CMS Interoperability and Prior Authorization Final Rule
CMS-0057-F expands Patient Access API content and requires Provider Access, Payer-to-Payer, and Prior Authorization APIs for impacted payers, with associated privacy, opt-in or opt-out, metrics, and operational provisions.
What the authority record establishes
CMS-0057-F expands Patient Access API content and requires Provider Access, Payer-to-Payer, and Prior Authorization APIs for impacted payers, with associated privacy, opt-in or opt-out, metrics, and operational provisions.
Binding on impacted payers by provision and compliance date
The exact official title, issuing body, jurisdiction, version or application record, and linked source define the scope of this page. Readers should not transfer the authority's status to a commercial product or infer transaction-, patient-, system-, site-, or organization-specific applicability from this summary.
Why it matters to this market
The rule makes versioned FHIR implementation, bulk data, member permission, endpoint discovery, data lineage, and production operations central payer interoperability requirements.
Affected operating stages
- Data Mapping
- Member Permission
- Provider Access
- Payer-To-Payer Exchange
- Prior Authorization
- API Monitoring
- Reporting
Capabilities to examine
FHIR API Gateway And Orchestration
Ask how the system or service identifies the controlling source and version, applies customer-specific interpretation, handles exceptions, preserves human judgment, and retains evidence for FHIR API gateway and orchestration.
FHIR Profile And Implementation-Guide Support
Ask how the system or service identifies the controlling source and version, applies customer-specific interpretation, handles exceptions, preserves human judgment, and retains evidence for FHIR profile and implementation-guide support.
SMART On FHIR Authorization
Ask how the system or service identifies the controlling source and version, applies customer-specific interpretation, handles exceptions, preserves human judgment, and retains evidence for SMART on FHIR authorization.
Bulk Data Access And Export
Ask how the system or service identifies the controlling source and version, applies customer-specific interpretation, handles exceptions, preserves human judgment, and retains evidence for bulk data access and export.
Provider Directory And Endpoint Discovery
Ask how the system or service identifies the controlling source and version, applies customer-specific interpretation, handles exceptions, preserves human judgment, and retains evidence for provider directory and endpoint discovery.
Consent, Authorization, And Data Segmentation
Ask how the system or service identifies the controlling source and version, applies customer-specific interpretation, handles exceptions, preserves human judgment, and retains evidence for consent, authorization, and data segmentation.
Payer And Claims Data Exchange
Ask how the system or service identifies the controlling source and version, applies customer-specific interpretation, handles exceptions, preserves human judgment, and retains evidence for payer and claims data exchange.
Data Quality, Lineage, And Provenance
Ask how the system or service identifies the controlling source and version, applies customer-specific interpretation, handles exceptions, preserves human judgment, and retains evidence for data quality, lineage, and provenance.
Conformance Testing And Validation
Ask how the system or service identifies the controlling source and version, applies customer-specific interpretation, handles exceptions, preserves human judgment, and retains evidence for conformance testing and validation.
Operational Monitoring And Exception Management
Ask how the system or service identifies the controlling source and version, applies customer-specific interpretation, handles exceptions, preserves human judgment, and retains evidence for operational monitoring and exception management.
Affected buyer audiences
- impacted health plans
- state programs
- provider organizations
- payer API platforms
- EHR and interoperability vendors
Implementation questions
- Which entities, products, populations, transactions, systems, sites, or jurisdictions are actually within scope?
- What is binding, what is guidance, and what is a technical or consensus standard?
- Which publication, adoption, effective, application, transition, and enforcement dates differ?
- Who owns legal, clinical, quality, regulatory, policy, or operational interpretation?
- How will a source revision affect open work and historical decisions?
Interpretation boundary
The publication does not determine payer-specific applicability or compliance and does not collapse prior-authorization requirements into every interoperability use case.