HomeRevenue Leakage IntelligencePrior Authorization Automation
Revenue Leakage · Pillar

Prior Authorization Software: The 2026 Automation Playbook

By Wale Fawehinmi 13 min read Published September 12, 2026 Category: Revenue Leakage

Prior authorization is the single most detested administrative process in American healthcare and one of the largest sources of preventable revenue loss. The math is brutal: 12 hours per physician per week spent on auth work, 24 percent of auth requests initially denied, and 2 to 5 percent of gross revenue lost to services rendered on expired or missing authorizations that then deny with no path to recovery. Everything below is how prior authorization software addresses that pool, and where it does not.

The good news: 2026 changed the math. The CMS Interoperability and Prior Authorization Final Rule (CMS-0057-F) forced payers to publish FHIR APIs for auth submission, cut response SLAs to 7 days standard and 72 hours expedited, and made prior auth denial patterns publicly reportable for the first time. The category is being restructured in real time.

1. The revenue that dies on expired auths

12 hrs/wk
Physician hours per week lost to prior authorization work. Per AMA 2024 Prior Authorization Physician Survey.
24%
Initial denial rate on prior auth submissions. Per AMA 2024.
2 to 5%
Percent of gross revenue lost to services rendered on expired or missing authorizations, in typical specialty practice audits.

On a 20 provider orthopedics group at $18M gross revenue running a middle-of-the-band 3 percent auth-related revenue loss, that is $540,000 per year in dead claims. On a 300 bed community hospital with $600M gross, it is $18M. And unlike a denial that at least has an appeal path, most auth-related denials are terminal: if the auth was missing or expired at the time of service and the retroactive request is denied (which it usually is), the claim is dead. No appeal wins that fight.

What makes this category unique is that it is preventable at the visit-scheduling step. Every one of these lost claims had a moment where a system could have looked at the auth status and stopped the visit from happening the wrong way. Nobody looked. That is what prior authorization software is supposed to solve.

2. What prior authorization software actually does

Every product marketed as prior authorization software does some combination of these four things:

Function
What it does
Ubiquity
Requirement lookup
Given a payer, CPT, and place of service, tell you whether auth is required. Powered by scraped payer rules or manual rule libraries. Freshness varies wildly.
Universal
Request submission
Submit the auth request through the payer portal, FHIR API (post CMS-0057-F), or fax gateway. Fax still handles 30 to 40 percent of volume in 2026.
Universal
Auth storage and lookup
Store the auth number, effective date, visit count, and expiration against the patient chart so downstream visits can reference it.
Universal
Expiration and visit-count tracking
Watch every active auth in the panel and alert before it expires or runs out of visits. This is the one that determines whether the pool actually shrinks.
Variable

All four are necessary. The first three are table stakes and every serious vendor does them. The fourth is where the products diverge and where the revenue actually lives. If the auth tracking is reactive (front desk asks the system when scheduling), the pool stays big. If it is proactive (system watches every active auth continuously and alerts before expiration or count exhaustion), the pool shrinks.

3. CMS-0057-F and what changed on January 1, 2026

The CMS Interoperability and Prior Authorization Final Rule took effect January 1, 2026 for Medicare Advantage, Medicaid, CHIP, and Qualified Health Plans on the ACA exchanges. It is the biggest structural change to prior auth in a decade. Three requirements matter for anyone thinking about auth software:

Payer FHIR API mandate

Payers must expose a Prior Authorization API using HL7 FHIR standards. In practice this means auth submission via API is now available where it was not before, response times can be measured programmatically, and the third-party fax gateways that dominated the market pre-2026 are becoming a legacy layer.

Response-time SLAs

Standard prior auth decisions must be returned within 7 calendar days. Expedited requests within 72 hours. The clock is enforceable and published. Software that can measure and enforce these SLAs against payers has leverage the old generation of tools did not.

Public metrics reporting

Payers must publicly report annual prior auth metrics including approval rate, denial rate, appeal overturn rate, average response time, and requests by requested service. For the first time, practices can compare a payer's actual behavior against its promises, and payer-specific auth strategy becomes data-driven instead of anecdotal.

The strategic implication Pre-2026, prior auth software was a productivity tool. Post-2026, it is a compliance and enforcement tool. Any vendor still selling you a fax gateway wrapped in a modern UI is selling you the old category. The new category integrates with payer FHIR endpoints, tracks SLA compliance per payer, and uses the public metrics to route requests through the payers most likely to approve. If your prior auth vendor cannot answer questions about their FHIR integrations and SLA tracking, they are behind.

4. The 2026 vendor map

Vendor
Category and notes
Tier
Availity Essentials
Payer-provider clearinghouse network. Broadest payer connectivity. Strong on submission, weaker on proactive expiration monitoring.
Enterprise
Waystar Priority Auth
Integrated with the broader Waystar RCM stack. Good for shops already on Waystar. Add-on pricing.
Enterprise
Change Healthcare Assurance PA
Post-2024-breach reputation issue but still deployed widely. Deep clearinghouse footprint.
Enterprise
Experian Health Authorizations
Bundled with their eligibility and coverage discovery products. Strong for shops that want a single vendor for the front-end revenue cycle.
Enterprise
Cohere Health
AI-first entrant. Strong on musculoskeletal, cardiology, and oncology auth automation. Often sold through payer partnerships.
AI-first
Rhyme Health
AI-first. Auth submission plus proactive requirement detection. Strong on payer FHIR integrations post-2026.
AI-first
Basys AI
AI-first. Focused on real-time auth determination at the point of order.
AI-first
Epic, Cerner, athenahealth (native)
EHR-native modules. Best integration with the existing chart. Auth requirement lookups often less current than dedicated vendors.
Native

5. Where in-market software falls short

Even the best products in the vendor map above share three consistent gaps. These are the places most of the auth-related revenue loss actually happens.

Gap 1: Retroactive detection, not proactive prevention

Most tools tell you an auth was needed when the claim comes back denied. By then the service is rendered and the recovery window is basically zero. The tools that DO run proactive checks usually run them at scheduling time only, not continuously. If the auth expires between scheduling and visit (common in physical therapy, oncology, and mental health with multi-visit auths), the system does not know.

Gap 2: Requirement libraries lag payer changes

Payers change their auth requirements constantly. Adding a CPT to the auth list, removing a diagnosis code from the medical necessity criteria, tightening the visit count on a category. Software vendors update their rule libraries on a schedule that ranges from daily (best) to quarterly (worst). If your vendor updates monthly and your payer changed a rule two weeks ago, you have two weeks of encounters at risk before your system knows about the change.

Gap 3: The last-mile clinical judgment

Software submits the auth. It does not draft the medical necessity narrative that gets the auth approved on the first pass instead of denied and re-submitted. The 24 percent initial denial rate is largely a documentation-quality problem, and software does not solve documentation quality. A clinician or a well-trained coder still writes the narrative, and the difference between a 20-minute rejection and a 5-day approval is often one paragraph of language.

6. A four-step prior auth automation workflow

Independent of what vendor you pick, the operational workflow that closes the auth-related revenue leak has four steps.

Step 1: Continuous auth-requirement monitoring

Every 24 hours, cross-check every scheduled visit for the next 7 days against payer auth requirements. Not just at scheduling time. Continuously. If a payer changes an auth rule tomorrow, tomorrow's affected visits get flagged before the visit happens. This one change catches most of the payer-rule-drift losses.

Step 2: Auth-status watch on every active authorization

Every approved auth in the system gets a proactive watch: 30-day expiration alert, 14-day, 7-day, and a visit-count remaining alert at 3 visits, 1 visit, and 0 visits. Alerts route to a named owner (front desk lead, care coordinator, auth specialist) with a service-level agreement of same-day action. No auth quietly expires while nobody was looking.

Step 3: AI-drafted medical necessity narrative

When a new auth request needs to be filed, the AI drafts the medical necessity narrative from the chart, cites the relevant clinical documentation, matches the payer's specific medical policy criteria, and queues it for a human reviewer. The reviewer confirms and submits. Time-to-submit drops from 20 minutes to 5. First-pass approval rate climbs from 76 percent to something in the high 80s.

Step 4: SLA and pattern tracking against payer

Track every submitted auth against the payer's public-reported SLA (post CMS-0057-F). When a payer misses the 7-day SLA, escalate. Track denial patterns per payer per service line so the medical necessity narrative for high-denial patterns gets stronger over time. Feed the public reporting back into your payer strategy.

7. Where the auth burden is heaviest by specialty

  • Orthopedics. Joint injections, MRI, PT visit counts, surgical procedures. Multi-visit auths dominate. Expiration and count tracking is the big lever.
  • Oncology. Chemotherapy regimens, radiation therapy, high-cost drugs, imaging. Every regimen change often needs a new auth. Fastest ROI on AI-drafted narratives.
  • Cardiology. Diagnostic imaging (echo, stress, CT angio), procedural (cath, EP studies), device implants. Payer rules churn fast.
  • Gastroenterology. Endoscopy, colonoscopy, high-cost drugs (biologics for IBD). Colonoscopy screening rules changed multiple times in 2024-2026.
  • Imaging (radiology owned). High-cost MRI and CT. Auth requirements vary sharply by payer and by clinical scenario. Requirement lookup freshness is the top lever.
  • Physical and occupational therapy. Visit counts are everything. Expiration and count-remaining tracking is the workflow.
  • DME. Item-by-item auth is common. Documentation requirements are stringent. Denial rates are the highest of any category.
  • Mental health. Multi-visit outpatient auths, extended IOP and PHP episodes. Care coordination workflow matters as much as software.

8. Five metrics to instrument

  1. Auth-related denial rate. Percent of denied claims with CO-197 or equivalent auth-related codes. Trend line over time by payer.
  2. First-pass auth approval rate. Percent of submitted auths approved without re-submission. Target: 85 percent or higher. Under 75 percent means the medical necessity narrative needs work.
  3. Time-to-auth. Days from auth needed to auth received. Post CMS-0057-F, target under 7 days for standard, under 72 hours for expedited.
  4. Expired-auth visits prevented. Number of visits that would have been rendered on an expired auth but were caught and rescheduled or re-authed first. This is the pool measurement.
  5. Payer SLA compliance rate. Percent of payer responses returned within the CMS-0057-F SLA. Below 90 percent per payer is a payer to escalate with your provider-relations rep.

9. Where to start Monday morning

  1. Pull the trailing 90 days of denials. Filter to auth-related codes. Group by payer plus CPT. That gives you the top 10 patterns your existing process is missing.
  2. Audit your active auths. Pull a list of every currently active authorization in your PM system with days-to-expiration and visits remaining. Anything with less than 14 days or 2 visits gets a named owner and a same-day plan.
  3. Score your current auth software against the four functions in section 2. Where does it help? Where does it fall short? The gap analysis becomes your buy-or-build decision.
  4. For the top 2 payers by auth volume, verify their CMS-0057-F FHIR endpoint status. If they published the API and you are still submitting via fax gateway, you are leaving speed on the table.
  5. Build the proactive expiration alert workflow in whatever you have today. Even a nightly report emailed to the front desk lead reduces the pool. Do not wait for the perfect tool.

See what a custom AI biller would do for your auth workflow.

The four-step workflow in this pillar, continuous requirement monitoring, proactive expiration and count tracking, AI-drafted medical necessity narratives, SLA tracking against payer, is exactly what our AI Biller does. Delivered in 30 days. Lives inside your PM environment. Money back if it does not outperform your current process on three metrics you pick.

See the AI Biller →

10. Frequently asked questions

What does prior authorization software actually do?
Four things in most in-market products: requirement lookup (does this CPT for this payer need auth), request submission (portal, FHIR API, or fax gateway), auth storage (the number, dates, visit count), and expiration tracking. The first three are universal; the fourth is where products diverge and where the revenue actually lives.
How much revenue do practices actually lose to prior authorization problems?
The AMA 2024 Prior Authorization Physician Survey found practices spend 12 hours per physician per week on auth work, 24 percent of auth requests are initially denied, and 2 to 5 percent of gross revenue is lost to services rendered on expired or missing authorizations. On a $10M practice that is $200K to $500K per year in dead revenue.
What is CMS-0057-F and why does it matter for prior auth software in 2026?
The CMS Interoperability and Prior Authorization Final Rule (effective January 1, 2026) forces payers to publish FHIR APIs for auth submission, enforces 7-day standard and 72-hour expedited SLAs, and requires public reporting of annual auth metrics. Pre-2026 prior auth software was a productivity tool. Post-2026 it is a compliance and enforcement tool.
What is the difference between prior authorization software and an AI biller?
Prior authorization software focuses on the auth transaction: submit, receive, store. An AI biller expands the scope to the whole workflow: continuously watching scheduled visits for auth requirements, monitoring active auth expirations and visit counts across the panel, alerting the front desk before a visit gets rendered on an expired auth, and drafting medical necessity narratives that improve first-pass approval.
What are the top prior authorization software vendors in 2026?
Three tiers. Enterprise: Availity Essentials, Waystar Priority Auth, Change Healthcare Assurance PA, Experian Health Authorizations. EHR-native: Epic, Cerner Millennium, athenahealth. AI-first: Cohere Health, Rhyme Health, Basys AI. The right choice depends on integration depth, payer mix, and whether you want a transaction tool or a workflow that fits your operation.
Does prior authorization automation work for small practices or only for hospitals?
It works at any size. At hospital scale the ROI is labor reduction on a large auth team. At small practice scale (1 to 30 providers) the ROI is preventing denials on services already rendered plus cutting front-desk burden. A specialty practice with a heavy auth footprint (orthopedics, cardiology, oncology, GI, imaging, DME) often sees larger relative gains than a hospital.
What is the fastest way to reduce auth-related denials in 30 days?
Three moves: 1) Run a report of every CO-197 denial for the trailing 90 days, grouped by payer plus CPT. 2) Build a proactive expiration alert for every active auth with 30/14/7-day notifications routed to a named owner. 3) Add a pre-visit auth check into scheduling the night before every visit. Together these three cut auth-related denials by 40 to 60 percent inside a quarter.

Want to talk through this for your practice specifically?

A 30-minute call. Bring your top 3 auth-related payer names, the specialty mix on your book, and one place you suspect the auth workflow is dropping revenue. We will tell you what a first-cycle audit would surface, what a continuous automation workflow would look like for your PM system, and whether we are the right partner to build it. No slides, no pitch.

Book a 30-minute consult →