CO Contractual Obligation · CARC Code 15
CO-15

Invalid or Non-Applicable Authorization Number

CO-15 means the payer rejected the authorization number on your claim — it doesn't exist in their system, doesn't match the billed service or provider, or has expired. Unlike CO-197 (no auth obtained), an auth record usually exists. The fix is identifying the mismatch and correcting it before the timely filing window closes.

Updated August 2026 · Group code: CO (provider write-off if not fixed) · Root cause: auth number mismatch or data entry error · Fix: corrected claim or auth amendment
4 typesDifferent Root Cause for Each
Often same-dayFix for Simple Typo Cases
Box 23Auth Number Field on CMS-1500
REF*G1Auth Number Segment on 837P
CO-15 in plain English

CO-15 means the authorization number on your claim is not recognized or does not apply to what was billed. The payer tried to validate the auth number against their system and it failed — either because it was typed wrong, the auth is for a different CPT code or provider, or it expired before the date of service. This is different from CO-197 (where no auth exists at all). Here, an auth usually exists but there is a disconnect between what the auth covers and what the claim says. Pull both the auth record and the claim, find the specific mismatch, and fix that specific field.

⚠️
Check the timely filing clock before anything else

CO-15 is contractual — it must be corrected and resubmitted within the payer's timely filing window. That window runs from the original date of service, not from the denial date. If you have 90 days from DOS and the denial arrived on day 60, you have 30 days left. Act the same week the denial arrives, not at the next AR review cycle.

Identify the mismatch — the fix is different for each type

CO-15 looks the same on every ERA. The mismatch that caused it is not. Pull the auth record and compare it to the claim before deciding how to respond.

1

Auth number entered incorrectly (typo)

The auth exists and is valid, but a data entry error — transposed digits, missing character, extra space — caused the payer's system to reject it. Most common type. The payer has the auth on file; the claim just referenced it wrong.

Fix: Corrected claim with correct auth number — same day
2

Auth is for a different CPT code or service

The auth number is valid, but it was obtained for a different procedure than what was billed. Common when a planned procedure changes after auth was obtained, or when billing staff uses a generic auth that doesn't cover the specific service rendered.

Fix: Auth amendment from UM — then resubmit
3

Auth is for a different rendering or billing provider

The auth was issued under one provider's NPI (e.g., the group) but the claim was submitted under a different NPI (e.g., the individual rendering provider), or the rendering provider changed after auth was obtained. Provider NPI on the claim must match the NPI on the auth record.

Fix: Auth transfer to correct provider — then resubmit
4

Auth expired before the date of service

A valid auth was obtained, but the service was rendered after the auth's validity period ended (typically 30–90 days from approval). Common for scheduled elective procedures or patients who reschedule beyond the auth window.

Fix: New auth or retro-auth extension — act fast

What to do when you receive CO-15

  1. Pull the auth record and the claim — compare every field
    Open the prior authorization record in your tracking system or payer portal. Place it next to the claim. Compare field by field: auth number (exact character match), CPT/HCPCS codes, rendering provider NPI, billing provider NPI, facility NPI, effective date range, and approved units. The first field that doesn't match is your root cause.
  2. Type 1 (typo): correct the auth number and resubmit
    If the auth number on the claim doesn't match the one in the auth record, correct it in Box 23 (CMS-1500) or REF*G1 (837P). Resubmit as a corrected claim (frequency code 7 on CMS-1500 / CLM05-3 = 7 on 837P). Add a brief note: "Corrected claim — auth number corrected per payer auth portal. Auth on file under member [ID], reference [auth number]."
  3. Type 2 (wrong service): call UM for an auth amendment
    Contact the payer's Utilization Management department. Explain the mismatch: "We have auth [number] for CPT [X] but the service rendered was CPT [Y] per the clinical record." Request an amendment to update the auth to the correct CPT code. Once UM confirms the amendment in writing or via portal, resubmit the claim with a note referencing the amended auth.
  4. Type 3 (wrong provider NPI): request auth transfer and resubmit
    Contact UM and request that the authorization be transferred to or reissued under the correct rendering/billing provider NPI. Provide both NPIs. Once UM confirms the transfer, correct the NPI on the claim and resubmit. Verify that the provider is in-network for the patient's plan — the NPI on the auth and the claim must match the contracted provider.
  5. Type 4 (expired auth): obtain a new auth or request a retro-extension
    Contact UM immediately. Ask if a retro-authorization extension is available — some payers will extend an expired auth if the service was scheduled within the original auth window but delayed. If not, obtain a new authorization. Note: an expired auth that generates CO-15 may also be worked as a CO-197 appeal if the expiration was caused by payer or scheduling delays outside the provider's control.
💡
Always verify the auth number character by character before submitting

CO-15 due to typos is 100% preventable. Before submission, visually confirm the auth number in Box 23 or REF*G1 matches the payer portal exactly — character by character, including leading zeros. Many billing systems truncate leading zeros or add trailing spaces. A one-field pre-submission check eliminates the most common CO-15 type entirely.

How to prevent CO-15

  • Verify the auth number character by character before every submission. A pre-submission audit step that compares Box 23 / REF*G1 to the payer portal auth record eliminates typo-based CO-15. This is a 30-second check per claim that prevents a 30-day rework cycle.
  • When a procedure changes after auth is obtained, require a new auth review before scheduling. Any change to the planned CPT code triggers an auth check. Build this as a hard stop in your scheduling or charge-entry workflow — a code change that isn't reflected in the auth record is a pending CO-15.
  • Track auth expiration dates in your scheduling system. When an auth is obtained, log the expiration date. Flag any appointment within 14 days of auth expiration for a renewal call before the visit date. Expired-auth CO-15 is entirely preventable with a proactive tracking system.
  • Standardize which NPI (group vs. individual) is used on auth requests. Decide at the practice level whether auths are requested under the group billing NPI or individual rendering provider NPI, and apply that consistently. Inconsistency between how auths are obtained and how claims are submitted is the primary cause of Type 3 CO-15.
  • Run a CO-15 denial report monthly by service type and payer. A spike in CO-15 on a specific code-payer combination reveals a systemic auth workflow gap. Address the process, not just the individual claims.

Frequently Asked Questions: CO-15

CO-15 means the authorization number submitted on the claim is not valid — it was rejected by the payer because it contains a typo, doesn't match the billed service or provider, or has expired. An authorization record usually exists; the issue is a disconnect between the auth on file and the information on the claim. It is almost always fixable with a corrected claim (for typos) or an authorization amendment (for service or provider mismatches).
CO-197 means no prior authorization was obtained at all before the service. CO-15 means an authorization was obtained and an auth number was submitted, but that number failed the payer's validation — due to a typo, service mismatch, provider mismatch, or expiration. CO-197 requires obtaining retro-authorization or filing an appeal. CO-15 usually requires a corrected claim with the right auth number or a call to UM for an amendment. CO-15 is generally faster to resolve than CO-197 because the underlying auth approval already exists.
Box 23 on the CMS-1500 is the prior authorization/referral number field. On an electronic 837P transaction, it maps to the REF*G1 segment in Loop 2300 (Claim Information). Some payers require it in an NM1 loop or a different qualifier — always verify the payer's specific billing manual. A common cause of CO-15 is a system that defaults the auth number to the wrong field or truncates it during electronic conversion.
CO-15 is better resolved as a corrected claim than as a formal appeal, in most cases. If the issue was a typo or a simple mismatch, a corrected claim with the correct auth number resolves faster than an appeal. Use the formal appeal process when the payer claims the auth doesn't exist but you have documentation it was approved — attach the auth approval confirmation (portal screenshot, approval letter, or UM call reference number) to the appeal. For expired auth situations, contact UM first before filing an appeal.

Denial codes commonly seen with CO-15

Seeing CO-15 repeatedly on the same service type?

Recurring CO-15 denials on specific CPT codes or payers signal a broken auth-to-claim handoff in your workflow. A free RCM audit identifies exactly where the disconnect is occurring and what process change eliminates it.