ABA prior authorization: what goes in the request and how long a payer has to answer
In this guide · 7 sections
An authorization number is not enough to make a claim payable. The approval can be for the wrong dates, service, units, provider, or location. The request, the tracker, the schedule, the note, and the claim need to describe the same service.
For a small applied behavior analysis (ABA) practice, the practical question is twofold: what belongs in the request, and when should this payer answer? The answer depends on the payer type, state, plan, and whether the request is complete.
Know which federal deadline applies
The Centers for Medicare & Medicaid Services (CMS) fact sheet and Interoperability and Prior Authorization Final Rule, CMS-0057-F, describe process requirements for specific "impacted payers." Those include Medicare Advantage organizations, state Medicaid and Children's Health Insurance Program (CHIP) fee-for-service programs, Medicaid managed care plans, CHIP managed care entities, and qualified health plan issuers on federally facilitated exchanges.
For prior authorization decisions on items and services other than drugs, the rule generally requires impacted payers other than those qualified health plans to send decisions within 72 hours for expedited requests and seven calendar days for standard requests. It also requires a specific reason when an impacted payer denies a request.
The operational requirements began January 1, 2026 for Medicare Advantage and state Medicaid and CHIP fee-for-service programs. For Medicaid and CHIP managed care, compliance attaches to rating periods beginning on or after January 1, 2026. That distinction matters. Do not state that every managed care plan in every state changed on January 1.
The rule does not put every employer-sponsored commercial plan under those decision timeframes. Qualified health plans on federally facilitated exchanges have denial-reason and metrics requirements, but CMS did not apply the same 72-hour and seven-day decision deadlines to them in this rule.
What a complete ABA request may need
CMS's August 2026 State Medicaid and CHIP Applied Behavior Analysis Toolkit is guidance to states, not a universal provider form. It discusses treatment planning and reauthorization elements that can help an owner review a payer's checklist.
Depending on the payer, a request may call for:
- Member and plan identifiers
- Referring or diagnosing provider information
- Diagnosis and supporting diagnostic record
- Assessment results and reassessment schedule
- Individualized treatment plan
- Measurable goals with baselines
- Planned services, frequency, and duration
- Caregiver goals when applicable
- Requested Current Procedural Terminology (CPT) codes and units
- Rendering provider, supervisor, group, and service location
- Anticipated duration, transition, or discharge planning
- Progress data for reauthorization
- Required signatures and dates
Do not add clinical detail simply because it might help. Send what the current payer policy and form require, using your privacy and security procedures. If the payer says the request is incomplete, record the missing item, the notice date, and when the corrected material was sent. A decision clock may depend on completeness under the applicable rule.
This work belongs to Authorizations, between benefit verification and clean claims.
Build one tracker that follows the approval
One controlled source of truth can help intake, scheduling, clinical operations, and billing compare the same authorization fields. Limit access by role, use the minimum necessary information, and apply the practice's privacy, security, retention, and access-review procedures. The controlled record may live in an approved system rather than one universal spreadsheet.
At minimum, track:
- Client record identifier
- Payer and exact product
- Request type: initial, change, or reauthorization
- Submission date and method
- Complete-request date, if different
- Standard or expedited status
- Reference number
- Requested codes and units
- Approved codes and units
- Units approved, units posted as used, units remaining, and the last reconciliation date
- Start and end dates
- Rendering provider or provider level
- Group, location, and place of service
- Authorization number
- Decision date and written notice
- Denial reason, appeal route, and deadline when applicable
- Reauthorization owner and next action date
A lead time is an internal operating choice unless a payer states it. A 30-day reauthorization reminder is not a universal rule. Work backward from the payer's current requirements, the authorization end date, and the time needed to prepare a complete clinical package.
Match the approval before each billing handoff
The live insurance verification checklist separates active coverage from authorization. Use both records.
active coverage isn’t approved hours. you need both before the first billable session.
- 1Before scheduling, confirm that the approval covers the intended date, code, provider or provider level, location, and available units.
- 2Before claim submission, compare the schedule and note to those same fields.
- 3Reconcile posted use back to the controlled record and investigate differences.
"Units used" should mean units reconciled from completed, documented services under the practice's defined workflow; "units remaining" should be the approved amount minus reconciled use, adjusted only for payer-approved changes.
An authorization does not guarantee payment. Eligibility can change. A provider may not be enrolled for the product or location. The service may not match the note. The claim may fail payer coding or filing rules. Keep authorization status specific.
Use the payer's public metrics carefully
CMS-0057-F requires impacted payers to publish specified prior authorization metrics. The first reporting cycle began in 2026 for prior-year data under payer-specific rules. A payer's page may show approval, denial, extension, and decision-time information.
Those metrics can help you understand a payer's published process. They do not predict whether one ABA request will be approved, and they are not a substitute for following up on a specific request. Alabama Medicaid's published page is one state example, not a national benchmark.
Prepare for the 2027 electronic exchange change
Prior Authorization application programming interface (API) requirements generally begin in 2027, with exact dates depending on payer type. An API can allow systems to check requirements, identify documentation, and exchange requests and decisions electronically. It does not remove the need to confirm the payer's rule or review the response.
If an authorization crosses January 1, 2027, ask the payer how it will handle revised ABA CPT codes and preserve the written answer with the authorization record.
Where this usually breaks
The request lives in a portal, the approved letter lives in email, the schedule lives in the clinical system, and the biller sees only an authorization number. The missing fields are often the fields that decide whether the claim matches.
Units remaining = approved − reconciled use. Example: 120 − 36 = 84
Bring the approval back into one structured tracker. Keep the payer scope and effective date attached to every rule. Escalate unanswered questions instead of guessing.
Want help finding the first place to check? Book a free billing review. No protected health information is needed.
Want help applying this to your practice?
We’ll look at what’s stuck in your billing and give you a one-page action plan — free, no commitment.
Book a free billing review