A practice manager told us recently that her office "does authorizations" and could not tell us how many were pending, how many were approved but expiring, or how many services had been performed without one. The authorizations lived in a fax folder, three payer portals and one coordinator's memory. When that coordinator took two weeks off in August, the practice received eleven CO-197 denials in September.
Prior authorization is a tracking problem before it is a clinical or payer problem. The service is either authorized for the dates and units performed or it isn't, and the only way to know on the day of service is a log that someone maintains. In 2026 that log has a new use: the federal decision deadlines that impacted payers must now meet.
Key takeaways
- Since January 1, 2026, Medicare Advantage plans and Medicaid and CHIP programs (including their managed care plans) must decide urgent prior authorization requests within 72 hours and standard requests within seven calendar days, and must give a specific reason for every denial. Employer plans and marketplace plans are not held to those timeframes by this rule.
- One log, one row per request, with the same columns every time. The deadline column is what turns the log into an enforcement tool.
- Three reports run from the log: overdue decisions, scheduled without authorization, and expiring authorizations. The second one is what prevents CO-197.
- Authorizations rarely survive a plan change. December is when the expiring report matters most.
- Keep a dated copy of every payer's authorization list. Half the "we thought it was exempt" denials are a list change nobody announced.
What changed on January 1, 2026
The CMS Interoperability and Prior Authorization final rule, CMS-0057-F, published in January 2024, covers Medicare Advantage organizations, state Medicaid and CHIP fee-for-service programs, Medicaid and CHIP managed care plans, and qualified health plan issuers on the federally facilitated exchanges. Beginning January 1, 2026, the Medicare Advantage, Medicaid and CHIP payers on that list must send prior authorization decisions within 72 hours for expedited requests and seven calendar days for standard requests. The marketplace issuers are covered by the rule's other provisions but were excluded from the decision timeframe requirement, so a marketplace plan's turnaround is still governed by its own rules and state law. For Medicare Advantage the change is real: the standard timeframe used to be 14 calendar days.
Two more provisions matter to a billing office. From 2026, impacted payers must give a specific reason when they deny a prior authorization, whatever the request method, which makes the denial letter useful for the appeal instead of a form paragraph. And impacted payers had to begin posting prior authorization metrics on their websites by March 31, 2026: approval and denial rates, appeal outcomes and average decision times. Those pages are worth reading for your top plans, because a plan's own published average is a number to quote back to it when a request is late.
The rule excludes drugs, and it does not reach employer-sponsored commercial plans, which are still governed by state law and contract. The same rule requires impacted payers to implement a Prior Authorization API by January 1, 2027, so that requests and decisions can move electronically between the EHR and the payer. Whether your EHR vendor has built to it is a question worth asking now, because portal-based requests will not disappear in January and the practices that benefit first will be the ones who asked.
The log: one row per request
A spreadsheet is fine; a shared one is better; a work queue inside the practice management system is best if it can hold these fields. What matters is that every row has the same columns:
| Field | Why it is there |
|---|---|
| Patient, date of birth, member ID | The claim must match the authorization exactly |
| Payer and plan type (MA, Medicaid MCO, commercial, marketplace) | Decides which deadline rule applies |
| Service, CPT or HCPCS codes, units, diagnosis | Authorizations are code- and unit-specific; a 99214 does not cover a 20610 |
| Ordering and rendering provider, site of service | Many denials come from a different rendering provider or a facility change |
| Date and time submitted, method, reference number | Starts the clock and proves the request was made |
| Urgent or standard | 72 hours versus seven calendar days for impacted payers |
| Deadline for the payer's decision | Calculated from the submission date; the follow-up trigger |
| Decision, decision date, authorization number, approved units, valid from and to dates | Everything the claim needs, and the expiration to watch |
| Scheduled date of service | Confirms the service falls within the valid dates |
The deadline column does the work. A standard request to a Medicare Advantage plan submitted on Monday, October 12 is due by Monday, October 19. An urgent request submitted Tuesday at 2 p.m. is due Friday at 2 p.m. Put the formula in the spreadsheet so nobody has to count, and have the log sort by deadline rather than by submission date. For commercial plans, enter the turnaround the contract or state law provides, or the plan's own published standard if there is nothing better; a deadline the practice chose is still better than none, because it tells the coordinator when to call.
The three reports the log makes possible
- Overdue decisions. Every request past its deadline with no decision. For impacted payers, call with the reference number and cite the rule's timeframe; ask for the decision or an escalation, and ask the representative to note the call. Under Medicare Advantage rules, a plan that fails to decide within the required time has in effect issued an adverse determination that the patient can appeal, and telling the plan you know that tends to produce a decision. For commercial payers, cite the state's prompt-decision law if one applies and the contract's turnaround language. Log every call.
- Scheduled without authorization. Every appointment in the next ten days for a service on the payer's authorization list with no approved row. This report should run every morning and go to the scheduler and the clinical lead. It is the report that prevents CO-197.
- Expiring authorizations. Every approved authorization with a "valid to" date in the next 30 days and units remaining, matched against scheduled services. Chemotherapy, infusions, physical therapy and imaging series are where this matters most, and December is where it matters most of all because many authorizations end with the plan year.
The year-end wrinkle
Authorizations rarely survive a plan change. A patient who moves from one Medicare Advantage plan to another during open enrollment, or from a marketplace plan to an employer plan on January 1, generally needs a new authorization from the new payer for services continuing into January. Some states require a transition period for ongoing treatment; many do not. Run the expiring-authorization report in early December against every patient whose coverage is changing, and start the new requests before the holidays.
Building the payer authorization list
You cannot track what you do not know needs tracking. For each of your top payers, download or request the current list of services requiring authorization and store it with a date. Payers change these lists, and a service that did not need authorization in March may need one in October. When a CO-197 denial arrives for a service you believed was exempt, check the list date before arguing. In our experience, about half of these turn out to be a list change nobody announced to the practice, and those are frequently appealable when the payer failed to give notice required by the contract.
Keep the list where the scheduler can see it. The scheduled-without-authorization report only works if the system knows which services need one, and that knowledge has to be entered as a flag on the procedure or the appointment type, by payer. A practice that stores the authorization list in the billing office and schedules from the front desk will keep finding out at the remittance.
A worked example
An orthopedic practice with six surgeons ran its first CO-197 report in months: 41 denials, $86,000 billed, over one quarter. Sorting them into causes took an afternoon. Nineteen were MRIs scheduled before the authorization decision arrived; the scans were done, the plan later approved a different date range, and the claims fell outside it. Twelve were injections billed under a partner who covered the clinic that day, when the authorization named the ordering surgeon. Six were physical therapy visits after the approved units ran out. Four were a Medicare Advantage plan's list change in June that nobody had seen. The practice built the log, added the three reports, and set a scheduling rule that no service on an authorization list is booked until the row shows a decision. The following quarter the report had seven denials, and four of them were appealed on the list-change point with the plan's own notice requirement quoted back.
Questions we hear
The payer approved by phone and gave a number. Is that enough?
Record the number, the representative's name, the date and time, and ask for written or portal confirmation. A phone number alone is often disputed later. A screenshot of the portal decision is worth keeping in the chart.
We got the authorization, billed it and still got CO-197. Why?
Check the four things that must match: codes, units, rendering provider and dates. Then check whether the authorization number made it onto the claim in the right field (loop 2300 REF*G1 on the 837P, item 23 on a paper CMS-1500). In our experience most "we had the auth" denials fall into one of those two buckets, and both are corrected claims rather than appeals.
Who should own the log?
One coordinator owns it, and one backup can run all three reports. If the practice cannot staff that, the tracking is a natural piece to hand to a denial management partner, since the same team sees the CO-197 denials and can close the loop. The RCM audit we run includes a count of services performed without an authorization on file, which is usually the number that convinces a practice to build the log.
What to do this week
- Pull the last 90 days of CO-197 denials and sort them into causes: no request, wrong dates or units, wrong provider, expired, list change.
- Build the log with the columns above, and enter every authorization currently pending or approved with future dates.
- Add the deadline formula: 72 hours for urgent and seven calendar days for standard requests to Medicare Advantage, Medicaid and CHIP plans; the contract or state standard for everyone else.
- Download your top five payers' authorization lists, date them, and flag the affected services in the scheduling system.
- Run the scheduled-without-authorization report for the next ten days and fix what it finds before the patients arrive.
