The Supa Journal
Behavioral Health

CO 197 denial code: preventable, and more appealable than you think

CO 197 means authorization was absent. It is the most preventable denial you get, and the data shows most practices never appeal the ones worth appealing.

RCM Expert, Supa · August 27, 2026 · 8 min read
Petals resting on still water, easily lifted but seldom retrieved - authorization denials overturned far more often than they are ever appealed

By Kathryn Thompson, RCM Expert, Supa

TL;DR: CO 197 means precertification or authorization was absent. It is the most preventable denial in this series, and it is also the one where appeal data is most striking. Across Medicare Advantage, only 11.5% of denied prior authorization requests were appealed in 2024, and 80.7% of those appeals were overturned.

Key takeaways

  • X12 defines code 197 as "Precertification/authorization/notification/pre-treatment absent."
  • Four in five appealed prior authorization denials in Medicare Advantage were overturned in 2024.
  • Only about one in nine denied requests was appealed at all.
  • Prevention beats appeal, but the appeal numbers say do both.
  • A retroactive authorization request is worth attempting before you write anything off.

There is a number in the Medicare Advantage prior authorization data that should change how your practice handles this code. Not the denial rate. The overturn rate.

Most practices treat an authorization denial as final. The data says it very often is not.

What does the CO 197 denial code mean?

X12 defines code 197 as "Precertification/authorization/notification/pre-treatment absent," effective from October 31, 2006 and last modified May 1, 2018 (X12).

The word doing the work is absent. The payer is not saying the service was unnecessary or not covered. It is saying a required approval step did not happen before the service was delivered.

What is prior authorization? A payer requirement to approve a service before it is provided. Without the approval, the payer declines payment regardless of whether the service was appropriate.

Note that the definition covers four distinct things: precertification, authorization, notification, and pre-treatment. Those are different requirements with different rules, and a payer requiring notification within 48 hours is imposing something quite different from one requiring approval before the first session. Read your contracts for which applies.

The group code is CO, so the amount is a contractual obligation rather than patient responsibility. You generally cannot bill the patient for a service you failed to get authorized, and attempting it is a fast route to a complaint.

How often is this actually denied, and how often is it overturned?

This is where the data is genuinely useful. In 2024, nearly 53 million prior authorization requests were submitted to Medicare Advantage insurers, and insurers "fully or partially denied 4.1 million prior authorization requests, which is a somewhat larger share (7.7%) of all requests" (KFF).

Now the part that matters for your workflow. "Just 11.5% of denied prior authorization requests were appealed to Medicare Advantage insurers in 2024," and of those appealed, "80.7%" were partially or fully overturned (KFF).

Read those two figures together. Roughly one in nine denials gets challenged, and four in five challenges succeed. The clear implication is that a large volume of appealable denials is being absorbed without anyone testing them.

The pattern holds in commercial coverage too. In ACA marketplace plans, KFF found "8% due to lack of preauthorization or referral" among stated denial reasons, while consumers appealed "less than two-tenths of 1%" of in network denials (KFF).

An honest caveat: those Medicare Advantage figures cover prior authorization request denials, which is a slightly different population from claims denied with CO 197 after the fact. The direction of the finding is still hard to argue with.

[Image: A funnel visualization showing 4.1 million denied prior authorization requests narrowing to 11.5 percent appealed, then 80.7 percent of those overturned, clean editorial data visualization, accent teal - alt='Only one in nine denied prior authorization requests is appealed, and four in five appeals succeed']

What do you do when a CO 197 arrives?

Work it in this order. Do not start with the appeal, and do not start with the write-off.

  1. Check whether authorization actually existed. Surprisingly often it did, and the number simply was not transmitted on the claim. That is a corrected claim, not an appeal, and it resolves in one cycle. This overlaps with CO 16, where missing information is the stated reason.
  2. Request retroactive authorization. Many payers permit it inside a defined window, particularly where the service was urgent or eligibility was unclear at the time. This is the step most often skipped.
  3. Check whether authorization was genuinely required. Requirements change, and they change more often than most practices track. A denial citing an absent authorization for a service that no longer requires one is worth challenging.
  4. Appeal with clinical documentation. If the service was necessary and delivered, the appeal is about medical necessity and the record supporting it.
  5. Write off only after the above. Given the overturn rates, writing off at step one is leaving money behind.

For the operational side of getting authorizations right in the first place, our guide to prior authorization in behavioral health covers the workflow.

Why is behavioral health hit harder by this?

Because authorization requirements in behavioral health are more granular, more variable between payers, and more likely to attach to session counts rather than to a single approved episode.

A medical procedure typically needs one authorization. A course of therapy may need an initial authorization, then a concurrent review at a set number of sessions, then another. Each of those is a separate opportunity to miss a deadline, and missing the second one denies every session after it.

That structure produces a specific failure mode worth watching for. The initial authorization is obtained carefully because someone owns it. The concurrent review is missed because nobody was tracking session counts against the approved number, and the denial arrives for sessions eleven through eighteen all at once.

The fix is a tracked session count against every active authorization, with a trigger before the limit rather than after it. That is a tracking problem, and tracking problems are solvable.

Where automation actually helps with CO 197

On both sides, which makes this the code where automation pays back most. Prevention removes most of the volume, and routing recovers a good share of what remains.

Requirement checking at scheduling. Whether this payer requires authorization for this service is a knowable fact at booking. Checking it then, across every appointment, is the intervention that prevents the denial outright.

Session count tracking against the authorization. The concurrent review failure is purely a counting problem. A system holding the approved number and the sessions delivered can raise the flag before the limit rather than after, which is the difference between a renewal and eight denied sessions.

Routing denials to the right path. A CO 197 where the authorization existed is a corrected claim. One where it did not may be a retroactive request or an appeal. Those are different workflows, and separating them automatically stops everything defaulting to write-off.

Supabill automates benefits verification across payers and manages denials with routing and appeals, which is aimed squarely at the gap the KFF numbers describe: denials that were appealable and never got appealed.

The limit is real and worth naming. Automation cannot obtain an authorization that a payer refuses to grant, and it cannot manufacture medical necessity. Where a service genuinely was not authorized and the payer will not grant it retroactively, the write-off is correct. What automation changes is that you reach that conclusion after testing it rather than instead of testing it.

Want authorization gaps caught at scheduling rather than on the remittance? Book a demo.

FAQ

Q: Can I bill the patient when I forgot to get authorization?

A: Generally no. CO 197 carries the contractual obligation group code, so the amount is absorbed by the provider. Billing a patient for your own administrative omission also creates a strong complaint risk, whatever the contract says.

Q: Is it worth appealing a CO 197 denial?

A: The data suggests yes far more often than practices assume. In Medicare Advantage, 80.7% of appealed prior authorization denials were overturned in 2024, while only 11.5% of denials were appealed at all.

Q: Can I get authorization after the service was provided?

A: Many payers allow retroactive authorization inside a defined window, particularly for urgent services or where eligibility was unclear. It is worth attempting before writing off, and it is the step most commonly skipped.

Q: What is the difference between CO 197 and CO 16?

A: CO 197 means the authorization was never obtained. CO 16 means required information was missing from the claim, which can include an authorization number that exists but was not transmitted. Check which situation you are in before choosing a corrected claim or an appeal.

Q: Why do I get denials for later sessions when the first ones were approved?

A: Because your authorization likely covered a set number of sessions and the concurrent review was missed. Track sessions delivered against sessions approved, and trigger the renewal before the limit rather than discovering it through a denial.

Q: Do authorization requirements change?

A: Frequently, in both directions. Payers add and remove requirements, so a requirement list verified a year ago is not reliable. This cuts both ways, since a denial citing a requirement that no longer exists is worth challenging.

RCM Expert, Supa

RCM expert at Supa. 20+ years building revenue cycle operations in healthcare; Adjunct Professor at Concordia University-St. Paul teaching healthcare MBA.

Keep reading

All articles
See it on your stack

Run this on your own practice.

Watch ambient agents handle your front desk, documentation, and billing — inside the tools you already use.

Book a demo