Electronic prior authorization (ePA) is submitting and deciding authorization requests machine-to-machine instead of by fax, phone, or portal. Two rails carry it: the legacy HIPAA X12 278 transaction, and the new FHIR APIs (HL7 Da Vinci CRD, DTR, and PAS) that CMS-0057 requires government-program payers to expose by January 1, 2027. Despite decades of the 278 existing, only about a third of prior authorizations are fully electronic — this guide explains both rails, why adoption stalled, and what the mandate changes.
Why the Fax Survived: The 278 Problem
The X12 278 has been the HIPAA-mandated PA transaction since the 2000s — and manual PA still costs $12.88 vs $0.05 electronic (CAQH). The 278 stalled for a structural reason: it can carry the request, but not the clinical documentation payers actually decide on. So the “electronic” request arrived, and the medical records followed by fax anyway. Automating the envelope without the evidence automated nothing.
The FHIR Rail: CRD, DTR, PAS
The Da Vinci guides fix exactly that gap, as three cooperating steps:
- CRD (Coverage Requirements Discovery) — at order entry, the EHR asks the payer: does this need auth, and what documentation do you require?
- DTR (Documentation Templates and Rules) — the payer's requirements arrive as executable questionnaires that pre-fill from the EHR's own FHIR data — the evidence problem, solved structurally.
- PAS (Prior Authorization Support) — the request, documentation attached, goes to the payer and the decision comes back — increasingly in seconds for rules-satisfied cases.
For implementers: our Da Vinci PAS implementation guide covers the build details, and the broader prior authorization automation guide places ePA in the full workflow.
What CMS-0057 Actually Requires (and When)
- Since January 1, 2026: decisions in 72 hours (expedited) / 7 days (standard), specific denial reasons on every denial, and public PA metrics each March 31 — for Medicare Advantage, Medicaid/CHIP, and federal-exchange QHP issuers.
- By January 1, 2027: the Prior Authorization API in production (plus enhanced Patient Access, Provider Access, and Payer-to-Payer APIs).
- Notable: CMS granted enforcement discretion on the 278 so payers may run FHIR-only — and proposed rule CMS-0062-P would make the Da Vinci guides mandatory from October 2027. There is no certification; compliance is implement-and-self-assure.
- Excluded: commercial/employer plans and original Medicare — though the industry pledge and EHR-side certification (HTI-4's ePA criteria) are pulling the commercial market the same direction.
The full mandate breakdown — who complies, who audits, what the penalty ladder looks like — is in our CMS-0057 guide.
What ePA Means for Each Player
- Providers: the decision clocks and denial-reason rules already apply — if your payers are slow or vague, that's now a compliance issue, not a fact of life.
- EHR and platform vendors: the payer APIs arriving through 2027 are free, standardized connectivity — the build-on-rails case for embedding PA (see our software guide) gets stronger every quarter.
- Payers: ~365 parent organizations are in scope, most building against the same Da Vinci guides — conformance testing (Touchstone, Connectathons) is the de-facto proof.
We implement both rails — 278 where it lives, FHIR CRD/DTR/PAS where the market is going — inside EHRs, platforms, and payer stacks. Explore our prior authorization automation services or talk to our team.



