Healthcare Interoperability
What Does the CMS Interoperability Rule Require?
The rule sets API, timeframe, and reporting duties for payers. If AI touches prior authorization or data exchange, it also sets the bar for audit trails and human review. Kriv AI helps regulated teams meet that bar.
The CMS Interoperability and Prior Authorization final rule (CMS-0057-F) requires impacted payers to run standardized APIs for patients, providers, and other payers, and to answer prior authorization requests within 72 hours for urgent cases and seven calendar days for standard ones. Operational provisions start in 2026; the APIs are due by January 1, 2027.
context
What the Rule Requires of Payers
CMS finalized the Interoperability and Prior Authorization rule, CMS-0057-F, in January 2024. Its stated aim is to "improve health information exchange to achieve appropriate and necessary access to health records" and to improve prior authorization processes through policy and technology.
Who is covered
CMS's fact sheet lists the impacted payers as "Medicare Advantage (MA) organizations, state Medicaid and Children's Health Insurance Program (CHIP) Fee-for-Service (FFS) programs, Medicaid managed care plans, CHIP managed care entities, and Qualified Health Plan (QHP) issuers" on the federally facilitated exchanges. Providers are not the regulated party for the payer duties below.
The four APIs
The rule centers on four application programming interfaces. The Patient Access API must add prior authorization information, excluding drugs, to the data patients can reach. A Provider Access API shares patient data with in-network providers. A Payer-to-Payer API makes claims and encounter data available when a patient changes plans. A Prior Authorization API is populated with the payer's list of covered items and services and supports electronic prior authorization requests.
CMS also names the technical standards: "HL7 FHIR Release 4.0.1" and the "HL7 FHIR US Core Implementation Guide (IG) Standard for Trial Use (STU) 3.1.1." Drugs are excluded from the prior authorization API requirements.
Prior authorization timeframes, reasons, and reporting
Impacted payers must "send prior authorization decisions within 72 hours for expedited (i.e., urgent) requests and seven calendar days for standard (i.e., non-urgent) requests." They must also "provide a specific reason for denied prior authorization decisions, regardless of the method used," and "publicly report certain prior authorization metrics annually by posting them on their website."
Key dates
CMS states that "impacted payers must also implement certain operational provisions, generally beginning January 1, 2026," and that "impacted payers have until primarily January 1, 2027, to meet the application programming interface (API) requirements." Check the CMS pages cited below for the current text before you plan against a date.
capabilities
What It Means for Providers
Electronic prior authorization reporting
CMS states that "MIPS eligible clinicians will report the Electronic Prior Authorization measure beginning with the Calendar Year (CY) 2027 performance period/CY 2029 MIPS payment year and eligible hospitals and CAHs beginning with the CY 2027 EHR reporting period." The measure asks clinicians to request a prior authorization electronically through a Prior Authorization API, using certified EHR technology, for at least one medical item or service, excluding drugs.
Payer versus provider, in short
Payers carry the API, timeframe, denial-reason, and public reporting duties. Providers and hospitals are affected through the electronic prior authorization reporting measure and through the faster, more structured data their payers must expose.
ai gap
Where AI Governance Comes In
The rule does not mention AI as a requirement. But the places where it shortens timelines and demands specific denial reasons are the same places teams reach for AI: triaging prior authorization requests, summarizing clinical documentation, mapping data into FHIR resources, and watching interfaces for failures. When AI sits in those steps, the rule's duties become governance questions.
A 72-hour or seven-day clock means an AI-assisted workflow needs a defined human review step for adverse or ambiguous outcomes, not only a fast one. A required denial reason means the system must keep a reviewable record of what a decision was based on. Public metrics mean the data behind them must be traceable. API traffic across payers, providers, and patients means interface monitoring with alerting when mappings or volumes drift.
In practice that comes down to an audit trail of each AI-assisted step, human approval before an adverse decision issues, role-scoped access to protected health information, and ongoing monitoring of the models and interfaces involved. See our pages on healthcare AI interoperability governance and AI governance for health plans and payers for how we approach each.
differentiation
Where This Page Fits Among Our Other Pages
This page explains what the rule requires. For the FHIR interface monitoring side, see our healthcare AI interoperability governance page. For payer-specific governance work, see AI governance consulting for health plans and payers. For audit readiness on the provider side, see our HIPAA AI audit readiness checklist for health systems, and for decision records, our guide to auditing an AI agent's decisions in a clinical setting.
engagement
How an Engagement Works
A scoped engagement usually starts by mapping where AI or automation touches prior authorization, data exchange, or member and provider communications. We then design review points, audit logging, and monitoring for those steps, test them against your own policies and the rule's published requirements, and hand over controls your compliance and technology teams can run. We do not give legal advice and do not resell any vendor's product, so confirm obligations with counsel and the CMS pages.
tiers
What You Get at Each Tier
1. Enterprise / regulated (health plans, health systems)
Mapping of AI and automation in prior authorization and data exchange, audit trail and human review design, and monitoring for the workflows in scope.
2. Fractional CTO / AI governance lead
Ongoing ownership of the AI governance program as deadlines and CMS guidance change, and review of new AI use cases against it.
3. Specialized advisory
A single session or second opinion on whether a proposed AI-assisted prior authorization workflow has adequate controls.
rate card
Kriv AI's Rates for This Work
These are Kriv AI's own published rate floors, not an industry average.
| Track | Kriv hourly rate | Typical engagement model | Minimum engagement |
|---|---|---|---|
| Enterprise / regulated (banks, broker-dealers, payment processors) | From $200/hr | Fixed-scope project or retainer | $8,000 |
| Fractional CTO / AI governance lead | $300 to $400/hr | Part-time, ongoing (monthly) | $8,000 |
| Specialized advisory (vendor evaluation, second opinion) | $400 to $700/hr | Hourly, per-session | Varies by engagement |
| Small business | $150/hr | Referred to Kriv AI's partner network | n/a |
get a quote
How to Get a Real Quote
The rates above are floors, not a quote. Actual price depends on which payer or provider workflows are in scope, which systems the AI touches, and how much logging and human review already exists. Book a discovery call and we will scope it honestly.
Straight answers
Frequently asked questions about What Does the CMS Interoperability Rule Require?
What does the CMS Interoperability and Prior Authorization rule require?
Impacted payers must implement Patient Access, Provider Access, Payer-to-Payer, and Prior Authorization APIs, meet prior authorization decision timeframes, give a specific reason for denials, and publicly report certain prior authorization metrics.
Who does the rule apply to?
CMS lists Medicare Advantage organizations, state Medicaid and CHIP fee-for-service programs, Medicaid managed care plans, CHIP managed care entities, and Qualified Health Plan issuers on the federally facilitated exchanges.
What are the prior authorization decision timeframes?
72 hours for expedited requests and seven calendar days for standard requests, according to CMS.
When do the requirements start?
CMS says operational provisions generally begin January 1, 2026, and impacted payers have until primarily January 1, 2027 to meet the API requirements.
Does the rule require AI governance?
No. The rule does not require AI. But where AI supports prior authorization or data exchange, the timeframes, denial reasons, and reporting create a need for audit trails, human review, and monitoring.
What does this cost with Kriv AI?
Kriv AI's rates start at a $200/hr floor for enterprise and regulated work, with an $8,000 minimum engagement. Specialized advisory runs $400 to $700/hr.
Talk to the team that would do the work
Bring your requirements to a working session with the person who'll actually deliver.
Book a Discovery Call