Skip to content

Stratgik — technology strategy and business systems engineering.
Delivery across the USA, UK, UAE and India.

Talk about a problem

AI Prior Authorization Automation and CMS-0057-F in the US

Published 28 September 2026 · 10 min read

What US payers and providers can legally automate in prior authorization, the CMS-0057-F 2026 and 2027 deadlines, and how to sequence the build.

AI Prior Authorization Automation and CMS-0057-F in the US

The short answer

US healthcare providers and payers can automate most of the prior authorization workflow with AI and FHIR APIs, but AI cannot make the medical necessity decision itself. Federal rule CMS-0057-F requires impacted payers to run four FHIR APIs, including a Prior Authorization API, by January 1, 2027, and since January 1, 2026 those payers must answer expedited requests within 72 hours and standard requests within seven calendar days. The practical build for a provider organization is therefore an assistive layer: document retrieval, payer rule lookup, packet assembly, status tracking and denial triage, with a licensed clinician signing every clinical judgment.

Below: what the rule requires, what AI may and may not do, where the savings are real, and how to sequence a build. Stratgik is a technology firm, not a law firm — confirm your obligations with US healthcare counsel before you ship.

Why prior authorization is the highest-value automation target in US healthcare operations

The burden is measured, not anecdotal. The 2025 AMA prior authorization physician survey of 1,000 practicing physicians found an average of 40 prior authorizations per physician per week, consuming about 13 hours of physician and staff time. Forty percent said their practice employs staff working exclusively on prior authorization; 95% reported care delays, and 26% said prior authorization had led to a serious adverse event for a patient in their care.

On the transaction side, CAQH has consistently identified prior authorization as the least automated of the core administrative transactions. Its 2024 Index estimated that moving to the electronic standard would save the industry roughly $515 million a year and save medical providers and staff about 14 minutes per authorization. The 2025 CAQH Index, published February 19, 2026, put the remaining savings opportunity from fully automating manual and partially manual transactions at $21 billion.

Fourteen minutes per authorization, across forty a week per physician, is the entire business case. No speculative AI productivity claim is needed to justify the work.

What CMS-0057-F actually requires, and by when

The CMS Interoperability and Prior Authorization final rule was released on January 17, 2024. It applies to Medicare Advantage organizations, state Medicaid and CHIP fee-for-service programs, Medicaid managed care plans, CHIP managed care entities, and Qualified Health Plan issuers on the federally facilitated exchanges. Drugs are excluded from the prior authorization provisions.

Two dates matter, and they are commonly conflated.

RequirementWho it bindsCompliance date
Expedited prior authorization decisions within 72 hours; standard decisions within seven calendar days (excluding drugs)Impacted payersJanuary 1, 2026
Specific reason given for every prior authorization denialImpacted payers2026
Annual public reporting of prior authorization metrics on the payer's websiteImpacted payersFirst report by March 31, 2026
Patient Access API, Provider Access API, Payer-to-Payer API and Prior Authorization APIImpacted payersJanuary 1, 2027

The CMS fact sheet and the rule's implementation page are the authoritative references.

The rule binds payers, not providers — the single most important planning input for a provider-side roadmap. Nothing obliges a hospital or specialty group to consume the new APIs, but from January 1, 2027 they will exist at impacted payers, and practices ready to call them will get decisions in hours where competitors wait days. Commercial plans outside the impacted categories are not covered at all, so a realistic 2027 architecture handles API-enabled and fax-and-portal payers side by side for years.

Voluntary payer commitments are moving faster than the rule in places

On June 23, 2025, AHIP announced that more than 50 health plans covering 257 million Americans had committed to six prior authorization reforms. The commitments include standardized electronic submission using FHIR APIs by January 1, 2027, reductions in the scope of medical prior authorization from January 1, 2026, honoring existing authorizations for 90 days during plan transitions, and real-time responses on at least 80% of electronic approvals by 2027.

Progress is partial. On April 7, 2026, AHIP and the Blue Cross Blue Shield Association reported that participating insurers had eliminated 11% of prior authorization requirements, about 6.5 million fewer requests, with reductions above 15% in Medicare Advantage. Plan for a mixed environment, not a clean cutover.

What AI may and may not do in a US prior authorization workflow

This is where most vendor pitches overreach. Two constraints are already binding.

Federal, Medicare Advantage. CMS has confirmed that Medicare Advantage organizations may use algorithms and AI to assist with coverage determinations, but a decision must rest on the individual enrollee's medical history, physician recommendations and clinical notes — not generalized datasets or predictions about similar patients. A predictive length-of-stay tool cannot by itself justify terminating post-acute care, and CMS reminded plans that AI can exacerbate inequities and that ACA non-discrimination requirements still apply (see Norton Rose Fulbright's analysis).

State, and spreading. California's SB 1120, the Physicians Make Decisions Act, took effect January 1, 2025, covering health care service plans, disability insurers and their contracted utilization review vendors. AI may not autonomously deny, delay or modify care, may not decide on generalized datasets alone, and must rely on the enrollee's specific clinical data; a licensed physician or other competent professional must make the medical necessity determination. Plans must disclose how AI is used, file written policies with regulators, and face audit by the Department of Managed Health Care and the Department of Insurance. Fenwick's write-up has the detail. Other states have followed with variations, so a national payer or UM vendor needs a per-state matrix.

The workable division of labor, for both payers and providers:

TaskSafe to automateRequires a human
Determining whether a service needs prior authorization for this payer and planYes — rules lookup, deterministic where possibleException handling
Finding and extracting supporting clinical documentation from the EHRYes — retrieval and summarization, with citations back to the source noteClinician review of the summary
Assembling and submitting the request packetYes — via FHIR API, X12 278 or portal automationSign-off on clinical content
Chasing status and logging decisionsYesNo
Classifying a denial reason and drafting an appealDraft onlyClinician review before submission
Deciding medical necessity, or denying, delaying or modifying careNoLicensed clinician, on individualized data

The build: what a realistic provider-side system looks like

Assume a specialty group or mid-sized health system. The architecture that survives audit and actually reduces hours has five components.

1. A payer rules layer. A maintained, versioned store of which services require authorization by payer, plan and place of service. This is data operations, not AI, and it is where most of the value sits — a request you never had to file costs nothing.

2. A documentation retrieval and assembly service. Pull the relevant notes, imaging reports, medication history and prior conservative-therapy evidence from the EHR against the payer's stated criteria. Every extracted claim carries a pointer back to its source document; unsourced generated text is an audit liability.

3. A submission adapter with two paths. FHIR submission using the HL7 Da Vinci pattern — coverage requirements discovery, documentation templates and rules, prior authorization support — for API-enabled payers from 2027, plus X12 278 and supervised portal automation for everyone else. Build the adapter interface first so payers can be added without touching the core.

4. A status and denial engine. Poll or subscribe for decisions, track against the 72-hour and seven-day clocks, and classify denials by reason so the appeal path is chosen by pattern rather than by whoever picks up the file. Because payers must now state a specific denial reason, this data is finally structured enough to learn from.

5. An audit log. Every AI-generated artifact, the model and version that produced it, the sources used, and the identity and timestamp of the human who approved it. If a regulator or plaintiff asks how a decision was made, this log is the answer. Build it on day one.

Data protection sits underneath all of it. Protected health information flowing to any AI vendor needs a HIPAA business associate agreement, a documented minimum-necessary analysis, and confirmation that your inputs are not used for model training. State privacy laws add consumer rights for data outside HIPAA's scope; our US privacy compliance page covers how those interact.

Implementation checklist

  • Confirm which of your payer mix is an "impacted payer" under CMS-0057-F and which is not. Size both populations.
  • Baseline your numbers: authorizations per week, touch time each, first-pass approval rate, denial rate by reason, days to decision.
  • Pull each impacted payer's publicly reported prior authorization metrics, required on payer websites since March 31, 2026, and compare them with your own experience.
  • Build the payer rules layer before the AI layer, and measure how many requests you can avoid filing at all.
  • Pick two high-volume, high-friction service lines for the first release. Do not start enterprise-wide.
  • Require source citations on every extracted clinical fact, and make clinician approval a blocking step, not a notification.
  • Execute business associate agreements with every vendor touching PHI; confirm no-training-on-your-data terms in writing.
  • If you perform or contract utilization review, build a state-by-state AI restriction matrix starting with California SB 1120, and file the policies your regulators require.
  • Design the FHIR adapter now even if no payer you work with is live yet; keep the fax and portal path first-class.
  • Instrument the audit log from the first commit, with model version, prompt, sources and approver on every artifact.
  • Re-measure at 60 and 120 days. If touch time has not fallen, the automation is in the wrong place.

What this costs and how to decide

A focused first release — rules layer for two service lines, retrieval and packet assembly, status tracking, audit log, one submission path — is a few months of a small senior team, not a multi-year program. The expensive mistakes are predictable: building a general-purpose "AI prior auth agent" before the payer rules data is clean, buying a platform whose terms do not survive a HIPAA review, and automating submission while leaving denial handling manual, which simply moves the queue.

Weighing a vendor platform against a system your team controls? Our build vs buy tool works through the trade-offs, and the AI automation opportunity scanner ranks prior authorization against other candidates in your operation.

Frequently asked questions

Does CMS-0057-F require providers to do anything by January 1, 2027?

No. The obligations fall on impacted payers — Medicare Advantage organizations, Medicaid and CHIP fee-for-service programs and managed care plans, and Qualified Health Plan issuers on the federally facilitated exchanges. Providers need not adopt the APIs. The incentive is speed: from 2027 the Prior Authorization API will exist at those payers, and organizations able to submit through it will see faster decisions than those still faxing.

Can AI legally deny a prior authorization request in the United States?

Not on its own. CMS has said Medicare Advantage organizations may use algorithms to assist coverage determinations, but the decision must rest on the individual's medical history and clinical circumstances rather than generalized data. California's SB 1120 goes further for plans it covers, prohibiting AI from autonomously denying, delaying or modifying care and requiring a licensed clinician to make the medical necessity determination. Treat AI as assistive and document the human decision.

What are the new prior authorization decision deadlines?

Since January 1, 2026, impacted payers must decide expedited requests within 72 hours and standard requests within seven calendar days, excluding prior authorizations for drugs. They must also give a specific reason for each denial and publish prior authorization metrics on their websites annually, with the first reports due by March 31, 2026.

Is HIPAA a barrier to using large language models for prior authorization?

It is a constraint, not a barrier. Any vendor processing protected health information on your behalf is a business associate and needs a business associate agreement. Apply the minimum necessary standard to what you send, confirm contractually that your data is not used to train shared models, and keep an audit trail of what was generated and who approved it. Some organizations reduce exposure further by de-identifying or by running models in their own cloud tenancy.

How much time does prior authorization automation actually save?

CAQH's 2024 Index estimated roughly 14 minutes saved per authorization by moving to the electronic standard, alongside about $515 million in annual industry savings. Against the AMA's 40 authorizations per physician per week, that is a substantial recovery of hours. Savings vary widely by payer mix, so baseline your own touch time before committing to a target.

Will the voluntary insurer commitments make this work unnecessary?

Unlikely in the near term. As of April 7, 2026, participating insurers reported eliminating 11% of prior authorization requirements. That is real progress but leaves the large majority in place, and the 80% real-time response target is set for 2027. Commercial plans outside the CMS-0057-F scope carry no federal deadline at all.

Prior authorization is the rare automation project where the regulatory deadline, the operational pain and the available standards all point the same way. The work that pays off is unglamorous: clean payer rules, sourced retrieval, two submission paths, structured denial data and an audit log that withstands scrutiny — with a clinician making every clinical call. If you are scoping this for a US provider or payer, start with our United States practice page, or see how we approach regulated builds under custom software.

Tell us what isn't working.

One process, one system, one decision you are stuck on. We will come back with how we would approach it, what it would take, and whether it needs building at all.

The Stratgik model

Strategy first. Technology that follows through.

Four stages, in order. Most businesses need them one at a time.