CMS-0057-F Prior Authorization Rule: No Verification Behind the Numbers
CMS-0057-F requires payers to publicly post prior authorization metrics — but CMS's own rule text confirms no independent audit or certification process backs the disclosure. The insurance industry's voluntary pledge has the identical gap.
CMS's own rule text confirms it built no independent verification process behind its prior authorization public reporting mandate — and the insurance industry's voluntary pledge has the identical gap. Here's what compliance and legal teams should track before either claim gets tested.
What you need to know
- The change: As of March 31, 2026, impacted payers under CMS-0057-F must publicly post prior authorization approval, denial, and appeal metrics — but CMS's own rule text states it does not address specific compliance and enforcement actions for the rule's provisions, and the rule does not establish a payer-wide independent certification or audit process for the posted metrics.
- Who is affected: Medicare Advantage organizations, state Medicaid and CHIP agencies, Medicaid/CHIP managed care plans, and QHP issuers on the federally facilitated exchanges.
- Why it matters: A parallel voluntary industry pledge to reduce prior authorizations has a similar limitation — its claimed 11% reduction is attributed to an AHIP-BCBSA survey whose underlying data AHIP has not published.
- What to do first: Compliance and legal teams should treat public PA disclosures as documents that may eventually be tested against independent verification, and build internal evidence trails accordingly.
- Key date or trigger: March 31, 2026 — first public PA metrics reporting deadline under CMS-0057-F.
This analysis continues in the PolicyEdge AI Intelligence Terminal, where members receive decision-grade intelligence on AI, regulation, and policy risk.