All services

Prior authorization: the write-off that started as a scheduling problem.

A missing or lapsed authorization is one of the only denials a practice usually cannot bill the patient for, which makes it the most expensive category of avoidable loss in the revenue cycle. The fix runs entirely before the appointment, never after.

Key takeaways

  • An unauthorized service is usually a full write-off, not a receivable. Most contracts treat the missing authorization as the practice's failure, so the patient cannot be billed for it.
  • Requirements are payer- and code-specific. The same procedure can need authorization from one plan and none from another, so a single shared checklist does not work.
  • An approval has an expiration date and a visit count. Care delivered after either limit is exceeded is treated the same as care delivered with no authorization at all.
  • A peer-to-peer review is usually faster than a written appeal. Request it immediately on denial; most payers set a short window to ask for one.

Why this sits upstream of billing, not inside it

Prior authorization is decided before the service is delivered, which means every failure here is locked in before a claim is ever generated. A biller who does everything else correctly, clean coding, accurate modifiers, a well-scrubbed claim, still cannot recover a service that required authorization and never got it. That is what makes this a scheduling and intake discipline first, and a billing discipline second: the work that actually prevents the loss happens days before the appointment, not after the remittance arrives.

The second reason this category is expensive is that it is frequently invisible until it is large. A single missed authorization is one denied claim. A workflow that does not track approval expiration dates and visit counts against the schedule accumulates lapses quietly across every recurring-visit patient in the practice, and the pattern usually surfaces only when someone reconciles a quarter of denials and finds the same root cause repeated dozens of times.

How prior authorization typically works across major payer types. Confirm current requirements and turnaround times directly with each payer, since both change.
Payer typeHow requirements are typically checkedTypical turnaroundWhat differs most
Traditional MedicareA defined, published list of services requiring prior authorization, checked against the current CMS listVaries by program; expedited review available for urgent needFar fewer services require it than commercial or Medicare Advantage plans
Medicare AdvantageEach plan publishes its own authorization list, generally broader than traditional Medicare'sPlan-specific; CMS has pushed toward faster, more standardized decision timeframes in recent yearsRequirements vary by plan even within the same insurer's product lines
Commercial payersChecked through the payer's provider portal (many run on shared platforms such as Availity) or by phoneCommonly a few business days standard, 24–72 hours expeditedCode-specific and updated on the payer's own schedule, sometimes with little notice
Medicaid (state-administered)State-specific portal or clearinghouse; managed-care Medicaid plans often layer their own requirements on topSet by the state; can be markedly slower than commercial timeframesRules differ by state and, within a state, by managed-care plan

The workflow, step by step

  1. 1Eligibility and requirement check. Confirm active coverage and look up whether the specific CPT/HCPCS code and diagnosis require authorization under that plan, before the visit is scheduled, not after.
  2. 2Documentation assembly. Gather the clinical notes, orders and medical-necessity justification the payer's own policy asks for, since a generic submission is the most common reason for an avoidable delay.
  3. 3Submission with tracking. File through the payer's required channel, portal, fax or phone, and log a reference number immediately, not after confirmation arrives.
  4. 4Proactive follow-up. Check status on a fixed schedule (commonly every 48–72 hours) rather than waiting for the payer to respond, since silence is not the same as approval.
  5. 5Peer-to-peer coordination. On denial, request a peer-to-peer review immediately and prepare the ordering physician for the call, rather than defaulting straight to a written appeal.
  6. 6Authorization tracking to expiration. Log the approval number, the visit count authorized and the expiration date against the actual schedule, and flag it before either limit is reached.
Pro tip

Ask about gold-carding for your highest-volume authorization-dependent procedures. A growing number of states and payers now exempt providers from prior authorization on specific services once they have demonstrated a consistently high approval rate over time. The criteria and covered services are entirely payer- and state-specific, so it takes a direct check against your own payer mix rather than an assumption that it applies, but for a practice doing the same handful of procedures at volume, it can remove the authorization step for those services entirely.

Common mistakes that turn into denials

Where prior authorization workflows break down, and what prevents each one.
MistakeWhy it happensPrevention
Authorization obtained for the wrong codeThe order changed after authorization was requested, and nobody re-checkedRe-verify authorization whenever the ordered code or diagnosis changes, not just at initial scheduling
Visit count exceeded mid-courseAn authorization approved a fixed number of visits, and nobody tracked the running count against the scheduleTrack authorized visits remaining the same way a bank account balance is tracked, not as a one-time approval
Authorization expired before the service was deliveredScheduling delays pushed the appointment past the approval windowCalendar the expiration date against the actual appointment date, not the date the authorization was requested
Peer-to-peer window missedThe denial letter sat unread, or the request was treated as a low priorityRoute every authorization denial to a named owner the same day it arrives
Assumed no authorization was neededThe practice used a rule of thumb instead of checking the specific plan's current policyCheck payer-specific requirements per code, every time, policies change without much notice

Do and don't

Do
  • Check authorization requirements before scheduling, per payer and per code.
  • Track every approval's visit count and expiration date against the actual calendar.
  • Request a peer-to-peer immediately on denial, before considering a written appeal.
  • Re-verify authorization whenever the ordered service changes.
  • Check whether gold-carding applies to your highest-volume authorization-dependent procedures.
Don't
  • Don't assume a service doesn't need authorization because it didn't last year.
  • Don't treat an approval as open-ended; every one has a limit.
  • Don't deliver care and hope authorization "should" apply retroactively.
  • Don't let a denial letter sit before requesting peer-to-peer review.
  • Don't rely on memory for payer-specific requirements; check the current policy.

Frequently asked questions

How long does prior authorization actually take?

It varies by payer and by whether the request is standard or expedited. Commercial plans commonly decide standard requests within a few business days and expedited requests within 24 to 72 hours, but the only reliable number is the one published in that specific payer's current policy, since timeframes are revised periodically and are sometimes governed by state prompt-authorization laws layered on top of the payer's own standard.

What is a peer-to-peer review and when do we ask for one?

A peer-to-peer is a direct conversation between the ordering physician and the payer's reviewing physician after an initial denial, usually the fastest path to reversing a medical-necessity denial without a full written appeal. Request it as soon as the denial letter arrives rather than waiting to exhaust other options, since most payers set a deadline for requesting it.

What is gold-carding and does it apply to us?

Gold-carding programs exempt a provider from prior authorization for specific services once that provider has demonstrated a consistently high approval rate over a defined period, and a growing number of states and payers have adopted some version of it. Eligibility criteria, the services covered and the renewal process are entirely payer- and state-specific, so check your own payer mix rather than assuming the exemption applies broadly.

Can a patient be billed if we deliver care without authorization?

Usually not. Most payer contracts treat a missing authorization as the practice's administrative failure rather than the patient's responsibility, which makes it a full write-off rather than a collectible balance. An Advance Beneficiary Notice, where applicable and signed in advance, is one of the few ways to shift that risk to the patient for Medicare-related denials.

Do you handle prior authorization as part of your service?

Yes. We run eligibility and authorization requirements before scheduling, submit and track every request to its expiration date, and prepare providers for peer-to-peer review when a request is denied, so authorization delays stop showing up as denied claims weeks later.

Chasing prior authorizations instead of running your schedule?

We will review your current authorization workflow, identify where approvals are lapsing or being missed, and show what it's costing.

Book a free claims review

Related resources