Ninety-eight days remain until the principal January 1, 2027 API compliance milestone in CMS-0057-F, though CMS states the exact dates vary by payer type. The two provisions most often treated as one build are not one build: Provider Access requires an opt-out, Payer-to-Payer requires an opt-in. Meanwhile the rule's required standards floor is older than the Da Vinci guides that are merely recommended, CMS-0062-P remains unfinalized, and ONC's new Cartos terminology service helps with version drift without touching conformance.
As of this publication, 98 days remain until January 1, 2027 — the date CMS-0057-F names for the Patient Access prior authorization enhancement, the Provider Access API, the Payer-to-Payer API, and the Prior Authorization API. CMS's own hedge: impacted payers have until compliance dates "generally beginning January 1, 2027" and "The exact compliance dates vary by the type of payer."
For MA organizations and state Medicaid/CHIP fee-for-service programs, January 1, 2027 is the operative date. For Medicaid and CHIP managed-care entities, the trigger is generally the rating period beginning on or after that date. For FFE QHP issuers, it is generally the plan year beginning on or after that date.
The operational provisions that landed January 1, 2026 — 72 hours for expedited decisions, seven calendar days for standard decisions, and a specific reason on every denial regardless of transmission method — have already sorted the field. Those requirements did not need an API. They needed a utilization management engine capable of generating a specific clinical or coverage rationale for each denial. Some payers discovered in the first quarter of this year that theirs could not.
Provider Access requires an opt-out. Impacted payers must maintain an attribution process associating patients with in-network or enrolled providers, share specified data with those providers by default, and allow patients to opt out. An opt-out model requires a documented patient-education and opt-out process, plus a reliable way to honor opt-out status.
Payer-to-Payer requires an opt-in. CMS finalized an opt-in process requiring affirmative member permission before exchange occurs — with plain-language educational resources and the ability for members to opt out after participating.
Those are not two configurations of one consent service. They are inverted default states, with different population-scale communication obligations, different audit evidence, and different timing relative to enrollment events. An opt-in model has to prove affirmative permission exists before a single resource leaves the building — and it has to capture that permission at a moment when the member has just changed payers and is least reachable.
Payer-to-Payer is bounded to a date of service within five years of the request; the rule generally requires at least five years of applicable claims and encounter data, USCDI clinical data, and qualifying non-drug prior-authorization information.
Freeze the required standards floor. The regulatory floor includes FHIR Release 4.0.1, US Core IG STU 3.1.1, SMART App Launch IG Release 1.0.0, FHIR Bulk Data Access v1.0.0 (STU 1) where bulk exchange is required, and OpenID Connect Core 1.0. CMS requires SMART App Launch 1.0.0 but strongly encourages 2.0.0 to support backend services authorization. Since the rule's publication, ONC has adopted updated versions of several relevant FHIR implementation guides through separate rulemaking. Conformance to what CMS requires and interoperability with the EHR on the other end of the connection are not the same test.
Leave loosely coupled anything that CMS-0062-P touches. The 2026 CMS Interoperability Standards and Prior Authorization for Drugs proposed rule closed its comment period on June 15, 2026 and has not been finalized. It would require impacted payers to report interoperability API endpoints and API usage metrics to CMS, among other changes. Keep drug PA routing, schemas, and reporting telemetry modular until CMS publishes final requirements.
One more decision to make deliberately: HHS has announced limited enforcement discretion regarding the HIPAA X12 278 prior-authorization transaction for entities that implement a fully FHIR-based Prior Authorization API under CMS-0057-F. That discretion does not eliminate the CMS-0057-F FHIR API obligation. An X12-only workflow is not a substitute for the required FHIR API.
ONC published Cartos, its public FHIR-enabled terminology service, announced in the ONC Standards Bulletin issue dated September 1, 2026. It offers a read-only FHIR R4 API, a browser-based terminology browser requiring no account, and downloadable terminology collections. It is genuinely useful for the version-confirmation problem — the same code system or value set existing in several repositories at several versions. ONC states plainly that Cartos "does not replace official content stewards, source terminology licensing requirements, implementation guides, regulations, or organizational compliance review." It reduces specification drift. It does not substitute for API conformance testing.
The question to put to your program this week: does the opt-in consent for Payer-to-Payer have a capture point that exists in a real enrollment workflow — and, if it does not, what share of your membership will be ineligible for automated Payer-to-Payer exchange on January 2?
Sources: CMS Interoperability and Prior Authorization Final Rule CMS-0057-F (fact sheet), CMS; 2026 CMS Interoperability Standards and Prior Authorization for Drugs Proposed Rule (CMS-0062-P), CMS; Cartos — ONC's Terminology Service (last updated September 1, 2026); ONC Standards Bulletin Issue 2026-3, September 1, 2026.
Discover how Addie helps health systems, post-acute providers, and payers improve throughput, reduce avoidable days, and deliver better transitions of care.
Get Started