Top

Authorization Span and Units

Authorization span and units refer to the approved date range and quantity of services (days, visits, hours, or units) that a payer has authorized for a specific level of care or service. Authorization span controls when care is covered, and authorized units control how much care is covered before new approval is required.

Kathryn Thompson
Reviewed by Kathryn Thompson · Updated September 2026

What it means

What "authorization span and units" means

Authorization span and units are the core details on a prior authorization or continued stay approval. They tell you when you can treat and how much you can bill under that approval.

  • The authorization span is the start and end date the payer has approved (for example: 02/01/2026 to 02/28/2026).
  • The authorized units are the quantity within that span (for example: 28 days of residential, 15 IOP visits, 120 units of 15 minutes each, or a fixed number of bed-days).

Every behavioral health auth has at least these three elements: the level of care or CPT/HCPCS code(s), the span dates, and the units. Miss any of those when you schedule or bill and you invite preventable denials.

Why authorization span and units matter operationally

Authorization span and units are not just a utilization concern. They are a revenue-control tool. Almost every CO-197 denial and many CO-97 or CO-109 denials in behavioral health trace back to a mismatch between billed dates or units and the approved span.

Operationally, auth span and units drive:

  • Scheduling: how far out you can book sessions or bed-days before you need concurrent review.
  • Billing rules: which dates and units your billing system should flag as non-billable or billable to self-pay.
  • Clinical transitions: when a client must step down a level of care, pause, or obtain additional auth.

If you bill even one day past the auth span or one unit over the limit, payers typically deny the full line. That pushes those dollars into AR, triggers avoidable appeals work, or writes them off entirely if you cannot retro-authorize.

How to read and use authorization span and units

When you receive an authorization approval by portal, fax, or EDI, you should pull out and normalize these items:

  • Span start and end dates: sometimes listed as "approved to" or "thru" date.
  • Authorized units and unit type: days, visits, hours, or 15-minute units, and whether they are per day or total for the span.
  • Service scope: exact level of care, CPT/HCPCS codes, and any modifiers attached to the auth.

In practice, you want your EHR or billing system set up so that:

  • Encounters cannot be scheduled or billed outside the auth span without a hard stop or a clear warning.
  • Bed-days or visits decrement against the authorized units in real time.
  • Staff see when units are nearly exhausted so concurrent review or a new auth can be initiated before dollars are at risk.

When you read remittance advice for a denial, compare the billed dates and units to the original auth span. If the denial lines up with units or dates outside the approved range, you can decide quickly whether to write off, rebill to self-pay, or pursue an appeal or retro-auth.

Common mistakes

  • Billing residential per diem through clinical discharge instead of auth end date, so the last 2 to 3 days of a 30-day stay deny with CO-197 when the payer only approved 27 days.
  • Assuming authorized units are per day when they are total for the span, for example billing 3 IOP group codes per day across 10 days against an auth for 20 total visits, which triggers CO-97 once the 20th visit is hit.
  • Not splitting claims when the authorization span changes mid-month, so a single UB-04 with dates 03/01 to 03/31 is billed under one auth and the last week denies as unauthorized units or dates.
  • Failing to update the EHR after concurrent review adds units, so staff stop services early while more days are actually approved, leaving authorized capacity unbilled.
  • Relying on verbal auth details from utilization review calls without getting the corrected auth letter or portal entry, then discovering during payment posting that the payer shortened the span or reduced units.

Why it matters in behavioral health

Behavioral health payers frequently carve out mental health and substance use benefits to separate vendors, and each vendor may define spans and units differently. One Medicaid MCO may approve residential as calendar days, while another approves as midnights or per-episode blocks. If your team does not capture those specifics, you risk systematic underbilling or repeated CO-197 denials.

Long episodes in residential, withdrawal management, PHP, and IOP make span and units management even more sensitive. Initial auths are often short, for example 3 to 7 days in detox or 10 days in residential, with required concurrent review to extend the span and add units. If concurrent review misses the deadline or clinical notes do not justify continuation, services roll into an unauthorized period in the middle of an active stay.

State Medicaid and Medicaid managed care contracts often set unique rules. Examples include hard caps on annual units per level of care, day limits that reset per calendar year rather than per episode, and special span rules for crisis or observation levels. Many plans also require that the authorization span align with specific ASAM level-of-care definitions, so a shift from 3.7 to 3.5 without a new or updated auth can make later days technically unauthorized even if the client remains in the same building. For behavioral health facilities, tight control of span and units is one of the only ways to keep concurrent authorization denials from becoming permanent write-offs.

How AI can help with Authorization Span and Units

AI can help by reading authorization letters, portal screenshots, and EDI responses, then extracting span dates, authorized units, and covered codes into a structured record tied to the client and episode. Agents can continuously compare scheduled or documented services against those rules, flag overage risk before the auth is exceeded, and alert utilization review staff when it is time to request more units or a new span.

At Supabill, the benefits-verification and auth agent can capture and normalize span and units across payers, then feed those constraints into a claims-scrubbing agent that holds payer-specific rules and stops claims that exceed approved dates or units. A denials agent can read every 835, classify CO-197, CO-16, N130, and MA130 denials by root cause, and point back to gaps in span or unit control. The human team still owns the judgment calls: negotiating exceptions with payers, conducting clinical concurrent review, deciding when to appeal versus write off, and updating program workflows so future spans and units are requested correctly.

FAQ

Is the authorization span based on admission date or on the payer's approved dates?

The authorization span is always based on the payer's approved start and end dates, not your facility's admission or discharge dates. Many behavioral health stays begin on a date different from the initial approved date, especially when admission occurs on a weekend and auth is obtained on the next business day. You should align billable dates with the approved span on the auth letter or portal entry and treat any care outside that span as either self-pay or subject to retro-auth efforts. Source

What counts as a "unit" in behavioral health authorizations?

Units are defined by the payer and the code set referenced in the auth. For outpatient psychotherapy, a unit often equals one CPT code per session. For IOP or PHP, a unit may be a visit or a group of hours per day. For residential and withdrawal management, units are usually days or bed-days. You need to check each auth to confirm whether units are per day, per week, or total for the span, since misinterpreting this is a common source of unauthorized-unit denials. Source

What happens if services continue after the authorized units or span are exhausted?

If services continue past the authorized units or beyond the span without an approved extension, payers usually deny those dates or units as not authorized, often with CO-197, N130, or MA130. Some payers will consider retro-authorization if you request it within a short window and provide strong clinical documentation. Others treat services outside the span as the patient's financial responsibility. From an RCM perspective, you should not assume retro-auth will fix the issue and should have a clear policy for when to seek retro-auth versus adjusting off. Source

Can one authorization span cover multiple levels of care in a behavioral health episode?

Most payers tie spans and units to a specific level of care, such as residential (commonly mapped to ASAM 3.5 or 3.7), PHP, or IOP. Moving a client from one level to another usually requires an updated auth, even if the same payer and facility are involved. Some Medicaid programs and MCOs allow a broader span that covers a continuum of care, but they still expect clear documentation for each level. When in doubt, verify with the payer whether the existing auth covers the new level of care or if a new span and set of units are required. Source

How should authorization span and units be stored in the EHR so they are useful for billing?

Authorization span and units should be stored as structured data tied to the payer, plan, episode, and level of care or codes, not as free-text notes. Ideally, your system enforces hard stops or high-visibility alerts when scheduled or documented services would exceed the span or units. That data should also be visible to utilization review staff, so concurrent review is triggered well before the span or units run out and so bills do not go out for unauthorized days by accident. Source

Sources

AI agents that run your billing.

The first agentic RCM that actually works.

Book a live demo