CMS-0057-F · Interoperability & Prior Authorization

The 2027 FHIR API deadline is close. Is your build actually compliant?

Interoplix gives Medicare Advantage, Medicaid, CHIP, and exchange payers an independent, engineering-level readiness assessment of their CMS-0057-F implementation on Azure, and the hands-on remediation to close the gaps before January 1, 2027.

Already in effect since 2026: 72-hour expedited / 7-calendar-day standard prior authorization decisions, specific denial reasons, and Patient Access API metrics reporting.

The regulation

Who must comply, and by when.

The CMS Interoperability and Prior Authorization Final Rule (CMS-0057-F) requires impacted payers to implement and maintain four HL7 FHIR APIs. The compliance date depends on payer type, and the operational provisions are already live.

Payer typeAPI compliance date
Medicare Advantage organizationsJanuary 1, 2027
State Medicaid & CHIP fee-for-service programsJanuary 1, 2027
Medicaid managed care plans & CHIP managed care entitiesFirst rating period on or after January 1, 2027
QHP issuers on the Federally Facilitated ExchangesFirst plan year on or after January 1, 2027

Source: CMS Interoperability and Prior Authorization Final Rule (CMS-0057-F), finalized January 2024. Prior authorization provisions exclude drugs.

The requirements

Four APIs. Each with its own failure modes.

Every API in the rule carries requirements that don't show up in a demo but do show up in an audit: consent handling, attribution accuracy, data completeness, and decision communication.

Patient Access API (enhanced)

The API required since CMS-9115-F must now also expose prior authorization information (status, decisions, and related data) so members can see what was approved, denied, and why. Annual usage metrics reporting to CMS began in 2026.

Provider Access API

In-network providers with a treatment relationship retrieve claims, encounters, USCDI data, and prior authorization information, individually and in bulk. Hinges on accurate patient attribution and a working opt-out process.

Payer-to-Payer API

When a member changes plans, the previous payer shares up to five years of claims, encounter, USCDI, and prior authorization data. Requires a patient opt-in process and plain-language member education materials.

Prior Authorization API

Providers check whether an item or service needs authorization, see documentation requirements, submit electronically, and receive a structured decision: approved with an end date, denied with a specific reason, or a request for more information.

How Interoplix helps

Independent validation, then hands-on remediation.

Most CMS-0057-F content is written by platform vendors selling software. Interoplix is an independent FHIR and HL7 integration practice: we assess what you have, whether vendor-built or in-house, and build what's missing on Azure Health Data Services. Published rates, scoped deliverables.

Tier 1

CMS-0057-F Readiness Assessment

$2,500 – $5,000 flat

API-by-API gap analysis against the final rule: FHIR conformance, prior auth workflow, consent and opt-in/opt-out handling, attribution, metrics reporting, and HIPAA posture. Written findings with a prioritised remediation roadmap your team or vendor can execute.

Tier 2

Implementation & Remediation

$150 – $250 / hour

Hands-on build on Azure Health Data Services: FHIR R4 services, prior authorization workflow integration, validation gates that stop bad data before write, CI/CD, and infrastructure as code, all reproducible and auditable.

Tier 3

Compliance Advisory Retainer

$3,000 – $6,000 / month

Ongoing architecture guidance through the deadline and beyond: vendor oversight, code and design review, metrics reporting readiness, and escalation coverage when integration incidents hit production.

Why an independent specialist

What we check that vendors won't.

Read: What compliance review actually looks like in 2027 →

Common questions

CMS-0057-F, answered precisely.

What is the CMS-0057-F compliance deadline?

The API requirements take effect January 1, 2027 for Medicare Advantage organizations and state Medicaid and CHIP fee-for-service programs; the first rating period on or after January 1, 2027 for Medicaid and CHIP managed care; and the first plan year on or after January 1, 2027 for QHP issuers on the FFEs. Operational requirements (decision timeframes, specific denial reasons, and metrics reporting) took effect in 2026.

Which APIs does the rule require?

Four FHIR APIs: the enhanced Patient Access API (now including prior authorization information), the Provider Access API, the Payer-to-Payer API, and the Prior Authorization API. All prior authorization provisions exclude drugs.

Are the Da Vinci implementation guides mandatory?

No. CMS mandates API capabilities, not specific implementation guides. The Da Vinci CRD, DTR, and PAS guides are recommended and widely adopted because they make the Prior Authorization API work with provider EHRs at scale. But conflating "recommended" with "required" leads to over-scoped projects, and ignoring them leads to APIs providers can't use.

What decision timeframes apply to prior authorization?

72 hours for expedited requests and 7 calendar days for standard requests, with a specific reason required for every denial. These took effect in 2026.

Can this be built on Azure Health Data Services?

Yes. AHDS provides a managed FHIR R4 service that anchors the required APIs, with Azure integration services handling prior authorization workflow, consent, attribution, validation, and audit. That stack is our specialty, and our reference pipeline is public on GitHub.

We already have a vendor. Why bring in Interoplix?

Because your vendor grades their own homework. An independent assessment validates that what was delivered actually satisfies the rule before CMS, a state Medicaid agency, or your members find the gaps for you. If the build is solid, you get documented evidence of readiness; if it isn't, you get a prioritised remediation plan while there's still time to act.

Months, not years, to the deadline.

A readiness assessment takes weeks, not quarters. Book a 30-minute call and we'll tell you honestly whether you need one, or email Joel directly at joel@interoplix.com.

Book a 30-minute call →