Prior authorization stalls care when nobody owns it. The fix is structural, not heroic: flag prior-auth-required services at scheduling rather than at check-in, keep a living payer requirements sheet, submit a complete packet the first time, and review a small set of metrics every week. Federal policy is pushing in the same direction. Under the CMS Interoperability and Prior Authorization final rule (CMS-0057-F, published January 2024), impacted payers must send prior authorization decisions within 72 hours for expedited requests and seven calendar days for standard requests, must give a specific reason for a denial, and must publicly report prior authorization metrics — with these operational requirements generally beginning January 1, 2026. Practices that build the workflow now will be positioned to exploit the payer-side APIs when they arrive.
What the CMS rule changes — and what it does not
CMS-0057-F applies to a defined set of "impacted payers": Medicare Advantage organizations, state Medicaid and CHIP fee-for-service programs, Medicaid managed care plans, CHIP managed care entities, and Qualified Health Plan issuers on the Federally Facilitated Exchanges. Here is what it obligates them to do, and roughly when.
| Requirement | Who it binds | CMS compliance timing |
|---|---|---|
| Decisions within 72 hours (expedited) and 7 calendar days (standard) | Impacted payers, excluding QHP issuers on the FFEs | Operational provisions generally beginning January 1, 2026 |
| Specific reason given for every denial, regardless of how the request was submitted | Impacted payers | Beginning in 2026 |
| Annual public reporting of prior authorization metrics on the payer's website | Impacted payers | Initial metrics reported by March 31, 2026 |
| FHIR-based Prior Authorization API (covered items, documentation requirements, request and response) | Impacted payers | Beginning January 1, 2027 |
| Provider Access API and Payer-to-Payer API | Impacted payers | By January 1, 2027 |
| New "Electronic Prior Authorization" measure under Promoting Interoperability | MIPS eligible clinicians; eligible hospitals and CAHs | CY 2027 performance / EHR reporting period |
Build a payer requirements sheet
The single artifact that separates practices that handle prior auth well from practices that do not is a maintained requirements sheet. One row per payer, one owner, one "last verified" date. Columns worth having:
- Payer and plan type (MA, Medicaid managed care, commercial, exchange)
- Services and CPT/HCPCS ranges that require authorization
- Submission channel, in order of speed — portal, API, fax, phone
- Stated turnaround commitment for expedited and standard requests
- Documentation checklist for the most common requests
- Appeal deadline and appeal channel
- Portal credentials owner (a role, not a person's personal login)
- Date last verified
Verify it quarterly and after any contract change. A requirements sheet that is eighteen months stale is worse than none, because staff trust it.
A five-step prior authorization workflow
- Identify at scheduling. The service is flagged as authorization-required at the moment the appointment is booked, not when the patient is standing at the desk. This is the highest-leverage change most practices can make, and it costs nothing but a rule in the scheduling template.
- Verify eligibility and benefits first. Authorizing a service under a plan the patient no longer has is a common and entirely avoidable waste.
- Assemble the packet once, completely. Incomplete first submissions are the most common cause of avoidable delay. Use the payer's own documentation checklist and the payer's own medical policy language.
- Submit through the fastest channel and log it. Reference number, date, time, submitter, channel, and the exact scope requested. If it is not logged, it did not happen.
- Track to decision. Set a tickler based on the payer's stated turnaround. Escalate the day it lapses — not the week after someone notices.
Who owns what
| Role | Owns |
|---|---|
| Scheduler | Flags authorization-required services at booking; captures the order and working diagnosis |
| Prior auth coordinator | Assembles documentation, submits, logs, tracks to decision, escalates |
| Clinician | Signs the clinical justification; conducts peer-to-peer reviews |
| Billing / RCM | Confirms the authorization number appears on the claim; catches PA-related denial codes |
| Practice manager | Owns the payer requirements sheet and the weekly metric review |
Small practices object that they do not have a dedicated prior auth coordinator. That is fine — the role can be a hat, not a headcount. What is not fine is the role being unassigned, because then it is nobody's, and the work surfaces only when a patient calls angry.
The metrics that actually move the needle
Track these weekly. Trend your own baseline rather than chasing a benchmark you read somewhere.
- Volume by payer and by service — tells you where to spend your process effort
- Percent submitted within one business day of the order — the metric you fully control
- Median days from order to decision, split by payer
- First-pass approval rate — a low rate almost always means an incomplete packet, not an unreasonable payer
- Percent of denials overturned on appeal — a high overturn rate means you are being denied on things you should have won upfront
- Appointments rescheduled or cancelled for a pending authorization — the only metric that measures patient harm directly, and the one to report to the clinicians
- Claim denials carrying a prior-auth-related reason code — the leak at the far end of the pipe
Denials, appeals, and peer-to-peer
CMS now requires impacted payers to state a specific reason for a denial, regardless of whether the decision came by portal, fax, email, mail, or phone. Use it. The moment a denial arrives:
- Categorize the reason: missing documentation, medical necessity, coding error, non-covered benefit, or administrative.
- Calendar the appeal deadline the same day. Missed appeal windows are pure, self-inflicted revenue loss.
- Treat missing-documentation denials as a workflow bug. Do not just resubmit — fix the checklist so that request type never goes out short again.
- Prepare the clinician for peer-to-peer. Hand them the payer's own medical policy, the specific criteria at issue, and the chart elements that satisfy them. Do not send a physician into a peer-to-peer cold.
- Trend denials by payer and reason. A consistent pattern with a single payer is a contracting conversation, not a coordinator problem.
Getting ready for the payer APIs
The API provisions of CMS-0057-F are obligations on payers, not on practices — but they only pay off for you if your systems can meet them halfway.
- Ask your EHR and practice-management vendor, in writing, what their roadmap is for the FHIR-based Prior Authorization API and the Da Vinci implementation guides CMS recommends (coverage requirements discovery, documentation templates and rules, and prior authorization support).
- Understand the new Electronic Prior Authorization attestation measure under Promoting Interoperability, which begins with the CY 2027 performance period for MIPS eligible clinicians and the CY 2027 EHR reporting period for eligible hospitals and CAHs.
- Clean your data now — accurate payer identifiers, provider NPIs, and a defensible standard documentation set per service line. An API cannot fix a bad packet; it will just deliver it faster.
- Do not dismantle the portal and fax workflow. The rollout is phased and payer-side, and the plans outside the rule are not going anywhere.
Prior authorization will not stop being annoying. It can stop being chaotic, and the difference between the two is about a day of setup and a fifteen-minute weekly review.
Common questions
How fast do payers have to decide a prior authorization request?
Under CMS-0057-F, impacted payers (excluding QHP issuers on the Federally Facilitated Exchanges) must send decisions within 72 hours for expedited requests and seven calendar days for standard requests, with these operational provisions generally beginning January 1, 2026. Plans outside the rule follow their own contracts and state law.
Does the CMS prior authorization rule cover drugs?
No. The rule's prior authorization provisions expressly exclude prior authorization for drugs.
Which plans count as "impacted payers"?
Medicare Advantage organizations, state Medicaid and CHIP fee-for-service programs, Medicaid managed care plans, CHIP managed care entities, and Qualified Health Plan issuers on the Federally Facilitated Exchanges.
What is the single highest-leverage change a small practice can make?
Flag authorization-required services at scheduling instead of at check-in, and submit a complete packet the first time. Incomplete first submissions are the most common cause of avoidable delay.