What is already in effect

Impacted payers (except QHP issuers on the FFEs) have been required, since January 1, 2026, to:

Source: the CMS fact sheet and the Federal Register text of CMS-0057-F.

Not yet due: standing up the four FHIR APIs. CMS delayed those from 2026 to January 1, 2027 after comments. Treating “we post PA metrics” as “we are API-compliant” is a category error.

What is still January 1, 2027

Patient Access API

Enhanced with prior authorization data. Builds on the 2020 Patient Access mandate.

Provider Access API

New. In-network providers retrieve claims, encounter, USCDI, and PA data for attributed patients, with opt-out.

Payer-to-Payer API

Up to five years of claims, clinical, and PA history when a member changes plans. Opt-in.

Prior Authorization API

Electronic requirement check, documentation, submit, and decision. Da Vinci CRD / DTR / PAS are the practical path; the rule does not name those IGs as the only legal option.

Date trigger varies by payer type: MA and state Medicaid/CHIP FFS use the hard January 1 date. Managed care and QHP issuers on FFEs use the rating / plan year beginning on or after that date. See the timeline.

Standards: rule text vs what teams ship

The final rule still points at 45 CFR 170.215 versions that include US Core IG STU 3.1.1, SMART App Launch 1.0.0, and USCDI v1. Several of those HTI-1 expiration dates have passed. CMS allows voluntary adoption of later versions. Production teams commonly implement a later US Core as a superset of the rule-text profiles. Document the version you actually serve in your capability statement and conformance evidence.

What this site is not

cms-0057-f.com is an independent educational resource published by Aurelianware, Inc. It is not CMS, not HHS, and not a certification. For a vendor-neutral overlay that implements the APIs beside QNXT, Facets, or HealthEdge, see the product page — not this explainer.

CHO compliance layer → Full timeline →