A physician spends more hours each week on prior authorization paperwork than most people spend on an entire part-time job, and roughly a quarter are now seriously considering leaving clinical medicine over administrative burden alone.
The American Medical Association's most recent prior authorization survey found physicians complete an average of 39 prior authorizations weekly, spending roughly 13 hours on the process, and 89 percent say it contributes directly to burnout. That's one specific administrative task, in one part of the healthcare system, consuming time that was never spent treating a single patient.
Automation is a genuine, well-documented answer to a real share of this burden, and at the same moment, it's at the center of some of the most consequential healthcare litigation currently working through US courts, over AI systems allegedly denying patient care at scale with minimal human oversight. Both of these things are true simultaneously, and a serious look at automation in healthcare administration has to hold them together rather than picking the convenient half. This article covers where automation is genuinely reducing administrative burden with solid evidence behind it, where it's gone wrong badly enough to end up in federal court, and what separates the two outcomes.
The scale of the administrative burden automation is responding to
It's worth being specific about why healthcare administration has become such a visible automation target, because the scale of the underlying problem is unusual even by the standards of administratively heavy industries. MGMA's 2026 burden report found that 90 percent of practices reported prior authorization requirements increasing over the past year, with three of the top five administrative challenges tied directly to Medicare Advantage plans specifically, prior authorization, claim denials and automatic downcoding. Separate AMA data has found physicians spending an average workweek of nearly 58 hours, of which only about 27 are direct patient care, with the rest split between indirect patient-related work and administrative tasks including prior authorizations and insurance paperwork.
Documentation carries its own separate, well-documented burden. Research tracking physicians' after-hours electronic health record use, sometimes called pajama time, found that in 2024, 22.5 percent of physicians reported spending more than eight hours a week on EHR tasks outside regular work hours. Surveys on burnout causes consistently rank documentation and EHR burden alongside administrative tasks as the two leading drivers, and the downstream cost isn't limited to physician wellbeing. It shows up in patient access too, since physicians spending more time on paperwork have less time and attention for direct care, and a meaningful share report that prior authorization specifically has led to treatment delays or abandonment for their patients.
Where automation is genuinely reducing this burden
Ambient clinical documentation
This is the area with the strongest, most recent independent evidence behind it. A 2025 quality-improvement study published in JAMA Network Open, involving 263 ambulatory physicians and advanced practice practitioners, found that reported burnout fell from 51.9 percent to 38.8 percent after just 30 days of using an ambient AI scribe, a tool that listens to a patient visit and automatically drafts clinical documentation for the physician to review and finalize, rather than requiring manual note-taking during or after each appointment. A 13-percentage-point drop in reported burnout within a single month, from a peer-reviewed study rather than a vendor case study, is a genuinely strong signal that this specific category of automation addresses a real, measurable source of strain rather than simply shifting work around.
The mechanism here matters for understanding why it works: the tool automates the drafting of documentation, not the clinical decision itself, and a physician still reviews, edits and approves every note before it becomes part of the medical record. This human-in-the-loop structure is a meaningful part of why this category of automation has drawn far less controversy and litigation than the claims-processing automation discussed later in this article.
Prior authorization submission and tracking
While prior authorization as a process remains the single most cited administrative burden in healthcare, the submission and status-tracking side of it is increasingly automatable in ways that reduce staff time without changing the underlying clinical decision. Tools that auto-populate prior authorization forms from existing patient records, flag which specific procedures require authorization before a claim gets submitted, and track the status of pending requests across multiple payers reduce the purely clerical portion of a process that AMA data shows consumes roughly 13 hours of physician and staff time weekly. This doesn't eliminate prior authorization's underlying burden, which is largely a function of payer policy rather than administrative process, but it meaningfully reduces the manual, repetitive portion of handling it.
There's also a relevant regulatory shift worth noting here: as of January 1, 2026, impacted payers across Medicare Advantage, Medicaid and Marketplace plans are required to respond to prior authorization requests within 72 hours for expedited requests and seven calendar days for standard ones. This timeline pressure on payers creates a direct incentive for practices to have reliable, automated tracking in place, since a faster payer response window only helps if a practice's own system catches and acts on that response promptly.
Scheduling, intake and routine patient communication
Appointment scheduling, intake form collection, insurance eligibility verification and routine reminder communication represent some of the most well-established, least controversial automation applications in healthcare administration, largely because they don't touch clinical decision-making at all. Automated eligibility verification, in particular, addresses a specific, well-known source of billing friction: confirming a patient's coverage and benefits before a visit rather than discovering a coverage gap after service has already been delivered, which reduces both claim denials and the administrative work of chasing payment after the fact.
Billing and claims submission accuracy
On the provider side, rather than the payer side covered in the risks section below, automation that checks claims for coding errors and missing information before submission reduces the denial rate attributable to simple administrative mistakes, which is a different and considerably less controversial category than automation used by payers to make the actual coverage decision. Catching a missing modifier or mismatched code before a claim goes out saves the far more expensive, time-consuming process of appealing a denial after the fact.
Where it's gone wrong: the claims denial litigation
This is the part of the automation conversation that healthcare administrators can't responsibly skip, because it's currently playing out in federal court with specific, documented allegations rather than hypothetical concerns. UnitedHealth Group is defending a class action lawsuit alleging that it used an AI algorithm called nH Predict, acquired through its naviHealth subsidiary, to make coverage decisions for post-acute care in Medicare Advantage plans. The lawsuit alleges the algorithm had a high rate of error, citing a figure, often reported as around 90 percent, representing the share of challenged denials that were ultimately reversed on appeal, and alleges that coverage decisions were effectively being made by the algorithm rather than by the clinical staff the insurance contracts specified. A federal judge dismissed several counts in the case but allowed others to proceed, and in 2026 a magistrate ordered UnitedHealth to disclose how the algorithm actually works, a significant development since it represents one of the first real looks inside a denial system of this kind.
Cigna faces a separate, parallel case over a system called PxDx, which reporting and court filings describe as automatically flagging mismatches between diagnosis and procedure codes for denial, with physicians reportedly spending an average of roughly 1.2 seconds reviewing each flagged claim, reviewing hundreds of thousands of claims in batches over a period of months. Cigna has disputed characterizing PxDx as an AI or algorithmic system at all, describing it instead as simple code-matching technology that's been used for over a decade, but a California court rejected part of Cigna's defense in March 2025 and allowed bad-faith and unfair competition claims to proceed. Humana has faced similar allegations as well, making this a pattern across multiple major insurers rather than an isolated incident at one company.
The common thread across these cases isn't that automation itself is the problem. It's the specific allegation that genuine clinical judgment, the kind insurance contracts promise policyholders, was replaced by an automated process with minimal or token human review, applied at a scale and speed, batches of claims denied per second in some allegations, that makes individualized clinical consideration effectively impossible regardless of what a human reviewer's job title technically was.
What actually separates safe automation from litigation-prone automation
Looking across both the well-evidenced opportunities and the ongoing litigation, a consistent pattern emerges that's worth naming explicitly, since it's the single most useful distinction for anyone implementing automation in a healthcare administrative setting.
Genuine human review versus token human review. The ambient scribe study showed real burnout reduction specifically because a physician reviews and finalizes every note before it becomes part of the record, a real, substantive check on the automated output. The claims denial litigation alleges the opposite: a human nominally in the loop, reviewing a claim in roughly a second, which is not meaningfully different from no review at all. The legal and ethical weight of "a human reviewed it" depends entirely on whether that review was substantive, and courts are increasingly willing to look past the formal structure to ask that question directly.
Assisting a decision versus making the decision. Automation that drafts a note, flags a coding error, or tracks a pending request assists a human who remains the actual decision-maker. Automation that determines, by itself, how many days of care a patient qualifies for, with the human role reduced to rubber-stamping the output, has crossed into making the decision, and that's precisely the line the current litigation is testing.
Transparency and disclosure. Part of what makes the nH Predict and PxDx cases so consequential is the alleged lack of transparency to patients and physicians about how heavily an algorithm was driving the decision, and in the UnitedHealth case specifically, the court ordering disclosure of how the algorithm works at all. Automation implemented with clear, documented logic that can be explained and defended if challenged carries meaningfully less legal and reputational risk than a system whose internal workings are treated as proprietary and undisclosed even to the physicians and patients it affects.
Scale and speed as risk multipliers. A single questionable automated decision is a problem. The same flawed logic applied to hundreds of thousands of claims in a matter of weeks, which is what several of these lawsuits allege, turns a correctable error into a systemic one affecting a large, identifiable class of patients, which is exactly the fact pattern that makes a case viable as a class action in the first place.
Compliance and privacy considerations specific to healthcare automation
Beyond the claims-denial-specific risks covered above, any automation touching patient data in a US healthcare setting operates under HIPAA, which imposes requirements that general business automation tools often aren't built to satisfy out of the box. A consumer-grade AI tool that a staff member adopts informally to help draft a patient communication or summarize a chart, without going through a formal vetting process, can create a HIPAA exposure the moment protected health information passes through a system that was never evaluated for that purpose, regardless of how well-intentioned the staff member's use of it was.
This connects directly to the broader governance challenge covered in general AI adoption research: informal, unvetted tool use tends to outpace formal policy by a wide margin, and healthcare administration carries a materially higher stake than most other business functions when that gap goes unaddressed, since the data involved is both legally protected and often genuinely sensitive to the patients it describes. A specific, written policy naming which tools are approved for which categories of patient data, reviewed against HIPAA's business associate agreement requirements before adoption rather than after, is a baseline necessity here in a way that's less universally true for general business automation.
Practical guidance for implementing automation responsibly
Start with the categories that have strong independent evidence and minimal controversy. Ambient documentation, scheduling, eligibility verification and claims accuracy checking all have real, peer-reviewed or well-documented evidence behind them and don't carry the same legal exposure as automated coverage decisions, making them a sensible starting point for any practice or organization new to healthcare automation.
Treat any automation touching a coverage or clinical decision with disproportionate scrutiny. Given the specific, ongoing litigation covered above, any system that influences whether a patient receives or continues to receive care deserves a meaningfully higher bar for human review, transparency and documented logic than a scheduling tool or a documentation assistant, regardless of how much efficiency the automated version promises.
Build genuine, substantive human review into any decision-adjacent system, and be able to demonstrate it. The distinction between real and token review is exactly what courts are currently scrutinizing in the ongoing cases, which means the practical test isn't whether a human technically touches the process, but whether that human has the time, information and authority to meaningfully change the outcome, and whether your organization could document that review was substantive if ever asked to.
Vet any tool touching patient data against HIPAA requirements before adoption, not after. This includes confirming a business associate agreement is in place where required and that the vendor's data handling practices have been genuinely reviewed, rather than assuming a tool is compliant because it's marketed toward healthcare use.
Expect continued regulatory and legal attention to this specific area, and build with that in mind. Given the active litigation, the court-ordered algorithm disclosure in the UnitedHealth case, and the new CMS prior authorization response-time requirements taking effect in 2026, automation touching coverage or clinical decisions is an area where the regulatory and legal landscape is actively shifting, which argues for conservative, well-documented implementation over aggressive automation that assumes today's lighter scrutiny will persist.
Common mistakes worth avoiding
Treating all healthcare automation as equally risky, or equally safe. Lumping an ambient documentation tool in with an automated coverage-denial system, either by over-restricting the former out of excessive caution or under-scrutinizing the latter by assuming it's just as benign, misses the genuinely important distinction between assisting a human decision and replacing it.
Letting staff adopt consumer AI tools informally for tasks touching patient data. This is the most common and most avoidable source of HIPAA exposure in healthcare automation, and it happens not through malice but through the same ordinary efficiency-seeking behavior documented across every industry's shadow AI research, applied here to data with considerably higher legal stakes.
Confusing the presence of a human reviewer with the presence of genuine review. A formal sign-off step that takes a fraction of a second to complete, as alleged in some of the current litigation, provides the appearance of oversight without its substance, and that gap is precisely what's being tested in court right now.
Assuming vendor claims about accuracy or compliance without independent verification. Given that several of the systems currently facing litigation were implemented by major, sophisticated organizations with substantial legal and compliance resources, a smaller practice or administrator should not assume that a vendor's marketing claims about accuracy or regulatory compliance are sufficient without independent scrutiny appropriate to the stakes involved.
Moving too fast on decision-adjacent automation because the efficiency gain looks compelling. The efficiency case for automating prior authorization submission or documentation is genuinely strong and well-evidenced. The efficiency case for automating the actual coverage decision is exactly where the current legal risk concentrates, and conflating the two categories' risk profiles because they both involve "AI in healthcare administration" is a costly category error.
Frequently Asked Questions
No, and the distinction matters. Ambient scribes assist a physician in drafting documentation that the physician then reviews and finalizes, with the clinical judgment remaining entirely human. The systems facing litigation are alleged to have made or effectively driven coverage decisions with minimal genuine human review, which is a fundamentally different risk category.
HIPAA's core requirements, a business associate agreement where required, appropriate safeguards for protected health information, apply to any system handling patient data regardless of whether it's described as AI. The practical risk is that AI tools are often adopted informally and quickly, outside the usual vetting process other healthcare software goes through, which creates exposure not because the rules are different but because the usual compliance process gets skipped.
That figure, as reported in connection with the lawsuit, refers to the share of challenged denials that were ultimately reversed on appeal, not an independently audited error rate across all claims the algorithm processed. It's a significant and widely cited figure, but it's worth understanding precisely what it measures rather than treating it as a general accuracy statistic for the system.
Not always. Cigna has specifically disputed describing its PxDx system as AI or algorithmic, characterizing it instead as rules-based code-matching technology. Regardless of the precise technical label, the legal and ethical questions at stake, whether genuine individualized review occurred, apply to any automated system making or substantially driving a coverage decision.
Starting with categories that have independent, peer-reviewed or well-documented evidence and that assist rather than replace human judgment, documentation support, scheduling, eligibility verification, claims accuracy checks, while applying far greater scrutiny, documentation and genuine human review to anything touching a coverage or clinical decision, given the active litigation and regulatory attention currently focused on exactly that category.



