CMS-0062-P: Drug Prior Authorization Moves Toward Faster, More Transparent Workflows

- September 22, 2026

Gina Collins

Chief Regulatory Officer

Autonomize AI’s perspective on the implications of the proposed rule for pharmacy management companies.

This paper reflects the proposed rule publicly available in CMS materials as of September 19, 2026. It is intended for strategic and operational planning and is not legal advice. Requirements, scope, and dates may change when CMS issues a final rule.

Executive Summary

The 2026 CMS Interoperability Standards and Prior Authorization for Drugs Proposed Rule (CMS-0062-P) may change before it is finalized, but the direction is clear: drug prior authorization is moving toward faster timelines, electronic workflows, greater transparency, and clearer explanations. Pharmacy management companies should begin connecting technical standards with benefit configuration, clinical criteria, evidence, decisions, communications, and reporting. Leaders can prepare by mapping requirements, evaluating denial quality, tracing cases end to end, clarifying client responsibilities, and prioritizing changes that support compliance while reducing costs and provider burden. AI can strengthen these workflows when it is grounded in approved policies, fully traceable, and accountable to human reviewers.

The Next Phase of Prior Authorization Is About Usable Answers

Electronic prior authorization has traditionally been framed as a way to replace phone calls, faxes, portals, and manual data entry. CMS-0062-P points toward a broader objective: making the response, not only the transaction, more timely, transparent, and useful to prescribers and patients.

This shift matters for pharmacy management companies at every level of technical maturity. Some may already exchange requests electronically but still rely on fragmented policy sources, broad denial language, or manual notice preparation. Others may have strong clinical processes but limited ability to expose requirements electronically or measure performance consistently. The starting points differ, but the desired outcome is the same: a timely, traceable, and understandable process.

What CMS is Proposing

Published April 14, 2026, CMS-0062-P builds on the 2020 interoperability rule and the 2024 CMS-0057-F final rule. CMS-0057-F addressed prior authorization for non-drug items and services; CMS-0062-P would bring drugs more fully into the same policy direction. The public-comment period closed June 15, 2026. As of September 19, 2026, the broader drug prior-authorization proposals have not been finalized, so dates and details may change in a final rule.

The proposed status of the rule should shape implementation decisions, but it should not become a reason for inaction. Federal interoperability requirements, rising transparency expectations, and increasing state oversight are converging around more measurable, electronic, and explainable pharmacy processes.The final mechanics may shift, but the pressure to modernize is unlikely to recede.

Pharmacy-Benefit Drugs

State Medicaid and CHIP fee-for-service programs, Medicaid managed care plans, CHIP managed care entities, and QHP issuers on the Federally-facilitated Exchanges would support applicable, unexpired versions of the NCPDP SCRIPT, Formulary & Benefit, and Real-Time Prescription Benefit standards. Medicare Part D already operates under electronic prescribing requirements, and the proposal seeks greater alignment across programs.

Medical-Benefit Drugs

Impacted payers would incorporate coverage and documentation requirements for medical-benefit drugs into the FHIR-based Prior Authorization API established under CMS-0057-F.

Specific Denial Reasons

For all drugs, the affected Medicaid, CHIP, and FFE QHP payers would provide the requesting provider a specific reason for denial, regardless of how the request or decision was transmitted.

Decision Timeframes

The proposal would align or clarify drug decision timeframes across affected programs. For FFE QHPs, the proposed maximum is 72 hours for standard drug requests and 24 hours for expedited requests. Medicaid covered outpatient drug requests generally already operate under a 24-hour requirement; CMS seeks to close remaining gaps.

Transparency and Measurement

Impacted payers would publicly report drug prior authorization metrics and submit expanded API usage metrics, increasing visibility into approvals, denials, timeliness, appeals, and electronic adoption.

Proposed Implementation Timeline

October 1, 2027: Proposed compliance date for most drug ePA, specific denial reason, decision timeframe, and updated interoperability requirements.

Beginning in 2028: Proposed reporting begins for drug PA and expanded API metrics, generally using 2027 data; exact deadlines and reporting levels vary by payer type.

Who is Affected?

The direct regulatory obligations vary by program. They principally reach state Medicaid and CHIP programs, Medicaid and CHIP managed care entities, FFE QHP issuers, and Medicare Advantage organizations and other payers already covered by CMS interoperability rules (through medical-benefit drug API requirements).

Pharmacy management companies, PBMs, utilization management vendors, specialty pharmacy partners, and technology platforms may not always be the named regulated entity. Operationally, however, many perform the functions the payer must rely on: maintaining formularies and criteria, accepting requests, orchestrating clinical review, generating responses, operating transaction connections, and producing metrics. Client contracts, delegation structures, service level agreements, and audit rights will therefore translate payer obligations into vendor requirements.

Large and small organizations should expect the same client question: Can you show, at the individual request level, which requirement applied, what information was evaluated, why the outcome occurred, what was communicated, when it was communicated, and whether the data appeared correctly across every channel?

What Implementation Will Require

Implementing the proposed rule will require organizations to connect transaction standards, policy content, clinical workflows, communications, and measurement across products and clients that may operate very differently today.

Two Technical Pathways

Pharmacy-benefit drugs would rely principally on NCPDP standards, while medical-benefit drugs would flow through FHIR-based APIs. Organizations that support both benefits must coordinate two standard ecosystems without creating two disconnected operating models.

Benefit and Ownership Boundaries

The same drug may be managed differently depending on benefit design, site of care, route of administration, payer product, and delegated arrangement. Correctly identifying the benefit, responsible entity, applicable workflow, and source of truth must happen early and consistently.

Policy and Client Variability

Formularies, utilization management criteria, documentation requirements, exceptions, and notice language often vary by client and line of business. Turning that variation into current, machine-usable content with effective dates, version control, and clear ownership will be substantial work.

Data and Attachment Readiness

Electronic submission does not guarantee complete or usable clinical information. Organizations must determine what information is required, accept structured data and attachments, reconcile conflicting content, and identify gaps without generating unnecessary requests to providers.

Governed Decision Support

Policies, formularies, and clinical criteria must come from approved sources with clear ownership, effective dates, and version control. Every decision should remain traceable to the evidence evaluated and the criteria applied.

Complete Auditability

Organizations must retain the source data, policy and formulary versions, generated summaries, reviewer actions and edits, final communications, and relevant timestamps associated with each case.

Workflow and Timeframe Orchestration

Short decision windows require more than a transaction connection. Intake, classification, clinical routing, outreach, review, escalation, and communication must operate against the correct clock, including expedited cases and exceptions.

Consistency Across Channels and Partners

A request may touch an EHR, transaction network, PBM platform, portal, clinical review vendor, call center, and correspondence system. Status, rationale, timestamps, and next steps must remain consistent across those handoffs.

Compliance Reporting

Public reporting and API metrics require stable definitions, reliable numerator and denominator logic, traceable source data, and reconciliation across operational systems. Many organizations will need to improve data capture before they can confidently report results.

End-to-End Testing and Change Management

Readiness depends on payers, providers, EHRs, transaction intermediaries, vendors, and client teams, not just one organization alone. Testing representative drugs, benefits, request types, failure paths, and downstream notices will require coordinated implementation and sustained operational training.

These challenges will look different by organization. A large PBM may have mature transaction capabilities but face significant integration, client configuration, and cross-channel consistency work. A smaller pharmacy management company may have fewer legacy platforms but need foundational standards expertise, data discipline, and partner support. The appropriate roadmap should reflect starting maturity while working toward the same outcome: a timely, traceable, and understandable process.

Why Clear Denial Reasons Are Particularly Difficult

Within that broader implementation, the requirement for a specific denial reason deserves particular attention. CMS says the reason should help the provider understand why the request was denied and what action is needed to resubmit or appeal. Examples include the applicable plan coverage criterion, why the submitted documentation did not support the requested drug, or why the drug was not considered necessary. Generic language such as “criteria not met,” “not medically necessary,” or “insufficient information” rarely gives the provider enough information to correct, resubmit, or appeal the request.

Producing a clear reason consistently is difficult because the explanation sits at the intersection of several systems and judgments:

  • The correct benefit, formulary, client configuration, diagnosis, drug, dose, route, and line of therapy must be identified.

  • Missing information must be distinguished from information that was present but did not support a requirement.

  • The same rationale must survive translation across NCPDP transactions, portals, letters, call center views, and downstream reporting.

  • The operative criterion and its version must be linked to the evidence actually submitted, not reconstructed after the fact.

  • The explanation must be clinically accurate, understandable, actionable, and consistent with appeal rights and governing notice rules.

  • Automation must not overstate what the record shows or create a rationale the reviewer did not adopt.

This is why a denial-reason library alone is insufficient. The organization needs a governed chain from policy to evidence to reviewer outcome to communication. The quality test is whether a provider can understand the gap and take the appropriate next step without another avoidable call or submission.

Where AI-Enabled Workflows Can Create Value

AI can reduce friction when it operates within defined pharmacy workflows, uses approved sources, and preserves human accountability. Its most defensible near-term role is not making autonomous coverage determinations. It is helping people and systems route requests, organize evidence, apply the correct context, draft communications, identify inconsistencies, and monitor performance more reliably. 

The most relevant workflows include:

Intelligent Benefit Routing

Use drug, route of administration, site of care, product, benefit configuration, and client rules to identify whether the request belongs under the medical or pharmacy benefit and route it to the responsible workflow. The agent can flag ambiguous cases rather than forcing a classification, reducing misroutes, delays, and duplicate work.

Prior-Authorization Intake and Submission Support

Normalize data from NCPDP transactions, FHIR exchanges, forms, clinical notes, and attachments; identify likely missing or conflicting information; and prepare a structured request package. Before submission, the same capability can translate documentation requirements into drug specific questions for the prescriber workflow.

Clinical and Policy Review Support

Assemble a concise evidence summary, retrieve the applicable formulary and criteria version, map submitted facts to individual requirements, and flag where clinical judgment or additional information is needed. The reviewer remains accountable for the outcome and rationale.

Denial and Next Step Communication

Draft a provider and patient appropriate explanation tied to the reviewer’s documented rationale, including the unmet requirements and the practical next step for resubmission or appeal. Validation rules can identify vague, unsupported, or inconsistent language before it is issued.

Appeals and Grievances Support

Bring together the original request, evidence, policy version, reviewer rationale, communications, new information, and applicable timeframe; prepare a case chronology and summary; and route the matter to the appropriate appeal or grievance path. Analytics can identify recurring causes of appeals, grievances, and overturns without replacing the independent review required by the applicable process.

Payment Integrity Support

Compare authorization terms such as drug, dose, quantity, duration, provider, site of care, and effective dates with downstream claims or encounters; surface mismatches for review; and preserve the evidence trail. This is an adjacent use case rather than a direct CMS-0062-P requirement, but it can reuse the cleaner authorization data and traceability created through implementation.

Compliance Monitoring and Reporting

Track timestamps, workflow status, handoffs, explanation quality, channel consistency, and reporting data; identify cases approaching a deadline; and surface patterns in incomplete requests, manual touches, resubmissions, appeals, grievances, and overturns.

Guardrails for Responsible AI Use

  • Use only the applicable, approved client policy and formulary sources, with effective dates and version control.

  • Require traceability from each material statement to submitted evidence and the governing criterion.

  • Keep the qualified reviewer accountable for clinical judgment and the final rationale where review is required.

  • Separate missing documentation messages from substantive coverage determinations.

  • Test for accuracy, unsupported statements, consistency, readability, bias, and performance across drug classes and populations.

  • Retain an audit record of source data, model or prompt version, generated draft, reviewer edits, final communication, and timestamps.

  • Measure outcomes such as incomplete-request rate, time to decision, manual touches, provider follow up, resubmission, appeal, and overturn.

Start Preparing Now

CMS-0062-P signals that electronic prior authorization is moving beyond digital transport toward a more transparent, measurable, and usable exchange. Pharmacy management companies should prepare for an environment in which the quality of an explanation is as visible as the speed of a transaction. Although specific standards, dates, and requirements may change, waiting for complete regulatory certainty creates unnecessary risk.

Begin by mapping proposed and final requirements across payer types, benefits, clients, standards, implementation dates, and accountable owners. Evaluate current denial reasons, trace representative cases from policy through appeal and reporting, and identify where fragmented data, inconsistent communications, and manual work create risk.

Use these findings to develop a phased roadmap that addresses anticipated compliance requirements while reducing provider burden and operating costs. Engage clients early to align on responsibilities, policy ownership, data availability, testing, performance metrics, audit evidence, and change control. By acting now, organizations can establish a connected foundation across benefit design, policy, data, clinical review, communication, and measurement. With that foundation in place, they can apply AI selectively to improve provider interactions, accelerate resolution, support more consistent decisions, and reduce uncertainty for patients waiting to begin or continue treatment.

Sources

CMS-0062-P proposed rule, Federal Register (April 14, 2026)

CMS fact sheet: 2026 Interoperability Standards and Prior Authorization for Drugs Proposed Rule

CMS-0062-P Comment Guide (May 2026)

CMS-0057-F fact sheet (context for non-drug prior authorization)

About the Author

Gina Collins is Chief Regulatory Officer at Autonomize AI, where she leads regulatory strategy, compliance, and enterprise risk management to support safe, scalable AI adoption in healthcare. With more than 20 years of executive leadership experience across payer, provider, and government healthcare sectors, she is known for driving operational transformation, strengthening governance, and translating complex regulatory requirements into practical solutions. Prior to Autonomize, Gina held leadership roles at the FDA’s Center for Devices and Radiological Health and a Fortune 13 global health services company, leading initiatives focused on regulatory transparency, operational risk, and compliance.