CMS Interoperability and Prior Authorization Rule (CMS-0057-F)

    What is the CMS Interoperability and Prior Authorization Rule?

    The CMS Interoperability and Prior Authorization Rule (CMS-0057-F), finalized in 2024, is the current federal mandate designed to modernize healthcare by speeding up prior authorizations and improving how your health data is shared between plans and doctors.

    This rule builds upon the foundation established by the original CMS Interoperability and Patient Access Rule (CMS-9115-F), which was introduced in 2020 to give patients their introduced standardized electronic access to their personal health information. Under the new CMS-0057-F guidelines, you may have greater control over how certain health information is shared, expanded electronic access to health information, and more timely prior authorization decisions. 

    The updated rule requires certain health plans to: 

    • Provide patients with electronic access to their health information 
    • Improve how health data is shared between patients, providers, and payers 
    • Support electronic prior authorization workflows

    The goal is to reduce administrative burden, improve care coordination, and help ensure patients have more timely access to their health information and care decisions.

    The rule is part of the cross-agency MyHealth eData initiative started in 2018 to facilitate data-sharing across public payers and provider organizations.

    Who is it for?

    Users of Medicare Advantage (MA) plans, state Medicaid programs both fee-for service (FFS) and managed care, Children’s Health Insurance Plans (CHIP) including FFS and managed care, and Qualified Health Insurance Plan (QHP) in the health insurance exchanges established by the Affordable Care Act (ACA). Other commercial plans may adopt similar capabilities but are not required to do so under this rule.

    How will it work?

    CMS requires payers to use standardized FHIR‑based (Fast Healthcare Interoperability Resources) APIs to enable secure, real-time data exchange.

    By January 1, 2027, impacted payers must implement and have fully operational the following APIs:

    1. Patient Access API (Enhanced) - Allows members to access their health data through third-party apps of their choice, with their authorization, including: 

    • Claims and encounter data
    • Clinical data (USCDI)
    • Prior authorization status, decisions, and related information 

    2. Provider Access API (NEW) - Allows in-network providers to request access to patient data from payers to support care coordination, including:

    • Claims and encounter data
    • Clinical data
    • Prior authorization information

    Access is limited to in-network providers and is subject to patient opt-out and provider attribution requirements.

    3. Payer-to-Payer API (NEW) - Allows patient data, with member authorization, to be shared when switching health plans. With patient opt-in, payers must exchange:

    • Claims and encounter data
    • Clinical data
    • Prior authorization history (generally including up to 5 years of available data maintained by the payer)

    This supports continuity of care and reduces duplication.

    4. Prior Authorization API (NEW) - Supports a fully electronic prior authorization process that allows providers to:

    • Determine whether prior authorization is required
    • Retrieve documentation requirements
    • Submit authorization requests electronically
    • Receive structured responses (approved, denied, or additional information required)

    The Prior Authorization API supports an end-to-end electronic workflow, enabling more timely determination, submission, and status tracking. These standardized APIs are intended to reduce reliance on manual workflows such as phone, fax, and payer portals.

    Prior Authorization Improvements

    These APIs support CMS’s efforts to modernize prior authorization processes and are designed to reduce delays in care and improve transparency.

    Key requirements (effective beginning 2026)

    • Faster decision timeframe
              •  Urgent requests: within 72 hours
              •  Standard requests: within 7 calendar days
    • Specific denial reasons must be provided
    • Public reporting of prior authorization metrics
    • Applies to medical items/services (does not currently include outpatient prescription drugs)

    What you and your provider need to do?

    For Members: Your Health Information Guide

    This new rule gives you more control over your health data than ever before. Here is a guide to your new capabilities:

    1.  Access Your Data with an App of Your Choice

    This refers to the Patient Access API. You can use a third-party mobile app to see your health history, including claims, clinical data, and prior authorization status.

    A Note on Third-Party Apps and Your Privacy:

    When you connect a third-party app to your health record, your data may no longer be protected by HIPAA. Before using any app, we strongly encourage you to review its privacy policy and understand how your information will be used.

    2.  Connect Your Health History from Other Plans

    This refers to the Payer-to-Payer API. You can request to have certain information from previous or concurrent health plans, such as claims, clinical information, and prior authorization information, transferred to create a single, more complete view of your health journey.

    3.  Manage Your Consent Choices

    You can securely manage your preferences at any time in the "Account Management" section of your MyHighmark member portal. There you will find two key choices:

    • Connecting Your Health History: Give permission for us to request your data from other health plans.
    • Sharing with Your Doctors: Decide whether certain health information maintained by Highmark is made electronically available to your in-network doctors. By default, this is on to support your care, but you can opt-out at any time.

    For providers:

    Use integrated systems (EHR or connected applications) to: 

    • Check prior authorization requirements
    • Submit requests electronically
    • Track status updates and decisions 

    Why is CMS doing it? / Why is it important?

    CMS is advancing interoperability to:

    • Give patients greater access and control over their health information
    • Improve coordination between providers and health plans
    • Reduce administrative burden and inefficiencies
    • Accelerate care by improving prior authorization workflows

    CMS describes the intent of the API, “Consumers routinely perform many daily tasks on their mobile phones – banking, shopping, paying bills, scheduling – using secure applications. We believe that obtaining their health information should be just as easy, convenient, and user-friendly.” 

    Ultimately, the rule aims to make accessing and using health information as easy and secure as other digital services. 

    Highmark Privacy & Security Disclaimer:
    Highmark is strictly committed to protecting your privacy. All data sharing is conducted using secure, encrypted technology in full compliance with HIPAA and all applicable state regulations. Changing your consent preferences is voluntary and will not affect your health care coverage or benefits.

    App developers API support

    Developers can build secure applications that connect to payer systems using FHIR APIs to:

    • Enable patient access to data
    • Support provider workflows
    • Facilitate real-time prior authorization