August 25, 2026 in The Standard

AI in Health Plan Member Experience Is a Risky Venture

Three regulations already on the books were written on the assumption that member outreach is finite, uniform, and human. Artificial intelligence makes it infinite, personalized, and automatic. Nobody reconciled those two things, and the plan carries the consequences.

By RaeAnn, Founder and Chief Executive Officer, HLTHWORKS

Who is actually doing this

Very few health plans built their member engagement capability. They bought it.

The standard architecture is a vendor contracted to close Star and HEDIS gaps, working a stratified list, calling and texting and emailing members, sometimes with its own clinicians making the outreach, often with a reward or incentive attached to completion. Multiple vendors run simultaneously against overlapping populations. Add a member-facing chatbot, an interactive voice system, and a broker or lead generation channel, and a mid-sized plan can have six or seven distinct systems talking to the same member.

Artificial intelligence has arrived inside all of them, and mostly not through a decision the plan made. It arrived because vendors added it. The plan did not procure artificial intelligence. It procured outreach, and the outreach became automated.

That matters because none of the obligations transfer. The Office for Civil Rights expressly declined to create a safe harbor for entities that rely on a vendor’s tool. The Telephone Consumer Protection Act places the consent burden on the calling business rather than the voice platform. Medicare Advantage rules hold the plan responsible for the conduct of its downstream sales force. And in the first state enforcement action against a healthcare artificial intelligence company, the attorney general said plainly that scrutiny falls on procurers as well as developers.

The plan did not procure artificial intelligence. It procured outreach, and the outreach became automated.

What the federal rules already require

There is no federal artificial intelligence statute governing health plan member engagement. There does not need to be. Four existing regimes already reach it.

SECTION 1557, PATIENT CARE DECISION SUPPORT TOOLS

The 2024 nondiscrimination rule, with a compliance date of May 1, 2025, requires covered entities to make reasonable efforts to identify tools that use variables measuring protected characteristics, and reasonable efforts to mitigate discrimination risk. Health insurance issuers are covered entities, because federal financial assistance includes Medicare Parts A, C, and D and Medicaid. The scope is clinical decision-making rather than scheduling or billing, and there is no safe harbor. Status should be confirmed, as counsel widely expects revision.

THE TELEPHONE CONSUMER PROTECTION ACT

The Federal Communications Commission ruled in February 2024 that artificially generated voices are artificial or prerecorded voices under the statute, and that ruling remains in force. Marketing calls to mobile numbers require prior express written consent. Informational calls require prior express consent. Statutory damages run five hundred to fifteen hundred dollars per call with no aggregate cap, which makes a ten thousand call campaign a fifteen million dollar exposure. Consumers may revoke consent in any reasonable manner.

MEDICARE ADVANTAGE MARKETING AND COMMUNICATION RULES

All marketing materials and election forms must be submitted to CMS through the Health Plan Management System. Any organization or individual compensated to perform lead generation, marketing, sales, or enrollment functions in the chain of enrollment is a third-party marketing organization, and every call between a third-party marketing organization and a beneficiary must be recorded. Plans must operate oversight procedures for each one and report noncompliance.

REWARDS AND INCENTIVES, AND BENEFICIARY INDUCEMENT

Rewards must be offered to all qualifying individuals, cannot discriminate on health status or chronic disease, cannot be cash or cash equivalents including reduced cost sharing, and cannot exceed the value of the health-related activity. Using a HEDIS measure as the basis of eligibility is not permitted. Noncompliance is a stated basis for sanction, and the beneficiary inducement penalty now runs to 25,595 dollars per violation.

Three places where the technology and the rule cannot both be right

These are not compliance gaps that better process closes. They are direct incompatibilities between what the technology does and what the regulation assumes.

The first is personalization against filing. Marketing rules assume a finite set of materials that can be submitted, reviewed, and stored. Generative systems produce a different variant for every member. There is no version of infinite variants that can be filed, and no plan has publicly solved this.

The second is targeting against uniformity. The entire value proposition of artificial intelligence in outreach is reaching the right member with the right offer at the right moment. The rewards and incentives rule requires that all qualifying individuals be included and treated the same, prohibits differentiating on health status, and specifically bars using a HEDIS measure to determine eligibility. A model that targets predicted gap closure is targeting on health status by construction.

The third is voice under two regimes at once. An automated call to a Medicare Advantage beneficiary in the chain of enrollment must be recorded under the marketing rules and separately consented under the Telephone Consumer Protection Act, and in ten states the recording itself requires all-party consent. Class actions were filed in California in 2026 alleging that artificial intelligence recorded people in healthcare settings without meaningful notice.

Where the rules differ, and the trap inside that

At least fifteen states have enacted requirements reaching artificial intelligence in health-related consumer interaction, and they do not agree with each other.

Some require disclosure only if the consumer asks. Some require it at the outset regardless. Some require it only in sales contexts. Utah sets the lowest threshold in the country by treating the collection of health data in a generative interaction as itself a high-risk interaction, which means outreach that asks a member about symptoms triggers disclosure without diagnosing or denying anything. Several states prohibit artificial intelligence from serving as the sole basis for an adverse coverage determination. One requires large carriers to report the share of denials that artificial intelligence assisted.

The practical answer for a national plan is to adopt the strictest standard everywhere. Disclose at the outset, in plain language, with a stated path to a human. Building fifty variants of a disclosure rule costs more than complying with the hardest one.

And here is the trap. Medicare Advantage standards supersede state laws that would otherwise apply to Medicare Advantage plans, with limited exceptions. So the same automated outreach may be governed by state law in the commercial book, by federal rules in Medicare Advantage, and by state Medicaid contract terms in a third line. A plan that answers this question once has answered it for one line of business.

Why the largest number is not a penalty

The regulatory exposure is real and quantifiable. It is not the biggest number in this article.

Consider what actually happens. A plan buys automated outreach to close gaps. Artificial intelligence makes contact nearly free at the margin, so volume rises. Several vendors run against overlapping populations without knowing about each other. The member receives more calls, more texts, and more messages from more parties, and answers fewer of them.

Then the Consumer Assessment of Healthcare Providers and Systems survey and the Health Outcomes Survey measure exactly that experience.

Most executives read that patient experience and complaint measures dropped from a weight of four to a weight of two beginning with the 2026 Star Ratings and concluded member experience matters less. At the portfolio level the opposite is happening. Survey measures moved from roughly thirty-two percent of the operational category breakdown to roughly thirty-five percent between measurement years 2025 and 2026, and are projected to move from thirty-one to thirty-six percent of total rating between the 2027 and 2029 Star Ratings, with some analyses placing the combined survey share near forty percent by 2029. The reason is that CMS is removing high-performing administrative measures, which were the safety net. The two Health Outcomes Survey measures on improving or maintaining physical and mental health increase to a weight of three.

So the survey is becoming worth more than the gaps the outreach was purchased to close.

The system deployed to raise Stars is capable of lowering them, and the damage arrives eighteen months later when nobody connects it back to the campaign.

That is the miss. Not a penalty notice. A quality bonus payment that does not arrive, traced to a campaign that hit every gap closure target it was given.

The checkpoints

What a plan and its vendors should be able to evidence, in the order a regulator or an auditor would ask.

CHECKPOINT

WHAT GOOD LOOKS LIKE

Inventory

Every system that contacts a member, including capability embedded in vendor products never procured as artificial intelligence. Named owner for each. Most inventories are between fifty and seventy percent complete, and the gap is vendor-embedded.

Classification

For each system, whether it informs a clinical determination, participates in the chain of enrollment, collects health data, or allocates a reward. Each answer pulls in a different regime, and most systems are misclassified as purely administrative.

Disclosure

Plain-language notice at the outset that the member is interacting with artificial intelligence, with a stated path to a person. Adopted as one national standard rather than fifty.

Consent

Telephone Consumer Protection Act consent by call type, recording consent where applicable, and health data consent where a generative interaction collects it. Timestamped and provable, since the burden falls on the plan.

Vendor terms

Audit rights, artificial intelligence disclosure, subprocessors named, and an express prohibition on training or model improvement using your data including de-identified derivatives. De-identification is the route vendors actually use.

Reward design

Eligibility defined by qualifying individual status rather than by open gap. This is the checkpoint most likely to fail on inspection today.

Substantiation

Documented evidence supporting any accuracy or performance claim relied upon, whether the claim came from the vendor or was repeated by the plan.

Escalation and stop

A named person who can pull a system out of production immediately, and at least one instance where that authority was used. A program that has never stopped anything has never been tested.

If member experience just went artificial intelligence first

Six things to document and monitor from the day the first automated system goes live, because none of them can be reconstructed later.

CONTACT VOLUME PER MEMBER, ACROSS ALL VENDORS

Not per campaign. Per member. This is the single number nobody currently owns, and it is the leading indicator of a survey problem. If no one can produce it, that is the finding.

HUMAN ESCALATION RATE AND TIME TO HUMAN

How often a member asks for a person, how long it takes, and how often the request fails. A rising escalation rate is the earliest warning that the automation is not working, and it arrives long before the survey does.

CONTAINMENT VERSUS RESOLUTION

Vendors report containment, meaning the interaction ended without a transfer. Containment and resolution are not the same thing, and a member who gave up is counted as a success. Insist on resolution measured independently.

ADVERSE OUTCOME RATE BY PROTECTED CHARACTERISTIC

For any system informing a determination, outcome distribution across the characteristics named in the nondiscrimination rule. This is the evidence the rule requires, and it cannot be produced retroactively.

CONSENT AND DISCLOSURE COMPLETENESS

The percentage of automated contacts with provable consent of the correct type and a delivered disclosure. Anything below one hundred percent is a countable exposure, and the count is per contact.

COMPLAINT TEXT, READ RATHER THAN COUNTED

Complaint volume is a lagging number. The language inside complaints is not. Members describe being unable to reach a person months before the survey field period.

What the C-suite and the board should see

These are different reports and most organizations produce only the first.

The executive report should run monthly and be operational. Contact volume per member with a stated ceiling. Escalation rate and time to human. Resolution rather than containment. Consent completeness. Complaint themes. Any system paused or removed, and why. It should carry a named owner, and the owner should not be the vendor manager.

The board report should run quarterly and answer five questions in one page. How many member-facing systems are in production and how confident are we in that count. Which of them participate in a determination that could be adverse to a member. What is our current exposure if consent completeness is wrong. What did the surveys tell us, and is the trend consistent with the outreach volume we are running. And has anyone independent of the operators reviewed this, and when did the board last see that review.

If the answer to the last question is that nobody outside the operating team has looked, that is the report.

The venture, and the risk

Nothing here argues against artificial intelligence in member experience. The economics are compelling, the workforce math is unforgiving, and members increasingly expect digital service. This is going to happen and it should.

But it is being deployed inside a regulatory structure built on assumptions that no longer hold, by vendors whose obligations do not transfer, measured against a survey that is quietly becoming the largest component of the rating, and governed in most organizations by nobody in particular.

Every one of those is fixable, and all four are cheaper to fix now than in the quarter a bonus payment fails to arrive. The plans that get this right will not be the ones that moved slowest. They will be the ones that could answer, on the day they were asked, how many systems were talking to their members and what those systems said.

Sources and further reading

  • Federal. 45 CFR 92.210, nondiscrimination in the use of patient care decision support tools, 2024 final rule. Federal Communications Commission Declaratory Ruling, February 2024, artificial intelligence generated voices under the Telephone Consumer Protection Act. 42 CFR Part 422 Subpart V, Medicare Advantage communication requirements, including third-party marketing organization definition and call recording. 42 CFR 422.134, reward and incentive programs. Beneficiary inducement civil monetary penalty under 42 USC 1320a-7a, as adjusted. 42 CFR 422.166, calculation of Star Ratings and measure weights.
  • State. Enacted requirements in California, Texas, Illinois, Utah, Colorado, Nebraska, Washington, Maine, New Jersey, and others governing artificial intelligence disclosure, consent, and use in coverage determinations. Tracked and maintained in the HLTHWORKS AI Regulatory Update.
  • Enforcement. State of Texas settlement with a healthcare generative artificial intelligence company, September 2024. Federal Trade Commission Operation AI Comply and subsequent orders concerning substantiation of artificial intelligence performance claims.

This article is analysis provided for general informational purposes. It is not legal advice and does not describe the obligations of any organization under the law of any jurisdiction. Requirements in this area change frequently and several provisions cited are subject to pending revision. Confirm every requirement against primary sources before acting.

HLTHWORKS transforms Medicare Advantage, Commercial, and Medicaid health plans, driving efficiency in the business of health, impact in the value and quality of care delivery, and simplicity in the patient journey.