Operations · Authorizations

ABA prior authorization: what goes in the request and how long a payer has to answer

6 min read
5Part of Operations · Level 5Authorizations — Have every hour authorized before it's delivered. See how we handle it →
In this guide · 7 sections
  1. Know which federal deadline applies
  2. What a complete ABA request may need
  3. Build one tracker that follows the approval
  4. Match the approval before each billing handoff
  5. Use the payer's public metrics carefully
  6. Prepare for the 2027 electronic exchange change
  7. Where this usually breaks

An authorization number is not enough to make a claim payable. The approval can be for the wrong dates, service, units, provider, or location. The request, the tracker, the schedule, the note, and the claim need to describe the same service.

For a small applied behavior analysis (ABA) practice, the practical question is twofold: what belongs in the request, and when should this payer answer? The answer depends on the payer type, state, plan, and whether the request is complete.

Know which federal deadline applies

The Centers for Medicare & Medicaid Services (CMS) fact sheet and Interoperability and Prior Authorization Final Rule, CMS-0057-F, describe process requirements for specific "impacted payers." Those include Medicare Advantage organizations, state Medicaid and Children's Health Insurance Program (CHIP) fee-for-service programs, Medicaid managed care plans, CHIP managed care entities, and qualified health plan issuers on federally facilitated exchanges.

For prior authorization decisions on items and services other than drugs, the rule generally requires impacted payers other than those qualified health plans to send decisions within 72 hours for expedited requests and seven calendar days for standard requests. It also requires a specific reason when an impacted payer denies a request.

The operational requirements began January 1, 2026 for Medicare Advantage and state Medicaid and CHIP fee-for-service programs. For Medicaid and CHIP managed care, compliance attaches to rating periods beginning on or after January 1, 2026. That distinction matters. Do not state that every managed care plan in every state changed on January 1.

The rule does not put every employer-sponsored commercial plan under those decision timeframes. Qualified health plans on federally facilitated exchanges have denial-reason and metrics requirements, but CMS did not apply the same 72-hour and seven-day decision deadlines to them in this rule.

Expedited: 72 hours Standard: 7 calendar daysfor items and services other than drugs
Medicare Advantage on the clock from Jan 1, 2026
Medicaid and CHIP fee-for-service on the clock from Jan 1, 2026
Medicaid and CHIP managed care rating periods starting on or after Jan 1, 2026
Plans on the federally facilitated exchanges denial reasons and metrics, not these clocks
Employer-sponsored commercial plans outside this rule's timeframes
CMS-0057-F decision timeframes apply to specific payer types. Identify the exact payer and product first.

What a complete ABA request may need

CMS's August 2026 State Medicaid and CHIP Applied Behavior Analysis Toolkit is guidance to states, not a universal provider form. It discusses treatment planning and reauthorization elements that can help an owner review a payer's checklist.

Depending on the payer, a request may call for:

  • Member and plan identifiers
  • Referring or diagnosing provider information
  • Diagnosis and supporting diagnostic record
  • Assessment results and reassessment schedule
  • Individualized treatment plan
  • Measurable goals with baselines
  • Planned services, frequency, and duration
  • Caregiver goals when applicable
  • Requested Current Procedural Terminology (CPT) codes and units
  • Rendering provider, supervisor, group, and service location
  • Anticipated duration, transition, or discharge planning
  • Progress data for reauthorization
  • Required signatures and dates

Do not add clinical detail simply because it might help. Send what the current payer policy and form require, using your privacy and security procedures. If the payer says the request is incomplete, record the missing item, the notice date, and when the corrected material was sent. A decision clock may depend on completeness under the applicable rule.

This work belongs to Authorizations, between benefit verification and clean claims.

Build one tracker that follows the approval

One controlled source of truth can help intake, scheduling, clinical operations, and billing compare the same authorization fields. Limit access by role, use the minimum necessary information, and apply the practice's privacy, security, retention, and access-review procedures. The controlled record may live in an approved system rather than one universal spreadsheet.

At minimum, track:

  • Client record identifier
  • Payer and exact product
  • Request type: initial, change, or reauthorization
  • Submission date and method
  • Complete-request date, if different
  • Standard or expedited status
  • Reference number
  • Requested codes and units
  • Approved codes and units
  • Units approved, units posted as used, units remaining, and the last reconciliation date
  • Start and end dates
  • Rendering provider or provider level
  • Group, location, and place of service
  • Authorization number
  • Decision date and written notice
  • Denial reason, appeal route, and deadline when applicable
  • Reauthorization owner and next action date

A lead time is an internal operating choice unless a payer states it. A 30-day reauthorization reminder is not a universal rule. Work backward from the payer's current requirements, the authorization end date, and the time needed to prepare a complete clinical package.

Match the approval before each billing handoff

The live insurance verification checklist separates active coverage from authorization. Use both records.

EligibilityIs the plan active? Active · ABA benefits today
AuthorizationAre the hours approved? 0 units approved yet

active coverage isn’t approved hours. you need both before the first billable session.

Eligibility and authorization are two different checks.
  1. 1Before scheduling, confirm that the approval covers the intended date, code, provider or provider level, location, and available units.
  2. 2Before claim submission, compare the schedule and note to those same fields.
  3. 3Reconcile posted use back to the controlled record and investigate differences.

"Units used" should mean units reconciled from completed, documented services under the practice's defined workflow; "units remaining" should be the approved amount minus reconciled use, adjusted only for payer-approved changes.

An authorization does not guarantee payment. Eligibility can change. A provider may not be enrolled for the product or location. The service may not match the note. The claim may fail payer coding or filing rules. Keep authorization status specific.

Use the payer's public metrics carefully

CMS-0057-F requires impacted payers to publish specified prior authorization metrics. The first reporting cycle began in 2026 for prior-year data under payer-specific rules. A payer's page may show approval, denial, extension, and decision-time information.

Those metrics can help you understand a payer's published process. They do not predict whether one ABA request will be approved, and they are not a substitute for following up on a specific request. Alabama Medicaid's published page is one state example, not a national benchmark.

Prepare for the 2027 electronic exchange change

Prior Authorization application programming interface (API) requirements generally begin in 2027, with exact dates depending on payer type. An API can allow systems to check requirements, identify documentation, and exchange requests and decisions electronically. It does not remove the need to confirm the payer's rule or review the response.

If an authorization crosses January 1, 2027, ask the payer how it will handle revised ABA CPT codes and preserve the written answer with the authorization record.

Where this usually breaks

The request lives in a portal, the approved letter lives in email, the schedule lives in the clinical system, and the biller sees only an authorization number. The missing fields are often the fields that decide whether the claim matches.

Portal · the requestEmail · the approved letterClinical system · the scheduleBilling · just an auth number
One controlled recordchecked against schedule · note · claim
Dates Code Units Provider Location

Units remaining = approved − reconciled use. Example: 120 − 36 = 84

Four scattered pieces become one controlled record. Example numbers only.

Bring the approval back into one structured tracker. Keep the payer scope and effective date attached to every rule. Escalate unanswered questions instead of guessing.

Want help finding the first place to check? Book a free billing review. No protected health information is needed.

Want help applying this to your practice?

We’ll look at what’s stuck in your billing and give you a one-page action plan — free, no commitment.

Book a free billing review