Guide

Prior auth as a solo: the workflow that fits in the margins

Summary

A solo prior-auth workflow is a short, repeatable loop, not a department. Keep a one-page list of which of your common codes need authorization per payer. When one is scheduled, verify eligibility and the auth requirement together, submit the medical-necessity justification written to the plan's published criteria, record the reference number, and track it to a decision before the visit. Put the approved auth number on the claim, and learn to tell an auth denial from an eligibility or coding one.

By Gale Editorial · Updated 2026-07-26. Every figure cited to a dated source. How we write.

What a solo prior-auth workflow actually looks like

For a practice of one, prior authorization is a short loop you run the same way every time, not a team you delegate to. The loop is: know which services need authorization, verify eligibility and the requirement together, gather and submit the clinical justification, record a tracking number, follow it to a decision before the visit, and put the approved number on the claim. Built once, it fits in the margins of a clinical day.

The reason to build it deliberately is that the alternative is a denial, and denials are both common and rarely contested. In-network denial rates in ACA marketplace plans run in the high teens on average, with wide variation between insurers, and consumers appeal well under one percent of the claims that are denied 1. A prior authorization is the point in the process where you prevent that denial cheaply, before the service, instead of fighting it expensively afterward — if you ever fight it at all.

The workflow below is written for the person who is also the scheduler, the clinician, and the biller. Every step is designed to take minutes and to leave a record, because in a solo practice the record is the only backup you have when a payer says a number was never received. The steps are ordered so the cheap checks happen first and the expensive discovery only happens on the exceptions the cheap checks flag.

Start with a service list, not a patient

The highest-leverage move is to build the list before the patients arrive: a single page of which of your common codes require prior authorization, by payer. Most of a solo practice's volume is a handful of codes, so the list is short, and once it exists most visits need no research at all — you already know whether this service, for this plan, needs an authorization. You only investigate the exceptions.

The requirement itself lives in each payer's own published policy, and there is no shared master list because every payer maintains its own. Aetna, for example, publishes its Clinical Policy Bulletins — the documents that state what it will authorize and the criteria it uses — on its provider portal 2. UnitedHealthcare publishes its policies and protocols, including which services need prior authorization, in its own separate library 3. Your contract with a given payer controls, so these are examples of where to look, not a rule that applies to every plan you bill.

Because the portals are laid out differently and change over time, the practical artifact is your own cheat sheet: code, payer, auth required yes or no, where you found it, and the date you checked. Re-verify it on a schedule rather than trusting a note from a year ago, since a plan can move a code onto or off its authorization list between plan years. The cheat sheet is the single thing that converts prior authorization from per-visit research into a lookup you already own.

Verify eligibility and the auth requirement in the same step

When a service that might need authorization is scheduled, verify eligibility and the authorization requirement in one pass. Eligibility verification is not a phone-tag exercise: CAQH CORE operating rules standardize the eligibility transaction — the electronic 270 request and 271 response — that payers must support, making a real-time eligibility check a defined step your clearinghouse or EHR can run 4. Use that same contact to confirm whether the specific code needs an auth.

The questions that actually prevent a denial are narrow: is the patient active on this plan today, does this exact code need prior authorization, is there a visit limit or concurrent-review trigger, and — separately — is an auth the same as a referral here. Asking them together means one interaction settles the visit instead of your discovering the authorization requirement only after the eligibility check already came back clean.

Write down what you learn with a reference number every time. A dated eligibility-and-auth note with a reference number is the difference between a payable appeal and your word against theirs, and in a solo practice you are the only person who will remember the call happened. The auth vs referral distinction in particular is worth settling explicitly, because a referral requirement and an authorization requirement are different obligations that deny in different ways and are not satisfied by the same document.

Write the clinical justification to the plan's own criteria

A prior authorization is granted or denied against published medical-necessity criteria, so the justification that works is the one written to those exact criteria, not to your general clinical impression. Payers publish the criteria they use — Aetna's Clinical Policy Bulletins are one example of a searchable library stating what a plan considers medically necessary 2. Reading the criterion before you write turns a paragraph of narrative into a checklist you can answer point by point.

The efficient version for a solo is a reusable template per common authorization: the elements the criterion asks for, in the order it asks for them, with blanks for the patient-specific facts. Most authorizations for the same service ask for the same things — the diagnosis, what has already been tried, and why the requested service is the appropriate next step — so you write the structure once and fill it in each time. That is how the clinical justification stops being a fresh essay on every request.

Specificity is what gets an authorization approved on the first pass. A request that names the diagnosis, the prior treatments and their results, and the reason the requested service meets the plan's stated criterion gives the reviewer everything the criterion requires. A vague request invites a request for more information, which is a delay you then have to chase — the most expensive outcome for a practice with no one to hand the chase to, and the one a criterion-shaped request is built to avoid.

Submit, capture the number, and track it to a decision

Submission is only half the step; the other half is capturing a tracking number and following it to a decision before the visit. Just as eligibility is a standardized transaction, claim status is too — CAQH CORE standardizes the 276 status request and 277 response payers must support, so you can check an authorization or claim electronically 4. Whichever channel you use, the request is not done until you have a confirmation number and a decision date.

The tracking is where solo workflows quietly fail, because there is no worklist unless you make one. A simple tickler — a dated list of pending authorizations with the reference number, the expected decision date, and the visit date — is enough. The point is that a pending authorization has an owner and a deadline, so an approval that is taking too long surfaces before the patient is in the room rather than after the claim denies.

If the decision will not come before the visit, that is a decision in itself: reschedule, proceed knowing the service is at risk, or ask about the plan's process for an urgent or retrospective review. Handling a missed or late authorization — the retro-auth path — is its own procedure with its own deadlines, and knowing in advance which of your payers allow it keeps a timing problem from turning into an automatic write-off.

Put the auth on the claim — and know why "auth on file" still denies

When the authorization is approved, the number has to travel onto the claim in the right field, and the claim has to match the authorization — same code, same units, same dates, same rendering provider. An authorization approved for one code does not cover a different code you end up billing, and a mismatch denies even though an auth genuinely exists. This is the most common way a correctly obtained authorization still produces a denied claim.

It also helps to know which denials are not authorization problems at all, because they are handled completely differently. A units denial, for instance, is often a Medically Unlikely Edit — CMS caps the units of a code one provider can report for one patient on one date, and publishes those values 5 — not a missing authorization, so the fix is the coding or a modifier, not an auth appeal. An eligibility lapse, a referral requirement, and a benefit exclusion each deny in their own way too.

Sorting the denial correctly on arrival is what keeps a solo from appealing the wrong thing. Before you write an appeal, confirm what actually denied: an auth-on-file denial is a matching or timing problem, a units denial is a coding limit, an eligibility denial is a coverage problem. Each has a different, faster fix than a generic appeal, and picking the right one the first time is the whole efficiency of doing this alone.

Prior auth by payer type: commercial, Medicare Advantage, Original Medicare

How much of this workflow you run depends on the payer, so sort your panel into three worlds. Commercial plans authorize the most and vary the most, which is why the per-payer cheat sheet matters. Medicare Advantage plans commonly layer their own prior-authorization rules on top of the Medicare benefit, so those patients behave more like commercial ones than like Original Medicare for authorization purposes. Original Medicare's footprint is comparatively narrow — but narrow is not none.

Because narrow is not none, an Original Medicare service is still worth confirming rather than assuming. For a behavioral health or prescribing practice, the version that recurs most is psych-med prior auths, where a plan requires authorization or step therapy before it will cover a medication. The loop is the same — check the requirement, write to the criteria, track the decision — but the criteria and the turnaround belong to whichever entity owns the pharmacy benefit, which is often not the medical plan, so confirm that ownership first before you spend time on the wrong portal.

The two distinctions worth keeping straight are the Medicare Advantage auth rules and what Original Medicare and prior auth actually require, because assuming a Medicare Advantage plan behaves like Original Medicare is a reliable way to miss an authorization. When a patient hands you a card, the first sorting question is which of the three worlds it belongs to, because that answer decides whether the rest of this workflow even applies to the visit in front of you.

When to fight, when to route around, and which auths are worth the labor

Not every authorization is worth pursuing, and a solo has to triage by value. Look up what a code actually pays before you invest in its authorization: CMS publishes a Physician Fee Schedule lookup that returns the approved amount and RVUs for a code 6, and a low-paying service buried under a heavy authorization burden may be one to refer out. The auth's labor is a real cost that, in a practice of one, lands entirely on you.

When an authorization is denied, the fast paths are usually not a formal written appeal. A peer-to-peer review — a call between you and the plan's reviewer — often resolves a medical-necessity denial faster than a letter, and a missed authorization may still be recoverable through the plan's retrospective-review process if you act inside its window. The choice among them turns on why it denied and how much time the deadline leaves you.

And sometimes the right move is to appeal, because the striking fact about denials is how rarely they are contested — appeals are filed on well under one percent of denied claims 1, which means a denial that is wrong usually stands simply because no one pushed back. A solo cannot appeal everything, but a denial on a service you obtained an authorization for, or one that contradicts the plan's own published criteria, is exactly the kind that is worth the letter and often wins it.

Common questions

By building the list once instead of researching every visit. Most of a solo's volume is a few codes, so a one-page sheet of which codes need authorization per payer covers most visits, and you only investigate exceptions. Verify eligibility and the auth requirement in the same call, write the justification to the plan's published criteria, and keep a dated tickler of pending auths. The system, not heroics, is what fits in the margins.

Its authorization footprint is much narrower than a commercial or Medicare Advantage plan's, which is part of why Original Medicare is lighter to bill — but narrow is not none, so confirm the specific service rather than assume. Medicare Advantage is different: those plans commonly layer their own prior-authorization rules on top of the benefit, so a Medicare Advantage patient is closer to a commercial one for auth purposes than to Original Medicare.

Usually because the claim did not match the authorization. An auth is tied to a specific code, unit count, date range, and rendering provider, and any mismatch denies even though an authorization exists. Confirm the billed code and units match the approved ones and the dates fall inside the auth window. A units denial can also be a coding limit rather than an auth problem, which is fixed in the coding, not by an appeal.

They are different requirements that deny in different ways. A referral is one provider directing a patient to another, often required by HMO-style plans; a prior authorization is the plan approving a specific service in advance. A plan can require one, both, or neither, so verifying whether a service needs an auth and whether it needs a referral are two separate questions to settle before the visit, not one.

Often, because denials are rarely contested — appeals are filed on well under one percent of denied claims, so a wrong denial usually stands only because no one pushed back. A solo cannot appeal everything, but a denial on a service you were authorized for, or one that contradicts the plan's own published criteria, is worth it. A peer-to-peer review is frequently faster than a written appeal for a medical-necessity denial.

Triage by what the service pays against what the authorization costs you in labor. Look up the code's approved amount in the CMS Physician Fee Schedule tool, and weigh a low-paying service with a heavy authorization burden against simply referring it out. The authorization work in a solo practice lands entirely on you, so treating your time as a real cost is part of the workflow, not a shortcut around it.

Run your practice on Gale

The software is free. Gale earns one flat 3.5% all-in per paid transaction — only on transactions that actually pay. No subscription, no setup fee, no network cut.

Start or manage a practice →

References

  1. 1.Kaiser Family Foundation (2025). Claims Denials and Appeals in ACA Marketplace Plans. KFF. linkThat in-network claim denial rates in ACA marketplace plans average in the high teens with wide insurer variation and that consumers appeal well under 1% of denials — the basis for why front-loading a prior-authorization workflow prevents denials that mostly go uncontested, and why a wrong denial is worth appealing.
  2. 2.Aetna (2026). Aetna Clinical Policy Bulletins. Aetna provider portal. linkThat Aetna publishes its Clinical Policy Bulletins — the medical-necessity criteria a service is judged against — on its provider portal, cited only as one named example of a payer's own published policy and never as what all payers require; a solo writes the justification to the criteria the specific plan publishes.
  3. 3.UnitedHealthcare (2026). UnitedHealthcare Policies and Protocols. UnitedHealthcare provider portal. linkThat UnitedHealthcare publishes its policies and protocols, including which services require prior authorization, on its provider portal — cited only as one named example of where a payer's auth requirements are looked up, never as a universal rule; each payer's portal differs.
  4. 4.CAQH (2026). CAQH CORE Operating Rules. CAQH CORE. linkThat CAQH CORE operating rules standardize the eligibility (270/271) and claim-status (276/277) transactions payers must support, making a real-time eligibility check and an electronic status inquiry defined, rule-governed steps a solo can build the workflow around.
  5. 5.Centers for Medicare & Medicaid Services (2026). Medically Unlikely Edits. Centers for Medicare & Medicaid Services (CMS). linkThat a Medically Unlikely Edit caps the units of a code one provider can report for one patient on one date and that CMS publishes the values — the basis for recognizing a units denial as a coding limit rather than a missing authorization.
  6. 6.Centers for Medicare & Medicaid Services (2026). Physician Fee Schedule Search. Centers for Medicare & Medicaid Services (CMS). linkThat CMS publishes a public Physician Fee Schedule lookup returning the approved amount and RVUs for a code in a locality — used here to triage which services are worth the authorization labor by what they actually pay.

https://www.gale.care/for-providers/va-prior-auth-workflow-solo · 6 sources. Competitor details are cited to dated public sources and maintained as they change; figures are estimates, not commitments. Synthetic demonstration.

Findability, by specialty

How practices like yours get found in local search and AI answers — the honest playbook, per specialty.

SEO for private practices · SEO for AI search / answer engines (all verticals)