Trusted By
CMS-0057-F set a hard deadline. By January 1, 2027, every Medicare Advantage organization, Medicaid managed care plan, CHIP managed care entity, and Qualified Health Plan issuer on the Federally-Facilitated Exchanges has to expose five FHIR APIs in production, with the Prior Authorization API at the center. The operational rules kicked in earlier, on January 1, 2026, locking payers into 7-day standard and 72-hour urgent decision timeframes, mandatory denial reasoning, and public performance metric reporting. The four data points below show what is on the line.
| Stat | What it means |
|---|---|
| Jan 1, 2027 | CMS-0057-F deadline for impacted payers to expose Patient Access, Provider Access, Provider Directory, Payer-to-Payer, and Prior Authorization FHIR APIs in production. |
| 72 hours / 7 days | Required maximum decision timeframes for urgent and standard prior authorization requests, effective Jan 1, 2026. Faxed submissions get no slower SLA. |
| $25B | Estimated annual administrative cost of manual prior authorization in US healthcare, before CMS-0057-F mandates the move to FHIR-based electronic submissions. |
| 14 hours | Average physician and staff time per week spent on prior authorization tasks per practice. ePA automation cuts this dramatically. |
Every impacted payer needs five FHIR APIs running in production by January 1, 2027. We build each one to the CMS-specified standards, with Da Vinci implementation guide alignment, SMART on FHIR authorization, and bulk export support where the rule requires it.
The HL7 Da Vinci Project defines the implementation guides CMS recommends for electronic prior authorization. Three Burden Reduction IGs work in concert to automate PA submission and review end to end. We build each one against the latest STU versions.
We build CRD endpoints that respond to FHIR CDS hooks from the provider’s EHR. The hook fires when a clinician orders a service, and the CRD endpoint returns benefit design, prior authorization requirements, documentation needs, and any utilization management policies that apply. Clinicians know upfront whether PA is required and what documentation they need to gather.
We build DTR services that surface payer-specific questionnaires in the EHR using SMART on FHIR. Questionnaires are pre-populated from EHR data via Clinical Quality Language (CQL) expressions, so clinicians fill in only the gaps. The completed QuestionnaireResponse flows directly into the PAS submission, eliminating manual documentation re-entry.
We build PAS endpoints that accept electronic prior authorization requests with FHIR Claim resources (or X12 278 mapped to FHIR), validate completeness against payer rules, route to the UM workflow, and return decisions back to the provider system. Supports approved, denied, partially approved, and pending-for-information outcomes with the required denial reason coding.
We integrate the Da Vinci workflows with your existing utilization management platforms, including custom rules engines, vendor UM systems (Cohere, Olive, Optum, EviCore), and internal review workflows. Auto-approval logic for clean requests, exception routing for complex cases.
We ensure you’re matched with the right talent resource based on your requirement.
Beyond the regulatory APIs and Da Vinci workflows, prior authorization platforms need the operational features that make ePA work for clinicians, UM nurses, and members. Our team builds these end-to-end.
The platform checks PA requirements in milliseconds against payer-specific clinical policies, plan benefits, and member eligibility. Surface requirements at the moment of clinical decision, not three days later.
We build automated documentation extraction from EHR data using FHIR queries and CQL expressions. Clinicians review and submit instead of starting from scratch. Documentation gaps surface inline before submission, not as denial reasons after.
We build rules-based decision engines that auto-approve clean requests against payer clinical policies, route gray-area cases to UM nurses, and escalate complex requests to medical directors. Configurable per payer, per service type, per benefit plan.
The platform tracks every request against the 72-hour urgent and 7-day standard timeframes mandated by CMS-0057-F. Surfaces approaching deadlines, escalates breach risk, and feeds the public reporting metrics CMS requires annually.
Every denial includes the specific clinical or administrative reason CMS requires. Reasons map to standardized code sets, surface in the Patient Access API so members can see them, and feed continuous improvement of clinical policy clarity.
We build appeals workflows that route denied requests to peer review, gather additional documentation, track regulatory appeal timeframes, and integrate with the member-facing portal for first-level appeals.
We build the reporting modules that capture and publish the prior authorization performance metrics CMS requires payers to report publicly. Auto-generated reports for the annual deadline, with audit trails for CMS examination.
We build provider-facing portals where in-network providers can submit PAs, check status, view determinations, and pull historical PA decisions for their attributed patients. Includes bulk submission tools and panel-level dashboards.
We build on a modern FHIR-native stack chosen for healthcare data volumes, HIPAA-eligibility, and the regulatory durability prior authorization software needs.
| Cloud Platforms |
AWS (HIPAA-eligible) | Microsoft Azure | Google Cloud | AWS HealthLake | Azure Health Data Services |
| FHIR Stack |
HL7 FHIR R4 | Aidbox | Firely Server | HAPI FHIR | Kodjin | Microsoft FHIR Service |
| Da Vinci Implementation Guides |
CRD STU 2.0 | DTR STU 2.0 | PAS STU 2.0 | PDex STU 2.0 | Plan-Net STU 1.1 |
| Standards and Profiles |
US Core IG | USCDI v1 / v3 | SMART App Launch 2.0 | CDS Hooks | Bulk Data Access (Flat FHIR) |
| Application Layer |
React | Node.js | TypeScript | .NET | Java Spring | PostgreSQL |
| Authorization and Identity |
OAuth 2.0 | OpenID Connect | Okta | Microsoft Entra ID | Auth0 |
| Translation and Integration |
Mirth Connect | Rhapsody | Apache Kafka | Apache NiFi | X12 278 | HL7 v2 |
| AI / ML Stack |
Python | TensorFlow | AWS SageMaker | Azure ML (for clinical policy automation and documentation parsing) |
| Security and Compliance |
AWS KMS | HashiCorp Vault | Drata | Vanta |
| Compliance frameworks |
HIPAA | HITECH | HITRUST CSF | CMS-0057-F | HL7 FHIR R4 | Da Vinci CRD/DTR/PAS | USCDI v1 and v3 | ASTP/ONC certification criteria | NIST CSF 2.0 | NIST SP 800-66 | ISO/IEC 27001:2022 | SOC 2 Type II | CMS Interoperability |
Three recent engagements where our team turned PA software into measurable compliance and operational results.
A regional Medicare Advantage organization covering 240,000 members needed to stand up all five FHIR APIs and migrate to Da Vinci ePA workflows. We built the FHIR R4 stack, implemented CRD/DTR/PAS, integrated with their existing UM platform, and went live with full CMS-0057-F compliance 9 months ahead of the January 2027 deadline. Average PA decision time dropped from 4.7 days to under 8 hours for clean requests.
Discover
A state Medicaid managed care plan covering 1.1M members needed to automate routine PA decisions while maintaining clinical review for complex cases. We built a configurable decision engine with payer-specific clinical policies, integrated with their UM platform, and added Da Vinci DTR for automated documentation gathering. Outcome: 73% of routine PA requests now auto-approve within minutes, freeing UM nursing time for the 27% of cases that need human review.
Discover
A specialty EHR vendor needed to ship embedded ePA capability to their 1,400 provider practice customers ahead of the CMS-0057-F provider-side requirements. We built a SMART on FHIR-launched ePA module with CRD/DTR client implementations, payer connectivity to 38 commercial payers and CMS, and one-click submission from the provider workflow. Provider PA submission time dropped from an average 23 minutes to under 3 minutes.
DiscoverCMS-0057-F primarily impacts payers, but the prior authorization software market spans payers, providers, EHR vendors, and intermediaries.
We build CMS-0057-F-compliant prior authorization platforms for MA organizations, with full Patient Access, Provider Access, Payer-to-Payer, and Prior Authorization API support, plus Da Vinci CRD/DTR/PAS workflow implementation.
We build PA platforms for Medicaid MCOs and state Medicaid Fee-for-Service programs. Includes state-specific clinical policies, dual-eligible coordination, and SDOH-related authorization workflows.
We build PA platforms for Children’s Health Insurance Program managed care entities. Pediatric-specific clinical policies, school-based services workflows, and family caregiver communication.
We build PA platforms for QHP issuers on the Federally-Facilitated Exchanges. Marketplace-aligned benefit design, special enrollment handling, and Affordable Care Act compliance.
We build PA software for TPAs handling self-insured employer programs and specialty pharmacy benefit managers handling drug-specific PA workflows. Both have unique workflow needs outside the CMS-0057-F rule but draw from the same FHIR stack.
We build embedded PA modules for EHR vendors and health IT companies that want to ship CMS-0057-F-compliant capability inside their existing products. CDS Hooks integration, SMART on FHIR launch, and white-label deployment.
Building CMS-0057-F-compliant prior authorization software is not a generic development project. It requires teams that know HL7 FHIR R4 inside out, that understand the Da Vinci Implementation Guides, that have actually built CDS Hooks integrations, and that know the UM workflow context the software has to plug into. At Bacancy, 14 years of healthcare engineering means our team brings that depth on day one. We deliver in two-week sprints with demo-driven progress reviews. We are not a generalist development shop learning healthcare on your project.
Prior authorization software is a healthcare technology platform that automates the workflow of requesting, evaluating, and approving payer authorizations for medical services. Modern PA software is built on HL7 FHIR R4 and the Da Vinci Implementation Guides (CRD, DTR, PAS) to comply with the CMS-0057-F Interoperability and Prior Authorization Final Rule.
CMS-0057-F is the federal rule finalized in January 2024 that requires impacted payers (Medicare Advantage, Medicaid FFS and managed care, CHIP, QHP issuers on FFEs) to implement five FHIR APIs by January 1, 2027: Patient Access, Provider Access, Provider Directory, Payer-to-Payer, and Prior Authorization. Operational rules including 72-hour urgent and 7-day standard decision timeframes started January 1, 2026.
The Da Vinci CRD, DTR, and PAS Implementation Guides are not strictly mandatory under CMS-0057-F, but CMS clearly signals them as the preferred path for the Prior Authorization API. Using Da Vinci accelerates compliance, improves EHR integration, and aligns with provider workflows. Most CMS-0057-F implementations we deliver use Da Vinci.
A focused PA module (one Da Vinci IG implementation, basic UM integration) runs $300,000 to $700,000. A complete CMS-0057-F compliance build for an impacted payer (all 5 FHIR APIs, full Da Vinci workflow, UM integration, public reporting) runs $1M to $3M depending on payer size and existing infrastructure. Bacancy scopes pricing to your environment.
A focused PA API module takes 6 to 9 months. A complete CMS-0057-F build for an impacted payer takes 12 to 18 months including all 5 FHIR APIs, Da Vinci workflow implementation, UM integration, and testing. Given the January 2027 deadline, organizations should start by Q2 2026 at the latest.
Yes. We integrate the Da Vinci ePA workflow with your existing UM platforms (Cohere, Olive, Optum, EviCore) or internal review workflows. The FHIR Prior Authorization API sits on top of your UM logic, not in place of it. We can also rebuild the UM engine if needed.
CMS-0057-F explicitly excludes drug PAs from the Prior Authorization API requirements, but we build drug PA workflows for specialty PBMs and pharmacy benefit managers using parallel architecture. NCPDP SCRIPT standards instead of FHIR Claim resources, but the same workflow patterns.
CMS-0057-F includes enforcement timelines and penalties for non-compliance. Impacted payers facing the deadline should start now to avoid Q4 2026 emergency builds. We can deliver focused compliance work in 6 to 9 months for payers that need to move quickly.
Both. Payer-side builds focus on the FHIR API server, UM integration, and clinical policy logic. Provider-side builds focus on EHR-embedded PA submission, CRD/DTR client implementations, and provider workflow integration. EHR vendors typically need both sides for their customer base.