Faster Prior Auth Is the Law Now. So Are Faster Denials.

Last week I wrote about the gap between the AI on the HFMA stage and the AI on the ground. This week something quieter is happening — and unlike the conference hype, it has a deadline.
While the industry argues about which model codes best, the federal government has been rewiring the single most expensive bottleneck in the revenue cycle: prior authorisation. Most practices I talk to do not realise the clock is already running.
The clock most people are ignoring
CMS’s Interoperability and Prior Authorization rule is not a 2030 idea. Parts of it are already live. Since January, impacted payers — Medicare Advantage, Medicaid managed care, the ACA exchange plans — have had to return standard prior-auth decisions in 7 days and urgent ones in 72 hours. Faster. By law.
Then comes the bigger shift. By 1 January 2027 — roughly six months out — those same payers must stand up electronic prior-authorisation APIs. Machine to machine. No more fax. No more portal roulette. Patients will even be able to pull up their own auth status, and the reason for a denial, on their phone.
On paper, this is the relief providers have been begging for. Read it again and you will see the trap.
Why “faster” cuts both ways
A faster pipe does not care which direction the water flows. If a payer can approve in 72 hours, it can also deny in 72 hours — with a clean, API-generated reason code and a timestamp. The same automation built to speed your approvals speeds their refusals.
We are already in that arms race. Hospitals spent close to $18 billion last year just overturning denials. And here is the number that should stop you cold: roughly 60% of denied claims are never resubmitted at all.
A faster “no” you still do not appeal is not relief. It is a faster write-off. The mandate changes the rails. It does not change the outcome.
What the rule actually rewards
An API is only as good as what you feed it. Clean inputs, clean exchange. Messy front end, faster rejection. The practices that come out ahead will not be the ones who waited for payers to flip the switch. They will be the ones who spent these six months getting ready to plug in:
- A front end that is already clean. Eligibility, benefits and documentation right the first time — because the API will surface your gaps instantly, not 45 days later.
- Prior-auth data that is traceable. If you cannot say where an auth request lives or what status it is in across every channel, the new transparency works against you, not for you.
- Payer-specific intelligence. The decision timelines are standardised now. Payer behaviour inside them is not. Knowing who fights what, and how fast, is still the edge.
- Governed automation. Let the machine move the request. Keep a human on the judgment. Auditable, every time.
None of that is triggered by the deadline. All of it decides whether the deadline helps you or hurts you.
The 2030 view
By 2030, electronic prior auth will be ordinary. Nobody will brag about having an API any more than they brag about having email. The differentiator will be what you did with the runway — whether you used these six months to clean your front end and instrument your data, or waited for January 2027 and hoped the rule would do the work for you.
It will not. Regulation builds the road. It does not drive the car.
One quiet plumbing problem a week — the CMS deadline, payer behaviour or code change that reaches your claims before it reaches the headlines. Written by Mihir Rajput, Founder & CEO of Medalyze Medtech.
Subscribe on LinkedIn →
End-to-End Revenue Cycle Management: How Automation.
From patient intake to final payment posting, the healthcare revenue cycle is full of friction points. How end-to-end automation removes.
Read More
Top Reasons Medical Claim Denials Are.
Claim denials are one of the biggest threats to healthcare revenue in the U.S. Why the rate keeps climbing, and.
Read More