CMS-0062-P remains a proposed rule, but the FY2027 IPPS final rule effective October 1 independently adopted updated versions of seven FHIR implementation guides originally proposed in CMS-0062-P. With the January 1, 2027 CMS-0057-F deadline approaching, payer and vendor teams need a version-governance review, not an assumption that compliance scope has been rewritten.
CMS-0062-P remains proposed, and its drug prior-authorization requirements are not yet enforceable. But the FY2027 IPPS final rule, effective October 1, independently adopted updated versions of seven FHIR implementation guides originally proposed in CMS-0062-P. That does not automatically turn the new versions into universal CMS-0057-F migration mandates. It does create an immediate governance question for payers and vendors approaching the January 1, 2027 API deadline: which versions are in production, which versions do trading partners support, and which version decisions are legally required versus technically prudent?
CMS-0057-F builds on the existing Patient Access and Provider Directory API framework. For impacted payers, it expands the Patient Access API to include non-drug prior-authorization data and requires three additional APIs: Provider Access, Payer-to-Payer, and Prior Authorization, primarily by January 1, 2027.
Impacted payers under CMS-0057-F include Medicare Advantage organizations, state Medicaid and CHIP fee-for-service programs, Medicaid managed care plans, CHIP managed care entities, and Qualified Health Plan issuers on the Federally Facilitated Exchanges. The Provider Directory API obligations for these payers arose principally under CMS-9115-F (the 2020 Interoperability and Patient Access final rule); CMS-0057-F adds the Provider Access, Payer-to-Payer, and Prior Authorization API requirements, and expands Patient Access API content to include non-drug prior authorization data.
The rule also carries operational provisions with compliance dates starting 01-01-2026, including decision timeframes for non-drug PA and provider notice requirements. The applicable CMS-0057-F API compliance dates are the near-term delivery risk; the prior-authorization decision-timeframe and notice requirements had earlier compliance dates.
CMS-0057-F's API requirements rest on mandated technical standards and CMS-recommended implementation guides. CMS's current guidance identifies FHIR R4.0.1, USCDI Version 3, US Core 6.1.0, and SMART App Launch 2.0.0 as part of the current standards environment, with Bulk Data Access v1.0.0 applying to the Provider Access and Payer-to-Payer APIs. CMS also maps recommended IGs by API, including CARIN Blue Button, PDex, US Drug Formulary, Plan Net, CRD, DTR, and PAS. CMS's current API guidance identifies updated versions of key standards, including US Core 6.1.0 and SMART App Launch 2.0.0. Teams still using older versions should confirm the applicable regulatory, certification, and trading-partner implications rather than assuming that an earlier implementation remains the optimal production target. The CMS-0057-F rule originally published a set of recommended implementation guides, including Da Vinci CRD STU 2.0.1, DTR STU 2.0.0, PAS STU 2.0.1, PDex US Drug Formulary STU 2.0.1, PDex Plan Net STU 1.1.0, and CARIN Blue Button STU 2.0.0. These IGs were recommended rather than required. That distinction matters: a recommendation can guide interoperable implementation without itself creating a blanket compliance obligation.
CMS-0062-P proposed making those IGs required and upgrading to newer versions. The FY2027 IPPS final rule (CMS-1849-F) finalized ONC's adoption of updated versions of seven implementation guides, effective 10-01-2026:
Where ONC had previously adopted earlier versions through the FY2026 IPPS/HTI-4 final rule, those earlier adopted versions were replaced effective October 1, 2026.
Because those IG version proposals originally lived in CMS-0062-P, many implementation teams treated CMS-0062-P finalization as the trigger for their IG version decisions. The reasoning was defensible: if the IG requirements are tied to the drug PA rule, the drug PA rule needs to finalize before you lock your standards.
That reasoning collided with reality on 10-01-2026.
The FY2027 IPPS final rule placed updated FHIR implementation guide versions into the federally adopted standards environment independent of CMS-0062-P's finalization. CMS has not stated that the IPPS-adopted versions automatically supersede CMS-0057-F's recommended IGs as a universal January 1 migration mandate. CMS continues to characterize the Table H3 IGs as recommended rather than required, while permitting updated versions of required standards under specified conditions. The practical requirement is version governance: teams need to document their selected versions, trading-partner support, applicable certification status, and the effect of version choices on end-user access to required API data. CMS currently describes CMS-0057-F IG selections as recommended and notes that impacted payers may use updated standards, specifications, or IGs where the updated version is not prohibited by applicable law, is ONC-approved, and does not disrupt end-user access to required API data. That means adoption of the newer IG versions is not automatically the same as a new universal payer compliance mandate, and teams should not assume that an existing implementation built to the CMS-0057-F recommendations is immediately out of compliance.
This is the critical distinction: finalized standards adoption is not the same as finalizing the drug PA policy scope, and it is not automatically the same as rewriting every CMS-0057-F payer implementation obligation. October 1 placed updated implementation guide versions into the federally adopted standards environment. It did not make drug PA decision timelines, NCPDP pharmacy-benefit requirements, drug PA reporting requirements, or drug PA data fields in the Patient Access, Provider Access, and Payer-to-Payer APIs enforceable. Those still live in CMS-0062-P, still proposed, still not finalized. Drug prior authorization requirements proposed in CMS-0062-P are not yet compliance obligations.
The FY2027 IPPS final rule did not finalize CMS-0062-P's drug prior-authorization mandates or automatically rewrite every CMS-0057-F payer implementation obligation. It did, however, place updated versions of key FHIR implementation guides into the federally adopted standards environment. With the January 1, 2027 API deadline approaching, payer and vendor teams should perform a version-governance review: confirm what their current build uses, what their partners support, which standards and IG versions CMS permits or recommends, and whether advancing versions now would create interoperability risk.
If your implementation team locked IG versions months ago against the original CMS-0057-F recommendations, the federal standards landscape has since changed. That does not by itself require an immediate migration, but it does require the organization to assess whether its chosen versions remain appropriate, supported by vendors and trading partners, and compatible with current CMS guidance. CMS has not stated that the IPPS-adopted versions automatically supersede CMS-0057-F's recommended IGs as a universal January 1 migration mandate. CMS continues to characterize the Table H3 IGs as recommended rather than required, while permitting updated versions of required standards under specified conditions. The practical requirement is version governance: teams need to document their selected versions, trading-partner support, applicable certification status, and the effect of version choices on end-user access to required API data. A version mismatch discovered in functional testing is an expensive problem with 90 days remaining. One found in production after January 1 is worse. The task now is a deliberate version-governance review, not a blanket assumption that the adoption requires immediate migration.
The CARIN Blue Button IG warrants specific attention: it drives the clinical content structure flowing through the Patient Access and Provider Access APIs. A version delta between your FHIR server output and what your trading partners expect will surface when data consumers attempt to parse the response.
The PAS, CRD, and DTR implementation chain is the other pressure point. In practice, many organizations are implementing the Prior Authorization API through the Da Vinci CRD-DTR-PAS workflow: CRD can identify whether prior authorization is required, DTR can retrieve documentation templates and rules, and PAS can support electronic request and response exchange. CMS recommends these IGs as a way to implement the required functionality; teams should confirm their chosen workflow provides the full required capability and interoperates with provider systems.
If trading partners implement incompatible IG versions, profiles, or mappings, the workflow can fail even where each endpoint is technically available. Version alignment and partner testing are therefore central implementation risks.
With roughly 90 days to January 1, clarity on what to lock for existing CMS-0057-F obligations, and what to keep adaptable pending CMS-0062-P finalization, is operational, not academic.
Lock now, for the 01-01-2027 deadline:
Keep flexible, pending CMS-0062-P finalization:
None of the drug-specific CMS-0062-P proposals is currently a finalized January 1, 2027 federal compliance obligation. Organizations may nevertheless choose to build shared capabilities early where that aligns with vendor road maps, existing contractual obligations, or enterprise architecture.
The planning assumption that has created the most exposure is this: treat CMS-0062-P finalization as the trigger for all FHIR standards decisions. Teams that made that assumption built in a dependency that does not exist. The FY2027 IPPS final rule placed updated IG versions into the federally adopted standards environment before the drug rule finalized. The standards track and the policy scope track have now diverged.
That divergence has a practical consequence: if you are waiting for CMS-0062-P to finalize before you conduct a version-governance review, you may not be ready to deploy on January 1. And if you locked IG versions before October 1 and have not assessed them against the versions now federally adopted through IPPS, you are carrying unexamined risk.
CMS-0062-P will finalize when it finalizes. There has been no announcement of a finalization timeline, and the drug PA requirements it proposes are not enforceable until that happens. But the API deadline does not wait for the policy package to close. The federally adopted standards environment changed. January 1 did not move.
CMS-0062-P remains proposed, and its drug-specific prior-authorization mandates are not yet enforceable. But the FY2027 IPPS final rule has already advanced the federally adopted versions of seven related FHIR implementation guides. That does not compel a blanket last-minute migration. It does compel a documented version-governance decision: identify what is required, what CMS recommends, what the organization has implemented, what trading partners support, and whether changing versions before January 1 would improve or impair interoperability. The drug-policy package can remain pending; the CMS-0057-F delivery date cannot.
Discover how Addie helps health systems, post-acute providers, and payers improve throughput, reduce avoidable days, and deliver better transitions of care.
Get Started