Prior authorization has always been a strange kind of bottleneck. Care may be clinically ready, the patient may be waiting, documentation may exist, and revenue may depend on the decision. Yet, the request can still move through portals, faxes, phone calls, and payer-specific rules before anyone gets a clear answer.
Now, the bottleneck has dates attached to it.
The Centers for Medicare & Medicaid Services released the Interoperability and Prior Authorization Final Rule on January 17, 2024. Impacted payers include Medicare Advantage organizations, Medicaid and Children’s Health Insurance Program fee-for-service programs, Medicaid managed care plans, CHIP managed care entities, and Qualified Health Plan issuers on Federally Facilitated Exchanges. Operational provisions generally began on January 1, 2026, while most application programming interface requirements begin on January 1, 2027.
For payers and providers, CMS-0057-F compliance has moved from planning to execution. The first public reporting deadline has passed, the larger Fast Healthcare Interoperability Resources API deadline is months away, and organizations still aligning owners, data maps, rule governance, or API strategy are already under pressure.
Where CMS-0057-F Compliance Stands Now
The first reporting deadline required impacted payers to publish prior authorization metrics by March 31, 2026, using calendar year 2025 data. Reports had to appear on each payer’s own public-facing website because CMS did not create a central reporting portal for public lookup.
Reporting levels also vary by payer type, which makes governance more than a communications task. Medicare Advantage organizations report at the contract level, fee-for-service programs report at the state level, managed care plans report at the plan level, and Qualified Health Plan issuers report at the issuer level.
The market is already behind. Artificer Health’s April 2026 scorecard found 1,114 of 1,296 impacted payers with zero evidence of published prior authorization data, while only 9% showed meaningful compliance effort. The same scorecard series later referenced only 9% of 1,304 payers as compliant after an expanded survey, and the latest figure shared for the blog brief says 1,185 impacted payers had published nothing.
WEDI’s March 2026 industry survey adds another warning signal: 10% of payers had not started implementation work yet. A plan missing the March 31 reporting deadline is already out of compliance, while the January 1, 2027 API deadline brings a larger build across data, workflow, governance, testing, and provider exchange.
CMS Prior Authorization Timeline For 2026 And 2027
The 2026 phase changed operational accountability across prior authorization. Impacted payers, excluding Qualified Health Plan issuers on Federally Facilitated Exchanges, must send decisions within 72 hours for expedited requests and seven calendar days for standard requests. CMS also requires a specific reason for denied prior authorization decisions, regardless of request channel. Drug prior authorization decisions remain outside the CMS-0057-F scope.
Public reporting covers eight required metric fields across standard and expedited requests. Payers must report approval and denial percentages, approval after appeal, mean and median decision times, and the percentage of extended reviews approved after extension.
Compliance teams also need to pay attention to calculation rules because the details change how reports should be built. Metrics exclude drugs; time is measured from payer receipt of the request; approval and denial totals include post-appeal outcomes; and appeals combine internal payer reviews with external or contracted reviews.
FHIR Prior Authorization API Requirements For 2027
The January 1, 2027 deadline covers four FHIR APIs: the enhanced Patient Access API, Provider Access API, Payer-to-Payer API, and Prior Authorization API.
The enhanced Patient Access API adds prior authorization information to member-accessible data. The Provider Access API shares patient data with in-network providers who have a treatment relationship, with attribution and opt-out requirements. The Payer-to-Payer API supports data exchange when a member changes coverage and requires opt-in. The Prior Authorization API lists covered items and services requiring prior authorization, documentation requirements, and request-response details.
The FHIR prior authorization API must communicate approval, denial with a specific reason, or a request for more information. Approval responses must include the date or circumstance when authorization ends. For payers, readiness depends on coverage rules, documentation requirements, service catalogs, response codes, authorization duration rules, audit trails, and API monitoring.
Electronic Prior Authorization And RCM Readiness
Electronic prior authorization changes revenue cycle management because authorization risk starts before billing. Missing evidence, unclear medical-necessity documentation, payer-specific rule variations, and manual status checks can delay care and payment long before a claim reaches adjudication.
Prior authorization status should be visible before scheduling and claim submission. Denial reasons should route to the responsible team, while requests for more information should trigger targeted documentation tasks with enough context for the next step.
CMS also finalized an Electronic Prior Authorization measure for eligible clinicians, hospitals, and critical access hospitals. Eligible clinicians begin reporting with the 2027 performance period, while eligible hospitals and critical access hospitals begin with the 2027 electronic health record reporting period.
Da Vinci PAS/CRD/DTR For Standards-Based Implementation
CMS strongly encourages Da Vinci implementation guides such as Payer Data Exchange, Prior Authorization Support, Coverage Requirements Discovery, and Documentation Templates and Rules. All four required APIs are HL7 FHIR APIs, with general compliance expected on January 1, 2027. Medicaid and CHIP managed care align to rating periods on or after the same date, while QHP issuers align to plan years.
Coverage Requirements Discovery helps expose coverage and documentation requirements in clinical workflows. Documentation Templates and Rules help collect medical necessity documentation. Prior Authorization Support enables direct request and response exchange using FHIR, with X12 mapping support where needed.
For implementation teams, technical conformance is only part of the job. The harder operational task is translating payer rules into computable, testable, auditable workflows providers can follow without adding another manual queue.
What Comes Next: CMS-0062-P And Drug Prior Authorization
CMS-0057-F covers non-drug medical items and services, while CMS-0062-P points to the next area of prior authorization reform. The proposed rule would extend the CMS-0057-F interoperability and prior authorization framework to drugs, add a payer API endpoint registry, and propose FHIR as the HIPAA standard for prior authorization.
CMS-0062-P was published on April 14, 2026; the comment period closed on June 15, 2026, and most provisions are proposed to take effect on October 1, 2027, if finalized.
For medical-benefit drugs, the proposal would add coverage and documentation rules into the existing FHIR Prior Authorization API. For pharmacy-benefit drugs, the proposal points to NCPDP standards, including SCRIPT, Formulary and Benefit, and Real-Time Prescription Benefit.
The proposal also expands API and reporting obligations. Patient, Provider, and Payer-to-Payer APIs would expose drug prior authorization status, dates, drug and dosage details, denial reasons, and documentation. Payers would also need to report API endpoints, FHIR capability statements, and technical documentation to a central CMS directory, with updates required within one week of changes and yearly verification.
CMS-0062-P remains proposed, so provisions and dates may change before finalization. The direction still matters for planning because drug prior authorization appears likely to follow the same path as medical items and services, with more structured data, more API exposure, more reporting, and less tolerance for opaque workflows.
Readiness Roadmap For 2026
A practical roadmap should begin with the requests creating the most manual effort. Teams should identify service lines, payers, and authorization categories with frequent delays, documentation gaps, resubmissions, and appeal activity.
A 2026 roadmap should cover six readiness areas:
- Rule and service inventory for high-volume authorization categories
- Documentation requirement mapping by payer, service, and urgency
- Workflow design across ordering, scheduling, revenue cycle, and utilization review
- FHIR data mapping, authentication, authorization, and API monitoring
- Reporting models for decision time, denial reasons, approvals, and rework
- Training and change readiness for payer and provider teams
The Coditas Advantage
The first public reporting deadline has passed, payer compliance appears uneven across the market, and the January 1, 2027 FHIR API deadline has become the larger pressure point. Organizations making progress in 2026 will treat prior authorization as a shared workflow across clinical, revenue, utilization, compliance, and technology teams.
The practical goal is fewer avoidable touches, clearer documentation, faster response handling, and cleaner data exchange before care delays and claim risk increase. Coditas helps healthcare organizations build FHIR-aligned prior authorization workflows, revenue cycle technology, payer-provider data exchange, and AI-ready healthcare platforms.
Connect with our healthcare technology experts to assess readiness and build a practical roadmap before the 2027 deadline.

