CMS Interoperability and Prior Authorization Final Rule Implementation Timeline
Two compliance deadlines reshape how payers handle prior authorizations and deny claims.

CMS-0057-F, the Interoperability and Prior Authorization final rule, sets two hard compliance dates for payers: January 1, 2026 and January 1, 2027. Published January 17, 2024, the rule doesn't regulate physician practices directly, but it rewires how payers must handle prior authorization decisions and data, and that changes what happens on the practice side of every fax, portal login, and denial letter. Understanding what each deadline actually forces payers to do is the difference between a practice that benefits from this rule and one that just keeps absorbing the same delays with new paperwork attached.
The two-deadline structure and why CMS split them
CMS didn't split this into two dates by accident. Stakeholders who commented on the proposed rule pushed back hard on the original timeline, arguing that building the required APIs (the electronic connections between payer and provider systems) would take longer than the agency first assumed. CMS agreed, and split the rule into a policy-and-process wave and a technology wave.
January 1, 2026 covers the non-technical provisions: decision turnaround times, denial reason requirements, public reporting. January 1, 2027 covers the API build-out: four separate application programming interfaces that payers must have live and functioning. Put plainly, 2026 is about what payers must do, and 2027 is about what payers must have built.
Neither date creates a direct legal obligation for a physician practice. But both dates change the operating environment a practice works inside every day, first through how payer staff process and communicate decisions, and later through whether a practice's EHR can talk to a payer's system without a human touching a fax machine.
This rule also isn't a standalone regulation. It builds on the 2020 CMS Interoperability and Patient Access final rule (CMS-9115-F), extending that earlier framework's data-sharing logic into the specific problem of prior authorization. And it's worth being precise about scope: drug prior authorizations are excluded entirely. This rule covers only medical items and services, though CMS has signaled that separate rulemaking on drug prior auth is under consideration.
What the January 1, 2026 deadline requires of payers
Starting January 1, 2026, most impacted payers, Medicare Advantage organizations, state Medicaid and CHIP fee-for-service programs, and Medicaid and CHIP managed care plans, face fixed decision clocks. Standard, non-urgent requests get a seven calendar day response window. Expedited, urgent requests get 72 hours.
Those clocks run on calendar time, not business hours. A 72-hour clock that starts at 1:00 AM on a Sunday runs out at 1:00 AM Wednesday, weekend included, no matter how a payer's claims department staffs its weekends. Extensions of up to 14 additional calendar days are allowed under specific program conditions, but the default is fixed and it applies no matter which channel carries the request: API, portal, fax, or phone.
The payer's response has to land in one of three buckets. Approve, and state when the authorization ends. Deny, and give a specific reason. Or request the specific additional information needed to decide, rather than a vague "more documentation required" holding pattern.
Public reporting starts alongside this. Beginning March 31, 2026, impacted payers must post aggregated prior authorization metrics on their public websites, covering the prior calendar year, meaning the first batch of data will cover calendar year 2025. That data has to include the full list of items and services subject to prior authorization, approval and denial percentages for standard requests, approval-after-appeal rates, extension rates, expedited approval and denial percentages, and average and median decision times.
For a practice that's dealt with the same slow-walking payer for years, this is the first time that payer's behavior gets measured against every other payer's behavior, in public, on a fixed schedule.
What the March 31, 2026 public reporting deadline reveals about prior authorization denial rates today
Because CMS hasn't published this data yet, no practice today can look up its top payer's actual denial rate on a government website. But a KFF analysis, drawing on data covering 25 million Medicare Advantage enrollees, 36 million Medicaid managed care enrollees, and 10.8 million ACA Marketplace enrollees, offers a preview of what standardized reporting is likely to surface.
Medicare Advantage plans denied 12% of standard prior authorization requests. Medicaid managed care plans denied 14%. ACA Marketplace plans denied 18%, the highest of the three segments. Those aggregate numbers hide enormous spread at the insurer level: among the 14 largest MA insurers, denial rates ranged from 5% (Elevance) to 17% (UnitedHealth). Medicaid managed care ranged from 2% (L.A. Care Plan) to 23% (Independent Health Group). ACA Marketplace ranged from 3% (Guidewell) to 25% (Centene).
The appeals data is where the real story sits. In Medicare Advantage, 80.7% of appealed denials got overturned. Medicaid managed care organizations reversed 47% of appealed denials. ACA Marketplace plans approved 43% of denials on appeal. Yet only 11.5% of denied requests ever got appealed in the first place, and a 2023 OIG report found that 89% of Medicaid enrollees simply don't appeal.
That gap, four out of five appealed MA denials winning reversal, but barely one in ten denials ever getting appealed, is where practice revenue quietly disappears. Most denials that would have flipped on appeal never get worked at all. Starting March 31, 2026, a practice will be able to pull its top payers' published denial rates, appeal outcomes, and decision-time averages and hold them up against its own claims data. That comparison didn't exist in standardized form before this rule.
What the January 1, 2027 deadline requires of payers and what it means for practice workflows
By January 1, 2027, four APIs have to be live: the Prior Authorization API, the Provider Access API, the Payer-to-Payer API, and an expanded version of the Patient Access API that now includes prior authorization status.
The Prior Authorization API is the one that changes daily workflow most directly. Built on the HL7 FHIR standard (Fast Healthcare Interoperability Resources), it lets a practice check in real time whether a service needs authorization, what documentation the payer wants, and submit the request electronically, replacing the fax-and-hold-music version of this process that most practices still run today. The same seven-day and 72-hour decision clocks from 2026 still apply here. The API is a channel for submitting the request faster, not a loophole that resets the timer.
The Provider Access API requires payers to share claims data, encounter data, clinical data under the USCDI standard, and prior authorization history with in-network providers who treat the patient, and to build an attribution process linking patients to their treating providers (patients can opt out). For a practice running a FHIR-enabled EHR, that means pulling a patient's authorization history and claims record from the payer before the appointment even starts, instead of discovering gaps mid-visit.
The Payer-to-Payer API addresses a specific, common failure: a patient switches coverage, and the new payer has no record of prior authorizations already granted under the old plan, so the practice ends up re-proving medical necessity for something already approved. Under this requirement, when coverage changes, the new payer has to identify the previous payer and offer the patient an opt-in, generally within a week of new coverage starting. The prior payer then has one business day to hand over five years of claims and authorization history. Continuity of authorization becomes the payer's job, not something a practice's billing staff has to chase down with old EOBs.
The expanded Patient Access API lets patients themselves check prior auth status, pending, approved with terms, or denied with the specific reason, through their own access to the Patient Access API.
CMS also granted enforcement discretion on a related technical point: covered entities building FHIR-based Prior Authorization APIs won't face HIPAA enforcement for not also using the older X12 278 transaction standard, an announcement CMS made February 28, 2024. That's a small detail with a real effect: it clears a technical obstacle that might otherwise have slowed FHIR adoption on legal grounds alone.
CMS has been direct that early coordination between practices and their technology vendors matters here. A practice's EHR and clearinghouse have to be FHIR-ready on the other end of that connection, or the payer's API doesn't do the practice any good regardless of how well the payer built it.
How the denial rates and workflow delays these deadlines address are already costing practices revenue
The volume alone is worth sitting with. Medicare Advantage plans processed nearly 53 million prior authorization requests in 2024, up 42% from 37.1 million in 2019. Of that 2024 volume, 4.1 million requests, 7.7%, got denied. And the denial rate itself has been climbing along with volume: 5.6% in 2020, 5.8% in 2021, 7.4% in 2022, 6.4% in 2023, 7.7% in 2024. More requests and a rising denial share compound each other; every point of increase multiplies against a much bigger base than it did five years ago.
That's Medicare Advantage specifically. Industry-wide, initial claim denial rates (across all payer types, not just prior auth) hit 11.8% in 2024, and industry sources tracking billing KPIs project 12% to 15% for 2025.
Rework on a single denied claim costs a practice somewhere between $25 and $118, depending on complexity, and that's before counting the staff hours spent chasing the denial down. At volume, that adds up fast across a practice's book of business. Timing makes it worse: the odds of full recovery on a claim drop sharply past 60 days in accounts receivable, and by 90 days a claim is often bumping up against a payer's timely filing limit, at which point earned revenue becomes a permanent write-off rather than a delayed payment. Independent practices generally aim to keep days in AR between 30 and 40, with AR older than 90 days held under 15% of the total, benchmarks that get harder to hit as payer-side automation expands what triggers a prior auth requirement in the first place.
None of this is new pressure. Industry data shows claim denials had risen 11% over the prior three years. What's new is the visibility the 2026 and 2027 deadlines are about to create, and the fact that an 80.7% MA overturn rate on appeal, alongside a 47% overturn rate for Medicaid managed care, means a large share of today's denials represent money a practice could get back, if someone works the appeal before the filing window closes.
What practices should do operationally between now and each deadline
Before January 1, 2026, the groundwork is mostly about knowing exactly which payers this rule touches. Medicare Advantage, Medicaid and CHIP managed care, and QHP issuers on the federally-facilitated exchanges are covered. Medicare fee-for-service, and most commercial plans outside the federal exchange are not. A practice should map its highest-volume prior auth payers against that list, then benchmark current turnaround times against the new seven-day and 72-hour standards, so there's a real baseline to compare against once the deadline hits. Building an internal denial tracker by payer and service line now means that when the March 2026 public data lands, there's something concrete to measure it against.
At March 31, 2026, the job is to actually use the data once it's published. Pull the denial rates, appeal overturn percentages, and average decision times for the practice's top payers, and compare those figures against the practice's own experience with each one. A denial rate that runs well above a payer's published aggregate is worth investigating, not shrugging off. And because payers are required, starting January 1, 2026, to give a specific reason for every denial, any denial that arrives without one after that date isn't just frustrating, it's a compliance gap worth flagging.
Before January 1, 2027, the conversation that matters most is with the practice's own vendors, not the payers. Ask directly whether the EHR and clearinghouse a practice runs will support FHIR-based connections to payer APIs by the deadline. Waiting to find out until the deadline arrives means absorbing months of avoidable delay, exactly the kind of cost this rule was built to eliminate.


