CO-197 means the payer has no record of a required authorization, precertification, or notification for the service. First find out whether an authorization actually existed. If it did, this is usually a claim data problem you can fix quickly. If it did not, your options are narrower: retro-authorization or an appeal.
1. What CO-197 means
- CO (Contractual Obligation): the provider is responsible. For in-network services, contracts usually bar billing the patient when the provider failed to get a required authorization.
- 197: precertification, authorization, notification, or pre-treatment absent.
2. CO-197 vs CO-15 vs CO-198
| Code | Meaning | Usual fix |
|---|---|---|
| CO-197 | No authorization on file | Find the auth; if none, request retro-auth or appeal. |
| CO-15 | Authorization number missing, invalid, or does not apply to the billed service or provider | Correct the auth number on the claim and resubmit. |
| CO-198 | Authorization exceeded, for example more visits or units than approved | Request an extension or appeal for the extra services. |
3. How to fix a CO-197 denial
- Search for the authorization in your records and the payer portal. Check dates, CPT codes, servicing provider, and location. A mismatch on any of these can produce a denial.
- If the auth exists, send a corrected claim with the authorization number (in the 837, the prior authorization reference in loop 2300). If it covered a different code or date range, ask the payer to update it.
- If no auth exists, ask whether the payer allows retroactive authorization. Many allow it in limited cases, such as emergencies or when eligibility was not known at the time.
- Appeal when the service was urgent, when the payer's own records were wrong, or when authorization was not actually required for that code. Include the clinical notes and any call reference numbers.
- Watch the deadlines for corrected claims and appeals. See timely filing limits by payer.
4. How to prevent CO-197
- Check authorization requirements at scheduling by payer, plan, and CPT code, not at check-in.
- Tie the auth to the encounter so the number, dates, and approved codes flow onto the claim automatically.
- Track expiring authorizations and visit counts for ongoing care like therapy or infusions.
- Re-check when the plan changes after the authorization was approved.
Our prior authorization guide covers the full workflow.
5. What changes in 2026 and 2027
The CMS Interoperability and Prior Authorization final rule (CMS-0057-F) applies to Medicare Advantage, Medicaid, CHIP, and ACA marketplace plans. Starting in 2026, affected payers must send prior authorization decisions within 72 hours for expedited requests and 7 calendar days for standard requests, and give a specific reason for denials. Prior authorization APIs follow in 2027. Faster decisions help, but they do not remove the need to request authorization in the first place.
Related: CO-50, CO-16, and the full CARC and RARC codes list.
Or have us build the AI biller that works these denials for you.
Our AI Biller reads every remittance, sorts denials by cause, drafts the correction or appeal, and flags anything close to its filing deadline. Delivered in 30 days. Money back if it does not outperform your current process on three metrics you pick.
See the AI Biller →Frequently asked questions
Want to talk through your denial patterns?
A 30-minute call. Bring your top denial codes and the numbers you already track. No slides, no pitch.
Book a 30-minute consult →