Top

Retroactive Authorization

Retroactive authorization is a payer approval for services that were already provided without required prior authorization or notification. It is usually granted as a one-time exception so the claim can be paid instead of denied for missing auth.

Kathryn Thompson
Reviewed by Kathryn Thompson · Updated September 2026

What it means

What retroactive authorization is

Retroactive authorization is payer approval that is requested and granted after services have already been rendered, when prior authorization or notification was required but not obtained on time. It is the payer saying, usually as an exception, that the services meet their criteria and can be treated as authorized for payment purposes.

You usually pursue retro auth when you face or expect denial codes that point to missing precert, prior authorization, or notification, and the services were otherwise covered and medically necessary. Each payer and plan sets strict rules on when retro auth is even allowed, what documentation is needed, and how far back they will go.

In behavioral health, retro auth is common around urgent admits, weekend or after-hours placements, and messy handoffs between utilization review and front office staff. Getting or missing retro auth directly swings whether a $15,000 residential episode or a $4,000 PHP run gets paid or written off.

Why retroactive authorization matters operationally

Retro auth is a pure damage-control play. It is more work, slower, and less predictable than getting prior auth, but it is often the only way to rescue high-dollar claims from hard denial. If you do not track and chase retro auth, the same services will cycle as CO-197 (no precert or authorization) and then age out of appeal or timely filing windows.

Operationally, retro auth touches several points:

  • Intake and benefits-verification teams flag missing or uncertain auth requirements.
  • Utilization review staff pull clinicals and submit the retro auth request.
  • Billing and follow-up teams track pending retro auths and time refiling before appeals and timely filing limits expire.

Every missed or late retro auth can:

  • Turn into a permanent denial, which cuts revenue and inflates denial rate.
  • Delay payment by 30 to 90 days while the payer reviews clinicals.
  • Invite more intense medical-necessity scrutiny, which can trigger chart requests or audits.

Getting clear on your retro auth workflow can mean the difference between saving 80 percent of fixable no-auth denials and writing them off as avoidable bad debt.

How retroactive authorization is used and read in the workflow

Practically, you use retro auth in three main situations:

  • The claim is already denied for no auth, and you are told by the payer that a retro auth request is allowed within a certain window.
  • The service just occurred, you realize prior auth was missed, and you submit retro auth before the first claim to avoid an avoidable denial.
  • Coverage or plan information changed late, for example an MCO switch, and you now must meet a different prior auth rule after the fact.

When a retro auth is granted, the payer issues an authorization number, service dates, and allowed units or days. Your team must:

  • Confirm the authorized dates match the episode or stay, and note any partial coverage.
  • Link the auth number to the correct claims and line items in your billing system.
  • Rebill denied claims promptly, or submit the initial claim with the retro auth reference where allowed.

You should also watch for subtle issues like:

  • Retro auth only covering part of the stay, so early days remain denied.
  • Payer approving clinically but still cutting payment with CO-45 (contractual) if the wrong level of care or place of service was billed.
  • Retro auth being granted, but claims staff not rebilling before timely filing expires.

Documenting every retro auth event, including who caused the miss and what fix was needed, is key if you want to drive down preventable no-auth denials over time.

Common mistakes

  • Assuming all payers allow retro auth and wasting weeks gathering clinicals, only to learn that a commercial PPO flatly refuses retro authorization for non-emergent residential admissions, so the entire stay becomes a write-off.
  • Getting a retro auth number for a 30-day residential episode but not noticing the payer only authorized days 5 through 30, then rebilling the full stay and being confused when days 1 to 4 keep denying as CO-197.
  • Winning retro auth on a Medicaid-managed-care PHP episode but failing to rebill before the plan's 120-day timely filing limit, so the claim returns as CO-29 instead of paying.
  • Only updating the retro auth number on the header of a UB-04 IOP claim and forgetting to attach or reference it on related CMS-1500 professional claims, which then deny separately for no authorization.
  • Treating retro auth approval as a guarantee of payment and ignoring medical-necessity flags, then being blindsided when the payer pays a few days and denies the rest as CO-50 after a deeper utilization review.

Why it matters in behavioral health

Behavioral health providers rely on retro authorization more than most, because admissions often happen in crisis and outside business hours. A patient may be admitted to residential treatment or withdrawal management late Friday night, with clinical staff focused on safety, not payer rules. By Monday, the window for "timely notification" may already be tight, and the only viable path is a retro auth request with strong clinical documentation.

Carve-outs make this worse. A patient might show a medical plan card at intake, but the behavioral health benefit is administered by a separate vendor that has entirely different prior auth rules. Your team might verify benefits with the medical carrier, admit to ASAM 3.5 residential, and learn a week later that the BH carve-out vendor needed pre-cert on day 1. At that point you are forced into retro auth with the vendor, often with stricter review and a risk that only a portion of the stay will be approved.

For long per-diem episodes like residential, PHP, and IOP, retro auth often intersects with concurrent review. A payer might agree retroactively that admission was appropriate, but only approve a limited block of days or sessions, then require ongoing concurrent review. If UR does not keep up with these check-ins, days past the last approved date can still deny, even though you won the initial retro auth.

State Medicaid and Medicaid-managed-care plans can be especially rigid. Some allow retro auth only for documented emergencies or coverage discovery, for example when eligibility is found after service. Others impose short filing windows or restrict retro auth to specific levels of care. In many markets, missing prior auth on a Medicaid residential admit means your only realistic options are partial retro approval, single-case agreement negotiation, or accepting a deep write-off.

How AI can help with Retroactive Authorization

AI can help with retroactive authorization by catching the problem earlier and organizing the messy admin work. An agent can read eligibility responses, plan documents, and prior-auth grids, then flag services that occurred without required auth, including carve-out mental health plans. It can draft retro auth request packets from existing clinical notes, attach the right codes and dates, and track payer-specific windows so your team knows which episodes are still salvageable.

Supabill's benefits-verification agent can identify when behavioral health benefits sit with a different vendor and highlight prior-auth requirements before or shortly after admission. Its claims-scrubbing agent can hold payer rules and flag likely CO-197 denials before you submit. A denials agent can read every 835, classify CARC and RARC patterns, and surface no-auth denials that are still within a retro auth or appeal window. The limit is clinical judgment and payer negotiation: humans still need to shape the medical-necessity story, handle peer-to-peer reviews, and decide when the dollars justify a retro auth push or a single-case agreement negotiation.

FAQ

Is a payer required to grant retroactive authorization if services were clearly medically necessary?

No. Retroactive authorization is almost always discretionary. Even if services were clearly medically necessary, payers set their own rules on whether they accept retro auth requests, what timeframes apply, and for which service types. Many commercial and Medicaid-managed-care plans refuse retro auth except for emergent admissions or coverage discovery situations. You can use medical necessity and parity arguments to advocate for payment, but there is no general legal right to retro auth.

How is retroactive authorization different from an appeal of a CO-197 denial?

Retro auth is a request for the payer to issue an authorization after the fact, usually routed through utilization review, while an appeal is a formal challenge to a denial that has already been adjudicated. Some payers tell you to first obtain retro auth, then resubmit the claim, and only appeal if that resubmission still denies. Others treat the retro auth request itself as the first level of appeal for a CO-197 denial. Your workflows should capture both paths and the related timelines so you do not lose appeal rights while waiting on a retro auth review.

Can Medicaid or Medicaid-managed-care plans approve retro authorization for behavioral health residential treatment?

Yes, but policies vary widely by state and plan. Some Medicaid programs allow retro auth for behavioral health residential stays only when the admission was emergent or when eligibility was confirmed late. Others prohibit retro auth for certain levels of care or require that the request be submitted within very short windows, for example a set number of days from admission or discharge. Always check the specific MCO or state Medicaid manual before investing time in a residential retro auth push. Source

If retro auth is granted, will all days or sessions in the episode be paid?

Not necessarily. Many payers issue partial retro approval, for example approving the admission and a limited number of days, then requiring ongoing concurrent review for the rest. They may also deny or downcode days that do not meet continued-stay criteria. In behavioral health, this can mean the first few residential days, which were focused on stabilization, are approved, while later weeks are reduced or denied unless clinical notes clearly document continued ASAM-level criteria.

What documentation should a behavioral health provider include in a retro auth request?

For behavioral health, strong retro auth packets usually include the admission assessment, risk and safety documentation, ASAM-level criteria mapping where applicable, treatment plan, daily or session notes for the requested period, and any collateral information that shows functional impairment or risk. You should also include insurance verification notes that explain any coverage confusion, especially when there was a behavioral health carve-out or plan change, because some payers are more flexible when the prior auth miss was tied to a documented plan-information issue. Source

Sources

AI agents that run your billing.

The first agentic RCM that actually works.

Book a live demo