Interoplix gives Medicare Advantage, Medicaid, CHIP, and exchange payers an independent, engineering-level readiness assessment of their CMS-0057-F implementation on Azure, and the hands-on remediation to close the gaps before January 1, 2027.
The regulation
The CMS Interoperability and Prior Authorization Final Rule (CMS-0057-F) requires impacted payers to implement and maintain four HL7 FHIR APIs. The compliance date depends on payer type, and the operational provisions are already live.
| Payer type | API compliance date |
|---|---|
| Medicare Advantage organizations | January 1, 2027 |
| State Medicaid & CHIP fee-for-service programs | January 1, 2027 |
| Medicaid managed care plans & CHIP managed care entities | First rating period on or after January 1, 2027 |
| QHP issuers on the Federally Facilitated Exchanges | First plan year on or after January 1, 2027 |
Source: CMS Interoperability and Prior Authorization Final Rule (CMS-0057-F), finalized January 2024. Prior authorization provisions exclude drugs.
The requirements
Every API in the rule carries requirements that don't show up in a demo but do show up in an audit: consent handling, attribution accuracy, data completeness, and decision communication.
The API required since CMS-9115-F must now also expose prior authorization information (status, decisions, and related data) so members can see what was approved, denied, and why. Annual usage metrics reporting to CMS began in 2026.
In-network providers with a treatment relationship retrieve claims, encounters, USCDI data, and prior authorization information, individually and in bulk. Hinges on accurate patient attribution and a working opt-out process.
When a member changes plans, the previous payer shares up to five years of claims, encounter, USCDI, and prior authorization data. Requires a patient opt-in process and plain-language member education materials.
Providers check whether an item or service needs authorization, see documentation requirements, submit electronically, and receive a structured decision: approved with an end date, denied with a specific reason, or a request for more information.
How Interoplix helps
Most CMS-0057-F content is written by platform vendors selling software. Interoplix is an independent FHIR and HL7 integration practice: we assess what you have, whether vendor-built or in-house, and build what's missing on Azure Health Data Services. Published rates, scoped deliverables.
API-by-API gap analysis against the final rule: FHIR conformance, prior auth workflow, consent and opt-in/opt-out handling, attribution, metrics reporting, and HIPAA posture. Written findings with a prioritised remediation roadmap your team or vendor can execute.
Hands-on build on Azure Health Data Services: FHIR R4 services, prior authorization workflow integration, validation gates that stop bad data before write, CI/CD, and infrastructure as code, all reproducible and auditable.
Ongoing architecture guidance through the deadline and beyond: vendor oversight, code and design review, metrics reporting readiness, and escalation coverage when integration incidents hit production.
Why an independent specialist
Read: What compliance review actually looks like in 2027 →
Common questions
The API requirements take effect January 1, 2027 for Medicare Advantage organizations and state Medicaid and CHIP fee-for-service programs; the first rating period on or after January 1, 2027 for Medicaid and CHIP managed care; and the first plan year on or after January 1, 2027 for QHP issuers on the FFEs. Operational requirements (decision timeframes, specific denial reasons, and metrics reporting) took effect in 2026.
Four FHIR APIs: the enhanced Patient Access API (now including prior authorization information), the Provider Access API, the Payer-to-Payer API, and the Prior Authorization API. All prior authorization provisions exclude drugs.
No. CMS mandates API capabilities, not specific implementation guides. The Da Vinci CRD, DTR, and PAS guides are recommended and widely adopted because they make the Prior Authorization API work with provider EHRs at scale. But conflating "recommended" with "required" leads to over-scoped projects, and ignoring them leads to APIs providers can't use.
72 hours for expedited requests and 7 calendar days for standard requests, with a specific reason required for every denial. These took effect in 2026.
Yes. AHDS provides a managed FHIR R4 service that anchors the required APIs, with Azure integration services handling prior authorization workflow, consent, attribution, validation, and audit. That stack is our specialty, and our reference pipeline is public on GitHub.
Because your vendor grades their own homework. An independent assessment validates that what was delivered actually satisfies the rule before CMS, a state Medicaid agency, or your members find the gaps for you. If the build is solid, you get documented evidence of readiness; if it isn't, you get a prioritised remediation plan while there's still time to act.
A readiness assessment takes weeks, not quarters. Book a 30-minute call and we'll tell you honestly whether you need one, or email Joel directly at joel@interoplix.com.
Book a 30-minute call →