Trusted By

pharmaplace
matt-tailbot
One-med-all
zoetis
callondoc
freyr

Why Healthcare Organizations Are Building Prior Authorization Software in 2026

CMS-0057-F set a hard deadline. By January 1, 2027, every Medicare Advantage organization, Medicaid managed care plan, CHIP managed care entity, and Qualified Health Plan issuer on the Federally-Facilitated Exchanges has to expose five FHIR APIs in production, with the Prior Authorization API at the center. The operational rules kicked in earlier, on January 1, 2026, locking payers into 7-day standard and 72-hour urgent decision timeframes, mandatory denial reasoning, and public performance metric reporting. The four data points below show what is on the line.

Stat What it means
Jan 1, 2027 CMS-0057-F deadline for impacted payers to expose Patient Access, Provider Access, Provider Directory, Payer-to-Payer, and Prior Authorization FHIR APIs in production.
72 hours / 7 days Required maximum decision timeframes for urgent and standard prior authorization requests, effective Jan 1, 2026. Faxed submissions get no slower SLA.
$25B Estimated annual administrative cost of manual prior authorization in US healthcare, before CMS-0057-F mandates the move to FHIR-based electronic submissions.
14 hours Average physician and staff time per week spent on prior authorization tasks per practice. ePA automation cuts this dramatically.

CMS-0057-F Compliance Modules We Build for impacted payers

Every impacted payer needs five FHIR APIs running in production by January 1, 2027. We build each one to the CMS-specified standards, with Da Vinci implementation guide alignment, SMART on FHIR authorization, and bulk export support where the rule requires it.

Prior Authorization API

We build the FHIR Prior Authorization API that lets providers check if PA is required, retrieve documentation requirements, submit requests electronically, and receive decisions back in near real time. Supports the full ePA loop with X12 278 translation when payers need a hybrid model. Tied to your existing utilization management (UM) system through configurable adapters.

Patient Access API (Extended)

We extend the existing Patient Access API to include prior authorization information (status, decisions, denial reasons), excluding drug PAs. Members can see why a request was denied, what documentation was used, and where the request sits in the queue. Aligned with the CARIN Consumer-Directed Payer Data Exchange (CARIN IG for Blue Button) and Da Vinci PDex.

Provider Access API

We build the Provider Access API that lets in-network providers retrieve claims, encounters, USCDI clinical data, and PA history for their attributed patients. Includes provider-patient matching workflows, attribution list maintenance, and patient opt-out support. Bulk export support via flat FHIR for panel-level retrieval.

Payer-to-Payer API

We build the Payer-to-Payer API that exchanges up to 5 years of claims, encounters, USCDI data, and PA history when members change plans. Includes patient opt-in workflows, attribution verification, and continuity-of-care handoff logic. Critical for MA, Medicaid, and QHP members moving between covered populations.

Provider Directory API

We update the existing Provider Directory API to meet the 30-day refresh cadence and standardized data class requirements under CMS-0057-F. Public, no-authentication directory of contracted providers, services, locations, and accepted plans. Aligned with Da Vinci Plan-Net IG.

Da Vinci Prior Authorization Workflows We Implement

The HL7 Da Vinci Project defines the implementation guides CMS recommends for electronic prior authorization. Three Burden Reduction IGs work in concert to automate PA submission and review end to end. We build each one against the latest STU versions.

Coverage Requirements Discovery (CRD)

We build CRD endpoints that respond to FHIR CDS hooks from the provider’s EHR. The hook fires when a clinician orders a service, and the CRD endpoint returns benefit design, prior authorization requirements, documentation needs, and any utilization management policies that apply. Clinicians know upfront whether PA is required and what documentation they need to gather.

Documentation Templates and Rules (DTR)

We build DTR services that surface payer-specific questionnaires in the EHR using SMART on FHIR. Questionnaires are pre-populated from EHR data via Clinical Quality Language (CQL) expressions, so clinicians fill in only the gaps. The completed QuestionnaireResponse flows directly into the PAS submission, eliminating manual documentation re-entry.

Prior Authorization Support (PAS)

We build PAS endpoints that accept electronic prior authorization requests with FHIR Claim resources (or X12 278 mapped to FHIR), validate completeness against payer rules, route to the UM workflow, and return decisions back to the provider system. Supports approved, denied, partially approved, and pending-for-information outcomes with the required denial reason coding.

Integration with Existing UM Systems

We integrate the Da Vinci workflows with your existing utilization management platforms, including custom rules engines, vendor UM systems (Cohere, Olive, Optum, EviCore), and internal review workflows. Auto-approval logic for clean requests, exception routing for complex cases.

Get a Free Prior Authorization Software Consultation

We ensure you’re matched with the right talent resource based on your requirement.

Your Success Is Guaranteed

We accelerate the release of digital products and guarantee your success

We Use Slack, Jira & GitHub for Accurate Deployment and Effective Communication.

Core Prior Authorization Capabilities Bacancy Can Build

Beyond the regulatory APIs and Da Vinci workflows, prior authorization platforms need the operational features that make ePA work for clinicians, UM nurses, and members. Our team builds these end-to-end.

Real-Time Requirement Determination

The platform checks PA requirements in milliseconds against payer-specific clinical policies, plan benefits, and member eligibility. Surface requirements at the moment of clinical decision, not three days later.

Automated Documentation Gathering

We build automated documentation extraction from EHR data using FHIR queries and CQL expressions. Clinicians review and submit instead of starting from scratch. Documentation gaps surface inline before submission, not as denial reasons after.

Configurable Decision Engine

We build rules-based decision engines that auto-approve clean requests against payer clinical policies, route gray-area cases to UM nurses, and escalate complex requests to medical directors. Configurable per payer, per service type, per benefit plan.

Statutory Timeframe Tracking

The platform tracks every request against the 72-hour urgent and 7-day standard timeframes mandated by CMS-0057-F. Surfaces approaching deadlines, escalates breach risk, and feeds the public reporting metrics CMS requires annually.

Denial Reason Codification

Every denial includes the specific clinical or administrative reason CMS requires. Reasons map to standardized code sets, surface in the Patient Access API so members can see them, and feed continuous improvement of clinical policy clarity.

Appeals and Reconsideration Workflow

We build appeals workflows that route denied requests to peer review, gather additional documentation, track regulatory appeal timeframes, and integrate with the member-facing portal for first-level appeals.

Public Metric Reporting

We build the reporting modules that capture and publish the prior authorization performance metrics CMS requires payers to report publicly. Auto-generated reports for the annual deadline, with audit trails for CMS examination.

Provider Self-Service Portal

We build provider-facing portals where in-network providers can submit PAs, check status, view determinations, and pull historical PA decisions for their attributed patients. Includes bulk submission tools and panel-level dashboards.

Tech Stack and Compliance Frameworks We Follow

We build on a modern FHIR-native stack chosen for healthcare data volumes, HIPAA-eligibility, and the regulatory durability prior authorization software needs.

Cloud Platforms

AWS (HIPAA-eligible) | Microsoft Azure | Google Cloud | AWS HealthLake | Azure Health Data Services

FHIR Stack

HL7 FHIR R4 | Aidbox | Firely Server | HAPI FHIR | Kodjin | Microsoft FHIR Service

Da Vinci Implementation Guides

CRD STU 2.0 | DTR STU 2.0 | PAS STU 2.0 | PDex STU 2.0 | Plan-Net STU 1.1

Standards and Profiles

US Core IG | USCDI v1 / v3 | SMART App Launch 2.0 | CDS Hooks | Bulk Data Access (Flat FHIR)

Application Layer

React | Node.js | TypeScript | .NET | Java Spring | PostgreSQL

Authorization and Identity

OAuth 2.0 | OpenID Connect | Okta | Microsoft Entra ID | Auth0

Translation and Integration

Mirth Connect | Rhapsody | Apache Kafka | Apache NiFi | X12 278 | HL7 v2

AI / ML Stack

Python | TensorFlow | AWS SageMaker | Azure ML (for clinical policy automation and documentation parsing)

Security and Compliance

AWS KMS | HashiCorp Vault | Drata | Vanta

Compliance frameworks

HIPAA | HITECH | HITRUST CSF | CMS-0057-F | HL7 FHIR R4 | Da Vinci CRD/DTR/PAS | USCDI v1 and v3 | ASTP/ONC certification criteria | NIST CSF 2.0 | NIST SP 800-66 | ISO/IEC 27001:2022 | SOC 2 Type II | CMS Interoperability

Outcomes Our Prior Authorization Builds Have Delivered

Three recent engagements where our team turned PA software into measurable compliance and operational results.

CMS-0057-F Compliance Delivered 9 Months Ahead of Deadline
Medicare Advantage

CMS-0057-F Compliance Delivered 9 Months Ahead of Deadline

A regional Medicare Advantage organization covering 240,000 members needed to stand up all five FHIR APIs and migrate to Da Vinci ePA workflows. We built the FHIR R4 stack, implemented CRD/DTR/PAS, integrated with their existing UM platform, and went live with full CMS-0057-F compliance 9 months ahead of the January 2027 deadline. Average PA decision time dropped from 4.7 days to under 8 hours for clean requests.

Discover
73% Auto-Approval Rate on Routine Requests
Medicaid MCO

73% Auto-Approval Rate on Routine Requests

A state Medicaid managed care plan covering 1.1M members needed to automate routine PA decisions while maintaining clinical review for complex cases. We built a configurable decision engine with payer-specific clinical policies, integrated with their UM platform, and added Da Vinci DTR for automated documentation gathering. Outcome: 73% of routine PA requests now auto-approve within minutes, freeing UM nursing time for the 27% of cases that need human review.

Discover
Embedded ePA Module Live Across 1,400 Provider Practices
EHR Vendor

Embedded ePA Module Live Across 1,400 Provider Practices

A specialty EHR vendor needed to ship embedded ePA capability to their 1,400 provider practice customers ahead of the CMS-0057-F provider-side requirements. We built a SMART on FHIR-launched ePA module with CRD/DTR client implementations, payer connectivity to 38 commercial payers and CMS, and one-click submission from the provider workflow. Provider PA submission time dropped from an average 23 minutes to under 3 minutes.

Discover

Healthcare Organizations We Build Prior Authorization Software For

CMS-0057-F primarily impacts payers, but the prior authorization software market spans payers, providers, EHR vendors, and intermediaries.

Medicare Advantage Organizations
Medicaid Managed Care Plans and State FFS Programs
CHIP Managed Care Entities
Qualified Health Plan Issuers (FFE)
Third-Party Administrators and PBMs
EHR Vendors and Health IT Companies

We build CMS-0057-F-compliant prior authorization platforms for MA organizations, with full Patient Access, Provider Access, Payer-to-Payer, and Prior Authorization API support, plus Da Vinci CRD/DTR/PAS workflow implementation.

  • 72-hour standard and 24-hour urgent response time enforcement
  • Public denial rate reporting per CMS-0057-F transparency mandate
  • HEDIS quality measure integration and Star Ratings impact tracking
  • C-SNP, D-SNP, and I-SNP dual-eligible workflow support

We build PA platforms for Medicaid MCOs and state Medicaid Fee-for-Service programs. Includes state-specific clinical policies, dual-eligible coordination, and SDOH-related authorization workflows.

  • MMIS integration across all 50 state variations
  • EPSDT and behavioral health carve-out coordination
  • Long-term services and supports (LTSS) authorization workflows
  • 1115 waiver program approval pathways

We build PA platforms for Children’s Health Insurance Program managed care entities. Pediatric-specific clinical policies, school-based services workflows, and family caregiver communication.

  • EPSDT well-child and immunization tracking
  • Pediatric specialty referral routing (developmental, behavioral, dental, vision)
  • Age-based benefit transition and eligibility renewal
  • Multi-guardian consent and family caregiver portal

We build PA platforms for QHP issuers on the Federally-Facilitated Exchanges. Marketplace-aligned benefit design, special enrollment handling, and Affordable Care Act compliance.

  • Essential Health Benefits categorization across bronze, silver, gold, platinum tiers
  • Cost-sharing reduction (CSR) variant plan handling
  • Special enrollment period and qualifying life event verification
  • Grace period and premium-payment status impact on PA decisions

We build PA software for TPAs handling self-insured employer programs and specialty pharmacy benefit managers handling drug-specific PA workflows. Both have unique workflow needs outside the CMS-0057-F rule but draw from the same FHIR stack.

  • Per-employer-group ERISA plan configuration and benefit variation
  • Stop-loss carrier coordination and reinsurance triggers
  • Formulary tier logic with NCPDP SCRIPT and step-therapy enforcement
  • Specialty pharmacy REMS enforcement and rebate coordination

We build embedded PA modules for EHR vendors and health IT companies that want to ship CMS-0057-F-compliant capability inside their existing products. CDS Hooks integration, SMART on FHIR launch, and white-label deployment.

  • Multi-tenant architecture with per-tenant configuration
  • SMART on FHIR launch and CDS Hooks service publishing
  • Epic Payer Platform, Cerner Ignite, Athenahealth Marketplace integration
  • ONC HTI-1 certification support and white-label OEM branding

Why Choose Bacancy for Prior Authorization Software Development

Building CMS-0057-F-compliant prior authorization software is not a generic development project. It requires teams that know HL7 FHIR R4 inside out, that understand the Da Vinci Implementation Guides, that have actually built CDS Hooks integrations, and that know the UM workflow context the software has to plug into. At Bacancy, 14 years of healthcare engineering means our team brings that depth on day one. We deliver in two-week sprints with demo-driven progress reviews. We are not a generalist development shop learning healthcare on your project.

Why Choose Bacancy for Prior Authorization Software Development
  • 14+ years building and modernizing healthcare IT systems
  • Dedicated healthcare practice with 250+ specialists on staff
  • Deep specialization in HL7 FHIR R4, Da Vinci IGs (CRD, DTR, PAS), SMART on FHIR, OAuth 2.0, and CQL
  • Integration depth across UM systems (Cohere, Olive, Optum, EviCore, internal review workflows) and EHRs (Epic, Cerner Oracle Health, Athenahealth, NextGen, eClinicalWorks, Allscripts, MEDITECH)
  • X12 278 to FHIR translation engineering for hybrid PA workflows
  • ISO/IEC 27001:2022 certified, with active ISO 13485 and SOC 2 Type II programs
  • Featured in industry directories including G2, Clutch, and GoodFirms
Talk to a Prior Auth Lead

What is prior authorization software?

Prior authorization software is a healthcare technology platform that automates the workflow of requesting, evaluating, and approving payer authorizations for medical services. Modern PA software is built on HL7 FHIR R4 and the Da Vinci Implementation Guides (CRD, DTR, PAS) to comply with the CMS-0057-F Interoperability and Prior Authorization Final Rule.

What does CMS-0057-F require, and when is the deadline?

CMS-0057-F is the federal rule finalized in January 2024 that requires impacted payers (Medicare Advantage, Medicaid FFS and managed care, CHIP, QHP issuers on FFEs) to implement five FHIR APIs by January 1, 2027: Patient Access, Provider Access, Provider Directory, Payer-to-Payer, and Prior Authorization. Operational rules including 72-hour urgent and 7-day standard decision timeframes started January 1, 2026.

Do we have to use the Da Vinci Implementation Guides?

The Da Vinci CRD, DTR, and PAS Implementation Guides are not strictly mandatory under CMS-0057-F, but CMS clearly signals them as the preferred path for the Prior Authorization API. Using Da Vinci accelerates compliance, improves EHR integration, and aligns with provider workflows. Most CMS-0057-F implementations we deliver use Da Vinci.

How much does custom prior authorization software development cost?

A focused PA module (one Da Vinci IG implementation, basic UM integration) runs $300,000 to $700,000. A complete CMS-0057-F compliance build for an impacted payer (all 5 FHIR APIs, full Da Vinci workflow, UM integration, public reporting) runs $1M to $3M depending on payer size and existing infrastructure. Bacancy scopes pricing to your environment.

How long does it take to build CMS-0057-F-compliant prior authorization software?

A focused PA API module takes 6 to 9 months. A complete CMS-0057-F build for an impacted payer takes 12 to 18 months including all 5 FHIR APIs, Da Vinci workflow implementation, UM integration, and testing. Given the January 2027 deadline, organizations should start by Q2 2026 at the latest.

Can the platform integrate with our existing utilization management system?

Yes. We integrate the Da Vinci ePA workflow with your existing UM platforms (Cohere, Olive, Optum, EviCore) or internal review workflows. The FHIR Prior Authorization API sits on top of your UM logic, not in place of it. We can also rebuild the UM engine if needed.

Does the platform handle drug prior authorizations?

CMS-0057-F explicitly excludes drug PAs from the Prior Authorization API requirements, but we build drug PA workflows for specialty PBMs and pharmacy benefit managers using parallel architecture. NCPDP SCRIPT standards instead of FHIR Claim resources, but the same workflow patterns.

What happens if we miss the January 2027 deadline?

CMS-0057-F includes enforcement timelines and penalties for non-compliance. Impacted payers facing the deadline should start now to avoid Q4 2026 emergency builds. We can deliver focused compliance work in 6 to 9 months for payers that need to move quickly.

Does Bacancy build the provider-side or payer-side?

Both. Payer-side builds focus on the FHIR API server, UM integration, and clinical policy logic. Provider-side builds focus on EHR-embedded PA submission, CRD/DTR client implementations, and provider workflow integration. EHR vendors typically need both sides for their customer base.