Everything health plans need to know about the CMS Interoperability and Prior Authorization Final Rule — the deadlines, the FHIR APIs, the decision timeframes — and how to comply without ripping out your UM system.
The CMS Interoperability and Prior Authorization Final Rule (CMS-0057-F), finalized in January 2024, overhauls how impacted health plans handle prior authorization. It does not eliminate prior authorization — it makes it faster, more transparent, and interoperable, through FHIR-based APIs, binding decision timeframes, specific denial reasons, and public reporting of prior-authorization performance.
Faster prior-authorization decision timeframes take effect — 72 hours for expedited/urgent and 7 calendar days for standard requests. Every denial must include a specific reason, and payers begin collecting prior-authorization metrics.
Impacted payers must publicly post their prior-authorization performance metrics (covering calendar year 2025) on their websites — and annually thereafter.
The four FHIR APIs must be operational: Patient Access, Provider Access, Payer-to-Payer, and the Prior Authorization API. State Medicaid and CHIP fee-for-service programs also reach their API deadline.
Exact applicability and dates vary by payer type and can be adjusted by CMS — always confirm your program's obligations against the current rule text before planning.
CMS-0057-F standardizes data exchange on HL7 FHIR. Four APIs are in scope:
Beyond the APIs, CMS-0057-F tightens the operational rules: 72-hour expedited and 7-day standard decisions, a specific clinical reason on every denial, and public reporting of prior-authorization metrics — approval and denial rates and average decision turnaround — posted on the payer's website each year.
For UM teams, the rule is really about the Prior Authorization API and the new operational and reporting requirements. Most established UM systems weren't built for FHIR CRD/DTR/PAS, the accelerated timeframes, or the metrics reporting. That leaves plans with a choice: a costly replacement of their system of record, or a way to add the compliant front door on top of what they already run.
This is exactly what AI-UM Care is built for. The UM Engine plugs in front of your existing UM system as a CMS-0057 front door — providing the FHIR CRD/DTR/PAS APIs, deterministic auto-adjudication (it never auto-denies; adverse decisions go to a clinician), and writing outcomes back into Jiva, HealthEdge GuidingCare, MedHOK, Evolent or a homegrown system through their own APIs. The Policy Codification Engine turns your CMS NCD/LCD and plan policies into the executable CQL the engine runs. Together they enable CMS-0057 in weeks, deployed single-tenant in your own cloud — so no member data leaves your environment.
No. CMS-0057-F does not eliminate prior authorization — it makes it faster and more transparent through FHIR APIs, quicker decisions, specific denial reasons, and public metrics.
The FHIR Prior Authorization API — along with the Patient Access, Provider Access and Payer-to-Payer APIs — must be operational by January 1, 2027. Faster decision timeframes and denial-reason requirements took effect January 1, 2026.
The Prior Authorization API is built on the Da Vinci PAS implementation guide, which carries the X12 278 prior-authorization transaction over FHIR, alongside the CRD and DTR guides.
Yes. A gateway engine like the AI-UM Care UM Engine adds the FHIR front door and deterministic decisioning on top of your existing UM system and writes results back into it — no rip-and-replace.
Book a demo — we'll show the FHIR front door, deterministic decisioning, and a write-back into a sample UM system.
Or email salesinfo@aiumcare.com