CMS Drug Prior Authorization Rule 2026: Provider Guide

CMS is continuing its push to modernize prior authorization, and prescription drugs are now a major part of that effort.

On April 10, 2026, the Centers for Medicare & Medicaid Services released the 2026 CMS Interoperability Standards and Prior Authorization for Drugs proposed rule, CMS-0062-P. The proposal would expand electronic prior authorization requirements to drugs, introduce or align decision timeframes for certain health plans, require more specific information when a drug authorization is denied, and make more prior authorization data available electronically.

For provider and revenue cycle teams, however, the most important point is that CMS-0062-P is still a proposed rule, not a final one. CMS closed the public comment period on June 15, 2026, and as of September 21, 2026, the agency still lists the rule as proposed.

That distinction is easy to miss because a separate set of CMS prior authorization requirements is already taking effect. Provider organizations are therefore operating in an unusual transition period: some changes are already mandatory in 2026, others begin in 2027, and the drug-specific requirements discussed in CMS-0062-P may still change before they are finalized.

Understanding which requirements belong in which category is essential for anyone making decisions about staffing, technology, workflow design, or prior authorization automation.

What is already changing in 2026?

Before looking at the new drug proposal, it helps to separate it from CMS’s earlier Interoperability and Prior Authorization Final Rule, CMS-0057-F, which was finalized in 2024.

CMS-0057-F primarily covers prior authorization for non-drug medical items and services. For many impacted payers, it established decision timeframes that began applying in 2026: generally no later than 72 hours for expedited requests and seven calendar days for standard requests, while still requiring payers to respond sooner when the patient’s clinical condition demands it.

Those finalized timeframes do not apply to drug prior authorizations, and Qualified Health Plan issuers on the Federally-facilitated Exchanges are excluded from those particular requirements.

The same final rule also requires impacted payers, beginning in 2026, to provide a specific reason when an applicable prior authorization request is denied. That requirement applies regardless of whether the request was submitted through an API, portal, fax, phone call, or another channel.

In practical terms, that means provider organizations are already seeing a shift toward more defined turnaround expectations and more actionable denial information for certain medical prior authorizations. The 2026 drug proposal would extend that broader modernization effort into an area that has historically involved its own mix of payer systems, pharmacy transactions, portals, and manual follow-up.

What CMS is proposing for drug prior authorization

CMS-0062-P addresses drugs covered under both the medical benefit and the pharmacy benefit, but it does not treat those workflows as identical.

For drugs covered under the medical benefit, CMS proposes requiring impacted payers to incorporate drug coverage and documentation requirements into their Prior Authorization APIs. The proposed compliance date is October 1, 2027.

If finalized, this would bring medical-benefit drugs into a framework similar to the one CMS has already established for non-drug medical services. Providers could have more standardized electronic access to information such as whether authorization is required, what documentation the payer needs, and the current status of a request.

For drugs covered through the pharmacy benefit, CMS is proposing a different technical pathway. Certain Medicaid, CHIP, and Federally-facilitated Exchange plans would be required to support standards developed by the National Council for Prescription Drug Programs, including NCPDP SCRIPT, NCPDP Formulary & Benefit, and NCPDP Real-Time Prescription Benefit. These standards are intended to support activities such as checking formulary information, retrieving real-time coverage details, and exchanging electronic prior authorization requests and decisions.

The proposed compliance date for those requirements is also October 1, 2027.

For RCM teams, the distinction is more than technical. “Drug prior authorization” can sound like a single workflow, but in practice, medical-benefit and pharmacy-benefit drugs often move through different systems, use different transactions, and involve different operational teams. Organizations that are preparing for greater automation should avoid designing a single generic process and assuming it will work equally well across both benefit structures.

Decision timeframes could become more standardized

CMS-0062-P also proposes changes to how quickly certain payers must respond to drug prior authorization requests.

This part of the proposal requires some nuance because there is not one universal drug prior authorization deadline that would apply to every payer and every medication.

For example, CMS proposes that Qualified Health Plan issuers on the Federally-facilitated Exchanges provide drug prior authorization decisions no later than 72 hours for standard requests and 24 hours for expedited requests, while still responding more quickly when the patient’s condition requires it.

Medicaid and CHIP requirements are more complicated because they interact with existing rules governing covered outpatient drugs and medical items and services. The applicable timeframe can therefore depend on the program, the payer, the benefit category, and the type of request.

For provider organizations, that makes blanket statements about a single “CMS prior authorization deadline” risky. A better operational approach is to preserve payer- and workflow-specific rules rather than assuming that every drug authorization should follow the same clock.

Denial information could become more useful

One of the more meaningful operational changes in CMS-0062-P is the proposal to require certain Medicaid, CHIP, and Federally-facilitated Exchange payers to provide providers with a specific reason for denying a drug prior authorization request beginning October 1, 2027.

That may sound like a relatively modest administrative change, but better denial information can have a large downstream impact.

A status of “denied” tells a team that something went wrong. It does not tell them what to do next. A specific denial reason can help determine whether the case needs additional clinical documentation, corrected administrative information, a different medication, a resubmission, an escalation, or an appeal.

That is particularly important in automated workflows. Automation is most valuable when it can turn a payer response into an actionable next step. If a system only retrieves a denial but cannot explain why the denial occurred, a human still has to investigate the case from the beginning.

More structured denial information could therefore make it easier for provider organizations to route work intelligently rather than treating every denial as the same type of problem.

More prior authorization information could become available electronically

The proposal would also expand the prior authorization information available through CMS interoperability APIs.

For drug prior authorizations, CMS proposes making information available such as authorization status, approval or denial dates, expiration information, the approved drug and dosage, specific denial reasons when applicable, and related administrative or clinical documentation submitted as part of the request.

That shift matters because the value of electronic prior authorization is not simply that a request moves through a digital channel. The larger benefit comes from making the response usable inside the provider’s workflow.

Consider a request that returns as “pending.” That status is only operationally useful if the team also knows when to check again, whether additional documentation is needed, and who owns the next step. An approval has limited value if the authorization number, effective dates, approved units, dosage, or other restrictions are not recorded correctly. A denial reason is most useful when it is captured in a structured field that can trigger the right follow-up.

This is where the conversation moves beyond interoperability standards and into actual revenue cycle operations. The question is not only whether information can be exchanged electronically, but whether that information arrives in a form that lets the organization move the case forward without creating another manual handoff.

CMS is also proposing more public reporting

CMS-0062-P would add new reporting requirements around drug prior authorization.

Under the proposal, impacted payers would begin publicly reporting certain drug prior authorization metrics in 2028 using data from the 2027 reporting period, with the specific timing and reporting level depending on payer type.

CMS is also proposing additional reporting related to use of the Provider Access, Payer-to-Payer, and Prior Authorization APIs.

Over time, this could give providers a clearer picture of how prior authorization performance differs across payer organizations. Instead of looking only at internal averages, RCM leaders may eventually have more external data to help identify whether a problem is specific to their own workflow or reflects a broader pattern with a particular payer.

Are payer portals and phone calls going away?

Probably not anytime soon.

CMS is clearly moving the industry toward more structured electronic exchange, but the reality of payer operations is still highly fragmented. Provider teams routinely work across APIs, EDI transactions, portals, payer representatives, documents, and phone systems, and those channels do not disappear simply because a new electronic standard is introduced.

Even the current CMS rules reflect that reality. The 2026 requirement to provide specific denial reasons under CMS-0057-F applies regardless of whether an applicable request was submitted through an API, portal, fax, phone, or another method.

That is an important point for organizations evaluating prior authorization automation. The most durable approach is unlikely to be one that assumes a single channel will eventually replace everything else. A better model is channel-aware automation: use structured electronic data when it is available, rely on portals when they contain the best information, use payer calls when clarification or exception handling is necessary, and return the result to the RCM team in a consistent format.

An API may be the fastest path for one payer. A portal may contain information that the API does not expose. A phone call may still be necessary when documentation is missing, a case is stalled, or conflicting information needs to be resolved.

The channel can change. The operational goal does not.

What provider and RCM teams should do now

Because CMS-0062-P is still proposed, providers do not need to redesign their workflows around its requirements today. But the rule gives organizations a useful view into where federal prior authorization policy is heading, and there are several practical steps teams can take without betting on the final wording.

First, separate medical-benefit and pharmacy-benefit drug workflows. Understanding which benefit applies, which systems are involved, and which team owns the work makes it easier to identify where automation can help.

Second, map where staff currently leave the EHR or RCM platform. Common examples include logging into payer portals, switching to a pharmacy system, calling a payer, uploading clinical documents, checking authorization status, and manually copying results between systems. Those handoffs are often where delays, duplicate work, and missing information accumulate.

Third, define what information is actually required to close the task. Depending on the workflow, that may include whether authorization is required, the authorization number, current status, missing documentation, effective and expiration dates, approved units or visits, denial reason, payer reference number, and the next action.

Finally, preserve source evidence. As payer interactions become more automated, teams need to know where consequential information came from. That might be an API response, portal result, call transcript, payer reference number, electronic transaction, timestamp, or supporting document.

The goal should be to make the workflow easier to audit as automation increases, not harder.

What CMS-0062-P means for prior authorization automation

The larger story behind CMS-0062-P is not simply that prior authorization is becoming more electronic. It is that payer communication is becoming more structured while still remaining distributed across several channels.

That changes what effective automation should look like.

A system that automates a phone call but leaves the result buried in an unstructured transcript has only solved part of the problem. The same is true of an API integration that retrieves a status but does not connect that status to the next operational step.

A stronger model is to automate the entire retrieval and follow-up layer: determine what information is needed, use the most appropriate payer channel to retrieve it, capture the result in structured fields, preserve the evidence behind it, and route exceptions to a person when human review is necessary.

That is the model SuperDial is designed around.

For prior authorization workflows, SuperDial can automate checks and status follow-up across payer channels and return structured information such as authorization requirement, authorization number, current status, validity dates, approved units or visits, missing documentation, next steps, and source evidence.

That approach does not depend on every payer behaving the same way. It is designed for the environment providers actually work in today, where APIs, portals, electronic transactions, and voice can all play a role.

As CMS continues to expand electronic prior authorization, the mix of those channels will evolve. The underlying operational requirement will remain remarkably consistent: get an accurate answer, preserve where it came from, and move the case to the correct next step.

Frequently Asked Questions

Is the CMS 2026 prior authorization for drugs rule final?

No. As of September 21, 2026, CMS-0062-P remains a proposed rule. CMS released the proposal on April 10, 2026, and closed the public comment period on June 15, 2026.

When would the proposed drug prior authorization requirements take effect?

Many of the major payer requirements in CMS-0062-P have proposed compliance dates beginning October 1, 2027. These include proposed electronic prior authorization requirements for medical-benefit drugs, pharmacy-benefit standards for certain plans, additional denial-reason requirements, and expanded prior authorization information through interoperability APIs.

Because the rule has not been finalized, those dates should still be treated as proposed.

What changed for prior authorization in 2026?

Under CMS-0057-F, certain requirements for non-drug medical items and services began taking effect in 2026. For impacted payers other than Qualified Health Plan issuers on the Federally-facilitated Exchanges, decisions generally must be provided no later than 72 hours for expedited requests and seven calendar days for standard requests, while still being made sooner when the patient’s clinical condition requires it.

Impacted payers must also provide a specific reason for applicable prior authorization denials. Those finalized requirements exclude drugs.

When are CMS Prior Authorization APIs required?

Under the 2024 final rule, impacted payers are required to implement Prior Authorization APIs beginning in 2027 for applicable non-drug medical items and services. CMS-0062-P proposes extending electronic prior authorization requirements further into drug workflows.

Does CMS-0062-P apply to every health insurance plan?

No. CMS interoperability requirements apply to specified payer categories and federal programs rather than every commercial health plan. Organizations should verify which requirements apply to a particular payer and plan instead of assuming the rule covers all insurance products.

Will electronic prior authorization eliminate payer calls?

Not necessarily. More structured electronic exchange can reduce administrative work, but provider workflows still depend on payer-specific systems and exceptions. A practical automation strategy should be able to use APIs and electronic transactions when available while maintaining portal and voice pathways for cases that cannot be resolved electronically.

Preparing for what comes next

CMS-0062-P is not yet a compliance mandate, but it provides a clear signal about the direction of prior authorization policy: more structured data, more electronic exchange, greater transparency around denials, and tighter expectations around response times.

Providers do not need to predict every detail of the final rule to prepare for that environment. They can start by reducing unnecessary manual handoffs, defining the exact information each authorization task needs, keeping evidence attached to payer responses, and building workflows that can adapt as new electronic channels become available.

Those changes are useful even if the final drug rule differs from the current proposal. They improve operations today while making future payer and regulatory changes easier to absorb.

SuperDial helps healthcare teams automate prior authorization checks and status follow-up across payer channels, returning the result as structured, auditable data. Bring us a representative workflow, and we’ll show you how it can run.

Sources

  • Centers for Medicare & Medicaid Services. 2026 CMS Interoperability Standards and Prior Authorization for Drugs Proposed Rule (CMS-0062-P). April 10, 2026.
  • Centers for Medicare & Medicaid Services. CMS Interoperability and Prior Authorization Final Rule (CMS-0057-F). January 17, 2024.
  • Centers for Medicare & Medicaid Services. Prior Authorization API — Frequently Asked Questions.
  • Centers for Medicare & Medicaid Services. Electronic Prior Authorization.

Run a pilot on a real workflow.

Bring a representative batch, define the output schema, and validate ROI with your payer mix in 30 to 90 days.