Top

CO-15: Required authorization number missing or bad

The payer is saying a required authorization or referral number is missing or invalid. The denied amount is treated as contractual and not billable to the patient unless you correct it.

What it means

The payer is telling you the claim needs a valid authorization or referral number and what you sent is missing, expired, or does not match their system. They see the service as not properly approved, so they are reducing payment under the terms of your contract. Mechanically, the claim failed an edit that checks the auth field against what is on file for that member, date range, level of care, or CPT/HCPCS. The denied amount is placed in contractual write off unless you correct the data with the proper auth number and get the payer to reprocess.

Why it happens in behavioral health

Behavioral health and SUD claims hit CO-15 often because almost every higher level of care needs preauthorization. Residential, detox, PHP, and IOP usually require an auth tied to exact date ranges and units, and the claim has to carry that exact number. If intake staff secured an auth but the number never made it into your billing system, your UB-04 goes out blank and the payer auto-denies with CO-15. You also see CO-15 when utilization management issues a new auth mid-stay but billing keeps using the original number. For example, a PHP gets extended after concurrent review, the payer issues a new auth span, and later days deny because the claim still shows the old number or wrong span. Telehealth IOP or outpatient psychiatry can hit the same problem when payers require a separate telehealth or group-therapy auth and the claim uses a generic outpatient number. Carve-out behavioral-health payers are strict about matching auths to level of care and provider. Claims may deny CO-15 if you bill under a different NPI or location than the one listed on the UM auth, or if group therapy codes are billed under an individual-therapy auth, even if the member clearly has behavioral benefits.

How to fix it

  • Confirm in the payer portal or UM system that an authorization exists for the member, level of care, dates, and provider NPI.
  • Check your claim to see if the auth or referral number is missing, mistyped, expired, tied to the wrong NPI, or for the wrong service type.
  • If a valid auth exists, update the claim with the correct auth number and correct span or units in your billing system.
  • If no auth exists, work with clinical and utilization review to request retro-authorization according to the payer's policy before appealing.
  • Resubmit a corrected claim electronically if the payer allows correction of missing or invalid auth numbers, otherwise file a formal appeal with UM records and proof of the auth.
  • After reprocessing, post the new remit, move any remaining CO-15 balance to contractual write off, and remove it from patient responsibility.

How to prevent it

  • At admission and before each concurrent review, verify in the payer portal that you have an active auth with correct dates, level of care, and provider NPI.
  • Feed UM data into your billing system so the correct auth number and span auto-populate claims by location, level of care, and payer.
  • Use claim-scrubber rules that flag behavioral-health claims missing an auth number or using one that does not match the billed dates or place of service.
  • When UM extends or changes an auth, update your scheduling and billing records the same day and rebalance any overlapping claims before submission.

AI agents that run your billing.

Denials like CO-15 are rarely a one-off. They trace back upstream to eligibility, coding, documentation, or a payer rule that changed. Supabill's agents work the whole revenue cycle to stop them at the source. See our guide on why behavioral health denials keep rising, or book a demo.

Book a live demo