HomeBlogCompliance & regulatory
CMS-0057-F and PT practices in 2027
CMS will require certain health plans to run new FHIR APIs in 2027. PT practices should know what changes at the payer boundary, and what does not.

The short version
- CMS-0057-F requires specified Medicare Advantage, Medicaid, CHIP, and Federally-facilitated Exchange payers to meet API requirements that generally begin January 1, 2027.
- The 2027 rule expands the Patient Access API and requires Provider Access, Payer-to-Payer, and Prior Authorization APIs.
- This is mainly a payer mandate. It does not make every physical therapy practice responsible for building a FHIR API.
- Separate prior authorization decision-time and denial-reason rules began in 2026 for impacted payers, subject to the rule's stated scope.
The first question to ask about CMS-0057-F is not whether your PT practice needs to build an API. It does not. The rule puts the principal technical obligation on specified health plans. What changes for a practice is the path between its records, the payer’s authorization rules, and the answer that comes back.
CMS’s CMS-0057-F fact sheet identifies Medicare Advantage organizations, state Medicaid and CHIP fee-for-service programs, Medicaid and CHIP managed care entities, and Qualified Health Plan issuers on the Federally-facilitated Exchanges. CMS calls them “impacted payers.” The rule does not cover every commercial plan or traditional Medicare.
For a PT owner, that distinction matters. The useful question for 2027 is simpler. Will the plans you work with give your team and EHR a cleaner way to find requirements, send an authorization request, and read a decision? CMS is building toward that outcome. A payer’s deadline is not a promise that every workflow will feel fixed on day one.
What does CMS-0057-F require by 2027?
CMS-0057-F is a federal interoperability and prior authorization rule that requires impacted payers to maintain specified FHIR-based ways to exchange health and authorization data. CMS lists HL7 FHIR Release 4.0.1 among the required standards and implementation specifications. The exact compliance date varies by payer type, but the core API requirements generally begin January 1, 2027.
The four pieces are easy to confuse. One already existed before this rule:
- Patient Access API. Impacted payers must add prior authorization information, excluding drug authorizations, to their existing patient-facing API by January 1, 2027. That gives a member’s chosen app access to more of the payer-held record.
- Provider Access API. Impacted payers must make individual claims and encounter data, USCDI data, and specified prior authorization information available to in-network or enrolled providers with a treatment relationship. Patients can opt out.
- Payer-to-Payer API. With a patient’s opt-in permission, impacted payers must exchange defined claims, encounter, USCDI, and specified prior authorization data. The requirement covers data with dates of service within five years of the request.
- Prior Authorization API. Impacted payers must publish covered items and services, identify documentation requirements, and support a prior authorization request and response. The response must show approval details, a specific denial reason, or a request for more information.
Calling these “four new APIs” is inaccurate. The Patient Access API came from an earlier CMS rule. CMS-0057-F expands it with authorization information and adds three new APIs. CMS’s API overview makes that split explicit.
Is this a new compliance obligation for PT practices?
No, not in the same way it is for the impacted payers. The rule requires those payers to build and maintain the APIs. A PT practice is not named as the organization that must stand up the payer-side API infrastructure.
There is a provider-facing part worth watching. CMS added an Electronic Prior Authorization measure for MIPS eligible clinicians and certain hospitals. It asks an eligible party to attest that it requested a prior authorization electronically via a Prior Authorization API, using data from certified EHR technology, for at least one medical item or service, excluding drugs. It can instead report an applicable exclusion. The timing has since moved: for hospitals and critical access hospitals, CMS has made it an optional bonus measure for the 2027 reporting period and mandatory from 2028, and it has proposed the same shift on the clinician side for the 2027 performance period. That is a program-specific measure, not a duty that applies to every PT practice.
Ask your EHR vendor a direct question: “When an impacted payer makes its Prior Authorization API available, how will we discover requirements, send the request, and see a response?” Then ask the plans that drive your authorization volume when they expect to support that workflow. “FHIR-ready” does not answer either question.
The day-to-day discipline stays familiar. Verify coverage at scheduling. Keep the evaluation, plan of care, and objective progress where the authorization team can retrieve them. Track the authorization status and expiration date before additional visits. Our guide to prior authorization for physical therapy covers that operating work in more detail.
What already changed in 2026?
The dates most likely to get mixed together are the 2026 process requirements and the 2027 API requirements. CMS sets a narrower scope for the decision-time rule. Impacted payers, excluding Qualified Health Plan issuers on the Federally-facilitated Exchanges for this provision, must send expedited decisions within 72 hours and standard decisions within seven calendar days, with the possibility of an extension to up to 14 days in certain circumstances. Beginning in 2026, they must also give a specific reason for a denied prior authorization decision, regardless of how the request was sent. These requirements exclude drug authorizations.
Impacted payers also must publicly report certain prior authorization metrics annually. CMS’s fact sheet says the operational and process policies had a compliance date starting January 1, 2026, with the initial set of metrics due by March 31, 2026. Those are payer obligations. They are useful for a practice because a more specific denial and a published process metric give your authorization team something concrete to follow up on.
The distinction matters when an authorization is delayed. The seven-day and 72-hour rules concern the payer’s decision timeframe. The 2027 Prior Authorization API concerns an electronic route for requirements, requests, and responses. One does not replace the other.
What should a PT practice do before 2027?
Do not turn this into a technical project your front desk has to solve. Turn it into a vendor and payer readiness check.
First, list the plans that generate the most therapy authorizations and flag which ones are in the CMS categories. Second, ask each payer contact whether its provider-facing workflow will change for the 2027 requirements and where it will publish its rollout information. Third, ask your EHR vendor for the practical answer, not the standards answer: what will your authorization coordinator click, what information will flow, and what will remain manual?
Then keep improving the process you own. A clean plan of care and consistent documentation make it easier to submit or correct an authorization request through any channel. Orion’s billing tools include eligibility at booking and billing workflows for PT practices. They are not a substitute for a payer’s API, but they help the team see the payer and patient context before a visit becomes an avoidable denial.
CMS is setting a floor for selected payers. The practices that benefit most will turn a new electronic pathway into a tighter authorization workflow. The rule cannot do that operating work on its own.
Book a live demo
See Orion run your practice.
A PT-specific walkthrough, transparent pricing, and straight answers. Your current EHR stays live the whole time.
