Skip to content
Ceci est une traduction de commodite. La version anglaise est la version officielle et juridiquement contraignante. Voir la version anglaise
US-VAMEDIUM coverage

Virginia Consumer Data Protection Act (VCDPA) — Automated Decision-Making: AI Compliance Requirements

Virginia's Consumer Data Protection Act (Va. Code § 59.1-575 et seq.), effective January 1, 2023, includes automated decision-making opt-out rights and data protection assessment requirements. Consumers have the right to opt out of processing for profiling in furtherance of decisions that produce legal or similarly significant effects — including employment decisions, credit decisions, and housing decisions. Controllers must conduct and document Data Protection Assessments (DPAs) before processing for automated decision-making. Threshold: applies to businesses that process data of 100,000+ Virginia consumers annually, or 25,000+ consumers and derive 50%+ revenue from data processing. Enforcement by Virginia AG — no private right of action; the 30-day cure period is PERMANENT (no sunset, unlike Colorado/Connecticut — CYCLE 5, 2026-08-22 verified this cycle via multiple sources including recordinglaw.com and privacylawmap.com). Civil penalties up to $7,500 per violation (Va. Code § 59.1-584). R522 (2026-08-26) BROADENED THIS ENTRY BEYOND THE VCDPA: Virginia also regulates AI through its INSURANCE regulator and its utilization-review code, and neither surface was represented here before. Bureau of Insurance Administrative Letter 2024-01 (22 July 2024, Commissioner Scott A. White) adopts the NAIC Model AI Bulletin shape and expects every licensed Insurer to maintain a written AIS Program — with Virginia's own stiffening: the Program should be designed to ELIMINATE (not merely mitigate) the risk of Adverse Consumer Outcomes, the Bureau strongly encourages verification and bias-testing methods, and § 1.9 expects notice to affected consumers that AI Systems are in use. Separately, HB 481 (2026 Acts of Assembly ch. 925) put a licensed-physician reservation over prior-authorization DENIALS — already in force for prescription drugs under Va. Code § 38.2-3407.15:2(E), extending to health care services on 1 January 2027 under § 38.2-3407.15:8(E) — which is the hard ceiling on autonomous AI utilization review in the Commonwealth. The entry key and name remain VCDPA-worded for registry-stability reasons (display names and 10 locale message files key off `virginia_vcdpa_ai`); the scope is what is written here, not what the key implies.

Summary of publicly-available regulatory text as of 2026-08-26. Verify against current official sources before relying on this for compliance decisions. Not legal advice.

Key Facts

Effective Date

January 1, 2023

Maximum Penalty

Two separate tracks, deliberately not merged: VCDPA — $7,500 per violation, Virginia AG enforcement (Va. Code § 59.1-584), no private right of action. INSURANCE (Title 38.2, the track AL 2024-01 and HB 481 run on) — not more than $5,000 for each KNOWING OR WILLFUL violation and not more than $1,000 for each violation without knowledge or intent subject to a $10,000 aggregate (Va. Code § 38.2-218(A), (B)), plus Commission-ordered restitution of direct actual financial loss (§ 38.2-218(D)(1)) and cease-and-desist proceedings (§ 38.2-219), imposable in addition to or without any other penalty provided by law (§ 38.2-218(E)).

What Your Business Must Do

12 compliance requirements identified. Critical requirements carry the highest risk of enforcement action.

Automated Decision-Making Opt-Out

High Priority

Under VCDPA § 59.1-577(A)(5), provide Virginia consumers with the right to opt out of processing for profiling in furtherance of automated decisions that produce legal or similarly significant effects (employment, credit, housing, education). Publish a clear opt-out mechanism in your privacy notice.

Deadline: January 1, 2023

Va. Code § 59.1-577(A)(5)

Data Protection Assessment (DPA)

High Priority

VCDPA § 59.1-580 requires controllers to conduct and document Data Protection Assessments before processing for targeted advertising, sale of personal data, profiling presenting a foreseeable risk of harm, sensitive-data processing, or other heightened-risk activity — including automated decision-making with significant effect on consumers. Retain assessments and provide them to the Virginia AG on written request (assessments are confidential and exempt from FOIA disclosure).

Va. Code § 59.1-580

VA Bureau of Insurance AL 2024-01 — Written AIS Program (governance, risk management, internal audit)

High Priority

On July 22, 2024 the Virginia Bureau of Insurance issued Administrative Letter 2024-01 to "All Companies Licensed to Conduct the Business of Insurance in Virginia and All Interested Parties", reminding Insurers that decisions, conduct, or actions impacting consumers that are made or supported by advanced analytical and computational technologies, including AI Systems, must comply with all applicable insurance laws and regulations — including those addressing unfair trade practices, unfair claim settlement practices, and unfair discrimination. All Insurers are expected to develop, implement, and maintain a WRITTEN program (an "AIS Program") for the responsible use of AI Systems that make or support decisions, conduct, and actions of the Insurer. Virginia's General Guidelines depart from the NAIC model text in a way that matters and should not be paraphrased away: § 1.1 states the AIS Program "should be designed to ELIMINATE the risk that the Insurer's use of an AI System will result in Adverse Consumer Outcomes" — eliminate, not mitigate — and Section 3 likewise directs Insurers to adopt controls "designed to understand and eliminate the risk of Adverse Consumer Outcomes". The Program should address governance, risk management controls, and internal audit functions (§ 1.2); vest responsibility for its development, implementation, monitoring, and oversight, and for setting the Insurer's AI strategy, with senior management accountable to the Board of Directors or an appropriate Board committee (§ 1.3); be tailored to and proportionate with the Insurer's use of and reliance on AI, with the scope of controls for a given use case reflecting and aligning with the Degree of Potential Harm to Consumers (§ 1.4); may be independent of or part of the Insurer's existing Enterprise Risk Management program and may adopt or rely on a third-party standard framework such as the NIST AI Risk Management Framework (§ 1.5); address AI use across the insurance life cycle including product development and design, marketing, use, underwriting, rating and pricing, case management, claim administration and payment, and fraud detection (§ 1.6); address all phases of an AI System life cycle including design, development, validation, implementation (both systems and business), use, ongoing monitoring and testing, updating and retirement (§ 1.7); and address AI Systems used with respect to regulated insurance practices whether developed by the Insurer or by a Third-Party vendor (§ 1.8). The letter defines the terms it operates on — "AI System", "Artificial Intelligence (AI)", "Algorithm", "Predictive Model", "Machine Learning (ML)", "Generative Artificial Intelligence", "Model Drift", "Third Party", and crucially "Adverse Consumer Outcome" (a decision by an Insurer that adversely impacts the consumer in a manner that violates applicable law or regulation) and "Degree of Potential Harm to Consumers" (the severity of adverse economic impact a consumer might experience as a result of an Adverse Consumer Outcome). The Bureau also recognizes the NAIC Principles on Artificial Intelligence adopted in 2020 as an appropriate source of guidance, emphasizing fairness and ethical use, accountability, compliance with state laws, transparency, and a safe, secure, fair and robust system.

Deadline: July 22, 2024

Virginia Bureau of Insurance Administrative Letter 2024-01, "The Use of Artificial Intelligence Systems" (July 22, 2024), Sections 1-3. Legislative Authority AS ENUMERATED BY THE LETTER ITSELF on page 2: unfair trade practices — Chapter 5 of Title 38.2 of the Code of Virginia; unfair claim settlement practices — Va. Code § 38.2-510 and 14 VAC 5-400; unfair discrimination — Va. Code §§ 38.2-508, 38.2-508.1 and 38.2-508.2; corporate governance — Article 5.2 of Chapter 13 of Title 38.2 and 14 VAC 5-265; rating — the Rating Laws in Title 38.2 of the Code and Title 14 of the Virginia Administrative Code; market conduct — Va. Code §§ 38.2-200, 38.2-515, 38.2-1317.1 and 38.2-1317.2. Penalty routing at Va. Code §§ 38.2-218 and 38.2-219.

VA AL 2024-01 § 2.0 / § 3.0 — AI Governance Framework, Risk Controls and Predictive Model Management

High Priority

Section 2.0 requires the AIS Program to include a governance framework for oversight of AI Systems that prioritizes transparency, fairness, and accountability in the design and implementation of AI Systems while recognizing that proprietary and trade secret information must be protected. An Insurer may adopt new internal governance structures or rely on existing ones, but the framework must address: the policies, processes, and procedures, including risk management and internal controls, to be followed at each stage of an AI System life cycle from proposed development to retirement (§ 2.1); the requirements the Insurer adopts to DOCUMENT compliance with the AIS Program policies, processes, procedures and standards, developed with Section 4 of the Letter in mind (§ 2.2); and the internal AI System governance accountability structure (§ 2.3), including the formation of centralized, federated or otherwise constituted committees comprising representatives from business units, product specialists, actuarial, data science and analytics, underwriting, claims, compliance and legal; scope of responsibility and authority, chains of command and decisional hierarchies; the INDEPENDENCE of decision-makers and lines of defense at successive stages of the AI System life cycle; monitoring, auditing, escalation and reporting protocols; and ongoing training and supervision of personnel. Section 2.4 adds a Predictive-Model-specific duty: processes and procedures for designing, developing, verifying, deploying, using, updating and monitoring Predictive Models, including a description of the methods used to detect and address errors, performance issues, outliers, bias, or unfair discrimination in the insurance practices resulting from the use of the Predictive Model. Section 3.0 requires the Program to document the Insurer's risk identification, mitigation and management framework and internal controls for AI Systems generally and at each life-cycle stage, addressing: the oversight and approval process for development, adoption or acquisition of AI Systems and identification of constraints and controls on automation and design (§ 3.1); data practices and accountability procedures including data currency, lineage, quality, integrity, bias analysis and minimization, and suitability (§ 3.2); management and oversight of Predictive Models including inventories and descriptions, detailed development-and-use documentation, and assessments of interpretability, repeatability, robustness, regular tuning, reproducibility, traceability, model drift and auditability (§ 3.3); validating, testing and RETESTING as necessary to assess the generalization of AI System outputs upon implementation — validation may take the form of comparing model performance on unseen data available at the time of model development to performance observed on data post-implementation, or measuring performance against expert review (§ 3.4); protection of nonpublic information, particularly personal information and privileged information, including unauthorized access to the Predictive Models themselves (§ 3.5); data and record retention (§ 3.6); and a narrative description of the model's intended goals and objectives and how the model is developed and validated to ensure the AI Systems relying on it correctly and efficiently predict or implement those goals (§ 3.7).

Deadline: July 22, 2024

Virginia Bureau of Insurance Administrative Letter 2024-01 §§ 2.0-2.4 (Governance) and §§ 3.0-3.7 (Risk Management and Internal Controls); corporate-governance authority as cited by the Letter at Article 5.2 of Chapter 13 of Title 38.2 (Va. Code §§ 38.2-1334.11 to 38.2-1334.17) and 14 VAC 5-265; unfair discrimination authority at Va. Code §§ 38.2-508, 38.2-508.1, 38.2-508.2

VA AL 2024-01 § 4.0 — Third-Party AI Systems and Data: Due Diligence, Audit Rights, Regulator Cooperation

High Priority

Section 4.0 requires each AIS Program to address the Insurer's process for acquiring, using, or relying on (i) Third-Party DATA used to develop AI Systems and (ii) AI SYSTEMS developed by a Third Party, which may include establishing standards, policies, procedures and protocols for three things. First, § 4.1 — due diligence and the methods the Insurer employs to assess the Third Party and its data or AI Systems acquired from the Third Party, to ensure that decisions made or supported by such AI Systems that could lead to Adverse Consumer Outcomes will meet the legal requirements imposed on the INSURER ITSELF; the compliance standard travels with the Insurer and is not delegated away with the model. Second, § 4.2 — where appropriate and available, the inclusion of contract terms that (a) provide audit rights and/or entitle the Insurer to receive audit reports by qualified auditing entities, and (b) require the Third Party to COOPERATE WITH THE INSURER with regard to regulatory inquiries and investigations related to the Insurer's use of the Third Party's product or services. Third, § 4.3 — the actual PERFORMANCE of those contractual audit rights and other activities to confirm the Third Party's compliance with contractual and, where applicable, regulatory requirements; holding the right is not enough, the Letter expects it to be exercised. Section 4 of the examination guidance (item 2) then mirrors this on the production side: where a rate filing, investigation, or examination concerns data, Predictive Models, or AI Systems collected or developed in whole or in part by Third Parties, the Insurer should expect the Bureau to request the due diligence conducted on Third Parties and their data, models or AI Systems; the CONTRACTS with Third-Party AI System, model, or data vendors including terms on representations, warranties, data security and privacy, data sourcing, intellectual property rights, confidentiality and disclosures, and cooperation with regulators; audits and/or confirmation processes performed regarding Third-Party compliance; and documentation of validation, testing and auditing including evaluation of Model Drift.

Deadline: July 22, 2024

Virginia Bureau of Insurance Administrative Letter 2024-01 §§ 4.0-4.3 (Third-Party AI Systems and Data) and Section 4 item 2 (Third-Party production expectations); market conduct authority as cited by the Letter at Va. Code §§ 38.2-200, 38.2-515, 38.2-1317.1 and 38.2-1317.2

VA AL 2024-01 Section 4 — Examination and Market Conduct Production Readiness

High Priority

Section 4 of Administrative Letter 2024-01 tells Insurers what the Bureau may demand and when. Its operative warning is that REGARDLESS of the existence or scope of a written AIS Program, in the context of a rate filing, examination, investigation, inquiry, or market conduct action, an Insurer can expect to be asked about its development, deployment, and use of AI Systems, or any specific Predictive Model, AI System or application and its outcomes (including Adverse Consumer Outcomes), as well as any other information or documentation deemed relevant by the Bureau — so the absence of a Program is not a shelter, it simply means the Insurer answers the same questions with worse evidence. The enumerated production list under item 1 covers: information and documentation relating to or evidencing the AIS Program, including (a) the written AIS Program, (b) documentation evidencing its ADOPTION, (c) the Program's scope including any AI Systems and technologies NOT included in or addressed by it, (d) how the Program is tailored to and proportionate with the Insurer's use of and reliance on AI Systems, the risk of Adverse Consumer Outcomes, and the Degree of Potential Harm to Consumers, and (e) the policies, procedures, guidance, TRAINING MATERIALS and other information relating to adoption, implementation, maintenance, monitoring and oversight — including processes for development, adoption or acquisition of AI Systems (identification of constraints and controls on automation and design; data governance and controls covering data lineage, quality, integrity, bias analysis and minimization, suitability, and Data Currency), processes for management and oversight of Predictive Models including the measurements, standards or thresholds adopted or used in development, validation and oversight, and protection of nonpublic information including unauthorized access to Predictive Models themselves (§ 1.1). Item 1.2 covers pre-acquisition/pre-use diligence, monitoring, oversight and auditing of Third-Party data or AI Systems. Item 1.3 covers documentation evidencing IMPLEMENTATION and compliance, including monitoring and audit activities: formation and ongoing operation of the Insurer's coordinating bodies for AI development, use and oversight; data practices and accountability procedures; inventories and descriptions of Predictive Models and AI Systems used to make or support decisions that can result in Adverse Consumer Outcomes; and, as to any specific model under investigation, documentation of compliance with applicable AI Program policies, information about the data used including source, provenance, lineage, quality, integrity, bias analysis and minimization, suitability and Data Currency, and information on techniques, measurements, thresholds and similar controls — plus documentation of validation, testing and auditing including evaluation of MODEL DRIFT, with the Letter noting that the nature of validation, testing and auditing should reflect the underlying components of the AI System, whether Predictive Models or Generative AI. The Letter closes by recognising that Insurers may demonstrate compliance through alternative means and practices differing from those it describes, stating that its goal is not to prescribe specific practices or documentation requirements but to ensure Insurers are aware of the Bureau's expectations and of what it expects to be produced on request; and that examinations, investigations and market conduct actions may be performed using procedures varying in nature, extent and timing in accordance with regulatory judgment, may follow the continuum of market actions described in the NAIC Market Regulation Handbook, and may involve contracted specialists with relevant subject matter expertise.

Deadline: July 22, 2024

Virginia Bureau of Insurance Administrative Letter 2024-01 Section 4 (Regulatory Oversight and Examination Considerations), items 1.1-1.3 and 2.1-2.4; examination and market conduct authority as cited by the Letter at Va. Code §§ 38.2-200 (powers of the Commission), 38.2-515 (power of Commission — Chapter 5 examinations and information gathering), 38.2-1317.1 and 38.2-1317.2

Prior Authorization Denials Must Be Approved by a Licensed Physician (HB 481, 2026 c. 925) — Ceiling on Autonomous AI Denial

High Priority

Virginia enacted a licensed-clinician reservation over prior-authorization denials in 2026, and it is the hard legal ceiling on any AI utilization-review deployment in the Commonwealth. HB 481 (2026 Regular Session), "relating to prior authorization; requiring physician review for denial", became Acts of Assembly Chapter 925. IN FORCE NOW: Va. Code § 38.2-3407.15:2 (the version law.lis.virginia.gov captions "Effective until January 1, 2027", whose citation line ends "2026, c. 925") provides at subsection E that "No carrier shall make an adverse determination, as defined in § 38.2-3556, of a prior authorization request for prescription drugs unless such adverse determination has been reviewed and approved by a licensed physician or, if a licensed physician is not available, a licensed pharmacist." FROM 1 JANUARY 2027 the regime splits and BROADENS: the successor § 38.2-3407.15:2 ("Effective January 1, 2027", carrier contracts; required provisions regarding prior authorization for DRUG BENEFITS, citation line "2026, cc. 213, 925") carries the same prescription-drug reservation at subsection E, while the new § 38.2-3407.15:8 ("Effective January 1, 2027", carrier contracts; required provisions regarding prior authorization for HEALTH CARE SERVICES, citation line "2026, cc. 881, 925, 1055") extends it to services generally at subsection E: "No carrier shall make an adverse determination, as defined in § 38.2-3556, of a prior authorization request for health care services unless such adverse determination has been reviewed and approved by (i) a licensed physician; (ii) in the case of mental health services, a licensed mental health provider if a licensed physician is unavailable; or (iii) in the case of dental services, a licensed dentist if a licensed physician is unavailable." COMPLIANCE READING: an AI System may triage, flag, summarise, or recommend, but it cannot BE the adverse determination — a named licensed human must review and approve the denial. Approvals are untouched; the reservation runs only to adverse determinations. AGGREGATOR TRAP CLEARED THIS ROUND: a web search surfaced three 2026 Virginia bills on AI in insurance and framed them as having been "pushed through by the end of the session". Checking each against the Legislative Information System's own records rather than the summary: HB 481 alone was enacted (status "Acts of Assembly Chapter", CHAP0925); SB 500 (prior-authorization denial reasons in plain language plus disclosure of any AI-based tools used in reviewing the request) has LIS status FAILED; and SB 586 (requiring health carriers to disclose to the Bureau of Insurance how AI is used to manage claims coverage, to submit the information enabling AI decisions on request, and to notify enrollees and providers when AI has been used to issue an adverse determination) has LIS status CONTINUED — passed the Senate but carried over, NOT law. Do NOT record SB 500 or SB 586 as Virginia obligations.

Deadline: January 1, 2027

Va. Code § 38.2-3407.15:2(E) (Effective until January 1, 2027 — prescription drugs) and § 38.2-3407.15:2(E) (Effective January 1, 2027 — drug benefits); Va. Code § 38.2-3407.15:8(E) (Effective January 1, 2027 — health care services); "adverse determination" as defined in Va. Code § 38.2-3556; enacted by HB 481, 2026 Acts of Assembly ch. 925

Privacy Notice — Automated Processing Disclosure

Medium Priority

Under VCDPA § 59.1-578, provide a reasonably accessible, clear, and meaningful privacy notice disclosing (1) categories of personal data processed, including for automated decision-making, (2) the purpose for processing, (3) how consumers may exercise their § 59.1-577 rights including the opt-out, and (4) categories of personal data shared with third parties.

Deadline: January 1, 2023

Va. Code § 59.1-578

SB 854 — Minors' Social Media Age-Assurance + Time-Limit Amendment (ENJOINED, not currently enforceable)

Medium Priority

Virginia SB 854 (signed by Gov. Youngkin 2025-05-02, amending the VCDPA, effective 2026-01-01) requires social media platforms to deploy "commercially reasonable methods" — neutral age-screening mechanisms, which may include algorithmic/AI-based age-estimation, not mere self-reported age — to determine whether a user is under 16, and if so to limit platform use to one hour per day absent verifiable parental consent to adjust the limit. On 2026-02-27, a federal court (E.D. Va.) granted a PRELIMINARY INJUNCTION blocking enforcement of the time-limit/age-determination provisions while litigation proceeds, notwithstanding the Virginia AG's 2026-02-18 announcement of intent to fully enforce. As of this cycle, the underlying VCDPA data-protection-assessment and opt-out duties above are unaffected and remain in force; only SB 854's minors-specific time-limit regime is currently enjoined. Do not treat SB 854's time-limit duty as currently enforceable; monitor the litigation.

Deadline: January 1, 2026

Va. Code § 59.1 (VCDPA, as amended by SB 854, 2025)

VA AL 2024-01 § 1.9 — Consumer Notice That AI Systems Are In Use, plus Verification and Bias Testing

Medium Priority

Section 1.9 of Administrative Letter 2024-01 states that the AIS Program "should include processes and procedures providing NOTICE to affected consumers that AI Systems are in use and provide access to appropriate levels of information based on the phase of the insurance life cycle in which the AI Systems are being used." This is a consumer-facing transparency expectation distinct from the internal governance duties, and it is one of the points on which Virginia's letter is more demanding than a bare adoption of the model text. It pairs with Section 3 of the Letter, in which the Bureau "strongly encourages the development and use of VERIFICATION AND TESTING METHODS to identify errors and bias in Predictive Models and AI Systems, as well as the potential for unfair discrimination in the decisions and outcomes resulting from the use of Predictive Models and AI Systems." Read together with § 2.4 (methods used to detect and address errors, performance issues, outliers, bias, or unfair discrimination) and § 3.2 (bias analysis and minimization), the practical output is a documented bias-and-error testing regime whose results the Insurer can produce, plus consumer-facing disclosure calibrated to the life-cycle phase — marketing and distribution, underwriting and rating, or claim administration. HONEST SCOPE NOTE, so this is not over-read: § 1.9 is expressed in the Letter's "should" register and is an expectation of the Bureau under existing law, NOT a free-standing statutory notice mandate with its own penalty; Virginia has no enacted insurance statute compelling AI-use notice to consumers as of this round (the 2026 bill that would have created one, SB 586, was CONTINUED rather than passed — see va_prior_auth_physician_review below). Its enforceable edge comes from the unfair-trade-practice and unfair-claim-settlement provisions the Letter cites, not from § 1.9 standing alone.

Deadline: July 22, 2024

Virginia Bureau of Insurance Administrative Letter 2024-01 § 1.9 (notice to affected consumers), Section 3 introductory text (verification and testing methods), § 2.4 and § 3.2 (bias detection and minimization); underlying authority as cited by the Letter at Chapter 5 of Title 38.2 (unfair trade practices) and Va. Code § 38.2-510 with 14 VAC 5-400 (unfair claim settlement practices)

Virginia Corporate Governance Annual Disclosure (CGAD) — AI Governance Elements, Filed by June 1

Medium Priority

Administrative Letter 2024-01 does not leave corporate governance as an abstraction: its Legislative Authority section states that Insurers "are required to report on governance practices and provide a summary of the Insurer's corporate governance structure, policies, and practices pursuant to the requirements of Article 5.2 of Chapter 13 of Title 38.2 of the Code and 14 VAC 5-265", and that "[t]hese requirements apply to elements of the Insurer's corporate governance framework that address the Insurer's use of AI Systems to support actions and decisions that impact consumers." So the AI-governance framework built under §§ 1.3 and 2.0-2.3 of the Letter is not merely examinable on request — to the extent it forms part of the corporate governance framework, it is reportable in the Insurer's annual CGAD filing. Article 5.2 comprises Va. Code § 38.2-1334.11 (definitions), § 38.2-1334.12 (disclosure requirement), § 38.2-1334.13 (contents of the Corporate Governance Annual Disclosure), § 38.2-1334.14 (confidentiality), § 38.2-1334.15 (NAIC and third-party consultants), § 38.2-1334.16 (rules and regulations), and § 38.2-1334.17 (sanctions). The filing is due "no later than June 1 of each calendar year" under § 38.2-1334.12. Practical consequence for an Insurer standing up an AIS Program: the senior-management-accountable-to-the-Board structure required by § 1.3 of the Letter, the cross-functional committee structure of § 2.3(a), and the chains of command and decisional hierarchies of § 2.3(b) are the elements most likely to require CGAD narrative, and they should be drafted once, consistently, for both audiences.

Va. Code §§ 38.2-1334.11 to 38.2-1334.17 (Article 5.2 of Chapter 13 of Title 38.2, Corporate Governance Annual Disclosure); 14 VAC 5-265; applied to AI governance by Virginia Bureau of Insurance Administrative Letter 2024-01, page 2, "Corporate Governance"

Virginia Utilization Review Standards — Good-Faith Information Gathering, Physician-Advisor Access, and Peer Reconsideration

Medium Priority

Virginia's general utilization-review code sits in Title 32.1 (health), not Title 38.2, and it constrains automated adverse determinations in three concrete ways that an AI utilization-review deployment must be built around. First, Va. Code § 32.1-137.13(B) provides that no entity shall render an adverse determination unless it has made a GOOD FAITH ATTEMPT TO OBTAIN INFORMATION from the provider — a model that decides on the record it happens to hold, without that attempt, produces a defective determination regardless of how accurate the model is. Second, § 32.1-137.13(B) entitles the provider, at any time BEFORE the entity renders its determination, to review the issue of medical necessity with a physician advisor or peer of the treating health care provider who represents the entity — so a human clinical channel must exist and be reachable on the way in, not only on appeal. Third, § 32.1-137.14(A) provides that a determination on RECONSIDERATION shall be made by a physician advisor, peer of the treating health care provider, or a panel of other appropriate health care providers with at least one physician advisor or peer of the treating health care provider on the panel — reconsideration cannot be automated. "Peer of the treating health care provider" is defined in § 32.1-137.7 as a physician or other health care professional who holds a nonrestricted license in the Commonwealth of Virginia in the same or similar specialty; "utilization review" is "a system for reviewing the necessity, appropriateness and efficiency of hospital, medical or other health care services". Notification timing: the treating provider must be notified in writing of any adverse determination within TWO WORKING DAYS of the determination, and orally by telephone within 24 HOURS for a prescription known to be for the alleviation of cancer pain, with the notice carrying instructions for seeking reconsideration under § 32.1-137.14 and appeal under § 32.1-137.15 (§ 32.1-137.13(A)); any reconsideration must be rendered and provided in writing to the treating provider and the covered person within 10 WORKING DAYS of receipt of the request (§ 32.1-137.14(C)); and if a peer review is requested during reconsideration, the request for reconsideration is vacated and treated as an appeal (§ 32.1-137.14(B)). HONEST CALIBRATION, because this is where Virginia differs from Illinois and Massachusetts and the difference should not be smoothed over: Title 32.1 does NOT reserve the INITIAL adverse determination to a clinician across the board. The only initial-determination physician reservation in § 32.1-137.13 is narrow — for an adverse determination relating to a prescription known to be for the alleviation of cancer pain, a physician advisor must review the issue of medical necessity with the treating provider. The broad initial-determination reservation for Virginia arrives instead through the insurance code, via HB 481 (see va_prior_auth_physician_review above), which is why both requirements are needed and neither is redundant.

Va. Code §§ 32.1-137.7 (definitions — "adverse determination", "peer of the treating health care provider", "utilization review"), 32.1-137.13 (adverse determination; good-faith information gathering; physician-advisor access; notice within two working days / 24 hours for cancer pain), 32.1-137.14 (reconsideration by physician advisor, peer, or panel; 10 working days), 32.1-137.15 (appeal), 32.1-137.16 (records), 32.1-137.17 (limitation on Commissioner's jurisdiction); Article 1.2 of Chapter 5 of Title 32.1

Who Does This Apply To?

Applies to businesses subject to the Virginia Consumer Data Protection Act — those that, in a calendar year, control or process personal data of 100,000+ Virginia consumers, OR of 25,000+ consumers while deriving 50%+ of gross revenue from the sale of personal data — that process personal data for profiling in furtherance of automated decisions with legal or similarly significant effects (employment, credit, housing, education). In scope means: provide a consumer opt-out of such profiling (Va. Code § 59.1-577(A)(5)); conduct and retain a Data Protection Assessment before that processing (§ 59.1-580), available to the AG on request; and disclose the automated processing in the privacy notice (§ 59.1-578). Enforced by the Virginia Attorney General (no private right of action, § 59.1-584); civil penalties up to $7,500 per violation; the 30-day cure period is PERMANENT — it has NO sunset date, unlike Colorado (expired 2025-01-01) or Connecticut (eliminated 2025-01-01). CYCLE 5 (2026-08-22): corrected two pervasive citation-number transpositions (§ 59.1-576 → § 59.1-577 for opt-out; § 59.1-578 → § 59.1-580 for the assessment duty, with § 59.1-578 itself reassigned to its real subject, the privacy-notice duty) plus a fabricated cure-period-sunset claim — see requirement-level notes and deadlineCalendar below. Scope turns on the VCDPA thresholds, not on company sector. R522 (2026-08-26) ADDED TWO FURTHER SCOPE GATES that do NOT turn on the VCDPA thresholds and reach businesses the VCDPA never touches. (A) INSURANCE — Bureau of Insurance Administrative Letter 2024-01 is addressed to "All Companies Licensed to Conduct the Business of Insurance in Virginia and All Interested Parties" and carries NO premium, asset, or employee threshold: the licence is the trigger. In scope means maintain a written AIS Program covering governance, risk management controls and internal audit, with senior management accountable to the Board (§§ 1.1-1.8, 2.0-2.4, 3.0-3.7); notify affected consumers that AI Systems are in use (§ 1.9); conduct third-party due diligence and obtain audit and regulator-cooperation terms (§§ 4.0-4.3); report AI-governance elements in the annual CGAD by June 1 (Va. Code §§ 38.2-1334.11 to 38.2-1334.17, 14 VAC 5-265); and be able to produce the Section 4 documentation set on demand in any rate filing, examination, investigation, inquiry or market conduct action — expressly "[r]egardless of the existence or scope of a written AIS Program". The Letter is guidance under existing law and creates no new penalty; exposure routes through the authorities it cites (Chapter 5 of Title 38.2; § 38.2-510 with 14 VAC 5-400; §§ 38.2-508, 38.2-508.1, 38.2-508.2; the Rating Laws; §§ 38.2-200, 38.2-515, 38.2-1317.1, 38.2-1317.2) to Va. Code §§ 38.2-218 and 38.2-219. (B) UTILIZATION REVIEW — carriers and their UR vendors face a licensed-clinician ceiling on adverse determinations: Va. Code § 38.2-3407.15:2(E) already forbids a prior-authorization adverse determination for prescription drugs unless reviewed and approved by a licensed physician (or a licensed pharmacist if no physician is available), and from 1 January 2027 § 38.2-3407.15:8(E) extends the same reservation to health care services with mental-health-provider and dentist fallbacks — both enacted by HB 481, 2026 Acts of Assembly ch. 925. Virginia's general UR standards in Title 32.1, Chapter 5, Article 1.2 (§§ 32.1-137.7 to 32.1-137.17) add a good-faith information-gathering precondition, a pre-determination physician-advisor/peer channel for the treating provider, and a rule that RECONSIDERATION must be decided by a physician advisor, peer of the treating provider, or a panel including one — but, honestly stated, Title 32.1 does NOT broadly reserve the INITIAL determination to a clinician (its only such reservation is for prescriptions to alleviate cancer pain), which is precisely why the HB 481 insurance-code route matters.

Recent Regulatory Guidance

guidance2024-07-22

Virginia Bureau of Insurance — Administrative Letter 2024-01, "The Use of Artificial Intelligence Systems"

Issued 22 July 2024 by Commissioner of Insurance Scott A. White to all companies licensed to conduct the business of insurance in Virginia and all interested parties. Adopts the NAIC Model AI Bulletin structure — definitions (AI System, Predictive Model, Machine Learning, Generative AI, Algorithm, Model Drift, Adverse Consumer Outcome, Degree of Potential Harm to Consumers, Third Party); a written AIS Program built on governance, risk management and internal controls, and third-party oversight; and a Section 4 catalogue of what the Bureau may request in a rate filing, examination, investigation, inquiry or market conduct action. Virginia-specific stiffening versus the model text: the Program should be designed to ELIMINATE rather than mitigate the risk of Adverse Consumer Outcomes (§ 1.1 and Section 3); the Bureau strongly encourages development and use of verification and testing methods to identify errors and bias in Predictive Models and AI Systems; and § 1.9 expects processes providing notice to affected consumers that AI Systems are in use, with access to information appropriate to the life-cycle phase. Legislative authority as the Letter itself enumerates it: Chapter 5 of Title 38.2 (unfair trade practices); § 38.2-510 and 14 VAC 5-400 (unfair claim settlement practices); §§ 38.2-508, 38.2-508.1, 38.2-508.2 (unfair discrimination); Article 5.2 of Chapter 13 of Title 38.2 and 14 VAC 5-265 (corporate governance); the Rating Laws in Title 38.2 and Title 14 VAC; and §§ 38.2-200, 38.2-515, 38.2-1317.1, 38.2-1317.2 (market conduct). Questions are directed to the Bureau's Division of Innovative Solutions & Strategies.

guidance2023-02

Virginia AG — Consumer Data Protection Act Summary (published 2023-02-02)

The Virginia Attorney General's Office published an official plain-language summary of the VCDPA covering consumer rights (access, correction, deletion, portability, opt-out of targeted advertising/sale/significant-effect profiling), controller obligations (privacy notice, data protection assessments for heightened-risk processing), and the AG's exclusive enforcement authority with a 30-day cure period and up to $7,500-per-violation civil penalties.

Industry Playbooks covering Virginia Consumer Data Protection Act (VCDPA) — Automated Decision-Making

These industry playbooks include jurisdiction-specific checklist items and guidance for Virginia Consumer Data Protection Act (VCDPA) — Automated Decision-Making.

Frequently Asked Questions

Does Virginia Consumer Data Protection Act (VCDPA) — Automated Decision-Making apply to my business?

Virginia's Consumer Data Protection Act (Va. Code § 59.1-575 et seq.), effective January 1, 2023, includes automated decision-making opt-out rights and data protection assessment requirements. Consumers have the right to opt out of processing for… Use Aegis Firma's free scanner to get a personalized assessment in under 5 minutes.

What is the penalty for non-compliance?

The maximum penalty under Virginia Consumer Data Protection Act (VCDPA) — Automated Decision-Making is: Two separate tracks, deliberately not merged: VCDPA — $7,500 per violation, Virginia AG enforcement (Va. Code § 59.1-584), no private right of action. INSURANCE (Title 38.2, the track AL 2024-01 and HB 481 run on) — not more than $5,000 for each KNOWING OR WILLFUL violation and not more than $1,000 for each violation without knowledge or intent subject to a $10,000 aggregate (Va. Code § 38.2-218(A), (B)), plus Commission-ordered restitution of direct actual financial loss (§ 38.2-218(D)(1)) and cease-and-desist proceedings (§ 38.2-219), imposable in addition to or without any other penalty provided by law (§ 38.2-218(E)).. Fines are typically scaled by company size, severity of violation, and whether violations were willful or accidental.

How do I comply with Virginia Consumer Data Protection Act (VCDPA) — Automated Decision-Making?

The 12 requirements above cover the core obligations. The fastest path to compliance is: (1) conduct an AI risk assessment, (2) document your AI systems, (3) implement transparency disclosures where required. Aegis Firma generates all required documents automatically.

Official Source

https://law.lis.virginia.gov/vacodefull/title59.1/chapter53/

Last updated: 2026-08-26 — verify at source before relying on this information.

Don't leave compliance to chance

Aegis Firma scans your AI tools, tells you exactly which regulations apply, and generates all required documents — in 30 minutes.

Start your free compliance scan