Prior Authorization API

What must be included in the impacted payer’s prior authorization response via the Prior Authorization Application Programming Interface (API)? 

Under CMS-0057-F, an impacted payer’s response to a prior authorization request must do one of three things: approve the request and specify the date or circumstance under which the authorization ends; deny the request and provide a specific reason for the denial; or request additional information needed to make a decision. 

What are the timeframe requirements for responses to prior authorization requests (other than for Qualified Health Plan [QHP] issuers on the Federally-facilitated Exchanges [FFEs])? 

Under CMS 0057-F, impacted payers (excluding QHP issuers on the FFEs) must deliver prior authorization decisions as expeditiously as a patient’s medical condition requires. Subject to that condition, payers have a maximum of 72 hours to respond to an expedited (i.e., urgent) request and seven calendar days to respond to a standard (i.e., non-urgent) request after receiving the request. 

These requirements apply to prior authorization for medical items and services, excluding drugs. Because the final rule did not alter prior authorization timelines for QHP issuers on the FFEs, these rules and related FAQs do not apply to them (89 FR 8880).

Impacted PayerStandard RequestExpedited/Urgent RequestRegulatory Citation(s)
Medicare Advantage organizationsSeven calendar days*72 hours*42 CFR § 422.568(b)(1)(ii); § 422.572(a)(1). Applicable integrated plans: § 422.631(d)(2). 42 CFR 422.568(b)(2) and 42 CFR 422.572(b)
State Medicaid fee-for-serviceSeven calendar days*72 hours42 CFR § 440.230(e)(1)(i)-(ii)
Medicaid managed care — managed care organizations (MCOs), Prepaid Inpatient Health Plans (PIHPs), and Prepaid Ambulatory Health Plans (PAHPs)No more than seven calendar days*No more than 72 hours*42 CFR § 438.210(d)(1)(i)(B) and (d)(2)(i). 42 CFR 438.210(d)(1)(ii) and 42 CFR 438.210(d)(2)(ii) 
State Children’s Health Insurance Program (CHIP) fee-for-serviceSeven calendar days*72 hours*42 CFR § 457.495(d)(2). 42 CFR 457.495(d)(1) 
CHIP managed care entities — MCOs, PIHPs, and PAHPsNo more than seven calendar days*No more than 72 hours*42 CFR § 457.1230(d), applying the managed-care authorization standards. 42 CFR 457.1230(d)

Response timeliness is measured in calendar time, not business hours. For example, an expedited request received at 1:00 AM Sunday must receive a response as expeditiously as the patient’s health condition requires and no later than 1:00 AM Wednesday. 

Requests marked with an asterisk (*) in the chart above may be granted an extension of up to 14 additional calendar days, subject to the program-specific regulatory conditions. 

These deadlines apply regardless of whether the request arrives through the application programming interface (API), portal, fax, phone, or another channel. 

How do impacted payers report Prior Authorization metrics to comply with the reporting requirement? Is there available guidance for format and method for submission of these metrics? 

Under the 2024 CMS Interoperability and Prior Authorization final rule (CMS-0057-F), beginning in 2026, and annually thereafter, impacted payers (Medicare Advantage [MA] organizations, state Medicaid and Children's Health Insurance Program [CHIP] programs, Medicaid managed care plans, CHIP managed care entities, and Qualified Health Plan [QHP] issuers on the Federally-facilitated Exchanges [FFEs]) must post certain aggregated prior authorization metrics from the previous year (89 FR 8889) on their public-facing website. MA organizations will report at the contract level, state Medicaid and CHIP FFS programs will report at the state level, Medicaid managed care plans and CHIP managed care entities will report at the plan level, and QHP issuers on the FFEs will report at the issuer level (89 FR 8897).

Payers must report the following metrics for medical items and services (excluding drugs) subject to prior authorizations each year:

  • A list of all items and services that require prior authorization (excluding drugs).
  • The percentage of standard prior authorization requests that were approved, aggregated for all items and services.
  • The percentage of standard prior authorization requests that were denied, aggregated for all items and services.
  • The percentage of standard prior authorization requests that were approved after appeal, aggregated for all items and services.
  • The percentage of prior authorization requests for which the timeframe for review was extended, and the request was approved, aggregated for all items and services.
  • The percentage of expedited prior authorization requests that were approved, aggregated for all items and services.
  • The percentage of expedited prior authorization requests that were denied, aggregated for all items and services.
  • The average and median time that elapsed between the submission of request and a determination by the payer, plan, or issuer, for standard prior authorizations, aggregated for all items and services.
  • The average and median time that elapsed between the submission of a request and a decision by the payer, plan, or issuer, for expedited prior authorizations, aggregated for all items and services.

(89 FR 8889 - 8890)

As we discuss in the final rule, CMS has developed a Prior Authorization Metrics Reporting Template (PDF) for impacted payers regarding recommended content and format for use in their public reports of prior authorization metrics as well as best practices about the website locations for the prior authorization metrics (89 FR 8892 - 8893). In addition, it may be helpful for impacted payers to review how the Medicare fee-for-service (FFS) program publicly reports prior authorization metrics and presents those metrics on its website (see Prior Authorization and Pre-Claim Review Initiatives) (89 FR 8892).

Are impacted payers required to make real-time decisions on prior authorization requests?

The final rule did not include a requirement for impacted payers to use the Prior Authorization Application Programming Interface (API) to make real-time decisions on prior authorization requests, but the automation that the API provides could improve decision timeframes. Though we anticipate that some responses or decisions may be made in real-time, other decisions will continue to necessitate review and evaluation by clinical reviewers (the 2024 CMS Interoperability and Prior Authorization final rule requires impacted payers, excluding Qualified Health Plan [QHP] issuers on the Federally-facilitated Exchanges [FFEs], to send decisions within 72 hours for expedited [i.e., urgent] requests and seven calendar days for standard [i.e., non-urgent] requests). Automating a complex process such as prior authorization will be an ongoing process of continuous improvement.

Does the March 31, 2026, compliance date for the prior authorization metrics reporting requirements in the 2024 CMS Interoperability and Prior Authorization final rule reflect the date on which reporting must begin, or the date on which metric data collection must begin for the purpose of being subsequently reported?

The 2024 CMS Interoperability and Prior Authorization final rule (CMS-0057-F) requires impacted payers (Medicaid Advantage [MA] organizations, state Medicaid and Children's Health Insurance Program (CHIP) programs, Medicaid managed care plans, CHIP managed care entities, and Qualified Health Plan [QHP] issuers on the Federally-facilitated Exchanges [FFEs]) to publicly report certain prior authorization metrics for the previous calendar year (89 FR 8897). Accordingly, the first year this requirement goes into effect, impacted payers must post prior authorization metrics for calendar year 2025 on their websites by March 31, 2026. Please note that this means that impacted payers are required to collect prior authorization metrics in 2025.

Each program office will send out a letter with program-specific information for complying with these requirements.

How should impacted payers account for appeals in terms of the total count of prior authorization decisions? 

The total number of approved prior authorization requests should include requests that were initially approved as well as requests that were approved after appeal. Additionally, the total number of denied prior authorization requests should include the requests that were denied after appeal. The prior authorization metrics reporting template is available here for reference Prior Authorization Metrics Reporting Template (PDF). This approach is taken because the overall approval/denial rate should reflect the total of all prior authorization requests, regardless of whether they were appealed or not.

Additionally, the “appeals” metrics do not differentiate between internal reviews by the impacted payer and reviews by an external organization contracted by an impacted payer. The appeals metrics should aggregate all levels of appeals.

The definition of an "appeal" for purposes of these metrics differs between types of impacted payers. For Medicare Advantage, appeals are defined at 42 CFR Part 422, Subpart M and for Qualified Health Plan (QHP) issuers on the Federally-facilitated Exchanges they are defined at 45 CFR 147.136(a)(2)(ii). Appeals for state Medicaid fee-for-service (FFS) programs are described in 42 CFR 431 Subpart E and for Medicaid managed care plans in 42 CFR 438 Subpart F. Appeals for state Children's Health Insurance Program (CHIP) FFS programs are described in 42 CFR 457 Subpart K and for CHIP managed care entities in 42 CFR 457.1260. States should report only appeals that qualify under these definitions for each program.

An episode of care can include more than one prior authorization request for specific services, procedures, or extended stays; for reporting the required prior authorization metrics, how should those prior authorizations be counted? 

The requirements in the 2024 CMS Interoperability and Prior Authorization final rule (CMS-0057-F) are structured around individual prior authorization requests and not episodes of care, meaning each prior authorization request should be counted and reported individually regardless of whether it is part of a broader episode of care.

Therefore, if an episode of care includes more than one prior authorization, the prior authorization for the initial hospital admission and then each subsequent prior authorization tied to that admission should be counted individually.

CMS-0057-F requires certain impacted payers to make prior authorization decisions within specific timeframes. Regarding these specific timeframes for these payers, when does the clock start for payers to process and decide prior authorization requests? (Note: CMS-0057-F did not make changes to prior authorization timeframe requirements for Qualified Health Plan (QHP) issuers on the Federally-facilitated Exchanges (FFEs), and FAQ content related to timeframes does not apply to QHP issuers on the FFEs.)

The prior authorization decision timeframe clock starts when an impacted payer receives a prior authorization request. Depending on the item or service, the payer may require documentation from the provider. The clock does not stop or restart if the payer requests additional documentation that was not disclosed to the provider when they submitted the original request; however, a payer may use an extension when permitted under the applicable program requirements. If such additional documentation is necessary, this must be communicated to the provider in a timely manner (affording the provider an opportunity to supplement the request) to ensure that the substantive decision to approve or deny the prior authorization request is made and notice is sent within the applicable adjudication timeframe. 

Within the Prior Authorization Application Programming Interface (API), the Coverage Requirements Discovery (CRD) implementation guide (IG) is a Health Level 7® (HL7®) Fast Healthcare Interoperability Resources ® (FHIR®) standardized workflow that allows providers to determine whether prior authorization is required, what coverage rules apply, and what specific documentation is needed (89 FR 8861). A check for coverage requirements and the CRD response, by itself, does not start the decision timeframe clock for a payer. While a CRD response may inform a provider that prior authorization is required and what documentation is needed, it alone does not constitute the submission of a prior authorization request. Accordingly, payers should not treat the electronic check for whether prior authorization is needed as the initiation of a prior authorization request for purposes of starting the decision clock. Rather, the clock starts when a prior authorization request is received.

Note: Through its recent proposed rule CMS-0062-P, CMS is proposing updates to the requirements for reporting of prior authorization decisions and API usage metrics. For further information, please refer to the Fact Sheet.

Page Last Modified:
09/01/2026 12:21 PM