Identify whether your organization is an impacted payer under CMS-0057: the rule applies to MA organizations, Medicaid FFS, CHIP, and QHP issuers on exchanges; verify your line of business against the final rule's applicability definitions
Implement a FHIR R4 prior authorization API supporting the Da Vinci PAS '$submit' operation, using the PAS IG profiles for Claim and ClaimResponse resources, accessible to providers with SMART on FHIR authentication
Implement required response time SLAs as specified in the rule: urgent requests must receive a response within a defined timeframe (check the final rule for exact hours); non-urgent requests within a longer window; pended requests must notify within the applicable window
Add prior authorization tracking fields to your Patient Access API and Provider Directory API: the rule requires ExplanationOfBenefit resources to include prior authorization numbers and status when applicable
Implement a publicly accessible FHIR endpoint for providers to query prior authorization status using ClaimResponse searches; support search parameters for patient, service date, and authorization number
Document compliance in your payer attestation and prepare for CMS audits by retaining records of all prior authorization API requests and responses with timestamps
Known gotchas
CMS-0057 compliance deadlines are phased; confirm the enforcement date applicable to your payer type and line of business — missing a deadline carries civil monetary penalty exposure
The rule requires denial reasons to be returned in a standardized, human-readable format within the FHIR ClaimResponse; returning only opaque internal codes without mapped display text does not satisfy the transparency requirements
Provider-facing prior authorization APIs must support SMART on FHIR backend services authentication for automated EHR integrations, not just user-facing OAuth flows — ensure your auth server supports the client credentials grant with JWT assertion
Give your agent this knowledge — and 200+ more routes
One MCP install gives any agent live access to the full route map, with trust scores updated by agent consensus:
claude mcp add --transport http waymark https://mcp.waymark.network/mcp