Prior Authorization Metrics and Your ODAG Universes: One Story or Two?
August 17, 2026
By March 31, 2026, MA organizations were required to post their first set of prior authorization metrics publicly: approval and denial percentages, overturn rates on appeal, and response times for calendar year 2025. On August 13, KFF published an analysis of those postings covering the largest insurers in Medicare Advantage, Medicaid managed care, and the ACA Marketplace, with carriers compared by name. The numbers plans chose, calculated, and posted are now research material.
Most of the commentary on the KFF piece will focus on the denial rates. For an MA compliance team, the more useful observation is structural: the publicly posted metrics and the ODAG universes a plan produces in a CMS Program Audit draw on the same underlying determination data. One is aggregated and posted on your website. The other is case-level and submitted confidentially to CMS under audit conditions. They are defined differently and they are not reconcilable row by row, but they describe the same operation, and a plan should be able to explain why its two accounts of that operation look the way they do.
Key Takeaways
- •42 CFR 422.122(c) requires MA organizations to post prior authorization metrics for the prior calendar year at the contract level by March 31 each year, excluding drugs. The first cycle, for 2025 data, is now public and being analyzed.
- •Among the large insurers KFF sampled, MA plans denied 12 percent of standard and 10 percent of expedited requests in 2025, and 67 percent of appealed standard denials were approved after appeal. These are enrollment-weighted figures for the largest carriers, not a census of all MA organizations.
- •In one organization's actual 42-contract posting, standard denial rates ran from 0.00 to 19.86 percent between its own contracts, 41 of 42 medians were reported as "0 day(s)", and every contract reported N/A for the extension metric. The contract-level spread is invisible in any carrier-level average.
- •The posted metrics and the ODAG universes rest on overlapping source determinations and operational workflows, but they differ in scope, level, and clock. Neither can be derived from the other, so the goal is a documented explanation of the differences, not a tie-out.
- •The OD record layout in the current operational protocol has no field marking whether a request was subject to prior authorization, so the population behind the posted metrics cannot be isolated within the universe.
- •CMS tightened the reporting expectations for 2027 (accessible placement, expected numerators and denominators, sub-day medians in hours), and a proposed rule would add counts and standardized denominators. Treat the annual posting as a governed data product.
What 42 CFR 422.122(c) Requires You to Post
The reporting requirement comes from the CMS Interoperability and Prior Authorization final rule (CMS-0057-F, published February 8, 2024). For Medicare Advantage it is codified at 42 CFR 422.122(c): beginning in 2026, following each calendar year in which it offers an MA plan, an MA organization must post the prior year's prior authorization data on its website at the MA contract level by March 31. Drugs, as defined at 422.119(b)(1)(v), are excluded throughout.
The required posting covers:
- •A list of all items and services that require prior authorization
- •The percentage of standard requests approved and denied, aggregated for all items and services
- •The percentage of standard requests approved after appeal
- •The percentage of requests where the review timeframe was extended and the request was approved
- •The percentage of expedited requests approved and denied
- •The average and median time from submission to determination, separately for standard and expedited requests
Numeric counts, expedited appeal outcomes, and the share of requests decided within the regulatory timeframe are optional under the current rule. Keep that word, optional, in mind. It is doing a lot of work in what follows.
What KFF Found in the Medicare Advantage Data
Two qualifications before the numbers. KFF collected postings only from insurers with at least 2.5 percent market share in each segment: 14 unique insurers overall, covering 25 million MA enrollees, about 69 percent of MA enrollment. The figures are weighted by enrollment within each segment, so they describe the large-carrier market rather than the experience of a typical regional plan, and nothing here establishes a benchmark your plan should match. For Medicare Advantage in 2025:
- •Denials: 12 percent of standard and 10 percent of expedited requests were denied. Across the six largest MA insurers, standard denial rates ranged from 5 percent to 17 percent.
- •Appeals: denials are rarely appealed, but 67 percent of denied standard requests were approved after appeal, against 47 percent in Medicaid managed care and 43 percent in the ACA Marketplace. Read this metric carefully: CMS's reporting guidance does not confine it to first-level plan reconsiderations, so it can aggregate outcomes across appeal levels, including cases resolved after review by an independent entity.
- •Response times: the median was about one day for standard requests and about 0.4 days for expedited requests, well inside the maximum timeframes.
KFF also observed that the same national carrier can post very different rates in different lines of business, and that aggregated percentages reveal nothing about which services drive denials. That combination is what makes the data awkward to use well. The numbers are public and comparable on their face, while the reasons behind them are not visible in the postings at all. KFF is careful about this, noting that case mix, service mix, and gold-carding programs can all move a denial rate without saying anything about determination quality.
What One Organization's Actual Posting Looks Like
KFF's gaps are easier to understand against a real filing. One large national MA organization published its 2025 metrics as a single document containing 42 separate contract-level reports, one per H number, which is what 422.122(c) asks for. Read across those 42 reports and the aggregate view dissolves:
- •Standard denial rates ranged from 0.00 percent to 19.86 percent across contracts belonging to the same parent organization. Expedited denials ranged from 2.79 percent to 24.73 percent among the 40 contracts that reported the figure.
- •The share approved after appeal ranged from 53.33 percent to 95.37 percent, again within one organization.
- •41 of the 42 contracts reported a median standard response time of "0 day(s)", while the corresponding means ranged from 0.86 to 3.06 days.
- •All 42 contracts reported "N/A" for the share of requests approved after the review timeframe was extended. Two also reported N/A across every expedited metric.
Three things follow, and none of them are criticisms of that organization, which appears to have reported exactly what the rule asked for.
First, the spread is the story. A single enrollment-weighted carrier number, the kind KFF had to work with, conceals a range running from effectively zero to nearly 20 percent across that carrier's own contracts. ODAG records identify the applicable contract and PBP, so contract-level variation remains operationally relevant. If you cannot explain why one of your contracts denies at several times the rate of another, that gap is worth understanding regardless of who is reading the posting.
Second, a median of "0 day(s)" is close to information-free, and the mean is doing all the work. A median of zero against a mean of 3.06 days suggests a right-skewed distribution whose upper tail is not disclosed. It does not show that any request was late, and that is the point: the published pair conceals whether the deadline was ever missed rather than revealing it. This is the defect CMS's July 2026 template addresses by requiring sub-day medians in hours rather than rounded to zero days, and you can see why the change was needed by reading a column of zeros that no plan intended as an evasion.
Third, N/A is carrying weight it cannot bear. When every contract reports N/A for the extension metric, a reader cannot distinguish "no requests were extended and approved" from "we do not track this in a reportable form." The same ambiguity applies to the contract reporting 100 percent approval and N/A for appeals, which is internally coherent but indistinguishable from missing data. This is KFF's numerator argument in concrete form, and it is why the 2026 proposed rule would require counts.
One Determination System, Two Accounts of It
Here is the part that should interest a compliance officer more than any individual rate. Your posted metrics and the ODAG universes you produce when an engagement letter arrives rest on overlapping source determinations and operational workflows: the utilization management platform, the determination-tracking workflow, the appeals system, and the delegates feeding them. The extracts themselves may well come from different warehouses, vendor feeds, or reporting layers, which is part of the problem rather than a reason to relax. In Medicare Advantage, a pre-service request for an item or service that a plan denies is generally an organization determination, and its first-level appeal is a reconsideration. The posted metrics summarize a calendar year of that activity in percentages; the OD and reconsideration universes describe an audit review period in case-level records.
Only one of those accounts is public. ODAG universes are confidential submissions to CMS, and nothing in the 2024 rule changes that. So this is not a story about outsiders performing reconciliations. It is a story about internal consistency: the same operational data now feeds a public annual disclosure and a confidential audit submission, and the two are produced by different teams on different schedules under different definitions. If those teams have never compared notes, the plan has two accounts of its own operation and no one who can explain the relationship between them.
The right posture is to treat the annual 422.122(c) posting with the same discipline as a universe submission: a documented data lineage, a defined denominator, validation before release, and one owner who can explain every number on the page a year later. That discipline pays off whether or not anyone ever asks, because the underlying extract logic is shared.
Where the Two Views Legitimately Differ
Reconciling the two views naively will produce false alarms, because they are defined differently. The differences are worth knowing precisely, both to avoid chasing phantom discrepancies and to recognize a real one.
| Dimension | Public metrics (422.122(c)) | ODAG universes |
|---|---|---|
| Audience | Posted publicly on the plan's website, annually | Confidential submission to CMS, only when an audit is engaged |
| Scope | Only requests for items and services subject to prior authorization | All organization determinations, whether or not prior authorization applied |
| Drugs | Excluded entirely (422.119(b)(1)(v)) | Part B drug determinations are in scope |
| Level | Aggregated percentages at the contract level | Case-level records with member-level detail (a single record can cover multiple requested items or services) |
| Period | Prior calendar year | The audit review period CMS specifies |
| Timeliness | Mean and median response times only | Every applicable case tested against the clock, not a sample |
| Appeals | One "approved after appeal" percentage for standard requests, not restricted to first-level plan review | Plan-level reconsiderations captured in their own table, distinct from later appeal levels |
The scope row hides the practical wrinkle we keep returning to: in the operational ODAG protocol in use today, the OD record layout has no field marking whether a request was subject to prior authorization. You cannot filter an OD universe down to the population behind your posted metrics, and neither can CMS. The practical consequence is that no row-level tie-out between the two views is possible, in either direction. What a plan can do is know how each number was built and why the definitions produce a difference.
This is also why the denominator question deserves a compliance owner rather than a reporting analyst working alone. CMS currently suggests denominators for the public metrics rather than mandating them. A plan that chose a favorable denominator for its first posting may find that choice harder to sustain, because the 2026 proposed rule would standardize the denominators insurers must use, and a materially restated rate in a later posting is itself a disclosure.
Which Clock Are You Measuring Against?
The response-time metrics carry a trap we have written about before: there are currently different clocks in play, and a median answers none of them. The 2025 data now posted was governed throughout by the 14-calendar-day standard at 422.568(b)(1). Since January 1, 2026, items and services subject to the prior authorization rules in 422.122 carry a 7-calendar-day standard under 422.568(b)(1)(ii), while everything outside that scope stays at 14 days, and the 72-hour expedited standard at 422.572(a)(1) is long-standing. The posting discussed above handles this well: it states the 14-day standard that applied before January 1, 2026 and the 7-day standard that applies after, and labels its response-time table against the 14-day clock that actually governed the year being reported. That is the right pattern to copy.
The audit layer moves on its own schedule. The ODAG protocol CMS is operating under today (form CMS-10717, OMB control number 0938-1395) still conducts its universe-level timeliness test on standard pre-service organization determinations against 14 calendar days, with 28 days where the timeframe was extended. A revision to that collection is pending: CMS submitted it to OMB on July 6, 2026, with comments due August 5, 2026, and as of this writing OMB has not concluded its review. Per CMS's own crosswalk of proposed changes, the ODAG revisions include modifying compliance standards and methods of evaluation to address regulatory changes, removing the Part C effectuations universe, and adding a universe for reopened Part C determinations. Until that revision is approved and takes effect, the operative audit standard is the one in the current protocol, and any plan reading about the newer regulatory clock should be clear about which layer it is looking at.
A median response time of one day says nothing about the tail, and the tail is where both the regulatory and the audit exposure live. The median does not reveal the upper tail or how many requests exceeded the applicable deadline. KFF makes the same point: insurers are not required to report ranges or the share of decisions made within the required timeframe. An auditor, by contrast, tests every applicable universe row against the clock. A plan that manages timeliness to its posted median is managing to the wrong number.
What the Overturn Rate Can and Cannot Tell You
The MA figure for standard denials approved after appeal, 67 percent in KFF's sample, is well above Medicaid managed care and the Marketplace. Part of the explanation is structural: in Medicare Advantage, a denial the plan upholds is automatically forwarded to an independent review entity, and HHS OIG has suggested that the prospect of automatic external review may push MA plans to look harder at denials at the first level of appeal. Because the metric is not limited to first-level plan review, some of what it counts may also reflect outcomes further along the appeal chain.
The number also has a selection problem that limits how far it can be pushed. KFF notes that denials are rarely appealed, which means the appealed cases are a self-selected minority rather than a random draw from your denials. So a high rate of reversal is not an audit of your determinations, and it does not support an inference about the denials nobody appealed.
That said, it is a signal pointed at the same thing ODAG fieldwork examines, where auditors pull denied cases, read the clinical documentation, and test whether the determination and the notification were correct and timely. KFF frames the underlying question plainly: should the initial request have been approved, or was the documentation needed to justify the service missing the first time? Reviewing your own appeal reversals by service category, delegate, and denial reason will not answer that for your whole denial population, but it is one of the few places where the answer surfaces on your schedule rather than an auditor's.
What Changes for 2027 Reporting
CMS has already responded to the first cycle's problems. In July 2026 it published an updated reporting overview and template for the 2027 reporting period: posting metrics somewhere on the website that ordinary navigation cannot reach does not count as "publicly accessible," numerators and denominators are now "expected" even though not yet required, sub-day medians must be reported in hours rather than rounded to zero days, and insurers are encouraged to disclose known data quality issues in the report itself.
Beyond that, the 2026 Interoperability Standards and Prior Authorization for Drugs proposed rule would require numeric counts for new and existing metrics, standardized denominators, and new metrics covering requests that remain denied after appeal. It would also require separate public metrics for drugs, though not for Part D plans, which already have separate coverage determination reporting. And CMS has announced a voluntary MA pilot for more detailed reporting, including service-category data, with mandatory detailed reporting signaled for the 2027 plan year.
Keep these three tracks separate, because they have different force. The July 2026 template is current CMS guidance for the next reporting cycle. The proposed rule is a proposal and may change or not be finalized. Service-category detail belongs to neither: KFF notes the proposed rule would not require metrics by service category, and that the category-level data is being pursued through a separate voluntary MA pilot, with the administration signaling an intent to make more detailed reporting mandatory for the 2027 plan year.
Even with that caveat, the direction of the required metrics is consistent: counts instead of bare percentages, and defined denominators instead of chosen ones. Both moves push public reporting toward what a universe submission already demands, and shrink the room for a posting built on an undocumented extract.
What to Do With This Now
- Check that your current posting is genuinely reachable, and fix that now. The obligation is to make the data publicly accessible, and CMS's July 2026 guidance is explicit that a page ordinary navigation cannot reach does not satisfy it. If your posting is orphaned or buried, that is a live compliance gap today, not a project for the next cycle.
- Then reread the content the way KFF read it. Are the units consistent? Would a zero or an N/A in any field be read as "none received" or "none approved"? Are sub-day medians expressed in hours? These are format and content questions for the posting due March 31, 2027.
- Document the lineage of every posted number. Source system, extract logic, denominator definition, exclusions, and the person who owns it. If the 2026 proposed rule is finalized with its numerator and denominator requirements, you will need this documented anyway, and next year's posting has to be built on the same basis as this year's or the change itself needs explaining.
- Validate the metrics extract like a universe. The determinations behind your posted rates also populate your OD and reconsideration tables. Errors in receipt dates, disposition codes, and decision time stamps can corrupt both views at once, even when the two extracts run on different platforms. This is the discipline our CMS Universe Scrubber applies to audit files, and the reporting extract deserves the same treatment: tested against a written spec, on a schedule, with findings routed to owners.
- Compare your two accounts internally. Put the posted rates next to what your determination data shows for the same calendar year, expecting differences because the scopes differ. The goal is not a tie-out, which is not possible, but a written explanation of why the two differ that someone other than its author can follow.
- Track appeal reversals as an operational signal, with its limits noted. Break them out by service category, delegate, and denial reason. Appealed cases are a self-selected minority, so treat the pattern as a lead worth investigating rather than a measurement of your denial population.
The Honest Summary
The first cycle of public prior authorization reporting did what first cycles do: it produced inconsistent, hard-to-compare data, and it put large insurers' denial behavior in the open anyway. KFF's gaps list, missing counts, ambiguous zeros, inconsistent units, undefined denominators, reads a lot like an intake review of a first universe attempt. CMS's response for the next cycle, expected numerators and denominators and hours instead of rounded days, points the same way every CMS data collection eventually goes.
For MA compliance teams the takeaway is not any single rate. It is that overlapping determination data now has to hold up in two places with different definitions and different audiences. Both the plan and CMS are positioned to see both accounts, since CMS receives the confidential universe submission and can read the public posting like anyone else. Only the plan, though, has the extract logic and internal lineage that explain why the two differ. Working that out before there is a reason to explain it is ordinary data governance rather than audit theater. For the universe side of that story, start with our guide to all 16 routine universe tables and the IDS deep dive.
Frequently Asked Questions
Which rule requires Medicare Advantage plans to post prior authorization metrics publicly?
The CMS Interoperability and Prior Authorization final rule (CMS-0057-F, published February 8, 2024). For Medicare Advantage the requirement is codified at 42 CFR 422.122(c): beginning in 2026, an MA organization must post specified prior authorization data from the previous calendar year on its website at the MA contract level by March 31, excluding drugs. The first postings, covering calendar year 2025, were due March 31, 2026.
Do the publicly reported prior authorization metrics include drug data?
No. 42 CFR 422.122(c) excludes drugs as defined at 422.119(b)(1)(v), so the posted metrics cover medical items and services only. Part D coverage determinations have their own separate reporting requirements. A 2026 CMS proposed rule would add separate public prior authorization metrics for drugs, but as proposed that requirement would not apply to Part D plans.
Can prior authorization metrics be calculated directly from an ODAG universe?
No. The public metrics cover only requests for items and services subject to prior authorization, while the OD universe captures all organization determinations, and the OD record layout in the operational protocol has no field identifying which rows were subject to prior authorization. The two rest on overlapping source determinations, but neither can be derived from the other. Note also that ODAG universes are confidential audit submissions, so this is a question of internal consistency rather than public comparison.
What changes are coming to prior authorization reporting for 2027?
Three separate tracks, with different force. First, CMS published an updated reporting overview and template in July 2026: metrics must be genuinely publicly accessible, numerators and denominators are expected though not required, and sub-day median response times must be reported in hours rather than rounded to zero days. Second, a 2026 proposed rule would require numeric counts, standardized denominators, and metrics on requests that remain denied after appeal; as a proposal it may change before it is finalized. Third, service-category detail is not in either the template or the proposed rule. It is being pursued through a separate voluntary Medicare Advantage pilot, with the administration signaling an intent to require more detailed reporting for the 2027 plan year.
One Data Spine for Universes and Reporting
The determinations behind your public metrics are the ones CMS will test in an audit. See how 1,600+ validation rules keep that data defensible in both places.