What the First Public Prior Authorization Reports Show, and What They Don't

Data current as of October 2026, based on calendar year 2025 reports.

For the first time, Medicare Advantage, Medicaid, CHIP and federally facilitated Marketplace plans are publishing a common set of prior authorization metrics under CMS's Interoperability and Prior Authorization final rule, CMS-0057-F. The first reports cover calendar year 2025 and were due on payers' public websites by March 31, 2026.

The reports are a genuinely new source of evidence about authorization operations, and they are easy to overinterpret. The early files show substantial variation in approval rates, appeal outcomes and turnaround times between individual plans and contracts. They do not, on their own, establish which insurer is "best," which initial denials were inappropriate, or how hard authorization feels for a provider treating a particular population. The most useful way to read the first cycle is as an operational baseline.

What CMS now requires payers to publish

CMS-0057-F requires impacted payers to post aggregated prior authorization metrics for medical items and services, excluding drugs, each year by March 31, using data from the previous calendar year. Impacted payers are Medicare Advantage organizations, state Medicaid and CHIP fee-for-service programs, Medicaid managed care plans, CHIP managed care entities, and Qualified Health Plan issuers on the federally facilitated exchanges.

For Medicare Advantage, the regulation (42 CFR 422.122) lists what must be posted: the items and services that require prior authorization; the percentage of standard requests approved, denied and approved after appeal; the percentage of requests approved after the review timeframe was extended; the percentage of expedited requests approved and denied; and the average and median time between submission and decision for both standard and expedited requests. Parallel rules apply to the other payer types.

One detail shapes every comparison: the reporting unit differs by program. Medicare Advantage organizations report at the contract level, Medicaid managed care plans at the plan level, Medicaid and CHIP fee-for-service programs at the state level, and Marketplace issuers at the issuer level. Even before looking at a single number, a Medicare Advantage contract and a Medicaid plan are different kinds of reporting unit.

"Payer approval rate" is too broad a concept

Aetna's 2025 Medicare Advantage report, a single 84-page file covering 42 contracts, shows why analysis belongs at the contract level rather than the brand level. Contract H0523 reported 97.61% of standard requests approved and 2.39% denied. Contract H0628, in the same file, reported 92.32% approved and 7.68% denied, and its expedited denial rate was 13.66%, against 2.94% for H0523.

That spread sits inside one insurer's Medicare Advantage portfolio. It is a warning against headlines that reduce a multi-contract organization to a single authorization percentage, unless the payer itself has published a properly aggregated company-level figure. Population, geography, plan type, service mix and utilization-management programs all differ across contracts. Each metric describes the reported activity of that reporting unit, not a fixed characteristic of the payer's brand.

Different programs can show very different denial rates

Humana's Medicare Advantage contract H4461, which its 2025 contract crosswalk lists as a Tennessee HMO, reported 280,178 standard requests, with 262,891 approved and 17,287 denied: a 93.83% approval rate and 6.17% denial rate. It reported a further 4,881 expedited requests, 90.64% of them approved.

UnitedHealthcare Community Plan of Virginia, a Medicaid managed care plan, reported 111,870 standard requests in its plan-level 2025 summary, with 87,089 approved and 24,781 denied: a 77.85% approval rate and 22.15% denial rate.

Those numbers are strikingly different, but they are not an apples-to-apples ranking. One is a Medicare Advantage contract and the other a Virginia Medicaid plan, serving different populations under different programs with potentially very different service mixes. The legitimate conclusion is narrower: the reports reveal meaningful variation, and that variation needs analysis at the plan and program level.

Even one plan's numbers can depend on which file you read

The Virginia example comes with a second lesson. UnitedHealthcare's plan-level summary for Virginia, linked from its Virginia provider page, is the source of the figures above. UnitedHealthcare also publishes a corporate Medicaid interoperability file that reports Virginia differently: it splits the state into Cardinal Care Medicaid (57,435 standard requests, 89.1% approved) and Cardinal Care LTSS (49,163 standard requests, 88.9% approved). Together those total 106,598 standard requests rather than 111,870, with approval rates near 89% rather than 78%. The corporate file also reports turnaround in days only and states that UnitedHealthcare does not extend review timeframes, while the Virginia summary reports 1,815 extended reviews.

Neither file explains the difference. It may reflect segmentation, timing or methodology, but the published documents do not say. For anyone using these reports, the practical rule is to cite the specific file, its date and its reporting unit alongside every number, and to treat a single figure without that context as incomplete.

Appeal-overturn rates are the most tempting metric to misuse

Humana's file states its appeal metric clearly: of 467 standard-request appeals for contract H4461, 313 were approved after appeal and 154 remained denied, a 67.02% approval-after-appeal rate measured out of total appeals. Aetna is less explicit. It reported 53.33% of standard requests as "approved after appeal" for contract H0523 and 89.47% for H0628, but its file gives no denominator, counts or definition. CMS's reporting template, published in July 2026 after the first reports were posted, says the metric should be a subset of the standard requests that were appealed.

That ambiguity matters, because "53% approved after appeal" is not the same claim as "53% of denials were overturned." Denials that were never appealed sit outside the denominator, and without counts a reader cannot tell how many appeals the percentage represents.

Even where the definition is clear, an overturn is not proof of a bad initial decision. Humana's report says so on every page: "An overturn on appeal does not necessarily indicate an inappropriate initial prior authorization decision because the overturn may be the result of additional information received or changes in the member's clinical presentation." A high overturn rate can still raise useful operational questions. For providers, the most actionable one is what information commonly arrives during appeal that could have been submitted with the original request.

Median turnaround can hide the shape of the workload

The reports also show why both mean and median matter. Humana's H4461 reported a mean of one day for standard requests but a median of zero days, and a mean of five hours with a median of zero hours for expedited requests. Aetna's H0523 reported a mean standard turnaround of 3.06 days against a zero-day median, and an expedited mean of 0.54 days, again with a zero-day median. UnitedHealthcare Community Plan of Virginia reported a standard mean of 2.2 days with a median of one day, and an expedited mean of 8.9 hours with a median of one hour.

A zero-day median suggests that at least half of the measured requests were decided on the same day under the report's methodology. It does not mean every request was immediate. A mean well above the median indicates that a subset of cases took much longer and pulled the average up, and for providers, those slower cases may be the ones consuming the most staff time.

Fast decisions do not eliminate authorization burden

Turnaround measures only one dimension of prior authorization. It does not capture how much provider work was needed before a request was considered complete, how often staff had to navigate a delegated vendor, how much documentation was assembled, how many portal or phone interactions occurred, or how often the requested service changed during review. A payer can report fast decisions while still creating substantial administrative work upstream. Conversely, a slower average does not reveal whether the delay came from complex clinical cases, missing provider information, plan review or something else.

The public metrics are valuable precisely because they add quantitative evidence. They should not be asked to answer operational questions they were not designed to measure.

2025 is a baseline before tighter 2026 decision deadlines

The timing of the first reporting year matters. The data describe requests handled in 2025, before CMS-0057-F's new decision timeframes took effect. Beginning in 2026, impacted payers other than Marketplace issuers must issue expedited decisions within 72 hours and standard decisions within seven calendar days; Aetna's file still labels its standard turnaround row against the previous 14-day standard. (For the background to those changes, see our overview of prior authorization reform in 2026, and for the separate proposal on drugs, the CMS drug prior authorization rule.)

The 2025 reports therefore give a baseline. When 2026 data become public by March 31, 2027, analysts can examine whether turnaround distributions changed under the new timeframes. A single year is a snapshot; two or three years begin to form a trend.

How providers can use the reports

Provider organizations do not need to turn the metrics into league tables. A more practical use is to combine public plan-level data with their own operational experience. An RCM or authorization leader can ask whether plans with higher reported denial rates also generate more internal rework, whether plans with higher appeal-overturn rates are tied to specific documentation gaps, and whether the organization's observed turnaround resembles what the payer reports.

That comparison can show where the provider's own process adds friction. If a payer reports same-day decisions for most requests but one service line routinely waits several days, the issue may be specific to that service, submission channel, documentation pattern or delegated vendor rather than the payer's program as a whole. Tracking that requires structured records of each prior authorization request: when it was submitted, through which channel, what was asked for, and when and how it was resolved. Public metrics are most useful when they prompt better questions about that internal data.

What the reports still do not tell us

The reports do not create a universal measure of authorization burden. They do not adjust for clinical complexity, service mix, population, contract design or the share of care that requires authorization in the first place. Two plans could report the same 95% approval rate while imposing very different authorization footprints, one requiring authorization for a narrow set of expensive services and the other across a much larger share of provider activity. A denial percentage describes the outcome of submitted requests, not how many potential requests were avoided, abandoned, redirected or never submitted because of payer requirements. Those limits should stay visible whenever the numbers are compared.

The biggest change is the existence of the dataset

The first CMS-0057-F reports do not settle the debate over prior authorization. What they do is move part of it from anecdote to public, plan-level evidence. For providers, researchers, regulators and payers, that creates an opportunity to watch approval rates, denial rates, appeal outcomes and decision times change over time, and pressure to ask a more precise question than whether a payer's prior authorization is "good" or "bad."

The useful question is which plans, services and stages of the process create friction, what the data can actually prove, and whether those patterns improve as the new requirements take hold. The 2025 reports are the first baseline, not the final verdict.

FAQ

What prior authorization metrics does CMS-0057-F require payers to publish?

For each reporting unit, payers must post the items and services that require prior authorization; the percentage of standard requests approved, denied and approved after appeal; the percentage approved after an extended review; the percentage of expedited requests approved and denied; and the average and median decision time for standard and expedited requests. Drugs are excluded.

Which payers have to publish prior authorization metrics?

Medicare Advantage organizations, state Medicaid and CHIP fee-for-service programs, Medicaid managed care plans, CHIP managed care entities, and Qualified Health Plan issuers on the federally facilitated exchanges. Commercial employer plans outside those programs are not covered by this requirement.

When are prior authorization metrics published?

Annually, by March 31, covering the previous calendar year. The first reports, covering 2025, were due March 31, 2026.

Does a high appeal-overturn rate mean the payer's denials were wrong?

Not necessarily. Appeals can include information the payer did not have at the initial review, and some payers' files do not define the metric's denominator. Humana's report states that an overturn does not necessarily indicate an inappropriate initial decision.

Sources

All retrieved October 5, 2026.

Run a pilot on a real workflow.

Bring a representative batch, define the output schema, and validate ROI with your payer mix in 30 to 90 days.