docs
Prior Authorization for Medical Billing Companies
How prior authorization affects billing companies: the 2026 CMS interoperability rule, auth-related denials, and tracking auth status across client practices.
Short answer
Prior authorization is a clinical, pre-service decision. A practice or its staff contacts the payer before rendering a service and gets approval. Billing companies do not submit those requests. They own what happens after the appointment: confirming the authorization number is on the claim, catching mismatches between the approved service and what was billed, and working the denials that arrive when something went wrong upstream.
The volume is substantial. Medicare Advantage insurers processed nearly 53 million prior authorization requests in 2024 and denied 7.7 percent of them, according to KFF. The 2026 CMS Interoperability and Prior Authorization Final Rule (CMS-0057-F) shortens payer decision timelines and mandates new FHIR APIs, which will change the upstream process and, in turn, the downstream denial patterns billing companies manage.
Sources: KFF Medicare Advantage Prior Authorization 2024; CMS CMS-0057-F fact sheet
---
What prior authorization is, and who does it
Prior authorization is how a payer reviews whether a planned service meets coverage criteria before the service occurs. The treating provider or their office staff submits the request through a payer portal, fax, phone call, or increasingly an electronic transaction. The payer reviews it and issues an approval, a denial, or a request for more information.
This work lives entirely within the practice workflow, before the visit. It requires clinical documentation, diagnosis rationale, and treating-provider credentials. A billing company handed a completed encounter has no practical path to submit an authorization retroactively, and payers generally will not accept one.
The billing company's relationship with prior authorization starts when the claim arrives for submission. By then the authorization number is either present or missing, and it either matches the services billed or it does not.
Sources: CMS Prior Authorization API FAQ
---
The administrative burden behind the denial volume
The scale of authorization work explains why auth-related denials are a persistent category for billing companies. The AMA's 2025 prior authorization physician survey, administered in December 2024 among 1,000 practicing physicians, found that practices complete an average of 40 prior authorizations per week and spend an average of 13 hours of physician and staff time on them weekly. Two in five physicians employ staff dedicated exclusively to prior authorization. Nearly three in four (74 percent) report that denials have increased over the past five years.
That burden produces errors. When a practice processes dozens of authorizations a week across multiple payers, each with its own portal, identifier format, and scope language, mismatches reach claims at a predictable rate. The auth number gets omitted from the claim, the approved CPT code differs from what was billed, or the authorization expires between approval and service. Each lands on the billing company as a denial to work.
Sources: AMA 2025 Prior Authorization Physician Survey; AMA press release
---
Authorization-related denial codes billers see most
When a claim is denied for an authorization problem, the payer gives the reason as a Claim Adjustment Reason Code (CARC) in the X12 835 remittance. CARCs are maintained by the Washington Publishing Company (WPC) on behalf of X12 and updated quarterly. The codes billing companies see most in the authorization category:
| CARC | Description |
|---|---|
| 15 | The authorization number is missing, invalid, or does not apply to the billed services or provider. |
| 197 | Precertification/authorization/notification/pre-treatment absent. |
| 198 | Precertification/notification/authorization/pre-treatment exceeded. |
| 210 | Payment adjusted because pre-certification/authorization not received in a timely fashion. |
| 284 | Precertification/authorization/notification/pre-treatment number may be valid but does not apply to the billed services. |
| 296 | Precertification/authorization/notification/pre-treatment number may be valid but does not apply to the provider. |
| 302 | Precertification/notification/authorization/pre-treatment time limit has expired. |
CARC 197 is the most common. It means the payer found no authorization record tied to the submitted code, date of service, and patient plan. CARC 15 usually means an authorization exists but the number on the claim is wrong or does not match the service. CARC 284 and 296 flag scope mismatches: the authorization was approved for a different code or a different rendering provider than what appears on the claim.
Each of these denials sends the billing company back to the practice to confirm what the authorization covered, then correct and resubmit or appeal. None resolve with the billing company acting alone, because the authorization record lives in the payer's system and the practice's workflow.
Sources: X12 Claim Adjustment Reason Codes; WPC CARC reference
---
The 2026 CMS Interoperability and Prior Authorization Final Rule (CMS-0057-F)
CMS published the Interoperability and Prior Authorization Final Rule (CMS-0057-F) on January 17, 2024. It applies to Medicare Advantage organizations, state Medicaid and CHIP fee-for-service programs, Medicaid managed care plans, CHIP managed care entities, and Qualified Health Plan issuers on the Federally Facilitated Exchanges.
Key provisions and effective dates:
- January 1, 2026: Impacted payers must issue standard prior authorization decisions within seven calendar days (reduced from 14) and urgent decisions within 72 hours. They must give a specific reason for any denial, whatever the channel the request came in through. Public reporting of prior authorization metrics begins.
- March 31, 2026: First set of public PA performance metrics due.
- January 1, 2027: Full compliance deadline for FHIR-based APIs. Payers must have a Prior Authorization API, Patient Access API, Provider Access API, and Payer-to-Payer API live in production.
The API requirement is what changes the upstream process for practices. When payers expose FHIR-based prior authorization APIs, EHR systems and dedicated PA platforms can submit and receive decisions programmatically instead of through portals and fax. That should clean up the authorization record (fewer mismatched identifiers, fewer missed submissions) and reduce the downstream denial volume billing companies absorb.
The transition will take years. CMS issued enforcement discretion in February 2024 for the HIPAA requirement to use the X12 278 standard as part of an electronic FHIR prior authorization process, so payers that choose the FHIR path are not required to route through X12 278. The plumbing is being built across 2025 and 2026, and denial patterns will not shift overnight.
Sources: CMS CMS-0057-F fact sheet; CMS CMS-0057-F main page
---
Gold-carding programs
Gold carding is a way some payers and states reduce prior authorization friction for providers with consistently high approval rates. A provider who has had, typically, 90 percent or more of their authorization requests approved over a qualifying lookback period is exempted from the requirement for those services for a set period.
CMS has encouraged Medicare Advantage plans to adopt gold-carding voluntarily. At the state level, as of late 2024 at least eight states had passed gold card legislation, including Arkansas, Colorado, Illinois, Louisiana, Michigan, and Texas, though specifics and covered service types vary by state. Texas extended its lookback from six months to one year. UnitedHealthcare launched a national Gold Card program in October 2024, requiring a 92 percent approval rate over a two-year lookback.
Gold carding matters to billing companies because it cuts authorization-tracking overhead for specific provider-payer combinations. A provider who holds gold card status with a plan does not need an auth number on covered claims for those services, so that is one fewer field to validate before submission. The catch is the tracking: the billing company has to know which client providers hold gold card status with which payers and for which codes, and that burden falls on them when the practice does not proactively communicate it.
Sources: CMS encouragement of MA gold carding; State gold card legislation overview
---
The multi-practice tracking problem
The upstream authorization process has always been fragmented. Each practice runs a different EHR or practice management system, each payer has a different portal, and authorization numbers come back in different formats stored in different fields, sometimes only in a notes field or a staff member's head. When the claim reaches the billing company, the authorization context arrives with whatever the practice exported.
Managing one practice through one EHR is hard enough. Managing twenty or fifty across different systems multiplies it. A billing company with 30 client practices is dealing with 30 workflows for authorization tracking, 30 ways an auth number might or might not appear on the encounter export, and 30 sets of staff who may or may not have confirmed authorization status before the appointment.
So billing companies cannot rely on client practices to deliver clean authorization data. They need a workflow layer that surfaces authorization gaps before submission, flagging claims where a covered service usually requires authorization but no auth number is present, and that routes auth-related denials into a structured work queue where staff can track the appeal or correction without losing the thread.
Sources: AMA 2025 Prior Authorization Physician Survey; KFF Medicare Advantage Prior Authorization 2024
---
How Medi handles authorization workflows for billing companies
Medi is a billing-company-first RCM platform. It does not submit prior authorization requests to payers; that work belongs in payer portals, practice EHRs, or a dedicated PA platform. Medi manages the billing side of the authorization problem.
At the claim level, Medi tracks authorization status as a first-class field. When a claim arrives without an auth number for a service that usually requires one, it surfaces in the pre-submission review queue so staff resolve it before the claim goes out. When a denial arrives with an auth-related CARC (197, 15, 284, or others), it routes to the per-line denial queue with the denial code, the payer's reason, and the claim context already assembled, so there is no manual triage.
For a billing company managing many practices, auth-related denials are then visible across all client practices in one work queue rather than buried in per-practice worklists. Staff working a 197 denial can see the auth status recorded at intake, the denial reason from the ERA, and the resubmission history in one place.
Medi does not replace the authorization submission workflow. It works the other side of that boundary, making sure what practices submit matches what billing companies bill and that denials get worked instead of logged.
---
When Medi is not the right fit
Medi is the wrong tool if your main problem is authorization submission volume: getting requests to payers faster, auto-populating authorization forms from clinical notes, or tracking payer decisions through a submission platform. That work requires clinical context Medi does not hold.
Purpose-built prior authorization platforms (sometimes called PA automation platforms) focus on the submission side: pulling clinical data from the EHR, submitting via payer portal or API, tracking turnaround times, and escalating stalled requests. Some EHR vendors build this into their workflow directly. A dedicated PA-submission vendor is the right fit for that problem.
Medi is the right fit when authorization submission is already handled and you need the billing workflow layer: tracking auth status at the claim level, catching mismatches before submission, and working auth denials across many client practices.
---
Frequently asked questions
Does Medi submit prior authorizations?
No. Medi does not submit prior authorization requests to payers. Submission is a pre-service clinical workflow that requires treating-provider credentials and documentation, so it belongs in the practice EHR, a payer portal, or a dedicated PA platform. Medi works after that step: tracking whether an authorization is on the claim, flagging mismatches before submission, and routing auth-related denials into a structured work queue.
What is CMS-0057-F?
CMS-0057-F is the 2024 CMS Interoperability and Prior Authorization Final Rule. It applies to Medicare Advantage plans, Medicaid and CHIP programs, and Qualified Health Plans on Federally Facilitated Exchanges. Starting January 1, 2026, covered payers must issue standard prior authorization decisions within seven calendar days and urgent decisions within 72 hours, and must give specific denial reasons. By January 1, 2027, they must have FHIR-based prior authorization, patient access, provider access, and payer-to-payer APIs live in production. The rule regulates payers, not billing companies directly, but it changes the upstream authorization process billing companies work around.
What denial code means a missing authorization?
CARC 197, "Precertification/authorization/notification/pre-treatment absent," is the most common code for a claim denied because no authorization record was found. CARC 15 means an authorization number was submitted but is missing, invalid, or does not apply to the billed service or provider. CARC 284 means the number may be valid but does not match the billed services. These codes are maintained by the Washington Publishing Company (WPC) on behalf of X12 and published at x12.org/codes/claim-adjustment-reason-codes.
What is gold carding?
Gold carding is a payer program that exempts providers with high prior authorization approval rates from the requirement for specific services. Thresholds vary, but a common benchmark is a 90 percent or higher approval rate over a qualifying lookback period. As of late 2024, at least eight states have passed gold card legislation, and some commercial payers, including UnitedHealthcare, have implemented national programs. For billing companies, gold card status on a provider-payer-code combination means claims for those services can go out without an auth number. Tracking which providers hold that status with which payers is part of pre-submission validation.
How does CMS-0057-F affect the denials billing companies work?
Starting January 1, 2026, the rule requires payers to give a specific denial reason for every prior authorization decision, whatever the submission channel. That should produce more specific CARC and denial-reason combinations on 835s, giving billing companies more to work with when a denial arrives. The FHIR API mandate, effective January 1, 2027, is the longer-term change: when authorization requests and decisions flow through structured APIs instead of portals and fax, the auth number that reaches the claim should be more accurate, reducing certain CARC 15 and CARC 197 volumes over time. The transition will be gradual.
Can a billing company appeal an authorization denial?
Yes, and it is often worth doing. KFF found that more than 80 percent of appealed Medicare Advantage prior authorization denials were overturned in 2024, yet only 11.5 percent of denials were appealed. That gap between the overturn rate and the appeal rate is revenue practices and billing companies leave on the table. A structured denial workflow that tracks auth-related denials, their appeal deadlines, and their resolution status is how a billing company captures that revenue systematically instead of case by case.
References
These public sources provide background for standards, terminology, or competitor context discussed on this page.
- CMS Health Plan Eligibility Benefit Inquiry and ResponseCenters for Medicare and Medicaid Services
- MGMA detecting and fixing leaks across the revenue cycleMedical Group Management Association