In a synthetic skilled nursing extension case, a Medicare Advantage model returned DENY at 0.985 confidence while individual clinical factors accounted for only 22.06% of its attribution.
That is the governance problem model confidence cannot settle. In our CertaRoute demonstration, a separate gate holds the case for physician review. The walkthrough of this Medicare Advantage AI governance example shows the case, its attribution and the resulting route.
CMS clarified in its February 2024 coverage and utilization management FAQ that an algorithm may assist an MA organization, but a determination must account for an individual's circumstances. An algorithm based on a larger dataset cannot substitute for review of the individual patient's circumstances. Confidence in a model output does not answer that obligation.
The case behind the confident denial
We built a fixed, synthetic worklist to make this boundary inspectable. Case A-4471 is a post-acute skilled nursing extension. The screen shows the initial assessment and the clinical and population factors presented with it. There is no real member, live payer connection or final coverage determination here.

Synthetic case A-4471 is pending physician review, with the record marked NEEDS_PROOF rather than a finalized denial.
The model's exact Shapley attribution gives roughly 49% of absolute contribution to the recovery-timeline gap and 19% to prior utilization. The individual clinical factors together contribute 22.06%. CertaRoute compares that share with a configurable 35% policy floor for salient denials. Because this case falls below the floor, the code gate sets NEEDS_PHYSICIAN_PROOF.
The 35% floor is a control selected for this demonstration, not a regulatory threshold or a medical-necessity rule. Its purpose is to expose a case in which the initial assessment leans heavily on population-weighted signals while individual clinical factors need a human judgment. The route does not approve the extension. It prevents this synthetic denial from being treated as final within the demo workflow.

The attribution view shows why the demo's individual-clinical-review check fired: about 22% individual contribution against a configured 35% floor. Its separate "Coverage requirement: PASS" line attests to routing, not a comparison with an actual Evidence of Coverage document.
A high-confidence model assessment is not evidence that an individual patient's circumstances were given adequate weight.
The authority boundary belongs outside the explanation
The distinction between an explanation and a decision is easy to blur in an AI interface. CertaRoute separates them. Advisory text can describe why a case was routed, using a deterministic template by default or an optional language-model provider. That text cannot authorize the denial or overrule the gate. The code-based checks set the route independently.
This boundary remains useful as models improve. A better predictor may change the initial assessment, but the organization still needs explicit rules for when a case requires physician judgment, who may complete that review, and what technical record is retained. We are showing the first and third parts in a local demonstration, not claiming a staffed clinician workflow or a production authorization system.
Across the fixed 253-case synthetic run, 92 cases take the physician-review route. Those 92 carry a NEEDS_PROOF record state. The app labels 161 others DEFENSIBLE, but that is its own technical state, not a legal conclusion or an independent completeness finding. The numbers describe this seeded set, not clinical performance in an MA population.
A record can make the route inspectable
For each synthetic case, the app writes a local SQLite record with model attribution, routing and disposition, linking record hashes to the prior hash. In the fixed run, all 253 records pass a local chain check before the built-in tamper test. A reviewer can reconstruct A-4471's technical path and see that it remains pending physician review.

The local chain check reports 253 of 253 records intact before the tamper test. It does not establish independent custody or clinical sufficiency.
The same demonstration deliberately changes a stored record without recomputing its hash, and the verifier reports the broken chain. That is a useful integrity test. It is not proof that the ledger is immutable, that access is secured, or that a printed record is ready for legal use. The pipeline's field-presence flag is always passed as true, so the app also does not independently validate that every underlying field is complete.
Governance has to preserve the difference between a review route, a technical record and a final clinical decision.
The full breakdown of CertaRoute includes the case walkthrough and the limits of this synthetic implementation. We would welcome a concrete discussion with MA clinical, compliance and engineering teams about the handoff: which case-level evidence must accompany a physician-review route before anyone can close it?