Top

Prior Authorization

Prior authorization is a payer requirement to obtain approval before delivering specific services, confirming that planned care is medically necessary and covered under the member's benefit. Prior authorization is typically required for higher-cost, high-utilization, or ongoing treatment and is a common denial trigger when missing or expired.

Kathryn Thompson
Reviewed by Kathryn Thompson · Updated September 2026

What it means

What prior authorization is

Prior authorization is a pre-service review by a health plan or behavioral-health carve-out vendor. The payer reviews clinical information before care starts, or before additional units or days are added, and decides whether the planned service meets its medical-necessity and benefit criteria.

In practice, prior authorization usually means your team submits demographics, diagnosis, planned CPT/HCPCS codes, ASAM or LOCUS level, and clinical notes to the payer. The payer issues an approval (auth) with a specific range: dates of service, allowed units, place of service, and sometimes named rendering providers.

Prior authorization is not the same as eligibility. A member can be active and covered, and you can still be denied payment because services were not authorized in advance or because you exceeded the authorized units.

Why prior authorization matters operationally

From an RCM lens, prior authorization is a high-impact choke point. Missing or invalid auth leads straight to CO-197 denials (precert/authorization/notification absent), N130 or MA130 remark codes, and often zero payment for otherwise clean claims. For per-diem programs, one missed concurrent review can mean tens of days fully denied.

Prior authorization also drives delays. If clinical teams do not complete the paperwork on time, patients wait, beds sit empty, or services are delivered at financial risk. If your authorization tracking is weak, you end up in a constant loop of retro-auth requests, appeal packets, and avoidable write-offs.

Operationally, you want to control three things:

  • Whether a service needs prior auth at all (plan, product, payer policy)
  • Whether the auth you have matches what you are billing (codes, units, dates, provider, location)
  • Whether your team is hitting payer timelines for initial and concurrent reviews

Every miss on those levers shows up in days in A/R, staff time on appeals, and write-offs that leadership will eventually notice.

How prior authorization is requested and used

The prior authorization process typically follows this pattern:

  • Front-end check: Verify benefits and confirm if the specific service, level of care, and provider type require auth.
  • Submission: Send the request through the payer portal, fax, or phone, with clinical documentation and planned codes.
  • Determination: Receive an approval, partial approval, denial, or request for more information within the payer's stated timeframe.
  • Tracking: Enter auth numbers, units, and date ranges into the practice management or EHR system, tied to the patient and episode of care.
  • Ongoing management: For long or intensive courses of care, submit concurrent reviews to extend days or units before the current auth expires.

In billing, a clean claim reflects the approved authorization: the billed dates fall within the auth window, the units stay at or below the authorized amount, and the codes and place of service line up with what the payer approved. When there is any mismatch, the payer often pays only up to the auth limit and denies the rest under CO-197, CO-50, or CO-97 with N130 or MA130 remarks.

For audits and appeal risk, accurate documentation is key. You want to be able to produce the original auth approval, clinical notes submitted, and any payer communications. Poor documentation converts what could have been a simple reopened claim into a full medical-necessity appeal or a permanent write-off.

Common mistakes

  • Assuming eligibility means no prior authorization is needed: The front desk sees "active coverage" on a commercial plan and schedules residential SUD at ASAM 3.5 without checking the plan's prior auth rules, leading to a CO-197 denial for the entire admission.
  • Not matching codes and levels of care to the authorization: The team obtains auth for IOP with specific CPT/HCPCS codes but billing submits PHP or a different group-code set, so the payer pays nothing or only partial units with CO-50 and N130 on the remittance.
  • Letting concurrent review dates slip: A 28-day residential stay is approved in two 14-day chunks, but no one requests extension before day 15, so days 15 through 28 deny under CO-197 and MA130 and are very hard to recover even with appeals.
  • Storing auth info outside the system of record: Auth numbers and limits live in spreadsheets or staff notebooks instead of the PM/EHR, so when billers code claims they unknowingly exceed unit caps and generate repeat CO-197 and CO-97 denials.
  • Treating prior auth as a guarantee of payment: Staff relax once they have an auth number and ignore documentation quality or coverage limits, then get hit with CO-50 denials when medical-necessity criteria are re-reviewed on the back end.

Why it matters in behavioral health

Behavioral health sits at the strict end of prior authorization. Residential treatment, PHP, IOP, TMS, intensive community services, and many SUD levels of care are almost always flagged for pre-service review. Even routine outpatient therapy can require auth after a certain visit count. If you do not treat prior auth as first-class work, you end up delivering weeks of care at full financial risk.

Carve-out vendors add another layer. Many large employers and Medicaid plans carve out behavioral health to a separate payer such as a managed behavioral health organization. Front-end teams may verify benefits with the medical plan only and miss that the BH carve-out has its own prior auth rules, its own portals, and its own timeframes. Claims then deny for missing auth even though the practice "confirmed benefits" with the wrong entity.

Concurrent authorization is critical for long per-diem programs. Residential and PHP stays are often approved for short windows and require new clinical reviews every few days. If the UR team does not align concurrent reviews to payer deadlines and length-of-stay rules, you see a strong pattern: the first few days pay, then the rest of the stay denies. With Medicaid managed care, those concurrent reviews can be tightly linked to state medical-necessity criteria and level-of-care tools such as ASAM, so even small documentation gaps can cause partial denials.

State Medicaid and MCOs often have very specific prior auth rules for SUD, MAT, and children's behavioral programs. Some require prior auth for telehealth BH, some do not. Some require different auths for the same level of care under different benefit programs. If you run multi-state programs, inconsistent handling of those rules translates into measurable revenue leakage, appeal burden, and potential compliance risk if services are delivered out of policy.

How AI can help with Prior Authorization

AI agents can take on the high-volume, rules-heavy parts of prior authorization. An agent can read benefits data, payer PDFs, and policy bulletins, then flag when a planned service, level of care, or place of service requires auth. It can pre-fill payer-specific auth forms, summarize clinical notes into the key criteria payers look for, and track upcoming concurrent review deadlines so your UR team spends more time on clinical nuance and less on paperwork.

Supabill's benefits-verification and claims-scrubbing agents can hold payer- and plan-specific auth rules in memory and compare each scheduled service and claim against those rules. A denials agent can read every 835, spot CO-197 and related N130 or MA130 remarks, and classify which denials reflect missing or mismatched auth so you can fix workflows upstream. The limit is judgment: humans still have to handle gray-zone medical-necessity discussions, pick the best appeal angle, negotiate with payer medical directors, and decide when to write off versus keep fighting.

FAQ

Is prior authorization a guarantee that a behavioral-health claim will be paid?

No. Prior authorization only confirms that, based on the information submitted, the planned service appears medically necessary and covered. Payment can still be denied later for reasons such as member ineligibility on the date of service, coding that does not match the authorized service, missing documentation, or claim submission outside timely filing limits. Behavioral-health claims are especially vulnerable to CO-50 medical-necessity denials when payers re-review clinical notes on the back end, even if an auth number was issued up front. Healthcare.gov explicitly cautions that prior authorization is not a payment guarantee. Source

What is the difference between a prior authorization and a referral?

A prior authorization is payer approval for a specific service or level of care, often based on clinical criteria and utilization rules. A referral is a direction from a primary care provider to see a specialist or program, usually required in HMO-style plans. In behavioral health you might have a PCP referral to a psychiatrist, plus a separate prior auth from the payer or BH carve-out for intensive services like PHP or residential. Both can be required, and missing either one can cause denials. See the referral and authorization descriptions on Healthcare.gov. Source

When should behavioral-health providers request prior authorization for higher levels of care?

Request prior authorization as early as possible, ideally before admission or service initiation. For urgent or emergent psychiatric admissions, many payers allow notification shortly after admission, but still require concurrent reviews within tight time windows. For planned services such as PHP, IOP, TMS, psychological testing, and long residential SUD stays, most payers expect auth requests before the start date and additional concurrent reviews before the current auth expires. State Medicaid programs may define specific timelines for requests and reviews, which are described in their provider manuals on Medicaid.gov. Source

How should prior authorization information be documented so it supports clean behavioral-health claims?

Document auth numbers, approval dates, authorized units or days, associated CPT/HCPCS codes, and the approved level of care in your EHR or practice-management system, not in personal notes or spreadsheets. Link the auth to the specific episode of care and update it when concurrent reviews change the limits. For per-diem residential and PHP/IOP, track which dates are covered under which auth range so billers do not cross date ranges or exceed units. Keeping this structured data in the system makes it easier to validate claims before submission and to respond quickly to payer audits and appeals. Source

Can behavioral-health services ever be authorized retroactively if prior authorization was missed?

Sometimes. Certain payers and Medicaid managed care plans may allow retro-authorization when there is a documented emergency, member eligibility confusion, or internal payer error. However, retro-auth is not guaranteed, often applies only to part of the stay, and usually involves extra administrative burden and appeal risk. For planned BH services, payers typically expect prior auth before treatment begins, and missing it can result in permanent CO-197 denials. Provider manuals from payers and state Medicaid agencies on Medicaid.gov outline any allowed retro-authorization policies. Source

Sources

AI agents that run your billing.

The first agentic RCM that actually works.

Book a live demo