Skip to content

Industry-specific operational data

Payer medical and coverage policy documents for RAG and criteria-matching models

Quick answer

A usable payer policy corpus has three layers with different rights: public Medicare NCD and LCD text, publicly posted commercial medical policies, and non-public material such as licensed criteria sets and internal desk procedures. Public posting is not a license. CPT descriptors in LCDs and billing articles sit behind AMA terms, commercial websites carry their own reuse terms, and proprietary criteria are generally not redistributable. Every chunk also needs effective and retirement dates so answers cite the version in force on the date of service.

By SourceX Editorial · Updated

This page is general information, not legal advice. Confirm requirements with counsel for your jurisdiction and use case.

Which payer policy sources exist, and what each one can support

Payer policy text falls into five source classes, and only some of them can be bought as a dataset. For a prior-authorization or denial-prevention RAG system, the classes differ less in content than in rights, update cadence and how well versions are preserved.

  • Medicare National Coverage Determinations (NCDs) and Local Coverage Determinations (LCDs) with billing and coding articles. CMS publishes these in the Medicare Coverage Database (MCD), which offers downloadable data sets alongside the document view pages.
  • Commercial and Medicare Advantage medical policies, clinical policy bulletins and reimbursement policies posted on payer websites, usually as PDFs or HTML with revision histories at the bottom.
  • Third-party clinical criteria sets such as InterQual and MCG, which plans license and apply in utilization management.
  • Aggregated policy databases. Policy Reporter's PolicyCore, for example, describes (as of October 2026) 850,000+ current and historical policies across medical, pharmacy and reimbursement policies, PA forms, coding guidelines and provider manuals [3]. Treat vendor figures as market practice, not verified counts.
  • Internal desk procedures, interpretation notes and reviewer job aids held by payers, delegated UM vendors and provider revenue-cycle teams. This is the non-public slice that explains how a policy is actually applied.

What rights cover public NCD and LCD text

Medicare coverage text is public, but the CPT codes and descriptors embedded in LCDs and billing articles are not free to reuse. CPT is an American Medical Association copyright, and the MCD presents AMA, ADA and NUBC user agreements before showing coded content and downloads. Read the agreement text you accept and record the date, because its scope governs what you may do with code descriptors.

The practical consequence is that a corpus built from MCD downloads carries an AMA licensing question the moment it stores CPT descriptors and serves them in RAG answers or redistributes them to customers. Teams typically separate the narrative coverage text from code tables, store codes as bare identifiers joined at query time from a source the company is separately licensed for, and keep a record of which license covered each field. Confirm the scope with counsel and with your own CPT license, because the click-through terms were not reviewed for this page.

Two technical gaps also matter. Check whether the download set includes supporting attachments, which are often reachable only from each document's view page. Retired LCDs and articles can move out of the current download set to the MCD archive, so a corpus that needs multi-year history should snapshot versions rather than rely on the latest download.

Why publicly posted commercial policies are not automatically licensed

A commercial payer's website posting makes a policy readable, not licensed for ingestion, embedding and retrieval in a commercial product. Website terms of use can restrict copying, automated collection and commercial reuse, and those terms change over time. Scraping payer sites at scale also produces a corpus whose provenance you cannot document for a customer's security or legal review.

Medicare Advantage plans add a regulatory wrinkle. Under 42 CFR 422.101(b)(6), when Medicare coverage criteria are not fully established, MA organizations may use internal coverage criteria based on current evidence, and those criteria must be publicly accessible [1]. That obligation increases what you can read; it does not grant a reuse license. CMS guidance on coverage criteria and algorithm use in MA determinations [1] also means customers will ask which criteria a model relied on, and third-party criteria such as InterQual and MCG are exactly the material a RAG product must not ingest without a license from the criteria owner.

How to license the non-public layer: criteria sets and desk procedures

Proprietary criteria sets are licensed to plans and providers for use, and those licenses generally do not allow the licensee to hand the content to a third-party AI vendor. If your product needs criteria logic, the cleaner routes are a direct agreement with the criteria publisher or a design that retrieves only a customer's own licensed copy inside the customer's tenant.

Internal desk procedures are different. They are typically authored by the payer or vendor organization itself, so the holder can license them, subject to employee-authorship and confidentiality checks. Useful document types include:

  • Reviewer job aids that map a policy section to the clinical documentation a nurse reviewer looks for.
  • Interpretation memos explaining how ambiguous criteria such as "failed conservative therapy" are applied.
  • Policy change bulletins and provider notices with effective dates.
  • Pend and denial reason mappings that tie policy sections to letter language, which matters because CMS-0057-F requires impacted payers to give specific reasons for denials [2].

These records may contain member examples. Health records require HIPAA de-identification by Safe Harbor or Expert Determination before delivery [4]. See PII redaction for LLM training data for how to measure what redaction misses, and employee-authored records for ownership checks on internally written procedures. SOP-style corpora outside payers are covered on the SOPs and playbooks page.

Rights and freshness decision table by source class

The decision you make per source class is whether it can enter the index, under what license, and how you will keep it current.

Illustrative example: invented to show structure; it does not describe an available dataset.

Source classCan it enter a commercial RAG index?Rights evidence to keepVersion riskTypical refresh
NCD narrative textUsually yes for narrative; check embedded codesMCD download date, license acceptance recordLow; reconsiderations change textMonitor MCD
LCD and billing article code tablesOnly under a CPT license covering your useAMA license scope, field-level lineageHigh; codes revised oftenWeekly diff
Posted commercial and MA policiesOnly with permission or a reviewed basisWebsite terms snapshot, permission letterHigh; silent revisionsPer-payer crawl of your licensed sources or vendor feed
Third-party criteria sets (InterQual, MCG)No, unless licensed from the publisherPublisher agreementAnnual editionsPer edition
Internal desk procedures and job aidsYes, if the holder licenses themLicense, authorship review, de-identification recordMedium; local editsPer delivery

How to model policy versions so answers cite the right one

A coverage answer is only correct for a date of service, so every chunk must carry the policy's effective date, retirement date and revision lineage. The most common failure is a retriever that returns the newest policy for a claim whose service date fell under the prior version, or that mixes two revisions in one answer. The RAG corpus quality guide covers dedup and conflict handling in general.

Store each version as an immutable record and filter by date before semantic ranking. A JSON Lines file, one UTF-8 record per line, is a convenient interchange format for this [5].

Illustrative example: invented to show structure; it does not describe an available dataset.

{"doc_id":"PAYER-A-MP-0412","version_id":"PAYER-A-MP-0412-r7","source_class":"commercial_medical_policy","line_of_business":["commercial","medicare_advantage"],"title":"Lumbar spinal fusion","effective_date":"2026-03-01","retired_date":null,"supersedes":"PAYER-A-MP-0412-r6","section_path":"Coverage criteria > 2.b","text":"Conservative therapy of at least six weeks...","code_refs":[{"system":"CPT","code":"22612","descriptor_stored":false}],"criteria_dependency":"none","license_id":"LIC-2026-031","rights_basis":"holder_license","phi_status":"none","retrieved_from":"supplier_export","sha256":"..."}

Fields worth enforcing: effective_date and retired_date for date-of-service filtering; supersedes for lineage; descriptor_stored to prove CPT text is not stored; criteria_dependency to flag policies that defer to a licensed criteria set you do not hold; and license_id plus rights_basis so each answer can be traced to its permission.

How to evaluate a payer policy RAG system

Evaluate on date-of-service correctness and criteria coverage, not just answer fluency. Build a test set where each question carries a service date, a line of business and a gold policy version, then score retrieval on whether the correct version is in the top results and generation on whether every cited criterion exists in that version.

Include hard negatives: the superseded version, the same policy for a different line of business, and the matching LCD from a different MAC jurisdiction. The distractor and near-duplicate retrieval guide explains how to construct them. For criteria extraction, score field-level precision on thresholds (durations, lab values, prior-treatment counts) and flag answers that cite a criteria set your license does not cover.

Ground-truth outcomes come from downstream records. Pairing policies with utilization management review records or prior authorization packets and decisions lets you test whether retrieved criteria predict the actual determination.

Questions to ask a supplier of payer policy data

Ask for evidence per document, not a blanket statement. Before signing, request:

  1. The source class of every document and the rights basis for each class.
  2. Whether CPT, CDT or other licensed code descriptors are present, and under whose license.
  3. Version history depth, including retired versions and how retirement dates were captured.
  4. Whether attachments, revision tables and provider bulletins are included.
  5. Authorship and confidentiality review for internal procedures.
  6. De-identification method and sample-check results for any record that touched member data.
  7. Delivery format, document IDs stable across refreshes, and a change feed for updates.

Buyers working across health administration data can start from healthcare administration buyers, and teams building document retrieval evaluations can see RAG evaluation datasets from company documents. Related industry corpora include hospital policy and procedure manuals; the industry data hub lists the rest. If you need the non-public layer, you can describe the payer policy data you need to SourceX.

Source licensed payer policy and procedure data through SourceX

SourceX sources operational datasets from US companies on request, including documents and finance and legal workflows, and does not source scraped web content. Every dataset is rights-reviewed for ownership and consents, personal details are removed or replaced before delivery, and health records require HIPAA de-identification; nothing is contracted until a supplier agrees. Describe the payer policy and desk-procedure data you need.

Frequently asked questions

Can I build a corpus from the Medicare Coverage Database downloads alone?

You can obtain NCD, LCD and article text that way, but you accept AMA, ADA and NUBC user agreements first, attachments may be excluded, and retired versions may move out of the current download set. Plan for code licensing and your own version snapshots.

Do Medicare Advantage transparency rules let me reuse plan criteria?

No. The requirement that internal coverage criteria be publicly accessible [1] makes the criteria readable for review. Commercial reuse in a product still depends on the plan's terms or an explicit license.

How often should a payer policy index refresh?

Local coverage documents change frequently, and commercial payers revise policies on their own schedules. A weekly diff with version-level change detection is a reasonable baseline; confirm each source's cadence.

Sources

  1. McDermott Will & Emery, "CMS Releases Guidance on Coverage Criteria, Use of AI and More" (2024). https://www.mcdermottlaw.com/insights/cms-releases-guidance-on-coverage-criteria-utilization-management-and-use-of-ai/
  2. Centers for Medicare & Medicaid Services, "CMS Finalizes Rule to Expand Access to Health Information and Improve the Prior Authorization Process" (2024). https://www.cms.gov/newsroom/press-releases/cms-finalizes-rule-expand-access-health-information-and-improve-prior-authorization-process
  3. Policy Reporter, "PolicyCore Current Policy Database". https://www.policyreporter.com/policycore/current-policy-database/
  4. U.S. Department of Health and Human Services, Office for Civil Rights, "Guidance Regarding Methods for De-identification of Protected Health Information in Accordance with the HIPAA Privacy Rule" (2012). https://www.hhs.gov/hipaa/for-professionals/special-topics/de-identification
  5. jsonlines.org, "JSON Lines". https://jsonlines.org/

Tell us what your models need

Share scope, volume, language, format, timing and licensing requirements.

Request data