I don’t know how to build a website. A person I trust showed me the one part that puts words on a page, and that is the only part I know how to do, so that is all this is. Words, in the order I wrote them.
I’m putting them somewhere they can be read because I’m about to be somewhere I can’t say them from.
If you’ve gotten one of the letters, or you’re going to, I wrote this for you.
I worked for them for thirteen years. I was never outside the methods because I built them. The people who explain me after what happens next will want me to have been an outsider. But that’s not the truth. I was good at my job. It would be easier for you if I’d been mediocre, overlooked, or passed over. I was promoted twice, and told more than once, by the person who ran my reviews, that I was being groomed for a director-level seat. I was the person other departments called when their numbers wouldn’t reconcile. For most of my career, I was the person in the room who could make an ugly outcome look inevitable, and I did it so well that few of my colleagues could tell the difference.
I found the efficiencies. That was the actual language we used in meetings. An efficiency is a place where the system was spending more than it needed to. Every efficiency I ever found made the system spend less. I wasn’t paid to think about where the difference went, so I never did. My job was to find the number, and I found a great many numbers. My performance reviews repeatedly reminded me that I was the shield, that my work protected the people who could not protect themselves. I believed it for thirteen years. I believed it the day I signed the offer letter and I believed it the last morning I badged into the building and I believed it on the day a system I helped design looked at a file with my daughter’s name on it and returned a number that told a room full of strangers she wasn’t worth the cost of saving.
That isn’t a metaphor. I’m not being dramatic to make a point land. A file existed, and that file had a column value low enough that someone was authorized to deny the treatment that would have kept her breathing. I have spent every day since then trying to decide what to do with the fact that I taught the machine how to hold that column.
This is not an apology. An apology asks something of the reader, and I’m not asking anything of you. I am disclosing. Disclosure is the act of telling a counterparty something they are entitled to know before they enter into an agreement with you, whether the agreement is a policy, a marriage, or the time you are about to spend reading this. You are entitled to know that the person writing it spent thirteen years on the other side of exactly the kind of letter you may have received. You are entitled to know that I did not stumble into understanding these systems. I built pieces for several of them. I am not a whistleblower in the sense the word usually carries, a person who found a secret and decided to share it. Everything I am about to describe was legal, board-approved, actuarially sound, and printed, in one form or another, in a disclosure document that arrived in an envelope that looked exactly like every other envelope, addressed to someone who did not read it closely enough, because the language is built by people like me, to be read exactly that way. Cruelty requires intent, and nothing in thirteen years of meetings ever required anyone to intend anything. That is the finding. Harm without malice, on a schedule, at scale. I am going to walk you through it the way I walked auditors and my own daughter’s oncologist through a coverage determination the week before I stopped being able to walk anyone through anything, because that’s the only gift I still have to give people who have not yet gotten the letter. Most of you will get the letter. I built the methods and found the efficiencies. You should know exactly whose hand is on these pages.
I have not named anyone here. Not the company or the state, and not any of the executives whose faces you may have already seen on a screen this year, saying the sentence every executive says. Something about the outcome being regrettable, the review being thorough. I am not protecting them. But if I gave you a name then it would be too easy for you to stop thinking. Give a reader a villain and the reader’s job is finished. They can decide how they feel about the villain, share the villain’s name, and feel the satisfaction of having identified the person responsible. I spent thirteen years watching that mechanism work on other companies’ scandals, watching a name absorb a population’s anger like a single spliced insulator absorbs a surge meant for the grid. I won’t build another one of those for you. If I give you a name, you’ll do what I did for thirteen years every time a name came across my desk. You will look it up, decide how you feel, and file it somewhere you’ll probably never look again.
The company I worked for is not unusual. Every large insurer runs some version of what I’m about to describe. Every large health system, lender, or employer with a self-funded plan runs some cousin of it. There is no villain. There are approximately four hundred thousand people in this country whose job, in whole or in part, is to do some version of what I did. Most of them have never met each other. Most of them believe that their particular piece of the machine is the responsible piece that keeps the whole thing from being worse than it would otherwise be. Most of them are not wrong about their piece.
I wrote a sentence in a notebook during my second week of training, while an instructor walked a room of new hires through loss development, and I meant it as a joke: modern suffering is rarely caused by villains. It is caused by spreadsheets. I thought I was being clever, not yet understanding that I was writing my own job description. That will take you considerably less time to understand than it took me,
because I’m going to hand you the shortcut I never had: every piece can be defensible and the sum can still be a machine that kills people on a schedule. I watched this happen from the inside, more times than I can count. A story would surface. A name would attach to it, usually a chief executive’s, occasionally a mid-level director’s if the mid-level director had been careless enough to put something in writing. The company would issue a statement using the word regrettable, and the public would spend its attention on the name for exactly as long as the news cycle required. When the name would resign, or retire, or in the rarer cases be replaced by someone whose first act was a listening tour, the machine underneath the name would not change one line of code. I know the process from the drafting side because I helped write two of those statements. The name is not incidental to the process. It is the part of the apparatus specifically designed to be sacrificed so business can continue as usual. It works because it is genuinely satisfying to watch a name fall. I have felt that satisfaction myself, watching other companies’ names fall, and until it was my own daughter in the file I did not once ask myself what happened to the machine underneath.
A machine does not require a name to be described. It requires a diagram. I want to show you that diagram.
A determination is the moment a claim meets its answer. Somebody, or something, opens a file, applies a set of rules, and returns one of four words: approved, denied, pending, referred. Everything before the determination is paperwork. Everything after the determination is a person’s life, rearranged around the word that was returned.
A claim arrives. It is not read, in the sense that a letter is read. It is parsed. Every field is extracted into a structured record: diagnosis code, procedure code, provider network status, prior authorization status, policy tier, days since enrollment, a column labeled utilization history that means, in practice, how much has this person already cost us. The record is passed to a rules engine, which is a piece of software that asks the record several thousand yes-or-no questions in sequence. Is the provider in-network? Was prior authorization obtained? Does the diagnosis code match an exclusion? Is the procedure code on the covered list for this tier? Each question either passes the claim to the next question or routes it to a human reviewer. That might sound like mercy, but routing to a human reviewer is a cost center. A human reviewer is more expensive per claim than a rules engine by roughly a factor of forty, and every claim that requires a human touch is a claim that has, by definition, already failed to resolve cleanly through the automated path, which means it’s disproportionately likely to be a claim that is expensive, ambiguous, or adversarial. The system is built, at every layer, to keep as many claims as possible away from a human being. And not because a person would be softer, though sometimes they are, but because a human is slower and slower costs money at scale in a way that is measured, reported, and used in the calculation of everyone’s bonus. Mine included.
When a claim reaches a human reviewer, the reviewer is not making a moral judgment. They are applying a policy document written by an actuarial team, reviewed by a legal team, approved by a state regulator, and priced into every premium collected that year. The reviewer has a target average handling time (usually between four and eleven minutes depending on claim complexity) and a quality score that measures, among other things, how consistently they apply the written policy rather than their own judgment, because inconsistent application is itself a liability. A thing that gets a company sued and loses in front of a jury. A reviewer who approves claims the policy does not clearly cover is not being generous, they are creating exposure. Exposure has a cost, and the cost is tracked back to the reviewer by name.
One of those quality-score systems I helped to design sampled a percentage of each reviewer’s closed claims every month and re-scored them against the written policy by a second, senior reviewer, and any determination that deviated from what the policy strictly allowed, in either direction, counted against the original reviewer’s score. A reviewer who wrongly denied a legitimate claim and a reviewer who wrongly approved an illegitimate one were penalized by the same system, at the same rate, for the same underlying offense, which the system defined as deviation from the document rather than harm to the claimant. There was no field anywhere in that scoring model for the human outcome of a determination. There was a field for consistency, because consistency is what a regulator audits, and a regulator has never once asked me, in an audit I sat through personally, what happened to the person on the other end of a correctly consistent denial. An audit trail protects the document. Every reviewer’s keystrokes, timestamp, and version of the policy language in effect on the date of determination are preserved specifically so that if a denial is challenged, the company can produce, instantly, a complete record proving the reviewer did exactly what the document required. The system was built, with genuine engineering care, to prove correctness. It was never designed to notice harm, because harm was not a variable anyone was required to track, and a company doesn’t measure what it isn’t required to report.
I remember, with a specificity I wish I didn’t have, the meeting where a colleague asked whether we should add a field to flag determinations involving a minor, so the company could review them with additional scrutiny, and the answer, delivered kindly, by someone I respected, was that a flag like that would create a paper trail suggesting the company treated some determinations differently than others, and a paper trail like that would itself become a liability in litigation. The flag’s absence is by definition a determination, made by careful people, for reasons that made total sense inside the room where it was made.
Before any of those questions can be asked at all, the claim must be reduced to what the system can read. That means codes, dates, network statuses, and dollar amounts. Everything else about the person, the body in the bed, the circumstances that produced the file, the story of how a family arrived at this particular envelope, has to be discarded at intake. Keeping the story was never in any specification I was handed, and in thirteen years I never once asked for it to be added, because a system that kept the story could not run at the speed and volume that justified building the system. Discarding is what makes the machine possible. It is also where every harm I am going to describe in this document lives. Those are the same operation, performed once, at the top of the pipeline, before anyone who could be blamed for it has touched the file.
None of this requires anyone to be cruel. The actuary who priced the policy was solving an equation that had to balance, because an insurer that does not balance its equation stops existing and covers nobody. The regulator who approved the policy was checking it against a legal standard that has nothing to say about mercy, because mercy is not a category regulators are equipped to measure. The reviewer who denied the claim was following a document that a room full of careful, credentialed people built with real expertise and real intent to keep a promise solvent for everyone who paid into it. Every single person in that chain can defend their piece in a deposition, under oath, without lying once. Nothing here is illegal and nothing here required anyone to decide anything. The determination that ends a person’s treatment is not a decision in the sense most people mean the word. It is an output.
A great many careful, defensible, individually reasonable choices, made by a great many people who will never meet each other or the person the claim belongs to, add up to an output, and the output is sometimes a number too low to keep a child alive. There is no meeting where anyone votes on that outcome specifically, because the outcome was never the agenda. The agenda was always the equation.
Every actuarial model that touches a human life eventually needs a column for what that life is worth. Most people have no idea that the column exists at all. Nobody in the industry is careless enough to call it “worth.” It is called “recoverable value,” or sometimes “expected lifetime value,” or in the more clinical corners of the field, “present value of future contribution.” The euphemism is doing real work, because a spreadsheet with a column labeled worth would make everyone who has to look at it uncomfortable enough to ask questions, and a spreadsheet with a column labeled recoverable value reads like accounting. Exactly like it’s supposed to.
The underlying method is called the human life value approach, and it’s been taught for decades in every life insurance underwriting course in the country, in plain sight, as the standard way to calculate how much coverage a person qualifies to buy: take projected future earnings, discount them to present value, and that number is what a family is entitled to insure against losing. Nobody objects to this version. It is disclosed, licensed, printed in consumer brochures with a reassuring photograph on the cover, because it’s being used to help a family buy protection, and a number attached to protection reads as generous.
But what happens when the identical arithmetic, the same discounting and mortality tables get pointed the other direction, at a claim instead of a policy, to decide not what a family is owed but what a company is willing to spend keeping someone alive to collect it? I did not have to design anything new. I only had to change which direction the number was facing. The calculation is not complicated. It starts with projected earnings, discounted to present value, over the remaining actuarial life expectancy of the person in question, adjusted for the industry and region they are likely to work in, adjusted again for any known health conditions that might shorten that expectancy or reduce their earning capacity, and then, in the more sophisticated models, cross-referenced against household composition, because a dependent’s projected value is calculated separately from an income-earner’s, on the theory that a household absorbs a dependent’s loss differently than it absorbs an earner’s loss.
I am describing this at the level of detail I would use to train a new analyst, so you can see that there’s nothing mystical about it. Anyone with a spreadsheet and access to a mortality table could reproduce these results in an afternoon. Every number that comes out of a calculation like this one is a description. It says what happened, historically, to people who resembled you on the variables the model was given. It does not say what should happen to you.
The household-composition adjustment is the part that took me longest to question, because on its surface it looks like the model being careful rather than cold. The theory is straightforward: the economic loss to a household when an earner dies is different in kind from the loss when a dependent dies, because an earner’s death removes income the household was relying on, while a dependent’s death, in the model’s own language, removes a cost center. I have typed that phrase into a spreadsheet cell. Cost center. It is standard actuarial vocabulary, taught in the same textbooks that teach present-value discounting, and nobody who taught it to me, and nobody I ever taught it to, intended it as a description of a child. And still, it became one when the formula was applied to a file with a child’s diagnosis code in it, because the formula doesn’t know the difference between a line item and a person. Building a model that could tell the difference was never part of anyone’s job description, including mine.
A ten-year-old has no earnings history. A ten-year-old has, depending on the model, either a small positive projected value based on statistical averages for her demographic decades in the future, discounted so heavily by the time-value calculation that it approaches zero, or in some of the cruder models I’ve seen, a value of zero outright, because the model was built for adult claimants and nobody thought to ask what it would do when a child’s file passed through it. I have seen both versions running in production and built variations of both. The model doesn’t have a column for what a child is worth to the people who love her.
I defended this model in an internal review once. I’m not proud of the sentence I am about to write, but disclosure is the point of this document, so here it is anyway. I said the blindness was the feature, that the model didn’t know who you were, only what you were, biologically, actuarially, and that the not-knowing was honest. The part that protected the system from the very bias everyone was afraid of. Favoritism, discrimination, a reviewer’s thumb on the scale for reasons that had nothing to do with the numbers. I believed that, and may have even been right about the version of bias I was defending against. I did not understand that blindness is a resource like any other, and every resource in a system built to optimize for solvency eventually gets spent. The blindness would be the first thing sacrificed. Publicly it survives forever, in the speeches, testimony, and brochures with the photographs of diverse, smiling families on the cover. People defending the system may even go on believing it is alive. The sacrifice happens somewhere else, in a subroutine nobody audits because the audit would cost more than the subroutine saves, and it happens there because that’s the one place a blind system can still learn to see, if seeing turns out to be profitable.
I don’t know for certain that this happened to the model I built. There is a difference between what I witnessed and what I suspect. I witnessed a column with no room for a child. What I suspect but cannot prove, yet have decided to say anyway, is worse. I will come back to it.
I won’t tell you her name. She was ten years old. She had reactive airways, which we managed with two inhalers and a pediatrician who knew her by sight. She liked birds. Not birdwatching in the organized sense, with a book and a life list, just birds. Like dinosaurs or horses, her interest arrived without explanation and stayed. She could name most of what showed up outside a window if you gave her a minute.
She had a sister. I won’t describe her either, except to say that whatever account follows in the rest of this document, the part of it that is mine to grieve privately stays private, and the part that belongs to a surviving child is not mine to spend on strangers. I am telling you exactly as much as the argument requires and not one sentence more.
We lost our house in a fire that took twelve thousand homes in a single county in a matter of days. Twelve thousand homes is a manageable emergency by the standards of the agencies that respond to these things. We were assigned a stadium. I am not being figurative. Somewhere in the weeks after, breathing air that four separate people told her, in four separate tones of practiced reassurance, that she would get used to, she developed the kind of fungal infection in her lungs that shows up in immunocompromised patients and burn victims and, increasingly, in children who have spent enough consecutive nights breathing the chemistry a wildfire leaves behind. The treatment is expensive but works most of the time, if started early enough.
The claim was routed as investigational, a category built for treatments the reviewer’s software doesn’t have a matching approval code for, and the appeal was denied by a person following a document I could have written during any one of the thirteen years when that was my job.
The word investigational did more work in this story than its four syllables suggest. It does not mean unproven or unsafe. It means the coding system a particular insurer licensed had not yet assigned an approval category to a treatment protocol that most of the physicians administering it considered standard practice. The average lag from the inside runs into years. She had only the handful of days a coding gap happened to occupy.
She died in a hospital three hundred miles from the house that had burned down.
I have read enough of my own industry’s language to know what it looks like when grief is being used as leverage, and I do not want to use her that way. There is a difference between a statistic and a fact. I would rather you carry the fact.
An assignment, in insurance language, is the transfer of a right or a benefit from one party to another. A policyholder assigns benefits to a hospital so the hospital can bill the insurer directly. A beneficiary designation assigns a death benefit to a named survivor. The word appears on nearly every form you will ever sign in this industry.
I am going to tell you something I have never told anyone, including the lawyer who represented me and the reporter who called four times. The efficiencies I found did not stay inside the company that employed me. I want to be careful here, because I am at the edge of what I actually know and I am choosing to walk past that edge anyway. You deserve to see me do it in the open rather than pretend the ground under this section is as solid as the ground under the last one.
What I know: a portion of the modeling work my team produced, work built to price individual health and property risk for our own policyholders, was licensed, under a data-sharing arrangement I signed off on without reading past the summary page, to a consortium of firms whose business was not insurance. The summary page called it a strategic analytics partnership, describing the licensed work as anonymized behavioral and risk scoring methodology, a phrase built entirely out of words too abstract to picture. I now understand that’s the exact function abstraction serves in a document like that one. I signed it in an afternoon between two other meetings. Asking for details about their business was not part of my job, and I had spent enough years inside a structure that rewarded not asking that the silence had become the kind of reflex you no longer notice.
What I suspect: the methods I built to decide who was worth insuring were repurposed, somewhere downstream, to decide who was worth almost anything else. The same underlying architecture, the same recoverable-value logic, wearing a different label, priced into a different product, sold to a different kind of client. I have no document proving this, only the professional recognition of my handwriting on work I never signed, restructured just enough that a lawyer could argue it was independently derived.
Every system eventually develops a place where it stops explaining itself. Complexity accumulates faster than oversight, decision by defensible decision, until there is a room nobody visits anymore except the people who already have the keys. I built part of that room. I do not know everything that happens in it now. I am telling you that I do not know, because an account that only tells you what I am certain of is a defense rather than disclosure.
A total loss is the insurance term for a covered item damaged beyond the point where repair costs less than replacement. The company pays out the assessed value and moves on. The term exists because someone, decades ago, needed a word for the moment a system decides a thing is no longer worth saving in its current form.
Housing is where the sorting starts, because housing is the first system most families touch and the last one most of them think to question. A mortgage requires insurance. Insurance requires a risk assessment. A risk assessment, in a region facing repeated climate disaster, increasingly returns a single word: uninsurable. Because the geography surrounding the home has been assigned a loss probability high enough that no actuarial model can price a policy that both covers the risk and remains profitable to sell.
Nobody arrives to condemn the house. The homeowner simply cannot renew, and without renewal cannot hold the mortgage, and without the mortgage the house becomes, in the exact language the industry uses for a piece of collateral nobody wants anymore, “a stranded asset.” The family is more likely to lose the house in a letter than a fire, arriving on schedule to inform them that coverage won’t be offered at any premium. In most jurisdictions the language is required to be neutral, factual, and unemotional so that no one can later argue the letter itself caused harm. I’ve written many variations of that letter. We called the exercise portfolio derisking, a phrase that describes an insurer withdrawing exposure from a region and describes nothing about the family standing in the driveway of a house that has turned from an asset to a liability with its family still living inside.
The families who absorb this first rarely have the resources to absorb it. That is neither coincidence nor conspiracy. The sorting looks like fairness because it is applied by a formula. Unlike a person, a formula has no memory of why the land was cheap. It only has the current probability of loss, and the probability does not care how the family arrived at the address it’s now being priced out of.
The mechanism underneath the letter is called reinsurance, and almost nobody who receives the letter has ever heard the word, though it is the actual reason the letter exists. A primary insurer does not hold the full risk of every policy it writes. It transfers a portion of that risk to a reinsurer, a company that insures insurance companies, in exchange for a premium of its own, and the reinsurer prices that transfer using climate models built on decades of loss data, models that have gotten, in the years I worked adjacent to this side of the industry, considerably better at their actual job, which is forecasting where the water and the fire are going next. When a reinsurer raises its price for a given region, or declines to offer coverage in that region at all, the primary insurer’s own economics change overnight, regardless of how the primary insurer feels about the families it’s covered there for twenty years. The letter that arrives at the kitchen table is, in most cases, a decision made by an entity the family will never correspond with.
There is a sequence on this side of the business that repeats so reliably you could set an actuarial calendar by it. The model underestimates a region’s risk. The underestimate expresses itself as a disaster, the fire that outran the containment assumptions, the water that arrived where the maps said it was improbable. The disaster generates data. The data corrects the model. And the corrected model, more accurate now than it has ever been, reprices the survivors out of the homes they have just finished rebuilding, because the risk was always there and the instrument has finally caught up to it. Every loss makes the instrument sharper, and the sharpening is paid for by the people the instrument is pointed at. No metric I was ever asked to report could distinguish the model improving from the harm arriving in a second form, because inside the reporting, those were the same event, and the reporting was the only place anyone was required to look.
I built analyses that fed into exactly this chain, downstream of some of the most accurate forecasting instruments the industry has ever produced, and their accuracy is what makes the sorting so fast and so total. A model that is wrong sorts people inefficiently, leaving room for error and appeal. A model that is right arrives at the correct answer on schedule, even if that answer is a family standing in a driveway holding a letter that used, in an earlier draft I helped review, a warmer word than uninsurable, before someone in legal pointed out that warmer words invite warmer expectations, and warmer expectations invite lawsuits.
Eligibility sounds neutral. It is one of the most carefully engineered words used in the industry because eligibility criteria are rarely built to exclude a category of person directly. They are built to exclude a category of circumstance, then the correlation between circumstance and person does the rest of the work without anyone having to write the exclusion down.
A school district’s insurance carrier requires a fixed address for a student’s enrollment file to remain active without triggering a review. A family displaced by fire, foreclosure, or eviction does not have one in the sense the form requires, and the triggered review is not punitive in its language. Instead it asks reasonable questions. Is the student receiving consistent instruction? Is the household stable enough to support attendance? Does the family have access to the resources the district assumes every enrolled student has? A desk, a device, a quiet hour? None of these questions is unfair in isolation. Asked on a recurring basis, of a family that has already lost the fixed point every other form in their life also requires, the questions function as a slow, procedurally correct filter, sorting a child out of the system that was supposed to be the one stable thing left.
I watched an eligibility review happen to a child I know well. The review was conducted by a person who was, by every account, kind. The forms were filled out correctly. The outcome was still a report filed with a county agency, because the form required a report to be filed once certain boxes were checked, regardless of what the kind person filling it out believed about the family in front of her.
A single flagged review does not, on its own, produce a removal, denial, or loss of anything permanent. It produces a note in a file, and the note is reasonable, and the note is also now permanent, because very few of these systems are built with a mechanism for a note to expire once the circumstance that generated it has resolved. A family that stabilizes six months after a flagged review does not get the note removed. It gets a second note, on a later form, from a different reviewer, referencing the first, because the form includes a field for prior concerns, and the field is populated automatically, and a reviewer seeing two notes reads a pattern where a stranger seeing the first note in isolation would have read a single hard season.
I’ve seen a family’s file accumulate five separate notes across three different systems, school, housing assistance, a county eligibility office, none of which ever spoke to any of the others directly, each one entered by someone acting in good faith on the information available to them in that moment, and by the time anyone assembled all five notes into a single picture, the picture looked like a pattern of instability that no individual note, read alone, would have supported.
Notice the clock in all of this. The family flagged by a review has days to respond. The form says so, with a date on it. The systems doing the flagging run on a different calendar entirely. A wrong note takes minutes to enter and, in my experience, years to dislodge, if it ever dislodges, and the years in between are lived by the family and not by the system, because the system has no mechanism for experiencing an interval. The speed a system demands of the people it processes, set against the speed at which it corrects its own mistakes, is a transfer of resources as real as any premium. It is simply collected in time instead of money, from households that have the least of it to spare.
This is the design principle underneath most eligibility systems: a system does not need cruelty at the point of contact if it has already encoded the cruelty into the form. The person filling out the form can be entirely decent. The form does not care, and the form, unlike the person, has an excellent memory.
Medical necessity is the phrase an insurer uses to determine whether a treatment is required, as opposed to elective, convenient, or, in the industry’s coldest register, experimental. The phrase sounds clinical. In practice it’s one of the most contested and least examined pieces of language in the system, because the person determining necessity is rarely the person who understands the medicine best. They’re the person who understands the policy language best. The paperwork is built to make them look interchangeable.
A treatment can be standard of care, meaning the overwhelming consensus of the medical field agrees it’s the correct response to a given diagnosis, and still be denied as not medically necessary under a specific policy’s language, because the policy language was written to a different, narrower standard, often years before the treatment became standard of care at all. The gap between when medicine updates its understanding and when a policy document updates its language isn’t small. In the cases I personally reviewed, the average gap ran between three and seven years, and every claim that arrived inside that gap was correctly denied, according to the document, and incorrectly, according to the medicine. There is no field on the form for that distinction.
There’s a related mechanism, less visible than a flat denial, called step therapy, which requires a patient to try and fail on a cheaper treatment before the insurer will authorize a more expensive one, even when the prescribing physician believes the more expensive treatment is clearly indicated from the start. Policy language for step therapy is not written as cruelty. It is written as stewardship, a reasonable-sounding requirement that a system confirm the inexpensive option genuinely doesn’t work before it approves the expensive one, and in most cases involving most conditions, this requirement costs a patient weeks, not lives. I built exception criteria for step-therapy protocols, cases where the requirement would be waived because failing first was medically dangerous rather than merely inconvenient, and I remember how narrow those exception criteria were kept, year over year, each renewal cycle. Every exception widened was a projected cost increase, and it had to be defended in the same room where the recoverable-value columns got defended, by the same people, using the same language.
The appeals process exists to catch these cases. Most people who have never filed an appeal imagine it as a conversation. It is not a conversation. It is a second determination, run by a different reviewer, against the same policy language, and unless the appellant can produce new information the first reviewer didn’t have, which most people can’t, because most people don’t have access to the internal coding manuals that would tell them what information would move the needle, the second determination usually returns the same answer as the first.
When an appeal does succeed, and the industry will tell you, accurately, that a meaningful share of appealed denials get overturned, the number is presented as evidence that the system corrects itself. I helped present that number. Here is what it measures: how often a family had the time, the literacy, the standing, and the money to keep fighting. It says nothing about how often the denial was wrong, because the denials that were wrong and never fought do not appear anywhere. There is no column for them. A family that accepts a wrong denial because the appeal deadline fell in the same week as a funeral is recorded, everywhere it is recorded at all, as a correct determination.
There’s a step after that one, and an honest document doesn’t get to skip its own exceptions. After the internal appeals are exhausted, a policyholder is entitled, on most plans, to an independent external review, conducted by a reviewer with no relationship to the insurer, who can overturn the denial outright. This exists because state regulators fought for it, and it works often enough that the industry has spent considerable effort making sure fewer people reach it than are entitled to. Most policyholders don’t know it exists, because the letter that discloses the right is written in the same seven-point register as everything else the letter needs you not to read closely. Some of the largest employer plans in the country are governed by a different federal framework entirely and aren’t required to offer the same external review. Most employees have no idea which kind of plan they’re enrolled in, because the enrollment materials aren’t required to tell them plainly, and the difference between frameworks isn’t something a person under deadline pressure, holding a denial letter with a ticking clock, has the time or the training to untangle. The exception is real. It just wasn’t built for the timeline a sick child actually has.
I built the variance analysis that let the company cut its post-claim review cycle by forty percent, and the internal appeals layer, the one a claim has to survive before it ever reaches an independent reviewer, runs that much faster because of work with my name on it. I was proud of it at the time. I didn’t think, until much later, to ask what a forty percent faster cycle actually improved. I know the answer now. It improved the average handling time metric, which improved the quarterly efficiency report, which improved the number a room full of people I liked used to describe, to each other and eventually to a board, how well the department was performing the exact function I no longer believe it was ever meant to perform.
There is a page in this document I wrote before every other page, in a chair beside an ICU bed, the night the hospital’s billing office paid its first visit. I am placing it here unrevised.
The hospital came in today to tell me that I owe eighty-seven thousand dollars for four days of my daughter’s life.
The hospital came in today to tell me that the bill is growing by twenty-three thousand dollars every day.
The hospital came in today to tell me that the meter keeps running while my daughter sleeps.
My daughter is not sleeping. My daughter is unconscious. The hospital does not know that distinction because the distinction is not relevant to the bill. The hospital sees a patient, a room number, a length of stay, and a balance due. The hospital does not see my daughter.
This is not a hospital failure. The hospital is functioning exactly as designed. The people in this building are trying to save my daughter. Some of them are breaking rules to do it. The bill is functioning exactly as designed too. The failure is further upstream.
The failure is in the architecture. The failure is in a system that allowed the question of whether my daughter receives medicine to become a budgeting decision made by a man who has never met her. The company took my premiums for thirteen years. Then, on the day my daughter began coughing up blood, it discovered a reason not to pay. The company has not failed. The failure is that we built a world where my daughter’s lung tissue and a quarterly earnings report are allowed to occupy the same equation.
A loss ratio is the share of every premium dollar an insurer pays back out in claims. Regulators require it to stay above a set floor, usually eighty to eighty-five percent, on the theory that an insurer paying out less than that is charging more than it needs to and should be made to lower its rates or refund the difference. On its own terms, it’s a reasonable instrument, built to keep an insurer honest about how much of your money is going toward your care.
What a loss ratio doesn’t do, and was never built to do, is distinguish between a company that’s losing money because the population it covers has gotten sicker, and a company that decided its covered population is no longer worth the trouble of keeping.
The company that employed me withdrew individual health coverage from an entire state over a period of five months, citing, in its public filings, a loss ratio that had crossed the threshold at which the state’s regulator would have required it to keep offering coverage at something closer to cost. The filing was accurate. The number was real. What the filing left out, because filings aren’t required to include it, is what happened to the people who held those policies once they were no longer offered.
I built a version of this accounting myself. Roughly eight hundred thousand people held individual policies with the insurer in question at the time of the withdrawal. Of those, internal modeling, the kind I used to run, projected that a defined percentage would successfully transition to a comparable employer-sponsored plan, a defined percentage would qualify for a public program, and the remainder, a number in the low six figures, would experience what the model called a coverage gap of undetermined duration. Undetermined duration is the phrase the industry uses when it knows the answer and has determined it doesn’t have to be reported.
I have since learned, from public health data that was far harder to find than the original filing was to produce, that the coverage gap for a meaningful share of that population lasted, on average, past eleven months. Over that same window, the mortality rate for chronic-condition patients in that population rose at a level the underlying model had, in fact, projected within a narrow margin. The model was accurate. Nobody was required to publish what the model already knew, because a loss ratio only measures what a company pays against what it collects. It has never been required to measure what a withdrawal costs the people who are no longer collected from at all.
There’s a final piece of vocabulary I want to give you, because once you have it you’ll start hearing it everywhere, the way you start noticing a car you’re about to buy in every parking lot. When an insurer stops writing new policies in a market but is still legally obligated to service the policies in force, the remaining book of business is called the runoff. It’s treated, internally, as a wind-down asset, valued not for its future but for how cleanly it can be closed. Staffing on a runoff book is reduced. Claims processing slows, not through any directive that says slow down, but through the ordinary attrition of a team that knows its department is being sunset and has, understandably, already started applying elsewhere.
A policyholder inside a runoff book experiences this as a company that has stopped answering the phone as quickly as it used to. There’s no requirement anywhere that a policyholder be told their policy has entered a wind-down classification, only that their claims keep being processed under the terms of the policy, which they are, eventually, by a shrinking team, at a pace nobody has to disclose in advance.
A system doesn’t have to hide a number to make it disappear. It only has to decide, correctly and legally, that the number belongs to someone else’s ledger. Every family the company exited became, on the date of exit, someone else’s statistic, someone else’s emergency room, someone else’s unfunded mandate, and the company’s own books closed clean, because the books were never required to follow the person past the door. The company didn’t choose to hurt eight hundred thousand people. It chose to stop being the party whose ledger recorded what happened to them. A system that can carry a person one fiscal quarter and learn, entirely lawfully, to spend her the next, has merely finished its math and moved the remainder to a column no one downstream is required to open.
I am not a policy expert in the sense of someone who writes legislation. I am an analyst who spent thirteen years learning exactly where the machinery breaks, and I think the people who come after me are entitled to what I learned, laid out plainly, as something closer to a blueprint than a complaint. Here is what I would build instead.
Every automated system that determines a benefit, a coverage, a rate, or an eligibility outcome for a human being should be required to publish, in plain language, not the algorithm itself but the complete list of variables the algorithm considers and the direction each variable moves the outcome. Not a summary or a simplified version written by a communications team. The actual list the engineers work from, translated at a reading level a policyholder without a graduate degree can use to understand why her own file returned the number it returned.
I’ve seen company after company argue that this transparency would let people game the system. I have sat on the other side of that argument in a boardroom, and the objection was never really about gaming. It’s about the discomfort of being seen. A system that cannot survive being fully described to the people it governs is a trap with excellent manners.
Every model that assigns a recoverable-value estimate to a human life should be required to disclose that it does so, in the document the policyholder signs, in the same typeface as everything else, not the seven-point font at the bottom of page four. If an insurer is willing to price a life, the insurer should be willing to say so out loud, to the person whose life is being priced, before the money changes hands. I do not believe most companies would survive that disclosure with their pricing models intact. A model too indefensible to describe to the person it is modeling is a model that shouldn’t exist, and the fastest way to retire an indefensible model is to require it to introduce itself.
Every determination that denies care, coverage, or benefit to a person under eighteen should require a named human signature, not a routing code, attached to a stated reason drawn from a finite, published list of permissible reasons, with that reason and that name entered into a public registry searchable by anyone. This is the same accountability we already require of every other profession whose decisions can end a life, extended, finally, to the profession that spends the most money deciding whose life is worth extending.
Every household displaced by a declared disaster should retain full coverage continuity for a minimum of eighteen months regardless of address stability, employment status, or any other variable that a displacement itself renders temporarily unmeasurable. A system that penalizes a family for the instability the system’s own disaster caused is compounding risk, on a schedule, against the people least equipped to absorb it.
Companies leave markets constantly. That’s a legitimate business decision, and I’m not arguing otherwise. But it isn’t legitimate for a company to walk away from a population it spent decades pricing, the day after that population’s risk profile stops being profitable, and leaving the transition to chance. To churches, or whatever remains of a state’s residual insurance pool, which is itself usually the insurer of last resort because every other insurer has already declined the risk.
Every company that exits a market it’s priced out of profitability should be required to fund, for a period equal to the number of years it operated in that market, an independent transition authority responsible for placing every displaced policyholder with continuous coverage before the exit is permitted to take effect.
Every model that determines a recoverable-value estimate should be subject to independent, adversarial certification at a fixed interval, conducted by a body with no financial relationship to the company being certified, empowered to test the model not against the company’s own validation data but against outcomes the company did not select. That certification verifies that the model performs well on the cases the model’s authors expected it to see, but it says nothing about the cases nobody thought to construct, which are (without exception) the cases that eventually reach a courtroom or a newsroom, because those are the only two institutions currently positioned to construct them after the fact, at a cost, in money and in years, that a family should never have been required to pay in order to be seen by the thing that was supposed to be seeing them all along.
Every appeal of a denied claim should be heard, at the final stage, by a reviewer employed by neither the insurer nor a firm the insurer retains, funded instead through a pooled assessment collected from every insurer operating in a given market. I built appeals systems for a company that also employed, trained, and evaluated the reviewers hearing those appeals. I don’t believe a single one of those reviewers was dishonest. I believe, having watched the incentive structure from the inside, that honesty and independence are not the same property, and a system that only asks for the first while structurally foreclosing the second will keep returning the same determination on appeal that it returned the first time, for reasons that have nothing to do with any individual reviewer’s integrity and everything to do with whose paycheck depends on which answer.
Every insurer that reports a loss ratio to a regulator as justification for withdrawing from a market should be required, in the same filing, to report the projected downstream outcome of the withdrawal for the population being exited: the modeled coverage-gap duration, the modeled change in mortality and morbidity for chronic-condition holders, the modeled number of households expected to lose housing as a secondary consequence of losing coverage. I know these models exist, because I built variants of several of them, run for internal planning only, in the same quarter the public filing was drafted to omit them. A loss ratio currently measures only what a company pays against what it collects. It has never been required to measure what a company’s absence costs the people it stops collecting from at all, and a regulator cannot weigh a decision honestly when only one side of its ledger is a matter of public record.
None of this requires burning anything down. I am describing a list of the disclosures, signatures, continuities, and transparencies a system would need to publish before I would trust it to hold anyone’s life in a column again. CLEAN SLATE.
An impairment, in underwriting language, is a condition that reduces the accuracy of a risk assessment. A car with a cracked frame is impaired collateral. A witness whose memory of an event has degraded is an impaired witness, in the specific legal sense that a court will weigh their testimony differently once the impairment is disclosed. I am disclosing mine.
My sleep has been terrible for a while now, and so these days I’m not terribly reliable about sequence: which conversation happened before which other one, whether a detail I’m certain of actually occurred or arrived later, assembled from grief and repetition into something that now feels indistinguishable from memory. I haven’t gone back through this document line by line to check every claim against a record, because in most cases there’s no record left to check against, and because I’m not confident I’d trust my own review if I ran one.
I’m telling you this now, near the end rather than the beginning, because I think a disclosure made too early gives a reader permission to discount everything that follows, and I needed you to read the rest of this on its own terms. I also think a disclosure withheld until the end is a kind of dishonesty I’m no longer willing to practice, having spent a career watching companies withhold exactly this kind of material fact until the moment it could do the least damage to them.
Some of what is in this document may be imprecise in its sequence. None of it, as far as I can tell, is imprecise in its substance. I built the models and saw the denial happen. I don’t need a perfect memory to stand behind that.
I’m not revising this document to account for the impairment. A revision implies there’s time for one, and a version of me still around to be trusted to make it honestly rather than defensively.
I’ve thought about whether admitting this undermines what I’ve written and have decided, after more time turning the question over than I’m proud of, that the opposite is true. Every document I helped a company produce disclosed its own limitations somewhere, usually on a page numbered high enough that few readers reached it, in language that would satisfy a regulator while staying vague enough to reassure everyone else. I learned that craft from experts. I’m choosing not to practice it. If a reader can’t trust an impaired witness who tells you plainly that she is impaired, I don’t know what standard of trust that reader is prepared to extend to anyone.
I would rather lose a reader to honesty than keep one through the kind of careful omission I spent a career perfecting.
Proof of loss is the document a policyholder is required to submit before a company will pay a claim. It’s supposed to establish, beyond reasonable dispute, that the loss happened, that it happened the way the claimant says, and that the value being claimed is the actual value of what was lost.
I have spent this entire document trying to write mine. I do not know what proof looks like for a loss like this one. There is no adjuster who will drive out and inspect it, no photograph that captures the dimensions of what a system extracts when it takes a child the way this one took mine, no comparable-sale data to establish fair value for a decade you don’t get to have. I have thirteen years of training in exactly this kind of documentation and none of it prepared me to file a claim on my own behalf, because the entire discipline was built on the premise that the one filing and the one suffering the loss are, in the abstract, the same person (never in the room, never at the desk). I have now been both and the training doesn’t transfer.
What I have instead of proof is an account. Everything in this document happened, to the best of an impaired witness’s understanding. I have spent enough of my life inside silence built and priced and approved by other people that I am not willing to spend what remains of it inside one I built myself.
I spent my career telling policyholders that the burden of proof rested with them. That the company would consider their claim once they had assembled the required documentation, in the specified format, by the set deadline, and that any gap in that documentation, however small or unrelated to the truth of the loss, was sufficient grounds for denial.
I understand, filing this, that I am now the policyholder, and that I haven’t met my own standard. I don’t have the documentation. Some of it burned. Some of it was never mine to keep. Some of it exists only inside a mind I have already told you not to fully trust. I’m filing anyway, in direct violation of the standard I spent a career enforcing on people who had far less than I do to file with, and I think that violation is, itself, part of what I’m trying to say. The standard was never really about proof. It was about who got to set the terms of what counted as proof, and I no longer believe the answer should always be the party with the most to lose by paying the claim.
I wrote a sentence into an early draft of this document that I promised myself I would keep, whatever else got cut: I am writing this because I am about to be silent. The silence will not be mine. The silence will be a contract.
I don’t know who reads this. I don’t know what becomes of it once it leaves my hands, and I’m not sure what I believe instead, except this: Every policy eventually reaches its term. Most lapse, unclaimed, unnoticed, the reason for them long since forgotten by everyone but the person who once needed the coverage. But some policies are held all the way to maturity, and when they are, decades later, they pay out in full, to someone who was not yet born when the first premium was paid. I don’t know if this is a policy anyone will hold that long. I’m filing it anyway. Somebody has to start the record.