top of page

Medicare Just Made AI Governance a Payment Issue

  • Jul 25
  • 5 min read

On July 14, CMS released the CY 2027 Physician Fee Schedule proposed rule (CMS-1848-P). Most of the coverage has focused on conversion factor cuts and practice expense methodology. Fair enough: those are the numbers that move budgets.

But buried in the Quality Payment Program section are two proposals that should have every health system's attention. Together, they mark the first time federal payment policy has attached clinician credit not to using AI, but to governing it.


First, a quick refresher on MIPS

If you don't spend your days inside the Quality Payment Program, the acronym does a lot of hiding. Here's what matters.


MIPS is how Medicare adjusts what it pays most clinicians based on performance. Created by the Medicare Access and CHIP Reauthorization Act of 2015, the Merit-based Incentive Payment System scores eligible clinicians across four categories — Quality, Cost, Promoting Interoperability, and Improvement Activities — and rolls them into a single composite score. That score determines a payment adjustment applied to every Part B claim two years later. Score above the performance threshold and you get a positive adjustment. Score below it and you take a penalty, up to negative 9 percent.

The program is budget-neutral by statute, which is the part people underestimate. Penalties fund bonuses. MIPS isn't a grant program where everyone who does well gets paid, it's a redistribution, and clinicians are scored against each other. Falling behind on a category isn't neutral. It's a transfer to the organizations that didn't.


Improvement Activities is the category these AI proposals live in. It's the smallest of the four by weight — currently 15 percent of the composite score — and historically the most attestation-based. Clinicians select from a CMS-maintained inventory of activities and attest to having performed them for at least 90 continuous days. Activities are weighted medium or high, and most clinicians need a modest combination to max the category.


That structure is exactly why the AI proposals matter more than 15 percent would suggest. The Improvement Activities inventory is where CMS signals what it considers good practice before it has the measurement infrastructure to score it directly. Activities that start here tend to migrate into quality measures, into conditions of participation, into MIPS Value Pathways requirements. The inventory is CMS thinking out loud about what it will eventually require.


And the frame is shifting underneath all of this. In the same rule, CMS proposes to sunset traditional MIPS reporting beginning with the 2029 performance year, pushing clinicians toward MIPS Value Pathways, i.e., specialty-specific bundles of measures and activities that CMS considers more clinically meaningful. So the definitions written into the improvement activity inventory now are the definitions that get inherited by whatever comes next.


What's actually in the rule


1. A new MIPS Improvement Activity: "Clinician Use of Artificial Intelligence (AI) to Improve Patient Care."

The activity would give clinicians credit for responsible, transparent use of AI across familiar use cases like ambient documentation, care gap identification, clinical trial matching, drafting patient responses.

Read the language closely, though. Credit isn't for deploying AI. It's for establishing policies to evaluate and monitor the tools you deploy. The activity is a governance activity wearing an adoption activity's clothes.


2. A modified decision support activity (IA_PSPA_16).

CMS proposes to explicitly incorporate AI-enabled predictive decision support and strengthen the oversight expectations that come with it: ongoing monitoring, root cause analysis, and mitigation of AI-related risks.

That's not a vague gesture toward "responsible AI." Those are three distinct operational capabilities, and most organizations can only claim one of them with a straight face.


Why this is the signal, not the noise

CMS isn't asking whether clinicians will use AI. That question is settled. What the agency is doing here is defining what accountable use looks like and attaching reimbursement to the definition.


For years, AI governance in healthcare has been treated as a compliance nice-to-have: a committee, a policy document, a vendor questionnaire filed away after procurement. This proposal reframes it entirely. Monitoring, evaluation, and risk mitigation aren't overhead on top of AI deployment. They're the mechanism by which AI earns its place in clinical workflows and now, potentially, the mechanism by which clinicians earn MIPS credit.


Which brings the MVP transition back into focus. The improvement activity framework these proposals live inside is itself on its way out. That doesn't diminish the signal, it raises the stakes. Whatever definition of "responsible use" survives this comment period is the one that gets carried forward.


Three things we're watching

How CMS defines sufficient "monitoring and evaluation." This is the whole ballgame. A definition that accepts an annual attestation and a policy binder produces one market. A definition that expects performance drift detection, subgroup analysis, and documented remediation produces a very different one. The comment period is where that line gets drawn.


Whether this becomes a template for other payers. CMS moves first; commercial plans follow. We've watched this pattern play out with quality measures, with interoperability requirements, with prior authorization reform. There's little reason to expect AI oversight to break the pattern.


The gap between health systems with real AI oversight infrastructure and those without. Right now that gap is invisible. It lives in the difference between organizations that can produce a monitoring record on request and organizations that would need six weeks and a consultant to assemble one. Attach it to a reporting requirement and the gap becomes visible. Attach it to payment and the gap becomes measurable.


Your window is open until September 14

The rule is open for public comment through September 14, 2026. If you're building, deploying, or governing clinical AI, this is a genuine opportunity to shape how "responsible use" gets defined in federal payment policy — before it hardens into a standard you're measured against.

A few things worth addressing in a comment, if you're drafting one:

  • What monitoring evidence is realistic to produce and retain for a mid-sized health system versus an academic medical center

  • Whether the activity should distinguish between AI categories by risk level — ambient scribing and predictive deterioration models don't warrant identical oversight

  • How responsibility should be allocated between deploying organizations and vendors, particularly for models the deployer cannot inspect

  • What "root cause analysis" means operationally when the model is a black box


The through line

We've been saying it at Alignmt AI since day one: trust in healthcare AI isn't declared, it's demonstrated. It's built through evidence — continuous, documented, and specific to the setting the model is actually running in.

Now Medicare appears to agree. And when Medicare agrees with you about what counts as evidence, the question stops being philosophical and starts being operational.


Read the rule:

If you're working through what these proposals would mean for your AI oversight program — or putting together a comment — we'd like to hear from you.

 
 
 

Comments


bottom of page