Skip to main content
The Practice
Billing operationsAugust 16, 2026

The Authorization Queue: Catch the Lapse Before the Visit Happens

Authorization lapses are discovered in billing but caused in scheduling — the thirteenth visit gets booked against a twelve-visit approval weeks before any denial arrives. This article rebuilds prior authorization as a tracked queue with six states, two ceilings per authorization, and a renewal trigger calculated from your visit frequency and the payer’s decision clock.

Callie Editorial 20 min read
The lapse issue
Two ceilings

Action required

Denial recovery queue

01 · Classify

Eligibility, coding, documentation

02 · Correct

Fix the root record

03 · Respond

Resubmit or appeal on time

Reason → owner → deadline → evidence → outcome

At a glance

What you’ll leave with

  • An authorization lapse is a scheduling failure that billing discovers later. The denial arrives weeks after the unauthorized visit was delivered, so fixing the problem where it surfaces — in billing — is always too late. The fix lives where the failure happens: the scheduler must know every patient’s remaining approved visits and end date at booking time.
  • Every authorization has two ceilings, and either one can end it: the approved visit count and the expiration date. Track both, because a patient attending twice a week exhausts a visit count long before a ninety-day window closes, while a patient attending sporadically hits the date first. The queue watches whichever ceiling is closer.
  • Renewal timing is arithmetic, not vigilance. Submit when remaining approved visits fall to your weekly visit frequency multiplied by the payer’s decision time in weeks, plus a buffer — for many government-regulated plans, that decision clock is now bounded by federal rule at seven calendar days for standard requests starting in 2026. A practice that calculates the trigger per patient stops depending on someone remembering to check.

The denial code says the authorization lapsed, and it lands on the biller’s desk. But rewind the tape: the lapse did not happen in billing, and it did not happen this week. It happened three weeks ago, at the front desk, in the four seconds it took to book a thirteenth visit against a twelve-visit approval — or to schedule into the week after an authorization’s end date. Everyone did their job. The therapist treated, the front desk scheduled the standing slot, the biller submitted a clean claim. The system failed because no part of it was watching the two numbers that decide whether a visit is payable before it happens: visits remaining and days remaining. This article rebuilds prior authorization as what it operationally is — a scheduling constraint managed as a tracked queue — so the practice finds out about a problem while it can still be fixed with a fax instead of a write-off.

The reframe

Why an authorization lapse is a scheduling failure

Follow the timeline of a typical lapse and the misdiagnosis becomes obvious. Day one: a payer approves twelve visits over ninety days. Week six: visit twelve happens, unremarked, because nobody’s workflow surfaces a running count at booking or check-in. Weeks seven and eight: visits thirteen and fourteen happen — delivered in good faith, documented, and unbillable. Week ten: the remittance arrives and billing discovers the problem, files for a retroactive authorization if the payer allows one, and starts an appeal if it does not. The practice experiences this as a billing problem because billing is where it surfaces. But billing is the smoke detector, not the fire. The fire is a schedule that will happily book a patient past either of their authorization’s two ceilings, because the person booking cannot see them.

The misdiagnosis matters because it decides where practices invest. Treat lapses as a billing problem and the fixes are downstream: faster appeals, retro-auth request templates, a spreadsheet the biller reconciles after claims bounce. All of that is cleanup. Treat lapses as a scheduling problem and the fix moves upstream to the only place it prevents anything: the moment of booking, and the daily check of what is already booked. A practice that cannot answer “how many approved visits does this patient have left, and when does the window close?” at the front desk — in the scheduler, not in a binder — does not have an authorization process. It has an authorization archive.

The landscape

Who actually requires prior authorization for therapy

Prior authorization is a payer-by-payer fact, not a category-wide one, and the pattern surprises people who are new to running a caseload. Original Medicare Part B generally does not require prior authorization for outpatient therapy services: it manages utilization after the fact, through the annual threshold amounts — above which the KX modifier attests continued medical necessity — and a targeted medical review process at a higher threshold. Medicare Advantage plans, by contrast, are run by private insurers and frequently do require prior authorization for the very same services, a distinction that catches practices when a patient switches from one to the other. In recent years large national carriers have expanded authorization requirements for outpatient therapy under their Medicare Advantage products, a shift ASHA and APTA have both tracked and pushed back on. Commercial plans and Medicaid managed-care organizations sit across the whole spectrum: some authorize episodes generously after an evaluation, some cap tightly and demand renewal paperwork every handful of visits, and a few require nothing at all.

The operational consequence: whether authorization is required is itself a data point your intake and verification step must capture per patient, per plan — not something anyone should assume from the payer’s name. A practice’s authorization queue therefore starts at eligibility verification, where “does this plan require prior auth for these codes, and what are its renewal rules?” gets asked and the answer gets written down where scheduling can see it.

The centerpiece

The queue: six states every authorization moves through

A queue is not a spreadsheet that lists authorizations. It is a discipline: every authorization is always in exactly one state, every state has an owner and an exit condition, and the queue gets reviewed on a schedule rather than when something breaks. Six states cover the whole life of an authorization. Run them in whatever tool you have — a capable EHR tracks most of this natively, and a shared sheet can carry a small practice — as long as the states, owners, and triggers are explicit.

  1. 01

    Flag at verification

    During eligibility verification, before the first visit, determine whether this plan requires prior authorization for the services you expect to deliver — evaluation and treatment codes separately, since plans often treat them differently. Record the answer either way: “no auth required” written down is what keeps someone from re-litigating the question at claim time. If authorization is required, the patient enters the queue in this state until the request goes out.

  2. 02

    Submit and log

    Send the request the way this payer requires — portal, form, fax — and log four things the moment it leaves: the date, the channel, the payer’s reference or case number, and exactly what was requested (codes, visit count, date span). The reference number is what turns every future phone call from an argument into a lookup. An authorization request that is not logged is, operationally, a request that was never sent.

  3. 03

    Chase while pending

    Every pending request gets a follow-up date the day it is submitted, calibrated to this payer’s decision clock — for Medicare Advantage, Medicaid, and CHIP plans, federal rule caps standard decisions at seven calendar days and expedited ones at seventy-two hours beginning in 2026, which tells you exactly when silence has become a problem worth a phone call. Chasing is a scheduled activity, not a reaction to a patient sitting in the waiting room without an approval.

  4. 04

    Activate with both ceilings visible

    When the approval arrives, transcribe it into the scheduler — not just the chart. The approved visit count, the start date, and the end date must be visible, or better, enforced, at the point of booking. This is the step most practices skip: the approval gets filed as a document instead of installed as a constraint, and from that moment the front desk is booking blind.

  5. 05

    Track the burn

    Each completed visit decrements the count; the queue always shows visits used, visits remaining, and days remaining for every active authorization. This is also where the renewal trigger lives: a per-patient threshold — calculated, not guessed, from visit frequency and the payer’s decision time — that flips the authorization into renewal the moment it is crossed. The arithmetic is in the next section.

  6. 06

    Renew or close

    Crossing the trigger starts the renewal: updated progress documentation, the request, and a new cycle through pending and active. If the episode is ending instead, close the authorization with a disposition — completed, discharged, moved to a new plan year — so the queue only ever contains live constraints. A queue full of dead rows stops being read, and a queue that stops being read is a binder.

The mechanics

Two ceilings, one trigger: the arithmetic of never lapsing

Every authorization ends in one of two ways, and your tracking has to watch both. The visit-count ceiling falls first for frequent attenders: a patient seen twice weekly consumes a twelve-visit approval in six weeks, however long the paper window runs. The date ceiling falls first for sporadic attenders: a patient who reschedules often can reach a ninety-day end date with visits still unused — and those visits do not roll over. The queue’s job is to project, for each patient, which ceiling arrives first at their actual attendance rate, and to start the renewal far enough ahead of that ceiling that the payer’s decision clock runs out before the visits do.

That lead time is arithmetic. Take the patient’s real visits per week — from attendance, not from the plan of care — multiply by the payer’s decision time in weeks, and add a buffer for gathering documentation and for the payer asking questions. The result is the renewal trigger, expressed in visits remaining: submit when the count falls to that number. A twice-weekly patient with a payer that decides in a week needs the renewal moving at roughly four to five visits remaining — two visits that will happen while the payer deliberates, plus buffer. The same patient with a payer that routinely takes three weeks needs the trigger at eight or nine. Set the trigger per authorization, write it into the tracker as a number, and the question “should we start the renewal?” stops requiring judgment at all.

Copy this

The authorization tracker: one row per authorization

Ten fields, whether the tracker lives in your EHR or a shared sheet. If your system cannot show the starred fields at booking time, that gap — not staff diligence — is where your next lapse comes from.

01

Patient + plan: name, payer, plan type (commercial / MA / Medicaid MCO), member ID

02

Auth reference #: the payer’s case number, from the submission log

03

Scope: CPT codes covered, and whether evaluation and treatment are authorized separately

04

Window: start date → end date *

05

Visits authorized: the approved count *

06

Visits used: decremented at each completed visit *

07

Visits remaining: authorized minus used — visible at booking *

08

Renewal trigger: “submit renewal at ___ visits remaining” (visits/week × payer decision weeks + buffer)

09

State: verification / submitted / pending / active / renewal / closed — with one owner’s name

10

Next action + date: what happens next and when, never blank while the authorization is live

Worked example

The trigger in practice: one patient, two ceilings, zero drama

Fictional case

Twenty visits, ninety days, and a renewal that starts itself

Every detail here is invented to show the arithmetic. Your payer’s decision times, renewal documentation requirements, and retroactive-authorization rules come from your contract and current payer policy — not from this example.

The approval

A pediatric SLP’s new patient is approved by a Medicaid managed-care plan for twenty treatment visits across a ninety-day window beginning March 2. The plan of care calls for two visits per week. At activation, the front desk enters both ceilings into the scheduler — 20 visits, ends May 31 — and the tracker row gets its trigger: this payer has been deciding standard renewals in about a week, so 2 visits/week × 1 week = 2 in-flight visits, plus a 3-visit buffer for pulling progress documentation and surviving a records request. Trigger: submit renewal at 5 visits remaining.

Which ceiling comes first

At the plan-of-care rate, twenty visits would take ten weeks — the visit count would run out around May 11, three weeks before the date ceiling. But the family reschedules two visits in April, so the projection shifts as the burn rate does: by late April the tracker shows 14 used, 6 remaining, and a realistic pace of about 1.8 visits per week. The visit ceiling is still arriving first. Nobody had to notice any of this; the tracker is doing the noticing.

The trigger fires

On May 4, visit fifteen completes and the count hits 5 remaining — the trigger. The queue flips the authorization into renewal, and the owner submits the request the next morning with updated progress data, logging date, channel, and the new case number. The five remaining visits cover the two weeks the payer takes to answer. The approval for the next episode arrives May 13, with 3 visits still unused on the old authorization. The new window is entered at activation, and the cycle restarts.

The counterfactual

Without the trigger, this story has a familiar second ending: visit twenty happens in early June — past May 31, as it turns out, because the April reschedules pushed the tail of the episode over the date ceiling — and two more visits happen while everyone assumes the renewal “must have gone through.” Three unbillable sessions surface on a remittance in July. The difference between the two endings was not effort or attentiveness. It was a number in a tracker that someone calculated once, in March.

The rules

Payer decision clocks are tightening — build the queue around them

The renewal trigger depends on knowing how long a payer takes to decide, and for a large class of plans that number is now bounded by federal rule rather than by habit. The CMS Interoperability and Prior Authorization final rule (CMS-0057-F, finalized January 2024) requires the payers it covers — Medicare Advantage plans, state Medicaid and CHIP programs, and Medicaid and CHIP managed-care plans — to answer standard prior authorization requests within seven calendar days and expedited requests within seventy-two hours, generally beginning January 1, 2026. The same rule requires those payers to give a specific reason when they deny a request, and to publicly report their authorization metrics — approval, denial, and appeal-overturn rates among them — with the first reporting due by March 31, 2026. Commercial plans outside the rule set their own clocks, subject to state law and accreditation standards, which is why the tracker records a decision time per payer instead of assuming one.

7 days

Standard decision ceiling

Maximum for standard prior auth decisions under CMS-0057-F for Medicare Advantage, Medicaid, and CHIP plans, generally from January 1, 2026.

72 hours

Expedited decision ceiling

Maximum for expedited requests under the same rule — the clock your urgent cases should be measured against.

Mar 31, 2026

First public metrics

Deadline for impacted payers’ first public reporting of prior authorization approval, denial, and appeal metrics under CMS-0057-F.

These ceilings are useful to a practice in two concrete ways. First, they calibrate the follow-up date in the pending state: for an in-scope plan, a standard request with no answer on day eight is not “still processing” — it is late, and the call you make can say so. Second, the published metrics give you, for the first time, payer-level denial and overturn rates to consult when deciding which panels are worth the administrative load their authorization behavior imposes.

When it fails

Denied anyway? The record you kept is the appeal

A well-run queue does not prevent denials; it prevents surprises. When a denial does come, the default should be to look hard at appealing rather than writing off, because the evidence says payer prior-authorization denials are wrong often enough to matter. When the HHS Office of Inspector General reviewed a stratified random sample of prior authorization denials issued by fifteen of the largest Medicare Advantage organizations during one week of June 2019, it found that 13 percent of the denied requests met Medicare coverage rules — services that likely would have been approved under original Medicare. A common cause was plans applying clinical criteria beyond what Medicare coverage rules contain. That is one program, one sample week, and one line of evidence — but it is the federal watchdog’s own arithmetic, and it argues against treating any single denial as final.

The appeal itself is mostly assembled from things the queue already holds: the reference number and submission log from the pending state, the exact scope requested, the progress documentation that supported the renewal, and — under CMS-0057-F, for in-scope plans — the payer’s specific stated reason for the denial, which tells you precisely what the appeal must rebut. Practices that lose appeals usually lose them for missing paperwork and blown deadlines, not weak clinical cases. The queue is what makes the paperwork exist and the deadlines visible.

Ownership

One owner, one daily glance, one weekly review

Queues fail socially before they fail technically: a tracker that belongs to everyone is updated by no one. Give the queue a single named owner — in a small practice usually the person who runs verification and scheduling, precisely because the queue is a scheduling instrument. The owner’s daily interaction is a glance, not a project: anything pending past its follow-up date, anything that crossed its renewal trigger, anything expiring inside the next two weeks. Ten minutes. The weekly review is the deeper pass, and it is short enough to survive contact with a real week:

Field checklist

06 items

The weekly authorization review

  • Every active authorization: visits remaining and days remaining both above their trigger lines — anything below is already in motion, with a next action and date filled in.
  • Every pending request: within the payer’s decision window, or chased today with the call logged against the reference number.
  • Every patient on the schedule next week: covered by an active authorization through their booked dates, or flagged to scheduling now — this single check is the one that prevents the classic lapse.
  • Every new evaluation completed this week: verification answered the authorization question, and treatment requests submitted where required.
  • Every closed authorization: marked with its disposition so the queue holds only live constraints.
  • One metric written down: lapsed-visit count this week. The queue is working when that number is a string of zeros — and the streak’s end is a process question, not a person question.

Billing discovers the lapse; scheduling causes it. Put the tracking where the cause lives, and the discovery never happens.

Does Medicare require prior authorization for outpatient therapy?

Original Medicare Part B generally does not require prior authorization for outpatient PT, OT, or speech-language pathology services. It manages utilization after delivery instead: above an annual threshold amount, claims carry the KX modifier as an attestation of continued medical necessity, and a targeted medical review process applies at a higher threshold. Medicare Advantage plans are different — they are administered by private insurers and frequently do require prior authorization for the same services, with rules that vary by plan and year. Verify per plan, and re-verify when a patient’s coverage changes.

How long does prior authorization take for therapy services?

It depends on the payer, which is why your tracker should record a decision time for each one. For Medicare Advantage, Medicaid, and CHIP plans covered by the CMS Interoperability and Prior Authorization final rule (CMS-0057-F), federal ceilings generally apply beginning January 1, 2026: seven calendar days for standard requests and seventy-two hours for expedited ones. Commercial plans set their own timelines under state law and accreditation standards. Whatever the clock is, log the submission date and set a follow-up date the same day — a request with no answer past the payer’s window is late, not pending.

When should we submit an authorization renewal request?

When remaining approved visits fall to a calculated trigger, not when someone happens to notice the count is low. Compute the trigger per authorization: the patient’s actual visits per week, times the payer’s decision time in weeks, plus a buffer of two to three visits for assembling documentation and absorbing payer questions. A twice-weekly patient with a seven-day payer needs the renewal moving at about four to five visits remaining. Write the trigger into the tracker as a number so starting the renewal is mechanical.

What happens if we treat a patient after the authorization expired?

The payer can deny the claims, and recovering payment depends on rules that vary widely: some payers allow retroactive authorization requests within a set window, some permit appeals with documentation of medical necessity, and some pay nothing outside an active authorization. Whether you may bill the patient instead typically depends on your contract and on notice requirements — often you cannot, or can only with advance written notice the patient agreed to. All of those are payer-specific questions to verify. Operationally, the answer is upstream: the weekly check that every booked visit is covered by an active authorization is what keeps you out of this situation.

Who should manage prior authorizations in a small practice?

One named owner, and preferably someone positioned in scheduling and verification rather than in billing — because the decisions an authorization governs happen at booking, not at claim submission. In many small practices this is the front-desk or intake coordinator, with the biller consulted on denials and appeals. What matters more than the title is the structure: a single queue, one owner, a ten-minute daily glance for triggers and overdue follow-ups, and a short weekly review that includes checking next week’s schedule against active authorizations.

Is it worth appealing a prior authorization denial?

Often, yes — look hard at every denial before writing it off. When the HHS Office of Inspector General sampled prior authorization denials issued by fifteen large Medicare Advantage organizations during one week in 2019, it found 13 percent met Medicare coverage rules, frequently because plans applied clinical criteria beyond what Medicare requires. Appeals are largely won on complete paperwork and met deadlines: the submission log, reference numbers, requested scope, progress documentation, and — for plans covered by CMS-0057-F — the payer’s specific stated denial reason, which tells you exactly what your appeal needs to rebut.

Primary sources

Bibliography / 6
  1. 01CMS Interoperability and Prior Authorization Final Rule (CMS-0057-F) — fact sheetCenters for Medicare & Medicaid Services
  2. 02Some Medicare Advantage Organization Denials of Prior Authorization Requests Raise Concerns About Beneficiary Access to Medically Necessary Care (OEI-09-18-00260)HHS Office of Inspector General
  3. 03Medicare Part B Review Process for Therapy ClaimsAmerican Speech-Language-Hearing Association
  4. 04Medicare Payment Thresholds for Outpatient Therapy ServicesAmerican Physical Therapy Association
  5. 05UnitedHealthcare Announces Broad Prior Authorization Requirements for Therapy and Chiropractic Services Under Its Medicare Advantage PlansAmerican Speech-Language-Hearing Association
  6. 06APTA, Provider and Patient Groups Push Major Reforms to Prior AuthorizationAmerican Physical Therapy Association

Written by Callie Editorial

Published August 16, 2026

Educational content, not legal, billing, or patient-specific clinical advice.