Top

Authorization Denial

Authorization denial is a payer decision to deny some or all claim lines because required prior authorization, precertification, or continued-stay approval was missing, expired, exceeded, or not documented correctly. Authorization denial can be technical, administrative, or clinical and often uses CARC codes such as CO-197 or CO-50.

Kathryn Thompson
Reviewed by Kathryn Thompson · Updated September 2026

What it means

What an authorization denial is

Authorization denial is a denial category where a payer refuses to pay for services because they were not covered under a valid authorization for that member, date range, level of care, or units. The issue is not coding or eligibility alone, it is the link between the service you billed and the authorization that the payer expected to see.

An authorization denial can be:

  • Technical: You had an authorization, but the number was missing, wrong, or not linked to the correct dates, CPT/HCPCS codes, or level of care on the claim.
  • Administrative: No authorization or notification was obtained before or during treatment even though the benefit required it.
  • Clinical: A concurrent review or medical-necessity review ended the authorization early or denied certain days, so units beyond that decision deny.

Unlike claim rejections, authorization denials usually come back on a remittance advice (835 / EOB) with a CARC and RARC, and often can be appealed, corrected, or addressed with retro-authorization within payer rules.

Why authorization denials matter operationally

Authorization denials are expensive because the allowed amount for the affected lines often goes to zero. For per-diem and long-stay behavioral programs, one missed or expired authorization can wipe out weeks of residential, PHP, or IOP revenue in a single denial.

They also create long-tail AR. Each authorization denial usually requires chart review, digging through portals or faxed authorizations, and coordination with clinicians or utilization review staff. That turns a one-touch claim into a multi-touch case, which drives up cost to collect and increases the risk that appeals miss timely limits.

Authorization denials are also an audit and compliance risk. Sloppy workflows around backdated orders, retro-authorization requests, or "creative" documentation to justify after-the-fact approvals can trigger payer scrutiny. Clean authorization management protects not only cash but also your utilization review and clinical teams from being pulled into avoidable payer disputes.

How to identify and work an authorization denial

Operationally, you spot authorization denials by how they appear on the remittance advice. Common patterns include:

  • CARC CO-197: "Precertification/authorization/notification absent." This is the classic code for missing or invalid authorization.
  • CARC CO-50: "These are non-covered services because this is not deemed a 'medical necessity' by the payer." In behavioral health, this often reflects a clinical denial tied to authorization or concurrent review.
  • CARC CO-16 + RARCs such as N130: "Claim/service lacks information" combined with a remark to check guidelines, which can point to a missing auth number or mismatch with plan rules.

When working an authorization denial, your first move should be classification. Ask three questions:

  1. Did an authorization exist at the time of service and is it visible in your system or the payer portal?
  2. Did the payer deny for technical reasons (missing or wrong auth number, code mismatch, incorrect dates) or for clinical reasons (service not medically necessary beyond a certain date or level of care)?
  3. Is retro-authorization or appeal allowed under this payer's policy and this product line (Medicare Advantage, Medicaid MCO, commercial)?

Your workflow then branches:

  • Technical issues: Correct the claim with the right auth number, units, or dates and resubmit, or send a corrected claim if the payer requires one.
  • Administrative "no auth" cases: Request retro-auth if permitted, often backed by clinical documentation, or adjust off when the plan explicitly excludes retro-approval.
  • Clinical denials: Use formal appeal or peer-to-peer review, with strong clinical notes, treatment plans, and ASAM-aligned criteria to support medical necessity.

A mature denial process will segment authorization denials in your denial reporting, report on them by payer and program, and tie them back to front-end workflows in benefits verification and utilization review so you reduce them at the source.

Common mistakes

  • Treating every CO-197 denial as non-appealable and writing off large residential or PHP stays, when the authorization actually exists but was not attached to the correct dates or program level in the claim.
  • Resubmitting the same claim multiple times without fixing the missing or incorrect auth number, which just generates repeated CO-197 or CO-16 denials and burns timely appeal windows.
  • Not tracking concurrent review end dates for per-diem residential stays, so days 11-21 get billed under the assumption of continued auth and later deny as non-authorized or not medically necessary.
  • Lumping clinical concurrent-review denials (payer shortens the stay using CO-50) together with simple missing-auth denials, which hides patterns that need different prevention tactics and appeal strategies.
  • Assuming that Medicaid or Medicaid MCOs will always allow retro-authorization for crisis admissions, and waiting too long to submit documentation so the request is rejected on timeliness, not clinical merit.

Why it matters in behavioral health

Behavioral health programs are highly exposed to authorization denials because many services sit under separate behavioral health benefits or carve-out vendors that have strict utilization management rules. A residential or IOP program might have three entities in the mix: the medical plan, the behavioral health carve-out, and a state Medicaid agency or MCO, each with its own authorization requirements and portals.

For long per-diem episodes such as residential treatment, partial hospitalization, and intensive outpatient, authorizations are often issued in short blocks with required concurrent review. If utilization review does not get the next block approved on time, the claim still goes out and looks clean, but all days after the last approved date deny. On paper your denial rate might look fine by claim count, while you are losing a large share of total authorized days by dollar amount.

State Medicaid and Medicaid MCOs frequently require service authorizations tied to very specific procedure codes, ASAM level-of-care descriptors, or modifiers. If your clinical team documents Level 3.5 but the claim goes out under a code commonly mapped to Level 3.1, the system can read that as a mismatch and deny days as unauthorized or not medically necessary. Carve-out vendors also may require separate authorizations for therapy vs medication management vs MAT, so one missing authorization can deny the entire episode even if other pieces were approved.

Behavioral health operators need tight coordination between scheduling, utilization review, and billing so that changes in level of care, step-downs, or extension requests are reflected in both the clinical record and the billing authorization grid. Without that, denials show up weeks later when the 835 posts and the opportunity for retro-authorization may already be gone.

How AI can help with Authorization Denial

AI can help with authorization denials by reading every 835 remittance and classifying denials consistently based on CARC/RARC combinations, payer, and program. Instead of a biller manually scanning lines for CO-197 or CO-50, an agent can tag the denial as technical vs clinical, surface whether an auth exists in your system, and group similar cases for bulk correction or appeal templates.

At Supabill, the denials agent holds payer-specific rules about which CARC/RARC codes map to authorization problems and can auto-route cases: missing auth numbers for rebill, likely retro-authorization opportunities to utilization review, and clear medical-necessity denials to your clinical leadership for peer-to-peer. A benefits-verification agent can also capture and store authorization requirements and reference numbers before treatment starts. Humans still own the high-judgment work: pushing for retro-auth in gray-zone situations, performing peer-to-peer reviews, and deciding when to fight a clinical denial versus adjusting off and tightening front-end workflows.

FAQ

How is an authorization denial different from a medical necessity denial?

Authorization denial focuses on whether a valid authorization existed and was properly documented for the service, date range, and level of care. Medical necessity denials focus on whether the service itself met the payer's clinical criteria. In behavioral health, the two often overlap: a concurrent review might end an authorization early for medical-necessity reasons and the payer then uses CO-50 for days beyond that date. Operationally, you work technical and administrative authorization denials with corrected claims or retro-auth requests, and you work medical-necessity denials through formal appeal, clinical letters, and sometimes peer-to-peer review.

Can you fix an authorization denial with a corrected claim, or do you always need an appeal?

It depends on why the authorization denial occurred. If an authorization exists and the denial is purely technical, many payers allow a corrected claim that adds the correct auth number, fixes the place of service, or adjusts the billed units to match what was approved. If there was no authorization on file at the time of service, you generally need to secure retro-authorization first or submit a formal appeal asking the payer to override its policy based on clinical circumstances. Medicare traditional rarely uses prior authorization in behavioral health, but Medicare Advantage, Medicaid MCOs, and commercial plans often have specific rules for both corrected claims and retro-auth requests. Source

Do Medicaid and Medicaid managed care plans require prior authorization for behavioral health services?

Many state Medicaid programs and Medicaid managed care organizations require prior authorization for certain behavioral health services, especially residential treatment, PHP, IOP, ABA, and some medication-assisted treatment. Requirements vary widely by state and plan, including which levels of care, duration limits, and ASAM criteria apply. Because policies differ, your team should maintain payer-specific grids for which behavioral services require prior auth and how often concurrent review is needed, and refresh them when state or contract rules change. Source

How can a billing team tell whether an authorization denial is clinical or technical?

Start by looking at both the CARC and RARC on the remittance, then cross-check against your authorization records and payer portal. If you see CO-197 with language about missing authorization and you cannot find an auth number, that points to an administrative or technical problem. If the denial only applies to some days or units, and the RARC references guidelines or medical necessity, that usually means the authorization ended earlier than you expected or a concurrent review shortened the stay. In that case the denial is clinical, and you will need clinical documentation and possibly a peer-to-peer review to contest it.

What is the best way to prevent authorization denials in a behavioral health program?

Prevention is about tight integration between benefits verification, scheduling, and utilization review. Before admission or start of treatment, confirm whether the benefit is managed by a behavioral health carve-out, what requires prior auth, and any limits on days or units. During treatment, track expiration dates and approved units for each level of care and trigger concurrent review requests early. On the billing side, ensure your EHR or practice-management system stores the correct authorization number, links it to the right encounter and CPT codes, and validates that claims are within the authorized ranges before submission. Source

Sources

AI agents that run your billing.

The first agentic RCM that actually works.

Book a live demo