Ceety Systems

Platforms

CMS prior authorization API rule for payers and providers

What CMS-0057-F requires: impacted payers, the four FHIR APIs and 2027 dates, 2026 decision timeframes, Da Vinci guides and next steps for providers.

By the Ceety Systems teamUpdated 7 min read

Key takeaways

  • CMS-0057-F applies to Medicare Advantage, Medicaid and CHIP (fee-for-service and managed care) and QHP issuers on the federally facilitated exchanges.
  • Process rules took effect in 2026: 72-hour expedited and 7-day standard decisions for most impacted payers, specific denial reasons and public metrics.
  • Four FHIR APIs are due in 2027: Patient Access (expanded), Provider Access, Payer-to-Payer and Prior Authorization.
  • CMS recommends the Da Vinci CRD, DTR and PAS guides for prior authorization; they are recommended, not required.
  • Providers get value only if their EHR and workflows connect to payer APIs, so start vendor conversations now.

The CMS Interoperability and Prior Authorization Final Rule (CMS-0057-F) requires Medicare Advantage organizations, Medicaid and CHIP programs and plans, and qualified health plan issuers on the federally facilitated exchanges to speed up prior authorization and share data through standard APIs. The process changes, including decision deadlines and specific denial reasons, applied from 2026. The four APIs are due in 2027.

This article summarizes who is covered, what is due when, which technical standards apply, and what provider groups and health tech startups should do. It is general information, not legal advice; check the rule text and CMS guidance for your situation.

Which payers does CMS-0057-F apply to?

According to the CMS fact sheet, "impacted payers" are:

  • Medicare Advantage organizations
  • State Medicaid and Children's Health Insurance Program (CHIP) fee-for-service programs
  • Medicaid managed care plans and CHIP managed care entities
  • Qualified health plan (QHP) issuers on the federally facilitated exchanges (FFEs)

The final rule excludes issuers offering only stand-alone dental plans and those offering QHPs only on the federally facilitated small business exchanges. State-based exchanges on the federal platform are not FFEs, so their QHP issuers are not covered. Commercial employer plans outside these programs are not directly subject to the rule, though some payers run one platform across lines of business.

What is due when?

Compliance dates differ by payer type. For the 2027 API requirements, the rule sets them as January 1, 2027 for Medicare Advantage organizations and state Medicaid and CHIP fee-for-service programs; the rating period beginning on or after January 1, 2027 for Medicaid and CHIP managed care; and plan years beginning on or after January 1, 2027 for QHP issuers on the FFEs. The 2026 process requirements follow the same pattern, one year earlier.

RequirementWhat it meansCompliance
Decision timeframes72 hours for expedited requests, 7 calendar days for standard requests (not QHP issuers on the FFEs)2026
Specific denial reasonTell the provider the specific reason for a denial, however the request was sent2026
Public prior authorization metricsPost certain metrics on the payer's website each year; first report due March 31, 20262026
Patient Access API metricsReport usage metrics to CMS annually2026
Patient Access API (expanded)Add prior authorization information (excluding drugs)2027
Provider Access APIShare patient data with in-network providers who have a treatment relationship2027
Payer-to-Payer APIExchange data when a patient changes payers, with patient opt-in2027
Prior Authorization APICovered items, documentation rules, and request and response2027

State Medicaid and CHIP fee-for-service programs can request an extension or exemption in certain circumstances, and QHP issuers on the FFEs can request an exception from the API requirements.

What do the 2026 prior authorization process rules require?

Decision timeframes

Most impacted payers must decide expedited requests within 72 hours and standard requests within 7 calendar days, or sooner if state law or contract requires. QHP issuers on the FFEs are excluded from these new timeframes; the rule notes they remain subject to existing federal rules that require decisions within 15 days for standard and 72 hours for expedited requests.

Denial reasons

All impacted payers must give a specific reason when they deny a prior authorization request, whether the request came by API, portal, fax or phone.

Public metrics

Payers must publicly report prior authorization metrics each year, such as the percentage of requests approved and denied and the average and median decision times, with the first report due March 31, 2026.

The prior authorization provisions exclude drugs, and they supplement rather than replace existing program rules such as Medicare Advantage and Medicaid managed care notice requirements.

What are the four APIs?

All four are built on HL7 FHIR (Fast Healthcare Interoperability Resources), using the API standards CMS adopted at 45 CFR 170.215.

Patient Access API

Already required since the 2020 interoperability rule. From 2027, it must also include prior authorization requests and decisions (excluding drugs), available within one business day of the payer receiving the request or of a status change.

Provider Access API

Lets in-network providers retrieve a patient's claims and encounter data (without remittances and cost-sharing), data in the US Core Data for Interoperability (USCDI), and certain prior authorization information. Payers must run an attribution process to link patients to providers, let patients opt out, and respond within one business day of a valid request.

Payer-to-Payer API

Moves the same categories of data from a patient's previous payer to the new one, limited to dates of service within five years, when the patient opts in.

Prior Authorization API

Lets a provider's system find out whether an item or service needs prior authorization, identify the documentation required, submit the request and receive the response: approval, denial with a reason, or a request for more information.

Which implementation guides should you use?

The rule requires the base standards and strongly recommends specific HL7 implementation guides. The CMS fact sheet lists:

  • Da Vinci Coverage Requirements Discovery (CRD) — tells the provider, at ordering time, whether prior authorization is needed.
  • Da Vinci Documentation Templates and Rules (DTR) — gathers the required documentation, pre-filling from the EHR where possible.
  • Da Vinci Prior Authorization Support (PAS) — submits the request and returns the decision.
  • Da Vinci Payer Data Exchange (PDex), PDex US Drug Formulary and PDex Plan-Net — for payer data exchange, formularies and provider directories.
  • CARIN Consumer Directed Payer Data Exchange (CARIN IG for Blue Button) — for patient access to claims data.

The published guides are on the HL7 site, for example Da Vinci PAS. The fact sheet names specific versions, and the rule lets payers use newer versions under certain conditions.

On standards, CMS's National Standards Group announced in February 2024 that it will not enforce the HIPAA X12 278 standard against covered entities that implement an all-FHIR Prior Authorization API under this rule. That lets payers build FHIR end to end without an X12 translation step, if they choose.

What does the rule mean for provider groups?

Providers are not the regulated party for the APIs, but they are the intended users, and the benefit depends on their systems.

  1. Ask your EHR vendor which Da Vinci guides it supports, on which releases, and with which payers.
  2. Map your prior authorization volume by payer and service line, so you know where automation would help most.
  3. Plan for the Electronic Prior Authorization measure. CMS-0057-F added it to the Merit-based Incentive Payment System (MIPS) Promoting Interoperability category starting with the CY 2027 performance period, and for hospitals and critical access hospitals starting with the CY 2027 EHR reporting period. Check CMS's current program rules, because annual payment rules can change how measures are scored.
  4. Use the Provider Access API for care coordination once payers turn it on, with patient-matching and access controls in place.

A small practice will mostly depend on its EHR or practice management vendor. A large health system should also decide whether to build its own integration layer for payers whose APIs its EHR does not yet reach.

What does it mean for health tech startups?

The rule creates room for prior authorization, revenue cycle and data products, but buyers will ask hard questions:

  • Conformance. Can you show your product works with CRD, DTR and PAS as published, and with real payer endpoints?
  • Security and privacy. Expect SOC 2 or HITRUST questions, a Business Associate Agreement, and clear rules on how you store and use protected health information.
  • Payer variation. Each payer's rules and documentation templates differ; your product has to handle that without custom code per payer.

For payers still building, the practical sequence is to confirm the 2026 process controls are measurable, then build the Prior Authorization API with a FHIR platform, rules engine and integration to utilization management systems, and test with provider partners well before the 2027 date. Our healthcare page explains how we approach FHIR and interoperability work with audit evidence built in.

Frequently asked questions

When is the CMS prior authorization API rule deadline?

The API requirements are due in 2027: January 1, 2027 for Medicare Advantage and Medicaid and CHIP fee-for-service programs, and the first rating period or plan year beginning on or after that date for managed care plans and QHP issuers on the FFEs. The process requirements, including decision timeframes, applied from 2026.

Does CMS-0057-F apply to commercial health plans?

Not directly. It applies to Medicare Advantage, Medicaid and CHIP programs and plans, and QHP issuers on the federally facilitated exchanges. Commercial employer plans outside those programs are not covered, though payers may apply the same platform across lines of business.

Are the Da Vinci implementation guides required?

No. CMS requires the base FHIR standards at 45 CFR 170.215 and strongly recommends the Da Vinci and CARIN guides. In practice, using the recommended guides makes it easier for provider systems to connect.

Does the rule cover prescription drugs?

No. The prior authorization provisions exclude drugs, including drugs covered under medical benefits. Drug prior authorization sits outside this rule.

Do providers have to use the Prior Authorization API?

Not under the payer requirements. Clinicians and hospitals reporting to Medicare's Promoting Interoperability programs have the Electronic Prior Authorization measure starting in 2027, so check current CMS scoring rules for how it affects you.

Tell us about your business.

Book a free consultation: a conversation about what you have and what you want. We’ll tell you honestly what you don’t need. Free, with no obligation.