What it does
The Prior Authorization API automates the three steps of a PA request that are still mostly manual today: finding out a prior auth is needed (Coverage Requirements Discovery), gathering and attaching the right supporting documentation (Documentation Templates and Rules), and submitting the request and getting a decision back (Prior Authorization Support).
Alongside the API, the underlying process rules changed too: urgent requests get a decision within 72 hours, standard requests within seven calendar days, and every denial has to come with a specific reason instead of a form letter.
Who calls it
The ordering provider's EHR, at the point of order, to check requirements (CRD) and pull the right documentation (DTR) before the request is even submitted.
The same system submits the completed request and receives status updates through Prior Authorization Support (PAS), instead of a portal, fax, or phone call.
Technical standards
| Standard | Version | Notes |
|---|---|---|
| Da Vinci CRD | STU 2.1 | Coverage Requirements Discovery. Surfaces whether a PA is needed, inside the provider's own workflow. |
| Da Vinci DTR | STU 2.1 | Documentation Templates and Rules. The questionnaire and attachment layer. |
| Da Vinci PAS | STU 1.2 | Prior Authorization Support. The FHIR-based replacement for X12 278 submission and response. |
| CQL | 1.5 | Clinical Quality Language. Encodes the payer's own medical-necessity rules for CRD/DTR to evaluate. |
The turnaround clock started before the API did
The 72-hour/7-day decision windows and denial-reason requirement took effect January 1, 2026, a full year before the API deadline. If your UM process can't hit those timeframes manually today, the API won't fix that on its own.
Ready to see where you stand?
Every requirement on this page is one line item in our free CMS-0057-F readiness survey.