Medicare's WISeR AI-assisted prior-authorization vendors denied 5,944 requests in three months, FOIA lawsuit revealed
Under CMS's WISeR model, private vendors use AI and machine-learning tools to screen prior-authorization requests for some Original Medicare procedures. The model began January 1, 2026 in Arizona, New Jersey, Ohio, Oklahoma, Texas and Washington. The Electronic Frontier Foundation sued after CMS missed deadlines on its Freedom of Information Act request. Files released through that case showed two vendors denied or non-affirmed 5,944 requests in the first three months. One request was still unanswered after 83 days, a figure that covers the whole process, including steps outside the vendor's control. Washington's vendor, Virtix Health, initially rejected more requests than it approved. CMS placed it under a corrective action plan for delays. Vendors can collect up to 20% of savings from avoided care, while CMS requires a human clinician to review every non-affirmation.
What the AI did
Private vendors used AI and machine-learning tools to read medical files and to sort and assess prior-authorization requests for certain Original Medicare procedures. Prior authorization means approval sought before a procedure is booked. A human clinician must review every non-affirmation. It has not been reported which AI tools were used or what part they played in the 5,944 denials.
First reported October 1, 2026 · Added to the register October 7, 2026 · 1 source
- Deployer
- Virtix Health
- Country
- United States
- When it happened
- January 1, 2026
- First reported
- October 1, 2026
What this means for you
Could this affect you?
Original Medicare patients in the six WISeR states seeking procedures such as epidural steroid injections, cervical fusion, nerve stimulators, knee procedures and skin substitutes, and the providers treating them, are exposed to AI-assisted denials and delays.
What to check
- Get the tracking number and the non-affirmation notice for every request.
- Resubmit denied requests with the missing records.
- Request peer-to-peer or expedited review where health is at risk.
- Monitor denial rates, turnaround times and vendor incentives if you use AI in coverage decisions.
Areas of your AI programme this touches
Timeline
- January 1, 2026Happened
- October 1, 2026First reported
Every fact and its source (9)
- WISeR model start2026-01-01“began January 1, 2026 and is scheduled to run through 2031”[1]
- FOIA request that led to the lawsuitEFF FOIA request filed January 29, 2026“The Electronic Frontier Foundation filed a Freedom of Information Act request on January 29, 2026.”[1]
- Regulator responseCMS corrective action plan for Virtix Health“CMS put it under a corrective action plan for delays.”[1]
- Corrective action plan end, per vendorAugust 14“the plan ended August 14”[1]
- Vendor incentiveUp to 20% of savings“vendors can collect as much as 20% of associated savings”[1]
- Human review requirementHuman clinician reviews every non-affirmation“CMS requires a human clinician with relevant expertise to review every non-affirmation.”[1]
- Potential population in scopeAbout 6.4 million Original Medicare enrollees“potentially affecting roughly 6.4 million people with Original Medicare”[1]
- Requests denied or non-affirmed in first three months5,944“5,944 prior-authorization requests during the first three months”[1]
- Longest unanswered request in released records83 days“one request was still unanswered after 83 days”[1]
Sources
- His Back Injection Entered Original Medicare's New AI Review. It Took a Lawsuit to Reveal 5,944 Denials and an 83-Day Wait247wallst.com · October 1, 2026
How this record is classified. Severity S (4/5): real harm to one organisation, data exposed, or a containment failure. OECD level: incident, an event in which an AI system led to actual harm. Evidence: Reported, meaning press reporting only.
The facts in At a glance and in Every fact and its source are quoted from the sources listed. The summary, What the AI did and What this means for you are written from those sources and checked against them automatically before publication. Records reflect what has been disclosed, not everything that has happened. Incidents are found through news feeds and the GDELT Project.

