Authorized but denied: matching auth to claim, digit by digit
Summary
An authorization only pays a claim that matches it exactly: the same CPT/HCPCS code and units, a date of service inside the authorized window, the same rendering and billing NPI and taxonomy code, the same place of service, and the auth number correctly placed on the claim form. Payer systems match these fields mechanically, not by confirming an authorization merely exists somewhere for the patient, so a mismatch on any single field denies the claim even with a valid authorization on record.
By Gale Editorial · Updated 2026-07-26. Every figure cited to a dated source. How we write.
The fields that actually have to match
Five fields typically have to align between the authorization and the claim: the CPT/HCPCS code and unit count, the date of service falling inside the authorized date range, the rendering and billing provider's NPI, the provider's taxonomy code, and the place of service. A mismatch on any one of these is enough to trigger a denial that reads as "no authorization on file," even though an authorization genuinely exists for that patient.
The authorization number itself also has to land in the right place on the claim — box 23 on the CMS-1500 form, per the National Uniform Claim Committee's own completion instructions for that form 1Ref 1National Uniform Claim Committee (2026).1500 Claim Form.That box 23 on the CMS-1500 is the designated field for the prior authorization number, per NUCC's own completion instructions. An authorization sitting correctly in your records but typed into the wrong box, or omitted from the claim entirely, produces the same denial as never having gotten the authorization at all.
Reading the denial: what CO-197 is actually telling you
CO-197 is the standard reason code payers use to flag a missing or non-matching precertification, authorization, or notification, and X12 maintains the full reason-code list it comes from 2Ref 2X12 (2026).Claim Adjustment Reason Codes.That CARCs, including CO-197, are the standard code list explaining why a claim was paid differently than billed, maintained by X12. Seeing CO-197 with a valid authorization in hand means the system didn't recognize a match — not that no authorization exists — so the next step is comparing the claim against the authorization field by field rather than simply resubmitting.
Whatever remark code rides alongside CO-197 on the remittance often narrows down which specific field failed to match, and X12 maintains that supplemental code list as well 3Ref 3X12 (2026).Remittance Advice Remark Codes.That RARCs supply the supplemental explanation narrowing down which field failed to match alongside a CARC. Read both together before calling the payer — it's the fastest way to find the actual mismatch instead of guessing at it.
Taxonomy and NPI mismatches: a quieter cause
An authorization is sometimes issued against a specific provider taxonomy code, and a claim submitted under a different taxonomy for the same NPI, or the wrong NPI in the rendering-provider field, can fail to match even when the authorization plainly names the right person. The National Uniform Claim Committee maintains the taxonomy code set and is the reference point for confirming which code should be attached to a given claim 4Ref 4National Uniform Claim Committee (2026).Health Care Provider Taxonomy Code Set.That provider taxonomy codes are maintained by NUCC and selected at NPI enrollment, and can be an authorization-matching field.
Taxonomy codes classify a provider's type and specialty and are selected once at NPI enrollment, which is why two providers with similar credentials can still carry different codes depending on how each one enrolled. This is a quieter failure mode than a wrong CPT code because nothing about the claim looks obviously wrong to a person reading it — the mismatch only shows up when you compare the taxonomy and NPI on the claim against exactly what the authorization specifies, field by field rather than by general impression.
Why payers weight these fields differently
Which fields a given payer's system checks strictly, and which it's more forgiving about, is a payer-specific configuration, not a universal rule — Anthem, Aetna, UnitedHealthcare, and Cigna each publish their own provider policy describing how their authorization and claims-matching processes work, and none of the four generalizes to how another payer behaves 5Ref 5Anthem (2026).Anthem Provider Policies.Anthem's own published provider policy as a named example of payer-specific authorization-matching rules6Ref 6Cigna (2026).Cigna Coverage and Claims Policies.Cigna's own published provider policy as a named example of payer-specific authorization-matching rules. Your specific payer's own published policy, not a general industry assumption, is what actually controls.
For a service or a payer relationship you bill often enough to be worth the setup, keeping a short internal note on that payer's specific matching quirks — which field it's strict about, which it tolerates — saves the repeat troubleshooting the next time an otherwise-valid authorization gets denied.
This denial pattern is common enough to be worth appealing, not absorbing
In-network claim denial rates in ACA marketplace plans average in the high teens, and consumers and providers together appeal well under 1% of denied claims — most denials, including matchable authorization mismatches, simply get absorbed rather than corrected 7Ref 7Kaiser Family Foundation (2025).Claims Denials and Appeals in ACA Marketplace Plans.That in-network denial rates average in the high teens and appeals are rare, framing why a fixable mismatch denial is worth correcting rather than absorbing. An auth-on-file denial caused by a field mismatch is usually one of the more fixable categories, because the underlying authorization is genuinely valid; the claim just needs to be corrected and resubmitted rather than appealed on the merits.
Compare the claim against the authorization field by field, correct whichever one doesn't match, and resubmit or appeal through the payer's standard process rather than treating the denial as final — the auth vs referral distinction and the retro-auth process cover two related situations worth knowing before you assume a denial means the authorization itself was invalid.
When correcting the mismatch doesn't resolve the denial
Correcting a genuine field mismatch and resubmitting resolves most auth-on-file denials, but occasionally the payer denies again anyway — at that point the issue has usually shifted from an administrative mismatch to an actual medical-necessity question, and treating it as the same fix won't work a second time.
Requesting the peer-to-peer review moves the conversation from a claims-matching mechanism to an actual clinical discussion between your practice and the payer's own reviewer, which is a genuinely different process than resubmitting a corrected claim and is worth invoking once the mismatch itself is confirmed clean. Keep the corrected claim and the original authorization on hand for that call, since the reviewer will be comparing the same fields a claims examiner already checked, just with clinical judgment layered on top.
Common questions
Run your practice on Gale
The software is free. Gale earns one flat 3.5% all-in per paid transaction — only on transactions that actually pay. No subscription, no setup fee, no network cut.
Start or manage a practice →References
- 1.National Uniform Claim Committee (2026). 1500 Claim Form. National Uniform Claim Committee (NUCC). link ✓That box 23 on the CMS-1500 is the designated field for the prior authorization number, per NUCC's own completion instructions
- 2.X12 (2026). Claim Adjustment Reason Codes. X12. link ✓That CARCs, including CO-197, are the standard code list explaining why a claim was paid differently than billed, maintained by X12
- 3.X12 (2026). Remittance Advice Remark Codes. X12. link ✓That RARCs supply the supplemental explanation narrowing down which field failed to match alongside a CARC
- 4.National Uniform Claim Committee (2026). Health Care Provider Taxonomy Code Set. National Uniform Claim Committee (NUCC). link ✓That provider taxonomy codes are maintained by NUCC and selected at NPI enrollment, and can be an authorization-matching field
- 5.Anthem (2026). Anthem Provider Policies. Anthem provider portal. link ✓Anthem's own published provider policy as a named example of payer-specific authorization-matching rules
- 6.Cigna (2026). Cigna Coverage and Claims Policies. Cigna provider portal. link ✓Cigna's own published provider policy as a named example of payer-specific authorization-matching rules
- 7.Kaiser Family Foundation (2025). Claims Denials and Appeals in ACA Marketplace Plans. KFF. link ✓That in-network denial rates average in the high teens and appeals are rare, framing why a fixable mismatch denial is worth correcting rather than absorbing
https://www.gale.care/for-providers/va-auth-on-file-still-denied · 7 sources. Competitor details are cited to dated public sources and maintained as they change; figures are estimates, not commitments. Synthetic demonstration.