Skip to content
هذه ترجمة للتسهيل فقط. النسخة الإنجليزية هي النسخة الرسمية والملزمة قانونيا. عرض النسخة الإنجليزية
US-MDMEDIUM coverage

Maryland Insurance AI Surface — MIA Bulletin 24-11, HB 820/SB 474 Utilization-Review AI (Ins. § 15-10B-05.1), and Bulletin 25-10 Imagery: AI Compliance Requirements

Maryland regulates insurance AI on THREE stacked surfaces, and only the third is healthcare-specific. (1) MIA BULLETIN 24-11, "The Use of Artificial Intelligence Systems in Insurance", issued 22 April 2024 by Commissioner Kathleen A. Birrane to all Insurers, Nonprofit Health Service Plans, Health Maintenance Organizations, and Dental Plan Organizations ("Carriers") holding a Maryland certificate of authority — Maryland's adoption of the NAIC Model Bulletin. It expects every Carrier to develop, implement, and maintain a WRITTEN AI Systems Program ("AIS Program") covering governance, risk management and internal controls, and third-party AI, and it tells Carriers exactly what documents the Administration will demand in a market conduct action. It creates no new statute: it routes AI conduct into Title 27 (Unfair Trade Practices) and COMAR 31.15, Title 27 Subtitle 3 (Unfair Claims Settlement Practices), Title 4 Subtitle 5 and COMAR 31.04.23 (Corporate Governance Annual Disclosure), Title 11 Subtitles 2 and 3 (P&C rating law), and Insurance §§ 2-205 through 2-209 (market conduct examinations). (2) MIA BULLETIN 25-10 (17 June 2025) applies that frame to a concrete technology — cancellation, nonrenewal, and claim denial based on satellite or aerial imagery — and expressly tells insurers using AI to enhance, interpret, or review such images to comply with Bulletin 24-11. (3) HB 820 (Ch. 747, 2025) and SB 474 (Ch. 670, 2025), both effective 1 October 2025, put the healthcare-AI duties into STATUTE: new Md. Code, Insurance § 15-10B-05.1 governs AI, algorithms, and other software tools used for utilization review, and amended § 15-10A-06 makes carriers report quarterly whether AI was used in each adverse decision, aggregated by zip code (implemented by MIA Bulletin 25-15). Above all of it sits the long-standing licensed-clinician reservation in § 15-10B-07, which no AI deployment can displace.

Summary of publicly-available regulatory text as of 2026-08-26. Verify against current official sources before relying on this for compliance decisions. Not legal advice.

Key Facts

Effective Date

April 22, 2024

Maximum Penalty

No AI-specific penalty schedule exists; exposure routes to the existing Insurance Article tracks (all fetched from mgaleg.maryland.gov this round): Md. Code, Insurance § 4-113(d) — instead of or in addition to suspending or revoking a certificate of authority, a penalty of not less than $100 but not more than $125,000 for EACH violation of the article, plus restitution to any person who suffered financial injury; § 27-305(a) — not exceeding $2,500 for each violation of § 27-303 (unfair claim settlement practices) and not exceeding $125,000 for each violation of § 27-303(9); § 15-10B-12(b)(4) — an administrative penalty of up to $5,000 for each violation of any provision of the private-review-agent subtitle (which is where § 15-10B-05.1 sits), alongside certificate denial/suspension/revocation, cease-and-desist, and patient restitution; § 15-10B-12(a) — misdemeanor, penalty not exceeding $1,000, each day a violation continues after the first conviction a separate offense; and § 1-301 — a willful violation of the article is a misdemeanor subject to a fine not exceeding $100,000.

What Your Business Must Do

19 compliance requirements identified. Critical requirements carry the highest risk of enforcement action.

Clinician Oversight of AI Decisions

Critical

R523 CORRECTION — this duty is in § 15-10B-05.1, not § 15-10A-06, and its operative words are narrower and sharper than the paraphrase this requirement previously carried. Md. Code, Insurance § 15-10B-05.1(c)(4) requires that an artificial intelligence, algorithm, or other software tool "does not replace the role of a health care provider in the determination process under § 15-10B-07 of this subtitle". That cross-reference is the whole ceiling, and § 15-10B-07(a) is unusually specific about who the human must be: ALL adverse decisions shall be made by a licensed physician, or a panel of other appropriate health care service reviewers with at least one physician on the panel, who is (i) board certified or eligible in the SAME SPECIALTY as the treatment under review AND (ii) knowledgeable about the requested health care service or treatment through ACTUAL CLINICAL EXPERIENCE. Two carve-outs change the credential: for a mental health or substance abuse service the reviewer must be a licensed physician (or panel including one) selected by the private review agent who is board certified or eligible in the same specialty OR is actively practicing or has demonstrated expertise in the service under review (§ 15-10B-07(a)(2)); for a dental service it must be a licensed dentist, or a panel with at least one licensed dentist knowledgeable through actual clinical experience (§ 15-10B-07(a)(3)). Note what this does NOT say: the statute does not merely require that a clinician "sign off" — it requires that the adverse decision BE MADE by a reviewer holding a specialty match to the treatment. An AI pipeline that routes every denial to one generalist medical director does not satisfy § 15-10B-07(a)(1) however much human review it interposes.

Deadline: October 1, 2025

Md. Code, Insurance § 15-10B-05.1(c)(4) (added by HB 820, Ch. 747, Acts of 2025, effective 1 Oct 2025), cross-referencing § 15-10B-07(a)(1)-(3) (adverse decisions by same-specialty board-certified physician; mental-health/substance-abuse and dental variants)

Absolute Bar — an AI, Algorithm or Software Tool May Not Deny, Delay or Modify Health Care Services

Critical

The single hardest line in Maryland's AI insurance law, and it was entirely unmodelled before R523. Md. Code, Insurance § 15-10B-05.1(d) states, as a standalone subsection outside the list of qualified duties in subsection (c): "An artificial intelligence, algorithm, or other software tool may not deny, delay, or modify health care services." Read the structure carefully, because it matters for how a product is built. Subsection (c) opens "Subject to subsection (d) of this section" — so every duty in (c) is subordinate to this bar, and satisfying the whole of (c) does not buy an exemption from (d). The bar is not limited to DENIAL: DELAY and MODIFICATION are named separately, which catches the two patterns that a denial-focused control misses — an automated pend or additional-information loop that defers care, and an automated step-down from the requested service to a cheaper alternative. Compliance reading: the tool may score, triage, flag, summarise, surface guideline matches, and prepare a recommendation; the adverse action itself must be taken by the § 15-10B-07 reviewer. Practically this means the system architecture must make it impossible for a model output to be committed as a determination without the qualified human act, rather than relying on a policy that says humans should intervene.

Deadline: October 1, 2025

Md. Code, Insurance § 15-10B-05.1(d) (added by HB 820, Ch. 747, Acts of 2025, effective 1 Oct 2025); subsection (c) is expressly made "subject to subsection (d)"

Maryland Utilization-Review Standing Reservations — Same-Specialty Reviewer, Compensation Independence, and the Retrospective-Denial Bar

Critical

STANDING UTILIZATION-REVIEW SWEEP (the Illinois / Massachusetts / Virginia lesson, now 4 for 4: when a state's insurance AI surface is opened, sweep its utilization-review code for clinical-peer reservations whether or not an AI act exists). Maryland's sweep found reservations that PREDATE HB 820 and bind independently of it, and § 15-10B-05.1(c)(4) explicitly incorporates them by cross-reference. § 15-10B-07(a)(1): all adverse decisions shall be made by a licensed physician, or a panel of other appropriate health care service reviewers with at least one physician on the panel, who is board certified or eligible IN THE SAME SPECIALTY as the treatment under review and knowledgeable about the requested service through ACTUAL CLINICAL EXPERIENCE; § 15-10B-07(a)(2) substitutes, for mental health or substance abuse services, a licensed physician selected by the private review agent who is same-specialty board certified or eligible OR is actively practicing or has demonstrated expertise in the service under review; § 15-10B-07(a)(3) substitutes a licensed dentist for dental services. § 15-10B-07(b) adds an INDEPENDENCE condition that is easy to overlook when automating: adverse decisions must be made by reviewers who are not compensated by the private review agent in a manner that violates Health – General § 19-705.1 or that DETERS THE DELIVERY OF MEDICALLY APPROPRIATE CARE — so a throughput or denial-rate incentive attached to the human confirming an AI recommendation is itself a defect. § 15-10B-07(c) then bars retrospective adverse decisions on services already preauthorized or approved, with only three exceptions in § 15-10B-07(d): information submitted was fraudulent or intentionally misrepresentative; critical requested information was omitted such that the determination would have been different; or the approved course of treatment was not substantially followed. § 15-10B-07(e) bars revising or modifying the criteria or standards used for the review to reach an adverse decision on preauthorized services. SYSTEM CONSEQUENCE: a model retrained or re-tuned mid-course cannot be turned on retrospective review of already-approved care — subsections (c) and (e) together foreclose exactly the pattern where an improved model re-scores a settled authorisation. Separately, § 15-10B-11(8) requires the criteria and standards used to conduct utilization review to be objective, clinically valid, compatible with established principles of health care, or flexible enough to allow deviations from norms when justified case by case — the last of which is a direct constraint on rigid automated thresholds.

Md. Code, Insurance § 15-10B-07(a)(1)-(3) (same-specialty licensed physician, mental-health/substance-abuse and dental variants), § 15-10B-07(b) (compensation independence, cross-referencing Md. Code, Health – General § 19-705.1), § 15-10B-07(c)-(d) (retrospective adverse decisions barred, three exceptions), § 15-10B-07(e) (no mid-course revision of criteria); § 15-10B-11(8) (criteria objective, clinically valid, compatible with established principles, or flexible enough for justified case-by-case deviation)

Quarterly Adverse-Decision Report Must Flag AI Use and Aggregate by Zip Code — First AI/Zip Report Due 30 January 2026

Critical

R523 SPLIT AND CORRECTION: this reporting duty is § 15-10A-06, not § 15-10B-05.1, and its real contents are far more specific than "the number and outcome of all adverse decisions involving AI use". TWO 2025 ACTS AMENDED § 15-10A-06, both effective 1 October 2025 and both confirmed against the General Assembly's own records: HB 820, Chapter 747, and SB 474, Chapter 670. HB 820's contribution is at § 15-10A-06(a)(1)(iii)6 — for each adverse decision issued under § 15-10A-02(f) the carrier must report the type of service at issue, whether the decision involved a prior authorization or step therapy protocol, and WHETHER AN ARTIFICIAL INTELLIGENCE, ALGORITHM, OR OTHER SOFTWARE TOOL WAS USED IN MAKING THE ADVERSE DECISION. SB 474's contribution is the zip-code aggregation and a growth trigger. Per MIA Bulletin 25-15 (25 September 2025), which implements both: carriers report the TOP 5 ZIP CODES for adverse decisions and the top 5 for grievance decisions, ranked by the RATIO of adverse or grievance decisions to CLEAN CLAIMS in each zip code, with zip code determined by the location of the proposed or delivered treatment, service or item; for each such zip code the carrier reports the number of adverse decisions (or grievance decisions), the number of clean claims, and the calculated ratio expressed as a percentage. GROWTH TRIGGER, § 15-10A-06(a)(2): if the number of adverse decisions for a TYPE OF SERVICE has grown by 10% OR MORE in the immediately preceding calendar year, or 25% OR MORE over the immediately preceding 3 calendar years, the carrier must additionally report a description of any changes in medical management contributing to the rise, any other known reasons for the increase, and a description of the efforts and actions taken to determine the reason. HARD DATES from Bulletin 25-15: the updated reporting form must be used beginning with the quarterly report for the period 1 October 2025 to 31 December 2025, DUE 30 JANUARY 2026; for the report due 30 October 2025 (covering 1 July to 30 September 2025) carriers could continue to use the prior form, and were NOT required to supply the aggregated zip-code data or the AI data during the 1 October to 30 October 2025 online filing period. DOWNSTREAM: § 15-10A-06(b) requires the Commissioner to compile an annual summary report, report any violations or actions taken under § 15-10B-11, and provide copies to the Governor and the General Assembly; § 15-10A-06(c) lets the Commissioner use the reported information as the BASIS FOR AN EXAMINATION under Title 2, Subtitle 2 — so a carrier's own AI flags and zip-code ratios are the trigger for the market conduct action described in MIA Bulletin 24-11 Section 4.

Deadline: January 30, 2026

Md. Code, Insurance § 15-10A-06(a)(1)(iii)6 (AI/algorithm/software-tool flag on each adverse decision, added by HB 820, Ch. 747, Acts of 2025), § 15-10A-06(a)(1) (quarterly report aggregated by zip code as required by the Commissioner) and § 15-10A-06(a)(2) (10% one-year / 25% three-year growth trigger, added by SB 474, Ch. 670, Acts of 2025), § 15-10A-06(b) (Commissioner annual summary to Governor and General Assembly) and § 15-10A-06(c) (report as basis for a Title 2, Subtitle 2 examination); implemented by MIA Bulletin 25-15, 25 September 2025

Written AI Systems Program (AIS Program) — MIA Bulletin 24-11 Section 3

Critical

MIA Bulletin 24-11 Section 3 states that "all Carriers authorized to do business in this state are expected to develop, implement, and maintain a written program (an \"AIS Program\") for the responsible use of AI Systems that make, or support decisions related to regulated insurance practices", designed to mitigate the risk of Adverse Consumer Outcomes. The bulletin defines an Adverse Consumer Outcome as a decision by a Carrier that is subject to insurance regulatory standards enforced by the Administration and that adversely impacts the consumer IN A MANNER THAT VIOLATES THOSE STANDARDS — so the risk being managed is legal non-compliance, not consumer dissatisfaction generally. The General Guidelines (1.1 to 1.9) fix the program's shape: it must be designed to mitigate the risk of Adverse Consumer Outcomes (1.1); address governance, risk management controls, and internal audit functions (1.2); vest responsibility for development, implementation, monitoring and oversight, and for setting AI strategy, with SENIOR MANAGEMENT ACCOUNTABLE TO THE BOARD or an appropriate board committee (1.3); be tailored to and proportionate with the Carrier's use of and reliance on AI, with controls scoped to each use case in line with the Degree of Potential Harm to Consumers (1.4); optionally sit inside the existing Enterprise Risk Management program and may adopt or rely on a third-party standard framework, with the NIST AI Risk Management Framework, Version 1.0 named as the example (1.5); cover the AI System's use across the whole insurance life cycle — product development and design, marketing, use, underwriting, rating and pricing, case management, claim administration and payment, and fraud detection (1.6); cover all phases of the AI System life cycle — design, development, validation, implementation of both systems and business, use, on-going monitoring, updating and RETIREMENT (1.7); cover AI Systems used for regulated insurance practices whether developed by the Carrier OR A THIRD-PARTY VENDOR (1.8); and include processes providing notice to impacted consumers that AI Systems are in use (1.9, carried separately at md_ais_consumer_notice). The proportionality test in Section 3 is explicit about its five factors: the nature of the decisions being made, informed or supported; the type and Degree of Potential Harm to Consumers; THE EXTENT TO WHICH HUMANS ARE INVOLVED IN THE FINAL DECISION-MAKING PROCESS; the transparency and explainability of outcomes to the impacted consumer; and the extent and scope of reliance on third-party data, Predictive Models and AI Systems.

Deadline: April 22, 2024

MIA Bulletin No. 24-11, "The Use of Artificial Intelligence Systems in Insurance" (22 April 2024), Section 3 and AIS Program General Guidelines 1.0-1.9; authority enumerated in Section 1 as Title 27 of the Insurance Article and COMAR Title 31, Subtitle 15 (unfair trade practices), Title 27, Subtitle 3 (unfair claims settlement practices), Title 4, Subtitle 5 and COMAR 31.04.23 (Corporate Governance Annual Disclosure), Title 11, Subtitles 2 and 3 (P&C rating), and Insurance §§ 2-205 through 2-209 (market conduct)

Market Conduct Examination Readiness — The Document Set Bulletin 24-11 Section 4 Says Will Be Requested

Critical

Bulletin 24-11 Section 4 is the operative half for a compliance build, because it enumerates what the Administration will actually ask for, and it opens by stating that a Carrier can expect to be asked about its development, deployment and use of AI Systems "REGARDLESS OF THE EXISTENCE OR SCOPE OF A WRITTEN AIS PROGRAM" — declining to write a program removes the document, not the questions. Item 1.1 requires, as to the AIS Program: (a) the written AIS Program; (b) information and documentation evidencing its ADOPTION; (c) its scope, INCLUDING ANY AI SYSTEMS AND TECHNOLOGIES NOT INCLUDED IN OR ADDRESSED BY THE PROGRAM — an explicit demand for the exclusions list, which is the request most likely to be unanswerable if the program was written without an AI inventory; (d) how the program is tailored to and proportionate with the Carrier's use of and reliance on AI Systems, the risk of Adverse Consumer Outcomes, and the Degree of Potential Harm to Consumers; and (e) the policies, procedures, guidance, TRAINING MATERIALS and other information on adoption, implementation, maintenance, monitoring and oversight, broken out into processes for development, adoption or acquisition (identification of constraints and controls on automation and design; data governance and controls including lineage, quality, integrity, bias analysis and minimization, suitability, and Data Currency), processes for management and oversight of Predictive Models including the measurements, standards or THRESHOLDS adopted or used in development, validation and oversight, and protection of non-public information including unauthorized access to the Predictive Models themselves. Item 1.2 covers pre-acquisition/pre-use diligence, monitoring, oversight and auditing of third-party data or AI Systems. Item 1.3 covers evidence of IMPLEMENTATION AND COMPLIANCE, including monitoring and audit activities: (a) formation and ongoing operation of the coordinating bodies; (b) data practices and accountability procedures; (c) management and oversight of Predictive Models and AI Systems, comprising (i) the Carrier's INVENTORIES AND DESCRIPTIONS of Predictive Models and AI Systems used to make or support decisions that can result in Adverse Consumer Outcomes, and (ii) as to any specific model under investigation, (1) documentation of compliance with all applicable AI Program policies, protocols and procedures, (2) information about the data used including source, provenance, lineage, quality, integrity, bias analysis and minimization, suitability and Data Currency, and (3) information on the techniques, measurements, thresholds and similar controls used; and (d) documentation on validation, testing and auditing INCLUDING EVALUATION OF MODEL DRIFT, reflective of whether the system is built on Predictive Models or Generative AI. Section 4 closes by noting that market conduct work may use any of the continuum of actions in the NAIC's Market Regulation Handbook and MAY INVOLVE CONTRACTED SPECIALISTS with relevant subject matter expertise.

Deadline: April 22, 2024

MIA Bulletin No. 24-11 (22 April 2024), Section 4 items 1.1(a)-(e), 1.2, 1.3(a)-(d) and 2.1-2.4; statutory examination framework at Md. Code, Insurance §§ 2-205 through 2-209 as cited in the bulletin's Section 1 "Enforcement" bullet

Individual Clinical Information Requirement

High Priority

R523 CORRECTION — cited to § 15-10B-05.1, not § 15-10A-06, and split into the statute's own positive and negative limbs. POSITIVE LIMB, § 15-10B-05.1(c)(1): the tool must base its determinations on (i) an enrollee's medical or other clinical history; (ii) individual clinical circumstances as presented by a REQUESTING PROVIDER; or (iii) other relevant clinical information contained in the enrollee's medical or other clinical record. The three are alternatives, and limb (ii) is the one most often missed in build: information the treating provider puts forward is a lawful basis in its own right, which means the pipeline must actually ingest and weigh provider-submitted clinical narrative rather than only structured claims data. NEGATIVE LIMB, § 15-10B-05.1(c)(2): the tool "does not base its determinations SOLELY on a group dataset". Note the word solely — Maryland does not ban population-level models; it bans a determination that rests on nothing else. A cohort model used as one input alongside the enrollee's own record is inside the line; the same model used as the decision is outside it. THIRD LIMB, § 15-10B-05.1(c)(3): the criteria and guidelines used for making determinations with the tool must comply with the requirements of Title 15 — the AI does not get a separate, looser criteria standard than a human reviewer would.

Deadline: October 1, 2025

Md. Code, Insurance § 15-10B-05.1(c)(1), (c)(2) and (c)(3) (added by HB 820, Ch. 747, Acts of 2025, effective 1 Oct 2025)

Non-Discriminatory AI Application

High Priority

R523 CORRECTION — cited to § 15-10B-05.1 and stated in the statute's own two-part form, which is stronger than the "protected characteristics" paraphrase this requirement previously carried. § 15-10B-05.1(c)(5): the use of the tool must not RESULT IN unfair discrimination — an outcome test, not an intent test, so a facially neutral model that produces disparate determinations is caught regardless of what features it was given. § 15-10B-05.1(c)(6): the tool must be "fairly and equitably applied, including in accordance with any applicable regulations and guidance issued by the federal Department of Health and Human Services" — Maryland deliberately incorporates the moving federal standard by reference, so the compliance target is not frozen at the 2025 text and a monitoring duty attaches to HHS guidance. Read this together with the insurance-wide route: for the same carrier, discriminatory AI outcomes are ALSO reachable as an unfair trade practice under Title 27 and COMAR Title 31 Subtitle 15, which is the frame MIA Bulletin 24-11 uses, so a health carrier faces both the § 15-10B-05.1(c)(5) route and the Title 27 route on one set of facts.

Deadline: October 1, 2025

Md. Code, Insurance § 15-10B-05.1(c)(5) and (c)(6) (added by HB 820, Ch. 747, Acts of 2025, effective 1 Oct 2025); parallel insurance-wide route via Title 27 of the Insurance Article and COMAR Title 31, Subtitle 15, as applied to AI by MIA Bulletin 24-11 (22 Apr 2024), Section 1 "Legislative Authority" and Section 3

AI Use and Oversight Must Be Written Into the Filed Utilization Plan

High Priority

A filing duty, not merely an internal-policy duty, and it was unmodelled before R523. Md. Code, Insurance § 15-10B-05.1(c)(8) requires that written policies and procedures "are included in the utilization plan submitted under § 15-10B-05 of this subtitle, INCLUDING HOW an artificial intelligence, algorithm, or other software tool will be used and WHAT OVERSIGHT WILL BE PROVIDED". Two named contents, both of which have to be specific enough to be assessed: the manner of use, and the oversight arrangement. This converts what would otherwise be a private governance document into a regulator-facing filing, and it means a material change to how the tool is deployed is a change to the filed utilization plan rather than an internal decision. It also creates the cleanest documentary hook the Commissioner has: the filed plan is the benchmark against which actual operation is tested on examination, so a divergence between the filed description and the running system is itself the finding.

Deadline: October 1, 2025

Md. Code, Insurance § 15-10B-05.1(c)(8), requiring inclusion in the utilization plan submitted under § 15-10B-05 (added by HB 820, Ch. 747, Acts of 2025, effective 1 Oct 2025)

The Tool Itself Must Be Open to Commissioner Inspection, and the Agent Examined at Least Every Five Years

High Priority

Md. Code, Insurance § 15-10B-05.1(c)(7) requires that the artificial intelligence, algorithm, or other software tool "is open to inspection for audit or compliance reviews by the Commissioner". The object of inspection is the TOOL, not merely the records about it — a materially stronger position than a document-production duty, and one that a vendor contract must be drafted to permit, since a carrier cannot open for inspection something it has no contractual right to expose. That statutory access sits on top of a standing examination cycle: § 15-10B-19(a) requires the Commissioner to examine the affairs, transactions, accounts, records and assets of each private review agent AT LEAST ONCE EVERY FIVE YEARS, and § 15-10B-19(b) on application for a certificate of registration under § 15-10B-03; those examinations are conducted under § 2-207, paid for under § 2-208, and reported under § 2-209. § 2-209(a) expressly names § 15-10B-19 and § 15-10B-20 among the examinations for which a complete report must be made, and § 2-209(c) gives the examined person a copy of the proposed report at least 30 DAYS before adoption plus a right to a hearing if requested in writing within that window — so there is a defined, short opportunity to correct an AI finding before it becomes an adopted report admissible in evidence under § 2-209(d). Material obtained in such an examination is confidential and privileged under § 2-209(g), but § 2-209(g)(3) lets the Commissioner use it to further any regulatory or legal action, and § 2-209(h) permits sharing with the NAIC and other regulators.

Deadline: October 1, 2025

Md. Code, Insurance § 15-10B-05.1(c)(7) (tool open to inspection); § 15-10B-19(a)-(e) (private review agent examined at least once every 5 years and on application, under §§ 2-207, 2-208, 2-209); § 2-209(a), (c), (d), (g), (h) (examination report, 30-day pre-adoption copy and hearing right, evidentiary effect, confidentiality, regulator sharing)

Purpose Limitation on Patient Data, and a Standalone No-Harm Duty

High Priority

Two further limbs of § 15-10B-05.1(c) that were unmodelled before R523 and that do not reduce to the accuracy or non-discrimination duties. § 15-10B-05.1(c)(10): patient data "is not used beyond its intended and stated purpose, consistent with the federal Health Insurance Portability and Accountability Act of 1996, as applicable". The phrase INTENDED AND STATED purpose is doing more than a HIPAA cross-reference — it binds the use to the purpose the entity itself has stated, which in practice is the purpose set out in the filed utilization plan under § 15-10B-05.1(c)(8). The direct build consequence: reusing utilization-review data to train, tune, or evaluate a model is a use beyond the stated purpose unless that training use was itself stated. § 15-10B-05.1(c)(11): the tool "does not directly or INDIRECTLY cause harm to an enrollee". The word indirectly is the operative one — it reaches harm mediated by a provider's reliance on the tool, by a delay the tool induces upstream, or by a downstream care decision made on the tool's output, none of which a denial-centred control catches. Neither limb has a materiality qualifier or a de minimis threshold.

Deadline: October 1, 2025

Md. Code, Insurance § 15-10B-05.1(c)(10) (purpose limitation, consistent with HIPAA as applicable) and § 15-10B-05.1(c)(11) (no direct or indirect harm to an enrollee) (added by HB 820, Ch. 747, Acts of 2025, effective 1 Oct 2025)

AIS Program Governance Framework — Accountability Structure and Predictive Model Controls

High Priority

MIA Bulletin 24-11 guideline 2.0 expects the AIS Program to include a governance framework for the oversight of AI Systems that PRIORITIZES TRANSPARENCY, FAIRNESS AND ACCOUNTABILITY in design and implementation, "recognizing that proprietary and trade secret information must be protected" — the bulletin builds the trade-secret carve-out into the governance expectation itself rather than leaving it as a defence. A Carrier may adopt new internal governance structures or rely on existing ones, but should address: the policies, processes and procedures, including risk management and internal controls, to be followed at EACH STAGE of an AI System life cycle from proposed development to retirement (2.1); the requirements adopted to document compliance with the AIS Program, developed "with Section 4 in mind" — i.e. documentation should be built to survive the examination request list, not merely to satisfy an internal auditor (2.2); and the internal AI System governance ACCOUNTABILITY STRUCTURE (2.3), which the bulletin unpacks into five named items: (a) the formation of centralized, federated or otherwise constituted committees comprised of representatives from appropriate disciplines and units — business units, product specialists, actuarial, data science and analytics, underwriting, claims, compliance, and legal; (b) scope of responsibility and authority, chains of command, and decisional hierarchies; (c) the INDEPENDENCE of decision-makers and lines of defense at successive stages of the AI System life cycle; (d) monitoring, auditing, escalation and reporting protocols and requirements; and (e) development and implementation of ongoing training and supervision of personnel. Guideline 2.4 adds a Predictive-Model-specific governance duty: the Carrier's processes and procedures for designing, developing, verifying, deploying, using, updating and monitoring Predictive Models, INCLUDING a description of the methods used to detect and address errors, performance issues, outliers, or unfair discrimination in the insurance practices resulting from the model's use.

Deadline: April 22, 2024

MIA Bulletin No. 24-11 (22 April 2024), AIS Program Guidelines 2.0, 2.1, 2.2, 2.3(a)-(e) and 2.4

AIS Program Risk Management and Internal Controls — Model Inventory, Validation, Drift and Retention

High Priority

MIA Bulletin 24-11 guideline 3.0 expects the AIS Program to document the Carrier's risk identification, mitigation and management framework and internal controls for AI Systems generally AND AT EACH STAGE of the AI System life cycle, addressing six items. 3.1: the oversight and approval process for the development, adoption or acquisition of AI Systems, and the identification of CONSTRAINTS AND CONTROLS ON AUTOMATION and design to align and balance function with risk — the bulletin treats deliberate limits on automation as a control in their own right. 3.2: data practices and accountability procedures, including data currency, lineage, quality, integrity, BIAS ANALYSIS AND MINIMIZATION, and suitability. 3.3: management and oversight of Predictive Models (including the algorithms used therein), comprising (a) INVENTORIES AND DESCRIPTIONS of the Predictive Models, (b) detailed documentation of their development and use, and (c) assessments such as interpretability, repeatability, robustness, regular tuning, reproducibility, traceability, MODEL DRIFT, and the auditability of these measurements where appropriate. 3.4: validating, testing and RETESTING as necessary to assess the generalization of AI System outputs upon implementation, including the suitability of the data used to develop, train, validate and audit the model — and the bulletin describes what validation can look like: "comparing model performance on unseen data available at the time of model development to the performance observed on data post-implementation, measuring performance against expert review, or other methods". 3.5: protection of non-public information, particularly consumer information, INCLUDING UNAUTHORIZED ACCESS TO THE PREDICTIVE MODELS THEMSELVES — the model is treated as an asset to be protected, not only the data. 3.6: data and record retention, specifically for Predictive Models a narrative description of the model's intended goals and objectives and how the model is developed and validated to ensure that the AI Systems relying on it correctly and efficiently predict or implement those goals. Bulletin 24-11 defines Model Drift as "the decay of a model's performance over time arising from underlying changes such as the definitions, distributions, and/or statistical properties between the data used to train the model and the data on which it is deployed".

Deadline: April 22, 2024

MIA Bulletin No. 24-11 (22 April 2024), AIS Program Guidelines 3.0, 3.1, 3.2, 3.3(a)-(c), 3.4, 3.5 and 3.6; "Model Drift" and "Predictive Model" as defined in Section 2 of the bulletin

Third-Party AI Systems and Data — Diligence, Audit Rights, and Regulator-Cooperation Clauses

High Priority

MIA Bulletin 24-11 guideline 4.0 expects each AIS Program to address the Carrier's process for acquiring, using or relying on (i) third-party DATA used to develop AI Systems and (ii) AI SYSTEMS DEVELOPED BY A THIRD PARTY, which may include establishing standards, policies, procedures and protocols on three points. 4.1: due diligence and the methods employed to assess the third party and its data or AI Systems, to ensure that decisions made or supported by them that could lead to Adverse Consumer Outcomes "will meet the legal standards imposed on the Carrier itself" — the standard travels with the Carrier and cannot be contracted down to the vendor's own. 4.2: where appropriate and available, the inclusion of contract terms that (a) provide AUDIT RIGHTS and/or entitle the Carrier to receive audit reports by qualified auditing entities, and (b) require the third party to COOPERATE WITH THE CARRIER WITH REGARD TO REGULATORY INQUIRIES AND INVESTIGATIONS related to the Carrier's use of the third party's product or services. 4.3: the actual PERFORMANCE of those contractual rights — exercising the audit or other confirmation activities to confirm the third party's compliance with contractual and, where applicable, regulatory requirements. Guideline 4.3 is the one that converts 4.2 from a procurement checkbox into an operating duty: holding an unexercised audit right does not satisfy it. Bulletin 24-11 defines "Third Party" for its purposes as an organization other than the Carrier that provides services, data, or other resources related to AI. Section 4 then makes the vendor file examinable in its own right: item 1.2 covers pre-acquisition and pre-use diligence, monitoring, oversight and auditing of third-party data or AI Systems, and item 2 requires production of due diligence conducted on third parties (2.1), the CONTRACTS themselves including terms on representations, warranties, data security and privacy, data sourcing, intellectual property rights, confidentiality and disclosures, and cooperation with regulators (2.2), audits or confirmation processes performed (2.3), and validation, testing and auditing documentation including evaluation of Model Drift (2.4).

Deadline: April 22, 2024

MIA Bulletin No. 24-11 (22 April 2024), AIS Program Guidelines 4.0, 4.1, 4.2(a)-(b) and 4.3; Section 4 items 1.2 and 2.1-2.4 (third-party documentation producible on examination); "Third Party" as defined in Section 2

P&C Rating Law Applies Regardless of Methodology — AI-Derived Rates, Rating Rules and Rating Plans

High Priority

Bulletin 24-11 Section 1 cites Subtitles 2 and 3 of Title 11 of the Insurance Article for the proposition that property/casualty rates must not be excessive, inadequate, or unfairly discriminatory, and then states the point that matters for AI: "The requirements of Title 11 apply REGARDLESS OF THE METHODOLOGY that the Insurer used to develop rates, rating rules, and rating plans subject to those provisions. That means that a Carrier is responsible for assuring that rates, rating rules, and rating plans that are developed using AI techniques and Predictive Models that rely on data and Machine Learning do not result in excessive, inadequate, or unfairly discriminatory insurance rates" — with respect to all forms of CASUALTY insurance including fidelity, surety and guaranty bond, and all forms of PROPERTY insurance including fire, marine and inland marine, and any combination of the foregoing. The underlying standard, fetched this round: Md. Code, Insurance § 11-306(b)(1) — rates may not be excessive or inadequate as defined under the subtitle, or unfairly discriminatory. The definitions are tighter than the slogan suggests. Under § 11-306(b)(2) a rate may not generally be held excessive unless it is unreasonably high AND the Commissioner has ruled under § 11-308(c) that a reasonable degree of competition does not exist in the applicable market — but § 11-306(b)(4) carves out PERSONAL LINES property and casualty insurance, where the Commissioner may hold a rate excessive WITHOUT the competition finding if the rate is unreasonably high and "is not actuarially justified based on commonly accepted actuarial principles". That carve-out is the sharpest edge an AI-derived personal-lines rate faces: the defence has to be actuarial justification, and a model whose rate cannot be explained in commonly accepted actuarial terms has no answer to it. § 11-306(c) lists the factors due consideration must be given, and § 11-306(e)(1)-(3) permits risk classification and modification by rating plans measuring variations in hazard or expense, but only by standards measuring differences that "have had a direct and substantial effect on losses or expenses". Finally § 11-306(e)(4): "Notwithstanding any other provision of this subsection, a rate MAY NOT BE BASED WHOLLY OR PARTLY ON GEOGRAPHIC AREA ITSELF, as opposed to underlying risk considerations, EVEN THOUGH EXPRESSED IN GEOGRAPHIC TERMS" — a direct statutory bar on the commonest form of AI proxy discrimination, where a model learns location as a stand-in for something it may not price on. § 11-301 confirms by internal cross-reference that § 11-306 sits in the same subtitle as the competitive-market definitions.

Md. Code, Insurance § 11-306(b)(1)-(5) (rates not excessive, inadequate or unfairly discriminatory; personal-lines actuarial-justification carve-out at (b)(4)), § 11-306(c) (factors), § 11-306(e)(1)-(3) (classification and rating plans; direct and substantial effect on losses or expenses) and § 11-306(e)(4) (no rate based wholly or partly on geographic area itself, even though expressed in geographic terms); § 11-301 (subtitle definitions); Title 11, Subtitles 2 and 3 as cited by MIA Bulletin 24-11 Section 1

AI-Assisted Satellite and Aerial Imagery May Not Ground a Cancellation, Nonrenewal or Claim Denial Unless the Image Is Clear, Accurate and Current

High Priority

MIA Bulletin 25-10 (17 June 2025, Commissioner Marie Grant), addressed to insurers writing any line of property insurance and to the Joint Insurance Administration, is a post-24-11 AI instrument verified in full this round. It begins from a permissive premise — the use of satellite or aerial imagery "is not categorically prohibited under the Insurance Article", and physical inspection by alternative means "may not be necessary in all situations" — and then sets a hard quality gate: "it is the Administration's position that an insurer may use satellite or aerial imagery as a basis for cancellation, nonrenewal, or claim denial ONLY IF THE IMAGE PROVIDES A CLEAR, ACCURATE, AND CURRENT VIEW OF THE PROPERTY". Concrete applications: images that are LOW-RESOLUTION, OUT-OF-FOCUS, BLURRY, OR DATED do not accurately represent the condition of the property and cannot justify a cancellation or nonrenewal without further investigation; images of a roof showing streaking or discoloration may not be sufficient to independently support cancellation or nonrenewal based on roof degradation (the bulletin footnotes that streaking or discoloration is in some cases nothing more than a cosmetic blemish); and where imagery ALERTS an insurer to a possible problem WITHOUT UNEQUIVOCALLY ESTABLISHING IT, the insurer should conduct further investigation, the appropriate method depending on the circumstances. The legal routing is explicit: Title 27, Subtitle 6 governs cancellations and nonrenewals for authorized insurers, and §§ 27-604 and 27-605 require a statement of the ACTUAL REASON in clear and specific terms, with the Commissioner able to disallow a proposed action where the statement contains erroneous information and there is no sufficient basis absent it; on a contested action the insured is entitled to review the images and other material relied upon, and under § 27-501(g) the INSURER BEARS THE BURDEN OF PERSUASION that the contested action was justified; and Title 27, Subtitle 3 — which applies to BOTH AUTHORIZED AND SURPLUS LINES INSURERS — makes it an unfair claim settlement practice under § 27-303 to misrepresent pertinent facts relating to the claim or coverage or to refuse to pay a claim for an arbitrary or capricious reason based on all available information, so that "denying a claim based on satellite or aerial images that are unclear or imprecise constitutes an unfair claim settlement practice". THE AI LINK IS EXPRESS, in the bulletin's own words: "Insurers that use artificial intelligence programs to enhance, interpret, or otherwise review satellite or aerial images should be familiar with the requirements laid out in Bulletin 24-11 regarding the use of artificial intelligence systems in insurance." An AI vision pipeline over aerial imagery is therefore governed by BOTH instruments at once — the AIS Program duties above, and this image-quality and burden-of-persuasion gate.

Deadline: June 17, 2025

MIA Bulletin 25-10, "Cancellations, Nonrenewals, and Claim Denials Based on Satellite and Aerial Imagery" (17 June 2025), including its footnote 3 cross-reference to Bulletin 24-11; Md. Code, Insurance Title 27, Subtitle 6 and §§ 27-604 and 27-605 (statement of actual reason in clear and specific terms; Commissioner may disallow on erroneous information); § 27-501(g) (insurer bears the burden of persuasion on a contested cancellation or nonrenewal); Title 27, Subtitle 3 and § 27-303 (unfair claim settlement practices; applies to authorized and surplus lines insurers alike)

Quarterly Review and Revision of AI Performance, Use and Outcomes

Medium Priority

R523 CORRECTION AND SPLIT. This requirement previously bundled two duties that live in two different statutes and cited the wrong one for the reporting half. It now carries only the INTERNAL quarterly review duty, which is Md. Code, Insurance § 15-10B-05.1(c)(9): the performance, use, and outcomes of the artificial intelligence, algorithm, or other software tool must be "reviewed and revised, if necessary and at least on a quarterly basis, to maximize accuracy and reliability". Three things in that sentence do real work. First, it is REVIEW AND REVISE — a review that finds a defect and changes nothing does not discharge the duty; the revision limb is expressly part of it. Second, "at least on a quarterly basis" is a floor, not a schedule, so a tool with known drift needs a shorter cycle. Third, the stated objective is to MAXIMIZE ACCURACY AND RELIABILITY, which is what the review must be measured against — not merely to confirm the tool still runs. The separate duty to REPORT adverse decisions to the Commissioner is § 15-10A-06 and now lives in md_adverse_decision_ai_zip_reporting below. NOTE for anyone comparing against MIA Bulletin 24-11: the bulletin's AIS Program guideline 1.7 asks Carriers to address on-going monitoring, updating and retirement across the AI System life cycle, but it is an EXPECTATION with no cadence; § 15-10B-05.1(c)(9) is a statutory duty with a quarterly floor. For a health carrier the statute governs.

Deadline: October 1, 2025

Md. Code, Insurance § 15-10B-05.1(c)(9) (added by HB 820, Ch. 747, Acts of 2025, effective 1 Oct 2025)

Notice to Impacted Consumers That AI Systems Are in Use, With Life-Cycle-Appropriate Access to Information

Medium Priority

MIA Bulletin 24-11 AIS Program guideline 1.9 expects the AIS Program to "include processes and procedures providing notice to impacted consumers that AI Systems are in use and provide access to appropriate levels of information based on the PHASE OF THE INSURANCE LIFE CYCLE in which the AI Systems are being used". Two distinct obligations sit in that sentence and they should not be collapsed: a notice that AI is in use, and graduated ACCESS TO INFORMATION whose depth varies by life-cycle phase — so the disclosure owed at marketing is not the disclosure owed at claim denial. The bulletin does not prescribe wording, timing, or a channel, and its closing section states that Carriers may demonstrate compliance through practices that differ from those described. What gives the expectation teeth is the surrounding law it routes to: transparency and explainability are named in Section 1 as among the unique consumer risks AI presents, the Section 3 proportionality test lists "the transparency and explainability of outcomes to the impacted consumer" as one of the five factors setting how strong the controls must be, and a materially misleading account of how a decision was reached is reachable as an unfair or deceptive act under Title 27 of the Insurance Article and COMAR Title 31, Subtitle 15. HONEST CALIBRATION, because this is where a customer will otherwise over-read the entry: Maryland has NOT enacted a general statutory AI-disclosure duty for insurance. Guideline 1.9 is an expectation in a bulletin. The one place Maryland turns AI transparency into a hard statutory duty is the reporting flag at § 15-10A-06(a)(1)(iii)6 — and that runs to the Commissioner, not to the consumer.

Deadline: April 22, 2024

MIA Bulletin No. 24-11 (22 April 2024), AIS Program General Guideline 1.9; proportionality factor (iv) in Section 3 ("the transparency and explainability of outcomes to the impacted consumer"); routed to Title 27 of the Insurance Article and COMAR Title 31, Subtitle 15 per Section 1

Corporate Governance Annual Disclosure Must Cover AI Governance — Domestic Insurers, Filed by June 1

Medium Priority

Bulletin 24-11's Section 1 authority list states that the Corporate Governance Annual Disclosure Act at Title 4, Subtitle 5 of the Insurance Article requires Carriers to report on governance practices and to provide a summary of corporate governance structure, policies and practices, with content, form and filing requirements set out in COMAR 31.04.23, and that "the requirements of CGAD and CGAD-R APPLY TO ELEMENTS OF THE CARRIER'S CORPORATE GOVERNANCE FRAMEWORK THAT ADDRESS THE CARRIER'S USE OF AI SYSTEMS to support actions and decisions that impact consumers". This is the one place the bulletin attaches AI content to an existing FILING rather than to an internal control. The statute, fetched this round: Md. Code, Insurance § 4-503(a)(1) requires that NOT LATER THAN JUNE 1 EACH CALENDAR YEAR, beginning in 2020, an insurer — or the insurance group of which it is a member and for which Maryland is the lead state — submit a Corporate Governance Annual Disclosure in the form and containing the information required by regulation; § 4-503(a)(2) routes a non-lead-state insurer's filing to the lead state's commissioner under that state's laws. § 4-503(b) requires a SIGNATURE OF THE CHIEF EXECUTIVE OFFICER OR CORPORATE SECRETARY attesting, to the best of that individual's belief and knowledge, that the insurer has implemented a corporate governance structure, policies and practices AND that a copy of the CGAD has been provided to the board or the appropriate board committee — so a Maryland-domiciled insurer's AI governance narrative is personally attested and board-delivered, not merely filed. § 4-503(c) lets the Commissioner require a CGAD from an insurer not otherwise obliged to file. § 4-503(d) allows reporting at the ultimate controlling parent, intermediate holding company, or individual legal entity level, with the criteria used stated and any change explained. § 4-503(f) avoids duplication: substantially similar information already submitted in another filing need not be repeated, but must be CROSS-REFERENCED in the CGAD. CRITICAL SCOPE LIMIT THAT THE BULLETIN DOES NOT MENTION: § 4-502(a) provides that the requirements of Subtitle 5 apply ONLY TO INSURERS DOMICILED IN THIS STATE. A foreign carrier writing Maryland business is inside Bulletin 24-11 but outside the Maryland CGAD duty; its AI governance narrative belongs in its domiciliary state's CGAD.

Md. Code, Insurance § 4-503(a)(1)-(2) (CGAD not later than June 1 each calendar year), § 4-503(b) (CEO or corporate secretary attestation and board provision), § 4-503(c), (d), (f); § 4-502(a) (subtitle applies only to insurers domiciled in Maryland) and § 4-502(c) (no limit on the Commissioner's Title 2, Subtitle 2 authority); COMAR 31.04.23 (CGAD-R) as cited by MIA Bulletin 24-11 Section 1; applied to AI governance elements by that same Section 1 bullet

Who Does This Apply To?

THREE SURFACES, DIFFERENT SCOPES AND DIFFERENT LEGAL WEIGHT — the distinction is the point and must not be smoothed over. (A) MIA BULLETIN 24-11 (22 Apr 2024) reaches ALL Insurers, Nonprofit Health Service Plans, Health Maintenance Organizations and Dental Plan Organizations holding a Maryland certificate of authority, for AI Systems that make or support decisions related to regulated insurance practices anywhere in the insurance life cycle — product development and design, marketing, distribution, underwriting and pricing, policy servicing, claim management, and fraud detection. There is no premium-volume, headcount or revenue threshold; the trigger is the certificate of authority plus the use of an AI System. Its weight is a REGULATORY EXPECTATION, not a statute: the bulletin creates no new law, routes conduct into Title 27 and COMAR 31.15, Title 27 Subtitle 3, Title 4 Subtitle 5 and COMAR 31.04.23, Title 11 Subtitles 2 and 3, and Insurance §§ 2-205 through 2-209, and states in its own closing text that Carriers may demonstrate compliance "through practices that differ from those described in this bulletin" and that its goal "is not to prescribe specific practices or to prescribe specific documentation requirements". What it does prescribe with precision is the DOCUMENT SET the Administration will request in a market conduct action, which is Section 4 and is where compliance work should be aimed. (B) MIA BULLETIN 25-10 (17 Jun 2025) reaches insurers writing any line of property insurance and the Joint Insurance Administration, plus surplus lines insurers on the unfair-claim-settlement limb, wherever satellite or aerial imagery grounds a cancellation, nonrenewal or claim denial — and expressly directs insurers using AI to enhance, interpret or review such images to Bulletin 24-11. (C) HB 820 (Ch. 747, 2025) and SB 474 (Ch. 670, 2025), effective 1 Oct 2025, are STATUTE and bind absolutely. Md. Code, Insurance § 15-10B-05.1(b) reaches carriers — insurers, nonprofit health service plans, HMOs, dental plan organizations, and any other person providing State-regulated health benefit plans — that use an AI, algorithm or other software tool for utilization review OR contract with or work through an entity that does, and reaches PBMs and private review agents using such a tool on a carrier's behalf. In scope on this surface means: the tool may not deny, delay or modify health care services at all (§ 15-10B-05.1(d)); determinations must rest on the enrollee's own clinical history, the requesting provider's presentation of individual clinical circumstances, or the clinical record, and never solely on a group dataset; the tool must not replace the § 15-10B-07 reviewer, who must be a licensed physician (or panel including one) board certified or eligible IN THE SAME SPECIALTY as the treatment under review and knowledgeable through actual clinical experience, with mental-health/substance-abuse and dental variants; use must not result in unfair discrimination and must be fair and equitable including per applicable HHS regulations and guidance; the tool must be open to Commissioner inspection; AI use and oversight must be written into the filed utilization plan; performance, use and outcomes must be reviewed and revised at least quarterly; patient data must not be used beyond its intended and stated purpose; and the tool must not directly or indirectly harm an enrollee. Reporting is separate and statutory: § 15-10A-06 requires the quarterly adverse-decision report to flag whether an AI, algorithm or other software tool was used, with SB 474 zip-code aggregation, per MIA Bulletin 25-15. Scope on every surface is a FUNCTION and an AUTHORISATION, never company size.

Recent Regulatory Guidance

guidance2025-10

Maryland HB 820 (Ch. 747, 2025) — AI in Health Insurance Utilization Review; MIA Bulletin 25-15 reporting

Maryland HB 820 (Chapter 747; effective 1 Oct 2025) requires that AI tools used in utilization review support — never replace — licensed-clinician judgment in medical-necessity determinations, base determinations on the enrollee's individual medical history and clinical circumstances (not solely population-level data), and not deny, delay, or modify health care services. Implementing it, MIA Bulletin 25-15 (with SB 474) requires carriers to identify any use of AI/algorithms/software tools in adverse-decision reporting and to aggregate the data by zip code.

guidance2024-04

MIA Bulletin No. 24-11 — The Use of Artificial Intelligence Systems in Insurance (22 April 2024)

Maryland's adoption of the NAIC Model Bulletin, issued by Commissioner Kathleen A. Birrane to all Insurers, Nonprofit Health Service Plans, Health Maintenance Organizations and Dental Plan Organizations holding a Maryland certificate of authority. Section 1 sets the legislative authority: Title 27 of the Insurance Article and COMAR Title 31, Subtitle 15 (unfair trade practices); Title 27, Subtitle 3 (unfair claims settlement practices); the Corporate Governance Annual Disclosure Act at Title 4, Subtitle 5 and COMAR 31.04.23, whose requirements "apply to elements of the Carrier's corporate governance framework that address the Carrier's use of AI Systems"; Subtitles 2 and 3 of Title 11 (P&C rating), which "apply regardless of the methodology that the Insurer used to develop rates"; and Sections 2-205 through 2-209 (market conduct actions). Section 2 defines Adverse Consumer Outcome, Algorithm, AI System, Artificial Intelligence, Degree of Potential Harm to Consumers, Generative AI, Machine Learning, Model Drift, Predictive Model and Third Party. Section 3 expects every Carrier to develop, implement and maintain a written AIS Program, with guidelines 1.0-1.9 (general), 2.0-2.4 (governance), 3.0-3.6 (risk management and internal controls) and 4.0-4.3 (third-party AI and data). Section 4 enumerates the documents the Administration will request on investigation or market conduct action, "regardless of the existence or scope of a written AIS Program". Corroborated by the NAIC implementation map (status as of 1 April 2026): "Maryland: Bulletin No. 24-11 – Adopted April 22, 2024", one of 25 adopted jurisdictions.

guidance2025-06

MIA Bulletin 25-10 — Cancellations, Nonrenewals, and Claim Denials Based on Satellite and Aerial Imagery (17 June 2025)

Issued by Commissioner Marie Grant to insurers writing any line of property insurance and to the Joint Insurance Administration. Satellite or aerial imagery is not categorically prohibited, but may ground a cancellation, nonrenewal or claim denial ONLY if the image provides a clear, accurate and current view of the property; low-resolution, out-of-focus, blurry or dated images cannot, and roof streaking or discoloration may not independently support cancellation or nonrenewal for roof degradation. Routed to §§ 27-604 and 27-605 (statement of actual reason in clear and specific terms), § 27-501(g) (insurer bears the burden of persuasion on a contested action) and § 27-303 (denying a claim on unclear or imprecise images is an unfair claim settlement practice, reaching authorized and surplus lines insurers alike). Expressly directs insurers that "use artificial intelligence programs to enhance, interpret, or otherwise review satellite or aerial images" to Bulletin 24-11.

guidance2025-09

MIA Bulletin 25-15 — Updates to Carrier Reporting Form for Adverse Decisions and Grievances (25 September 2025)

Implements HB 820 (Ch. 747) and SB 474 (Ch. 670), both Acts of 2025 amending Md. Code, Insurance § 15-10A-06 effective 1 October 2025. HB 820 requires a carrier, when reporting the number of adverse decisions issued, to identify whether an artificial intelligence, algorithm, or other software tool was used in making the adverse decision. SB 474 requires the reported information to be aggregated by zip code: the top 5 zip codes for adverse decisions and the top 5 for grievance decisions, ranked by the ratio of adverse or grievance decisions to clean claims in each zip code, with zip code based on the location of the proposed or delivered treatment, service or item, reporting per zip code the number of adverse decisions (or grievance decisions), the number of clean claims, and the calculated ratio as a percentage. HARD DATES: the updated form must be used beginning with the quarterly report for 1 Oct 2025 to 31 Dec 2025, DUE 30 JANUARY 2026; carriers could use the prior form for the report due 30 October 2025 and were not required to supply the zip-code or AI data during the 1-30 October 2025 online filing period.

Key Case Law & Precedent

Lokken v. UnitedHealth Group (D. Minn., filed 2023)

US District Court, District of Minnesota · 2023

Class action alleging UnitedHealth's nH Predict AI system was used to deny Medicare Advantage coverage in violation of medical-necessity standards. An illustrative national example of the AI-driven benefits-denial failure pattern that Maryland HB 820's clinician-final-decision rule addresses — not independently confirmed as a case the Maryland Insurance Administration itself cites. Plaintiffs allege AI overrode clinician judgment in a large share of disputed claims.

Outcome: CYCLE 10 (2026-08-22) UPDATE: Judge John Tunheim's 2025-02-13 ruling PARTIALLY GRANTED UnitedHealth's motion to dismiss (unjust-enrichment and bad-faith-insurance claims dismissed on Medicare-preemption grounds, 5 of 7 counts; breach-of-contract and implied-covenant-of-good-faith claims allowed to proceed) and held UNH's internal appeal process was effectively "futile" for plaintiffs, waiving the exhaustion requirement. Web-verified this cycle (Tressler LLP, Live Insurance News, Whatley Kallas): in March 2026 a federal magistrate judge ordered UnitedHealth to disclose the nH Predict algorithm's specifications (6 of 7 discovery categories largely sided with plaintiffs) — a significant evidentiary win — and the case is now moving toward class certification as of this cycle, one of the most closely watched health-insurance AI cases in 2026. Not settled, not concluded.

Case reference

Frequently Asked Questions

Does Maryland Insurance AI Surface — MIA Bulletin 24-11, HB 820/SB 474 Utilization-Review AI (Ins. § 15-10B-05.1), and Bulletin 25-10 Imagery apply to my business?

Maryland regulates insurance AI on THREE stacked surfaces, and only the third is healthcare-specific. (1) MIA BULLETIN 24-11, "The Use of Artificial Intelligence Systems in Insurance", issued 22 April 2024 by Commissioner Kathleen A. Birrane to all… Use Aegis Firma's free scanner to get a personalized assessment in under 5 minutes.

What is the penalty for non-compliance?

The maximum penalty under Maryland Insurance AI Surface — MIA Bulletin 24-11, HB 820/SB 474 Utilization-Review AI (Ins. § 15-10B-05.1), and Bulletin 25-10 Imagery is: No AI-specific penalty schedule exists; exposure routes to the existing Insurance Article tracks (all fetched from mgaleg.maryland.gov this round): Md. Code, Insurance § 4-113(d) — instead of or in addition to suspending or revoking a certificate of authority, a penalty of not less than $100 but not more than $125,000 for EACH violation of the article, plus restitution to any person who suffered financial injury; § 27-305(a) — not exceeding $2,500 for each violation of § 27-303 (unfair claim settlement practices) and not exceeding $125,000 for each violation of § 27-303(9); § 15-10B-12(b)(4) — an administrative penalty of up to $5,000 for each violation of any provision of the private-review-agent subtitle (which is where § 15-10B-05.1 sits), alongside certificate denial/suspension/revocation, cease-and-desist, and patient restitution; § 15-10B-12(a) — misdemeanor, penalty not exceeding $1,000, each day a violation continues after the first conviction a separate offense; and § 1-301 — a willful violation of the article is a misdemeanor subject to a fine not exceeding $100,000.. Fines are typically scaled by company size, severity of violation, and whether violations were willful or accidental.

How do I comply with Maryland Insurance AI Surface — MIA Bulletin 24-11, HB 820/SB 474 Utilization-Review AI (Ins. § 15-10B-05.1), and Bulletin 25-10 Imagery?

The 19 requirements above cover the core obligations. The fastest path to compliance is: (1) conduct an AI risk assessment, (2) document your AI systems, (3) implement transparency disclosures where required. Aegis Firma generates all required documents automatically.

Official Source

https://mgaleg.maryland.gov/mgawebsite/legislation/details/hb0820?ys=2025RS

Last updated: 2026-08-26 — verify at source before relying on this information.

Don't leave compliance to chance

Aegis Firma scans your AI tools, tells you exactly which regulations apply, and generates all required documents — in 30 minutes.

Start your free compliance scan