Key Takeaway
Artificial intelligence and algorithmic systems can help doctors, insurers and public programs process large volumes of information quickly. But when a system moves from supporting a decision to effectively determining whether a person receives funded treatment, rehabilitation or another essential service, efficiency becomes a question of rights and accountability.
A September 21, 2026 Guardian article, summarizing John Oliver’s examination of UnitedHealth Group, raises this concern through the U.S. insurance market. Disputes over algorithmic claims management show that the central problem is not the existence of an algorithm itself. It is a decision model in which a person may not understand why coverage was denied or who remains responsible for the outcome.
For Georgia, the issue is no longer purely theoretical. Gross written insurance premiums exceeded GEL 1.4 billion in 2025, with health insurance accounting for 43% of the market. At the same time, Georgia’s Personal Data Protection Law directly addresses solely automated decisions that have legal, financial or similarly significant effects. The relevant policy question is therefore not whether algorithms should be used at all, but which decisions may be automated, how understandable their logic is, and where meaningful human control must remain.
When an Algorithm Stops Advising and Starts Deciding
Algorithmic systems in healthcare can perform very different functions. One can assist diagnosis, another can forecast hospital capacity, another can flag suspected fraud, and another can evaluate whether treatment or rehabilitation meets coverage criteria.
The risk lies in confusing these roles. If a system provides a recommendation and a qualified human makes the final decision, there remains room to identify errors and account for individual circumstances. If the model’s output becomes the practical basis for an automatic denial, a patient’s condition can be compressed into an average statistical profile.
The issue became prominent in U.S. Medicare Advantage. A 2023 STAT investigation examined an algorithm used by UnitedHealth subsidiary NaviHealth to predict rehabilitation duration. UnitedHealth said the tool was a guidepost, while employees interviewed by STAT described pressure to align coverage decisions closely with the predicted dates. That distinction is the heart of the governance problem: what the system says is one question; how an organization operationalizes it is another.
A Faster Decision Is Not Automatically a Better Decision
The economic case for automation in insurance is understandable. Processing thousands of claims manually is expensive; faster decisions can reduce administrative costs, while data analysis can identify anomalies and risks that a person might miss.
But in medical coverage, the cost of error is much higher than in an ordinary transaction. A rejected online purchase can be resubmitted; a rejected treatment can create delay, financial strain and health consequences. This is why the U.S. Centers for Medicare & Medicaid Services has tightened prior-authorization rules in recent years. Medical-necessity determinations must consider the circumstances of the individual, including medical history, physician recommendations and relevant clinical criteria. Beginning with the 2026 coverage year, Medicare Advantage organizations also submit information to CMS on internal coverage criteria used in prior authorization.
The underlying principle is important beyond the United States: an algorithm can process data, but a medical-necessity decision should not become an opaque black-box answer.
Georgia’s Insurance Market Is Already Large Enough for the Question to Matter
According to Georgia’s Insurance State Supervision Service, gross written premiums exceeded GEL 1.4 billion in 2025, 12% above the previous year. Health insurance accounted for 43% of the market, and 21% of the population used medical insurance services. Georgia had 19 registered insurers and 26 insurance brokers.
According to calculations by BTU researchers, applying the published 43% rounded share to a conservative GEL 1.4 billion base gives approximately GEL 602 million. Because the regulator says total premiums exceeded GEL 1.4 billion and the 43% figure is rounded, this is not the official exact amount of health-insurance premiums. It is only a conservative scale estimate.
At this scale, the quality of technology-assisted decisions becomes a consumer-protection issue. Insurers have legitimate incentives to improve claims processing, fraud detection, service speed and risk analysis. But if more consequential decisions rely on automated profiling, the system needs to do more than generate a fast yes or no. It must support a decision that can be explained and challenged.
Georgia Already Has a Legal Principle of Human Intervention
Article 19 of Georgia’s Personal Data Protection Law provides an important framework. Subject to defined exceptions, a person has the right not to be subject to a decision based solely on automated processing, including profiling, when it produces legal or similarly significant effects. In relevant cases, the law also provides safeguards involving human participation, the right to express a point of view and the ability to contest the decision.
The law also requires a data-protection impact assessment in high-risk circumstances, including fully automated decisions with legal, financial or other significant consequences and large-scale processing of special-category data. Health information is explicitly treated as special-category data.
This means algorithmic insurance decisions in Georgia do not operate in a regulatory vacuum. But data-protection law is not a complete framework for clinical AI. Separate questions remain about medical validity, model testing, bias, clinical accountability, audit standards and how systems perform after deployment.
The International Direction: Higher Impact Requires Higher Control
The European Union’s AI Act classifies certain AI systems used for risk assessment and pricing in life and health insurance as high-risk. The same framework treats access to essential public services, including healthcare, as a particularly sensitive area. The logic is not to prohibit AI. It is to require stronger transparency, risk management, data quality and accountability when a system can materially affect a person’s rights or health.
The World Health Organization takes a similar direction. WHO’s guidance emphasizes human autonomy, safety, transparency, explainability, accountability, inclusiveness and equity. The central idea is that AI should be a safely governed tool, not a substitute for professional or institutional responsibility.
Georgia cannot simply copy every international rule. The market, public-financing structure, prevalence of private insurance and technological capacity differ. But one principle travels well across systems: when an algorithm affects access to healthcare or a major financial interest, “the system decided” is not a sufficient explanation.
What a Consumer Should Be Able to Do
Where AI or another algorithmic system participates in a high-impact insurance decision, four practical safeguards matter. The consumer should know that automation played a role; receive an understandable explanation of the type of data and criteria involved; have a meaningful route to human review; and be able to identify the organization responsible for correcting an error.
That does not require an insurer to publish proprietary source code. Companies can have legitimate trade-secret and cybersecurity interests. But technical complexity should not erase the consumer’s ability to understand and contest a consequential decision.
For business, this is also a trust issue. Health insurance is purchased in advance on the expectation that contracted services will be available when needed. If denial logic is opaque or no accountable decision-maker is visible, the administrative savings from automation can reappear as reputational and regulatory cost.
BTU Researchers’ Assessment
According to an assessment by BTU researchers, the right direction for Georgia is not to stop algorithmic decision support. Well-governed automation can reduce queues, speed up claims, improve fraud detection and reduce some forms of human error.
But high-impact decisions – such as denying funding for treatment or making a major financial decision based on health risk – should be held to a stricter standard. A minimum governance model should include human oversight, meaningful explanation, a clear appeal route, data-protection impact assessment and periodic independent review of system performance.
The relevant performance metric is therefore not only how quickly a system processes a claim. It is whether the decision is fair, understandable and contestable.
Conclusion
Algorithms can be powerful tools in healthcare, but they should not become invisible final judges. Where the answer determines access to treatment or significant financial responsibility, efficiency cannot replace professional judgment and individual rights.
Georgia already has an important legal foundation: rights around automated decision-making, the possibility of human intervention, and impact-assessment requirements for high-risk data processing. The next step is to turn these principles into practical technology-governance standards. Good use of AI in healthcare is not when an algorithm replaces a person; it is when the system helps people make better decisions while responsibility remains clear.
This material is analytical and educational. It does not constitute medical advice, diagnosis or treatment instructions. For a specific health issue, consultation with an appropriate healthcare professional is required.
Data and Main Sources
The Guardian – “John Oliver on UnitedHealth Group: ‘Algorithmically driven, ruthless arbiters of who lives and who dies’”, September 21, 2026:
https://www.theguardian.com/tv-and-radio/2026/sep/21/john-oliver-united-healthcare
STAT – “UnitedHealth pushed employees to follow an algorithm to cut off Medicare patients’ rehab care”, November 14, 2023:
https://www.statnews.com/2023/11/14/unitedhealth-algorithm-medicare-advantage-investigation/
Centers for Medicare & Medicaid Services – 2024 Medicare Advantage and Part D Final Rule:
https://www.cms.gov/newsroom/fact-sheets/2024-medicare-advantage-and-part-d-final-rule-cms-4201-f
Centers for Medicare & Medicaid Services – Part C Utilization Management Annual Data Submission:
https://www.cms.gov/medicare/audits-compliance/part-c-part-d-compliance-audits/part-c-utilization-management-um-annual-data-submission
Insurance State Supervision Service of Georgia – 2025 market performance and 2026 update:
https://insurance.gov.ge/en/News/parlamentshi_dazghvevis_sakhelmtsifo_zedamkhedvelobis_samsakhuris_sametvalkureo_sabchos_skhdoma_gaimarta3
Law of Georgia on Personal Data Protection:
https://new.matsne.gov.ge/en/document/view/5827307
World Health Organization – Ethics and governance of artificial intelligence for health:
https://www.who.int/publications/i/item/9789240029200
European Union – Artificial Intelligence Act, Regulation (EU) 2024/1689:
https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:32024R1689
Prepared by the academic team of Business and Technology University and the BTUAI Research Team, Tbilisi, Georgia.



