RatedWithAI

RatedWithAI

Accessibility scanner

Algorithmic DiscriminationSeptember 8, 2026

The Algorithm Flagged the Physician. Now the Hearing Needs a Reason.

Credentialing is one of the few corporate processes that comes with a statutory hearing attached. Drop a vendor risk score into it and the committee inherits a burden most AI deployments never face: explaining, to the person adversely affected and under oath, what the facts were.

30 days
An adverse privileges action beyond this is reportable to the NPDB
Conditional
HCQIA immunity — it depends on the adequacy of your process, not the outcome
§1981
Reaches independent contractors, so contractor status is not a shield

Automation Is Fine Until It Ranks Someone

Credentialing has an enormous clerical surface: primary source verification, licence and DEA status, board certification, sanctions checks, expirables tracking, gap reconciliation. Automating that work is uncontroversial and is where the return actually is. The verification either matches the primary source or it does not, and a machine checking a registry is doing the same thing a coordinator did, faster.

The legal character changes the moment the software stops reporting facts and starts producing judgements — a composite risk score, a recommended privilege set, a flag for focused professional practice evaluation, a ranking of applicants. Now the output is an opinion about a person's competence, and it has entered a process where that person has enforceable procedural rights.

Low risk
Primary source verification and expirables tracking
Deterministic checks against an authoritative registry. Log the source and the timestamp and this is straightforward automation.
Low risk
Document parsing and application completeness checks
Watch for extraction errors that read as omissions by the applicant — a parsing failure recorded as a non-disclosure is how a clerical bug becomes a credentialing allegation.
Moderate
Sanctions and exclusion list matching
Fuzzy name matching produces false positives that fall unevenly across ethnic name distributions. Require human adjudication of every hit before it reaches a file.
High risk
Composite risk or quality scoring of applicants
An opinion about competence expressed as a number. Must be explainable at a hearing and defensible under disparate impact analysis.
High risk
Predicting future malpractice or adverse events
Prediction from historical claim data reproduces specialty and patient-population effects. The base rates make individual prediction weak, and a weak model driving a career-affecting action is the worst combination available.
Do not deploy
Automated non-renewal or privilege restriction
A professional review action with no human decision-maker who can testify to the reasonable belief HCQIA requires. Several state ADS statutes independently require meaningful human review of consequential decisions.

HCQIA Immunity Is a Process Guarantee, Not an Outcome Guarantee

The Health Care Quality Improvement Act gives peer reviewers immunity from damages, which is why medical staff processes are structured the way they are. The immunity is presumed, and the presumption is rebuttable by a preponderance of the evidence that one of four conditions was not met.

  • A reasonable belief the action furthered quality health care.
  • A reasonable effort to obtain the facts of the matter.
  • Adequate notice and hearing procedures, or a fair procedure under the circumstances.
  • A reasonable belief the action was warranted by the facts known after that effort.

The two bolded elements are where a black-box score does damage. If the committee's record consists of a vendor output and a vote, opposing counsel gets to ask what facts the committee knew, and the honest answer is a number nobody in the room could derive. That is a plaintiff's argument that no reasonable effort to obtain the facts was made — and once the presumption falls, the immunity that made peer review viable goes with it.

The fix is not to abandon the tool. It is to make the score an input to a human investigation that generates its own record: what was reviewed, what was found, what the physician said in response, and what the committee concluded on the facts. If the file would support the action with the score redacted, the immunity analysis is intact.

Which Anti-Discrimination Statutes Reach a Privileging Decision

Health systems often assume that because medical staff members are not employees, employment discrimination law is out of the picture. Several statutes do not care about that distinction.

§

Section 1981

Prohibits race discrimination in the making and enforcement of contracts, and applies to independent contractors. A privileging relationship is contractual, so a model with disparate racial impact is exposed here regardless of employment status. There is no administrative exhaustion requirement and the damages are uncapped.

§

Section 1557 of the ACA

Reaches health programmes and activities receiving federal financial assistance. The 2024 final rule requires covered entities to identify and mitigate discrimination risk in patient care decision support tools, and the compliance posture it establishes — inventory, evaluate, mitigate, document — is the one regulators will expect for provider-facing tools as well.

§

Title VII and the ADA

Apply directly to employed physicians, advanced practice providers, nurses and every other credentialed employee. Most systems run employed and independent staff through the same credentialing pipeline, so a single model is simultaneously inside and outside Title VII depending on the applicant.

§

State ADS and civil rights statutes

Colorado's AI Act treats consequential decisions in employment and healthcare services as high risk and requires impact assessments and notice. Illinois HB 3773 amends its Human Rights Act to reach AI in employment decisions. California's FEHA regulations on automated decision systems impose recordkeeping and testing duties. None of these were written for credentialing, and all of them are drafted broadly enough to cover it.

§

State fair procedure doctrine

Independent of statute, several states impose a common law fair procedure requirement on hospital privileging. California's is the most developed. It obliges a rational connection between the evidence and the decision — a standard an unexplainable score is poorly placed to satisfy.

The Inputs That Look Neutral and Are Not

Disparate impact does not require intent. It requires a facially neutral practice that falls more harshly on a protected group without adequate business justification. Credentialing data is unusually full of variables that do this.

Malpractice claim history

Claim frequency tracks specialty, procedure volume, and the payer mix and demographics of the patient population far more strongly than it tracks competence. Physicians serving high-acuity or underserved populations carry more claims for reasons that have nothing to do with the quality of their care.

Training location and foreign medical graduate status

A direct proxy for national origin. Using it as a model feature — or using any variable strongly correlated with it, such as licensure pathway — invites a national origin claim that requires the system to justify the variable's business necessity.

Years since graduation and career stage

A proxy for age. Any feature that penalises longer careers, or that penalises recent entry in a way that correlates with age, is an ADEA exposure for employed providers and a state law exposure more broadly.

Gaps in practice history

Caregiving leave, parental leave, disability leave and military service all produce gaps. A model that treats a gap as a negative signal discriminates on characteristics that are separately protected, and the ADA requires individualised assessment rather than a categorical rule.

Patient satisfaction and complaint volume

The literature on demographic bias in patient ratings is well established, particularly for women physicians and physicians of colour. Feeding raw satisfaction data into a competence score imports that bias wholesale.

Historical privileging outcomes as the training label

The most consequential and least visible choice. If the model is trained to predict what your committee decided before, it reproduces whatever pattern produced those decisions, and it does so with a consistency no individual reviewer could achieve.

What to Have in Place Before the Tool Touches a File

1. Bylaws and governance
  • Amend medical staff bylaws to describe how automated screening is used and where human judgement is required
  • Record that no adverse action issues without an individualised human review that stands on its own record
  • Assign ownership of the tool to a named committee, not to the credentialing vendor relationship
  • Define the escalation path when the model and the reviewer disagree, and require the disagreement to be documented
2. Vendor diligence
  • Obtain the feature list and demand removal of protected-class proxies
  • Require subgroup performance data — accuracy by race, sex, age and training origin, not aggregate accuracy
  • Contract for the right to audit, and for cooperation and testimony in any hearing or litigation
  • Reject any contract term that makes model documentation a trade secret unavailable to a physician in a hearing
  • Confirm the vendor is not a consumer reporting agency in disguise, which would trigger FCRA notice and dispute duties
3. Bias testing
  • Run a pre-deployment disparate impact analysis on your own applicant population, not the vendor's
  • Repeat annually and after any model update, and treat a version change as a new deployment
  • Test the human-plus-model system, since reviewers defer to scores and the combined outcome is what gets litigated
  • Preserve results under a defensible privilege posture, but do not commission a test you intend to bury
4. Due process and records
  • Give the applicant notice that automated screening is used and what data feeds it
  • Provide a route to correct inaccurate underlying data before the committee sees it
  • Ensure the hearing record would support the action with the model output redacted
  • Retain model version, inputs and output for every decision under the same retention schedule as the credentials file

Frequently Asked Questions

The vendor says the model is proprietary and will not share the features. Can we still use it?

You can, and you will own the consequences alone. In a fair hearing the physician is entitled to know the basis of the action, and 'the vendor will not tell us' is not an answer that supports a reasonable belief the action was warranted by the facts known. Trade secret protection can be handled with a protective order; a vendor unwilling to disclose under one is telling you the tool cannot be used for consequential decisions, only for triage that a human then independently justifies.

Is a credentialing screening vendor a consumer reporting agency under FCRA?

It can be. A third party that assembles information bearing on a person's character, general reputation or personal characteristics and furnishes it for use in employment decisions is a consumer reporting agency, and that captures more credentialing products than vendors like to admit. If FCRA applies, you owe disclosure and authorisation before procurement, and a pre-adverse action notice with a copy of the report and a summary of rights before you act. Get a written position from the vendor and do not accept a verbal assurance.

Can we use the model only to prioritise which files a human reviews closely?

This is the safest deployment and it is still not risk-free. Triage that routes some physicians to closer scrutiny produces differential treatment if the routing correlates with a protected characteristic, and heightened scrutiny reliably finds more to act on. Test the routing decision for disparate impact the same way you would test a final decision, and ensure the eventual action rests on facts found in the review rather than on the fact of having been selected for it.

How does this interact with the FPPE and OPPE requirements accreditors already impose?

Ongoing and focused professional practice evaluation are exactly the places where scoring tools are being marketed, because the data is already being collected. The accreditation framework requires the criteria to be defined in advance and applied consistently, which is compatible with a model, but it also expects the evaluation to be clinically meaningful. A statistical flag that triggers focused evaluation must be defensible as a clinical criterion, and a flag that mostly identifies high-volume proceduralists is a workload measure wearing a quality label.

We are a telehealth network credentialing across many states. Does that change the analysis?

It multiplies it. You inherit the ADS and civil rights statutes of each state where the provider practises, along with each state's fair procedure doctrine and any delegated credentialing agreements with the facilities you serve. Delegation contracts typically require the delegate to follow the delegator's standards, so an automated screen applied uniformly across the network has to satisfy the strictest state in the footprint, not the average one.

The Redaction Test

Before any adverse credentialing action leaves the committee, take the file and cover the model output. If what remains — the investigation, the documents, the physician's response, the committee's findings — would independently support the action, the tool did its job as a triage aid and the record survives a hearing.

If the case collapses without the score, you are not making a peer review decision. You are ratifying a vendor's prediction, in a forum that will ask you to explain it, with an NPDB report as the injury on the other side.