Prior authorization just became a lot more visible. Payer PA data is public for the first time, Gartner formally defined intelligent PA as its own market category, and CMS added two final rules and a significant proposed rule to the compliance stack. In about three weeks, the industry got a public scorecard, a buyer's framework, and new implementation deadlines all at once.
"A year ago, most PA conversations started with 'how fast can you process.' Now buyers are leading with audit trails, state compliance, and measurable outcomes. The questions are getting more specific, and that's a good sign for the market."
— Daniel Friedman, CEO, Ethermed
Payer PA Data Is Now Public
For the first time, payers are required to publish PA denial rates, approval rates, and turnaround times. In practice, KFF looked at the first wave of data and found it aggregated, inconsistently formatted, and difficult to compare across plans. These standards will get tighter, the data will get more granular, and eventually plans will be compared side by side on PA performance. The organizations thinking now about how to interpret and act on that data will be ahead when it starts to matter.
On a related note, the Electronic Frontier Foundation filed a FOIA lawsuit against CMS seeking details on the WISeR pilot, the Innovation Center model that uses AI to review PA requests in traditional Medicare. EFF is asking for vendor agreements, training data, and bias testing records. Whether or not the lawsuit succeeds, it reflects a growing expectation that AI in coverage decisions needs to be transparent and explainable.
CMS Keeps Adding to the Compliance Stack
Two final rules and a significant proposed rule this month.
The Claims Attachments Final Rule (CMS-0053-F) sets national standards for electronic claims attachments and e-signatures, adopting X12N 275 and 277 (Version 6020) along with HL7 C-CDA. It is effective May 26, 2026, with a compliance deadline of May 26, 2028. CMS originally proposed including prior auth attachments in this rule but dropped them from the final version, citing potential conflicts with CMS-0057-F and the existing X12N 278 PA transaction standard.
Three weeks later, CMS answered the PA question with CMS-0062-P, proposed April 10. CMS is proposing to replace the X12N 278 with HL7 FHIR as the HIPAA standard for prior auth transactions, and to move the Da Vinci CRD, DTR, and PAS implementation guides from strongly recommended to required for the PA API. If finalized, this would make FHIR the legal floor for PA transactions across all HIPAA-covered entities. The comment period is open through June 15, 2026.
The 2027 MA and Part D rule tightens star ratings, supplemental benefit oversight, and denial documentation standards for MA plans. If you are an MA plan, the audit surface just got bigger.
Federal and State Activity on AI
The White House released its National Policy Framework for Artificial Intelligence in March. It is a set of legislative recommendations, not binding law. The central ask is federal preemption of state AI laws that impose undue burdens, with continued reliance on existing sector-specific regulators like CMS and FDA rather than a new federal AI agency.
State legislatures are not waiting. Alabama's Senate passed SB 63, which would require a licensed health care professional to make the final call on any AI-driven PA denial and mandate annual non-discrimination certification for insurers using AI in utilization review. Utah passed a law requiring insurers to disclose when AI is used to review authorization requests, effective January 2027. Manatt's policy tracker counts more than 240 AI-related health care bills introduced across 43 states so far in 2026.
Whatever happens federally, state requirements are real now. Any PA automation operating across multiple states needs to handle different rules in different jurisdictions, and needs audit-ready documentation either way.
Gartner Defines "Intelligent Prior Authorization" as a Market
Gartner's 2026 Market Guide for Intelligent Prior Authorization formally recognizes AI-driven PA as a distinct market category. This gives buyers a defined framework to evaluate vendors. Expect RFP criteria to start reflecting Gartner's definitions of what intelligent PA should include: guard-railed automation, exception routing, multi-rail connectivity, and clinical oversight. The bar for what counts as credible in a sales conversation is moving from "we have AI" to "here are the numbers."
For health plans evaluating vendors, this is a good development. More structure, more benchmarks, and a clearer picture of what to expect.
Interoperability and Standards
ONC released Lantern 3.0 for monitoring health IT developer compliance and published a 2026 ePA testing roadmap with connectathon events open to vendors. If you are looking to demonstrate FHIR PA readiness, those are worth getting on the calendar. WEDI's latest survey shows CMS-0057-F readiness is still uneven across payers and providers, which is worth tracking as enforcement gets closer.
Closing Thought
This was one of the busier three-week stretches we have tracked. Public PA data, a defined market category, state-specific AI requirements, a proposed shift to FHIR-based PA transactions, and new CMS implementation timelines all landed at once. The common thread is that prior auth is getting more measurable from the outside.
At Ethermed, that is the environment we have been building for. If your team is working through what any of these changes mean for your operations, we are always happy to talk.



