CMS-0062-P proposes to extend CMS interoperability and electronic prior authorization requirements to prescription drugs. This report explains how the proposed rule builds on CMS-0057-F, where FHIR prior authorization and NCPDP standards fit and what payers should assess now.
Foreword: Technology is just the precursor
The US healthcare system is approaching a consequential interoperability milestone. CMS-0057-F, the CMS Interoperability and Prior Authorization Final Rule, is already reshaping prior authorization for non-drug items and services. CMS-0062-P now proposes to extend comparable interoperability, transparency and electronic prior authorization requirements to prescription drugs. Together, the final and proposed rules give payers a clear view of the direction of travel while narrowing the window in which to prepare.
The processes may have become increasingly digital, but the standards which govern them haven't caught up. Digital systems need to communicate with each other and not just co-exist; that interoperability is the vital layer in any successful healthcare ecosystem.
When interoperability isn’t prioritized, it manifests as industry misalignment, amplifying missing information and delays and reducing the role of clinicians to facilitators of information exchange. When clinical decisions are treated as a sequence of check boxes rather than a matter of case-by-case evaluation, the likelihood of authorization requests being substituted or denied increases. Patients pay the price for a process failure, not a clinical one.
This report focuses on CMS-0062-P, the proposed CMS rule extending interoperability and prior authorization requirements to prescription drugs, and provides a practical snapshot of what impacted payers need to do now. Many organizations already have APIs, portals and electronic workflows, but readiness is uneven. The decisive work is not simply connecting systems. It is integrating clinical and administrative workflows, digitizing policy and routing requests through the right benefit pathway so that every decision can be explained at any given moment.
That matters because technology is only the precursor. Regulatory compliance can create the conditions for faster, more transparent care, but payers, pharmacy benefit managers (PBMs), providers and technology vendors must turn those conditions into an operating model. Organizations that treat the rules as a short-term IT project risk automating the weaknesses of the current process.
At Star, we see this as an opportunity to move from fragmented transactions to context-driven care so that patients receive the care they need when they need it. This is our philosophy, and our long-term plan for guiding health organizations toward true interoperability and a culture of continually evolving healthcare standards. This is just the beginning.
CMS-0057-F compliance and CMS-0062-P prior authorization interoperability challenge
Prior authorization (PA) is a defining feature of the fragmented, multi-payer US healthcare system. Insurers use it to manage coverage, utilization and cost, while providers use it to demonstrate why an item, service or drug is medically necessary. Too often, those activities take place across disconnected portals, faxes, calls and proprietary systems. Providers cannot see requirements early enough, payers receive incomplete information and patients experience the consequences as delayed or substituted treatment or, in some cases, abandonment of medical procedures. Electronic prior authorization can reduce that friction only when the systems around it are interoperable.
The policy backdrop is also shifting from fee-for-service toward value-based care, in which outcomes and coordination matter more than the volume of activity. Interoperability is essential to that shift. When coverage, cost, PA requirements and documentation are visibly closer to the point of care, decisions can be made with more clinical context and less avoidable rework.
Mandates explained
CMS-0057-F is the formal regulation code for the CMS Interoperability and Prior Authorization Final Rule. Published by the Centers for Medicare & Medicaid Services, it requires healthcare payers to support standardized HL7 FHIR APIs to improve patient access, provider access and prior authorization processes for non-drug items and services. Operational requirements (denial reasons, metrics) generally began in 2026, including specific denial reasons and shorter decision timeframes. API development and enhancement requirements generally apply from January 1, 2027, including Patient Access, Provider Access, Payer-to-Payer and Prior Authorization APIs.
CMS-0062-P is the 2026 proposed rule from the Centers for Medicare & Medicaid Services extending interoperability and electronic prior authorization mandates to cover prescription drugs. It requires impacted payers to support electronic PA, update health IT standards and introduce additional interoperability endpoint and API-usage reporting. For drugs covered under a medical benefit, it proposes FHIR-based PA requirements Da Vinci framework (Da Vinci DTR, Da Vinci CRD and Da Vinci PAS); for pharmacy-benefit drugs, it proposes specified NCPDP standards (NCPDP SCRIPT - ePA, Formulary & Benefit - F&B, and Real-Time Prescription Benefit - RTPB). Several provisions would begin October 1, 2027, if finalized.
The distinction between the two rulings matters. CMS-0057-F requires impacted payers to act, while CMS-0062-P provides a proposed drug-specific target against which to assess architecture, workflows and investment. Waiting for finalization may reduce regulatory uncertainty, but it also compresses the time available to digitize policy, test routing and change operating processes.
Since the run-up to the deadline is relatively short, organizations will have to put aside time and budget to make it happen. But those who saw friction with previous mandates, because they chose an unsuitable vendor or lacked adequate resources to manage the change in-house, could risk failing to realize this new layer of compliance.
Depending on where each organization is within their compliance journey, each roadmap will require different expertise and different initiatives. For many healthcare leaders, particularly those within smaller organizations, this will be where they stall.
This next phase will require payers, PBMs and healthcare providers to deliver final requirements and prepare for proposed drug provisions in different ways. Together, these changes represent something beyond a regulatory exercise. They demand coordinated operational and technological transformation to deliver faster and more transparent access to care that yields positive long-term results.

CMS-0062-P and the drug prior authorization black box
CMS-0057-F is already reshaping prior authorization for non-drug items and services, while CMS-0062-P proposes extending comparable CMS interoperability and electronic prior authorization requirements to prescription drugs. It is this second, drug-focused shift that payers now need to prepare for.
The path forward for healthcare organizations is complex. While these regulatory updates may well result in lowering the barrier to care, they also pose more challenges around processing diagnoses, comorbidities and medication requests, especially for pharma. Faster PA simultaneously means faster access and faster denial. This is where the need for transparency around authorization decisions becomes even stronger.
This is a real opportunity for payers to lead: being upfront about the reasoning behind approvals and denials, and surfacing supporting information early, is what builds trust with providers and patients. – Manuel Vera, Product Manager, Star
The current PA process can be viewed as a “black box” comprising coverage criteria, formularies and utilization policies that are often difficult for providers and patients to see until a request has already been submitted. The emerging regulatory model begins to open that box. For example, coverage, cost, PA requirements and documentation can become visible closer to the point of care, while denial reasons and performance metrics create greater accountability after a decision. It means that coverage terms and expected costs become visible to doctors and patients before or during the visit, not only after a request has already been submitted.
All stakeholders are accountable in their own way. For instance, as PBMs have negotiating power over which medications get approved, all access flows through them. This includes pharmacies like CVS and Optum, some of the largest PBMs in the US. They get to disseminate medication and costs, so they’ll have to understand how these new mandates affect their access to the market.
Payers also face operational and reputational risk. If they treat interoperability as a short-term compliance project rather than a core system change, they may over-deny, damaging trust and member retention, or over-approve, affecting the bottom line. Better transparency supports quicker decisions, but only when policy, clinical oversight and reporting are designed around the APIs.
Similarly, payers and physicians need to be aware of reasons for approvals and denials so that they can be more informed in the future, and requests can be authorized with more efficiency and accuracy. Traditionally, healthcare professionals would only get this opportunity through monthly sales meetings, but new legislation means this must change.

Industry learning must be constant and data-driven, meaning manual updates won’t work. And without it, prescriptions could be delayed or substituted. Quarterly formulary updates cannot keep pace with evolving reasons behind medical decisions; organizations must monitor for real-time policy changes, clinical evidence and utilization criteria, to breed a culture of constant innovation across all healthcare environments. These compliance updates ought to be treated as an opportune moment to improve the patient experience and to improve treatment outcomes, not simply as an incentive to avoid penalties.
For pharma, earlier visibility creates a different role. Rather than entering only after a denial, manufacturers gain the opportunity to support the process earlier, helping ensure the clinical picture is current and complete before a decision is made. The goal is not to influence the payer’s decision, but to reduce avoidable delay caused by missing or outdated information.
Proactive, real-time education on the costs and biologics of medications is going to be essential, and you can’t do that without electronic records or practice management vendors. Alternatively, you lose the prescription, or worse—end up prescribing something else. – Mahesh Naphade, Global Head of Healthcare and Life Sciences, Star
FHIR prior authorization and the move beyond manual workflows
Today, PA relies heavily on manual processes and back-and-forth communication between payers, providers and PBMs. Even though providers often have dedicated staff whose roles center around PA requests, the administrative burden is still felt by physicians who must spend a significant amount of time filling out paperwork instead of patient care.
The most crucial blocker is the siloed nature of how stakeholders work. Since payers, providers and PBMs all operate independently of each other, PA is effectively staggered across disparate workflows, so providers submit requests without visibility into requirements of the payer; payers make subsequent decisions behind closed systems; and patients rarely have clarity about why the decision was made.
Pharma companies are usually only involved now that a request is denied, rather than acting early to prevent delays to treatment. Until that moment, the decision-making process is opaque. This doesn’t just impact the prescribing process; it leaves patients with uncertainty about their treatment before they’ve even left the doctor’s office. Long term, this transpires into higher abandonment rates, where patients feel compelled to give up on the PA process before the request has even been approved or denied.
A culture built on reactivity does not lend itself to proactive patient care. Fast Healthcare Interoperability Resources (FHIR) provides a structured way to exchange health information and clinical context through API-based workflows. FHIR prior authorization can therefore make the information supporting a request more consistent and machine-readable. It can help payers receive the medication requested, allergies, current medications, comorbidities and supporting evidence in a more consistent form. But FHIR does not itself make the decision, guarantee correct routing or eliminate every request for additional information.
The HL7 Da Vinci project is a family of FHIR implementation guides for payer-provider workflows, including coverage requirements discovery, documentation templates, prior authorization, clinical data exchange and payer data exchange. Under CMS-0062-P, if finalized, FHIR and specified implementation guides would become core standards for relevant medical-benefit drug PA. More broadly, that also extends to payer-provider data exchange itself, not just the PA transaction.
PA is finally moving from a financial decision to a clinical decision that has financial impact. – Mahesh Naphade, Global Head of Healthcare and Life Sciences, Star
One of the most important things an API can support is speed. By reducing manual handoffs, organizations can make decisions with more of the patient’s clinical circumstances in view, not solely based on coverage or cost.
The API is purely a communication layer; it is policy, benefit determination, routing, workflow integration and clinical review which decide whether the faster exchange produces a useful result.
PA processes for medical-benefit and pharmacy-benefit drugs are distinct: medical-benefit drug PA follows the FHIR and Da Vinci pathway, while pharmacy-benefit drug PA adheres to NCPDP standards. The new payer ecosystem bridges the two protocols conveniently, for minimal clinician intervention.

Technical principles for CMS interoperability and prior authorization
Connectivity is very different to interoperability. Many healthcare organizations already operate digital systems, but they don’t communicate in the same language. This is an industry problem, not a technical one. Previous standards have enabled systems to represent the same information differently, which is what has allowed for processes to break down.
That is why the underlying API communication layer is so important, as it enables wider communication. However, it is just that: a layer. Being compliant does not inherently guarantee interoperability. The capabilities around the API must determine the benefit, route the request, apply policy, manage exceptions and return information that providers and patients can act on.
For example, the same drug can sit under the medical benefit for one payer and the pharmacy benefit for another. A provider who submits through the wrong pathway doesn’t just get a slower answer, they simply get an automatic rejection, and the request is returned to them to start over. Multiply that across a portfolio of drugs and payers, and it becomes clear why coverage rules, benefit determination, routing and workflow integration around the APIs (not the APIs themselves) are what decide whether interoperability happens—which is why FHIR and NCPDP have to work as one coordinated system and not two parallel ones.
Without one shared meaning of data between digital systems, organizations become misaligned and misunderstood although they’re working toward the same goals. To have a common understanding of industry terminology, we need to code the data it communicates. FHIR introduces that constraint, forcing all organizations to be consistent in the ways they interpret, process and exchange said data.
FHIR creates greater consistency and clarity around industry terms, reducing ambiguity in the information exchanged. Greater specificity can improve the care experience and reduce avoidable requests for clarification. It does not, however, guarantee that data is complete, routed correctly or sufficient for an immediate decision; those outcomes depend on the workflows and governance around the standard.
Interoperability is 80% politics and 20% technical work. Having two systems talk to each other is easy, but getting organizations to agree on what data is exchanged and how it is represented and governed over time, that’s hard. – Yanick Gaudet, Interoperability Solution Architect, Star
Through the convergence of clinical and financial workflows, clinical, reimbursement and authorization processes can become more closely connected. CMS-0057-F requires important parts of that foundation for non-drug items and services; CMS-0062-P proposes to extend and update it for drugs. But this does not simply mean adopting software. It must start with strategy.

Payers moving beyond manual PA processing must follow a strict routine. The starting point is policy digitalization, or translating narrative coverage and utilization policies into governed, machine-readable rules, templates and clinical criteria.
This is seen by the industry as the biggest hurdle for payers today. Once policy is machine-readable, workflow automation becomes possible, making the existing review sequence so straightforward cases progress automatically and complex cases reach the appropriate reviewer without manual triage.
None of this works, though, without benefit classification and protocol routing. This means identifying whether the medical or pharmacy benefit applies and moving dynamically between FHIR and NCPDP workflows rather than forcing every request down a single pathway. Payers also need integrated fallback systems, keeping portals, fax and other contingency routes connected to one authorization record so legacy and outage traffic doesn't become a separate silo outside the audit trail.
The last element is consent management—or the embedding of privacy, security and member choice into the workflow—which must include payer-to-payer consent processes. Under CMS-0062-P, the Payer-to-Payer API would be required to carry drug-specific prior authorization data (status, approval, end dates, and dosage) so that active medication authorizations move with the patient and treatment isn’t interrupted during a plan transition. In practice, that means capturing a patient's explicit opt-in for payer-to-payer data transfer automatically, for example, when they switch insurers, since consent that isn't captured now of the plan change is one of the biggest practical blockers payers report.
Under such a system PA requests will evolve into clinically rich exchanges that allow payers to make data-driven decisions in the best interest of the patient.
Interoperability readiness is less about technical capability, and more about understanding your current state and what you need to do next based on that. Where am I? Where do I want to go? – Yanick Gaudet, Interoperability Solution Architect, Star

From CMS compliance to context-driven care
While the healthcare industry is vast, the availability of healthcare-specific knowledge, particularly around compliance, isn’t so much. For smaller pharmacy systems which may have the budget but not the expertise, this leaves a significant gap in their compliance journey.
Those smaller firms will have to seek help with deploying new, compliant systems. But they’ll also have to learn how to use them. They’ll need to understand how it’s going to impact their workflow and how to adapt as a vendor when there are further CMS or FHIR updates.
The challenge then stops being technical implementation and becomes organizational change management, with humans at the forefront. This is how impacted organizations can assess their position against the new CMS mandates and the direction they need to take.
Effective interoperability means that policies, workflows, routing, documentation, consent, reporting and user interfaces work together. The practical question is not simply whether an API exists, but whether a complete request can move through the correct pathway and return a timely, explainable response.
Getting there starts with an honest assessment of where you stand:
- Understand the new mandates and identify impacted areas: Determine which CMS requirements apply to your organization, which systems and stakeholders will be affected, and how the new mandates build on any previous interoperability regulations.
- Review previous interoperability investments: Assess existing FHIR implementations, API capabilities and prior CMS compliance efforts to identify what can be leveraged, where gaps remain and whether legacy systems are still fit for purpose.
- Identify specific workflow gaps: Evaluate where clinical, reimbursement, PA and reporting workflows remain disconnected, and how manual processes or organizational silos might hinder compliance.
- Evaluate internal capability: Assess whether your organization has the human strategy, governance, technical expertise and change management needed to deliver and scale interoperability and whether engaging a specialist partner could accelerate implementation.
How Star can help
This is exactly the work we do alongside payers, PBMs and providers. We run the CMS-0062-P readiness assessment, discover what's already compliant, what needs upgrading, what still must be built and what gets to be delegated.
Once this assessment has been carried out, we can implement FHIR and Da Vinci build-out for medical-benefit drug PA, the orchestration layer that classifies each request, routes it through the correct pathway, and reroutes automatically between FHIR and NCDPD when it doesn’t, and policy digitization and workflow automation so the straightforward cases clear themselves. It's the same approach behind every Star engagement: deep healthcare expertise paired with the technical capability to design, build and scale what's needed.
The goal is connected care: the clinician understands what is required at the point of care, the request is submitted correctly, the payer returns a timely and transparent decision, and the patient can access treatment, an alternative or support more quickly.










