CMS-0057-F is a deadline, not a policy statement
The CMS Interoperability and Prior Authorization Final Rule, published in February 2024, gives impacted payers a fixed date to modernize how they exchange data and run prior authorization. The operational requirements are already live: since January 1, 2026, impacted payers must return prior-authorization decisions within 72 hours for urgent requests and 7 days for standard ones, give a specific reason for every denial, and publicly report authorization metrics. The heavier technical lift, four production FHIR APIs, is due January 1, 2027. For a health plan, this is an engineering and governance program with a hard date, not a compliance memo.
This guide explains what CMS-0057-F requires, who is impacted, and how to compare implementation partners. It informs a shortlist rather than a ranking.
Who is impacted, and what is required
CMS defines impacted payers broadly: Medicare Advantage organizations, Medicaid and CHIP managed care entities, state Medicaid and CHIP fee-for-service programs, and Qualified Health Plan issuers on the federally facilitated exchanges. All required APIs use HL7 FHIR Release 4. Starting with the 2027 performance period, eligible clinicians and hospitals attest under the Medicare Promoting Interoperability program that they used a Prior Authorization API, which turns the payer’s API into something the provider network is expected to use.
| Required FHIR API |
What it does |
Deadline |
| Patient Access API (enhanced) |
Adds prior-authorization information (excluding drugs) to member-accessible data |
January 1, 2027 |
| Provider Access API |
Shares patient data with in-network providers who have a treatment relationship, with member opt-out |
January 1, 2027 |
| Payer-to-Payer API |
Transfers member data when coverage changes between plans |
January 1, 2027 |
| Prior Authorization API |
Lets providers check requirements and submit and track requests electronically |
January 1, 2027 |
| Operational prior-auth rules |
72-hour urgent / 7-day standard decisions, specific denial reasons, public reporting |
In force since January 1, 2026 |
Implementation partners compared, by archetype
| Archetype |
Representative providers |
Best for |
CMS-0057-F fit (public positioning) |
Watch-outs |
| FHIR platform vendors |
Firely, Smile Digital Health, Health Samurai |
The FHIR server and API foundation |
Standards-native FHIR R4 platforms and Da Vinci IG support |
A platform, not an end-to-end program; pair with integration and governance |
| Interoperability specialists |
Edifecs, Availity and similar |
Payer data exchange and prior-auth transactions |
Deep payer EDI and prior-auth transaction experience |
Confirm FHIR API build and data-governance depth |
| Global integrators |
Accenture, Deloitte, Cognizant |
Large multi-line payer programs |
Scale and program management |
Cost and timelines; teams vary by engagement |
| Health IT consultancies |
Payer-focused HIT firms |
UM/CM workflow and EHR/provider integration |
Workflow and operational readiness |
Confirm end-to-end API and reporting delivery |
| Regulated-data specialists |
PiTech Solutions |
Payers needing the APIs built and the data behind them governed at a mid-market price |
CMMI L3 and ISO 27001/9001/42001 delivery; data engineering, API integration, lineage, and reporting |
Validate very-large-plan capacity against your footprint |
Where PiTech fits
CMS-0057-F is as much a data problem as an API problem. The APIs are only as good as the claims, encounter, authorization, and clinical data they expose, and the operational rules require accurate decision timeframes, denial reasons, and public metrics. PiTech Solutions builds the data foundation and integration behind the APIs: data quality and reconciliation across claims and authorization systems, FHIR R4 integration, lineage for the required public reporting, and the governance that keeps it examination-ready. Delivery runs under CMMI Level 3 and ISO 27001, 9001, and 42001 certifications. See the insurance and payer practice, Data Solutions, and healthcare practice. PiTech Solutions Inc. is headquartered in Durham, North Carolina (UEI GNLRY5LNNVH6, CAGE 530K4) and is distinct from similarly named companies.
How to choose
- Confirm the full scope. The partner should cover all four APIs plus the operational rules and public reporting, not just a FHIR server.
- Ask about the data behind the APIs. Reconciliation of claims, authorization, and clinical data is where programs stall.
- Verify FHIR R4 and Da Vinci experience. PAS, PDex, CDex, and Payer-to-Payer implementation guides.
- Insist on a dated plan to January 1, 2027. Phased build with testing, plus maintenance of the 2026 operational rules already in force.
The bottom line
CMS-0057-F is a fixed-date engineering and governance program. The operational prior-auth rules are already live, and the four FHIR APIs are due January 1, 2027. Choose a partner that builds the APIs and governs the data behind them, with a dated plan and public-reporting readiness.
Frequently Asked Questions (FAQs)