Get a Quote

Home » All Articles » CMS 0057: What Providers Need to Know About the New Prior Authorization Rule

CMS 0057: What Providers Need to Know About the New Prior Authorization Rule

CMS 0057: What Providers Need to Know About the New Prior Authorization Rule

Table of Contents

  • CMS 0057 (CMS-0057-F) regulates payers, not providers, but reshapes prior authorization turnaround, denial transparency, and electronic submission for everyone who submits PA requests. 
  • January 1, 2026 introduced a 7 day standard / 72 hour expedited decision window and mandatory specific denial reasons; these are already in effect. 
  • January 1, 2027 is the deadline for four required FHIR APIs: Patient Access, Provider Access, Payer to Payer, and Prior Authorization. 
  • Traditional Medicare and standalone Part D are excluded; the rule covers Medicare Advantage, Medicaid/CHIP, and FFE qualified health plans. 
  • Provider readiness (EHR/clearinghouse FHIR support, tracking denial reasons now) determines whether a practice actually captures the efficiency gains once payers comply. 

What Is CMS 0057?

CMS 0057, officially CMS-0057-F, is the Centers for Medicare & Medicaid Services’ Interoperability and Prior Authorization Final Rule. CMS finalized it in January 2024, and its provisions are phasing in through January 2027. The rule’s stated goal is to reduce the burden prior authorization places on patients, providers, and payers by forcing faster decisions, clearer denial reasons, and standardized electronic data exchange. 

It is easy to confuse CMS 0057 with earlier interoperability rules like CMS-9115-F, which introduced the original Patient Access API. CMS 0057 builds on that foundation and adds three new APIs, tighter decision timelines, and public reporting requirements that did not exist before.

Who the Rule Actually Applies To

CMS 0057 regulates payers, not providers. Specifically, it applies to: 

  • Medicare Advantage organizations 
  • State Medicaid and CHIP fee for service programs 
  • Medicaid managed care plans and CHIP managed care entities 
  • Qualified Health Plan issuers on the federally facilitated exchanges 

Traditional Medicare, Medicare Part D plans, and QHPs sold outside the federally facilitated exchanges are not covered. Providers are not directly regulated, which is why so much of the existing coverage of this rule is written for payers and health IT vendors. But the operational effects land squarely on provider practices, since payers are the ones providers submit authorizations to and wait on for decisions. 

Revenue Cycle Management

Neolytix delivers end-to-end RCM, denial management, A/R optimization, and payer contract negotiation, built around your specialty’s billing requirements.

Key Deadlines and Requirements

Effective date 

What changes 

January 1, 2026 

Covered payers must decide standard prior authorization requests within 7 calendar days and expedited requests within 72 hours. Every denial must come with a specific, actionable reason regardless of how the request was submitted. 

March 31, 2026 

Payers must begin publicly reporting prior authorization metrics annually on their websites, along with Patient Access API usage data. 

January 1, 2027 

Four FHIR based APIs must be live: an enhanced Patient Access API (now including prior authorization data), a Provider Access API, a Payer to Payer API, and a Prior Authorization API. 

The January 2026 provisions are already in effect as of this writing. The January 2027 API deadline is the one most payers are still building toward. 

The Four APIs, in Plain Terms

  • Patient Access API: Already required under the 2020 interoperability rule; CMS 0057 expands it so patients (and, by extension, the providers helping them) can see prior authorization status and outcomes alongside claims and clinical data. 
  • Provider Access API: Lets in network providers pull a patient’s claims, encounter, and prior authorization data directly from the payer, if the patient has not opted out. 
  • Payer to Payer API: Requires payers to exchange up to five years of a patient’s history when that patient switches plans, so a new payer (and the provider treating that patient) is not starting from zero. 
  • Prior Authorization API: Standardizes how providers submit requests and receive decisions electronically, using HL7 FHIR and Da Vinci implementation guides instead of fax, portal, or phone. 

What This Means for Provider Workflows

Because providers are not the regulated party, nothing in CMS 0057 forces a practice to change its systems. In practice, three things shift once payers comply: 

  1. Faster, more predictable turnaround. A 7 day ceiling on standard decisions (72 hours for urgent) gives billing and clinical staff a firm number to plan around and to escalate against when a payer misses it. 
  2. Denial reasons become actionable. Payers can no longer send a bare denial. A specific reason means staff can correct and resubmit faster, instead of guessing or calling the payer. 
  3. Electronic submission becomes viable at scale. Once a payer’s Prior Authorization API is live, practices that can submit through it stand to cut the phone and fax work that drives most PA administrative burden today. 

None of this is automatic. Payer implementations will vary in quality and timing through 2027, and a practice’s EHR or clearinghouse needs to support the relevant FHIR standards to take advantage of the new APIs. Practices that wait to engage until the deadline passes will be behind payers that are already testing connections.

How Providers Can Prepare

  • Ask your top payers by volume where they are in their CMS 0057 implementation, and whether a Prior Authorization API is available for testing yet. 
  • Confirm your EHR or clearinghouse vendor’s roadmap for FHIR based prior authorization support. 
  • Track denial reason data starting now. Once payers must provide specific reasons, that data becomes a real lever for reducing preventable denials. 
  • Flag PA turnaround time internally so staff know the 7 day and 72 hour benchmarks and can escalate when a payer misses them. 

How Neolytix Helps

Providers navigating this shift do not need to become health IT experts to benefit from it. Neolytix has managed prior authorization and revenue cycle operations for providers for over 14 years, and our teams already track payer-specific turnaround times and denial patterns as part of day to day RCM management. As payers roll out CMS 0057 compliant processes, that means faster escalation when a payer misses a deadline, and faster resubmission once denial reasons are actually specific enough to act on. For a closer look at how prior authorization delays affect revenue today, see our Prior Authorization Bottleneck breakdown. 

Conclusion

CMS 0057 will not require providers to buy new software or change vendors, but it will change what providers can reasonably expect from every payer they work with: faster decisions, real denial reasons, and eventually, electronic prior authorization that does not depend on fax machines. The January 2026 process changes are already live. The January 2027 API deadline is close enough that providers who start asking their payers questions now will be in a stronger position than those who wait. 

Schedule a Consultation

Neolytix partners with healthcare organizations across revenue cycle, credentialing, and administrative operations ,14+ years of expertise and AI-enabled automation to reduce inefficiencies and drive sustainable growth.

Frequently Asked Questions

Is CMS 0057 the same as CMS-0057-F?

Yes. CMS 0057 and CMS-0057-F both refer to the CMS Interoperability and Prior Authorization Final Rule.

No. The rule regulates payers (Medicare Advantage, Medicaid, CHIP, and FFE qualified health plans), not providers directly. Providers benefit from the changes payers must make.

There are two. January 1, 2026 for prior authorization process changes (decision timelines, denial reasons), and January 1, 2027 for the four required FHIR APIs.

No. Traditional Medicare and standalone Medicare Part D plans are not covered by this rule.

Seven calendar days for standard requests and 72 hours for expedited requests, as of January 1, 2026.

Share:

Table of Contents

Credentialing Delays Are Costing You $45K–$150K Per Provider

  • Cut Credentialing Cycle Times From 120 Days to Under 45
  • Free Downloadable Guide

Neolytix Identifies an Average of $341K in Payer Contract Revenue Opportunities — Get Your Assessment Done Today