Back to Blog
Regulation Akshay Singh

What the CMS Prior Authorization Final Rule Means for Infusion Centers

CMS published the Interoperability and Prior Authorization Final Rule (CMS-0057-F) in early 2024, with implementation dates spread from 2026 through 2027. The rule applies to Medicare Advantage plans, Medicaid managed care plans, CHIP plans, and qualified health plans on the federal exchange. It does not apply directly to commercial fully-insured plans outside the exchange or to self-funded employer health plans.

For infusion centers and DME providers, the rule changes how payers are required to process prior authorization requests and communicate decisions. It does not change whether prior authorization is required, and it does not standardize what documentation payers can require. Understanding what changed and what did not is important for setting accurate expectations about its practical impact.

What the Rule Requires of Payers

The rule establishes several new requirements for affected payers. The most operationally significant for providers are the response time requirements and the reason for denial requirement.

For standard prior authorization requests, covered payers must now respond within 7 calendar days. For expedited (urgent) requests, the response window is 72 hours. These are mandatory response windows, not targets. The 7-day and 72-hour clocks start from when the payer receives a complete, compliant authorization request.

Payers must also now provide a specific reason for any denial, not just a denial notification. The denial reason must be specific enough to allow the provider to understand what is missing or incorrect, and to appeal if appropriate. This requirement addresses a long-standing complaint from providers that denial notices were too vague to guide a meaningful response.

The rule also requires payers to implement an HL7 FHIR-based prior authorization API by January 2027. This API is intended to allow providers to check authorization requirements and submit requests programmatically, rather than through payer portals or phone calls. For providers using software systems that implement the API, this could eventually simplify the submission process substantially.

What the Rule Does Not Change

The rule does not limit payers' ability to require prior authorization for services they choose to require it for. A Medicare Advantage plan can still require prior authorization for the same infusion therapies it required it for before the rule. The rule constrains how payers process and respond to requests, not which services they require authorization for.

The rule also does not standardize documentation requirements. Each payer can still require its own set of supporting documentation with a prior authorization request. The clinical information, lab values, step therapy documentation, and specialist attestations that a payer requires are still within each payer's discretion to define. The standardization in the rule is about submission format (FHIR API) and response timelines, not about the substance of what payers can require.

Importantly for small providers, the FHIR API requirement applies to payers, not to providers. Providers are not required to implement or use the API. The API creates an option that practice management software vendors and tools like Coral can use to submit and track requests more efficiently, but small practices that cannot or choose not to use FHIR-enabled submission are not penalized. The existing portal submission and phone auth pathways remain available.

Practical Impact on Infusion Center Intake Now

For infusion centers, the most immediately meaningful change from the rule is the stricter response timeline for covered plans. If you are submitting to a Medicare Advantage plan and you submit a complete request, you should expect a response within 7 days. If you are waiting more than 7 days with no response or follow-up request from the payer, you have a documented basis to escalate.

The specific denial reason requirement is also practically useful. Before the rule, a denial that came back as "not medically necessary" without further detail required coordinators to call the payer to find out what was actually deficient. Under the new requirement, the denial should tell you specifically what was missing or why the request did not meet coverage criteria. That specificity should reduce the call volume needed to diagnose denials and should make appeals more targeted.

There is a practical caveat: payer compliance with these requirements will vary. Rules take time to implement operationally, and payers that are slow to update their denial communication processes will still send vague denial letters. Providers should monitor denial quality from their key payers and be prepared to request specificity when it is not provided.

The Provider-Side Bottleneck Remains Unchanged

The rule does not address the provider-side of the authorization process. Once payers are compliant, the 7-day clock starts when the payer receives a complete, compliant request. It does not start when the referral arrives at the infusion center.

The gap between referral arrival and authorization submission, which is where most of the four-day average intake delay occurs for small infusion centers, is not addressed by this regulation. A payer responding within 7 days of submission is still responding 7 days from whenever the provider got around to submitting. If submission happens two or three days after referral arrival because of manual document processing burden, the patient's wait to treatment start is still 9 to 10 days even under full payer compliance with the rule.

This is the distinction we return to consistently when talking with clinic administrators: the regulatory change improves the payer side of the equation, and that is meaningful. But it does not touch the provider-side processing time that inflates the total wait for patients. Both sides of the equation need to improve for patients to see substantially shorter delays from referral to infusion start.

Looking Toward the FHIR API Implementation

The January 2027 FHIR API deadline for payers is the more transformative requirement in the rule, but it is also further out and depends on what providers actually do with the API once it is available.

The API requirement means that major Medicare Advantage and Medicaid managed care payers will have a standardized programmatic interface for prior authorization by 2027. For software tools that submit authorizations on behalf of providers, this creates the possibility of direct API submission rather than portal navigation. That shift has the potential to reduce the submission time and the portal-specific navigation burden that currently adds friction to the process.

Whether small infusion centers will benefit from FHIR API submission depends on whether the tools they use implement it, and how well payers actually implement the API requirements. Early adoption of any healthcare IT standard tends to be uneven. The rule creates the obligation; operational reality will determine how smoothly it works in practice.

The regulatory direction is clear. Prior authorization is getting more electronic, with stricter payer response requirements and programmatic submission pathways. For small specialty providers who have managed prior authorization manually, this environment creates pressure to modernize intake processes to be able to take advantage of the faster, more structured pathways as they become available.