Electronic Prior Authorization Goes Live January 1. Is Anyone Actually Ready?
The federal electronic prior authorization requirements take effect on January 1, 2027, about 90 days from now. In late September, the American Medical Association sent CMS a letter asking it to hold that date.
Some health plans have been asking for a delay, arguing that physicians aren't engaged enough to make electronic prior authorization (ePA) work yet. The AMA's response was blunt. AMA CEO John Whyte, MD, wrote that the idea that physicians aren't interested, rather than not supported, "is a manufactured problem created to justify a delay."
I've spent a long time in revenue cycle, and I think both sides are describing something real. The technology is closer to ready than it has ever been. The people who have to use it are not. If you run a revenue cycle, the next 90 days are about closing that gap in your own organization, whatever CMS decides about enforcement.
What happens to prior authorization on January 1, 2027?
Under the CMS Interoperability and Prior Authorization Final Rule (CMS-0057-F), payers must have prior authorization APIs available in 2027. CMS has also broadened its reform efforts beyond payers' own commitments to include providers and EHR vendors.
In plain terms, the goal is for a prior auth request to move from your EHR to the payer electronically, with the documentation attached and the decision coming back into your workflow. No fax, no phone tree, no retyping the same clinical details into a payer portal.
CMS has been building toward this all year. In May it selected 29 organizations, including health systems, EHR developers, physician practices and digital health companies, for its Electronic Prior Authorization Acceleration initiative. In April it proposed extending prior authorization requirements to drugs, including electronic prior auth and shorter decision timeframes.
Why is the AMA fighting a delay?
The AMA's letter worries that broad nonenforcement during 2027 would slow development, testing and deployment, "leaving physicians reliant on faxes, phone calls, payer portals, and repeated data entry while patients continue waiting for medically necessary care."
The part of the letter I'd hand to every revenue cycle leader is the list of what practices still don't know:
what capabilities will actually be available on January 1
what workflow changes to expect
how to report problems when something breaks
"Without clear and timely information, practices cannot build change management plans, train staff, participate in testing or serve as active partners," the letter says.
That matches my thoughts. When a new process fails in revenue cycle, the usual cause is that nobody told the person doing the work what changed, why it changed, or who to call when it doesn't work. A technology that's ready doesn't help a team that hasn't been trained on it.
Which payers and EHRs are already live?
Some payers aren't waiting. UnitedHealthcare, Network Health, and Aetna have already gone live with the relevant APIs through their work with Epic.
The EHR vendors are building on their side too. Epic lists "interoperability to speed up prior authorization" as one of the priorities on its development roadmap. Oracle Health announced AI agents for revenue cycle work, including prior authorization, as part of a push into front-end and mid-cycle operations.
Some health systems are already getting returns. UT Health San Antonio's chief value officer said denial appeals and prior authorization are where AI is starting to produce measurable revenue, including prior auth help built directly into the clinical workflow.
One development to watch: Epic CEO Judy Faulkner said in late September that the company had paused most technology development for about six weeks to focus on cybersecurity. Epic's spokesperson said the roadmap hasn't changed. If you're an Epic organization, ask your Epic team directly whether the security work affects anything you're counting on for January.
What do Aetna's bundled prior authorizations tell us?
This is my favorite prior auth story of the quarter.
Aetna is now bundling prior authorizations for all types of cancer in its Medicaid plans across eight states. Instead of a separate request for chemotherapy or immunotherapy and another for radiation and imaging, the oncology team submits one request that covers the treatment plan. Aetna expects to extend the program to Medicare and commercial plans in the first half of 2027.
Aetna's own survey explains why: 74% of providers named administrative burden as the top challenge facing clinical staff, and 31% said prior authorization is the single biggest factor.
Bundling shows a direction that goes beyond ePA. Making prior auth electronic makes the same number of requests faster. Bundling reduces the number of requests. The payers and providers who make real progress will need both.
If your organization has an oncology program and contracts with Aetna, find out now whether your team is using bundled requests. If they're still submitting one request per service, you're doing extra work you no longer have to.
What should revenue cycle leaders do in the next 90 days?
Whether CMS holds the date or delays enforcement, here is the readiness plan I'd run between now and January 1.
1. Map your top payers. List your top ten payers by volume and sort them into three groups: live on prior auth APIs, testing, or silent. Payers will build incrementally, often starting with certain lines of business rather than everything at once. Your plan has to work with partial coverage.
2. Get specific answers from your EHR vendor. Which prior auth capabilities are you already licensed for? Which cost extra? What will be turned on by January 1, and what's on the roadmap after that? Some EHR payer integration modules carry an added cost and only work when the payer participates. Find that out now.
3. Keep a fallback workflow. Faxes and payer portals are not going away on January 2. For every payer that isn't live, your team needs to know which process to use. Write it down so nobody has to guess.
4. Train the people who touch prior auth. That includes your preservice team, clinic schedulers, ordering providers' staff, and anyone in a specialty with heavy prior auth volume like oncology, imaging and surgery. Tell them what's changing, what isn't, and exactly who to call when something breaks. That last item is the gap the AMA flagged.
5. Set up an issue-reporting path. When an electronic request fails or a payer response doesn't come back into the workqueue, someone needs to own it and someone needs to escalate it to the payer or vendor. Decide who that is before January, not after.
6. Baseline your numbers before go-live. Measure average turnaround time by payer, the number of staff touches per authorization, and your authorization-related denial rate. If you don't capture the "before," you'll never be able to prove the "after," and your CFO will ask.
What will prior authorization look like by 2030?
In RCM 2030: Strategy and Survival for Revenue Cycle Leaders, I wrote that prior authorization is where hospitals will feel the biggest difference this decade. By 2027, payers must make APIs available. By 2030, I expect routine cases to look instant: the order triggers the payer's rules in real time, the clinical documentation attaches, and the decision flows back into the EHR without your team touching it.
Will every case be instant? No. Complex cases will still need human review. But the idea that you need a small army to push prior auth requests through fax machines will finally be over.
January 1 is the first step toward that. It won't be clean. Some payers will be ready and some won't, and some workflows will break in ways nobody predicted. The organizations that come out ahead will be the ones that trained their people, kept a fallback in place and measured the results from day one.
Frequently asked questions
When is the electronic prior authorization deadline?
The API requirements under the CMS Interoperability and Prior Authorization Final Rule (CMS-0057-F) are scheduled to take effect January 1, 2027. Some health plans have asked CMS to delay enforcement; the AMA has asked CMS to hold the date.
Which payers already support electronic prior authorization?
As of late September 2026, UnitedHealthcare, Network Health and Aetna had gone live with relevant APIs through their work with Epic. Other payers are expected to roll out in stages.
What is a bundled prior authorization?
A bundled prior authorization combines several related services into one request. Aetna's oncology program, for example, combines medical oncology services like chemotherapy or immunotherapy with radiation oncology services like imaging.
What should hospitals do to prepare for electronic prior authorization?
Map which payers are live, confirm what your EHR vendor will turn on by January 1, keep a fallback workflow for payers that aren't ready, train staff, set up an issue-reporting path and baseline your turnaround times and auth-related denials before go-live.
Want to see where your revenue cycle stands? The RCM AI Readiness Scorecard is a free self-assessment across denial prevention, coding and documentation, patient financial engagement, cash forecasting and governance. You check what's live today, not what's planned, and you'll see where your gaps are.
For the full picture of preservice in 2030, including prior authorization, eligibility and estimates, read RCM 2030: Strategy and Survival for Revenue Cycle Leaders and the RCM 2030 Companion Guide for Operations.
I cover what this means for health systems every Sunday in RCM 2030 Weekly. Subscribe on LinkedIn.

