ClinicOps  /  Briefings  /  Prior authorization

Operations Guide · Published July 22, 2026 · Updated July 2026

Prior Authorization for Independent Practices: The Complete Operations Guide

Thirteen hours a week, per doctor, on work nobody pays you for. This is the operations guide to the prior authorization process: where it breaks inside an independent practice, and what a version that doesn't leak actually looks like.

The prior authorization process is how a medical practice secures a payer's approval before delivering a service: confirm the service needs it, submit the clinical documentation, track the request to a decision, and appeal any denial. Most independent practices run this on memory instead of a system.

Key takeaways

  • Prior authorization takes 13 hours of physician and staff time per doctor, every week, and the average physician completes about 40 requests a week (AMA, 2025).
  • 40% of practices employ someone who works exclusively on prior auth. That's a full-time salary for what a system should handle in the background (AMA, 2025).
  • 50% of providers name missing or inaccurate data at submission the number-one driver of rising denials, ahead of any clinical disagreement (Experian Health, 2025). It's a capture problem you can fix.
  • 79% of physicians say patients at least sometimes abandon treatment because of authorization delays; 26% report a delay that led to a serious adverse event (AMA, 2025).
  • The fix isn't more staff or new software. It's one tracked process: clear owners, follow-up alarms, a denial log, and expiration dates. That's the difference between a fax pile and a system.

Thirteen hours. That's the physician and staff time your practice burns on prior authorization every week, for every doctor. It's the AMA's 2025 figure, and it climbed, it didn't fall. About 40 requests a week, per physician, up from 39 the year before. Right now, somewhere in your office, that work is in motion: a fax that half-sent, a payer portal someone's locked out of, a sticky note that says "call the plan back" with no date on it.

You know all this. You live it. So this guide skips the part where we explain what prior authorization is. You could explain it to us. Instead it does three things: shows you where the process actually breaks inside an independent practice, puts a number on what that's costing you in revenue you've already earned, and lays out what a version that doesn't leak looks like. One your own team runs. Not a service you rent by the plan.

What prior authorization really costs a practice

Start with the money, because that's the part that hides.

The 13 hours the AMA counts aren't abstract. They're a person, often a specific person you could name, spending most of two days a week on hold, keying the same clinical notes into three different portals, and chasing decisions that should have been automatic. 40% of practices now employ someone whose entire job is prior authorization. That's a full-time salary for coordination work a system should be handling quietly in the background.

Then there's the money that leaks out the far end. Missing or inaccurate data at submission is the number-one driver of rising denials, named by 50% of providers (Experian Health, 2025), not a clinical fight but a capture miss. Every one of those is a service you delivered, or nearly did, that now has to be reworked or written off. Reworking a single denied claim runs health systems about $57.23 (Premier, 2023). A small practice's number is its own, but the direction is identical: you pay twice for work you should have been paid for once. That is the malpractice of money: the preventable kind you would never accept on the clinical side.

26%
of physicians report a prior authorization delay that led to a serious adverse event: hospitalization, permanent impairment, in the worst cases worse. AMA, 2025

And the cost that never lands on a spreadsheet: the patient who walks. 79% of physicians say patients at least sometimes abandon treatment because the authorization took too long (AMA, 2025). That 26% figure above is the one that keeps an owner-physician up at night, because it stops being a billing problem and becomes a clinical one with your name on it. That is a cost you can actually prevent. Not by working harder inside a broken process, but by fixing the process.

Get the free Prior Auth Rescue Kit

The tracker and denial log we build for clients, packaged for you to keep. Chart-number-only, ready to drop into ClickUp, Monday, Asana, or a spreadsheet.

Get the free Rescue Kit

The prior authorization process, step by step

Every practice runs the same seven stages, whether or not anyone has ever drawn them out. And the problem is almost never that a stage is hard. It's that no one owns the stage, and there's nowhere the whole thing lives except in someone's head and a drawer of fax confirmations.

Here's the prior authorization process the way your team actually experiences it, and the precise point each stage tends to come apart.

The prior authorization pipeline: seven stages, seven places it leaks A vertical pipeline of the seven prior authorization stages and the point where each one leaks, all sealed by one tracked system. THE LEAK MAP Seven stages. Seven places your money leaks. 1 Determine requirement You find out at the denial. 2 Gather documentation A thin file resets the clock. 3 Submit Wrong channel, and it sits. 4 Track to a decision Gone till the patient calls. 5 Follow up on the clock Nobody knows the deadline. 6 Work the decision Denials sit unappealed. 7 Watch expiration The approval lapses first. One tracked system seals all seven.
The seven-stage prior authorization pipeline. Every stage leaks without a system; one tracked process, with owners and alarms, seals all seven.
  1. Decide whether the service even needs authorization. Requirements shift by payer, by plan, and by quarter. The failure mode: you learn a service needed prior auth when the claim comes back denied, weeks later. The fix is boring and it works. Keep a current requirement list, payer by payer, that your front desk checks before the patient leaves the building.
  2. Gather what the payer will actually accept. Not what you think proves medical necessity, but what that specific reviewer needs to see. Submit it thin and you get a request for more information, which resets the clock. Data problems drive a large share of denials; a short documentation checklist per service kills most of them before they start.
  3. Submit through the right channel. One payer wants the portal, the next wants a fax, a third wants a phone call. Send it to the wrong place and it doesn't bounce back. It just sits. Log the method and the confirmation number every single time.
  4. Track it to a decision. This is where most practices lose the thread. The request leaves the building and disappears until the patient calls asking why their MRI hasn't been scheduled. What closes the gap: one board, one named owner per request, status visible to anyone who looks. Not a folder. A board.
  5. Follow up on the clock, their clock. As of January 2026, many plans have to decide urgent requests within 72 hours and standard ones within seven days. If you don't know the deadline, you can't push on it. Set a follow-up cadence of 48 hours, five days, and ten days, so nothing ages in silence.
  6. Work the decision. Approved, schedule it. Denied, appeal it. And here's the part that should bother you: denials are frequently overturned on appeal, yet many are never appealed at all. The barriers are staff, time, and a quiet belief it won't work (AMA, 2025). A denial log plus a reusable appeal packet turns "we didn't get to it" into "it's handled."
  7. Watch the expiration date. The one everybody forgets. Authorizations expire. An approval you fought two weeks for lapses before the procedure happens, and you're back at stage one, or eating the denial. Every approved auth needs an expiration alarm the day it's issued. We wrote a full guide on authorizations that expire before the visit.

Notice what all seven have in common: none of them are clinical. They're coordination. You don't have a prior authorization problem. You have a system problem wearing a prior authorization costume.

The prior auth process at a glance
StageWhere it breaksThe fix
1. Determine requirementYou find out at the denial, weeks laterPayer-by-payer requirement list at the front desk
2. Gather documentationThin submission → request for info → clock resetsDocumentation checklist per service
3. SubmitWrong channel; it sits instead of bouncingSubmission log with method + confirmation #
4. TrackRequest vanishes until the patient callsOne board, one owner per request
5. Follow upNobody knows the payer's deadlineAlarm cadence: 48 hrs / 5 days / 10 days
6. Work the decisionDenials sit because appealing feels hopelessDenial log + reusable appeal packet
7. ExpirationApproval lapses before the procedureExpiration date + alarm on every approval

What a working prior auth system looks like

You don't need new software. Most practices are already sitting on everything they need inside the tools they pay for: ClickUp, Monday, Asana, even a well-built spreadsheet. What's missing isn't a platform. It's the wiring.

A prior auth process that doesn't leak has five parts:

  • One tracker, one source of truth. Every request in a single place. Never a sticky note, never a personal inbox.
  • A named owner per request. "The team handles it" means no one does. Each request carries one person's name until it closes.
  • An alarm cadence. 48 hours, five days, ten days. The system nudges before anything ages, so following up stops being a memory test.
  • A denial log. Every denial captured with its stated reason, so you appeal fast, and you start seeing the pattern: the payer, the service, the one missing field that keeps costing you.
  • Expiration tracking. Every approval carries its expiration date and an alarm. Nothing lapses.

None of that is exotic. For someone who's built it before, it's a Tuesday-afternoon job. The reason most practices don't have it isn't capability. It's that the person who'd build it is the same person drowning in the work it would fix. If that's your practice manager, this is theirs to own: a system where nothing slips on their watch, because the board catches what a fax pile can't.

One rule that isn't optional for a US practice: protected health information never goes into a project tool. You track by chart number, never patient name or diagnosis. Built right, the board holds the workflow and your EHR holds the PHI, and the two never cross. Any system that asks you to paste patient details into a task is the wrong system.

Sample data, illustrative. A demo prior-auth board in a standard project tool, chart numbers only, never patient names or diagnoses.

The system, piece by piece

This guide is the map. Each part below is a build you can put in place this month, free, and yours to keep. Live guides are linked; the rest are on the way.

  • Free prior authorization tracking spreadsheet soon

    Sheets, Excel, and ClickUp versions of the one tracker every request lives in.

  • The any-payer prior authorization checklist soon

    What to confirm before you submit, so thin submissions stop resetting the clock.

  • The 48-hour prior auth pipeline soon

    The alarm cadence that keeps requests from aging in silence.

  • The auth-expiration system

    Live: the owner-and-alarm build that stops approved auths from lapsing before the visit.

  • The denial log that catches patterns soon

    Turn scattered denials into a list that tells you what to fix.

Prior authorization by the numbers

If you're building the case internally, to an owner, a partner, or yourself, here are the figures worth citing, each with its source and date. Use them. That's what they're for.

Prior authorization, measured
NumberWhat it meansSource
13 hrs / weekPhysician and staff time spent on prior auth, per physician, every weekAMA, 2025
~40 / weekPrior authorization requests the average physician completes weekly (up from 39 in 2024)AMA, 2025
40%Practices that employ staff working exclusively on prior authorizationAMA, 2025
79%Physicians reporting patients at least sometimes abandon treatment due to PA delaysAMA, 2025
26%Physicians reporting a PA delay led to a serious adverse eventAMA, 2025
50%Providers naming missing or inaccurate data the top driver of rising denialsExperian Health, 2025
$57.23Cost to rework a single denied claim (health-system data; a practice's figure differs)Premier, 2023

Outsource, hire, or build a system?

Three ways to deal with prior auth. Only one of them you still own at the end.

Outsource it

Hand it to a prior-auth or RCM vendor, usually billed per plan or as a slice of collections. It moves the work off your desk. It also moves the knowledge off your team. When the vendor changes or you leave them, the process walks out the door with them, and your cost climbs with every request you send.

Hire a dedicated coordinator

40% of practices have. It works, right up until that person is out sick, on vacation, or gone. Front-office roles are among the highest-turnover seats in a practice. Hire without a documented system behind them and you've bought a single point of failure with benefits.

Build a system your team runs and owns

The work stays in-house, the knowledge lives in the process instead of one person's head, no per-request meter runs, and it survives turnover because the next hire inherits a board, not a mystery. This is the option that gets cheaper over time instead of more expensive.

We're not neutral here. Building the system is what we do, in plain sight, at published prices. But the honest version is this: if your volume is low and steady, a sharp coordinator with a good tracker might be all you need, and we'll say so on a call. The moment DIY stops working is when the same leaks keep happening no matter who's doing the job. That's the signal the problem was never the person.

Find your leak before you fix it

Two ways to start, both free.

Take the tracker and denial log and run it yourself, or get a 15-minute Leak Audit where we put a real number on what your prior auth process is costing, using your own volume.

Frequently asked questions

Does every service need prior authorization?

No. Requirements vary by payer and plan, and they change often. The real problem isn't that everything needs authorization. It's knowing which services do before you deliver care, instead of finding out when the claim is denied.

How long does prior authorization take?

It varies widely by payer and service. As of January 2026, many plans must decide urgent requests within 72 hours and standard requests within seven days, but real-world timelines still run longer. Tracking each request against the payer's own deadline is how you keep them from aging.

What should a practice do when a prior authorization is denied?

Appeal it. Denials are frequently overturned on appeal, yet many are never appealed at all because the process is time-consuming (AMA, 2025). Log the denial with the payer's stated reason, request a peer-to-peer review where it applies, and reuse a standard appeal packet so a denial becomes a task, not a write-off.

Can a practice bill for the time spent on prior authorization?

Generally no. Prior authorization is unreimbursed administrative work, which is exactly why the time cost matters. Thirteen hours per physician every week is time you pay for and never bill (AMA, 2025).

Who should own prior authorization in a small practice?

One named owner per request, working a tracked process, not "whoever has time." Shared ownership is why requests disappear until the patient calls. The owner can change from one request to the next, and what can't change is that every request has exactly one.

Is prior authorization reform going to fix this on its own?

Not soon, and not evenly. Federal rules (CMS-0057-F) and state gold-carding laws are narrowing the burden for some plans, but most commercial coverage is untouched and the biggest changes land in 2027. Build the system now, and let reform make it easier, not do it for you.