The definitive guide to the CMS final rule requiring Medicare Advantage organizations, Medicaid managed care plans, state Medicaid and CHIP agencies, and QHP issuers to implement FHIR-based APIs and streamline prior authorization processes.
CMS-0057-F is the CMS Interoperability and Prior Authorization final rule, released January 17, 2024 and published in the Federal Register on February 8, 2024. It applies to Medicare Advantage organizations, state Medicaid and CHIP programs, Medicaid and CHIP managed care plans, and QHP issuers on the Federally-facilitated Exchanges.
| Requirement & date | What payers must do |
|---|---|
| Prior authorization process In effect Jan 1, 2026 |
Give a specific reason for every denial and publicly report prior authorization metrics. All impacted payers except QHP issuers on the FFEs must also decide urgent requests within 72 hours and standard requests within 7 calendar days. |
| Four FHIR APIs From Jan 1, 2027 |
Patient Access (with prior authorization data), Provider Access, Payer-to-Payer, and Prior Authorization APIs live in production. January 1, 2027 is a hard date for MA organizations and state Medicaid and CHIP FFS programs; managed care plans comply by the rating period, and QHP issuers on the FFEs by the plan year, beginning on or after that date. |
| Electronic prior authorization measures CY 2027 performance period |
New attestation measures for MIPS eligible clinicians, hospitals, and CAHs under Promoting Interoperability. |
One-page summary: CMS-0057-F fact sheet · Every deadline and extension pathway: compliance timeline · The official source: CMS fact sheet
CMS-0057-F establishes enforceable requirements for impacted payers to implement standards-based FHIR APIs, accelerate prior authorization decisions, and publicly report transparency metrics. It builds upon the 2020 CMS Interoperability and Patient Access final rule and represents the most significant federal push toward real-time health data exchange.
Requires payers to give patients access to claims, clinical data, and prior authorization information through FHIR-based third-party apps of their choice.
Enables in-network providers to retrieve adjudicated claims, encounter data, USCDI clinical data, and prior authorization details for their attributed patients.
Mandates automated health data exchange when patients change payers, ensuring continuity of care with up to five years of historical data.
Streamlines the PA process by enabling providers to electronically determine requirements, query documentation needs, and submit requests from within their EHR.
The rule applies to a broad range of payer types across Medicare, Medicaid, CHIP, and the ACA marketplace. Stand-alone dental plans (SADPs) and FF-SHOP issuers are excluded.
CMS finalized a phased schedule. Prior authorization process requirements have been in effect since January 1, 2026. The four FHIR APIs remain due January 1, 2027. Full detail, including extension and exemption pathways: CMS-0057-F compliance timeline.
Now in force. All impacted payers must provide specific denial reasons and publicly report prior authorization metrics. All except QHP issuers on the FFEs must also respond within 72 hours (urgent) / 7 calendar days (standard). Annual Patient Access API metrics reporting to CMS also began.
All four FHIR-based APIs must be live: Patient Access API (with PA data), Provider Access API, Payer-to-Payer API, and Prior Authorization API. Applies to MA organizations and state Medicaid/CHIP FFS programs by this date; managed care plans and QHP issuers by rating/plan year beginning on or after this date.
New "Electronic Prior Authorization" measures under the MIPS Promoting Interoperability performance category and the Medicare Promoting Interoperability Program begin. Eligible clinicians, hospitals, and CAHs report a yes/no attestation.
The rule text at 45 CFR 170.215 still cites the versions below. Several of those HTI-1 expiration dates have passed. Payers may voluntarily adopt later US Core / USCDI versions as a superset — document what you actually serve. See 2026 status.
| Standard | Specification | Citation |
|---|---|---|
| HL7 FHIR | FHIR Release 4.0.1 | 45 CFR 170.215(a)(1) |
| US Core IG | HL7 FHIR US Core IG STU 3.1.1 (rule text; HTI-1 expiration was Jan 1, 2026) | 45 CFR 170.215(b)(1)(i) |
| SMART App Launch | SMART Application Launch Framework IG 1.0.0 (rule text; HTI-1 expiration was Jan 1, 2026) | 45 CFR 170.215(c)(1) |
| Bulk Data Access | FHIR Bulk Data Access (Flat FHIR) v1.0.0: STU 1 | 45 CFR 170.215(d)(1) |
| OpenID Connect | OpenID Connect Core 1.0 (errata set 1) | 45 CFR 170.215(e)(1) |
| Content Standard | USCDI v1 (rule text) — later USCDI versions may be adopted voluntarily | 45 CFR 170.213 |
More questions, with answers sourced to the rule text: full CMS-0057-F FAQ.
Cloud Health Office is a vendor-neutral overlay for CMS-0057-F — FHIR APIs and prior authorization support without replacing QNXT, Facets, or HealthEdge. Source-available.
Read the CHO compliance layer →