January 1, 2027 is closer than it looks. Most health plans have already bought their compliance platforms. The FHIR vendor is signed and the API endpoints exist. Yet many data and IT leaders share the same worry. The platforms are ready, but the data behind them is not.
That is the real story of the CMS Interoperability and Prior Authorization Final Rule, known as CMS-0057-F. It reads like an API mandate. In practice, it is a data mandate. This post explains what the rule requires, why the remaining work is data work, and how to make real progress in the next 90 days with a focused payer data ops approach.
What does CMS-0057-F require, and when?
CMS finalized the rule in January 2024. It applies to Medicare Advantage organizations, state Medicaid and CHIP programs, Medicaid and CHIP managed care plans, and qualified health plans on the federally facilitated exchanges.
Some requirements are already in force:
Since January 1, 2026
Expedited prior authorization decisions within 72 hours and standard decisions within 7 calendar days, with a specific reason for every denial.
March 31, 2026
The first public report of prior authorization metrics, repeated every year on the payer website.
January 1, 2027
Four FHIR APIs must be live. Patient Access, Provider Access, Payer-to-Payer, and Prior Authorization. Each serves regulated data to a different consumer, from members and their apps to other insurers.
CMS-0057-F is not alone. The No Surprises Act has required accurate provider directories since 2022. Plans must verify every provider record every 90 days and publish updates within 2 business days. States also keep raising the bar on encounter data submissions, where every rejected record must be fixed and resubmitted by staff.
Why is compliance a data problem, not an API problem?
Because the APIs speak FHIR and your data does not. Claims live in core administration systems such as Facets or QNXT. Enrollment arrives in X12 834 files. Prior authorization records often sit in fax images and free text. Provider data is split across credentialing systems, rosters, and reference feeds.
What you hold today
Claims in Facets or QNXT
Enrollment in X12 834 files
Prior auth in fax images and free text
Provider data across credentialing, rosters, reference feeds
Mapping, matching, validation
Identity resolution: one golden record per member and provider
Mapping: X12 and core system data into FHIR resources
Executable validation rules: the regulator's own checks, run before data leaves
What must be served
Patient Access API
Provider Access API
Payer-to-Payer API
Prior Authorization API
The compliance surface is on the right and the platforms that serve it are bought. The unfinished work sits in the middle column.
The gap between those sources and a compliant API is mapping, matching, and validation. Data must be translated into FHIR resources and pass the implementation guides the rule points to, including US Core, CARIN Blue Button, and the Da Vinci guides for prior authorization. Every record must match the right member or provider. An endpoint that serves mismatched or stale data will fail validation, frustrate members, and invite audit questions.
The 90 day action plan
Days 1 to 30
Audit your four regulatory pipelines
Measure, do not build. Score each pipeline against the same validation rules the regulators use, and trace every failure to its source.
A scored, board ready picture of where you stand and what the gaps cost each year
Days 31 to 60
Fix the most important pipeline first
Pick the pipeline with the highest compliance risk or the largest leakage, and remediate it at the source rather than repairing records downstream.
A mapping fixed once, preventing thousands of future rejections
Days 61 to 90
Turn compliance into an operation
Put the routine in place: monthly reconciliation, attestation workflow, dashboards for rejection rates and data freshness, and lineage.
A running operation on January 1, 2027, not a scramble
Each phase produces something the next one needs. Skipping the audit is what turns month two into a guess.
Days 1 to 30: audit your four regulatory pipelines
Start by measuring, not building. Score each pipeline against the same validation rules the regulators use.
Test your CMS-0057-F data readiness
Pull a sample of claims, clinical, and prior authorization records. Map them to FHIR, run them against the implementation guides, and trace every failure to its source.
Measure provider directory compliance
How long does a provider update take to reach your public directory? The law allows 2 business days. How large is your attestation backlog against the 90 day verification clock?
Compare your membership against the federal and state files, member by member. For dual eligible members this means D-SNP enrollment reconciliation across two governments, every month.
Quantify encounter data quality
What is your state submission rejection rate? If it is above 5 percent, calculate the monthly rework cost and the root causes behind it.
End the month with a scored, board ready picture of where you stand and what the gaps cost each year.
Days 31 to 60: fix the most important pipeline first
Do not try to fix everything at once. Pick the pipeline with the highest compliance risk or the largest leakage and remediate it at the source.
Three disciplines do most of the work. Identity resolution matches members and providers across systems and creates one golden record. Mapping translates X12 and core system data into the FHIR resources the APIs must serve. Executable validation rules run the regulator's own checks before data leaves your environment, not after a rejection comes back.
Days 61 to 90: turn compliance into an operation
Compliance is not a project with an end date. Directories decay every month. Enrollment files change daily. States update their submission rules. In the final phase, put the routine in place: monthly reconciliation with a discrepancy queue, an attestation workflow for provider data, dashboards for rejection rates and data freshness, and lineage so you can answer a regulator's question about any record.
When January 1, 2027 arrives, you want a running operation, not a scramble.
What does it cost to wait?
Industry experience puts the rework cost of a rejected submission at roughly $35 per record in labor and delay. A wrong directory entry can force a plan to honor in network pricing and absorb the difference. A missed member status flag can quietly reduce risk adjusted revenue by tens of thousands of dollars per member per year.
All of this lands inside an administrative budget that is already squeezed. Medicare Advantage rate updates for 2027 are near zero while medical costs keep rising.
Frequently asked questions
What is the CMS-0057-F deadline?
Prior authorization timeframes and denial reasons took effect on January 1, 2026. The four FHIR APIs must be live by January 1, 2027.
Which payers must comply with CMS-0057-F?
Medicare Advantage organizations, state Medicaid and CHIP programs, Medicaid and CHIP managed care plans, and qualified health plans on the federally facilitated exchanges.
Is buying a FHIR platform enough for compliance?
No. The platform serves data. Compliance depends on the quality of the data behind it: correct mapping, matched identities, and current records.
Start where it hurts
The mandates are set and the dates will not move. The good news is that 90 days of focused data work changes the picture. Begin with a data readiness assessment to score your four pipelines, or explore our payer data ops services to see how each pipeline gets fixed and run. Your platforms are bought. Now make the data behind them compliant, accurate, and audit ready.
Artha Solutions healthcare expertise, and help to achieve your compliance targets
We score all four regulatory pipelines against the validation rules the regulators actually apply, fix the mapping at the source, and leave the reconciliation, attestation, and lineage running as an operation. Schedule a call with us now.