Indiana: AI health laws
2 entries on the map: 2 in force.
Payer and utilization review AI
Insurers', benefit managers' and utilization reviewers' use of AI, including prior authorization and claim denials.
HB 1271, Payment of Health Claims (House Enrolled Act 1271, Public Law 88-2026)
Bars an insurer from using an automated process, system or tool, including AI, as the sole basis to downcode a claim based on medical necessity without an employee or contractor reviewing the covered individual's medical record, requires insurers to disclose in an easily accessible and readable manner when AI is used to make an adverse prior authorization determination or to downcode a claim, and bars providers from using such tools to submit a claim without review by a provider or other person involved in developing it.
Physician read. From July 1, 2026, a physician or practice may not use an automated process, system or tool, including AI, to submit a claim under a state-regulated accident and sickness policy, HMO contract or dental preferred provider plan (Medicaid is excluded) without review by a provider or other person involved in developing the claim. Those insurers may not use such a tool as the sole basis to downcode a claim on medical necessity grounds unless an employee or contractor reviews the patient's medical record, must notify the provider of each downcode with claim adjustment and remittance codes, the reason and clinical criteria and the original and revised codes and payments, must allow at least 180 days to appeal, and must disclose when AI is used to make an adverse determination on a prior authorization request or to downcode a claim.
Notes: iga.in.gov bill pages need JavaScript and the enrolled act could not be opened there, so status, dates and text come from LegiScan's bill page and its copy of the enrolled act. SECTION 6 of the act adds the AI rules as a new chapter, IC 27-1-52 (Downcoding of Health Benefits Claims), with the effective-date line July 1, 2026; the chapter does not apply to the Medicaid program or Medicaid managed care organizations (IC 27-1-52-0.3) and directs the Department of Insurance to adopt rules. The provider rule is IC 27-1-52-9(b); a health benefits claim is a claim a provider submits for payment under a health plan as the chapter defines it. The act also limits retroactive rate reductions, sets time frames for claim audits and overpayment recovery, and requires hospital payment-assistance notices. The chapter does not say to whom the insurer's AI disclosure must be made.
Patient disclosure of AI use
Telling patients that AI is used in their care or in messages to them.
Also relevant here: HB 1271, Payment of Health Claims (House Enrolled Act 1271, Public Law 88-2026) (under payer and utilization review AI).
Clinical decision and chatbot limits
Limits on AI in clinical decisions and on health chatbots, including AI presenting itself as a licensed professional.
Nothing in this category was found in the review of Sept 29, 2026.
Mental health AI
AI in therapy and mental health care.
Nothing in this category was found in the review of Sept 29, 2026.
Data and privacy
Health and consumer data, biometrics, and data used to train AI.
SB 5, Consumer Data Protection (Senate Enrolled Act 5, Public Law 94-2023), IC 24-15
Gives Indiana consumers rights to confirm, correct, delete and obtain a copy of their personal data and to opt out of targeted advertising, sale and profiling in furtherance of decisions with legal or similarly significant effects, requires consent to process sensitive data, including a mental or physical health diagnosis made by a health care provider and biometric data, and requires data protection impact assessments, enforced by the attorney general after a 30-day cure period with civil penalties of up to $7,500 per violation.
Physician read. It places no duty on practices that are HIPAA covered entities, and protected health information is exempt. Since Jan. 1, 2026, health apps and other businesses outside HIPAA that meet the thresholds must get consent before processing a health diagnosis or biometric data and must honor opt-outs from consequential profiling.
Notes: Provisions were read in the 2026 edition of IC 24-15 on iga.in.gov; the history note for IC 24-15-1-1 (applicability and exemptions) shows one amendment since enactment, by P.L.236-2025. IC 24-15-1-1 exempts any covered entity or business associate governed by the HIPAA privacy, security and breach notification rules as an entity. The act defines sensitive data to include a mental or physical health diagnosis made by a health care provider, genetic or biometric data processed to identify a person, a known child's data and precise geolocation. The Jan. 1, 2026 start date is given by LegiScan and the attorney general's guide.
Federal law also applies in every state: see federal law and policy.
Most recently checked Sept 29, 2026. General information, not legal advice. How the map works, and the data.