CMS-0057-F set the current obligations. A follow-on proposed rule, CMS-0062-P, would change three things that materially affect how payers should plan the next two years — and one of them turns a recommendation into a requirement.
An important qualifier up front, because it governs how you should act on this: CMS-0062-P is a proposed rule. It was published in April 2026, its comment period closed in June 2026, and as of this writing it has not been finalised. What follows describes the proposal as drafted. A final rule can differ, and dates in particular can move.
What it proposes
1. The Da Vinci Implementation Guides become mandatory
Under CMS-0057-F, the guides — CRD, DTR, PAS, PDex, Plan-Net and CARIN Blue Button — are strongly encouraged. The proposal would require conformance to them from 1 October 2027.
For payers already building to the guides, this changes little beyond removing ambiguity. For any payer who read "strongly encouraged" as licence to implement their own interpretation of a FHIR prior-authorization API, it converts that work into rework with a date attached.
2. Electronic prior authorization extends to drugs
CMS-0057-F excluded drugs from the prior authorization API. The proposal would bring them in — which matters disproportionately, because pharmacy is where prior authorization volume concentrates and where the data most often sits with a pharmacy benefit manager rather than the payer. If your delegated-entity work treated pharmacy as out of scope, this is the item to revisit.
3. FHIR-based transactions as adopted HIPAA standards
The proposal would adopt FHIR-based prior authorization and clinical data exchange as HIPAA standards. This is the most consequential item structurally and the least discussed, because it changes the relationship between the FHIR pathway and the long-standing X12 278 transaction — moving FHIR from an accepted alternative toward a named standard in its own right.
The timeline, and how firm each date is
Two of these are settled and two are not:
- January 2026 — in force. Decision timelines and specific denial reasons, with reporting following.
- January 2027 — final. The four FHIR APIs. This is a firm obligation under CMS-0057-F.
- October 2027 — proposed. Mandatory conformance to the Da Vinci guides, if finalised as drafted.
- Drugs and the HIPAA standards change — proposed, with sequencing dependent on the final rule.
How to plan against a proposal
The temptation is to wait for a final rule. That is reasonable for scope decisions and unreasonable for architectural ones, because the two carry different costs if you guess wrong.
Act now on anything that is cheap if the proposal changes and expensive if it does not. Building to the Da Vinci guides is exactly that: if the mandate is finalised you are ready; if it is softened or delayed you have still built to what your trading partners use. There is no scenario where conforming to the guides was the wrong call.
Plan but do not build for pharmacy. Reopen the conversation with your pharmacy benefit manager now, because contractual lead times are long and that is the part you cannot compress later. Hold the engineering until scope is settled.
Watch the HIPAA standards item if you run X12 278 alongside a FHIR pathway. It affects which rail is authoritative and, in time, your operations and vendor relationships more than your API surface.
What this means for a roadmap
Practically, it argues for treating CMS-0057 as the first phase of a multi-year programme rather than a project that ends in January 2027. Teams that build a conformant, tested implementation and keep the testing and evidence habit running will absorb the October 2027 date as a checkpoint. Teams that build something bespoke against the letter of the current rule will meet it as a second project.
The direction of travel is not ambiguous, even where the dates are: toward named implementation guides, wider scope, and FHIR as a standard rather than an option. Planning against that direction is sound regardless of what the final rule says.
Nirmitee builds and tests FHIR APIs for payers and health-tech platforms. Our healthcare interoperability team runs readiness assessments, Implementation Guide builds and conformance-testing engagements; for the platform side see our healthcare software product engineering practice. Talk to our team.



