On January 1, 2027, prior authorization will not suddenly become automatic.
Something real will happen: CMS-regulated health plans must begin supporting standardized electronic APIs for medical prior authorization. Decision-time requirements have already tightened, seven days for standard requests, seventy-two hours for urgent. Major payers, EHR vendors, and health systems are actively building toward electronic workflows. This is genuine progress, and it’s worth rooting for.

But walk into a specialty practice today.
One person is checking tomorrow’s patients in a payer portal. Another is tracking an imaging authorization that’s been pending for nine days. A third is faxing a primary care office for a missing HMO referral, then typing the result back into an EHR that wasn’t natively connected to any of it.
That is the part of prior authorization the API does not solve by itself.
The next few years won’t be a clean switch from “manual” to “electronic.” They’ll be a transition into a hybrid authorization environment, where APIs, payer portals, fax, phone, clinical documentation, and provider-to-provider referrals all coexist. The practices that prepare for that reality will have a real operational advantage. The ones waiting for January 1 to flip a switch will be waiting a long time.
The gap between the announcement and the practice
The American Medical Association’s May 2026 survey of practicing physicians found that only one in three believe the latest insurer reforms will make a meaningful difference, while 95% say prior authorization still delays access to necessary care. The reforms are real; the relief hasn’t reached the exam room yet.
MGMA, which supported the reforms, has been candid that the 2025 industry pledge is voluntary, with no accountability or reporting mechanism behind it, and has pointed out that many of the same principles appeared in a 2018 consensus statement, after which prior authorization remained practices’ most-cited administrative burden. Good intentions, signed twice, haven’t yet changed the daily workload.
And prior authorization isn’t shrinking — in some corners, it’s expanding. In 2026, CMS launched the WISeR Model in Arizona, New Jersey, Ohio, Oklahoma, Texas, and Washington. For selected Original Medicare services, providers may submit prior authorization in advance or, if they don’t, face pre-payment medical review. This does not mean all of Original Medicare is moving to prior authorization. But it is a clear signal that authorization and medical-review requirements are evolving rather than disappearing — with implications across multiple specialties, including pain management, where selected services such as electrical nerve stimulator implants are within the model’s scope.
The readiness gap worth understanding
Here’s the part that reframes the whole 2027 conversation — and it’s genuinely encouraging in some ways, if you know what to plan for.
In 2026, CMS convened an early-adopter coalition to accelerate electronic prior authorization, and the commitment behind it is real: the major ambulatory EHRs, the largest national payers, and several leading health systems have all joined. The industry is moving in the right direction, and that momentum matters.
At the same time, it helps to understand what “early adopter” means at this stage, so practices can plan realistically. That coalition exists, in CMS’s own framing, to identify and work through the workflow, technical, and operational details that come with a change this large — the right way to approach it, and also a sign that meaningful work remains. The organizations piloting these flows today are largely big health systems with dedicated integration teams, not independent specialty practices. And the rule requires payers to offer the APIs; it encourages, rather than requires, providers to adopt them, and it recommends rather than mandates the specific workflow standards that make the technology usable inside an EHR. Each payer-EHR pairing will come online at its own pace.
CMS is deliberately giving provider adoption room to mature. Beginning with the 2027 performance period, eligible clinicians can satisfy the new electronic prior authorization measure by attesting that they submitted at least one qualifying medical authorization electronically through the new API workflow. That’s an important starting point — and it also illustrates how far the industry still has to go before every specialty authorization runs electronically from end to end. The distance between “submit one electronically” and “run every authorization this way” is exactly where the day-to-day burden still lives.
Even the most recognized electronic prior authorization deployments so far remain targeted collaborations among specific payers, EHRs, and provider organizations. That progress is meaningful — but it’s very different from ubiquitous electronic coverage across every payer, specialty, service, and practice. What we see across our own customers is consistent with that: practices on the most modern EHRs are still, for now, working with many authorizations in payer portals rather than native electronic flows. The rails are being built. The daily workflow is still catching up, exactly what you’d expect this early in a transition of this scale.
The channel the rules don’t reach
There’s one category of work the 2027 rules weren’t designed to address, and it happens to be one of the heaviest in specialty care: the referral coordination between specialists and primary care.
Most HMO plans run on a gatekeeper model. The primary care physician authorizes specialist care, and a specialist can only see the patient, and be paid, when a referral is on file. So specialist offices spend enormous effort routing requests back to primary care: chasing a missing referral so a visit gets paid, moving referral numbers and records between two offices. Much of it still happens by fax.
CMS-0057-F modernizes payer–provider prior authorization. It does not, by itself, modernize every provider-to-provider referral workflow. For specialty practices, that means missing PCP referrals, records, and supporting documentation can stay manual even as payer APIs improve. Automation that only works on the modern payer channels leaves this loop — high-volume, provider-side, and structural to how HMOs operate — exactly where it’s always been.
The other side of the transaction
Health plans are also deploying increasingly sophisticated automation on their side of prior authorization — the large majority of health-plan leaders expect AI to add value here. That’s not a threat to fear; it’s a reason provider-side readiness matters more, not less. If the payer’s side of the conversation is getting faster and more automated, a practice still working authorizations by hand falls further behind.
The answer isn’t to reject automation. It’s to insist on the right kind, automation that is transparent, auditable, clinically grounded, and built to get complete, correct requests to the right destination faster. That standard matters for everyone in the system, providers and payers alike, because the shared goal is the same: getting patients to appropriate care without the delay.
What patients feel: knowing where things stand
There’s a dimension of prior authorization that rarely gets discussed, because the people who feel it most aren’t in the room when software is chosen: the patients.
Today, a patient waiting on authorization for imaging or a procedure usually has no idea where things stand. They were told they need a test; then they wait, with no visibility, sometimes calling the office to ask whether “the insurance thing” went through. The practice, buried in the work of chasing it, often can’t give a confident answer either. It’s one of the quietest sources of anxiety in specialty care.
The 2027 rules recognize this. The expanded Patient Access API is designed so that patients can see whether an authorization is pending, approved, or denied — with the reason, if denied. It’s a good direction. But it’s a payer-side view, arriving on the payer’s timeline, reflecting the plan’s record.
We think patients deserve that visibility sooner, and closer to their care. ColigoMed’s patient experience gives patients visibility into the benefit information and authorization status available to their practice — without another call to the front desk. For the patient, it turns an opaque wait into a clear one. It’s a small thing that patients notice immediately, precisely because no one has offered it to them before.
The five pillars of real prior authorization automation
Having spent the last few years building in this space, here’s the standard I believe every specialty practice should hold any technology to (ours included). Strip away the category labels – fax automation, API automation, voice AI, portal automation and ask one question instead: is the patient authorized and ready for care? Everything else is a means to that end.
Five tests separate automation that owns the outcome from automation that only works one channel. I’ll be direct about where we’ve focused ColigoMed against each — not because we’re the only option, but because these are the tests we built the product to pass.
- Does it know when authorization is required? Across every payer’s different rules, not one payer, not one specialty, and before a request is ever submitted. This is where generic tools fail first: they can submit, but they can’t tell you a submission is even needed. We built ColigoMed to make that determination across payers and specialties at the moment the order is placed, so nothing falls through and nothing gets submitted that didn’t need to be.
- Can it assemble the evidence? Pulling the right clinical documentation from the chart to satisfy this payer’s criteria for this service, rather than handing your staff a blank form. A determination is only useful if the request that follows is complete. ColigoMed assembles the payer-and procedure-specific evidence automatically, which is what turns a “yes, this needs auth” into a submission that actually gets approved the first time.
- Can it act through whatever channel the payer requires? API where it exists, portal where it doesn’t, fax and phone where the work still lives and referrals between offices, which no API covers. This is the heart of the hybrid reality, and it’s the design principle we’re proudest of: ColigoMed is channel-independent by architecture. It routes each request through whatever the payer actually uses today, and shifts to the new APIs as they come online, including the order-initiated referral fax to the PCP that the 2027 rules never touch.
- Can it close the loop inside the EHR? Writing coverage, patient cost, and authorization outcome back as structured data — not a transcript, a PDF, or another work queue. If a human still retypes the copay, the rekeying, and its errors, survive. ColigoMed writes the details back as discrete structured fields: coverage, cost share, network status, authorization outcomes, into the system your team already works in. That closed loop is what makes “touchless” literal rather than aspirational.
- Can it prove what it did? Complete action logs, human override, and clearly defined autonomy thresholds, so your team trusts the automation instead of double-checking it, which is no savings at all. We designed ColigoMed to run supervised before it runs autonomously, with every action logged and the level of autonomy set per payer and workflow by you, not us. In a moment when AI in healthcare is rightly under scrutiny, we think earned trust — not black-box speed — is the only foundation worth building on.
There’s a word for software that meets these tests rather than just summarizing information for a human to act on: agentic AI — software that takes a defined goal and executes a sequence of approved actions. In prior authorization, that means recognizing the order, determining requirements, collecting evidence, submitting through the appropriate channel, tracking the response, and escalating the true exceptions to a person — instead of presenting one more inbox for staff to work. Used responsibly, with the governance test above, that’s the difference between technology that removes work and technology that reshuffles it. It’s the difference we built ColigoMed around.
Specialty knowledge is the last test
A cardiology practice navigating the imaging-authorization gauntlet lives a different life than a pain management practice sequencing procedures, a pulmonology group managing sleep studies and biologics, or a GI practice authorizing infusions. The payers differ, the criteria differ, the denial patterns differ. Automation trained generically on “healthcare” breaks precisely where specialty care is most specific: which is exactly where the burden concentrates.
It’s why we didn’t build ColigoMed as a generic engine with a specialty label on it. We’re LIVE in cardiology, pulmonology, and pain management today, with each specialty’s payer rules, procedures, and denial patterns built in — and an architecture designed so the next specialty is a configuration, not a rebuild. That’s the bar. Whatever you evaluate, hold it to these tests: the outcome, the channels, the write-back, the auditability, and the specialty depth.
The bottom line
2027 will not eliminate prior authorization. It will create a new operating environment.
The practices that win won’t be the ones waiting for every payer and EHR connection to become perfect. They’ll be the ones that can work across both worlds at once — electronic APIs where they exist, portals and fax where they remain, and intelligent human escalation where judgment is required.
That’s the problem we’re building ColigoMed to solve: touchless eligibility and end-to-end, agentic prior authorization for specialty care — from the order, across every channel, to the approval written back in your EHR. Built to pass all five tests, and to prove it on your own data before you commit.
ColigoMed provides AI-driven eligibility verification and prior authorization automation for specialty medical practices. Learn more at coligomed.com.
Sources & Further Reading
Becker’s Payer Issues, “7 prior authorization updates for 2026” (Jan 26, 2026) — CVS real-time approval rates, Deloitte 93% AI survey, congressional hearings, WISeR pilot states, and 2026 state law changes. https://www.beckerspayer.com/payer/5-prior-authorization-updates-for-2026/
Becker’s Payer Issues, “Insurers’ prior authorization commitments, 1 year in” (Jul 2026) — AMA finding that physicians haven’t felt the pledged reforms; 72-hour/7-day decision clocks; first-ever public payer PA metric reporting; CMS pledge expansion to providers and EHR vendors. https://www.beckerspayer.com/policy-updates/insurers-prior-authorization-commitments-1-year-in/
MGMA, “The Prior Authorization Landscape in 2025” — AHIP pledge commitments and timelines, the voluntary/no-accountability critique, and the 2018 consensus statement precedent. https://www.mgma.com/articles/the-prior-authorization-landscape-in-2025
MGMA, “Modifying workflows and embracing automation help practices, patients” — member reports of expanding PA requirements, including tiered/closed-network plans, infusions, and generic drugs. https://www.mgma.com/articles/modifying-workflows-and-embracing-automation-help-practices-patients
Undark Magazine, “Will AI Fix Prior Authorization — or Make It Worse?” (Jul 15, 2026) — WISeR vendors’ share of “averted expenditures” and the 11% decline in PA requests (Jun 2025–Apr 2026) with unknown denial-rate impact. https://undark.org/2026/07/15/medicare-prior-authorization-ai/
Becker’s Payer Issues, “4 recommendations to bring oversight to AI-driven prior auth: MACPAC” (May 2026) — MACPAC transparency recommendations for Medicaid PA automation and AI use. https://www.beckerspayer.com/payer/medicaid/4-recommendations-to-bring-oversight-to-ai-driven-prior-auth-macpac/
National Health Law Program, “Federal AI Policy Threatens Prior Authorization Reform” (Jan 2026) — patient-advocate perspective on AI-enabled PA becoming a de facto standard ahead of regulation. https://healthlaw.org/federal-ai-policy-threatens-prior-authorization-reform/
CMS, Interoperability and Prior Authorization Final Rule (CMS-0057-F) — FHIR-based PA API requirements (Jan 1, 2027) and decision timeframe provisions. https://www.cms.gov/newsroom/fact-sheets/cms-interoperability-prior-authorization-final-rule-cms-0057-f



