CO-15 means the payer rejected the authorization number on your claim — it doesn't exist in their system, doesn't match the billed service or provider, or has expired. Unlike CO-197 (no auth obtained), an auth record usually exists. The fix is identifying the mismatch and correcting it before the timely filing window closes.
CO-15 means the authorization number on your claim is not recognized or does not apply to what was billed. The payer tried to validate the auth number against their system and it failed — either because it was typed wrong, the auth is for a different CPT code or provider, or it expired before the date of service. This is different from CO-197 (where no auth exists at all). Here, an auth usually exists but there is a disconnect between what the auth covers and what the claim says. Pull both the auth record and the claim, find the specific mismatch, and fix that specific field.
CO-15 is contractual — it must be corrected and resubmitted within the payer's timely filing window. That window runs from the original date of service, not from the denial date. If you have 90 days from DOS and the denial arrived on day 60, you have 30 days left. Act the same week the denial arrives, not at the next AR review cycle.
CO-15 looks the same on every ERA. The mismatch that caused it is not. Pull the auth record and compare it to the claim before deciding how to respond.
The auth exists and is valid, but a data entry error — transposed digits, missing character, extra space — caused the payer's system to reject it. Most common type. The payer has the auth on file; the claim just referenced it wrong.
Fix: Corrected claim with correct auth number — same dayThe auth number is valid, but it was obtained for a different procedure than what was billed. Common when a planned procedure changes after auth was obtained, or when billing staff uses a generic auth that doesn't cover the specific service rendered.
Fix: Auth amendment from UM — then resubmitThe auth was issued under one provider's NPI (e.g., the group) but the claim was submitted under a different NPI (e.g., the individual rendering provider), or the rendering provider changed after auth was obtained. Provider NPI on the claim must match the NPI on the auth record.
Fix: Auth transfer to correct provider — then resubmitA valid auth was obtained, but the service was rendered after the auth's validity period ended (typically 30–90 days from approval). Common for scheduled elective procedures or patients who reschedule beyond the auth window.
Fix: New auth or retro-auth extension — act fastCO-15 due to typos is 100% preventable. Before submission, visually confirm the auth number in Box 23 or REF*G1 matches the payer portal exactly — character by character, including leading zeros. Many billing systems truncate leading zeros or add trailing spaces. A one-field pre-submission check eliminates the most common CO-15 type entirely.
Recurring CO-15 denials on specific CPT codes or payers signal a broken auth-to-claim handoff in your workflow. A free RCM audit identifies exactly where the disconnect is occurring and what process change eliminates it.