Key Takeaways
- Reform is fixing prior authorization's process, faster decisions and APIs, while leaving the governance untouched. The proprietary, unaudited policy logic that generates denials is the root cause.
- Most commercially insured Americans sit in self-funded ERISA plans that state PA laws cannot reach. Faster data exchange without reformed medical policy produces faster denials, not fewer.
- Guidelines are written in clinical language that does not map to the ICD-10 and CPT codes payers use. The evidence meant to define appropriate care becomes the instrument used to demand proof it was delivered.
- The pragmatic fix is to work backwards from revenue cycle. Every guideline and trial should ship a structured administrative crosswalk and advocate for new codes where none exist.
- Standardized PA metrics across all lines of business would make the aggregate burden visible without waiting for FHIR. It is a politically achievable ask the reform community has not made.
- MedTech that sells AI as capital equipment with no reimbursement and UM strategy loses. The winners design the coverage pathway before the product.
Prior authorization reform has a process problem and a governance problem. Washington is solving the process problem. Nobody is solving the governance problem. That distinction matters enormously for anyone trying to predict where this ends up.
The current reform moment is real. The CMS Prior Authorization Final Rule, FHIR-based API mandates, state legislation, and industry pledges to approve 80 percent of requests in real time represent meaningful pressure on a system that has imposed enormous and largely unaccountable administrative burden on providers and patients for decades. The momentum is genuine. The framing, however, is wrong, and wrong framing produces solutions that address the surface of the problem while leaving the root cause intact.
The governance layer nobody enforces
Prior authorization is the most visible instrument of utilization management, not the only one. Step therapy, quantity limits, site-of-service rules, and concurrent and retrospective review run on the same proprietary policy logic, and the governance problem described here applies across all of them. The broader UM landscape is mapped in Utilization Management and Prior Auth.
The prior authorization system is not primarily a technology problem or a process problem. It is a governance problem, specifically a governance problem with no meaningful enforcement mechanism for the population where the burden is heaviest.
State legislation is jurisdictionally constrained in ways that most reform advocates understate. The coverage and scope of any PA reform law depends entirely on the type of plan involved, and most commercially insured Americans are in plans that remain beyond state reach.
| Plan type | Who governs it |
|---|---|
| Fully insured commercial | State law where the plan is domiciled, not where the member lives |
| ACA plan | State law where both the plan and the member reside |
| Self-funded commercial (ASO) | Federal ERISA regulation, effectively insulated from state PA reform |
| Medicaid | Both state and federal regulation under CMS and HHS |
| Medicare and Medicare Advantage | Federal regulation under CMS and HHS, with limited state authority |
The most aggressive state PA reform laws, the ones with teeth around timelines, appeal rights, and clinical review requirements, cover a minority of the commercially insured population. The people most likely to experience PA burden in a commercial context are often the least likely to benefit from state legislative action.
Federal interoperability efforts are better designed but similarly constrained in what they can accomplish. The FHIR-based prior authorization API mandates for Medicare Advantage and Medicaid will improve data exchange and potentially reduce decision timelines for those populations. What they will not do is change the underlying business rules that generate denials in the first place.
Faster data exchange without reformed medical policy logic produces faster denials, not fewer. The CMS interoperability mandate addresses the plumbing. The problem is in the policy.
The policy lives in a black box. Payer medical policy and PBM pharmacy policy are proprietary documents, inconsistently applied across lines of business, and rarely reconciled against each other at the total cost of care level. The economic accountability gap between medical benefits and pharmacy benefits is where enormous clinical and financial value disappears. Care decisions that optimize one bucket create cost in the other, and the system has no mechanism to hold anyone accountable for the combined outcome. The business rules that govern prior authorization decisions are not public, not standardized, and not subject to meaningful external audit. That is not an operational detail. It is the root of the problem.
The scale of this problem is not abstract. As of 2025, more than 1,155 health insurers filed with the NAIC, each maintaining proprietary medical policies that are individually constructed, inconsistently standardized, and subject to change without public notice. Roughly 66 PBM companies operate in the US pharmacy benefit market, with three of them controlling about 80 percent of all prescription claims, each maintaining its own formularies, pharmacy policies, and step therapy requirements that operate largely independently of the medical benefit. Layered on top of both are the benefit products themselves. Analysis of more than 76,000 employer benefit plans reflects a market where 67 percent of covered workers are enrolled in self-funded arrangements, each plan carrying its own benefit design, cost-sharing structure, and coverage exclusions negotiated independently by the employer.
Even CMS, which operates the most structured coverage framework in the system, reflects this fragmentation. Where a National Coverage Determination exists, it provides a single federal standard. Where one does not, which is the majority of clinical situations, each regional Medicare Administrative Contractor issues its own Local Coverage Determination, producing materially different coverage logic for the same clinical intervention depending solely on geography. The collision of medical policy, pharmacy policy, benefit design, and regionally variable government coverage logic produces a combinatorial explosion of coverage determination variance that no single stakeholder fully controls, no regulatory body fully sees, and no provider can reliably predict before care is delivered. The prior authorization system does not operate on top of this complexity. It emerges from it.
Some have raised questions about payer agency in medical necessity determinations, given that payers lack the requisite patient-provider relationship to make treatment decisions. The standard defense is that payers are simply determining whether care will be covered under the member's benefits, not directing clinical care. It is a distinction that grows thinner every year and deserves far more regulatory scrutiny than it currently receives.
How evidence gets weaponized, and why the research community is complicit
The life sciences industry, clinical researchers, and professional societies bear more responsibility for the prior authorization crisis than they publicly acknowledge. Not simply because they fail to advocate loudly enough against it. The more uncomfortable truth is structural.
Clinical evidence and guidelines are almost universally written without consideration for how a payer's actuary team will evaluate them against administrative claims data or how the payer or PBM will eventually operationalize them. Inclusion and exclusion criteria in landmark trials are defined in clinical language, ejection fraction thresholds, biomarker levels, symptom severity scales, functional classification scores, cancer staging. These are the right criteria for defining who benefits from an intervention. They are almost never defined in a way that maps cleanly to the administrative data sets, the ICD-10, CPT, and revenue codes, that payers use to identify populations and make coverage decisions. Some could argue the data asymmetry is now so significant that the system has outgrown the ICD-10, CPT, and HCPCS framework. Regardless of the long-term path, collaborative work to advance data standards and ontologies is urgently needed.
In the absence of that work, the consequence is predictable and largely avoidable. When a payer medical policy team implements a coverage policy based on a clinical guideline, it faces a translation problem with no authoritative answer. The guideline says one thing in clinical language. The claims system speaks a different language entirely. Payer teams then do one of two things. They build their own value sets using internal clinical resources or third-party vendors and their own editorial art, or they require administrative documentation burden as a proxy for clinical criteria they cannot verify from claims data alone.
Both responses are rational from the payer's perspective. Both create friction the guideline authors never intended and rarely acknowledge. And both represent a quiet transfer of power.
The evidence that was supposed to define appropriate care becomes the instrument used to require proof that appropriate care was delivered. The payer is not ignoring the evidence. It is weaponizing it.
The NYHA classification is the most instructive historical example of how badly this can go. The New York Heart Association functional classification, Class I through IV, appears in virtually every major heart failure guideline. It drives treatment decisions, risk stratification, and device eligibility across clinical practice. It is also entirely subjective, entirely clinician-assessed, and entirely absent from administrative data. There is no ICD-10 code for NYHA Class. There is no claims field where a provider documents functional classification. It exists in clinical notes, in registry data, in physician judgment, and nowhere that a payer actuary can systematically access, audit, or apply to program design.
The result is that payers building UM policies around heart failure interventions that reference NYHA criteria must either accept clinician attestation at face value, require additional documentation that creates burden, or develop proxy criteria using diagnosis codes and procedure history that approximate NYHA class without capturing it accurately. All three options create friction. None of them are the payer's fault. The fault belongs to decades of guideline development that treated administrative operationalizability as someone else's problem.
The latest example is the 2026 AHA, ACC, ADA, and ASN guideline for cardiovascular-kidney-metabolic syndrome. It is remarkable evidence guidance addressing a large and growing problem, delivered without any framework to represent it administratively. There are no ICD-10 codes from the CMS and CDC ICD-10 Maintenance Committee or the World Health Organization to represent CKM syndrome as a disease. It cannot be represented in claims data, economically projected, or designed for under insurance benefits. The payer is left with essentially one option, require individualized documentation for every patient, procedure, and treatment justified on CKM guidelines. The guidelines exist in a clinical vacuum.
Heart failure staging offers a parallel example. The universal definition of HF stages A through D is clinically meaningful and well established. Claims data reflect only stages C and D, roughly 3 percent of the actual HF population. Stages A and B, where prevention and early intervention are most effective and most cost-efficient, are essentially invisible to payers and providers alike when operating on administrative data. This is the same blind spot developed at length in Heart Failure's Stage A and B Blind Spot and in What PREVENT Prevents.
The pattern is not confined to cardiology. Cancer staging tells the same story. The TNM system that drives oncology treatment and trial eligibility lives in registries and pathology reports, not in the ICD-10 claims a payer adjudicates, so stage-based coverage runs on the same proxies and documentation demands. Valve disease is another. The severity grade that decides whether a patient qualifies for valve replacement, mild, moderate, or severe, is not a coded field, even though the intervention hinges on it. The instructive counterexample is chronic kidney disease. CKD stages one through five were written into ICD-10 as discrete codes, which is precisely why CKD population management and value-based nephrology programs are buildable in a way heart failure prevention is not. The difference is not clinical importance. It is whether someone did the work to make the construct administratively real.
These are not data problems. They are guideline-to-policy translation problems that professional organizations have the power to fix and have not prioritized fixing.
The case for working backwards from revenue cycle
The instinctive response to the translation gap is to point toward FHIR-based clinical data exchange as the long-term solution. If payers could access clinical data directly, ejection fractions, biomarker results, staging criteria, through TEFCA-enabled exchange, the reliance on administrative approximations would diminish and the data asymmetry would close.
That future is real and worth building toward. But reimbursement and economics are a long way from being FHIR-enabled at the granularity required to close this gap in practice. Waiting for FHIR infrastructure to mature before addressing the guideline-to-administrative-data translation problem is the wrong sequencing. It defers a solvable problem into a future that is further away than reform advocates suggest. The more pragmatic path is to work backwards from revenue cycle now, while FHIR infrastructure develops in parallel.
What that means concretely. When a professional society or research team designs the inclusion and exclusion criteria for a landmark trial or a clinical practice guideline, the final step before publication should be a structured administrative crosswalk. That is a formal mapping of every clinical criterion to its closest ICD-10, CPT, HCPCS, or revenue code equivalent, with explicit acknowledgment of where no administrative analog exists. Where gaps exist, the society should either advocate for new code creation, as should have happened with CKM syndrome before the guidelines published, or provide explicit guidance on acceptable documentation alternatives that payers can build into their UM policies without improvising.
This is not asking clinical researchers to become billing coders. It is asking them to acknowledge that an actuary sits at the end of the evidence pipeline, and that actuary's ability to apply the evidence accurately determines whether patients receive the care the evidence supports. Shaping evidence with that constraint in mind is not a compromise of clinical rigor. It is a completion of it.
In practice, this means accounting for administrative operationalizability in trial design itself. Define included and excluded populations first using administrative data ontologies, and add them as a structured appendix to the study. Consider deliberately any clinical qualifier that may not be part of revenue cycle exchange. Ask whether it is needed for clinical validity or evidence demonstration, and whether its absence from administrative data will predictably become the hook payers use to require documentation burden. Designing around that asymmetry before publication is far less costly than correcting it after a UM policy has already been built around it.
What standardized PA metrics could actually do
There is a second lever available that requires neither FHIR maturity nor federal legislative action, standardized prior authorization metrics across lines of business.
Currently, PA performance data is fragmented by payer, by line of business, by benefit type, by state, and by reporting requirement. The result is that nobody has a reliable picture of the system's aggregate burden. Advocacy organizations cite studies. Payers cite different studies. CMS cites encounter data that covers only a portion of the commercially insured population. The policy conversation is built on incomplete and incomparable evidence.
If prior authorization metrics were standardized across commercial fully insured, self-funded ERISA, Medicare Advantage, and Medicaid lines of business, the aggregate data would reveal the burden in ways current fragmented reporting cannot. Standardized metrics would inform better policy and governance regardless of interoperability capability. This is a lever that does not require FHIR adoption to yield insight. Even with API-forward mandates, many providers remain capital-constrained and continue to use payer or PBM portals as their primary interface. Measurement transparency does not depend on interoperability maturity.
| Metric | Why it matters |
|---|---|
| Approval rates by condition and procedure | Shows where policy actually restricts care rather than where volume happens to be |
| Denial rates with reason coding | Separates clinical denials from administrative and documentation denials |
| Time-to-decision distributions | Moves the conversation past averages to the tail where harm occurs |
| Appeal rates and outcomes | A high overturn rate signals a policy problem, not a provider problem |
| Burden hours by provider type | Quantifies the administrative cost the system currently treats as free |
| Downstream clinical outcome linkage | Connects a coverage decision to what happened to the patient |
None of this requires new technology infrastructure. It requires a federal mandate for uniform PA reporting across all lines of business, establishing the foundation for CMS, ERISA, and state regulatory alignment. That is a politically achievable ask. It is also one the reform community has largely not made, because the focus has been on process speed rather than measurement transparency. The transparency case is developed further in Prior Authorization Transparency.
The MedTech and life sciences blind spot
There is a third stakeholder group that understands this problem inadequately and suffers for it commercially, medical technology companies whose devices are often sold as capital equipment while they build heavily in regulated AI.
MedTech companies invest significantly in regulated AI and consistently underinvest in understanding revenue cycle management, prior authorization, and market access fundamentals. The commercialization model that dominates the sector, selling AI-enabled diagnostic capabilities as a feature bundled into capital equipment, is built on a business logic that made sense when hospitals had capital budgets and technology-enabled care was a differentiator. Neither of those conditions reliably holds anymore.
What MedTech often underappreciates is that payer UM governs the payment and use of their equipment under the guise of medical necessity. If the payer determines that high-cost imaging can only be covered on certain clinical indications or after lower-cost prior testing, then the technology itself becomes a cost that requires justification before it is authorized. Conversely, if a new AI platform can detect certain attributes and keep the provider in the clinical loop, those attested structured outputs can become the hook that supports accelerated payer approval for the next step in testing or management.
The AI can be a solution to the UM problem, or it can be its victim. Which outcome occurs depends entirely on how deliberately the evidence and commercial strategy were built.
MedTech companies also fund and deliver clinical trials to generate the evidence required for FDA clearance and market entry. But the patients they include or exclude, and the endpoints they gather, rarely map cleanly to payer claims data. The result is that Appropriate Use Criteria and payer medical policy fill the vacuum. Payers define coverage themselves based on whatever administrative data is available, deny where they find inadequate evidence in the form they can operationalize, and leave the remainder to appeals, peer-to-peer reviews, and heavy administrative burden on the provider. The evidence was designed to satisfy a regulatory standard. The payer is trying to apply a reimbursement standard. Those two standards are not the same, and MedTech rarely plans for the gap between them. The same pattern in point-of-care ultrasound is traced in AI-Guided POCUS Has a Market Access Problem.
The result is that AI clinical value exists in the product but cannot be accessed by the reimbursement system. The device and its AI become costs to the provider and health system, too often without the HEOR evidence base needed to defend the value proposition, pursue provider-level reimbursement, or offset the cost of adoption. Without that reimbursement architecture, adoption stays anchored to capital budgets that are under pressure.
The companies that will win in AI-enabled diagnostics are not those with the best algorithms. They are those that understand both clinical and economic requirements, including UM controls and reimbursability, as product-market fit for the buyer that actually controls adoption, the payer, the CFO, and the value analysis committee. If the reimbursement pathway is not designed before the product is designed, the product will not scale, regardless of its clinical merit.
What actually changes the trajectory
The prior authorization problem will not be solved by any single intervention. FHIR mandates help at the margins of a specific population. State laws help for a subset of the commercially insured. AI automation speeds a broken process without reforming the underlying policy logic. Each of these is real progress. None of them is sufficient. What changes the trajectory is four things working together.
| Stakeholder | The change required |
|---|---|
| Professional organizations | Translate clinical standards into administrative-data-ready specifications. Build crosswalks from clinical criteria to ICD-10 and CPT, advocate for new codes where gaps exist, and treat economic operationalizability as a design requirement rather than an afterthought. |
| Life sciences and trial sponsors | Design evidence with administrative operationalizability built in from day one. Map inclusion and exclusion criteria to codes in the protocol, engage payer actuaries during guideline development, and advocate for new codes when a clinical construct has no administrative representation. |
| Payers | Publish and standardize the metrics of their PA programs across lines of business, making the aggregate burden visible and measurable enough to enable accountability rather than perpetual anecdote. |
| Federal governance | Treat payer medical policy as a regulated instrument with transparency and consistency requirements, rather than a proprietary trade secret that can be constructed, applied, and revised without external accountability. |
None of these are happening at sufficient scale today. All are achievable. The governance gap is not a permanent feature of the system. It is a choice, made implicitly, every time a guideline publishes without an administrative crosswalk, every time a payer constructs a UM policy without disclosing its logic, and every time a reform conversation focuses on process speed rather than policy accountability.
The puzzle is solvable. The question is which stakeholders have the standing and the incentive to lead, and whether they will act before the next cycle of legislative momentum fades into another round of incremental progress that leaves the root problem intact.
Frequently asked questions
What is the difference between prior authorization's process problem and its governance problem?
The process problem is speed and friction, how long a decision takes and how much paperwork it requires. The governance problem is the underlying policy logic that generates denials in the first place, which is proprietary, inconsistently applied, and not subject to external audit. Current reform is fixing the process and leaving the governance untouched.
Why can't state prior authorization laws fix the problem for most people?
Coverage depends on plan type. The most aggressive state PA laws reach fully insured and ACA plans, but most commercially insured Americans are in self-funded ERISA plans that federal law insulates from state reform. The people most likely to face PA burden are often the least likely to benefit from state action.
Will FHIR APIs and the CMS interoperability rule reduce denials?
They will speed data exchange for Medicare Advantage and Medicaid, but they do not change the business rules that generate denials. Faster data exchange without reformed medical policy logic produces faster denials, not fewer. The mandate addresses the plumbing while the problem sits in the policy.
How does clinical evidence get weaponized in prior authorization?
Guidelines are written in clinical language such as NYHA class, ejection fraction, or CKM syndrome that does not map to the ICD-10 and CPT codes payers use. Without a crosswalk, payers build their own proxy criteria or demand documentation as proof, and the evidence meant to define appropriate care becomes the instrument used to require proof that it was delivered.
What is an administrative crosswalk and who should build it?
It is a structured mapping of every clinical criterion in a guideline or trial to its closest ICD-10, CPT, HCPCS, or revenue code equivalent, with explicit notes where no analog exists. Professional societies and trial sponsors should build it as the final step before publication, and advocate for new codes where gaps exist.
What would standardized prior authorization metrics accomplish?
Standardizing PA metrics across commercial fully insured, self-funded ERISA, Medicare Advantage, and Medicaid would make the aggregate burden visible and comparable, which today it is not. It requires a federal reporting mandate rather than new technology, and it does not depend on FHIR maturity.
Why is prior authorization a MedTech and life sciences problem?
Payer utilization management governs whether a device or AI capability gets paid for under medical necessity. Evidence built for FDA clearance rarely maps to payer claims data, so coverage stalls. The companies that win design the reimbursement and UM pathway before the product, not after.
This piece is analysis and commentary based on public sources and professional experience as of the date noted, and nothing in it constitutes legal, clinical, or financial advice. Figures on insurer, PBM, and self-funded plan counts reflect NAIC filings, pharmacy benefit market analyses, and published employer benefit surveys, and coverage-governance characterizations are general descriptions of common industry structures rather than statements about any specific company or plan. Interpretive conclusions are the author's opinion. All views reflect independent professional judgment and do not represent the views or positions of any current or former employer or affiliated organization.