Sources and review notes
These links support definition-level research and do not establish the regulatory status, safety, or suitability of any product.
Current 42 CFR 422.101 requires Medicare Advantage organizations to apply specified Traditional Medicare coverage sources and, for medical-necessity determinations, consider the applicable criteria, whether the service is reasonable and necessary, the enrollee's medical history, physician recommendations, and clinical notes. It limits when an MA organization may create internal coverage criteria and requires specified criteria, evidence, sources, and rationale to be publicly accessible. Section 422.138 limits prior authorization in coordinated care plans to confirming coverage criteria or medical necessity or, for supplemental benefits, clinical appropriateness, and restricts later medical-necessity denials after an approval except in defined circumstances. CMS's 2024 MA rule also requires MA utilization-management committees to review policies, while the 2025 rule adds annual health-equity analysis and public reporting for specified enrollee groups. CMS-0057-F separately sets decision-time, denial-reason, public-metric, and future API requirements for defined impacted payers and non-drug items and services; CMS's implementation FAQ states that the API does not require real-time decisions and that some requests continue to need clinical review. These sources do not create one universal utilization-management workflow, coverage rule, medical-necessity definition, turnaround time, appeal path, or automation permission for every payer, product, drug, service, or jurisdiction. Buyers must identify the governing program, contract, benefit year, jurisdiction, benefit and service, member status, network status, controlling coverage policy and version, request type, urgency, required evidence, reviewer qualifications, decision deadline, notice content, peer review, reconsideration and appeal rights, continuity rules, and authoritative source before configuring automation. Systems should preserve the original request and clinical record; retrieve only current, applicable criteria; show exact source, version, effective date, matching facts, missing information, uncertainty, and conflicts; distinguish administrative completeness from clinical appropriateness and coverage; and route adverse, ambiguous, urgent, pediatric, disability-related, or exception cases to qualified reviewers without using generated text as the sole basis for a decision. Acceptance testing should cover approvals, denials, partial approvals, requests for information, duplicates, withdrawals, changes in condition, concurrent and retrospective review, transitions of care, deadlines, notices, appeals, overrides, downtime, policy updates, delegated entities, and end-to-end reconciliation with claims and authorization systems. Teams should measure complete and incomplete requests, approval and denial rates, overturns, time to decision, deadline breaches, pending age, repeat submissions, reviewer disagreement, missing or wrong-policy use, access delays, abandoned care, complaints, manual work, and outcomes by benefit, service, plan, provider, geography, language, disability, low-income or dual-eligibility status, and other locally relevant groups. Metrics require stable denominators and context and do not prove appropriate care, lawful coverage, cost savings, fairness, or causation. Governance should include policy owners, clinical and legal approval, version and change control, role separation, audit trails, sampling, error correction, incident response, member and provider communication, and contractually defined vendor responsibilities.