How do I know if a service needs prior authorization?
Quick Answer
Check the payer's prior authorization list on their provider portal, search by the specific CPT/HCPCS code, and verify against the patient's plan. Always document the authorization number or the confirmation that no auth was required before rendering the service.
Step-by-Step Instructions
Check the payer's prior authorization list
Most payers publish a list of services that require prior authorization on their provider portal. Search by CPT/HCPCS code or procedure description. Medicare publishes Local Coverage Determinations (LCDs) that indicate when services require documentation of medical necessity.
Verify the specific CPT/HCPCS code
Prior auth requirements are code-specific. A service that requires auth under one code may not under another. Use the exact code you plan to bill, not a similar one. Check both the procedure code and any associated modifiers.
Confirm the patient's plan requirements
Prior auth requirements vary by plan within the same payer. A service that requires auth on one UHC plan may not on another. Verify the patient's specific plan by checking eligibility through the payer portal or calling the payer.
Submit the prior authorization request
If auth is required, submit the request through the payer portal, fax, or phone. Include the CPT code, diagnosis, clinical justification, and provider information. Most payers respond within 5–15 business days. Urgent requests may be processed in 72 hours.
Document the authorization number
Once approved, record the authorization number, the approved number of visits/units, the date range, and any conditions. Enter this in your practice management system and include it on the claim (Box 23 on the CMS-1500). Without the auth number on the claim, you risk a CO-197 denial.
If no auth is required, document that too
Note in the patient record that you verified no prior auth was needed, including the date, the method of verification (portal, phone call), and the reference number. This protects you if the payer later denies for no authorization.
Common Mistakes to Avoid
Assuming a service does not need auth because it didn't last year — payer auth lists change frequently.
Not verifying the patient's specific plan — auth requirements vary by plan within the same payer.
Forgetting to put the auth number on the claim (Box 23) — results in CO-197 denial.
Rendering the service before auth is approved — retro-auth is difficult and often denied.
Not documenting the verification call — without proof, you cannot appeal a retro denial.
