WellthCareContact
Employer Benefits StrategyOpinionFor HR & Benefits Leaders

The Fiduciary You Never Hired

You've done the hard work. You've benchmarked your TPA fees, audited your PBM contract, and reviewed your stop-loss policy. Your fiduciary checklist is solid. But there's a quiet risk sitting right inside your health plan administration that almost nobody talks about. It's an algorithm.

Specifically, the automated prior authorization engines, claims adjudication models, and network adequacy tools that silently decide whether your participants get care and how much your plan pays. These systems are making fiduciary-level decisions every single day. Yet most plan sponsors have never once asked: Who trained this model? What data did it learn from? Does it systematically deny mental health claims at a higher rate?

Your algorithm is already acting as a fiduciary. Under ERISA, any entity that exercises discretionary authority over claims or benefits must be prudently selected and monitored. But algorithms aren't listed in your service agreements. No one appointed them. And most sponsors never think to audit them.

Three Risk Zones You Can't Afford to Ignore

1. Prior Authorization Engines and the Duty of Loyalty

Ask what population a prior auth model was trained on and whose benefit designs it reflects. A model built on a carrier's pooled book, which can mix insured plans and different benefit designs, may not match your self-funded plan's broader coverage. The algorithm optimizes for the population it learned from, not for your specific members. When its denials don't match your plan document, that's a conflict of interest.

Example: An algorithm flags certain high-cost procedures as "likely unnecessary" because it saw high denial rates in insured plans with different benefit designs. Your self-funded plan has broader coverage. But the algorithm applies the same pattern. Result: denials that don't match your plan document. That's a breach of the duty of loyalty.

2. Claims Adjudication Logic and the Duty of Prudence

Automated claims edits, repricing rules, and bundling algorithms can produce consistent, silent errors. The duty of prudence reaches the service providers who run these systems. A sponsor that never checks how they pay has not met that duty. Consider a bundling algorithm that combines two unrelated procedures into one payment, paying the provider $150 less than the plan document requires per claim. Across 10,000 claims, that's $1.5 million in underpayments that later surface as provider disputes and participant balance bills. If you never audit that algorithm's logic, you're not being prudent.

3. Network Adequacy Algorithms and the Duty to Inform

Network optimization tools can drop providers based on cost or utilization patterns without rechecking whether the network still meets the plan's access standards. If your plan promises timely access to a primary care provider within 15 miles, but the tool dropped the only in-network clinic in a rural zip code, you've misled participants and potentially violated the duty to disclose accurate plan information.

Why This Is So Rarely Discussed

The benefits industry has treated algorithms as neutral automation. But modern AI does not stop at applying rules. It learns patterns and creates new rules that no human explicitly wrote. Regulators are catching up. In 2024, the DOL's ERISA Advisory Council held hearings on claims and appeals procedures, where witnesses raised concerns about AI-driven claim review.

Plaintiffs' attorneys have already tested the theory. In Kisting-Leung v. Cigna (E.D. Cal. 2023), plaintiffs alleged that Cigna used automated systems to deny claims without meaningful individualized review, and the court found the alleged "repeated and systematic failures" sufficient to plausibly suggest a breach of ERISA's duties of loyalty and prudence. The parties settled for nearly $6 million in 2025. A denial by a black-box algorithm is harder to defend than one by a human reviewer. If you can't explain how the decision was made, you can't prove it was consistent with plan terms. That's a litigation nightmare.

Five Practical Steps to Close the Gap

You don't need to become a data scientist. You just need to add a new item to your fiduciary review.

  1. Demand an Algorithmic Fiduciary Impact Statement. Ask your carrier or TPA for a written attestation that every automated decision tool has been validated for compliance with your specific plan documents, no discriminatory impact, an error rate below 1%, and a documented override rate.
  2. Name the algorithm in your service agreements. Require the carrier to treat the algorithm as a "delegate" under your fiduciary liability policy. Demand full transparency on model updates, training data, and audit logs.
  3. Conduct a biannual algorithmic fiduciary audit. Hire a third-party auditor to run a random sample of claims and authorizations through your plan documents manually, then compare to the algorithm's decisions. Look for systematic deviations.
  4. Push for a fiduciary API standard. Encourage the industry to adopt a data interface that lets plan sponsors access raw algorithmic decisioning logs. You can't monitor what you can't see.
  5. Train your benefits committee. Teach them to ask: "Who reviews the reviewer of the prior auth engine?" If the answer is "our carrier's medical director," that's not enough.

Mental Health Parity Already Requires an Algorithm Check

The mental health question at the start of this post already has an answer in federal law. Under the Mental Health Parity and Addiction Equity Act (MHPAEA), a group health plan that imposes prior authorization or other nonquantitative treatment limitations on mental health and substance use disorder benefits must perform and document a comparative analysis showing those limits are no more restrictive than the limits on medical and surgical benefits. The analysis covers both the design and the application of each limit, and the plan must provide it to the DOL, HHS, or Treasury, or to an applicable state authority, on request. Participants can ask to see the processes, strategies, and evidentiary standards behind a limit.

That turns the algorithm question into a document request. If your carrier's prior authorization model denies mental health claims at a higher rate than medical claims, the comparative analysis must explain why and show the difference is not baked into the tool's design. A sponsor that cannot produce that analysis is already out of compliance, whatever the courts do next. The DOL finalized a rule in 2024 that expanded these requirements; the Departments signaled in 2026 that they plan to revise that rule, but the statutory obligation from the 2021 law remains in force.

Ask your carrier for the NQTL comparative analysis behind its prior authorization and other utilization management tools. If the answer is silence, you have your answer.

What This Means for You

You've spent years optimizing your PBM contract, benchmarking your TPA, and reviewing your stop-loss coverage. That's all smart work. But the biggest unmanaged fiduciary risk today sits inside a black box that no one ever appointed and no one ever audited.

The DOL is watching. One automated-denial case has already settled. And your participants are depending on you to do the right thing.

It's time to add one line to your fiduciary checklist: Audit the algorithm.

Want a practical template for requesting an Algorithmic Fiduciary Impact Statement from your carrier? I've prepared a one-page RFI document you can adapt. Reach out to continue the conversation.

← Back to Blog

This isn't insurance as usual.

Get Your Eligibility Results

30-minute call • Personalized Pension & Store projections

• No disruption to your current plan