Medical Necessity
Medical necessity is the payer standard that a service must be clinically appropriate, consistent with accepted standards of care, and not primarily for convenience in order to be covered. Medical necessity is defined in federal and state rules and in individual payer policies, and it is the core reason behind many behavioral health authorization requirements and denials.
What it means
What medical necessity means
Medical necessity is the gatekeeper concept payers use to decide if a service is covered, even when the patient has active eligibility. In plain language, the service must be clinically appropriate for the diagnosis and severity, at the right level of care, and aligned with accepted standards of practice.
Most payer definitions share a few core elements:
- The service is reasonable and necessary to diagnose or treat an illness or condition.
- The service is provided at the most appropriate and least intensive level that can safely meet the patient's needs.
- The service is not primarily for the convenience of the patient, family, or provider.
- The service is supported by clinical documentation and treatment planning.
Medicare, Medicaid, and commercial plans all publish their own medical necessity policies. For Medicare, this often lives in National Coverage Determinations (NCDs) and Local Coverage Determinations (LCDs). Commercial payers use their own clinical guidelines or adapt tools such as ASAM criteria for substance use or other behavioral health guidelines.
Why medical necessity matters operationally
For revenue cycle, medical necessity is not theory. It is dollars and days in A/R. A claim can be perfectly coded and submitted on time, then still deny if the payer decides the service was "not medically necessary." These usually show up as CO-50 denials or a similar combination of CARC and RARC codes.
Operationally, medical necessity hits your workflow at several points:
- Benefits and auth: During benefits verification, you confirm whether a service requires prior auth and what criteria apply. Missing or weak auth exposes you to future medical necessity denials and CO-197.
- Clinical documentation: Progress notes, treatment plans, and discharge summaries must show why the level of care is needed and why it is still needed across days or weeks. If the documentation does not support the level, you invite payer downgrades or denials.
- Concurrent review and continued stay: For longer episodes, payers repeatedly check whether continued treatment remains medically necessary. If your team misses updates or sends thin clinical notes, coverage may stop mid-stay.
- Post-payment audit risk: Even paid claims can be recouped later if auditors decide they were not medically necessary. That turns into retrospective revenue loss and compliance risk.
Ignoring medical necessity usually does not hurt you on day 1. It shows up two or three months later as avoidable denials, long A/R tails, and unrecoverable write-offs.
How payers apply and communicate medical necessity
Payers do not "feel" medical necessity. They apply written criteria. For behavioral health this often includes:
- Diagnosis and severity thresholds.
- Risk factors such as suicidality, withdrawal risk, or functional impairment.
- Required interventions and frequency at each level of care.
- Defined discharge or step-down criteria.
These criteria live in multiple places: plan documents, behavioral health carve-out policies, medical policies on payer portals, Medicare NCDs and LCDs, and Medicaid provider manuals. Many are updated regularly, which creates operational drift if your team still works off last year's rules.
On paper and in remits, medical necessity shows up in different ways:
- Authorization letters: Approvals usually specify dates, units, and sometimes the guideline used. Anything outside that window is at risk.
- Denial letters and 835s: CO-50 is the classic "not medically necessary" CARC, sometimes paired with RARCs like N130 or MA130 that point to policy details or missing documentation.
- Explanation of Benefits (EOB): Patient-facing EOBs may say "service not covered" or "not medically necessary" which can trigger complaints or appeals.
Operationally, you want tight feedback loops between clinicians, utilization review, and your RCM team so everyone is working from the same understanding of what the payer will treat as medically necessary.
Common mistakes
- Treating an authorization as proof of medical necessity, then being surprised when days 11 to 20 of a residential stay deny as CO-50 because the concurrent review notes did not support continued stay criteria.
- Using the same canned residential or PHP progress note for all patients, so documentation never clearly ties risk, functional impairment, or failed lower levels of care to the current intensity, which gives payers an easy argument to downcode or deny.
- Not checking the behavioral health carve-out's separate medical necessity policy and assuming the medical plan's criteria apply, which leads to denials when the carve-out vendor uses a different guideline for IOP or SUD treatment.
- Ignoring RARCs like N130 or MA130 on a CO-50 denial and just writing off the balance, instead of reading the policy reference to see if an appeal or corrected documentation would restore coverage.
- Letting long-stay claims sit unbilled until discharge, then discovering too late that the payer only approved the first segment of treatment and will not pay the rest due to lack of timely concurrent reviews supporting continued medical necessity.
Why it matters in behavioral health
In behavioral health, medical necessity is often the main lever payers use to control costs for high-intensity and long-duration care. Residential, PHP, and IOP services are frequent targets. Payers may approve a short initial auth, then require intensive concurrent reviews to extend coverage. If your documentation does not hit each element of their level-of-care criteria, they label days as "custodial," "not acute," or "not medically necessary."
Carve-outs complicate this further. The behavioral health vendor may have completely different medical necessity criteria from the medical plan and may rely heavily on tools such as ASAM criteria or internal clinical guidelines. ASAM levels are commonly mapped to coverage rules, but each payer applies them differently. If your team does not know the specific carve-out's interpretation, you can lose whole weeks of residential or IOP revenue on a single case.
State Medicaid and Medicaid MCOs add another layer. Many have detailed medical necessity definitions in their state plans and provider manuals and often require specific psychosocial assessments, treatment plans, and evidence of community-based alternatives considered or tried. For SUD and mental health, Medicaid may require documented failure at outpatient or lower levels before approving residential. That means missing one sentence about prior treatment attempts can turn into a full denial on a 30-day stay.
Because behavioral health episodes are long and billed per diem or per service over weeks, medical necessity issues often surface late. By the time CO-50 denials hit your 835, you may be months past the dates of service with limited appeal windows, which turns into big-dollar write-offs rather than small clean-up tasks.
How AI can help with Medical Necessity
AI can help with medical necessity by doing the grunt work your team never has time for. An agent can pull the latest payer and carve-out policies, highlight the behavioral health criteria for each level of care, and flag mismatches between scheduled services and what the plan typically considers medically necessary. On the back end, AI can read every 835, cluster CO-50 and related RARCs like N130 and MA130, and surface patterns by payer, program, and length of stay so you know exactly where documentation and utilization review are falling short.
Supabill's benefits-verification agent can capture not just eligibility and copays, but also whether a service requires prior auth, whether it is managed by a BH carve-out, and any high-level medical necessity notes visible on the portal. The denials agent reads each remit, tags medical-necessity related denials, and routes them with payer-specific appeal deadlines and policy references. Supanote can support clinicians with structured templates that remind them to document risk, functional impairment, and failed lower levels of care tied to payer criteria. AI will not and should not make the clinical judgment call about whether treatment is appropriate, and it will not negotiate with medical directors. Your clinicians and utilization review team still own the story, the peer-to-peers, and the final decision to appeal or discharge.
FAQ
Who actually defines medical necessity for a given patient's coverage?
Medical necessity is defined primarily by the patient's benefit plan. For Medicare, the definition comes from federal law and CMS guidance, including National and Local Coverage Determinations that describe when services are considered reasonable and necessary for diagnosis or treatment. For Medicaid, each state's plan and Medicaid agency define medical necessity in statutes, regulations, and provider manuals. Commercial payers set their own criteria in plan documents and medical policies, and behavioral health carve-outs often publish separate guidelines. Providers contribute the clinical judgment and documentation, but the plan's definition controls whether the claim gets paid.
Is prior authorization a guarantee that services will be paid as medically necessary?
No. Prior authorization is only a preliminary approval based on the information available at the time. Payers often include language in auth letters that payment is still subject to medical necessity and coverage rules at the time of claim review. For behavioral health, that means even an approved residential or PHP auth can be partially denied later if concurrent documentation does not support continued medical necessity. Operationally, you should treat auth as a necessary condition, not a guarantee, and keep documentation aligned with the criteria throughout the stay. Source
How do medical necessity denials typically show up on remits and EOBs?
On the 835, medical necessity denials most often appear as CARC CO-50, sometimes combined with remark codes like N130 or MA130 that point to policy limitations or missing documentation. In some cases, payers use CO-16 plus a remark code that references medical necessity criteria or documentation requirements. Patient-facing EOBs usually translate this into phrases like "service not medically necessary," "not covered under plan guidelines," or "service not covered for this diagnosis." Your denials workflow should treat these as a distinct category, separate from technical denials like eligibility or timely filing.
What can behavioral health programs do upfront to reduce medical necessity denials?
The most reliable levers are upfront: use payer-specific intake and documentation checklists tied to the relevant level-of-care guidelines, confirm who manages the behavioral health benefit during benefits verification, and set a schedule for timely concurrent reviews on long stays. Clinicians should explicitly document risk, functional impairment, failed lower levels of care, and why a lower level is not safe yet. RCM should capture payer criteria in internal playbooks so utilization review, clinicians, and billers are working from the same expectations. Source
When is it worth appealing a medical necessity denial in behavioral health?
It is usually worth appealing when the documentation supports acute risk or high impairment that clearly meets the payer's written criteria, or when the denial letter misquotes or misapplies the plan's own policy. Large-dollar denials on residential, PHP, or IOP are especially appeal-worthy if the episode length is significant. Before appealing, compare the denial rationale to the plan's published behavioral health or ASAM-based policies and confirm you have progress notes, assessments, and treatment plans that speak directly to each criterion. Thin documentation or purely family-driven admissions without clear risk factors are much harder to overturn.
Related terms
Benefits verification is the process of confirming a patient’s active coverage, financial responsibility, and authorization requirements with the payer before services are rendered. VOB can be manual (phone, fax, portal) or electronic (eVOB using 270/271 transactions or integrated portals).
Denial rate is the percentage of submitted claims that are denied by payers during a defined period. The metric can be calculated based on claim counts or dollar amounts and is usually reported at first submission or across the full claim lifecycle.
Remittance advice is the payer's official notice explaining how a claim was paid, adjusted, or denied, usually sent electronically in the HIPAA 835 format. An ERA lists allowed amounts, patient responsibility, payer write‑offs, and denial or adjustment codes for each claim and service line.
Explanation of Benefits (EOB) is the statement a health plan sends to a member that explains how a claim was processed, what the plan paid, and what the patient may owe. An EOB is not a bill, but it is the member-facing version of the claim outcome that providers see in a remittance advice.
Related denial codes
Not deemed a medical necessity
Precertification, authorization, or notification absent
Refer to plan benefit documents for coverage details
Claim contains incomplete or invalid information
Claim lacks information or has a submission error
