Billing & RCM

Prior Authorization Workflows That Don't Stall Care

Prior authorization stalls care when nobody owns it. The fix is structural, not heroic: flag prior-auth-required services at scheduling rather than at check-in, keep a living payer requirements sheet, submit a complete packet the first time, and review a small set of metrics every week. Federal policy is pushing in the same direction. Under the CMS Interoperability and Prior Authorization final rule (CMS-0057-F, published January 2024), impacted payers must send prior authorization decisions within 72 hours for expedited requests and seven calendar days for standard requests, must give a specific reason for a denial, and must publicly report prior authorization metrics — with these operational requirements generally beginning January 1, 2026. Practices that build the workflow now will be positioned to exploit the payer-side APIs when they arrive.

What the CMS rule changes — and what it does not

CMS-0057-F applies to a defined set of "impacted payers": Medicare Advantage organizations, state Medicaid and CHIP fee-for-service programs, Medicaid managed care plans, CHIP managed care entities, and Qualified Health Plan issuers on the Federally Facilitated Exchanges. Here is what it obligates them to do, and roughly when.

RequirementWho it bindsCMS compliance timing
Decisions within 72 hours (expedited) and 7 calendar days (standard)Impacted payers, excluding QHP issuers on the FFEsOperational provisions generally beginning January 1, 2026
Specific reason given for every denial, regardless of how the request was submittedImpacted payersBeginning in 2026
Annual public reporting of prior authorization metrics on the payer's websiteImpacted payersInitial metrics reported by March 31, 2026
FHIR-based Prior Authorization API (covered items, documentation requirements, request and response)Impacted payersBeginning January 1, 2027
Provider Access API and Payer-to-Payer APIImpacted payersBy January 1, 2027
New "Electronic Prior Authorization" measure under Promoting InteroperabilityMIPS eligible clinicians; eligible hospitals and CAHsCY 2027 performance / EHR reporting period
Two exclusions worth writing on the wall: the rule's prior authorization provisions do not apply to prior authorization for drugs, and most commercial and employer-sponsored plans are not "impacted payers." Those requests still run on contract terms and state law. Your workflow has to handle both worlds at once.

Build a payer requirements sheet

The single artifact that separates practices that handle prior auth well from practices that do not is a maintained requirements sheet. One row per payer, one owner, one "last verified" date. Columns worth having:

  • Payer and plan type (MA, Medicaid managed care, commercial, exchange)
  • Services and CPT/HCPCS ranges that require authorization
  • Submission channel, in order of speed — portal, API, fax, phone
  • Stated turnaround commitment for expedited and standard requests
  • Documentation checklist for the most common requests
  • Appeal deadline and appeal channel
  • Portal credentials owner (a role, not a person's personal login)
  • Date last verified

Verify it quarterly and after any contract change. A requirements sheet that is eighteen months stale is worse than none, because staff trust it.

A five-step prior authorization workflow

  1. Identify at scheduling. The service is flagged as authorization-required at the moment the appointment is booked, not when the patient is standing at the desk. This is the highest-leverage change most practices can make, and it costs nothing but a rule in the scheduling template.
  2. Verify eligibility and benefits first. Authorizing a service under a plan the patient no longer has is a common and entirely avoidable waste.
  3. Assemble the packet once, completely. Incomplete first submissions are the most common cause of avoidable delay. Use the payer's own documentation checklist and the payer's own medical policy language.
  4. Submit through the fastest channel and log it. Reference number, date, time, submitter, channel, and the exact scope requested. If it is not logged, it did not happen.
  5. Track to decision. Set a tickler based on the payer's stated turnaround. Escalate the day it lapses — not the week after someone notices.

Who owns what

RoleOwns
SchedulerFlags authorization-required services at booking; captures the order and working diagnosis
Prior auth coordinatorAssembles documentation, submits, logs, tracks to decision, escalates
ClinicianSigns the clinical justification; conducts peer-to-peer reviews
Billing / RCMConfirms the authorization number appears on the claim; catches PA-related denial codes
Practice managerOwns the payer requirements sheet and the weekly metric review

Small practices object that they do not have a dedicated prior auth coordinator. That is fine — the role can be a hat, not a headcount. What is not fine is the role being unassigned, because then it is nobody's, and the work surfaces only when a patient calls angry.

The metrics that actually move the needle

Track these weekly. Trend your own baseline rather than chasing a benchmark you read somewhere.

  • Volume by payer and by service — tells you where to spend your process effort
  • Percent submitted within one business day of the order — the metric you fully control
  • Median days from order to decision, split by payer
  • First-pass approval rate — a low rate almost always means an incomplete packet, not an unreasonable payer
  • Percent of denials overturned on appeal — a high overturn rate means you are being denied on things you should have won upfront
  • Appointments rescheduled or cancelled for a pending authorization — the only metric that measures patient harm directly, and the one to report to the clinicians
  • Claim denials carrying a prior-auth-related reason code — the leak at the far end of the pipe

Denials, appeals, and peer-to-peer

CMS now requires impacted payers to state a specific reason for a denial, regardless of whether the decision came by portal, fax, email, mail, or phone. Use it. The moment a denial arrives:

  1. Categorize the reason: missing documentation, medical necessity, coding error, non-covered benefit, or administrative.
  2. Calendar the appeal deadline the same day. Missed appeal windows are pure, self-inflicted revenue loss.
  3. Treat missing-documentation denials as a workflow bug. Do not just resubmit — fix the checklist so that request type never goes out short again.
  4. Prepare the clinician for peer-to-peer. Hand them the payer's own medical policy, the specific criteria at issue, and the chart elements that satisfy them. Do not send a physician into a peer-to-peer cold.
  5. Trend denials by payer and reason. A consistent pattern with a single payer is a contracting conversation, not a coordinator problem.

Getting ready for the payer APIs

The API provisions of CMS-0057-F are obligations on payers, not on practices — but they only pay off for you if your systems can meet them halfway.

  • Ask your EHR and practice-management vendor, in writing, what their roadmap is for the FHIR-based Prior Authorization API and the Da Vinci implementation guides CMS recommends (coverage requirements discovery, documentation templates and rules, and prior authorization support).
  • Understand the new Electronic Prior Authorization attestation measure under Promoting Interoperability, which begins with the CY 2027 performance period for MIPS eligible clinicians and the CY 2027 EHR reporting period for eligible hospitals and CAHs.
  • Clean your data now — accurate payer identifiers, provider NPIs, and a defensible standard documentation set per service line. An API cannot fix a bad packet; it will just deliver it faster.
  • Do not dismantle the portal and fax workflow. The rollout is phased and payer-side, and the plans outside the rule are not going anywhere.

Prior authorization will not stop being annoying. It can stop being chaotic, and the difference between the two is about a day of setup and a fifteen-minute weekly review.

Common questions

How fast do payers have to decide a prior authorization request?

Under CMS-0057-F, impacted payers (excluding QHP issuers on the Federally Facilitated Exchanges) must send decisions within 72 hours for expedited requests and seven calendar days for standard requests, with these operational provisions generally beginning January 1, 2026. Plans outside the rule follow their own contracts and state law.

Does the CMS prior authorization rule cover drugs?

No. The rule's prior authorization provisions expressly exclude prior authorization for drugs.

Which plans count as "impacted payers"?

Medicare Advantage organizations, state Medicaid and CHIP fee-for-service programs, Medicaid managed care plans, CHIP managed care entities, and Qualified Health Plan issuers on the Federally Facilitated Exchanges.

What is the single highest-leverage change a small practice can make?

Flag authorization-required services at scheduling instead of at check-in, and submit a complete packet the first time. Incomplete first submissions are the most common cause of avoidable delay.