ClinicOps / Briefings / Prior authorization
Prior Authorization · Published Aug 4, 2026
How do you stop prior authorizations from expiring before the visit?
An approved authorization that lapses before the patient is seen is the quietest way a practice loses money. The work was done. The payer said yes. And then a date passed in a folder nobody was watching.
To stop prior authorizations from expiring before the visit, put every approved auth on one list with a named owner and an expiration date, then set automatic alerts that fire 14, 7, and 2 days out and reach a second person. A two-minute weekly review confirms nothing slipped. No new software required, just a pattern your team runs every week.
Key takeaways
- An approved auth that lapses before the visit is pure lost revenue: the work was done and the payer already said yes.
- Expiry is a tracking problem, not a knowledge problem. Your team knows auths expire; the failure is that nothing is watching the date.
- The fix is four moves: one list, an owner per auth, staged alarms (14, 7, 2 days), and a two-minute weekly review.
- The alarms must reach a second human, so a single sick day cannot sink a date.
- It runs in the tools you already own (ClickUp, Monday, Asana, or a spreadsheet), chart numbers only, no protected health information.
Every practice manager knows the feeling. A prior auth comes back approved, everyone exhales, and it goes into the pile of things that are handled. Six weeks later the patient finally comes in for the MRI, and the auth window closed eleven days ago. Now it is a rework, a delay, an annoyed patient, and sometimes a write-off. Nobody did anything wrong, exactly. That is the problem. There was no system, so there was no one to blame and nothing to catch it.
This guide walks through the fix. It is not software you have to buy, and it is not a new person you have to hire. It is a small operating pattern you can build this week inside the tools you probably already own. Here is what it looks like running: every approved auth on one board, watched by the clock instead of by memory.
| Chart # | Service / CPT | Payer | Approved | Expires | Days left | Alert |
|---|---|---|---|---|---|---|
| PT-4471 | MRI, lumbar | Aetna | Jul 2 | Aug 20 | 2 | Escalate expires in 2d |
| PT-6642 | Echocardiogram | Humana | Jul 20 | Aug 24 | 6 | Owner + backup expiring in 7d |
| PT-5108 | Sleep study | Cigna | Jul 15 | Aug 30 | 12 | Owner expiring in 14d |
| PT-3320 | CT, sinus | UHC | Jul 28 | Sep 10 | 23 | On track |
| PT-2276 | PT, eval | BCBS | Jun 12 | Aug 12 | -1 | Lapsed renew or rebook |
Why approved auths still expire
An expiring auth is almost never a knowledge problem. Your team knows auths expire. It is a tracking problem, and it usually has the same three roots:
- It lives where nobody looks
The auth sits in an email, a fax, or a note in the practice-management system, but not in any list that someone reviews on purpose.
- No one owns it after approval
Getting the approval had an owner. Watching the approval did not. When an auth is nobody's job, it is everybody's blind spot.
- There is no alarm
The only thing standing between the auth and its expiry date is someone happening to remember on the right day.
Fix those three and the leak closes. An auth without an owner and a due date is not tracked. It is just stored. Here is how to actually track it.
The system, in four moves
- One list, every auth. Create a single place where every prior auth lives from the moment it is requested to the moment the service is delivered. One list, not one per provider or per payer. Each auth is a row with a handful of fields: patient (a chart number, never clinical detail), service, payer, date approved, date it expires, and status. The expiry date is the single most important field, because it is the one that costs you money when it is missing.
- An owner on every row. Every auth gets one named owner: the person responsible for making sure that service happens inside the window, or that the auth is renewed if it will not. This is not necessarily the person who filed it. It is whoever will notice.
- Alarms before the edge, not at it. This is the piece almost every practice is missing. Set automatic reminders that fire well before the expiry date: an alert to the owner at 14 days out when the service is not yet scheduled, a second alert at 7 days that also copies a backup so a single sick day cannot sink it, and a final flag at 2 days that escalates to the practice manager. The specific days matter less than the principle, that the reminder reaches a human with time to act and a second human if the first one is out.
- A weekly two-minute review. Once a week, someone opens the list sorted by expiry date and looks at the top. That is the whole ritual. Auths approaching their window get scheduled or renewed. It takes two minutes because the alarms have already done the watching; the review just confirms nothing fell through the automation.
What this looks like in your tools
In ClickUp, Monday, or Asana, this is one list or board with a due-date field set to the expiry date, an assignee per item, and native date-based automations for the 14, 7, and 2-day alerts. Documents and clinical detail stay in your practice-management system or EHR. The tracker only carries the metadata it needs to never miss a date. That separation is deliberate, and it keeps protected health information out of the project tool entirely.
The free Rescue Kit includes the prior auth tracker with follow-up and expiration alerts wired in, plus a denial log. Google Sheets, Excel, and ClickUp-ready, chart-number-only.
Get the free Rescue KitHow to know it is working
You will feel it before you can measure it, but two numbers tell the story:
- Expired-auth rework per month. This should fall to near zero within the first full cycle.
- Auths renewed on time versus let lapse. When the alarms are doing their job, renewals stop being emergencies.
If your practice does a meaningful volume of authorized services, closing this one gap often pays for the entire effort of building the system, several times over, in the first quarter. It is the front half of the full prior authorization operations system, and the fastest piece to stand up on its own.
The honest catch
None of the four moves is hard. Building them so your team actually runs them, week after week, once the initial enthusiasm fades, is the hard part. A tracker everyone abandons in a month is worse than no tracker, because it looks handled while it quietly is not. The work is in the design of the ownership and the alarms, and in the training that makes it stick. That is exactly the part most practices get wrong on their own, and exactly the part we build.
Where to go next
- Prior Authorization for Independent Practices: the complete operations guide
The seven-stage process, where each stage leaks, and the system that seals it.
- Free prior authorization tracking spreadsheet (Sheets, Excel, ClickUp)
The board from this guide, ready to download, with the expiration alarm built in.
- Prior auth takes 13 hours a week per physician. Here is the fix
What a tracked system gives back in time, per physician, every week.
- Prior authorization by the numbers (2026)
Eight sourced figures that make the case for a tracked system.
See where you stand
Two ways to start, both free.
Take the tracker and denial log and run it yourself, or book a 20-minute Leak Audit where we put a real number on what expiring auths are costing you, using your own volume. A diagnosis, not a pitch.
Frequently asked questions
Why do approved prior authorizations expire before the visit?
Because an approval has a limited validity window and usually nothing is watching the date. The auth lands in an inbox, a fax pile, or a note in the practice-management system with no single owner and no alarm, and the service gets scheduled after the window has already closed.
How far in advance should I be alerted before an auth expires?
Use staged alerts: 14 days out to the owner, 7 days out copying a second person, and 2 days out escalating to the practice manager. The exact days matter less than the principle, which is that the reminder reaches a human with time to act and a backup if the first person is out.
Do I need special software to track prior authorization expirations?
No. One list with a due-date field set to the expiration date, one assignee per row, and native date-based automations does it inside ClickUp, Monday, Asana, or a spreadsheet you already own. It is an operating pattern, not a purchase.
Is it safe to track auths outside the EHR?
Yes, if you track by chart number only. Keep patient names, dates of birth, and diagnoses in the EHR. The tracker carries only the metadata it needs to never miss a date, so no protected health information ever enters the project tool.