exhausted to appeal. If those allegations are proven, this would not be a technology failure. It would be a decision to point a technology at the population it was ostensibly designed to serve.

Two facts outside the complaint give the allegations context. An October 2024 Senate investigation found that UnitedHealth’s denial rate for post-acute care rose from 10.9 percent in 2020 to 22.7 percent in 2022, after the company began using naviHealth and nH Predict in 2019. The court in the Lokken case cited that finding in its March 2026 discovery ruling, concluding that it made records predating the algorithm’s deployment relevant to the plaintiffs’ breach of contract theory. That is how a congressional report becomes a discovery argument.

What the February 2025 Ruling Actually Held

Most coverage of this case reports that it survived dismissal. What survived, and what did not, is the part hospital counsel should focus on.

On February 13, 2025, Judge John Tunheim dismissed five of the seven counts on Medicare Act preemption grounds. Unjust enrichment, insurance bad faith, negligence per se, unfair and deceptive insurance practices, and unfair competition all went out. Two claims proceed: breach of contract and breach of the implied covenant of good faith and fair dealing. The court also held that the Medicare appeals process was effectively futile for these plaintiffs, waiving the exhaustion requirement that would otherwise have barred the suit.

That outcome should shape how any provider organization thinks about its own exposure. In the Medicare Advantage context, tort theories aimed at coverage decisions run hard into preemption. What survived was the contract claim, and the reason it survived is instructive: the plaintiffs point to Evidence of Coverage documents promising that clinical staff and physicians make claims decisions. The alleged wrong is not that the algorithm was inaccurate. It is that the organization promised human judgment and, plaintiffs say, did not deliver it.

That is a promise-and-delivery problem, and it is one hospitals can create for themselves in their own patient consent forms, medical staff bylaws, payer contracts, and public representations about how care decisions get made.

The Regulatory Floor Has Already Been Set

The healthcare industry has treated AI governance largely as an internal ethics question. It is also a compliance question, and the regulatory floor is already in place.

On February 6, 2024, CMS issued FAQs interpreting the CY2024 Medicare Advantage final rule (CMS-4201-F). The guidance draws a clear line. CMS stated that an algorithm determining coverage based on a larger data set instead of the individual patient’s medical history, the physician’s recommendations, or clinical notes would not be compliant with 42 C.F.R. § 422.101(c). On terminating post-acute care specifically, CMS stated that a software tool may assist in predicting a length of stay, but that prediction alone must not be used as the basis to terminate services; the patient must no longer meet the level of care requirements at the time services are terminated, which can only be determined by re-assessing the individual patient’s condition before the notice of termination issues.

CMS did not prohibit AI. It made the organization responsible for the output.

Two related requirements deserve more attention than they usually get.

First, algorithms cannot quietly move the goalposts. CMS addressed the risk that AI tools, as they are trained and updated, may drift from the publicly posted coverage criteria the organization has represented it follows, without anyone consciously deciding to change coverage policy. Internal coverage criteria built into an automated system must remain within what is publicly accessible under § 422.101(b)(6). If your tool is producing decisions you cannot explain and document against public criteria, you are already out of compliance.

Second, and this is the strongest single hook in the whole framework, adverse medical necessity determinations require human review by someone qualified. Under 42 C.F.R. § 422.566(d), an adverse medical necessity decision must be reviewed by a physician or other appropriate health care professional with expertise in the field of medicine or health care appropriate to the service at issue. Not a reviewer. Not a workflow. A qualified clinician with subject-matter expertise. Any AI implementation that cannot demonstrate that this review happened, on this patient, is exposed regardless of how good the algorithm is.

Why This Is Sharper in Post-Acute Rehabilitation

To see why algorithmic substitution is particularly dangerous here, look at what Medicare’s coverage standard for inpatient rehabilitation actually requires.

IRF admission is covered only where the patient requires active and ongoing therapeutic intervention across multiple disciplines, can reasonably be expected to participate in and benefit from an intensive rehabilitation program of at least three hours of therapy per day at least five days per week, and requires physician supervision including face-to-face visits by a rehabilitation physician at least three times per week throughout the stay. Coverage must be supported by a comprehensive pre-admission screening conducted within the 48 hours immediately preceding admission, and by an individualized overall plan of care developed within the first four days of admission, both grounded in the specific patient’s condition and functional status.

The error data shows how demanding that standard is in practice. According to CMS’s Medicare Learning Network, drawing on the 2024 Medicare Fee-for-Service Supplemental Improper Payment Data, medical necessity accounted for 93.8 percent of improper payments for inpatient rehabilitation hospitals in the 2024 reporting period, with insufficient documentation accounting for the remaining 6.2 percent. Across IRF services overall, the projected improper payment amount was $2.0 billion at a rate of 26.5 percent.

That is the standard plaintiffs allege nH Predict was replacing with a population-based discharge prediction. An algorithm cannot conduct a pre-admission screening. It cannot perform a face-to-face clinical assessment. It cannot develop an individualized plan of care. Where AI output substitutes for those requirements, the problem is not only governance. It is a failure to deliver the covered service Medicare paid for.

The Legal Exposure Is Not Theoretical

Healthcare providers sometimes read insurance litigation and conclude it has little to do with them. Here, that conclusion is wrong. Provider organizations that integrate AI into clinical workflows, prior authorization support, utilization management, or care coordination face real legal risk if that AI functions as a decision-maker rather than a decision-support tool.

Breach of contract is the theory that survived preemption in Lokken, and it is the one to take most seriously. It arises where plan documents, provider agreements, patient consent forms, or public representations state that clinical decisions will be made by qualified medical professionals, and AI substitution makes those representations false.

Negligence may arise where AI outputs replace individualized clinical assessment and a patient is harmed by a decision the physician would not have made independently. Note the preemption caveat: in Medicare Advantage coverage disputes, tort claims of this kind have run into the Medicare Act, as they did in Lokken. That defense is far weaker for a provider sued over patient care rather than coverage. The AI does not absorb the liability. The organization does.

False Claims Act exposure may arise under some fact patterns where AI-driven denials or care limitations are used to retain federal reimbursements without delivering the care those payments are intended to fund. Where it applies, this theory has the sharpest teeth, because it carries treble damages and qui tam provisions allowing employees and whistleblowers to sue on the government’s behalf.

Civil rights exposure is emerging and serious. CMS has warned that AI algorithms can exacerbate discrimination and bias, and that Medicare Advantage organizations must ensure their AI use does not violate Section 1557 of the Affordable Care Act. HHS’s 2024 Section 1557 final rule specifically regulates discrimination through patient care decision support tools, at 45 C.F.R. § 92.210. An AI trained on historical data encodes historical disparities. If it consistently produces different outcomes by race, age, disability status, or geography, the organization using it owns that disparity.

Governance exposure runs upward as well. In February 2026, the HHS Office of Inspector General issued its Medicare Advantage Industry Segment-Specific Compliance Program Guidance, its first MA-specific compliance guidance since 1999. It is voluntary and non-binding, but it sets out expanded oversight expectations for artificial intelligence use, third-party vendors, and vertically integrated organizations, alongside recommendations that organizations review denial and appeal trends to confirm their policies do not inappropriately restrict coverage. Voluntary guidance is where enforcement expectations get published before they get enforced.

The financial-markets consequences are now visible too. An amended shareholder derivative complaint filed August 7, 2026 in Minnesota federal court, brought on behalf of the corporation against current and former UnitedHealth directors and officers, puts algorithmic denial of post-acute care alongside Medicare billing and cybersecurity allegations as governance failures. Whatever becomes of it, the message for boards is that AI deployment decisions are now being characterized as oversight decisions.

What Responsible AI Governance Actually Requires

The question is not whether to use AI. AI has genuine value in clinical settings: synthesizing longitudinal data, flagging risk signals, supporting differential diagnosis, improving care coordination across complex patients, and surfacing population-health patterns no individual clinician could track manually.

The question is whether the organization has built the governance to ensure AI does what it should, which is deepen the clinician’s understanding of the individual patient, rather than what it should never do, which is make the decision for them.

Five requirements are no longer optional.

First, document the AI’s role at the point of care, not just in policy. A policy stating that AI is decision-support is insufficient if the clinical record does not reflect physician engagement with and independent assessment of that patient. When a physician reviews an AI output and concurs, that is a clinical decision and it should read like one. When the AI output and the clinical record are indistinguishable, no physician decision has been documented, and no physician defense is available.

Second, make physician override non-punitive, accessible, and tracked. If override rates approach zero, that is not evidence the AI is always right. It is evidence that the culture has suppressed clinical independence. Plaintiffs in Lokken specifically allege that employees faced termination for departing from the algorithm’s outputs. If proven, that allegation would eliminate any good-faith argument that the tool was used as a guide, which is precisely the argument UnitedHealth is making.

Third, audit denial and reversal rates against physician-only benchmarks. If AI-assisted decisions produce denials at rates that diverge significantly from purely physician-driven decisions, particularly in post-acute care and skilled nursing, that divergence is a liability signal. It is also exactly the internal data OIG has indicated organizations should be reviewing and that plaintiffs’ counsel will seek in discovery.

Fourth, treat federally reimbursed programs as a distinct compliance environment. Any AI tool used in Medicare Advantage, Medicaid, or other federally funded programs operates under requirements that general healthcare AI best practices do not satisfy. Coverage decisions must rest on the individual patient’s circumstances, and AI predictions about population-level patterns are not individualized determinations. Have compliance counsel review the implementation against CMS’s February 2024 guidance and § 422.566(d) before a denial pattern emerges, not after.

Fifth, treat patient-facing transparency as a legal expectation rather than an ethical preference. Patients have a right to understand how decisions about their care are being made. As this litigation develops, organizations that can show they disclosed AI’s role in the assessment process, and that a physician made the final determination, will be in a fundamentally different position from those that cannot.

Where the Case Stands

Discovery is proceeding under the March 9, 2026 order, which requires UnitedHealth to produce documents dating to January 2017 across a broad set of categories: policies and procedures for post-acute care claims and employee training, documents analyzing or discussing nH Predict, records concerning the naviHealth acquisition and projected post-acute cost savings, materials on government investigations into the company’s use of AI in claims adjudication, performance evaluation and compensation records for post-acute care coordinators and medical directors, documents on its internal AI review board and the identity of its members, and contact information for the staff who issued Notices of Medicare Non-Coverage to 300 members of the proposed nationwide class. The court rejected UnitedHealth’s argument that documents predating the tool’s 2019 deployment were irrelevant. It did not order production of everything plaintiffs sought.

The case is now moving toward class certification. The plaintiff group has grown well beyond the two estates named in the original 2023 complaint. Optum rebranded naviHealth to Home and Community Care in 2024, so readers searching the original name will not find the current entity.

Each ruling, on discovery scope, on what internal governance documents must be produced, on how decision-support is legally distinguished from decision-making, will influence how healthcare organizations approach AI governance and how they will be evaluated when they get it wrong.

The organizations best positioned are not the ones using AI least. They are the ones using it most deliberately: documented governance, physician accountability at every decision point, regular outcome audits, and a clear understanding that the patient in front of the clinician is never reducible to the database behind the algorithm.

AI can tell a clinician what happened to patients who looked like this patient on paper. Only the physician can determine what is happening to this patient, today, in this room, and what that patient actually needs.

That distinction is good medicine. In the current legal environment, it is also the difference between a defensible practice and a discovery order.

Stephenson, Acquisto & Colman is a California-based healthcare reimbursement litigation firm with decades of experience representing healthcare providers in disputes involving payers, coverage denials, and regulatory compliance. If your organization has questions about AI governance in clinical or coverage decision-making, or about your exposure in the evolving regulatory environment, contact our office.


Sources and Citations

Allegations described in this article are allegations. Neither the Lokken litigation nor the shareholder derivative action has been adjudicated on the merits, and UnitedHealth denies the claims against it.

The Litigation

  • Estate of Gene B. Lokken, et al. v. UnitedHealth Group, Inc., et al., U.S. District Court, District of Minnesota, Case No. 0:23-cv-03514 (JRT/SGE), filed November 14, 2023.
  • Estate of Lokken v. UnitedHealth Grp., Inc., No. 23-cv-3514 (JRT/SGE), Doc. 91, Memorandum Opinion and Order Granting in Part and Denying in Part Motion to Dismiss (D. Minn. Feb. 13, 2025). Source for the dismissal of five counts on Medicare Act preemption, the survival of the breach of contract and implied covenant claims, and the futility holding waiving exhaustion.
  • Estate of Lokken v. UnitedHealth Grp., Inc., No. 23-cv-3514 (JRT/SGE), Doc. 162, Order Granting in Part and Denying in Part Motion to Compel (D. Minn. Mar. 9, 2026), reported at 2026 WL 658883. Source for the scope of the discovery order and the January 2017 date range.
  • Amended shareholder derivative complaint, filed August 7, 2026, U.S. District Court, District of Minnesota.

UnitedHealth’s Response

  • Statement of Optum spokesperson to Becker’s Payer Issues, March 2026, on the use of naviHealth and nH Predict in coverage determinations. https://www.beckerspayer.com/legal/judge-orders-unitedhealth-to-hand-over-broad-discovery-in-ai-coverage-denial-case/

Investigative Journalism

  • Ross, Casey, and Bob Herman. “Denied by AI: How Medicare Advantage plans use algorithms to cut off care for seniors in need.” STAT News, March 13, 2023. https://www.statnews.com/2023/03/13/medicare-advantage-plans-denial-artificial-intelligence/
  • Ross, Casey, and Bob Herman. “UnitedHealth pushed employees to follow an algorithm to cut off Medicare patients’ rehab care.” STAT News, November 14, 2023. Part of the four-part “Denied by AI” series, a 2024 Pulitzer Prize finalist in investigative reporting. https://www.statnews.com/denied-by-ai-unitedhealth-investigative-series/

Congressional Oversight

  • U.S. Senate Permanent Subcommittee on Investigations, majority staff report on Medicare Advantage post-acute care denials, October 2024. Source for the increase in UnitedHealth’s post-acute denial rate from 10.9 percent in 2020 to 22.7 percent in 2022.

Federal Regulatory Guidance

  • Centers for Medicare & Medicaid Services. “Frequently Asked Questions related to Coverage Criteria and Utilization Management Requirements in CMS Final Rule (CMS-4201-F).” HPMS Memo, February 6, 2024. https://www.aha.org/system/files/media/file/2024/02/faqs-related-to-coverage-criteria-and-utilization-management-requirements-in-cms-final-rule-cms-4201-f.pdf
  • Centers for Medicare & Medicaid Services. “Medicare Program; Contract Year 2024 Policy and Technical Changes to the Medicare Advantage Program.” CMS-4201-F, 88 Fed. Reg. 22120 (Apr. 12, 2023). https://www.federalregister.gov/documents/2023/04/12/2023-07115/medicare-program-contract-year-2024-policy-and-technical-changes-to-the-medicare-advantage-program
  • Centers for Medicare & Medicaid Services. “Inpatient Rehabilitation Hospitals & Inpatient Rehabilitation Units.” Medicare Learning Network Provider Compliance Tips. Source for the 93.8 percent medical necessity share and the $2.0 billion projected improper payment amount, drawn from the 2024 Medicare Fee-for-Service Supplemental Improper Payment Data. https://www.cms.gov/training-education/medicare-learning-networkr-mln/compliance/medicare-provider-compliance-tips/inpatient-rehabilitation-hospitals
  • U.S. Department of Health and Human Services. “Nondiscrimination in Health Programs and Activities.” 89 Fed. Reg. 37,522 (May 6, 2024).
  • U.S. Department of Health and Human Services, Office of Inspector General. “Medicare Advantage Industry Segment-Specific Compliance Program Guidance.” February 3, 2026. First MA-specific compliance guidance since 1999; voluntary and non-binding.

Federal Statutes and Regulations

  • 42 C.F.R. § 422.101(c) — Medical necessity determinations based on the individual patient’s circumstances. The provision at issue in CMS’s AI guidance.
  • 42 C.F.R. § 422.101(b) and (b)(6) — MA coverage criteria requirements and publicly accessible internal coverage criteria.
  • 42 C.F.R. § 422.566(d) — Physician or appropriate health care professional review of adverse medical necessity determinations.
  • 42 C.F.R. § 412.622(a)(3)–(5) — IRF coverage requirements, including the pre-admission screening, individualized overall plan of care, and intensity-of-therapy standards.
  • 45 C.F.R. § 92.210 — Nondiscrimination in the use of patient care decision support tools.
  • 31 U.S.C. §§ 3729–3733 — False Claims Act.
  • 42 U.S.C. § 18116 — ACA Section 1557.

Additional Sources

  • American Medical Association. “Principles for Augmented Intelligence Development, Deployment, and Use.” 2023.

This article is provided for general informational purposes and does not constitute legal advice. Coverage rules, agency guidance, and case law change, and application depends on specific facts and jurisdiction.

Our Partners Have a Combined Legal Experience of Over 100 Years

Meet our experts