Four Health Systems Automated the Prior Authorization Question, Not the Answer
The piece of the federal prior authorization mandate that shipped five months early is the piece that cannot deny anything. Ochsner, Froedtert ThedaCare, Denver Health and Summit Health can now see instantly whether an insurer requires authorization. Whether that authorization is granted, how fast, and on what grounds are governed by different provisions of the same rule, and those have been legally binding since January 2026 without a single launch announcement.
- What went live is discovery, not decision. Four health systems and three payers, UnitedHealthcare, Network Health and Aetna, are using the Coverage Requirements Discovery API to establish whether an authorization is needed, with 16 further payers in testing, more than five months before the 1 January 2027 compliance date.
- That is one function of one of four APIs the rule requires. CMS-0057-F obliges impacted payers to run Patient Access, Provider Access, Payer-to-Payer and Prior Authorization APIs by the same date, and the Prior Authorization API must return the approval, the denial with a specific reason, or a request for more information.
- The provisions that determine whether a patient is treated took effect nineteen months ago. Since 1 January 2026, impacted payers have owed decisions within 72 hours for expedited and seven calendar days for standard requests, plus a specific reason for every denial, and the first public reporting of approval and denial rates fell due on 31 March 2026.
The distinction matters commercially because the two halves fail differently. Discovery removes phone calls, faxes and portal retyping from the front of the process, which is real administrative saving and lands on the provider’s cost line. It does not shorten a decision, raise an approval rate or narrow the grounds for refusal, which is where a manufacturer’s volume and a patient’s treatment actually sit. A reader can stop here with the full picture. The sections below are the detail.
What actually went live, and how narrow it is
Epic announced on 17 August that clinicians at Ochsner Health, Froedtert ThedaCare Health, Denver Health and Summit Health can determine at the point of ordering or scheduling whether an insurer requires prior authorization. Previously each system maintained its own list of payer requirements, which is expensive to keep current and causes delays when it drifts out of date.
The mechanism is Coverage Requirements Discovery, an industry-standard interface that queries the payer directly. UnitedHealthcare, Network Health and Aetna are live, and sixteen more payers are in testing. Ochsner’s assistant vice president for revenue cycle and financial clearance framed the benefit precisely: a manual, time-consuming process becomes a streamlined one, reducing administrative burden.
That framing is accurate and it is worth reading closely, because it is a claim about burden rather than about outcomes. Where no authorization is required, treatment can begin immediately instead of waiting on a check. Where one is required, the request can start sooner. Neither statement asserts that more requests are approved or that any are decided faster.
The prior authorization sequence as structured by the CMS Interoperability and Prior Authorization final rule, against what the 17 August launch covers. Stage order is illustrative of workflow, not a regulatory numbering.
CMS-0057-F as published · Company announcement 17 August 2026 · Compiled 19 August 2026
Three of the four required interfaces are not in this announcement
The CMS Interoperability and Prior Authorization final rule requires impacted payers, broadly Medicare Advantage organisations, Medicaid and CHIP programmes and qualified health plan issuers on the federally facilitated exchanges, to run four interfaces from 1 January 2027: Patient Access, Provider Access, Payer-to-Payer and Prior Authorization. The Prior Authorization interface must communicate whether the payer approves the request and when that authorization ends, denies it with a specific reason, or asks for more information.
Coverage Requirements Discovery sits ahead of all of that. It resolves whether the question needs asking. The stages that follow, assembling the documentation a payer wants, submitting the request and receiving the determination, are the substance of the mandate and none of them appears in this launch.
That is not a criticism of the participants. Shipping the front of a sequence first is sound engineering, and doing it five months early with three payers live and sixteen testing is a meaningful implementation signal in a programme where the harder deadline is an engineering one. It does mean the announcement measures progress against burden rather than against access.
The provisions that decide treatment have been in force for nineteen months, quietly
Separately from the interface requirements, CMS-0057-F imposed operational obligations that took effect on 1 January 2026. Impacted payers owe prior authorization decisions within 72 hours for expedited requests and seven calendar days for standard ones. Every denial must carry a specific reason rather than a generic refusal. And payers must publish prior authorization metrics annually, including approval and denial rates, with the first report due on 31 March 2026 covering the previous calendar year.
None of those required an API. None generated a launch announcement. All three bear directly on whether a therapy reaches a patient and how quickly, which is precisely the question a manufacturer’s access team, a specialty pharmacy and a patient are asking.
For commercial teams the practical consequence is a measurement one. Faster discovery compresses the interval between the decision to treat and the submission of a request. It leaves untouched the interval between submission and determination, and it leaves the denial rate exactly where it was. Anyone modelling improved time to therapy from electronic prior authorization should separate those two intervals, because only the first has moved and only for the payers and systems that are live.
Two things worth watching. Whether the published metrics from March 2026 show any movement in approval rates now that specific denial reasons are mandatory, since that is the only public dataset that answers the outcome question rather than the burden question. And whether the sixteen payers in testing convert before January, because a discovery interface that covers three payers in a system that contracts with thirty leaves most of the manual list-keeping exactly where it was.
