CMS Interoperability Final Rule, FHIR, and AI Voice in 2026
By Sagar Shankaran, Founder of CallSphere
CMS-0057-F, the 2024 Interoperability and Prior Authorization Final Rule, plus the 2026 CMS-0062-P proposed rule for prior-authorization drugs, reshape what AI voice and chat must do with FHIR APIs.
Key takeaways
CMS finalized the Interoperability and Prior Authorization Final Rule (CMS-0057-F) in January 2024. The 2026 CMS-0062-P proposed rule extends FHIR-based electronic prior authorization to drugs. AI voice and chat agents that book appointments, check eligibility, or pre-screen authorizations need to plug into the same FHIR rails.
What the rule says
CMS-0057-F was published January 17, 2024 (89 FR 8758). It applies to Medicare Advantage organizations, Medicaid managed care plans, state Medicaid agencies, CHIP managed care entities, and qualified health plans on the Federally-Facilitated Exchanges. The rule requires impacted payers to:
- Implement and maintain a Patient Access API (HL7 FHIR R4 + USCDI v1) starting January 1, 2027 expansions;
- Implement a Provider Access API for treating providers;
- Implement a Payer-to-Payer API supporting member-data portability;
- Implement a Prior Authorization API (CRD/DTR/PAS IGs) for non-drug items and services beginning January 1, 2027;
- Send PA decisions within 72 hours for expedited and 7 calendar days for standard requests;
- Publicly report PA metrics annually.
CMS-0062-P, published April 14, 2026, extends prior-authorization to drugs via FHIR or NCPDP standards beginning October 1, 2027, with public comment open through June 15, 2026.
Hear it before you finish reading
Talk to a live CallSphere AI voice agent for healthcare in your browser — 60 seconds, no signup.
What AI voice/chat must do
For AI voice agents in healthcare, the rule turns FHIR from "nice to have" into the integration pattern. An AI agent confirming a referral or pre-screening a prior authorization should call the Provider Access API to read clinical context, the Prior Authorization API to submit and track requests, and the Patient Access API to surface PA status to the patient. The 72-hour and 7-day SLAs mean an agent that makes the right API calls can shorten total cycle time materially.
Closed-loop monitoring is now a requirement: the agent should log every PA submission, status check, and approval/denial outcome, with model-version metadata. That telemetry feeds CMS's annual public reporting and the entity's own audit trail.
CallSphere compliance posture
Explore a live demo and compare current plans to find the right fit for your business.
flowchart LR
A[Caller] --> B[Voice Agent]
B --> C[Patient Access\nFHIR API]
B --> D[Provider Access\nFHIR API]
B --> E[Prior Auth API\nCRD/DTR/PAS]
E --> F[Payer]
F --> G[72h Expedited\n7d Standard]
G --> H[(healthcare_voice\nAudit)]
Compliance checklist
- Stand up FHIR R4 client libraries against Patient, Provider, Payer-to-Payer, and PA APIs.
- Implement DTR (Documentation Templates and Rules) workflows in the agent.
- Track PA submissions, status checks, and outcomes in the audit trail with model metadata.
- Honor the 72-hour and 7-day decision SLAs by triggering escalations.
- Surface PA status to patients on demand via Patient Access API queries.
- Log every API call (request, response, latency) for compliance reporting.
- Capture USCDI v3 fields where supported alongside USCDI v1 baseline.
- Stand up the public PA-metrics reporting pipeline.
- Track CMS-0062-P (drug PA) progression; plan NCPDP integration in parallel.
- Re-test integration with each payer FHIR-server upgrade.
FAQ
Does CMS-0057-F apply to commercial-only payers? No. It applies to MA, Medicaid managed care, state Medicaid, CHIP, and FFE QHPs.
Still reading? Stop comparing — try CallSphere live.
See the healthcare AI agent handle a real call — complete, industry-specific, and live in your browser. No signup.
Are providers in scope? Indirectly — they consume Provider Access and Prior Authorization APIs but are not the regulated entity.
Is OAuth required? Yes, FHIR APIs use OAuth 2.0 with SMART-on-FHIR profiles for patient access.
Can AI agents submit PAs autonomously? Yes if the workflow is documented, providers approve, and the agent records human-in-the-loop confirmations.
Sources
- CMS-0057-F Final Rule: https://www.cms.gov/priorities/burden-reduction/overview/interoperability/policies-regulations/cms-interoperability-prior-authorization-final-rule-cms-0057-f
- CMS-0062-P Proposed Rule: https://www.cms.gov/priorities/burden-reduction/overview/interoperability/policies-regulations/cms-interoperability-standards-prior-authorization-drugs-proposed-rule-cms-0062-p
- HL7 FHIR R4: https://hl7.org/fhir/R4/
- Da Vinci PA Implementation Guides: https://www.hl7.org/about/davinci/
- CMS Electronic Prior Authorization overview: https://www.cms.gov/priorities/electronic-prior-authorization/overview

Written by
Sagar Shankaran· Founder, CallSphere
LinkedInSagar Shankaran is the founder of CallSphere, where he builds production AI voice and chat agents deployed across healthcare, hospitality, real estate, and home services. He writes about agentic AI, LLM engineering, and shipping voice agents that handle real calls in production.
Try CallSphere AI Voice Agents
See how AI voice agents work for your industry. Live demo available -- no signup required.