One health plan posted an 832-page list of billing codes without a word of plain English. Another buried its required data behind a password-protected portal. A third published numbers that didn't add up — and admitted its own data "should not be relied upon."
That's what the AMA found when it audited 15 Medicare Advantage plans for compliance with CMS's new prior authorization transparency requirements. These aren't obscure regulatory footnotes. They're the data your practice needs to know which services require authorization, from which payers, with what turnaround times — and most plans are making it nearly impossible to access.
For practices still tracking PA requirements manually, this is a nightmare. For practices running AI, it's an opportunity.
What CMS-0057-F Actually Requires — and Why It Matters Now
The CMS-0057-F Interoperability and Prior Authorization final rule, finalized in 2024, includes transparency provisions that took effect in 2026. The requirements are specific and consequential for every practice that submits prior authorizations:
- Machine-readable lists of all items and services requiring prior authorization, published publicly by every health plan in Medicare Advantage, Medicaid managed care, and ACA marketplaces
- Separate lists for standard and expedited request pathways
- Free, open, publicly accessible publication — not behind password-protected portals (CMS explicitly stated that portal-only access "does not satisfy the requirement")
- Plain-language service descriptions alongside procedure codes (CPT codes alone are insufficient)
- Turnaround times in hours if less than one day (not "0 days")
- Clear denominators specified for each reported metric
In theory, this transparency gives practices an unprecedented view into payer PA requirements. In practice, the AMA's audit shows most plans are turning compliance into a compliance theater that's worse than no data at all.
The AMA Audit: How Health Plans Are Weaponizing Compliance
AMA President Willie Underwood III reviewed 15 Medicare Advantage plans and the findings are damning:
"Patients should not need a portal password, a billing manual or medical training to find and understand a health plan's prior authorization practices." — AMA President Willie Underwood III
The specific failures paint a picture of systematic obstruction:
- The 832-page code dump: One plan posted 832 pages of raw billing codes — CPT, HCPCS, ICD-10 — without a single plain-language description. A practice manager trying to determine whether a specific procedure requires PA would need to know the exact billing code, then cross-reference it against 832 pages. This technically satisfies the letter of the old regulation while violating its entire purpose.
- Portal-locked data: Multiple plans published their PA lists exclusively through password-protected portals, requiring provider credentialing just to see what services need authorization. CMS has now explicitly stated this doesn't count.
- Self-contradicting numbers: One plan published metrics that didn't add up and acknowledged its own data "should not be relied upon." When a plan publicly admits its transparency data is unreliable, the transparency mandate has failed at the most fundamental level.
CMS responded with updated guidance addressing each of these failures — plain language required, portal-only access prohibited, hours-based turnaround reporting mandated. But updated guidance doesn't solve the operational problem. Even good transparency data is useless if your staff can't operationalize it.
Why Manual PA Tracking Is Already Broken — and Getting Worse
Consider what a billing team faces right now. Under CMS-0057-F, every health plan in MA, Medicaid managed care, and ACA marketplaces must publish and maintain its PA requirements list. For a practice that contracts with 15 payers, that's 15 separate lists — each updated on the plan's own schedule, in the plan's own format, with the plan's own interpretation of "plain language."
Now add the expanding PA footprint. CMS has 8 new botulinum toxin injection codes slated for prior authorization requirements in traditional Medicare. PA requirements are growing, not shrinking, even as CMS pushes transparency.
The FHIR electronic PA mandate makes this even more urgent. CMS has laid out a clear timeline:
| Year | Electronic PA Status | Impact |
|---|---|---|
| 2027 MIPS | Optional (bonus points) | Early adopters gain MIPS scoring advantage with FHIR-enabled CEHRT |
| 2027 Ambulatory Specialty Model | Optional reporting | Mandatory model participants begin electronic PA measurement |
| 2028 MIPS | Mandatory | Most physicians must demonstrate electronic PA capability |
| TBD (MSSP) | Under CMS review | ACOs likely next for FHIR-enabled electronic PA requirements |
The trajectory is unmistakable. Practices that don't have AI-powered PA infrastructure by 2027 will be building it under deadline pressure in 2028 — while simultaneously absorbing new PA requirements like the botulinum toxin codes, managing 15+ payer transparency lists, and trying to hit MIPS quality thresholds.
How AI Turns Transparency Data Into Automated Compliance
Machine-readable PA lists weren't designed for human consumption. They were designed for exactly what AI does: ingest structured data, parse it, map it to operational workflows, and act on changes automatically.
Here's what AI-powered PA compliance monitoring looks like in practice:
1. Continuous List Ingestion
AI agents monitor every contracted payer's machine-readable PA list on a continuous cycle. When Aetna updates its MA plan to add a new procedure code, the AI detects the change within hours — not weeks later when a claim gets denied. The 832-page code dump? AI parses it in seconds, maps every code to plain-language descriptions, and flags the specific services your practice actually performs.
2. Payer Rule Auto-Update
When a payer changes its PA requirements, AI automatically updates the practice's internal rule engine. Staff don't need to read a bulletin. Nobody needs to update a spreadsheet. The eligibility verification workflow automatically incorporates the new requirement the next time that service is scheduled.
3. Real-Time Authorization Checks at Scheduling
When a patient schedules a procedure, AI cross-references the CPT codes against every active payer PA list. If authorization is required, the system initiates the PA request before the patient arrives — not when the biller discovers the requirement days after the service was rendered. This is the front-end prevention that eliminates authorization-related denials entirely.
4. Compliance Gap Detection
AI compares what plans publish against what they actually enforce. When a plan's published turnaround time says "72 hours" but their actual response patterns show 5-7 business days, AI flags the discrepancy. When a plan's data "should not be relied upon" — as one plan admitted — AI cross-validates against denial patterns and historical authorization outcomes to build a more accurate operational picture.
5. FHIR-Ready Electronic PA Submission
With the 2028 MIPS mandate approaching, AI systems built on FHIR standards are already submitting electronic prior authorizations through standardized APIs. Practices using AI PA automation today won't need a retrofit when the mandate hits. They'll already be compliant — and they'll have 18+ months of performance data to demonstrate it.
The AMA's Bigger Push: What's Coming Next
The AMA isn't stopping at transparency audits. They're pushing for structural changes that will further advantage AI-powered practices:
- Regulations covering all PA-like processes: Any process functioning as prior authorization — regardless of what it's called (including "precertification" delegated to third-party vendors) — should be subject to the same transparency requirements. This closes the loophole where plans outsource PA to vendors who operate outside the transparency mandate.
- PA metrics at point of enrollment: The AMA wants PA data available to prospective members on Medicare Plan Finder and Healthcare.gov, so patients can factor authorization burden into plan selection. This creates competitive pressure on plans with excessive PA requirements.
- Standardized templates: Currently recommended but not required. The AMA wants mandatory standardized formats so that PA data is comparable across plans — exactly the kind of structured consistency that makes AI ingestion even more efficient.
"Consistent formats would make information easier for patients and physicians to understand and compare across plans." — AMA
Every one of these changes makes AI-powered PA monitoring more valuable. Standardized templates mean cleaner data ingestion. Point-of-enrollment metrics mean more data points for AI to analyze. Universal coverage of PA-like processes means no blind spots in the AI's payer rule engine.
The Manual vs. AI PA Compliance Gap
The gap between manual and AI PA compliance widens with every regulatory update:
| Capability | Manual Process | AI-Powered PA |
|---|---|---|
| PA list monitoring | Quarterly review (if at all) | Continuous, automated |
| New requirement detection | Discovered via denied claims | Detected same day as publication |
| 832-page code dump processing | Days of staff time | Seconds |
| Multi-payer rule synchronization | Spreadsheets, tribal knowledge | Unified rule engine, auto-updated |
| FHIR electronic PA readiness | Requires system upgrade | Built-in from day one |
| Compliance gap detection | Reactive (post-denial) | Proactive (pre-submission) |
| 2028 MIPS readiness | Rush implementation under deadline | Already compliant |
The practices that treat CMS-0057-F transparency data as an AI input — not a staff reading assignment — will have a structural advantage that compounds every quarter. More accurate PA submissions. Fewer authorization-related denials. Faster turnaround on urgent requests. Complete compliance with the FHIR mandate before it arrives.
The Bottom Line: Transparency Data Is AI Fuel
CMS didn't create transparency requirements so that billing staff could read 832-page documents. It created them so that the prior authorization process could become standardized, measurable, and — ultimately — automated. The health plans that are currently gaming the requirements with code dumps and portal locks are fighting a losing battle against a regulatory trajectory that points directly at FHIR-based electronic PA.
The practices that win are the ones that treat every payer's machine-readable PA list as a data feed — not a PDF to file. AI reads what your staff can't. It updates what your spreadsheets won't. And it submits what your fax machine shouldn't.
The 2028 MIPS mandate isn't a deadline. It's an inevitability. Build the AI PA infrastructure now — while it's still a competitive advantage and not a compliance scramble.