Most Prior Authorization Lists Have Never Been Audited by Anyone Who Wasn't Defending Them
Here's a number that should stop every utilization management conversation: of prior-auth denials in Medicare Advantage, only about one in nine is ever appealed — and of those appeals, roughly four in five get overturned (KFF's analysis of CMS's 2024 data). Read that again. When someone pushes back, the plan's own process concludes the denial was wrong 80% of the time.
That asymmetry is the single most important fact about a prior authorization portfolio, and most plans have never computed what it means for their own list. Six things we've learned building a workbench that does.
1. The list is a portfolio, and portfolios have losers. Every code on the auth list costs money on every request — intake, nurse review, physician time — including the 92% you approve. A code you almost always approve can lose money on every denial-that-sticks and still sit on the list for a decade. Price the whole requirement, not the marginal denial.
2. Denial rate is an output, not a dial. Being below the 7.7% MA average is not an opportunity to deny more, and being above it is not proof of rigor. It's a function of your criteria and your case mix. Treat it as a diagnostic, never a target.
3. Deterrence is real — and it cuts both ways. The best causal evidence we have (Medicare Part D) says most of prior auth's savings come from requests never submitted, not from denials upheld. Some of that deterred care was low-value. Some of it was a patient who gave up. A savings model that counts all deterrence as a win has decided not to ask which.
4. The clocks are no longer yours. Seventy-two hours expedited, seven calendar days standard, a specific reason on every denial, and your metrics published for the public every March. The federal rule is in force now. A list you can't defend code-by-code is a list you'll be explaining metric-by-metric.
5. Automation is asymmetric by law. Regulators let algorithms approve; they don't let an algorithm be the sole basis for a denial — a physician has to own that. So automation makes approving nearly free while denying keeps a human floor. That pushes strategy in one direction: fewer, better-targeted requirements.
6. The right question is almost never "deny more or deny less." It's: which codes earn their review cost, which should auto-approve, which should come off the list entirely — and what the change does to patients, providers, and the metrics you're about to publish.
We built these questions into a workbench that takes a plan's own authorization list and works the economics code by code — every assumption editable, every benchmark cited, and a findings report that says plainly what the numbers cannot carry. It runs entirely in the browser; nothing entered ever leaves the machine.
The thread through it all: a prior auth list is a set of decisions somebody made once, under different rules. The plans that will do well under the new transparency are the ones re-making those decisions on purpose.
When did your organization last retire an authorization requirement — and what did it take?