Overview
The Prior Authorization API is a suite of CMS-mandated FHIR-based APIs that together enable electronic prior authorization between providers and payers. Established by the CMS Interoperability and Prior Authorization Final Rule (CMS-0057-F) in January 2024, the API suite comprises the Da Vinci Coverage Requirements Discovery (CRD), Documentation Templates and Rules (DTR), and Prior Authorization Support (PAS) Implementation Guides. Compliance dates begin January 2026 for most covered payers.
Covered payers include Medicare Advantage, Medicaid managed care, CHIP managed care, and Qualified Health Plans on the federally-facilitated exchange. The APIs apply to prior-authorization workflows for items and services other than drugs (pharmacy PAs continue to use Surescripts/NCPDP channels).
The workflow unfolds in three phases. CRD surfaces coverage requirements at order time via CDS Hooks — the EHR fires a hook when the clinician selects an item requiring PA, the payer's CRD service evaluates coverage and returns cards indicating whether PA is needed and what documentation is required. DTR launches within the EHR (as a SMART app or embedded component) to help the clinician complete the required documentation using payer-supplied templates. PAS submits the completed PA request to the payer and receives a decision — approval, denial, or pended for further review.
The architectural goal is to move PA workflows out of fax, phone, and portal-based manual processes into structured FHIR-based data exchange. For providers, the workflow is embedded in their EHR rather than requiring separate portal logins. For payers, the inbound PA requests arrive as structured data rather than free-text fax attachments, enabling faster adjudication and more-consistent decisions.
CMS-0057-F adds operational requirements beyond the technical APIs. Payers must respond to standard PA requests within 7 calendar days and urgent requests within 72 hours (stronger than prior timelines). Payers must report annual PA volume, approval/denial rates, and processing times. PA data for active authorizations must be transferred via the Payer-to-Payer API when members switch plans. These requirements extend beyond technical FHIR implementation to substantive PA-process reform.
For RCM and revenue-cycle operations, the Prior Authorization API represents transformative potential. Denials traceable to PA process friction — missed deadlines, incomplete documentation, scope creep — drop materially when the workflow is structured, EHR-integrated, and with real-time payer feedback. Authorization-related AR delays compress as the process moves faster. Early-adopter estimates suggest 30–60% reduction in PA-related claim denials in target specialties once the infrastructure matures.
Prior Authorization API is one of the compliance areas where documentation discipline determines audit outcomes more than policy sophistication. Practices that invest in clean Prior Authorization API records, consistent prior authorization workflows, and auditable da vinci crd evidence come out of OIG, RAC, and MAC audits with materially smaller recoupment exposure than practices with equivalent policies but weaker paper trails.
Industry benchmark
CMS-0057-F compliance dates: CRD, DTR, PAS APIs by January 2026 for most covered payers. PA decision timelines: standard 7 days, urgent 72 hours. Annual PA-metric public reporting begins 2027.
Worked example
A physician at a hospital orders a cardiac MRI. The EHR fires the order-select CDS Hooks; the payer's CRD service returns a card indicating PA is required and provides a link to launch DTR. The clinician launches DTR as an embedded SMART app, completes the payer-specified documentation using pre-populated chart data, and submits via PAS. The payer returns an approval within 4 hours; the MRI is scheduled without denial risk.
Frequently asked questions — Prior Authorization API
Does the API apply to drugs?
No — the CMS-0057-F PA API applies to non-drug items and services. Drug PAs continue to use Surescripts/NCPDP channels with separate modernization trajectories.
When do payers have to comply?
January 2026 for most covered payers. Some components have phased timelines; consult specific rule text for each component's compliance date.
Does the API replace portal-based PA?
Over time. Portal-based workflows continue for unusual-circumstance and non-covered-payer PAs, but the rule's intent is to move the mainstream workflow into FHIR-based structured exchange.
Disclaimer
This glossary entry is operational reference for revenue-cycle and medical-billing professionals. It is not legal, clinical, or contractual advice. Industry benchmarks cite named public sources where available; always verify against the current guidance from the authority body before relying on a number in a contract, policy, or compliance filing.