Agentic AI

Prior-authorization agents: what the CMS rule and the evidence actually say

Prior authorization is being automated from both ends at once — providers building agents to submit and appeal, payers running algorithms to adjudicate. What the CMS-0057-F final rule now requires, what the published evidence shows an agent can and cannot do, and the one guardrail regulators drew around automated denials. As of July 2026.

By Jonas WeirReviewed by Jonas Weir · editorial reviewUpdated

The short version

  • Prior authorization is being automated on two sides at once: provider agents that assemble and appeal requests, and payer algorithms that adjudicate them. The two are governed by the same new federal rule but pull in opposite directions.
  • The CMS-0057-F final rule requires affected payers to decide expedited requests within 72 hours and standard requests within seven calendar days from 2026, and to run a FHIR-based Prior Authorization API by 2027 — the rails any submission agent depends on.
  • The burden is real: the late-2024 AMA survey put practices at 39 prior-authorization requests per physician per week and 13 hours of staff time, with 89% saying it worsens burnout.
  • Early evidence is document-level, not outcome-level: in a 2026 evaluation, LLM-drafted letters had correct ICD-10 coding 79.3% of the time and a false statement 3.5% of the time — and payer approval was never measured.
  • Regulators drew one hard line: an algorithm may assist a coverage determination but cannot be the sole basis for a denial, which must rest on the individual patient's circumstances.

Prior authorization is the paperwork checkpoint between a clinician's decision and a payer's payment — the requirement that a treatment, scan, or admission be approved before it happens. It is also the single most automated-against workflow in American healthcare right now, because both sides of the transaction have reached for AI at the same time. Providers are building agentic tools to assemble and submit requests; payers run algorithms to screen and decide them. This guide reads the two together, against the federal rule that now sets the rules of play and the published evidence on what these agents can actually do. As of July 2026.

Two prior authorizations, two kinds of agent

Almost every vendor conversation collapses a distinction worth keeping. There are two agents in this story, and they want opposite things.

The provider-side agent works for the clinician. Its job is to remove 13 hours of weekly staff time 4 by reading the chart, finding the documentation a payer will demand, drafting the request in the payer's format, tracking the decision clock, and — when a request is denied — drafting the appeal. Its incentive is approval and speed.

The payer-side algorithm works for the plan. Its job is to screen incoming requests against coverage criteria, flag the costly ones, and route or decide them. Its incentive is consistency and cost control. When these two systems face each other across a claim, the result can be an automated request meeting an automated denial, with a patient in the middle. The federal rule that took effect this year is the first serious attempt to govern that collision.

What the CMS-0057-F rule changes

The CMS Interoperability and Prior Authorization final rule (CMS-0057-F) was published in the Federal Register in February 2024 1. It does two things that matter for agents: it puts a clock on decisions, and it standardizes the pipes.

ProvisionWhat it requiresEffective
Expedited decision timeframeDecision within 72 hours2026 1
Standard decision timeframeDecision within 7 calendar days (halved from 14)2026 1
Specific denial reasonPayers must give a specific reason for every denial2026 2
Public metrics reportingPayers publicly report prior-authorization metrics; first data due March 31, 20262026 2
Prior Authorization APIA FHIR-based API to exchange requests and decisionsJanuary 1, 2027 2

The affected payers are Medicare Advantage organizations, state Medicaid and CHIP programs, and qualified health plan issuers on the federally facilitated exchanges 2. The API provision is the load-bearing one for automation. Today most prior authorization moves by fax, phone, and web portal — which is why an "agent" often means a system doing robotic clicking through a portal a human designed. The rule replaces that with a standard interface built on the HL7 Da Vinci Prior Authorization Support (PAS) implementation guide, whose stated goal is to let "a provider's system, at point of service, ... request authorization (including all necessary clinical information to support the request) and receive" a response 3. Standard pipes are what turn brittle screen-scraping into something an agent can call reliably — the same interoperability shift covered in our note on the model context protocol in health IT.

A clock plus an API changes the economics of automation on both sides. A seven-day standard window rewards a payer that can decide quickly and cheaply, which means more algorithmic screening. The same window rewards a provider who can submit a complete, well-documented request the first time, which means more drafting agents. The rule did not create the automation; it set the tempo it runs at.

The burden that pulls providers in

The pressure behind provider-side agents is not subtle. The American Medical Association's prior-authorization survey, fielded in late 2024 across 1,000 practicing physicians, found that practices complete an average of 39 prior-authorization requests per physician per week and spend 13 hours of physician and staff time on them 4. In that survey, 89% of physicians said prior authorization increases burnout, 93% said it delays access to care, and more than one in four — about 27% — reported that it led to a serious adverse event for a patient in their care 4. Those attitudes track the broader picture in our physician attitudes to AI tracker.

There is also a documented gap between how prior authorization is handled and how it could be. The 2024 CAQH Index put electronic adoption of prior authorization at roughly 40% — the lowest of the core administrative transactions — and estimated that moving a single manual authorization to the fully electronic standard saves providers about 14 minutes 8. Multiply 14 minutes across 39 weekly requests and the appeal of automation is obvious. The question is what the automation can be trusted to do.

What provider-side agents can do today

Here the honest answer is: draft well, decide nothing. The best current evidence is document-level. A 2026 peer-reviewed evaluation built 29 standardized nephrology scenarios — each with real coding, labeling, and guideline support — and had an LLM draft the prior-authorization letter, then scored the output against clinician review 7. The letters were strong on the surface: ICD-10 coding was correct in 79.3%, 93.1% used valid references, and 89.7% showed clinical reasoning rated "strong." They were also imperfect in exactly the ways that matter: a false statement appeared in 3.5% of letters, and errors clustered in predictable places — disease staging, citation accuracy, and omitted safety considerations 7.

Two limits keep this result modest, and the authors name both. The scenarios were "relatively straightforward" and drawn from a single specialty, and every letter came "from a single model version at a single time point" 7. Most important, the study measured document quality — it never measured whether a payer approved the request. A letter that reads well to a nephrologist and a letter that clears a plan's utilization review are different tests, and only the second one pays for care. When you see a vendor cite a drafting-accuracy number, ask for the approval-rate number; as of July 2026 that number is rarely published.

This is the register to hold agents in: a well-built submission agent is a fast, tireless drafter that still needs a clinician to catch the 3.5% and to own the signature. The human in the loop here is doing real work — verifying that a fluent letter is also a true one — because a hallucinated clinical detail in a prior-authorization request is a documentation error with a patient attached.

The payer side, and the line regulators drew

The mirror image is where the stakes climb. When a plan automates adjudication, the failure mode is worse than a wasted draft — it is a denied treatment. The evidence that this failure mode is real predates the current generation of agents. A 2022 review by the HHS Office of Inspector General examined a sample of Medicare Advantage prior-authorization denials and found that 13% of the denied requests actually met Medicare coverage rules — meaning the care would likely have been approved under original Medicare 5. The denials in that sample came before today's algorithmic screening was widespread; automation can make a screening process faster and more consistent, but it inherits — and can scale — whatever the criteria get wrong.

Regulators responded with a specific guardrail, and it is the most important sentence in this whole area. CMS's Contract Year 2024 Medicare Advantage rule requires that a medical-necessity determination be based on the individual patient's circumstances 6. CMS has clarified that an algorithm or software tool may assist a coverage determination but cannot be its sole basis: a tool "that determines coverage based on a larger data set instead of the individual patient's medical history, the physician's recommendations, or clinical notes would not be compliant" 6. Read plainly, that rule tells a payer its adjudication agent can triage and recommend, but a human must own any denial and must have looked at the specific patient. It is the payer-side equivalent of keeping a clinician on the signature — and it is enforceable.

A capability-and-limits summary

TaskWhat agents can do nowWhere a human stays required
Assemble a requestRead the chart, gather documentation, draft in payer formatVerify the clinical facts and the codes 7
Submit and trackCall the FHIR PA API, watch the decision clockOwn the attestation on the submission 1
Draft an appealProduce a structured, cited rebuttal quicklyConfirm the appeal is true and complete 7
Screen incoming requests (payer)Flag, triage, and route by criteriaA human decides any denial on the individual case 6
Report metricsCompile the public reporting the rule requiresSign off on accuracy 2

The pattern across the table is consistent: agents are strong at assembly, retrieval, and speed, and weak — or legally constrained — at the moment of a consequential decision. That is the same division of labour our revenue-cycle and coding agents guide finds on the billing side of the same claims.

How to read this

Four cautions travel with everything above. First, the strongest efficiency numbers come from the administrative-burden literature, not from controlled trials of agents; a 14- minute saving per transaction 8 is a workflow estimate, not an outcome. Second, the drafting-quality evidence is early, single-specialty, and silent on payer approval 7, so it tells you an agent can write a credible letter, not that the letter gets paid. Third, the rule's timeframes and API dates are compliance milestones, and compliance dates slip; confirm the current CMS-0057-F schedule before planning around it 12. Fourth, the payer-side guardrail is a legal requirement about who decides, and it does not by itself make the underlying criteria correct — the OIG finding that 13% of denials met coverage rules 5 was a criteria-and-review problem that automation can inherit.

The useful frame is the two-sided one we opened with. Prior-authorization automation is an arms race between a provider agent optimizing for approval and a payer algorithm optimizing for cost, refereed by a federal rule that sets the clock, standardizes the pipes, and insists a human own any denial. An organization deploying an agent on either side should be able to answer one question first: at the point where this system's output becomes a decision about a real patient, who is the accountable human, and what did they see?

Sources and method

This guide synthesises the CMS-0057-F final rule and its fact sheet 12, the HL7 Da Vinci PAS interoperability standard the rule relies on 3, the AMA's late-2024 prior-authorization survey for the burden figures 4, the 2022 HHS OIG denial review 5, CMS's Contract Year 2024 Medicare Advantage rule for the individualized-determination requirement 6, a 2026 peer-reviewed evaluation of LLM-drafted authorization letters 7, and the 2024 CAQH Index for adoption and time figures 8. Every figure is drawn from the primary source cited beside it and was checked live as of July 2026. We revisit this page on a 180-day cycle and whenever CMS changes a compliance date or new denial data is published. For the method behind reading any of the underlying studies, see how to read an AI validation study.

Questions & answers

  • What is a prior-authorization agent?

    It is an AI system that carries out steps in the prior-authorization workflow with some autonomy — reading the chart, assembling the clinical evidence, drafting the request or the appeal, and in some designs submitting it through a payer's interface. Payers deploy the mirror image: algorithms that screen and adjudicate those same requests. Both are governed by the CMS-0057-F final rule.

  • Does the CMS prior-authorization rule allow AI to deny care?

    The rule shortens decision timeframes and standardizes data exchange; a separate CMS rule governs the denial itself. CMS has clarified that an algorithm may assist a Medicare Advantage coverage determination but cannot be the sole basis for a denial, which must rest on the individual patient's circumstances, the treating physician's recommendations, and the clinical record.

  • How accurate are AI-generated prior-authorization letters?

    The published evidence is early and document-level. In a 2026 evaluation across 29 standardized nephrology scenarios, LLM-drafted letters had correct ICD-10 coding in 79.3% and valid citations in 93.1%, but a false statement appeared in 3.5% and the study never measured whether payers actually approved the requests. Treat current results as drafting quality, not approval outcomes.

Sources

  1. Centers for Medicare & Medicaid Services. Medicare and Medicaid Programs; Patient Protection and Affordable Care Act; Advancing Interoperability and Improving Prior Authorization Processes (CMS-0057-F). Federal Register. 2024;89(27):8758. www.federalregister.gov/documents/2024/02/08/2024-00895/medicare-and-medicaid-programs-patient-protection-and-affordable-care-act-advancing-interoperability
  2. Centers for Medicare & Medicaid Services. Fact Sheet: CMS Interoperability and Prior Authorization Final Rule (CMS-0057-F). 2024. www.cms.gov/newsroom/fact-sheets/cms-interoperability-prior-authorization-final-rule-cms-0057-f
  3. HL7 International. Da Vinci Prior Authorization Support (PAS) FHIR Implementation Guide, STU 2.1. 2024. hl7.org/fhir/us/davinci-pas/STU2.1/
  4. American Medical Association. Prior Authorization Physician Survey (fielded late 2024, 1,000 practicing physicians). 2025. www.ama-assn.org/system/files/prior-authorization-survey.pdf
  5. HHS Office of Inspector General. Some Medicare Advantage Organization Denials of Prior Authorization Requests Raise Concerns About Beneficiary Access to Medically Necessary Care (OEI-09-18-00260). 2022. oig.hhs.gov/reports/all/2022/some-medicare-advantage-organization-denials-of-prior-authorization-requests-raise-concerns-about-beneficiary-access-to-medically-necessary-care/
  6. Centers for Medicare & Medicaid Services. Medicare Program; Contract Year 2024 Policy and Technical Changes to the Medicare Advantage Program (CMS-4201-F). Federal Register. 2023;88(70):22120. www.federalregister.gov/documents/2023/04/12/2023-07115/medicare-program-contract-year-2024-policy-and-technical-changes-to-the-medicare-advantage-program
  7. Quality assessment of large language model-generated prior authorization letters in nephrology. Frontiers in Digital Health. 2026;8:1767648. doi.org/10.3389/fdgth.2026.1767648
  8. CAQH. 2024 CAQH Index Report: From Transactions to Trust. 2025. www.caqh.org/hubfs/Index/2024%20Index%20Report/CAQH_IndexReport_2024_FINAL.pdf