You've done the hard work. You've benchmarked your TPA fees, audited your PBM contract, and reviewed your stop-loss policy. Your fiduciary checklist is solid. But there's a quiet risk sitting right inside your health plan administration that almost nobody talks about. It's not a person, not a vendor-it's an algorithm.
Specifically, the automated prior authorization engines, claims adjudication models, and network adequacy tools that silently decide whether your participants get care and how much your plan pays. These systems are making fiduciary-level decisions every single day. Yet most plan sponsors have never once asked: Who trained this model? What data did it learn from? Does it systematically deny mental health claims at a higher rate?
Here's the blunt truth: Your algorithm is acting as a fiduciary. Under ERISA, any entity that exercises discretionary authority over claims or benefits must be prudently selected and monitored. But algorithms aren't listed in your service agreements. No one appointed them. And most sponsors never think to audit them.
Three Risk Zones You Can’t Afford to Ignore
1. Prior Authorization Engines and the Duty of Loyalty
Most prior auth algorithms are built by carriers using their own book of business-insured plans, fully pooled data, mixed populations. If your plan is self-funded, that algorithm may be optimizing for your carrier's total book, not for your specific members. That's a conflict of interest.
Example: An algorithm flags certain high-cost procedures as "likely unnecessary" because it saw high denial rates in insured plans with different benefit designs. Your self-funded plan has broader coverage. But the algorithm applies the same pattern. Result: denials that don't match your plan document. That's a breach of the duty of loyalty.
2. Claims Adjudication Logic and the Duty of Prudence
Automated claims edits, repricing rules, and bundling algorithms can produce consistent, silent errors. A 2023 court case found that a plan's reliance on an unreviewed automated pricing system could be a fiduciary breach. Why? Because the plan sponsor never checked if the system was paying correctly.
Consider this: A bundling algorithm combines two unrelated procedures into one payment, underpaying the provider by $150 per claim. Over 10,000 claims, that's $1.5 million in overpayments to the plan-or underpayments that trigger provider disputes and participant balance bills. If you never audit that algorithm's logic, you're not being prudent.
3. Network Adequacy Algorithms and the Duty to Inform
Carriers now use real-time network models to "optimize" narrow networks-removing providers based on cost or utilization patterns without rechecking whether the network still meets the plan's access standards. If your plan promises timely access to a primary care provider within 15 miles, but the algorithm dropped the only in-network clinic in a rural zip code, you've misled participants. And potentially violated the duty to disclose accurate plan information.
Why This Is So Rarely Discussed
The benefits industry has treated algorithms as neutral tools-just automation. But modern AI doesn't simply apply rules. It learns patterns and creates new rules that no human explicitly wrote. Regulators are catching up. In 2024, the DOL's ERISA Advisory Council held hearings on AI in health plan administration. Expect enforcement actions soon.
Plaintiffs' attorneys are circling too. A denial by a black-box algorithm is harder to defend than one by a human reviewer. If you can't explain how the decision was made, you can't prove it was consistent with plan terms. That's a litigation nightmare.
Five Practical Steps to Close the Gap
You don't need to become a data scientist. You just need to add a new item to your fiduciary review.
- Demand an Algorithmic Fiduciary Impact Statement. Ask your carrier or TPA for a written attestation that every automated decision tool has been validated for compliance with your specific plan documents, no discriminatory impact, an error rate below 1%, and a documented override rate.
- Name the algorithm in your service agreements. Require the carrier to treat the algorithm as a "delegate" under your fiduciary liability policy. Demand full transparency on model updates, training data, and audit logs.
- Conduct a biannual algorithmic fiduciary audit. Hire a third-party auditor to run a random sample of claims and authorizations through your plan documents manually, then compare to the algorithm's decisions. Look for systematic deviations.
- Push for a fiduciary API standard. Encourage the industry to adopt a data interface that lets plan sponsors access raw algorithmic decisioning logs. You can't monitor what you can't see.
- Train your benefits committee. Teach them to ask: "Who reviews the reviewer of the prior auth engine?" If the answer is "our carrier's medical director," that's not enough.
What This Means for You
You've spent years optimizing your PBM contract, benchmarking your TPA, and reviewing your stop-loss coverage. That's all smart work. But the biggest unmanaged fiduciary risk today sits inside a black box that no one ever appointed-and that no one ever audited.
The DOL is watching. Plaintiff lawyers are circling. And your participants are depending on you to do the right thing.
It's time to add one line to your fiduciary checklist: Audit the algorithm.
Want a practical template for requesting an Algorithmic Fiduciary Impact Statement from your carrier? I've prepared a one-page RFI document you can adapt. Reach out to continue the conversation.
