A four-provider primary care practice we audited last quarter was running about 22 prior authorizations a week. At roughly 15 minutes each, with an industry-quoted blended labor cost around $11 per PA, that is somewhere near $13,000 a year in pure PA labor. Then add the PA-related denials we found in their AR — the no-auth-on-file write-offs, the expired auths, the wrong-CPT-on-the-auth resubmissions — plus the operational tax of reschedules and same-day cancellations driven by missing auths, and the all-in bleed grew by another $20,000 to $35,000 a year in revenue and avoidable cost. That is a single practice. Industry estimates suggest well over a million prior authorizations are processed across the country every working day, and AMA Prior Authorization Physician Practice Survey work consistently ranks PA as the single largest administrative tax on independent practice.
2026 is the first year that has actually moved the needle on this. The CMS Interoperability and Prior Authorization Final Rule went live on January 1, and parts of the industry now have real APIs where they used to have fax machines. But not all of it. This post walks through what is actually working now, what is still manual and will probably stay manual into 2027, and how independent practices should structure a PA workflow this quarter to capture the easy wins without overpaying for vaporware. It is the fourth piece in our Wave 4 RCM Foundations cluster, and it sits next to our work on net versus gross collection rate and RVU benchmarks by specialty.
What Actually Changed in 2026 — CMS Interoperability and Prior Authorization Final Rule
The rule everyone is referring to is CMS-0057-F. The first wave took effect January 1, 2026 for what CMS calls “impacted payers” — Medicare Advantage organizations, Medicaid managed care plans, CHIP managed care entities, and Qualified Health Plan issuers on the Federally-facilitated Exchanges. (Fee-for-service Medicaid and CHIP have related obligations under other API tracks but are not in scope for the Prior Authorization API in the same way.) If a payer is in that “impacted” bucket, they are now on the hook for four APIs:
- A Patient Access API for members to pull their own data.
- A Provider Access API so providers can get patient data they treat.
- A Payer-to-Payer API so the data follows the patient when they switch plans.
- A Prior Authorization API built on the HL7 Da Vinci Prior Authorization Support (PAS) Implementation Guide.
That last one is the change. The PAS Implementation Guide is the FHIR-based standard that lets a provider’s system submit a PA request, attach the supporting clinical documentation, and receive a decision in a structured response — instead of faxing six pages to a payer portal and waiting. Important timing distinction: the shortened decision standards (72 hours for urgent, seven calendar days for non-urgent / standard) and the public PA metrics reporting requirement kicked in for the 2026 reporting period. The Prior Authorization PAS API endpoint itself has a January 1, 2027 compliance date — so impacted payers are racing to stand up FHIR PAS now, but the regulatory mandate to use that endpoint is next year, not this one.
The catch — and this is the part the vendor demos tend to skip — is that only impacted payers must comply. A commercial PPO that is not on the ACA exchange is not in scope. That means most BCBS commercial groups, most UnitedHealthcare commercial books, and most Cigna commercial plans are not required to expose a PAS endpoint. They still might over time, because the standard creates pressure, but right now the rule does not force them.
What’s Working Right Now (Real Automation, Not Buzzwords)
Setting aside the vendor hype, here is what is actually moving the needle in independent practices in 2026:
- Electronic prior authorization (ePA) for medications via NCPDP SCRIPT. The pharmacy benefit side of PA is the most mature. CoverMyMeds, Surescripts, and the EHR-integrated ePA flows handle the vast majority of pharmacy benefit PAs electronically. For practices that administer drugs in office — Botox, infusions, biologics — getting medication PA into the ePA pipe is one of the highest-leverage automation moves available.
- Eligibility and benefits checks at scheduling. Modern eligibility APIs return more than just active/inactive coverage. They flag PA-required CPTs by plan, surface remaining deductible, and confirm in-network status — at the point the appointment is booked, not at the point the patient walks in. Catching “PA required” five days before the visit is a different problem than catching it the morning of.
- Payer portal RPA (robotic process automation). For payers without a usable PAS endpoint — which is still a lot of them — bots that log into the payer portal, navigate the PA form, and submit documents reduce manual time on the high-volume payers by something like 70 percent. It is not glamorous, and the bots break when the portal redesigns, but the math works.
- FHIR PAS status polling. As impacted payers stand up PAS endpoints ahead of the 2027 compliance date, status polling is starting to replace the “log into the portal and click around” task that used to eat a billing FTE. The bigger this footprint gets, the more time it gives back.
- Pre-claim PA flagging in the scrubber. Good claim scrubbers now carry LCD and NCD rule logic that catches “this CPT requires PA for this plan” before the claim is dropped. That stops the no-auth-on-file denial at the door instead of after the EOB comes back.
What’s Still Manual in 2026 (And Probably Still Will Be in 2027)
It is worth being honest about where automation stops. These are the places where staff still have to do the work:
- Most BCBS commercial groups (representing somewhere north of 90 million covered lives) are not impacted by the rule and have no obligation to expose PAS endpoints.
- High-touch specialty PAs that require payer-specific narrative documentation — cardiology advanced imaging (cardiac MR, MR-PET), interventional cardiology PCI scheduling, neurology Botox documentation for chronic migraine, certain OB procedures with payer-specific medical-necessity standards — still need a human to assemble the clinical story.
- Peer-to-peer calls. When the initial submission denies and the practice has to put a treating physician on the phone with the payer’s medical director, no API solves that.
- Out-of-network PAs. Variance between payers is enormous and there is no standard to automate against.
- Clinical documentation review for medical necessity. An algorithm can flag the codes that need PA; a human still has to read the chart and confirm the documentation supports the criteria.
What This Costs You If You Don’t Automate
The dollar math is worth doing for your own practice. Start with the direct labor: 22 PAs per week times 15 minutes per PA times the common industry-quoted $11-per-PA blended labor cost lands a solo practice somewhere around $13,000 per year just in PA processing time. That is before any of the downstream damage.
Then layer in PA-related denials. In our client audit book, PA-related denials — primarily CARC 197 (“Precertification/authorization/notification/pre-treatment absent or invalid”) plus the related 15, B7, and 198 family — typically account for 7 to 12 percent of total denial volume. On a $1.5 million practice running a 10 percent denial rate, that is roughly $10,000 to $15,000 a year in revenue that should have been collected if the PA had been handled upstream. (For the broader denial-code framing, see our top medical billing denial codes breakdown.)
Then add the operational tax: reschedules and no-shows driven by missing or incorrect PAs. When a patient shows up and the auth is not on file, the practice either delivers the service uncompensated, delays it, or cancels it. Each path has a cost — clinical, operational, and reputational. Worked through, a four-provider primary care practice without a structured PA workflow loses an estimated $35,000 to $50,000 a year to PA inefficiency. Scale that proportionally for larger practices and the case for investment becomes obvious.
What Specialties Get Hit Hardest by PA
PA burden is not evenly distributed. The practices that feel it most are the ones running high-PA-density code mixes:
- Neurology: Botox for chronic migraine, EMG, sleep studies, infusion therapy. Botox alone — J0585 plus the 64615 administration code, which together can run $650 to $1,100+ per session depending on units and MAC fee schedule — is a PA-heavy workflow that benefits enormously from a documented payer-specific approach. See our Botox for chronic migraine billing piece for the coding specifics.
- Cardiology: Advanced imaging (cardiac PET, cardiac MR), interventional procedures, CRT and ICD implants. See cardiac cath and PCI billing for an example of where PA, bundling, and modifier rules intersect.
- OB/GYN: Maternal-fetal medicine consults, complex hysterectomy approaches, infertility treatments.
- Family practice and internal medicine: Branded drugs (especially the newer GLP-1 class), specialist referrals in HMO products, advanced imaging.
How to Build a Real PA Workflow This Quarter
If you want to actually move on this in 90 days, here is the sequence we recommend:
- Pull all PA-related denials from the last 12 months. That is mainly CARC 197, plus the related 15, B7, and 198 family. Count by payer and by CPT. You will find a heavy concentration in a small number of combinations.
- Tag the top five payer-CPT combinations. That short list is where your workflow build pays off the most. Ignore the long tail until the top five are solved.
- Move the PA check upstream. Add an eligibility and PA-requirement check at scheduling, not at the visit, not at the claim. Catching it five days early is a different operational problem than catching it after the EOB.
- Route each PA-required service to the right channel — ePA for pharmacy benefit, FHIR PAS or portal RPA for impacted payer medical benefit, manual for everything else. Do not try to automate the long tail first.
- Instrument it. Days to decision, approval rate, denial rate, peer-to-peer rate. If you do not measure these monthly you will not improve them. (For the broader KPI framing, see our revenue cycle metrics that matter and RCM best practices posts.)
How AMS Solutions Handles PAs for Clients
We have been doing medical billing for independent practices since 1992, and PA has gotten harder every year of that. Here is how we handle it inside our RCM service today:
- Eligibility and PA flagging at scheduling using payer eligibility APIs, so the practice knows before the visit whether an auth is required.
- An ePA pipe for medication PAs, so pharmacy benefit auths route to the electronic standard instead of fax.
- A trained PA team for high-volume payer portal work, with portal RPA where the volume justifies it.
- A documentation library of payer-specific medical necessity templates by CPT — so the submission is right the first time and avoids the peer-to-peer escalation that eats clinical time.
- Active denial workdown on PA-related denials (CARC 197 and the related family), with peer-to-peer support ready when the medical director call is needed.
- Monthly PA performance reporting for each client: approval rate, average decision time, denial root cause by payer-CPT combination, and a forward look at where the next workflow tightening pays off.
None of that is magic. Most of it is what should already be running inside a competent billing operation. The reason it is rare is that it requires a billing partner that has built the integrations, trained the people, and instrumented the reporting — not a software license bolted onto a practice with no one to run it. If you want to talk through what a real PA workflow would look like for your practice, you can book time with me directly at meetings.hubspot.com/mgardner7.
— Madison Gardner, President, AMS Solutions
Want the service-level view? See how AMS pairs automation with AAPC-certified billers in our AI-assisted medical billing overview.