A Closer Look at the Flexibility Offered to Covered Entities with API Standards Under the New Interoperability Rule

The healthcare system in the United States has had problems with sharing patient information quickly between payers, providers, and patients. This is especially true for prior authorization, which is when health insurers approve or deny payment for certain services before the care happens. This process has been slow and complicated. It often involves fax machines, phone calls, and long wait times. These delays add extra work for medical office staff and cause care to be slower, which can upset both providers and patients.

To improve this, the Centers for Medicare & Medicaid Services (CMS) made the Interoperability and Prior Authorization Final Rule (CMS-0057-F) on January 17, 2024. This rule wants healthcare data to be shared better. It also wants prior authorizations to be handled more easily by using new technology, especially API (Application Programming Interface) standards. Medical practices, especially those dealing with Medicare, Medicaid, CHIP, and Qualified Health Plans, will need to follow this rule over the coming years. It is important to know the flexibility the rule gives and how it will change daily work.

The CMS rule says that all affected payers must use Health Level 7® (HL7®) Fast Healthcare Interoperability Resources® (FHIR®) APIs by January 1, 2027. These APIs help payers, providers, and patients share information faster. They reduce the need for slow manual steps.

  • Patient Access API: Lets patients see their own prior authorization data, including documents, statuses, and decisions.
  • Provider Access API: Allows in-network providers to see patient data and prior authorization info to help with care.
  • Prior Authorization API: Automates approval workflows so providers and payers can communicate fast and get quicker decisions.
  • Payer-to-Payer API: Transfers patient data when people change insurance plans to keep care continuous without delay.

Before these APIs, practices had to follow different and complicated prior authorization rules from many payers. This slowed down work and used up resources. The CMS rule sets clear standards to make this easier and help patient care.

Flexibility in API Standards: A Key Feature for Covered Entities

The CMS rule also gives covered entities like hospitals, clinics, and health plans some freedom in how they follow the new rules. In the past, healthcare used older standards like the X12 278 transaction for prior authorization, based on HIPAA rules. These older standards worked but became outdated and slowed down new technology use.

The National Standards Group (NSG) and CMS understand this problem. They said covered entities do not have to keep using the old X12 278 transaction if they switch to the new FHIR-based Prior Authorization APIs. There will be no penalties for not using the old method. This gives covered entities a chance to move faster to newer and better technology without being held back by old rules.

Organizations can use either only FHIR APIs or a mix of FHIR and X12 APIs. This helps them switch at a comfortable speed based on their technology, money, and needs. This is very helpful for many practices and health plans because they are ready for change at different levels.

Allowing a mix of API standards lets work change slowly without sudden interruptions. It helps avoid problems in care and billing that could happen if the switch is done too fast.

HIPAA-Compliant Voice AI Agents

SimboConnect AI Phone Agent encrypts every call end-to-end – zero compliance worries.

Challenges the Rule Addresses for Medical Practice Administration

Medical practice administrators and owners have found prior authorization to be a big problem. Before this CMS rule, the process often meant:

  • Trying to figure out different and complex rules from each payer.
  • Making many phone calls and sending faxes to insurance companies.
  • Waiting 20 to 30 minutes or more on hold to get approval.
  • Keeping track of requests manually with no real-time updates.
  • Delays that caused patient treatments to be postponed or canceled.

These problems increase the work for staff, reduce time spent with patients, and can hurt money flow because of denials or slow approvals.

The CMS rule wants to fix these by automating prior authorization using standard APIs. The rule says:

  • Providers can send authorization requests electronically.
  • Payers must respond within 72 hours for urgent requests and seven days for regular ones.
  • If authorization is denied, clear reasons must be given so corrections or appeals are easier.
  • Payers will have to report prior authorization data publicly, helping with fairness and improvement.

This new way reduces the time administrators spend on old communication methods and lets them focus on scheduling and documentation better.

How the Rule Supports Improved Care Coordination

The Provider Access API makes it easier for in-network providers to get patient data. This helps medical practices by:

  • Giving faster access to clinical and claim data during authorization and treatment planning.
  • Helping providers work together to avoid repeat tests or procedures.
  • Making patient transfers between providers smoother, especially for those seeing many specialists.

The Payer-to-Payer API helps patients who change insurance plans by making sure their health information moves with them. This keeps care going without gaps. For areas with many Medicaid clinics, like Baltimore, this makes managing patients and insurance easier.

These APIs help reduce delays and extra work, while improving the quality of care.

AI and Automation Integration in Prior Authorization Workflows

Artificial Intelligence (AI) and automation are becoming more important with the new interoperability APIs. Some companies, like Simbo AI, focus on AI tools for front-office phone work and answering services. They help healthcare offices handle communication better.

Prior authorization talk often happens over the phone. Staff need to explain complicated information about approval, documentation, and denials. AI can help by:

  • Answering common patient questions automatically.
  • Checking authorization status in real time using API links.
  • Scheduling callbacks or routing calls to the right place automatically.
  • Reducing wait times and letting staff focus on harder tasks.
  • Giving patients accurate and quick information without delay from humans.

When AI works with the FHIR-based APIs from the CMS rule, practices can make their internal work and patient talks smoother. This lowers staff work, improves communication accuracy, and meets new rules better.

Automation also helps clinical staff by making sure authorization requests are sent correctly and on time, lowering denials due to mistakes or missing paperwork.

For healthcare IT managers, adding AI automation with CMS APIs can make operations run better and keep up with new tech changes.

AI Call Assistant Manages On-Call Schedules

SimboConnect replaces spreadsheets with drag-and-drop calendars and AI alerts.

Start Now →

Financial and Operational Implications for Medical Practices

The CMS rule expects big savings in the long run. It estimates about $15 billion saved over ten years by cutting down admin costs and delays in prior authorization. For medical offices, this means:

  • Less time spent by clinical and admin staff on prior authorization tasks.
  • Faster approvals that let patients get scheduled and treated sooner.
  • Less money lost from denied or late claims.
  • Not having to use many different payer websites, because APIs unify access.

Payers must also report prior authorization data yearly, including reasons for denials. This makes things more open. Admins can find patterns in delays or denials, which helps fix problems or work with payers better.

Hospitals and bigger practices involved in CMS programs, especially those under the Merit-based Incentive Payment System (MIPS), will benefit. They must report electronic use of payer APIs. This pushes more use of digital technology and gives extra rewards.

Regional and Organizational Considerations for Covered Entities

Medical organizations working in Medicaid clinics or health exchanges in the U.S., like in Baltimore and other cities, gain several benefits from the CMS rule:

  • Better data sharing lowers the challenges of working with many government programs.
  • Patients get better access to their health data, helping them make informed choices.
  • Providers work better together because clinical and billing data are easier to get.
  • The option to adopt APIs in phases lets organizations update technology step by step without upsetting services.

Since technology and money vary across regions, this flexibility helps healthcare groups adopt API standards in line with what they can handle. It also helps smaller practices by letting them use outside vendors or AI services like Simbo AI to manage parts of prior authorization calls, which might be too costly to handle inside.

Voice AI Agent for Small Practices

SimboConnect AI Phone Agent delivers big-hospital call handling at clinic prices.

Start Building Success Now

Supporting Education and Adoption

CMS offers materials to help with learning the new standards. There are fact sheets, guides, and templates on prior authorization data. These help payers and providers improve their systems and talk clearly with patients and staff.

CMS also works on simple and clear educational resources for all involved, including patients. Patients can now see more of their health data through Patient Access APIs. This helps them understand their care and insurance approvals better.

In summary, the CMS Interoperability and Prior Authorization Final Rule gives covered entities freedom in how they use new API standards. By encouraging HL7 FHIR-based Prior Authorization APIs and allowing delays on older standards, the rule meets different organizations’ needs and tech readiness.

Medical administrators, owners, and IT managers should know this flexibility well. The healthcare field is moving toward automated, faster workflows that cut down admin work and improve patient care. AI tools like Simbo AI can help offices handle patient contact and prior authorization tasks better as the rules change.

Frequently Asked Questions

What is the CMS Interoperability and Prior Authorization Final Rule CMS-0057-F?

The CMS Interoperability and Prior Authorization Final Rule CMS-0057-F aims to enhance interoperability and streamline prior authorization processes for Medicare, Medicaid, and CHIP by requiring the implementation of specific APIs, including Patient Access, Provider Access, Payer-to-Payer, and Prior Authorization APIs.

When do the new interoperability requirements take effect?

The compliance dates for the new interoperability requirements generally begin on January 1, 2026, with various provisions, including implementation of certain APIs, required by January 1, 2027.

What is the purpose of the Patient Access API?

The Patient Access API allows patients to access their health data, including prior authorization information, facilitating better understanding of their healthcare and the authorization processes involved.

How does the Provider Access API support care coordination?

The Provider Access API allows in-network providers to access necessary patient data for treatment, which aids in better care coordination and retrieval of claims data essential for billing.

What prior authorization information must the Prior Authorization API include?

The Prior Authorization API must include a list of covered items and services, documentation requirements for approvals, and status updates on prior authorization requests—whether approvals, denials, or requests for additional information.

How will the rule improve prior authorization decision timeframes?

The rule mandates that payers send prior authorization decisions within 72 hours for urgent requests and within seven calendar days for standard requests, improving response times and patient care.

What are the reporting requirements for impacted payers?

Beginning January 1, 2026, impacted payers must report annual metrics on Patient Access API usage and prior authorization processes to promote transparency and efficiency.

What resources must payers provide to inform patients about API data exchange?

Payers are required to provide plain language educational resources to explain the benefits of API data exchanges and to inform patients about their options to opt-out or opt-in.

How does the rule affect MIPS eligible clinicians?

The rule introduces a new measure for MIPS eligible clinicians to electronically request prior authorizations through the Prior Authorization API starting in the 2027 performance period.

What flexibility is provided to covered entities regarding API standards?

Covered entities may utilize FHIR-only or FHIR and X12 combination APIs, allowing limited flexibility in compliance with previously established HIPAA transaction standards.