Since 1 January 2026, payers covered by the CMS Interoperability and Prior Authorization final rule must decide expedited authorization requests within 72 hours and standard requests within 7 calendar days, give a specific reason for every denial, and publicly report authorization metrics annually. Four FHIR APIs, including a Prior Authorization API, must be operational by 1 January 2027.
This is the first federal rule in years that gives providers something enforceable to push against on authorization delay. Most practices have not yet changed a single workflow to take advantage of it, which is a missed opportunity, because the leverage only exists if you measure and cite it.
What the rule is, and who it covers
CMS-0057-F, released on 17 January 2024 and published in the Federal Register the following month, applies to a specific set of payers:
- Medicare Advantage organizations
- Medicaid and CHIP managed care entities
- State Medicaid and CHIP fee-for-service agencies
- Qualified Health Plan issuers on the federally facilitated exchanges
Note carefully what is absent. Commercial group health plans and traditional Medicare fee-for-service are not covered. Neither are drug authorizations, which are excluded from the API requirements. So a practice whose worst authorization delays come from a large commercial employer plan gains no direct rights here, though the industry-wide direction of travel still helps in negotiation.
What took effect in 2026
The operational provisions are in force now and are the part providers can actually use.
- Decision timeframes. Seventy-two hours for expedited requests and seven calendar days for standard requests. A payer exceeding these on a covered plan is out of compliance, and that is a materially different conversation from complaining about slowness.
- Specific denial reasons. Payers must provide the reason for a denial, which converts an unappealable “not medically necessary” into something you can actually respond to.
- Public reporting. Covered payers must publicly report authorization metrics annually, with the first report due 31 March 2026 covering calendar year 2025. These reports are a genuinely useful and almost entirely unused source of leverage, because they let you compare a payer’s published approval rates and turnaround times against what you are actually experiencing.
- Patient Access API content. Prior authorization information, excluding drugs, must be included in the data available through the existing Patient Access API.
- A new MIPS measure. CMS added an Electronic Prior Authorization measure to the Health Information Exchange objective under the MIPS Promoting Interoperability performance category, which puts electronic authorization on the reporting agenda for eligible clinicians rather than leaving it as an operational preference.
What is coming in 2027
By 1 January 2027, covered payers must run four production FHIR APIs:
- Patient Access API, which most already operate under the 2020 interoperability rule.
- Provider Access API, giving in-network providers access to patient claims, encounter, and clinical data.
- Payer-to-Payer API, rebuilt as an enforceable API after the previous version went largely unenforced.
- Prior Authorization API, supporting electronic submission of requests and status checks.
The 2026 requirements are process and governance work. The 2027 requirements are engineering, and they are the harder deadline. Existing X12 transactions are not replaced, so for a period providers will be operating across both standards.
How to use this operationally
Rights that nobody measures are not rights. Four concrete changes:
- Timestamp every authorization request and decision for covered plans, and report on breaches monthly by payer. Without this data you cannot make a compliance argument, and with it you can.
- Escalate on the deadline, not on frustration. A request citing the 72-hour expedited requirement on day four is a different communication from a follow-up call, and it should go to the payer’s compliance or provider relations function rather than the authorization queue.
- Read your payers’ published metrics when the annual reports land and compare them against your own experience. A gap between a payer’s reported turnaround and your measured turnaround is a contracting conversation.
- Insist on the specific denial reason and appeal against it rather than against the outcome. Most authorization denials on covered plans are administrative or documentation-related rather than genuine coverage determinations.
Why authorization still drives denials
The rule improves timelines. It does not remove the underlying failure modes, which remain the largest preventable category in most revenue cycles: authorization not obtained before the service, authorization obtained for a different code than the one performed, authorization expired before the date of service, or the wrong entity contacted because the benefit is administered by a carve-out.
Denial rates across the industry have been running near 11.8% on initial submission, with more than 40% of providers reporting rates at or above 10%, and roughly 60% of denied claims never reworked at all. Authorization failures are disproportionately represented in that population precisely because they are procedurally unappealable: the service happened without the required approval and no amount of clinical documentation repairs that after the fact.
Which is why authorization is an upstream discipline rather than a billing function. It belongs at scheduling, with the code that will actually be performed, verified against the correct administering entity. That is how it sits inside prior authorization services and eligibility verification, upstream of denial management rather than inside it.
On the technology question: AI is genuinely useful here, and the evidence is better than for most RCM automation claims. American Hospital Association analysis found health systems deploying AI for prior authorization reported a 22% decrease in authorization-related commercial denials and an 18% decrease in denials for services deemed not covered. The governance rules that make that safe are set out in what AI can and cannot safely do in 2026, and the service layer is AI-powered RCM with human-led review.
Authorization burden is heaviest in advanced imaging, where a protocol change at the scanner can invalidate an approval that was correct when obtained; that interaction is covered in radiology billing in 2026. For where authorization ranks against the year’s other revenue pressures, see the biggest revenue cycle management challenges in 2026.
To see what authorization failures are currently costing you by payer and service line, start with a free instant revenue audit.
Frequently asked questions
What is CMS-0057-F?
The CMS Interoperability and Prior Authorization final rule, requiring covered payers to speed up authorization decisions, explain denials, publicly report metrics, and implement four FHIR APIs. Operational provisions took effect 1 January 2026 and API requirements are due 1 January 2027.
How long can a payer take to decide a prior authorization in 2026?
For covered payers, 72 hours for expedited requests and 7 calendar days for standard requests. These apply to Medicare Advantage, Medicaid and CHIP managed care, state Medicaid and CHIP fee-for-service, and federally facilitated exchange QHPs.
Does the rule apply to commercial insurance?
No. Commercial group health plans are outside its scope, as is traditional Medicare fee-for-service. Drug authorizations are also excluded from the API requirements.
What are the four required APIs?
Patient Access, Provider Access, Payer-to-Payer, and Prior Authorization, all HL7 FHIR-based and required to be operational by 1 January 2027.
Where can I see a payer’s authorization performance?
Covered payers must publicly report authorization metrics annually, with the first report due 31 March 2026 for calendar year 2025. Compare the published figures against your own measured experience with that payer.
Does the rule reduce authorization denials?
Not directly. It shortens decision timelines and requires specific denial reasons, which improves your ability to respond. The common failure modes, missing or mismatched authorizations, remain a provider-side workflow problem.