Service

The CMS Interoperability and Prior Authorization Final Rule (CMS-0057-F) is a federal rule that sets prior authorization decision timeframes, denial-reason, public reporting and API requirements for Medicare Advantage organizations, Medicaid and CHIP programs and plans, and certain exchange issuers. It applies to those impacted payers and shapes the work of the utilization management organizations that act for them. Integral Healthcare Solutions (IHS) aligns your prior authorization procedures, notices and reporting to CMS-0057-F; your clinicians decide and your engineers build the APIs.

Last reviewed: October 2026.

What is CMS-0057-F?

CMS-0057-F is the final rule titled "Medicare and Medicaid Programs; Patient Protection and Affordable Care Act; Advancing Interoperability and Improving Prior Authorization Processes." It was published on February 8, 2024 at 89 FR 8758 and took effect April 8, 2024 (Federal Register, document 2024-00895).

The rule splits its requirements into two groups with different dates. CMS states: "Impacted payers must also implement certain operational provisions, generally beginning January 1, 2026. In response to public comment on the proposed rule, impacted payers have until compliance dates, generally beginning January 1, 2027, to meet the API development and enhancement requirements in this final rule. The exact compliance dates vary by the type of payer" (CMS fact sheet).

The operational provisions this page covers are:

On the API side, CMS requires impacted payers "to add information about prior authorizations (excluding those for drugs) to the data available via that Patient Access API ... This requirement must be implemented by January 1, 2027" (CMS fact sheet).

Drugs are outside the rule. CMS states: "As with all policies in this final rule, this provision does not apply to prior authorization decisions for drugs" (CMS fact sheet). CMS proposed in April 2026 to extend prior authorization requirements to drugs (CMS-0062-P, CMS fact sheet). This page covers the 2024 final rule only and does not treat that proposal as final.

Who needs it and what triggers it

The rule applies to impacted payers, which CMS lists as "Medicare Advantage (MA) organizations, state Medicaid and Children's Health Insurance Program (CHIP) Fee-for-Service (FFS) programs, Medicaid managed care plans, CHIP managed care entities, and Qualified Health Plan (QHP) issuers on the Federally Facilitated Exchanges (FFEs), (collectively 'impacted payers')" (CMS fact sheet). Delegated utilization management organizations that run prior authorization for those payers carry the work in practice; the fact sheet does not address delegates directly, so how a delegate is bound is a question for the plan's counsel.

The work usually starts with one of these events:

How IHS helps

IHS works through a fixed process against the operating provisions of CMS-0057-F that apply to your organization:

  1. Gap assessment. IHS reviews your prior authorization policies, intake workflow, decision tracking, notice templates and reporting against the rule's operating provisions.
  2. Document and evidence mapping. IHS builds a crosswalk from each provision to a process owner and the record that shows it is met.
  3. Drafting. IHS drafts the decision-tracking, denial-reason communication, escalation and public metrics reporting procedures, for your medical director, compliance lead and counsel to review and approve.
  4. Mock file review. IHS tests a sample of prior authorization files against the drafted procedures and the rule's timeframes and denial-reason provisions, and lists what would not hold up.
  5. Readiness support. IHS drafts responses to the mock review findings and staff walkthrough material for the people who handle requests.

What your organization supplies: current UM policies, sample prior authorization files, notice and denial templates, reporting data, and named engineering and legal leads.

The limit: API builds are your engineers' work. Medical necessity decisions are your clinicians'. IHS does not give a legal opinion on which provisions apply to you.

Related IHS pages: Compliance Services, Compliance Program Development, Case Management and UM and NCQA Utilization Management.

What to have ready

Gathering these items before the first working session shortens the gap assessment. Items that quote the CMS fact sheet for the final rule published at 89 FR 8758 reflect its text. The escalation procedure, the drug-separation rules and the engineering lead are IHS's working list items.

When the list is together, the introductory call is the place to start.

How it compares

Plans and delegates often weigh these routes. They are not exclusive.

RouteWhat it isHow it relates to CMS-0057-F
CMS-0057-F compliance workA federal requirement for the impacted payers CMS lists (CMS fact sheet).The rule itself; the operating provisions apply to impacted payers whether or not they hold an accreditation.
URAC Health Utilization Management accreditationA URAC accreditation for utilization management. IHS has not reviewed URAC's current standards text for this page.This page does not compare URAC's timeframes to the rule. Any comparison is made against the current URAC standards text.
NCQA Utilization Management accreditation or certificationAn NCQA utilization management program. IHS has not reviewed NCQA's current program text for this page. Maureen Plumstead leads IHS's NCQA accreditation work.This page does not compare NCQA's timeframes to the rule.
Plans not on CMS's listPayers outside the impacted payer categories.The fact sheet lists who is covered; it does not list who is excluded. Coverage is confirmed by your counsel.

What it costs

CMS-0057-F is a federal regulatory requirement, not an accreditation program; IHS found no application fee for it on the pages reviewed. CMS does not publish a fee schedule for compliance with the rule on the pages we reviewed; your costs depend on scope, meaning the number of products, delegates, notice channels and reporting systems involved. IHS scopes each engagement after a free introductory call.

What this is not

Frequently asked questions

What is the CMS Interoperability and Prior Authorization Final Rule (CMS-0057-F)?

CMS-0057-F is a federal final rule, published in the Federal Register on February 8, 2024 at 89 FR 8758 and effective April 8, 2024. It sets prior authorization operating requirements for impacted payers, generally beginning January 1, 2026, and API requirements, generally beginning January 1, 2027. CMS states that the exact compliance dates vary by the type of payer.

Which health plans are impacted payers under CMS-0057-F?

CMS lists Medicare Advantage organizations, state Medicaid and CHIP fee-for-service programs, Medicaid managed care plans, CHIP managed care entities, and Qualified Health Plan issuers on the Federally Facilitated Exchanges, collectively called impacted payers.

What are the prior authorization decision timeframes?

CMS requires impacted payers, excluding QHP issuers on the Federally Facilitated Exchanges, to send prior authorization decisions within 72 hours for expedited (urgent) requests and seven calendar days for standard (non-urgent) requests. IHS tests sample files against those timeframes in a mock file review.

What must a denial notice say under the specific-reason requirement?

CMS states that beginning in 2026, impacted payers must provide a specific reason for denied prior authorization decisions, regardless of the method used to send the request. The decision may be communicated by portal, fax, email, mail or phone. IHS drafts denial-reason language and the procedure behind it for your clinical and legal reviewers to approve.

Which prior authorization metrics must we post publicly, and when?

CMS requires impacted payers to report certain prior authorization metrics annually by posting them on their website, with the initial set due by March 31, 2026. IHS works from the final rule with your reporting team to map each metric to its data source and owner.

Does CMS-0057-F apply to drug prior authorizations?

No. CMS states that, as with all policies in the final rule, the denial-reason provision does not apply to prior authorization decisions for drugs, and the Patient Access API requirement covers prior authorizations excluding those for drugs. CMS proposed in April 2026 to extend prior authorization requirements to drugs (CMS-0062-P, CMS fact sheet). This page covers the 2024 final rule only and does not treat that proposal as final.

Do QHP issuers on the federal exchange have to meet the 72-hour and 7-day timeframes?

CMS excludes QHP issuers on the Federally Facilitated Exchanges from the decision timeframe requirement in its fact sheet. They remain on CMS's list of impacted payers for the rule's other provisions.

Does CMS-0057-F apply to our delegated utilization management vendor?

The CMS fact sheet names the impacted payers; it does not address delegated utilization management vendors on the page we reviewed. Whether a delegate is bound directly or through its contract with the plan is a question for the plan's counsel. IHS can align a delegate's procedures to the obligations the plan passes down.

What is the difference between the January 2026 operational deadlines and the January 2027 API deadlines?

CMS states that impacted payers must implement certain operational provisions generally beginning January 1, 2026, and have until compliance dates generally beginning January 1, 2027 to meet the API development and enhancement requirements. The API work, including adding prior authorization information to the Patient Access API by January 1, 2027, is an engineering build.

How do we coordinate UM policy changes with the Prior Authorization API build?

IHS builds a crosswalk from each operating provision to its process owner and record, and your engineering lead uses the same crosswalk to see which procedures the API work touches. IHS drafts the procedures; your engineers build the APIs.

Talk with IHS's CEO

A 30-minute introductory meeting with Thomas G. Goddard, JD, PhD, to scope what your organization needs.

Schedule a Free Discovery Session