What happens when a provider needs prior authorization but the request still depends on payer portals, fax, phone calls, or manual document exchange?
CMS is moving certain prior authorization workflows toward standardized electronic exchange. Under the CMS Interoperability and Prior Authorization final rule, certain impacted payers must support a Prior Authorization API for medical items and services beginning January 1, 2027. Separate operational requirements, including decision timeframes and specific denial reasons, generally began in 2026.
For providers, the change is not simply about replacing a fax with a digital form. The CMS framework connects prior authorization data, documentation requirements, requests, responses, and status information through standards-based technology.
This guide explains how the process works and what healthcare organizations should know in 2026 as the 2027 API requirements approach.
What Is Electronic Prior Authorization?
Electronic prior authorization, or ePA, is the electronic exchange of information needed to request and process authorization for a healthcare service or item.
Depending on the implementation, the workflow can support:
- Identifying whether prior authorization is required
- Reviewing coverage and documentation requirements
- Sending patient and clinical information
- Submitting the authorization request
- Receiving payer responses
- Checking authorization status
- Receiving approval, denial, or requests for more information
CMS describes the Prior Authorization API as a mechanism that can identify documentation requirements and support prior authorization requests and responses.
What CMS Changed With the Interoperability and Prior Authorization Final Rule
CMS finalized the Interoperability and Prior Authorization final rule, CMS-0057-F, in 2024. The rule applies to specific categories of impacted payers, including:
- Medicare Advantage organizations
- State Medicaid and CHIP fee-for-service programs
- Medicaid managed care plans
- CHIP managed care entities
- Qualified Health Plan issuers on Federally-facilitated Exchanges
The rule includes both operational requirements and API requirements. The exact compliance date depends on the provision and payer type.
CMS Electronic Prior Authorization Timeline
The current timeline has two major stages.
| Timeline | What Changes |
| January 1, 2026 | Certain impacted payers must meet operational prior authorization requirements |
| January 1, 2026 | Certain payers must provide specific reasons for denied prior authorization requests |
| March 31, 2026 | Initial prior authorization metrics reporting deadline |
| January 1, 2027 | Prior Authorization API requirements begin for impacted payers |
| CY 2027 | MIPS-eligible clinicians begin reporting the Electronic Prior Authorization measure, subject to applicable requirements or exclusions |
| CY 2027 | Eligible hospitals and CAHs begin reporting the electronic prior authorization measure under the Medicare Promoting Interoperability Program |
CMS states that the API compliance dates generally begin January 1, 2027, while several operational provisions began January 1, 2026.
How Does Electronic Prior Authorization Work?
A typical electronic prior authorization workflow can be understood in several steps.
1. Identify Whether Authorization Is Required
The process begins by determining whether the planned item or service requires prior authorization. A standards-based electronic workflow can help retrieve payer requirements rather than requiring staff to search through multiple sources manually.
However, practices should still verify the applicable payer policy and patient-specific requirements.
2. Review Documentation Requirements
The Prior Authorization API is designed to communicate information about covered items and services and documentation requirements. This can help the provider determine what information the payer expects before submitting the request.
Depending on the service, required information may include:
- Patient information
- Diagnosis information
- Procedure or service details
- Clinical documentation
- Previous treatment information
- Supporting test results
- Provider information
3. Pull Information From the EHR
One of the key benefits of an electronic workflow is reducing repeated manual data entry. CMS encourages providers to work with EHR vendors to prepare their systems for electronic prior authorization and FHIR API testing.
When properly integrated, relevant information can move from the provider’s existing workflow into the authorization request.
4. Submit the Prior Authorization Request
The provider submits the request electronically through the supported workflow. The CMS final rule requires the Prior Authorization API to support a request and response process for impacted payers.
The electronic request can reduce reliance on separate payer portals, fax transmission, and repeated manual entry, depending on payer and system implementation.
5. Receive the Payer’s Response
The payer’s response can communicate whether the request is:
- Approved
- Denied
- Waiting for additional information
For an approval, the API must communicate the authorization end date or circumstance when the authorization ends. For a denial, it must communicate a specific reason.
6. Track the Authorization
The authorization status should then be available within the provider’s workflow or connected technology. Tracking matters because an authorization is not simply a one-time approval. Staff may need to confirm:
- Authorization number
- Approved service
- Approved dates
- Approved units
- Status
- Expiration
- Additional documentation requirements
The exact fields available depend on the payer’s implementation.
What Are the CMS Prior Authorization Decision Timeframes?
CMS established specific decision timeframes for certain impacted payers. For medical items and services, impacted payers generally must provide:
- Expedited requests: within 72 hours
- Standard requests: within 7 calendar days
The standard seven-calendar-day timeframe does not apply to Qualified Health Plan issuers on the Federally-facilitated Exchanges under this particular provision. Other contractual or state requirements may impose different or shorter timeframes.
These are payer decision timeframes, not a guarantee that every prior authorization will be approved within that period.
What Information Must Be Included With a Denial?
Beginning in 2026, impacted payers must provide a specific reason when denying a prior authorization request for applicable medical items and services.
The purpose is to give providers information that can help them determine whether correction, additional documentation, resubmission, or appeal may be appropriate.
This is important for revenue cycle teams because vague denial information can make it harder to determine the correct next action.
What Is the CMS Prior Authorization API?
The Prior Authorization API is the technology component of CMS’s electronic prior authorization framework. Under the final rule, impacted payers must implement and maintain an API that:
- Contains information about covered items and services
- Identifies documentation requirements
- Supports prior authorization requests
- Supports payer responses
- Communicates approval information
- Communicates denial information and the specific denial reason
- Communicates requests for additional information
The API requirement begins January 1, 2027, for impacted payers under the final rule.
What Is FHIR and Why Does It Matter?
FHIR stands for Fast Healthcare Interoperability Resources. It is a healthcare data standard used to exchange information between systems in a structured way.
CMS’s final rule requires specified APIs to use adopted standards, including HL7 FHIR Release 4.0.1 and related implementation specifications.
For providers, the important point is simple:
FHIR helps different healthcare systems exchange structured information using a common technical framework.
That is different from sending a document through fax or uploading files manually into separate payer portals.
Does Electronic Prior Authorization Mean Fax and Portals Will Disappear?
Not necessarily. CMS is encouraging movement away from manual workflows, but provider and payer workflows will continue to vary during implementation.
CMS’s electronic prior authorization guidance specifically encourages providers to prepare for electronic workflows while working with their EHR vendors and payer partners.
A practice should therefore treat electronic prior authorization as an additional technology-enabled workflow that requires implementation and testing, rather than assuming every payer will operate identically on January 1, 2027.
Electronic Prior Authorization and MIPS
CMS also created an Electronic Prior Authorization measure for eligible clinicians under the MIPS Promoting Interoperability performance category.
For the CY 2027 performance period, MIPS eligible clinicians must attest that they requested at least one applicable prior authorization electronically through a Prior Authorization API using data from certified EHR technology, or report an applicable exclusion.
This means practices participating in MIPS should review their 2027 workflow and reporting requirements rather than waiting until the end of the performance period.
Electronic Prior Authorization for Hospitals and CAHs
Eligible hospitals and critical access hospitals also have an electronic prior authorization measure under the Medicare Promoting Interoperability Program.
For the 2027 EHR reporting period, applicable hospitals and CAHs must attest to requesting at least one applicable prior authorization electronically through a Prior Authorization API using certified EHR technology, or report an applicable exclusion.
CMS’s current electronic prior authorization guidance also notes that the measure becomes mandatory for eligible hospitals and CAHs beginning with the CY 2028 reporting period under the relevant finalized rule.
What Should Medical Practices Do Before 2027?
Healthcare organizations should start with workflow and technology readiness rather than waiting for the implementation deadline.
Check EHR Capabilities
Ask your EHR vendor:
- Does the system support electronic prior authorization?
- Can it connect with payer Prior Authorization APIs?
- Does it support required FHIR-based workflows?
- How will authorization information appear in the EHR?
- Can staff track authorization status?
- What upgrades are required?
CMS specifically recommends that providers discuss implementation timelines, API capabilities, testing, system upgrades, and training with their EHR vendors.
Review Current Prior Authorization Workflows
Document how your practice handles:
- Authorization requests
- Documentation collection
- Payer submissions
- Status checks
- Denials
- Additional information requests
- Appeals
- Expiration dates
- Authorization numbers
Then identify which steps are manual and which could move into an electronic workflow.
Train Staff
Electronic prior authorization changes the workflow, but it does not remove the need for staff oversight. Staff should understand:
- When authorization is required
- What information must be submitted
- How to monitor requests
- How to respond to additional information requests
- How to handle denials
- How to document authorization details
- When to escalate an issue
Test Before the Deadline
CMS encourages providers to participate in FHIR API testing with EHR vendors and payer partners. Testing can help identify:
- Missing data
- Integration problems
- Documentation gaps
- Authentication issues
- Workflow errors
- Status-tracking problems
CMS’s current guidance specifically recommends early testing to identify gaps and validate real-world workflows.
What Are the Benefits of Electronic Prior Authorization?
Electronic prior authorization is designed to reduce manual administrative work and improve information exchange. Potential workflow benefits include:
- Less fax-based communication
- Less duplicate data entry
- Easier access to documentation requirements
- More standardized information exchange
- Better visibility into authorization status
- Faster transmission of supporting information
- Improved integration between EHR and payer workflows
CMS identifies reduced reliance on manual, portal-based, and fax workflows as one of the goals of electronic prior authorization.
However, implementation quality matters. An electronic workflow can still create delays if data are incomplete, payer requirements are unclear, systems do not integrate correctly, or staff do not know how to manage exceptions.
Electronic Prior Authorization vs. Manual Prior Authorization
| Electronic Prior Authorization | Manual Prior Authorization |
| Uses structured electronic exchange | Often relies on portals, fax, phone, or manual forms |
| Can connect with EHR workflows | Staff may re-enter information |
| Supports API-based data exchange | Information may move between separate systems |
| Can provide structured status information | Status may require manual checking |
| Uses standardized technical frameworks | Workflow can vary significantly by payer |
| Requires technology integration and testing | Requires more manual workflow management |
The goal is not simply to make the same manual process digital. The larger change is creating a more connected exchange between providers, payers, and health IT systems.
What About the 2026 CMS Prior Authorization for Drugs Proposal?
This is an important distinction for content published in 2026.
CMS issued the 2026 CMS Interoperability Standards and Prior Authorization for Drugs proposed rule, CMS-0062-P, on April 10, 2026. The proposal would extend many electronic prior authorization requirements to drugs and proposes additional changes involving standards, reporting, and decision timeframes.
Because it is a proposed rule, its proposals should not be presented as current final requirements. For current provider planning, organizations should distinguish between:
- Requirements already finalized under CMS-0057-F
- Requirements beginning in 2026
- API requirements beginning in 2027
- 2026 proposals that may change if finalized
This distinction is especially important when publishing compliance content.
Electronic Prior Authorization Readiness Checklist
Use this checklist to prepare for the upcoming CMS requirements:
- Identify which payers your practice works with
- Determine which prior authorizations are required
- Review your current authorization workflow
- Confirm EHR electronic prior authorization capabilities
- Ask your EHR vendor about FHIR and API support
- Identify manual fax and portal workflows
- Create a process for tracking authorization status
- Train staff on electronic workflows
- Establish a process for handling denials and additional information requests
- Test integrations before the 2027 implementation date
- Monitor CMS updates for proposed and finalized rule changes
FAQs About Electronic Prior Authorization
What is electronic prior authorization?
Electronic prior authorization is the electronic exchange of information between providers and payers to request and process authorization for applicable healthcare services or items. CMS’s framework uses standards-based APIs to support requests, responses, documentation requirements, and authorization information.
When does the CMS Prior Authorization API requirement begin?
For impacted payers under CMS-0057-F, the Prior Authorization API requirements begin January 1, 2027. The exact requirements and compliance dates vary by payer type.
What are the CMS prior authorization decision timeframes?
For applicable impacted payers, expedited prior authorization decisions generally must be provided within 72 hours and standard decisions within seven calendar days. The seven-day provision does not apply to QHP issuers on Federally-facilitated Exchanges under this particular CMS rule.
What is a Prior Authorization API?
A Prior Authorization API is a standards-based electronic interface that supports the exchange of prior authorization information between providers and payers. CMS requires impacted payers to use the API to communicate coverage and documentation requirements and support authorization requests and responses beginning in 2027.





