The Center for Medicare & Medicaid Services (CMS) released the CMS Interoperability and Prior Authorization Final Rule on January 17, 2024, which according to CMS.gov “emphasizes the need to improve health information exchange to achieve appropriate and necessary access to health records for patients, healthcare providers, and payers,” and seeks to improve prior authorization practices.
ABOUT PRIOR AUTHORIZATIONS
According to the Final Rule, prior authorization refers to, “the process through which a health care provider … obtains approval from a payer before providing care.” Here, healthcare providers (“providers”) include individual clinicians, acute care hospitals, ambulatory surgical centers, or clinics.
The Final Rule further states that prior authorization requirements are established by insurance plans (“payers”) to “help control costs and ensure payment accuracy by verifying that an item or service is medically necessary, meets coverage criteria, and, for some payers, is consistent with standards of care before the item or service is provided.”
The process involves a “prior authorization request,” from a provider and a “prior authorization decision,” by a payer.
IMPACTED PAYERS
The Prior Authorization Final Rule is said to apply the following payers, designated by the Rule as “impacted payers”:
- Medicare Advantage (MA) organizations;
- State Medicaid fee-for-service (FFS) programs;
- State Children’s Health Insurance Program (CHIP) fee-for-service (FFS) programs;
- Medicaid managed care plans;
- CHIP managed care entities; and,
- Issuers of Qualified Health Plans (QHPs) offered on the Federally-Facilitated Exchanges (FFEs).
APPLICATION PROGRAMMING INTERFACES
Application Programming Interfaces (APIs), which enable different applications to communicate with each other, are a key focus of the Final Rule used to achieve the goal of data interoperability between payers, providers, and patients.
To facilitate the exchange of health care data, the Final Rule utilizes the following APIs:
Patient Access API
Previously, the related CMS Interoperability and Patient Access final rule required impacted payers to “implement and maintain a standards-based Patient Access API,” which must “allow patients, through the health apps of their choice, to easily access their claims and encounter information as well as clinical data.” Clinical data includes laboratory results, provider remittances, and patient cost-sharing pertaining to such claims, if maintained by the impacted payer.
The current Prior Authorization Final Rule does not propose a new Patient Access API, but adds to the existing one, the requirement that, “impacted payers include information about certain prior authorizations in the data that are available through the Patient Access API.”
According to Table H3 of the Final Rule, the required standards are as follows:
- 45 CFR 170.215(a)(1) HL7 FHIR Release 4.0.1
- 45 CFR 170.215(b)(1)(i) HL7 FHIR US Core IG STU 3.1.1.
- 45 CFR 170.215(c)(1) HL7 SMART Application Launch Framework IG Release 1.0.0.
- 45 CFR 170.215(e)(1) OpenID Connect Core 1.0, incorporating errata set 1
Provider Access API
The Final Rule requires impacted payers to “implement and maintain a Provider Access API to share patient data with in-network providers with whom the patient has a treatment relationship.”
Such data is to include the following:
- Adjudicated claims and encounter data (excluding provider remittances and patient cost-sharing information)
- All data classes and data elements included in a content standard at 45 CFR 170.213 (USCDI)
- Prior authorization information
According to Table H3 of the Final Rule, the required standards for this API are as follows:
- 45 CFR 170.215(a)(1) HL7 FHIR Release 4.0.1
- 45 CFR 170.215(b)(1)(i) HL7 FHIR US Core IG STU 3.1.1.
- 45 CFR 170.215(c)(1) HL7 SMART Application Launch Framework IG Release 1.0.0.
- 45 CFR 170.215(d)(1) FHIR Bulk Data Access (Flat FHIR) IG (v1.0.0: STU 1)
Payer-to-Payer API
The Payer-to-Payer API is designed to “exchange patient data when a patient moves between payers to ensure continued access to their health data and support continuity of care between payers,” according to the Final Rule.
In a similar manner to the Provider Access API, the Payer-to-Payer API data exchanged includes adjudicated claims and encounter data (excluding provider remittances and patient cost-sharing information); all data classes and data elements included in a content standard at 45 CFR 170.213 (USCDI); and certain information about the patient’s prior authorizations.
Impacted payers are required to request data from a patient’s previous payer “no later than 1 week from the start of coverage or at the patient’s request,” with the patient’s permission being necessary, and any data received as a result must be integrated into the patient’s record.
Modified from the initial Proposed Rule, data related to denied prior authorizations will be excluded under the Final Rule and impacted payers are only required to “exchange data with a date of service within 5 years of the request.”
According to Table H3 of the Final Rule, the required standards for this API are as follows:
- 45 CFR 170.215(a)(1) HL7 FHIR Release 4.0.1
- 45 CFR 170.215(b)(1)(i) HL7 FHIR US Core IG STU 3.1.1.
- 45 CFR 170.215(d)(1) FHIR Bulk Data Access (Flat FHIR) IG (v1.0.0: STU 1)
Prior Authorization API
Under the Final Rule, a Prior Authorization API must be implemented and maintained by payers in order to “streamline the prior authorization process,” and providers are to use this API to determine whether a specific payer requires prior authorization for a certain item or service.
The API will also be used to “allow providers to query the payer’s prior authorization documentation requirements directly from the provider’s system,” allowing for the “automated compilation of necessary information to submit a prior authorization request.”
According to Table H3 of the Final Rule, the required standards are as follows:
- 45 CFR 170.215(a)(1) HL7 FHIR Release 4.0.1
- 45 CFR 170.215(b)(1)(i) HL7 FHIR US Core IG STU 3.1.1.
- 45 CFR 170.215(c)(1) HL7 SMART Application Launch Framework IG Release 1.0.0.
Provider Directory API
The Final Rule notes that the building and maintenance of a Provider Directory API was previously required under the CMS Interoperability and Patient Access final rule and that implementation by applicable impacted payers should have begun.
It seeks to build on that prior work, noting that most MA organizations are “supported by entities with an operational and technical infrastructure that can support the [new and revised] API requirements because these organizations can leverage existing staff and vendor resources from implementation of the Patient Access and Provider Directory APIs.” It also takes the opportunity to “encourage developers to integrate within their apps, network information from payers’ Provider Directory APIs for easy patient access.
The Final Rule also requires modifications to “incorporate the expiration date ONC adopted at 45 CFR 170.215(b)(1)(i), and to remove the SMART App Launch IG at 45 CFR 170.215(c)(1) and OpenID Connect Core at 45 CFR 170.215(e). It also notes that payers may use an updated version of a required standard under certain conditions, such as:
- If the National Coordinator has approved the updated version for use in the ONC Health IT Certification Program;
- The updated version of the standard does not disrupt an end user’s ability to access the required data via that API; and,
- The updated standard is not prohibited by law.
According to Table H3 of the Final Rule, the required standards for this API are as follows:
- 45 CFR 170.215(a)(1) HL7 FHIR Release 4.0.1
- 45 CFR 170.215(b)(1)(i) HL7 FHIR US Core IG STU 3.1.1.
ADDITIONAL PRIOR AUTHORIZATION PROCESSES & MEASURES
CMS is finalizing proposals for the prior authorization process apart from the use of APIs. This includes the following:
- Requiring that impacted payers send notices to providers when they make a prior authorization decision;
- A specific reason for denial must be provided when denying a prior authorization request;
- Impacted payers (other than QHP issuers on FFEs) will be required to respond to prior authorization requests within certain timeframes; and
- All impacted payers will be required to publicly report certain metrics about their prior authorization process policies.
CMS is also finalizing new electronic prior authorization measures under the Merit-based Incentive Payment System (MIPS) Promoting Interoperability Program for eligible hospitals and Critical Access Hospitals (CAHs), and under the MIPS Promoting Interoperability performance category for eligible clinicians.
RELATION TO HTI-1 RULE
API standards for health information technology are addressed in 45 CFR 170.215, and it can be noted that recently the API and other standards underwent revisions that delineated the “purpose and scope more clearly for each type of standard or implementation specification,” by the ONC Health Data, Technology, and Interoperability: Certification Program Updates, Algorithm Transparency, and Information Sharing (HTI-1) Final Rule.
When it comes to the Prior Authorization Rule, CMS states that impacted payers will, “only be required to use the specifications that CMS has identified as necessary for the Patient Access, Provider Access, Provider Directory, Payer-to-Payer, and Prior Authorization APIs.”
The standards being finalized (which include updated citations) are as follows:
- Health Level Seven (HL7®) Fast Healthcare Interoperability Resources (FHIR®) Release 4.0.1 at 45 CFR 170.215(a)(1) (HL7 FHIR).
- HL7® FHIR® US Core Implementation Guide (IG) Standard for Trial Use (STU) 3.1.1, which expires on January 1, 2026, at 45 CFR 170.215(b)(1)(i) (US Core IG).
- HL7® SMART Application Launch Framework IG Release 1.0.0 which expires on January 1, 2026, at 45 CFR 170.215(c)(1) (SMART App Launch IG).
- FHIR® Bulk Data Access (Flat FHIR) IG v1.0.0: STU 1 at 45 CFR 170.215(d)(1) (Bulk Data Access IG).
- OpenID Connect Core 1.0, incorporating errata set 1 at 45 CFR 170.215(e)(1) (OpenID Connect Core).
It can also be noted that in the Final Rule, CMS will allow impacted payers to use updated versions of the standards, specifications, or implementation guides (IGs) prior to the adoption of updated versions in regulation, although this will be subject to certain conditions and must not, “disrupt an end user’s ability to access the data available through the API.” Conversely, impacted payers must adhere to the expiration dates for applicable standards found in the HTI-1 Rule.
Finally, it should also be noted that in the Prior Authorization Final Rule, CMS states in relation to the HTI-1 rule that although related, “these rules address separate areas of CMS and ONC authority.” It further states that, “We are not finalizing any modifications from the proposed rule based on HTI-1 other than updating our regulatory citations and incorporating expiration dates ONC has finalized for particular standards at 45 CFR 170.215.”
Categories: DATA ACCESS & INTEROPERABILITY
Leave a Reply