Medicare Advantage organizations face a new utilization-management data submission
CMS now requires MA organizations to submit information about internal coverage criteria used by the organization or its delegates for Part C prior authorization.
Editorial figure by Prior Auth Monitor. Source context: Centers for Medicare & Medicaid Services.
Coverage criteria become a governed data problem
The annual submission pushes a familiar UM challenge into a more explicit recordkeeping obligation. A plan may use national coverage rules, internal criteria, licensed clinical content, and criteria operated by delegated entities. Those sources cannot be managed safely as an undifferentiated document library.
Plans need to identify the criterion, its source, applicable service and population, effective period, approving authority, delegation relationship, and change history. The submission also makes it harder to treat a vendor's content library as a black box separate from the plan's accountability.
What buyers should test
A demonstration should show how a criterion is introduced, reviewed, approved, versioned, assigned to a line of business, applied to a case, and included in a regulator-ready export. Teams should also test how delegated criteria are represented and how conflicts between a delegate's workflow and the plan's policy are escalated.
Clinical criteria vendors, core UM platforms, delegated specialty organizations, and decision-intelligence products occupy different parts of this chain. Their records should be compared by operating role rather than by asking whether each product broadly supports 'prior authorization.'
Enterprise buyer test
Translate this change into the exact population, record type, workflow stage, decision owner, effective date, and evidence that could be affected. Ask current or prospective providers to demonstrate the named workflow with representative data and an exception—not a polished feature tour. Record what official documentation establishes, what a provider states, what the team observes, and what remains unresolved.
A defensible review also identifies the dependency outside the product. Authority interpretation, policy configuration, data quality, integrations, human judgment, approval rights, release governance, training, and retained evidence may remain customer or service responsibilities. The evaluation should preserve those boundaries instead of treating a technology claim as the complete operating model.
What we will watch next
Prior Auth Monitor will watch the named source and affected market records for later evidence that changes status, scope, availability, implementation timing, workflow consequence, or the limits of the initial report. A later announcement does not silently overwrite this dated account; the change ledger preserves the sequence.