Explore our Topics:

Epic’s prior auth API has a narrow scope. Given WISeR’s troubles, that’s not a bad idea.

Epic has announced that four health systems implemented its API to check if services need prior authorization. While not exactly groundbreaking, it’s functional –which can’t be said for AI-powered prior auth in Medicare.
By admin
Sep 18, 2026, 12:47 PM

At its annual User Group Meeting, Epic announced that four health systems and a handful of payers had launched real-time prior authorization checks. The vendor’s application programming interface, based on an industry standard API known as Coverage Requirements Discovery, will verify whether a medical service requires prior authorization.

It’s a key step forward from manually poring over lengthy insurer-issued documents to determine if prior authorization could impact a patient’s care journey. The tool is valuable in part because research points to significant differences in prior authorization volume among large insurers. Epic also said the API satisfies one requirement of the long-awaited Interoperability and Prior Authorization Final Rule that goes into effect Jan. 1, 2027.

That said, it’s a small step. The API on its own doesn’t cover processes such as obtaining prior authorization, which practice-based physicians must do nearly 40 times per week, or appealing denials, which impact about one in seven prior authorization requests. Both are cornerstones of the final rule and the broader debate about the administrative burdens of prior authorization.

Given that AI-driven prior authorization efforts continue to make headlines for the wrong reasons, though, the scope of Epic’s announcement makes perfect sense.

Automating one step in a “complex process”

Leaders at the health systems mentioned in the announcement – Ochsner Health, Froedtert ThedaCare Health, Denver Health, and Summit Health – point to the potential to streamline access to care and reduce delays when clinical teams can quickly check if a service needs prior authorization. Looking before placing an order or scheduling an appointment, for example, lets care teams know if they can proceed right away or need to start the approval process first.

The workflow also benefits payers, who under the final rule are on the hook for implementing prior authorization APIs to speed up decision-making. The Centers for Medicare & Medicaid Services will require decisions within 72 hours for urgent requests and one week for standard requests. (That likely explains why 16 more payers are testing Epic’s API, according to the company’s statement.)

CMS has noted that “[a]utomating a complex process such as prior authorization will be an ongoing process of continuous improvement.” 

To understand why Epic may have started with automated prior authorization checks, and not automation of the process itself, look no further than the short but tumultuous history of the Wasteful and Inappropriate Service Reduction pilot.

Broader automation not ready for prime time

WISeR has faced opposition from the get-go, with critics arguing that AI-driven prior authorization in traditional Medicare would lead to increased denials and delayed care. (It hasn’t helped that states have been left to craft their own policies on AI in prior authorization amid limited guidance from the Trump administration.) 

This summer, the Senate blocked a bid to end WISeR before its scheduled conclusion in 2031. Last week, records obtained by the Electronic Frontier Foundation through a FOIA lawsuit against CMS suggest the concerns about denials and delays are well founded – in part because technology vendors were moving too fast. 

The EFF reported that 30% of prior authorization requests didn’t garner a response within five days, with 10% lingering for more than a week and a half. There was another underlying issue: The systems simply weren’t ready. 

WISeR launched just six months after it was announced. EFF documents showed that multiple vendors contracting with CMS reported technical challenges after go-live, including “unclear governance processes, and lack of time for end-to-end testing with the provider community.” One vendor was still testing features in April 2026 – months into the program.

Though time may tell, WISeR as it currently stands seems poised to land on the list of healthcare’s maligned technology implementations. Against that backdrop, using a functional API to check if prior authorization is necessary, and then executing established workflows to seek approval, represents a simpler but far more logical step than turning the entire prior authorization process over to unproven systems.


Brian Eastwood is a Boston-based writer with more than 10 years of experience covering healthcare IT and healthcare delivery. He also writes about enterprise IT, consumer technology, and corporate leadership.


Show Your Support

Subscribe

Newsletter Logo

Subscribe to our topic-centric newsletters to get the latest insights delivered to your inbox weekly.

Enter your information below

By submitting this form, you are agreeing to DHI’s Privacy Policy and Terms of Use.