Policy · Prior authorization & utilization review

Public Reporting of Prior-Authorization Metrics

Public prior-authorization metrics can improve accountability only when the numerator, denominator, service scope, timing rule, appeal treatment, and plan product are defined precisely.

Why this topic requires a distinct policy analysis

Public prior-authorization metrics can improve accountability only when the numerator, denominator, service scope, timing rule, appeal treatment, and plan product are defined precisely.

The policy problem is not simply whether an organization can produce a status, report, authorization, credential flag, or data transaction. The harder question is whether the status means what later users think it means. For public reporting of prior-authorization metrics, the governing decision is whether the requested item or service satisfies the applicable coverage and utilization-management rules for the particular patient and plan. The evidence can travel through several organizations before reaching the person who experiences the consequence, which is why source, timing, and role must remain visible.

This public reporting of prior-authorization metrics analysis uses a source-first method. It separates binding law from guidance and private policy; distinguishes a technical or administrative event from the substantive judgment behind it; and treats correction as part of the system rather than an afterthought. That method is intentionally more demanding than a checklist because delay or denial can affect access to treatment while an overbroad approval process can undermine benefit design and program integrity.

Governing framework and contested boundaries

CMS-0057-F requires annual public reporting

Impacted payers must publicly post specified aggregate prior-authorization metrics for the prior calendar year; the first reporting for 2025 data was due in 2026. The requirement creates comparability only within the definitions CMS specifies.

The legal and operational significance is easy to miss because the visible status is shorter than the rule that produced it. In the context of Public Reporting of Prior-Authorization Metrics, the working record should connect this proposition to the authorization request, coverage criteria, clinical documentation, reviewer rationale, decision notice, and appeal record. That matters because a clinical coverage question can be mistaken for a documentation defect, or an administrative defect can be escalated unnecessarily to a clinician. For an audit, the first task is therefore to recover the underlying source, date, actor, and condition rather than infer them from the status label.

For individual prior-authorization measurement cases, chronology should remain visible. A conclusion based on information available on one date should not be retroactively rewritten by later information; instead, the later development should be recorded as a correction, update, appeal result, or new decision.

Approval percentages require a denominator

A percentage is interpretable only if readers know which completed requests are included and how withdrawn, duplicate, incomplete, or pending requests are handled. Journalists should not compare percentages across organizations without checking definitions.

The proposition is narrow but consequential. It determines what can be automated, what needs professional judgment, and what must remain visible to a later reviewer. In the context of Public Reporting of Prior-Authorization Metrics, the working record should connect this proposition to the authorization request, coverage criteria, clinical documentation, reviewer rationale, decision notice, and appeal record. That matters because a clinical coverage question can be mistaken for a documentation defect, or an administrative defect can be escalated unnecessarily to a clinician. A defensible workflow should make that boundary explicit in both policy language and system configuration.

For prior-authorization measurement, the limiting language is as important as the headline rule. Operational teams should preserve the condition described above whenever the result is copied into a portal, credential file, denial notice, data feed, or policy summary; otherwise a narrow proposition can become a categorical one.

Appeal approvals can affect totals

CMS guidance explains that approved prior-authorization requests include requests approved after appeal for the relevant metric. A plan with more initial denials can therefore produce a superficially similar final approval rate to a plan that approves appropriately at first review.

This point becomes most important when the information moves from one organization to another. In the context of Public Reporting of Prior-Authorization Metrics, the working record should connect this proposition to the authorization request, coverage criteria, clinical documentation, reviewer rationale, decision notice, and appeal record. That matters because a clinical coverage question can be mistaken for a documentation defect, or an administrative defect can be escalated unnecessarily to a clinician. A downstream reader may see the result without seeing the conditions that made the result valid, so provenance and limiting language matter.

For prior-authorization measurement, evidence quality should match consequence. The greater the effect on access, professional mobility, or public characterization, the stronger the case for primary-source verification and a clear distinction between allegation, administrative status, and final decision.

Decision time should not be reduced to a single average

CMS requires specified timing metrics, but operational reporting should also examine distributions and urgent versus standard requests. Averages can hide long-tail delays affecting a smaller group of patients.

The distinction also has a timing dimension. In the context of Public Reporting of Prior-Authorization Metrics, the working record should connect this proposition to the authorization request, coverage criteria, clinical documentation, reviewer rationale, decision notice, and appeal record. That matters because a clinical coverage question can be mistaken for a documentation defect, or an administrative defect can be escalated unnecessarily to a clinician. A rule, credential, authorization, investigation, or data standard can change; decisions should be reconstructable using the version that actually applied on the relevant date.

Service mix changes apparent performance

Plans covering different populations and service categories may face different authorization volumes and complexity. Raw cross-plan rankings can be misleading without case-mix and product context.

The issue is not solved by adding a human name to the workflow. In the context of Public Reporting of Prior-Authorization Metrics, the working record should connect this proposition to the authorization request, coverage criteria, clinical documentation, reviewer rationale, decision notice, and appeal record. That matters because a clinical coverage question can be mistaken for a documentation defect, or an administrative defect can be escalated unnecessarily to a clinician. Human accountability requires access to the relevant evidence, authority to disagree with an automated or prior conclusion, and a record explaining the final determination.

When evaluating prior-authorization measurement, separate legal minimums from optional institutional choices. An organization may adopt a stricter internal process, but readers should be able to tell whether the requirement comes from law, contract, technical implementation, or local governance.

Public metrics do not directly prove clinical appropriateness

A low denial rate can reflect good policy or permissive criteria; a high denial rate can reflect restrictive policy, inappropriate submissions, or service mix. Performance evaluation requires both quantitative data and review of reasons and outcomes.

Operational convenience can obscure legal category. In the context of prior-authorization measurement and transparency, the working record should connect this proposition to the authorization request, coverage criteria, clinical documentation, reviewer rationale, decision notice, and appeal record. That matters because a clinical coverage question can be mistaken for a documentation defect, or an administrative defect can be escalated unnecessarily to a clinician. A single portal field may combine several concepts that remain distinct in statute, regulation, contract, and professional practice.

A practical safeguard in prior-authorization measurement is a documented path for exceptions and correction. If the rule is being applied automatically, a qualified person should be able to identify the source criterion, inspect the relevant facts, and explain why the result does or does not fit the individual case.

2026 proposed rules would add more metrics

CMS proposed additional prior-authorization and API metrics in CMS-0062-P. Those additions remain proposals until finalized.

The strongest safeguard is not additional paperwork for its own sake. In the context of prior-authorization measurement and transparency, the working record should connect this proposition to the authorization request, coverage criteria, clinical documentation, reviewer rationale, decision notice, and appeal record. That matters because a clinical coverage question can be mistaken for a documentation defect, or an administrative defect can be escalated unnecessarily to a clinician. It is a record that lets another qualified reviewer reproduce the reasoning and identify what information would have changed the outcome.

Machine-readable reporting would improve research

Structured historical data, methodology notes, and archived prior-year reports would make trend analysis more reliable. Transparency should include version control rather than replacing old reports silently.

This is also a measurement problem. In the context of prior-authorization measurement and transparency, the working record should connect this proposition to the authorization request, coverage criteria, clinical documentation, reviewer rationale, decision notice, and appeal record. That matters because a clinical coverage question can be mistaken for a documentation defect, or an administrative defect can be escalated unnecessarily to a clinician. If organizations count events differently, apparent performance differences may reflect definitions rather than better or worse underlying decisions.

In prior-authorization measurement, this point also creates a transparency obligation. People affected by the process should be able to identify the operative standard and, where applicable, understand how to correct inaccurate facts without having to reverse-engineer an opaque vendor or internal workflow.

How the process should be mapped

Step 1: Coverage policy is identified before the request is submitted

At this stage of prior-authorization measurement and transparency, coverage policy is identified before the request is submitted. The request should begin with a versioned identification of the benefit, item or service, and any coverage or documentation rule. A workflow that discovers criteria only after a denial has already been issued creates avoidable rework and makes later measurement difficult. The handoff should produce a durable artifact so the next participant can see what was decided and what remains open.

Step 2: The clinical request is mapped to the payer’s documentation and coverage criteria

In prior-authorization measurement and transparency, this step is where policy becomes workflow: the clinical request is mapped to the payer’s documentation and coverage criteria. Clinical documentation should be matched to the actual criterion without stripping away context. Structured forms are useful when they capture the relevant facts; they become hazardous when the form itself becomes the substantive rule. A later audit should be able to reconstruct the responsible actor, source material, and timestamp without relying on memory.

Step 3: Administrative completeness is separated from clinical review

For prior-authorization measurement and transparency, the operational question here is how to make 'administrative completeness is separated from clinical review' both efficient and reviewable. Administrative completeness should be resolved separately from medical-necessity judgment. Missing fields, eligibility issues, coding mismatches, and out-of-network status can require different remedies from a clinical adverse determination. The process should not force a high-consequence judgment into a field designed only for routing.

Step 4: An initial decision is made and communicated with a specific reason when required

For prior-authorization measurement and transparency, this stage should be explicitly owned: an initial decision is made and communicated with a specific reason when required. The decision record should identify who decided, what standard was used, what information was available, when the decision was made, and whether the outcome was approval, denial, modification, or a request for more information. Ownership matters because delay or denial can affect access to treatment while an overbroad approval process can undermine benefit design and program integrity.

Step 5: Additional information, reconsideration, peer discussion, or appeal proceeds under the applicable plan rules

A mature prior-authorization measurement and transparency implementation treats this as a control point rather than an invisible transfer: additional information, reconsideration, peer discussion, or appeal proceeds under the applicable plan rules. Informal reconsideration, peer discussion, internal appeal, external review, and grievance procedures should be mapped separately. A clinician should never have to guess whether an informal call is consuming a formal appeal deadline. Exceptions and correction should be captured at the same stage rather than handled off-system.

Step 6: Final disposition is incorporated into authorization, claims, reporting, and quality-improvement systems

The prior-authorization measurement and transparency process should state what completion means for this step: final disposition is incorporated into authorization, claims, reporting, and quality-improvement systems. After disposition, organizations should connect the authorization record to downstream scheduling, claims, appeal, and metric systems without silently changing the meaning of the original decision. That definition prevents a status change from being interpreted more broadly than the evidence supports.

Evidence architecture: what a later reviewer should be able to reconstruct

A high-quality record for prior-authorization measurement and transparency should make five questions answerable without reconstruction from memory: who acted, under what authority, using what information, on what date, and with what effect. The most useful core record is the authorization request, coverage criteria, clinical documentation, reviewer rationale, decision notice, and appeal record. The precise documents differ by organization, but the principle does not: evidence should be linked to the decision it supported rather than collected in a separate archive that cannot be connected to the outcome.

For prior-authorization measurement and transparency, version control is part of evidence quality. A source can be correct today and have been different when the original decision was made. Regulations can take effect after publication; payer criteria can be revised; licenses and certifications can change status; a query can return a later update; API standards can advance. The audit record should therefore preserve both current state and historical decision context.

Correction in prior-authorization measurement and transparency should also be structured. A person challenging inaccurate information should be told which source must be corrected, who owns the local record, how a downstream update will be handled, and whether the original event remains historically relevant. Silent overwriting can be as misleading as failure to correct because it erases the chronology needed to understand earlier decisions.

Failure modes and overstatements

Failure mode 1: Overreading — CMS-0057-F requires annual public reporting

A common failure is to remove the condition from the rule and retain only the outcome. Impacted payers must publicly post specified aggregate prior-authorization metrics for the prior calendar year; the first reporting for 2025 data was due in 2026. The requirement creates comparability only within the definitions CMS specifies. For prior-authorization measurement and transparency, this can distort scheduling, claims payment, appeals, public metrics, and patient access. The organization should separate an upstream fact from its own downstream judgment and document the criterion it is independently applying.

Failure mode 2: Overreading — Approval percentages require a denominator

A second-order error occurs when a correct first decision becomes an overbroad downstream label. A percentage is interpretable only if readers know which completed requests are included and how withdrawn, duplicate, incomplete, or pending requests are handled. Journalists should not compare percentages across organizations without checking definitions. For prior-authorization measurement and transparency, this can distort scheduling, claims payment, appeals, public metrics, and patient access. The workflow should permit a human reviewer to inspect the underlying evidence and correct the status without creating a parallel undocumented process.

Failure mode 3: Overreading — Appeal approvals can affect totals

Operational shorthand becomes risky when it is treated as a legal conclusion. CMS guidance explains that approved prior-authorization requests include requests approved after appeal for the relevant metric. A plan with more initial denials can therefore produce a superficially similar final approval rate to a plan that approves appropriately at first review. For prior-authorization measurement and transparency, this can distort scheduling, claims payment, appeals, public metrics, and patient access. The audit trail should preserve the original event and the later correction rather than silently overwriting one with the other.

Failure mode 4: Overreading — Decision time should not be reduced to a single average

Automation magnifies this problem because the same assumption can be repeated at scale. CMS requires specified timing metrics, but operational reporting should also examine distributions and urgent versus standard requests. Averages can hide long-tail delays affecting a smaller group of patients. For prior-authorization measurement and transparency, this can distort scheduling, claims payment, appeals, public metrics, and patient access. The policy should state whether this is a legal requirement, a technical implementation choice, or an institutional criterion; the consequence should match that source.

Failure mode 5: Overreading — Service mix changes apparent performance

The error often appears during handoff rather than in the original expert review. Plans covering different populations and service categories may face different authorization volumes and complexity. Raw cross-plan rankings can be misleading without case-mix and product context. For prior-authorization measurement and transparency, this can distort scheduling, claims payment, appeals, public metrics, and patient access. The organization should test this failure mode with exception cases, not only with ordinary cases that already fit the expected pattern.

Failure mode 6: Overreading — Public metrics do not directly prove clinical appropriateness

This is especially vulnerable to hindsight because later information can make an earlier record appear clearer than it was. A low denial rate can reflect good policy or permissive criteria; a high denial rate can reflect restrictive policy, inappropriate submissions, or service mix. Performance evaluation requires both quantitative data and review of reasons and outcomes. For prior-authorization measurement and transparency, this can distort scheduling, claims payment, appeals, public metrics, and patient access. A quality review should sample both adverse and favorable outcomes to detect whether the same assumption is creating false positives and false negatives.

Failure mode 7: Overreading — 2026 proposed rules would add more metrics

The risk is asymmetric: an incorrect adverse label can persist even after the source issue is resolved. CMS proposed additional prior-authorization and API metrics in CMS-0062-P. Those additions remain proposals until finalized. For prior-authorization measurement and transparency, this can distort scheduling, claims payment, appeals, public metrics, and patient access. The correction is to carry the trigger, date, actor, and limiting condition with the result and to require primary-source review before a new high-consequence use.

Failure mode 8: Overreading — Machine-readable reporting would improve research

A dashboard or credential flag can make a nuanced event look binary when the governing rule is not. Structured historical data, methodology notes, and archived prior-year reports would make trend analysis more reliable. Transparency should include version control rather than replacing old reports silently. For prior-authorization measurement and transparency, this can distort scheduling, claims payment, appeals, public metrics, and patient access. A defensible system should record what evidence was considered, what evidence was unavailable, and what later information would require the conclusion to be revisited.

What should be measured

Initial approval and denial rates with a defined denominator

For approval and denial rates, publish the denominator and explain whether appeals, duplicates, withdrawals, incomplete requests, and requests for information are included. Without those definitions, comparisons can reward different counting rules rather than better administration. For prior-authorization measurement and transparency, publish the definition alongside the number so that changes in policy, case mix, data capture, or effective dates are not mistaken for changes in performance.

Requests for additional information separated from final denials

For time-to-decision measures, report standard and expedited requests separately and avoid relying on a single average. Medians, distributions, and cases exceeding defined thresholds reveal long-tail delay that an average can hide. For prior-authorization measurement and transparency, publish the definition alongside the number so that changes in policy, case mix, data capture, or effective dates are not mistaken for changes in performance.

Median and distribution of decision time rather than a single average

For appeals, link the final result to the original decision. A high post-appeal approval rate can identify documentation problems, difficult criteria, or avoidable first-level error; it does not establish the cause without review of reason categories. For prior-authorization measurement and transparency, publish the definition alongside the number so that changes in policy, case mix, data capture, or effective dates are not mistaken for changes in performance.

Appeal and reconsideration outcomes linked to the original decision

For clinician burden, distinguish time spent entering data, searching for criteria, resubmitting information, arranging peer review, and pursuing appeal. One aggregate “administrative time” number can conceal the step that most needs redesign. For prior-authorization measurement and transparency, publish the definition alongside the number so that changes in policy, case mix, data capture, or effective dates are not mistaken for changes in performance.

Administrative effort required from clinicians and staff

For service mix, stratify by type of service, urgency, product, and population where privacy permits. A plan handling a different case mix may not be comparable to another plan even when the headline metric has the same name. For prior-authorization measurement and transparency, publish the definition alongside the number so that changes in policy, case mix, data capture, or effective dates are not mistaken for changes in performance.

Differences by service category, urgency, plan product, and patient population

For reversals and corrections, preserve the reason. A reversal after new information is different from a reversal because the same evidence was misread or a rule was applied incorrectly. For prior-authorization measurement and transparency, publish the definition alongside the number so that changes in policy, case mix, data capture, or effective dates are not mistaken for changes in performance.

Stakeholder implications

Treating physicians

For Treating physicians, the immediate question in prior-authorization measurement and transparency is not the headline label but what decision this stakeholder is authorized to make. The safest record links that decision to current primary evidence and states what would trigger reconsideration. The recurring risk is that a clinical coverage question can be mistaken for a documentation defect, or an administrative defect can be escalated unnecessarily to a clinician. The practical countermeasure is to preserve the authorization request, coverage criteria, clinical documentation, reviewer rationale, decision notice, and appeal record and make the stakeholder's own criterion visible.

Patients and authorized representatives

Patients and authorized representatives may see only one slice of prior-authorization measurement and transparency. The workflow should identify which facts originated elsewhere, which facts were independently verified, and which judgment belongs to this stakeholder rather than to the upstream source. The recurring risk is that a clinical coverage question can be mistaken for a documentation defect, or an administrative defect can be escalated unnecessarily to a clinician. The practical countermeasure is to preserve the authorization request, coverage criteria, clinical documentation, reviewer rationale, decision notice, and appeal record and make the stakeholder's own criterion visible.

Payer medical directors and utilization-management staff

For Payer medical directors and utilization-management staff, timing matters in prior-authorization measurement and transparency. A stale status or unexplained alert can be as misleading as failure to act on a current, well-supported concern, so escalation and correction pathways should be explicit. The recurring risk is that a clinical coverage question can be mistaken for a documentation defect, or an administrative defect can be escalated unnecessarily to a clinician. The practical countermeasure is to preserve the authorization request, coverage criteria, clinical documentation, reviewer rationale, decision notice, and appeal record and make the stakeholder's own criterion visible.

Health-system revenue-cycle and authorization teams

From the perspective of Health-system revenue-cycle and authorization teams, accountability in prior-authorization measurement and transparency requires more than receiving data. The recipient should know the source, legal significance, limitations, and currentness of the information before using it for a consequential decision. The recurring risk is that a clinical coverage question can be mistaken for a documentation defect, or an administrative defect can be escalated unnecessarily to a clinician. The practical countermeasure is to preserve the authorization request, coverage criteria, clinical documentation, reviewer rationale, decision notice, and appeal record and make the stakeholder's own criterion visible.

Regulators, researchers, and journalists

Regulators, researchers, and journalists also need a mechanism for disagreement in prior-authorization measurement and transparency. High-consequence systems should allow the recipient to obtain underlying evidence, document contrary information, and avoid turning another organization's shorthand into an independent factual finding. The recurring risk is that a clinical coverage question can be mistaken for a documentation defect, or an administrative defect can be escalated unnecessarily to a clinician. The practical countermeasure is to preserve the authorization request, coverage criteria, clinical documentation, reviewer rationale, decision notice, and appeal record and make the stakeholder's own criterion visible.

Governance controls

Publish the operative criteria and identify the authority behind them

Publish the operative criteria and identify the authority behind them. Written policy should specify the owner, the trigger, the evidence required, the permissible outputs, and the correction path. A control that exists only in training slides is difficult to audit and easy to bypass. For prior-authorization measurement and transparency, this control should be testable with real case records rather than inferred from policy language alone.

Record how automated and human review interact

Record how automated and human review interact. System design should reinforce the rule rather than merely display it. Required fields, reason codes, version identifiers, and escalation paths can make the correct behavior easier while preserving room for individualized judgment. For prior-authorization measurement and transparency, this control should be testable with real case records rather than inferred from policy language alone.

Preserve formal appeal rights independently of informal reconsideration

Preserve formal appeal rights independently of informal reconsideration. Oversight should review both false positives and false negatives. A program that measures only whether it caught problems can become overinclusive; a program that measures only speed can become superficial. For prior-authorization measurement and transparency, this control should be testable with real case records rather than inferred from policy language alone.

Measure reversals and root causes rather than only gross denial counts

Measure reversals and root causes rather than only gross denial counts. Vendor contracts should preserve the organization’s ability to audit source data, logic, turnaround, corrections, and security. Outsourcing a function does not erase the need for accountable governance. For prior-authorization measurement and transparency, this control should be testable with real case records rather than inferred from policy language alone.

Design urgent pathways around clinical risk rather than queue order

Design urgent pathways around clinical risk rather than queue order. Changes should be versioned with effective dates and communicated to users before implementation. Otherwise a later reviewer cannot know which rule or configuration produced a prior result. For prior-authorization measurement and transparency, this control should be testable with real case records rather than inferred from policy language alone.

Treat policy changes as versioned rules with effective dates and audit trails

Treat policy changes as versioned rules with effective dates and audit trails. Correction is part of governance, not an exception to it. The organization should know how to amend its own record and which downstream recipients may need updated information. For prior-authorization measurement and transparency, this control should be testable with real case records rather than inferred from policy language alone.

Applied scenarios

Scenario 1: Testing the boundary between cms-0057-f requires annual public reporting and approval percentages require a denominator

A health organization receives a case in which cms-0057-f requires annual public reporting and approval percentages require a denominator appear to point in different directions. The analysis should not begin with a preferred outcome. It should begin with the source rules: Impacted payers must publicly post specified aggregate prior-authorization metrics for the prior calendar year; the first reporting for 2025 data was due in 2026. A percentage is interpretable only if readers know which completed requests are included and how withdrawn, duplicate, incomplete, or pending requests are handled. The limiting points are equally important: The requirement creates comparability only within the definitions CMS specifies. Journalists should not compare percentages across organizations without checking definitions.

A sound resolution in prior-authorization measurement would identify the actor responsible for deciding whether the requested item or service satisfies the applicable coverage and utilization-management rules for the particular patient and plan, document the evidence available on the relevant date, and state whether the second issue changes the first conclusion or merely adds context. The scenario illustrates why the authorization request, coverage criteria, clinical documentation, reviewer rationale, decision notice, and appeal record should remain available for audit. It also shows why a correction mechanism is essential when later information changes a premise without erasing the historical event.

Scenario 2: Testing the boundary between appeal approvals can affect totals and decision time should not be reduced to a single average

A downstream reviewer sees a status generated from appeal approvals can affect totals, but the underlying record also contains facts relevant to decision time should not be reduced to a single average. The analysis should not begin with a preferred outcome. It should begin with the source rules: CMS guidance explains that approved prior-authorization requests include requests approved after appeal for the relevant metric. CMS requires specified timing metrics, but operational reporting should also examine distributions and urgent versus standard requests. The limiting points are equally important: A plan with more initial denials can therefore produce a superficially similar final approval rate to a plan that approves appropriately at first review. Averages can hide long-tail delays affecting a smaller group of patients.

Scenario 3: Testing the boundary between service mix changes apparent performance and public metrics do not directly prove clinical appropriateness

A system update changes how service mix changes apparent performance is represented while an older decision based on public metrics do not directly prove clinical appropriateness remains in a downstream record. The analysis should not begin with a preferred outcome. It should begin with the source rules: Plans covering different populations and service categories may face different authorization volumes and complexity. A low denial rate can reflect good policy or permissive criteria; a high denial rate can reflect restrictive policy, inappropriate submissions, or service mix. The limiting points are equally important: Raw cross-plan rankings can be misleading without case-mix and product context. Performance evaluation requires both quantitative data and review of reasons and outcomes.

Scenario 4: Testing the boundary between 2026 proposed rules would add more metrics and machine-readable reporting would improve research

A physician or organization challenges an adverse result by pointing to the distinction between 2026 proposed rules would add more metrics and machine-readable reporting would improve research. The analysis should not begin with a preferred outcome. It should begin with the source rules: CMS proposed additional prior-authorization and API metrics in CMS-0062-P. Structured historical data, methodology notes, and archived prior-year reports would make trend analysis more reliable. The limiting points are equally important: Those additions remain proposals until finalized. Transparency should include version control rather than replacing old reports silently.

Questions decision-makers should ask

  • What is the exact statute, regulation, contract, technical specification, bylaw, or policy that authorizes the relevant step in prior-authorization measurement and transparency?
  • Which actor is making the consequential decision, and which actors are only transmitting or verifying information?
  • What facts trigger the rule, and which facts are merely contextual?
  • Is the cited source current law, a final rule with a future compliance date, proposed policy, guidance, or a private standard?
  • What date matters, and is the record using the version that actually applied on that date?
  • What exception or limiting condition would change the result?
  • What primary record would resolve a conflict between two databases or status fields?
  • How can an affected person submit contrary evidence or correct an identity or factual mismatch?
  • If automation is involved, what does the system decide, what does it recommend, and which human can override it?
  • What downstream systems or organizations receive the result, and how will a later correction propagate?
  • Which metrics reveal error and reversal, not merely volume and speed?
  • Does the public-facing explanation distinguish allegation, process, administrative status, and final adjudication?

What the evidence does not establish

An authorization is not a guarantee that a later claim will be paid

An authorization is not a guarantee that a later claim will be paid; eligibility, coding, network status, and other claim conditions can remain relevant. In prior-authorization measurement and transparency, the appropriate conclusion depends on the precise authority, the role of the decision-maker, and the complete record. A publication should state the narrower proposition and identify any additional fact that would be required for a stronger claim.

A denial is not a clinical diagnosis and does not by itself prove that the requested care is medically inappropriate

A denial is not a clinical diagnosis and does not by itself prove that the requested care is medically inappropriate. In prior-authorization measurement and transparency, the appropriate conclusion depends on the precise authority, the role of the decision-maker, and the complete record. A publication should state the narrower proposition and identify any additional fact that would be required for a stronger claim.

A fast decision is not necessarily a correct decision, and a slow decision is not necessarily unlawful without identifying the governing timeframe and its trigger

A fast decision is not necessarily a correct decision, and a slow decision is not necessarily unlawful without identifying the governing timeframe and its trigger. In prior-authorization measurement and transparency, the appropriate conclusion depends on the precise authority, the role of the decision-maker, and the complete record. A publication should state the narrower proposition and identify any additional fact that would be required for a stronger claim.

Policy implications

The strongest reform agenda for prior-authorization measurement and transparency is not to eliminate review or to maximize frictionless automation. It is to make the relevant judgment more accurate, visible, and correctable. That means clear legal triggers, current source data, proportionate information collection, qualified human judgment where judgment is required, documented reasons, explicit deadlines, and a durable correction trail.

For institutions evaluating prior-authorization measurement and transparency, the practical test is whether an independent reviewer can reconstruct the path from source evidence to consequence. For physicians and other affected professionals, the test is whether the process identifies the actual authority and provides a realistic method to correct error. For policymakers and journalists, the test is whether public metrics and status labels preserve the distinctions necessary to avoid misleading conclusions.

The larger principle is that institutional reliability depends on more than a correct rule. It depends on applying that rule to the right person, the right facts, and the right moment in time. In prior-authorization measurement and transparency, that principle requires the source, actor, date, and downstream consequence to remain distinguishable. The operational framework is therefore both a substantive policy issue and an information-governance issue.

Reading prior-authorization metrics as policy evidence

Public reporting becomes useful only when the metric preserves the decision pathway that produced it. An approval rate that combines initial approvals, approvals after additional documentation, approvals after reconsideration, and approvals after formal appeal can answer a broad question about eventual access, but it cannot answer why the first decision occurred. Conversely, an initial-denial rate without the eventual disposition can exaggerate the practical consequence of a reversible documentation problem. A credible reporting system should therefore preserve both the first decision and the final disposition, linked by a common request identifier or an equivalent auditable method.

Time metrics require the same discipline. An average decision time can improve even while a small group of patients experiences very long delays. For policy evaluation, median time, upper-percentile time, and the share of cases approaching or exceeding the governing deadline are more informative than a single average. Urgent and standard requests should be reported separately because their legal timeframes and clinical consequences differ. Requests for additional information should also remain visible rather than disappearing from the denominator, because repeated information requests can be a major source of administrative burden even when the eventual decision is an approval.

The CMS public-reporting requirements create a national baseline, but they should not be mistaken for a complete measure of clinical appropriateness. A high approval rate can coexist with unnecessary paperwork if nearly every request ultimately succeeds only after repeated submissions. A low denial rate can also conceal access problems if clinicians avoid requesting services they expect will be denied. The opposite inference is equally unsafe: a higher denial rate does not by itself demonstrate improper utilization management if the service mix, benefit design, or submission quality differs materially. Comparisons should therefore disclose product type, service categories, urgency, and any major change in criteria or workflow during the measurement period.

California's reporting reforms create another useful lesson: the purpose of measurement is not merely publication but policy feedback. When a jurisdiction uses reported data to identify services with consistently high approval rates, the next question is whether prior authorization continues to add enough value to justify the burden. That analysis should look beyond gross approval percentage. It should examine whether the authorization step changes care, prevents clinically inappropriate use, detects benefit exclusions, or mainly delays services that are almost always approved. Removal of low-value authorization requirements is a policy judgment, not an automatic mathematical consequence of a threshold.

Journalists and researchers should also treat vendor-generated dashboards cautiously. A payer may use several utilization-management vendors, delegated medical groups, pharmacy-benefit arrangements, or plan products. Unless the denominator follows the same organizational boundaries as the numerator, a dashboard can create an apparently precise but incomplete picture. Methodology notes should identify who supplied the data, which requests were excluded, how withdrawn or duplicate requests were treated, and whether decisions by delegated entities were included.

Finally, public reporting should make correction possible. If a payer discovers that a coding change or extraction error altered a published rate, the corrected value should not silently overwrite the historical number. A transparent correction notice should identify the affected period, the reason for revision, and whether policy conclusions based on the original data remain valid. Prior-authorization metrics are most valuable when they function as an auditable public record rather than a promotional scorecard.

A minimum methodology note for every public prior-authorization dashboard

A public dashboard should publish its counting rules alongside the numbers. At minimum, readers should be able to determine what constitutes one request, whether resubmissions are linked to the original request, how duplicates and withdrawals are treated, whether delegated entities are included, and which product lines are represented. The reporting period should also identify major changes in benefit design, authorization criteria, vendor contracts, or electronic workflow that could affect comparability with earlier periods.

Decision-time reporting should identify the start and end points used by the measure. If the legal clock begins when the plan receives the information necessary to make a decision, a separate patient-experience measure can still begin at first submission. Publishing both can reveal whether delay occurs before completeness or during payer review. The methodology should also say how weekends, holidays, extensions, and urgent classifications are handled.

For approval and denial rates, the denominator should remain visible. A percentage without the number of requests can make a small service category look equivalent to a high-volume category. When data are suppressed for privacy or statistical reliability, the dashboard should say so rather than leaving the reader to assume that no requests occurred. Changes to historical data should carry correction notes with dates and reasons.

These practices make the dashboard more useful to regulators, clinicians, journalists, and plans themselves. The purpose is not to create one league table of “good” and “bad” payers. It is to produce evidence that can support questions about burden, access, consistency, and whether particular authorization requirements continue to justify their cost.

Sources and Authorities

Each source below was audited against the official publisher on August 9, 2026. Laws, proposed rules, and agency pages change; time-sensitive requirements should be checked against the current official source.

CMS — Interoperability and Prior Authorization Final Rule (CMS-0057-F)

CMS — Prior Authorization API FAQ

CMS — APIs, Standards, and Implementation Guides

CMS — 2026 Interoperability Standards and Prior Authorization for Drugs Proposed Rule

California Health & Safety Code § 1367.01

California SB 306 — Prior Authorization Reporting

Related Articles

Educational information notice: this article provides general educational information for physicians, medical staff, and policy audiences and is not legal or medical advice. It does not create an attorney-client or physician-patient relationship. Statutes, regulations, proposed rules, and agency guidance change; individual matters require qualified counsel.

Approved for publication by Kanwar Partap Singh Gill, MD · Published August 10, 2026 · Law and policy current through August 9, 2026

You may be interested in

Pages that share this one’s legal or clinical territory, and a few that approach it from somewhere else entirely.

Or start from the whole collection: policy and regulation, patient education, what changed this week, or ask the library a question.