CMS-0057-F explained: the Interoperability and Prior Authorization rule, in plain terms

CMS-0057-F, the Interoperability and Prior Authorization rule

CMS-0057-F, the Interoperability and Prior Authorization Final Rule, is the biggest change to how US payers exchange data since the original Patient Access rule. It sets firm deadlines for faster prior authorization decisions and for four FHIR APIs that payers must run.

This guide explains who it applies to, what it requires, when, and how to meet it without building everything from scratch.

Who it applies to

The rule covers "impacted payers":

Providers are affected too. From the 2027 performance period, the "Electronic Prior Authorization" measure is part of the Merit-based Incentive Payment System (MIPS) Promoting Interoperability category and the Medicare Promoting Interoperability Program for hospitals.

What it requires, and when

CMS-0057-F timeline: decision timeframes and metrics from 2026, four FHIR APIs from 2027

From 1 January 2026: faster, clearer decisions

From 1 January 2027: four FHIR APIs

The four CMS-0057 APIs connecting a payer to members, providers, other payers and clinicians

  1. Patient Access API: the existing API, extended so members can also see their prior authorization requests and decisions.
  2. Provider Access API: in-network providers can retrieve their patients' claims, encounter data, clinical data and prior authorizations, with a member opt-out.
  3. Payer-to-Payer API: when a member changes plans, the new payer can request up to five years of data from the old one, with the member's permission.
  4. Prior Authorization API: providers can find out whether an item or service needs prior authorization, what documentation is required, and submit the request and get the decision, all over FHIR.

The standards behind it

CMS names a set of HL7 FHIR implementation guides for these APIs:

CMS has also said it will use enforcement discretion for payers who handle prior authorization over FHIR with Da Vinci PAS rather than the X12 278 transaction alone.

What a payer actually has to build

Meeting the rule means running, securing and connecting a lot of moving parts:

How Perfuse does it

CRD, DTR and PAS between the EHR and the payer

Perfuse is a free, Apache-2.0 healthcare integration engine with the whole CMS-0057 stack built in. It is one file to download, with nothing else to install.

Perfuse also does everything an integration engine does: HL7 v2, FHIR, X12, DICOM and CDA over twenty connector types, with a durable queue, a web console and full monitoring. So the same engine that feeds your FHIR server from existing systems also serves the APIs.

Get started

  1. Download Perfuse from the latest release.
  2. Run perfuse serve and open http://127.0.0.1:8080.
  3. Read the manual for the CMS-0057 setup.

Related: Da Vinci CRD, DTR and PAS explained.