Indiana: AI health laws

2 entries on the map: 2 in force.

Payer and utilization review AI

Insurers', benefit managers' and utilization reviewers' use of AI, including prior authorization and claim denials.

In forceLaw

HB 1271, Payment of Health Claims (House Enrolled Act 1271, Public Law 88-2026)

In force since Jul 1, 2026 (signed Mar 4, 2026)

Bars an insurer from using an automated process, system or tool, including AI, as the sole basis to downcode a claim based on medical necessity without an employee or contractor reviewing the covered individual's medical record, requires insurers to disclose in an easily accessible and readable manner when AI is used to make an adverse prior authorization determination or to downcode a claim, and bars providers from using such tools to submit a claim without review by a provider or other person involved in developing it.

Physician read. From July 1, 2026, a physician or practice may not use an automated process, system or tool, including AI, to submit a claim under a state-regulated accident and sickness policy, HMO contract or dental preferred provider plan (Medicaid is excluded) without review by a provider or other person involved in developing the claim. Those insurers may not use such a tool as the sole basis to downcode a claim on medical necessity grounds unless an employee or contractor reviews the patient's medical record, must notify the provider of each downcode with claim adjustment and remittance codes, the reason and clinical criteria and the original and revised codes and payments, must allow at least 180 days to appeal, and must disclose when AI is used to make an adverse determination on a prior authorization request or to downcode a claim.

Applies to: Accident and sickness insurers, HMOs, insurers with dental preferred provider plans and their third-party contractors (not Medicaid or Medicaid managed care); providers that submit claims to them
Also touches: Patient disclosure of AI use

Notes: iga.in.gov bill pages need JavaScript and the enrolled act could not be opened there, so status, dates and text come from LegiScan's bill page and its copy of the enrolled act. SECTION 6 of the act adds the AI rules as a new chapter, IC 27-1-52 (Downcoding of Health Benefits Claims), with the effective-date line July 1, 2026; the chapter does not apply to the Medicaid program or Medicaid managed care organizations (IC 27-1-52-0.3) and directs the Department of Insurance to adopt rules. The provider rule is IC 27-1-52-9(b); a health benefits claim is a claim a provider submits for payment under a health plan as the chapter defines it. The act also limits retroactive rate reductions, sets time frames for claim audits and overpayment recovery, and requires hospital payment-assistance notices. The chapter does not say to whom the insurer's AI disclosure must be made.

Checked against its sources

Patient disclosure of AI use

Telling patients that AI is used in their care or in messages to them.

Also relevant here: HB 1271, Payment of Health Claims (House Enrolled Act 1271, Public Law 88-2026) (under payer and utilization review AI).

Clinical decision and chatbot limits

Limits on AI in clinical decisions and on health chatbots, including AI presenting itself as a licensed professional.

Nothing in this category was found in the review of Sept 29, 2026.

Mental health AI

AI in therapy and mental health care.

Nothing in this category was found in the review of Sept 29, 2026.

Data and privacy

Health and consumer data, biometrics, and data used to train AI.

In forceLaw

SB 5, Consumer Data Protection (Senate Enrolled Act 5, Public Law 94-2023), IC 24-15

In force since Jan 1, 2026 (signed May 1, 2023)

Gives Indiana consumers rights to confirm, correct, delete and obtain a copy of their personal data and to opt out of targeted advertising, sale and profiling in furtherance of decisions with legal or similarly significant effects, requires consent to process sensitive data, including a mental or physical health diagnosis made by a health care provider and biometric data, and requires data protection impact assessments, enforced by the attorney general after a 30-day cure period with civil penalties of up to $7,500 per violation.

Physician read. It places no duty on practices that are HIPAA covered entities, and protected health information is exempt. Since Jan. 1, 2026, health apps and other businesses outside HIPAA that meet the thresholds must get consent before processing a health diagnosis or biometric data and must honor opt-outs from consequential profiling.

Applies to: Businesses that control or process personal data of at least 100,000 Indiana consumers, or of 25,000 while deriving more than 50% of gross revenue from selling personal data; HIPAA covered entities and business associates are exempt

Notes: Provisions were read in the 2026 edition of IC 24-15 on iga.in.gov; the history note for IC 24-15-1-1 (applicability and exemptions) shows one amendment since enactment, by P.L.236-2025. IC 24-15-1-1 exempts any covered entity or business associate governed by the HIPAA privacy, security and breach notification rules as an entity. The act defines sensitive data to include a mental or physical health diagnosis made by a health care provider, genetic or biometric data processed to identify a person, a known child's data and precise geolocation. The Jan. 1, 2026 start date is given by LegiScan and the attorney general's guide.

Checked against its sources

Federal law also applies in every state: see federal law and policy.

Most recently checked Sept 29, 2026. General information, not legal advice. How the map works, and the data.