Prior Authorization Basics
Prior authorization is one of the most misunderstood parts of medical billing, mostly because of what people assume it guarantees. This article covers what it actually confirms, what it doesn't, and the timing rule that matters most.
What prior authorization actually is
Prior authorization (often shortened to "prior auth" or "PA") is a payer's advance review of a planned procedure, confirming that it's medically necessary and appropriate under the patient's policy before the service is performed. Many procedures that get billed to medical insurance — sleep appliances, therapeutic Botox in some cases, certain oral surgery — require it.
What a prior authorization confirms
- That the procedure is medically valid and appropriate given the documented condition
- That it's a covered benefit under the patient's specific policy
- That you have permission to proceed and bill for it
What a prior authorization does NOT confirm
This is the part that trips people up most: an approved prior authorization does not tell you how much the payer will actually pay.
It confirms the procedure is valid and will be considered for coverage. It does not lock in a dollar amount. The actual payment still depends on where the patient stands with their deductible, their coinsurance structure, and the allowed amount for that code — exactly the same variables covered in the Deductibles, Coinsurance & Out-of-Pocket Max article. A patient can have a fully approved prior auth and still owe the full fee out of pocket, if they haven't met their deductible yet.
Practical implication: when a patient asks "how much will insurance cover," a prior auth approval isn't the answer to that question. If they want a specific number, the most reliable way to get one is for the patient to call their insurer directly and ask — payers are often more transparent with policyholders than with providers on this point. You can also share the codes with the patient so they have exactly what to ask about.
The timing rule that matters most
Prior authorization has to happen before the procedure, not after.
Most payers will not accept a prior auth request retroactively once a service has already been performed. If a claim comes back denied because prior auth was missing, and the visit already happened, resubmitting typically won't fix it — see Reading a Denial for how to handle that specific situation. A small number of exceptions exist (true emergencies, certain Medicaid retro-authorization policies), but these shouldn't be assumed available — they're payer-specific and uncommon.
This is why prior auth status should be checked and resolved as part of scheduling, before the day of the procedure, for anything that requires it. Treat it as a pre-visit checklist item, not a post-visit cleanup task.
How the process differs by payer
Every payer handles prior authorization slightly differently:
- Some can be submitted and approved electronically, often within a day or two
- Some require fax submission
- Some, like sleep apnea appliances, commonly require a bundle of supporting documents submitted together: a prescription from the patient's physician, the sleep study results, and a CPAP affidavit (for patients who couldn't tolerate CPAP therapy)
- Turnaround time varies significantly — some payers respond within a couple of days, others can take weeks, especially if they request additional documentation
There's no universal timeline to rely on. Always account for turnaround time when scheduling a procedure that requires prior auth, rather than assuming it'll come back quickly.