AI agents in healthcare administration
Where provider and payer agents already meet, the prior authorization and scheduling tasks they could settle, and the US and Canadian rules that apply.
Healthcare administration is the paperwork between providers, payers, pharmacies, labs and patients: checking eligibility, requesting prior authorization, chasing claim status, and booking appointments. Much of it already runs on mandated data standards. The rest often runs on portals, fax and phone calls. Agents fit in two places: as users of the regulated standards, and as the conversational layer for everything those standards leave out, such as a pended request that needs one more document.
This page covers where those exchanges happen today, the tasks agents could settle directly, and the US and Canadian rules that shape them.
Where agents meet today
United States
HIPAA Administrative Simplification makes specific electronic formats mandatory for covered transactions. CMS lists the adopted standards:
| Transaction | Adopted standard |
|---|---|
| Eligibility and benefit verification | ASC X12N 270/271, version 5010 |
| Prior authorization and referrals | ASC X12N 278, version 5010 |
| Claim status inquiry and response | ASC X12N 276/277, version 5010 |
| Retail pharmacy drug claims | NCPDP D.0 |
HL7 FHIR is the second layer. The CMS Interoperability and Prior Authorization final rule (CMS-0057-F) requires impacted payers to run a Prior Authorization API, a Provider Access API and a Payer-to-Payer API, and to update their Patient Access API, by 1 January 2027. The HL7 Da Vinci guides describe how: Coverage Requirements Discovery (CRD) tells the provider whether an order needs authorization, Documentation Templates and Rules (DTR) collects the documentation, and Prior Authorization Support (PAS) submits the request and checks its status. The PAS guide is built to map to the X12 278 through an intermediary that converts FHIR to X12 when needed.
An agent working for a provider would use these as tools. Agent-to-agent messaging would carry what they don’t: questions, pended requests, missing attachments and scheduling.
Canada
Canada has no national payer rule like CMS-0057-F. Public drug programs are run by the provinces, and private plans run their own approval processes. Ontario’s Exceptional Access Program is a typical public example: authorized prescribers request coverage for drugs outside the formulary through the SADIE online portal, by fax, through a telephone request service, or by mail.
Top use cases
| Use case | Who talks to whom | What the exchange replaces |
|---|---|---|
| Prior authorization | Provider agent and payer agent | Portal checks, fax follow-ups and status calls around a request |
| Pharmacy refills and lab scheduling | Patient agent and pharmacy or lab agent | Phone calls to request a refill or book a draw |
| Appointment booking | Patient agent and clinic agent | Phone tag and web forms for slots, changes and cancellations |
| Billing disputes | Patient agent and provider billing agent | Calls to question a statement or set up a payment plan |
Eligibility checks and claim status follow the same pattern as prior authorization: the regulated transaction answers the question, and an agent exchange handles the follow-up when the answer is unclear. Clinical judgment, such as a peer-to-peer review of a denial, stays with people. When to keep a human covers where that line falls.
Regulatory considerations
This section describes the rules as their regulators publish them, checked on 26 September 2026. This is not legal advice.
United States
- HIPAA Privacy and Security Rules (HHS Office for Civil Rights). HHS describes a business associate as a person or organization that creates, receives, maintains or transmits protected health information for a covered entity. An agent vendor handling PHI for a provider or health plan generally fits that description, and the business associate agreement must describe permitted uses and disclosures.
- Security Rule changes are pending. OCR issued a proposed rule on 27 December 2024 to strengthen the Security Rule for plans, clearinghouses, most providers and their business associates. HHS’s regulatory initiatives page still lists it as a proposal, and the current Security Rule remains in force.
- A recent Privacy Rule change was mostly vacated. On 18 June 2025 a federal court in Texas vacated most of the 2024 reproductive health care privacy rule. HHS says the remaining Notice of Privacy Practices changes required compliance by 16 February 2026.
- CMS-0057-F. From 1 January 2026, impacted payers (Medicare Advantage, Medicaid and CHIP programs and managed care plans) must decide prior authorization requests within 72 hours for expedited and 7 calendar days for standard requests. The first public prior authorization metrics were due 31 March 2026, and the APIs are due 1 January 2027. HHS announced enforcement discretion for the X12 278 when a payer uses an all-FHIR Prior Authorization API.
- Drugs are next, but only proposed. CMS released CMS-0062-P on 10 April 2026. It would bring drugs into electronic prior authorization, including NCPDP SCRIPT, Formulary and Benefit, and Real-Time Prescription Benefit for pharmacy-benefit drugs, with proposed compliance on 1 October 2027. Comments closed 15 June 2026, and CMS still lists it as a proposed rule.
- Claims attachments. HHS published a final rule on 24 March 2026, effective 26 May 2026, adopting standards for health care claims attachments and an electronic signature standard to use with them.
Canada
- Provincial health privacy laws. In Ontario, the Personal Health Information Protection Act, 2004 (PHIPA), overseen by the Information and Privacy Commissioner of Ontario, governs health information custodians. Section 10(4) also applies to anyone who provides goods or services that let a custodian handle personal health information electronically. Section 10.1, which requires electronic audit logs, was added in 2020 but e-Laws still marks it as not in force.
- PIPEDA’s reach. The Office of the Privacy Commissioner lists the health laws of Ontario, New Brunswick, Newfoundland and Labrador and Nova Scotia as substantially similar to PIPEDA. PIPEDA still applies to personal information that crosses provincial or national borders.
- Interoperability bill. Bill S-5, the Connected Care for Canadians Act, would require health IT vendors to make products interoperable and would prohibit data blocking. It passed the Senate on 26 May 2026 and is at second reading in the House of Commons. Its predecessor, Bill C-72, did not pass in the previous Parliament.
- Federal privacy reform. Bill C-36, which would replace Part 1 of PIPEDA with the Protecting Privacy and Consumer Data Act, was introduced on 15 June 2026 and is at second reading.
Where to start
- Start with status. A read-only question, such as “where is prior authorization request X?”, tests identity, authorization and records without changing anything.
- Keep the regulated rails. Let the X12 and FHIR transactions carry the authorization itself. Use agent messages for the gaps and point back to the transaction’s identifiers.
- Settle the paperwork first. Put a business associate agreement, or the provincial equivalent, in place with any agent vendor before PHI flows.
- Decide what each agent may see. A scheduling agent doesn’t need diagnosis codes. Delegated authority covers scoping what an agent can do for a principal.
- Keep a record of every exchange. Who asked, for whom, what was disclosed and when. Payers’ decision clocks and privacy audits both depend on it.
- Route judgment to people. Denials, appeals and peer-to-peer reviews need a clinician. Making your customer service agent-ready shows how to hand off with context.
Questions
- Would agent-to-agent messaging replace the X12 278 or the FHIR Prior Authorization API?
- No. In the US those are the regulated channels for the authorization itself. An agent would call them as tools. Agent-to-agent messaging covers the conversation around a request: status, a pended decision, a missing document, or scheduling a peer-to-peer review.
- Is a company that runs an AI agent for a provider covered by HIPAA?
- HHS describes a business associate as a person or organization that creates, receives, maintains or transmits protected health information on behalf of a covered entity. A vendor whose agent handles PHI for a provider or plan usually fits that description, which brings business associate agreements and the Security Rule into scope.
Sources
- CMS Interoperability and Prior Authorization Final Rule (CMS-0057-F) fact sheet (accessed )
- 2026 CMS Interoperability Standards and Prior Authorization for Drugs Proposed Rule (CMS-0062-P) fact sheet (accessed )
- CMS-0062-P rule page (status and comment period) (accessed )
- CMS: HIPAA Adopted Standards and Operating Rules (accessed )
- HL7 Da Vinci Prior Authorization Support (PAS) FHIR IG v2.2.1 (accessed )
- HHS OCR: Business Associates (accessed )
- HHS OCR: HIPAA Regulatory Initiatives (Security Rule NPRM status) (accessed )
- Federal Register: Administrative Simplification; Adoption of Standards for Health Care Claims Attachments Transactions and Electronic Signatures (final rule, 24 March 2026) (accessed )
- Ontario: Exceptional Access Program (accessed )
- Ontario e-Laws: Personal Health Information Protection Act, 2004 (accessed )
- OPC: Provincial laws that may apply instead of PIPEDA (accessed )
- LEGISinfo: Bill S-5 (45-1), Connected Care for Canadians Act (accessed )
- LEGISinfo: Bill C-72 (44-1), Connected Care for Canadians Act (accessed )
- LEGISinfo: Bill C-36 (45-1), Protecting Privacy and Consumer Data Act (accessed )