CMS 2026 prior authorization rules apply to specified impacted payers and medical items or services excluding drugs. The CMS final-rule fact sheet sets 72 hours for expedited decisions and seven calendar days for standard decisions for impacted payers other than QHP issuers on Federally-facilitated Exchanges, while all impacted payer classes must supply a specific denial reason. ABA teams should verify the product and route first.

Identify an impacted payer before starting a clock

CMS's current FAQ index identifies Medicare Advantage organizations, state Medicaid and CHIP fee-for-service programs, Medicaid managed care plans, CHIP managed care entities, and QHP issuers on Federally-facilitated Exchanges. Commercial employer plans outside those classes do not enter the rule simply because they use prior authorization. Record program, product, legal entity, service, drug exclusion, submission route, receipt event, and governing citation.

Qualify every queue row before measuring it. Confirm the coverage date, payer class, exact product, request type, medical-item or service scope, submission method, and source version. Keep an excluded or unresolved row visible in a separate state with its reason. This prevents a mixed commercial and government-program queue from producing a persuasive but invalid compliance percentage.

Use the right 2026 process rule

CMS's announcement explains that the 72-hour expedited and seven-calendar-day standard limits apply to impacted payers other than QHP issuers on the FFEs. The specific-reason requirement reaches all impacted payer classes and applies regardless of submission method. Existing federal, state, contract, and notice duties can add shorter clocks or more detail, so the CMS rule is one layer in the record.

Define receipt and urgency evidence

A queue needs the payer-confirmed receipt time, request class, urgency basis, service, attachments, missing-information event, decision time, reason, notice recipient, and escalation owner. Preserve fax confirmations, portal receipts, API responses, call references, and returned transactions. If a payer changes the request class or claims the packet was incomplete, retain both positions and request the governing source in writing.

Use a clock ledger with one row for every material event. Record the submitting sender, receiving entity, timestamp and time zone, artifact or reference number, event meaning, unresolved question, and next action. Keep practice transmission, intermediary acceptance, payer receipt, request-for-information, decision, and notice as separate events. A portal success screen may prove upload while leaving payer receipt or completeness unresolved.

Urgency belongs to the request and source, not to a staff preference. Preserve the clinician's documented basis when clinical judgment is part of the applicable expedited route, plus any payer classification response. Operations can route and track the request. Qualified clinicians own clinical facts and do not alter them to fit a clock category.

Read metrics with their denominator

The CMS metrics template illustrates public reporting for prior authorization activity. A CMS 2026 prior authorization rules dashboard should keep standard and expedited requests separate, define the mature cohort, and distinguish approvals, denials, requests for more information, withdrawals, and unresolved cases. Public payer averages provide context. They do not establish the due date or likely result for one member.

A fictional clock audit

Leena's team predeclares 17 impacted, non-drug authorization requests whose decision clocks matured in July. Fourteen have a matched receipt, request class, decision time, specific outcome, and written reason when denied. Evidence completeness is 14 of 17, or 82.4%. The other three remain in the denominator with owners and ages. The result measures the practice record, not payer compliance or authorization quality.

The team reports timeliness separately only after it verifies the start event and due rule for each row. It also separates standard from expedited requests. A record can be evidence-complete and late, timely and poorly documented, or unresolved at the cutoff. Those states answer different operational questions.

Keep the process rule separate from the case decision

A decision clock and specific denial reason support transparency. Coverage, medical necessity, clinical appropriateness, authorization scope, appeal rights, continuity, claim acceptance, and payment still depend on the governing program, benefit, request, and notice. Store the payer's reason exactly, then route clinical questions to the qualified clinician and procedural questions to the applicable payer, program, compliance, or legal owner.

Review the written notice for the decided service, dates, units or scope, cited basis, effective date, appeal route, deadline, representation rules, continuation conditions, and accessible contact method. The CMS process rule supplies a federal layer. The person's actual next step comes from the complete source record.

Escalate from the source record

When the verified clock expires, contact the payer through the designated channel, preserve the reference number, and use the notice, contract, regulator, or program escalation route that applies. An ABA clinician supplies clinical evidence within scope. Operations manages timestamps and routing. Legal or compliance owners interpret conflicts. Software may calculate elapsed time after the start event is verified, while qualified people choose the response.

Related resources

Sources