Which Health Plans Publish Their Prior Authorization Criteria, and Which Only Name a Vendor
Nirmitee.io Engineering
Author

Ask a health plan why a request was denied and you will usually get a policy number. Ask to see the rule behind it and the answer splits three ways. Of the 254 payers we assessed in September 2026, 62 publish the full medical criteria they decide on, 112 publish part of it, and 73 publish a code list and the name of a vendor. That last group is roughly one payer in four, and no software on the market can pre-check a request against them, because the rule is not public to check against.
What we did
In September 2026 we collected the public policy documents of 278 US health plans: medical policies, clinical guidelines, drug policies, payment policies and prior authorization code lists, 65,851 documents in total. We read them, and for the 254 plans with enough material to assess, we recorded whether the document set is enough to decide a request without calling the plan. Everything below is a 15 September 2026 snapshot of what those payers published on their own websites.
The three tiers, and what each one costs a provider
The dividing line is not whether a payer has a policy library. Almost all of them do. The line is whether the medical necessity decision itself is written down in public, or whether the document stops at "reviewed against nationally recognised criteria" and names a licensed product.
| Tier | Payers | What the payer publishes | What a provider can do with it |
|---|---|---|---|
| Full criteria | 62 | Policy text with explicit numeric thresholds, ALL-of and ANY-of criteria trees, documentation lists and CPT, HCPCS and ICD-10 code tables | Check the chart against the rule before submitting, and know the answer |
| Partial | 112 | Policy text is public, but medical necessity for some services points to InterQual, MCG or a delegated vendor | Some service lines are checkable, others are not, and the split is rarely stated up front |
| Proprietary | 73 | A prior authorization code list, sometimes a criteria hierarchy statement, and a vendor name | Confirm that authorization is required, then submit blind |
The open end: payers you can actually build a check against
The 62 payers at the open end are not a fringe group. They include some of the largest policy libraries in the country.
- Aetna publishes its Clinical Policy Bulletins in full. We collected 1,268 documents, of which 938 are bulletin pages. The obesity surgery bulletin states BMI cut-offs, including separate thresholds for patients of Asian ancestry and a separate adolescent pathway. The spinal fusion bulletin requires a documented failure of at least six weeks of conservative therapy and lists the imaging findings that must be present. Both carry their own code tables.
- Cigna writes its own coverage policies with explicit ANY-of and ALL-of trees, numeric thresholds, quantity limits and covered or not-covered code tables, across the 878 documents we collected.
- Blue Cross and Blue Shield of Alabama goes further than prose. Its 2,101 documents include the criteria as HTML and as a structured criteria tree, with the code list attached per line of business. That is a policy library already shaped like software.
- AmeriHealth Caritas is the largest set we collected, 4,308 documents across its Medicaid, D-SNP and Marketplace plans. Each clinical policy carries a description, clinical findings, criteria, limitations, codes and references, and its prior authorization pages name neither InterQual nor MCG.
- Humana Medicare Advantage takes a different route to the same place. Each coverage policy lists the applicable national and local Medicare determinations by contractor jurisdiction, then gives Humana's own criteria for the jurisdictions or services where Medicare has no local rule, with duration thresholds such as "despite four weeks of conservative care".
- Blue Cross and Blue Shield of Rhode Island is the cleanest example of all. It publishes every prior authorization policy as a PDF, plus machine-readable spreadsheets that map each CPT or HCPCS code to its authorization requirement and to the criteria source, for each line of business. Almost nobody else publishes the source of the criteria alongside the code.
- Florida Blue writes its own Medical Coverage Guidelines, 835 documents, and names no licensed criteria library for them.
Two caveats matter even here. First, openness is often line-of-business specific: Aetna's commercial bulletins are fully public while its Medicare Advantage line leans on Medicare determinations plus MCG as supplemental criteria. Second, an open payer can still delegate whole service lines. Cigna's own policies are explicit, but radiology, cardiology, musculoskeletal, sleep, gastroenterology and oncology programs run through eviCore, and behavioral health runs on MCG behavioral guidelines that are not published.
The middle: the policy is public, the decision is not
The 112 payers in the middle are the ones most likely to be misread. Their libraries look complete. The gap only shows up when you read the section of each policy that decides the case.
UnitedHealthcare is the clearest worked example, because the boilerplate overstates the problem and the detail corrects it. A sentence naming InterQual as proprietary and unpublished appears in roughly 73% of its policy PDFs, so counting mentions is useless. We read the coverage rationale section of all 1,834 medical policies instead. On that measure, 21% point only to InterQual, 15% mix InterQual with their own criteria, 28% carry their own criteria trees and 26% are proven or unproven indication lists. So about 36% of the library depends on InterQual for at least part of the decision, and about 64% is decidable from the public text. Usefully, 57% of the policies also include a section listing the medical records the reviewer will look for.
Elevance publishes its medical policies and clinical UM guidelines in full, with position statements and coding tables, and separately licenses MCG for inpatient, level-of-care and precertification review. Its specialty programs run through Carelon, whose guidelines are public. So one payer is open, partial and closed depending on which door the request comes through.
Blue Cross and Blue Shield of Alabama sits in both tiers for the same reason: its own policies are fully public, and inpatient and post-acute medical necessity falls to InterQual. It does at least publish which InterQual subsets it uses, which is more than most.
The closed end: a code list and a vendor name
At the other end, the document sets are very small, and they are small because there is nothing to publish.
- Alignment Health publishes no plan-owned medical policies. Medical necessity runs on MCG, offered through a view-only tool with no print or download. We collected four documents in total.
- Gold Kidney Health Plan publishes its decision hierarchy honestly: Medicare rules first, then internal coverage criteria approved through its own UM governance, then a recognised guideline library such as MCG or InterQual. None of the internal criteria are posted. Four documents.
- Leon Health posts no prior authorization list, no medical policy and no criteria statement. Authorizations go through the provider portal. Three documents, one of which is a covered DME list.
- Healthfirst shows that closed is not the same as lazy. It publishes 163 detailed reimbursement policies. The coverage criteria sit in medical policies that are cited by number and never published, alongside MCG guideline IDs.
- Martin's Point publishes its medical-benefit drug criteria in full, and six plan-owned service policies. Everything else defers to Medicare rules, then MCG.
The volume gap is stark. The 73 payers in the proprietary tier publish 1,351 documents between them, a median of six each. The payers publishing full criteria run to a median of about 414 documents each. Those figures are our own count across the corpus index, and they are the most direct measure of the asymmetry: one group has written the rules down, the other has licensed them.
Who is actually behind the decision
Naming a criteria library is now close to universal. Of the 254 payers, 212 name InterQual or MCG somewhere in their public material: InterQual at 138 payers, MCG at 124, with many naming both for different service lines. Specialty review vendors are layered on top of that.
eviCore is named by 70 payers, Carelon by 51, Evolent by 32, Optum by 28, Prime Therapeutics by 27 and Magellan by 20. For a provider this matters more than the payer's own tier. A request for advanced imaging at a payer that publishes excellent surgical policies may still be decided by a vendor with its own guideline set and its own portal. Some of those vendors publish their criteria, which is why a delegated program is not automatically a dead end, and why the first question about any denial should be who reviewed it, not which plan issued the card.
The format problem underneath the transparency problem
Even the public material is mostly built for human eyes. Across all the prior authorization lists we collected, 2,359 are PDFs and 418 are web pages, against 317 spreadsheets, 22 JSON files and 7 CSVs. Only 48 of the 254 payers publish a prior authorization list in any machine-readable format at all.
Where they do, the scale is real: San Francisco Health Plan publishes about 83,500 rows, Meridian Illinois about 59,000, Ambetter Arkansas 18,111. Those are usable inputs for a revenue cycle team the day they are downloaded.
Change tracking is the weaker half. About 52% of the documents carry an effective date and 40% carry a revision history, but only 2% of prior authorization lists publish a change history. A list without a change log means every refresh is a full re-read, because nothing tells you which of 18,000 rows moved.
What this means for you
If you run a health plan
From 1 January 2027, the CMS Interoperability and Prior Authorization rule requires impacted payers' prior authorization APIs to be populated with the list of items and services that need authorization, to identify all documentation required for approval, and to return an approval, a denial with a specific reason, or a request for more information. The regulation text is explicit about the documentation requirement, and that is the part closed criteria make hard. If the rule that decides the case lives in a licensed product your members and providers cannot read, you still have to express its documentation requirements through an API. Payers in the open tier are mostly compiling something they already wrote. Payers in the closed tier have to write it first, or negotiate what they can expose from a vendor contract. That is a longer piece of work than an API build, and the clock on it is the same.
If you are a provider or an RCM team
Split your payer mix by tier before you buy anything. For the open tier, the criteria are specific enough to check against the chart, so denials there are largely a documentation discipline problem you can fix. For the closed tier, effort is better spent on clean submission, fast response to information requests and a tight appeals path, because there is no rule to pre-check. Ask each vendor you evaluate which of your top payers they hold real criteria for, by name.
If you are building tools
You can build genuine pre-submission checks against 62 payers today, and partial checks across a good share of the 112. For the remaining 73, the honest output is "this needs review", and a product that says anything more confident is guessing. Being explicit about that boundary is a feature. Providers can plan around a system that tells them where it is certain, and they cannot plan around one that is uniformly confident and occasionally wrong.
How to check your own position this week
- Take your top 20 payers by authorization volume and open each one's provider policy page. Look for a policy library, not a prior authorization list. The presence of one and the absence of the other is the whole test.
- For each payer with a library, open two policies in service lines you submit often and read the medical necessity section. If it states thresholds, you are in the open tier for that service. If it says "refer to InterQual" or "reviewed against MCG", you are not.
- Note the delegated vendor per service line. Imaging, cardiology, oncology, musculoskeletal, sleep and genetic testing are the ones most often carved out, and the vendor decides, not the plan.
- Check whether the prior authorization list is a spreadsheet or a PDF, and whether it has a change history. That single fact decides whether keeping current is a download or a quarterly re-read.
- Map your denial volume against the tiers. Denials at open-tier payers are usually fixable with better documentation. Denials at closed-tier payers need a different play.
Limitations
This is a snapshot taken on 15 September 2026, and payer websites change. We assessed only what each payer publishes publicly, so material behind a provider portal login is not represented, and a payer that shares criteria with contracted providers privately will look more closed here than it is in practice. The counts are of documents and payers, not of members or of authorization volume, so a tier with fewer payers may still cover more lives. Tier assignments are ours, made by reading the decision sections of each payer's own documents, and several payers genuinely sit across two tiers depending on the line of business. The per-tier document counts in this post are our own calculation from the corpus index.
If you are working through this in earnest, our interoperability team builds the payer-facing side of this problem, from policy digitisation to the FHIR APIs the 2027 deadline calls for, and our healthcare AI agents practice builds the provider-side checks that use them. Talk to our team if you want your own payer mix scored against these tiers.
Further reading: CMS-0057-F explained for the rule and its deadlines, the true cost of prior authorization for what the current process spends, and the prior authorization software buyer's guide for what to ask vendors.
Ready to scale?
Talk to our healthcare engineering team about building, integrating, and shipping faster.
Frequently Asked Questions
Does my insurer publish the prior authorization criteria it decides on?
What is the difference between a prior authorization list and a medical policy?
What does it mean when a policy says criteria are InterQual or MCG?
Which payers are the best examples of published criteria?
Does CMS-0057-F force payers to publish their criteria?


