COContractual Obligation · CARC Code 170
CO-170

Payment Adjusted Because Pre-certification/Authorization Was Not Obtained

CO-170 is a prior authorization denial — the payer required advance approval for this service, and none was on file when the claim was adjudicated. Act immediately: most payers have a retro-auth window that closes within 30–60 days of the date of service. After that window, your only option is a formal appeal.

Updated July 2026·Group: CO (write-off unless retro-auth obtained or appeal won)·Urgency: Act within 72 hours — retro-auth windows close fast
72 hrsEmergency Retro-Auth Window (Most Payers)
30–60 daysNon-Emergency Retro-Auth Window
≠ CO-15CO-170 = No Auth; CO-15 = Auth Doesn't Match
EmergencyServices Cannot Be Retroactively Denied (Federal Law)
CO-170 in plain English

CO-170 means the payer required prior authorization for this service and didn't have one on file. Act immediately — call the payer's retro-auth line today, not next week. For emergency services, federal law generally protects you: a prudent layperson standard applies and payers cannot retroactively deny emergency care. For non-emergency services, you have a limited window to request retro-auth before your only option becomes a formal appeal.

Time is the most critical factor in CO-170 — the retro-auth window closes fast

Retro-authorization windows are fixed and non-extendable in most payer contracts. For emergency/urgent services: typically 24–72 hours from time of service, sometimes up to 30 days. For non-emergency services: typically 30–60 days from date of service. After the window closes, the claim goes to formal appeal — a longer, less reliable process with lower success rates. When you receive a CO-170, call the payer's retro-auth department the same day.

The two most common prior-auth denial codes — completely different fixes

CO-170 — No Auth at All

  • Prior authorization was not obtained before the service was rendered
  • The payer has no auth on file for this claim
  • Fix path 1: call retro-auth department, request retroactive authorization
  • Fix path 2 (emergency): appeal citing prudent layperson standard and federal emergency care law
  • Fix path 3 (if retro-auth window closed): formal claim appeal with full clinical documentation
  • Prevention: add this procedure to your prior-auth required list; check before next scheduling

CO-15 — Auth Exists but Doesn't Match

  • An authorization was obtained, but it doesn't match the claim as billed
  • Mismatch: wrong date of service, wrong CPT code, wrong facility, wrong rendering provider, or wrong place of service
  • Fix: call auth department and ask to amend the authorization to match the service rendered
  • Or: resubmit the claim with the correct auth number that covers what was actually billed
  • No retro-auth process needed — the auth exists, it just needs correction
  • Prevention: verify all four auth parameters match before DOS: date range, code, facility, provider

8 scenarios that generate CO-170 — and the right action for each

ScenarioWhy the Auth Was MissingActionWhat to Do
Auth not requested — staff didn't know this procedure required it Payer auth requirements change quarterly. A procedure that didn't require auth last year may require it now. Staff relied on outdated knowledge or didn't check the payer's current auth list. Retro-Auth Call retro-auth line immediately. Submit clinical documentation package. Update your payer-specific auth-required list for this procedure going forward.
Patient presented as emergency — no time for prospective auth Emergent presentation required immediate treatment. Federal law (ACA, EMTALA) and most state laws prohibit requiring prior authorization for emergency services. Emergency Override Appeal citing the prudent layperson standard and the patient's presenting symptoms. Attach the emergency documentation: chief complaint, vital signs, physician determination of emergency status. Federal law protects this scenario.
Auth obtained for wrong CPT code The auth was requested using a different procedure code than what was ultimately performed (e.g., auth for 27447 but performed 27446, or auth for initial consult but follow-up was billed). Retro-Auth Amendment Call auth department, explain the code discrepancy, and request an auth amendment to cover the correct CPT. This is closer to CO-15 territory — the auth exists but was for a different code.
Auth obtained for different date of service Auth was approved for a specific DOS range, and the service was rendered outside that window — patient rescheduled, procedure was delayed, or billing used the wrong date. Retro-Auth or Appeal If within retro-auth window: request retro-auth for the actual DOS. If the DOS is correct and the auth had the wrong date range, contact auth department to amend. If window closed: appeal with documentation showing clinical continuity.
Patient transferred to out-of-network facility — auth not transferred Auth obtained for in-network facility; patient was transferred to OON hospital for level of care. The auth doesn't follow the patient across network boundaries in most payer systems. Appeal Appeal citing continuity of care, lack of available in-network alternatives, and the clinical necessity of the transfer. If the transfer was emergent, the emergency care federal protection applies.
Auth obtained under wrong insurance plan — patient had a plan change Patient changed plans mid-auth process. Auth approved under old plan doesn't carry to new plan. Common with Medicaid managed care plan changes or employer open enrollment switching. New Retro-Auth Verify correct plan at time of service. Request new retro-auth under the current plan. This is also a registration issue — update patient insurance verification workflow to catch mid-care plan changes.
Auth approved but number not documented — claim submitted without it Authorization was actually obtained and is on file, but the auth number was not entered into the claim. The payer's system sees no auth number and generates CO-170. Claim Correction Locate the auth number in your system (usually in the patient's account notes or PM system). Submit a corrected claim with the auth number in box 23 (CMS-1500) or the appropriate loop/segment (837P: loop 2300, REF*G1). No retro-auth needed — auth exists.
Payer added auth requirement mid-authorization process Payer updated their auth-required list after the appointment was scheduled but before the service was rendered, creating a gap where neither the provider nor the patient could have known in advance. Appeal Appeal citing the payer's retroactive imposition of a requirement that wasn't in force when the appointment was scheduled. Document when the appointment was booked vs. when the payer's auth requirement took effect. Many state insurance departments consider this an unfair claims practice.

How long you have to request retroactive authorization

Emergency / Urgent
24–72 hrs
From time of service. Most payers require notification within 24–48 hours of an emergency admission. Federal law generally requires coverage regardless of notification for true emergencies.
Medicare Advantage
30 days
CMS requires MA plans to allow retro-auth requests up to 30 days post-service for non-emergency services. Some plans are more generous.
Commercial / BCBS
30–60 days
Most commercial plans allow 30–60 days from DOS. BCBS varies by plan (Federal vs. state plans differ). Always call to confirm the specific plan's window.
Aetna / UHC / Cigna
30–45 days
Major national commercial plans typically allow 30–45 days. Check the specific plan's provider manual for the exact window — exceptions apply for urgent cases.
Medicaid MCO
Varies by state
Medicaid managed care retro-auth windows are state-specified. Some states require same-day notification for inpatient; others allow 10–30 days. Check the specific MCO's provider operations manual.
TRICARE
30 days
TRICARE allows retro-auth requests within 30 days of an emergent or urgent service. Routine services require prospective auth with no retro pathway.
📋
Always call to confirm — payer windows change and plan-level rules override general timelines

The windows above are general guidelines. Individual plan contracts can set shorter or longer windows. The safest approach: when you receive a CO-170, call the payer's retro-auth line the same day and ask for the specific window for this plan. Document the call: date, representative name, reference number, and the window they gave you.

What to do when you see CO-170 on a remittance

  1. Verify first: was auth actually obtained but just not submitted?
    Check the patient's account in your PM system for a documented auth number. Check the claim file — was Box 23 (CMS-1500) populated? Was the 837P Loop 2300 REF*G1 segment included? If an auth number exists but wasn't on the claim, submit a corrected claim with the auth number. This resolves the denial without retro-auth. Only proceed to retro-auth if no auth number exists anywhere in the patient's record for this DOS.
  2. Call the payer's retro-auth line today — confirm the window and start the process
    Call the retro-auth department (not the general claims line) and ask: (1) Does this plan have a retro-auth process for this service type? (2) What is the submission deadline from the DOS? (3) What clinical documentation is required? (4) Is there a case reference number for this request? Document the call completely. Some payers start a retro-auth case during this call; others require a written submission. Get the fax number and address for the retro-auth department.
  3. Assemble the retro-auth clinical package and submit
    A retro-auth request requires the same documentation that would have supported a prospective auth. Gather: the complete medical record for the service (H&P, progress notes, diagnostic results, operative notes if applicable); the treating physician's letter of medical necessity; supporting clinical criteria (payer's coverage policy, relevant LCD/NCD, clinical guidelines); and — critically — a concise explanation of why prospective auth was not obtained (emergency, urgency, administrative gap). Submit to the retro-auth department via their designated channel. Fax with a cover sheet that references your earlier call and the case number they gave you.
  4. File a formal appeal if retro-auth is denied or the window has closed
    If retro-auth is denied, or if the window has already closed before you caught the CO-170, file a formal claim appeal. The strongest CO-170 appeal arguments: (a) Emergency or urgent clinical presentation that precluded prospective auth — cite the prudent layperson standard and federal emergency care regulations; (b) Service met all the payer's clinical coverage criteria — attach the documentation that would have supported prospective auth; (c) Administrative error or miscommunication — attach proof of any auth-related contact that occurred; (d) Payer's retroactive auth requirement was not clearly disclosed in the provider contract. Include all clinical documentation and the treating physician's narrative.
  5. Fix the prevention gap after the current denial is resolved
    CO-170 is a systemic failure, not a one-time oversight. For every CO-170 denial, identify why the auth wasn't obtained: was this procedure not on your auth-required list? Did staff not check before scheduling? Was it a knowledge gap about this payer's requirements? Then fix the specific gap: update the auth-required list, update the scheduling workflow, train the responsible staff, and add a pre-visit auth verification step for this payer-procedure combination. One CO-170 means you have a process gap — investigate and close it.

4 auth parameters that must match before every date of service

Auth ParameterWhat to VerifyWhere It Appears on ClaimCommon Mismatch
Auth NumberAuth number is documented in the patient's account and will be entered on the claimCMS-1500 Box 23; 837P Loop 2300 REF*G1Auth obtained but not entered on claim → corrected claim fixes this without retro-auth
Date of ServiceThe approved DOS range on the auth covers the actual date of service — not just the scheduled dateAuth letter / payer portal auth detailPatient rescheduled; auth expired; billing used charge capture date not the service date
Procedure CodeThe CPT/HCPCS codes on the auth match what will be billed — including add-on codes if the payer separately requires themAuth letter / payer portal auth detailAuth for initial CPT; additional intraoperative procedures performed; or add-on codes not auth'd separately
Rendering Provider & FacilityThe auth is for the specific rendering provider NPI and the specific facility NPI where the service will be renderedAuth letter — provider and facility listedProvider substituted day-of; patient transferred to different facility; locum tenens not listed on auth
Verify all 4 parameters the day before the scheduled service — not the day of

Auth verification done the morning of service is too late if there is a discrepancy — there is no time to correct it before the patient presents. Run your pre-service auth verification 24–48 hours before each scheduled date of service. This gives you time to amend the auth, update the DOS range, or add a missing CPT before the patient arrives.

For when retro-auth is denied or the window has closed

VIA: Prior Authorization Appeals Department

Date: [Date]  |  Payer: [Payer Name]  |  Claim #: [Claim #]

Member ID: [Member ID]  |  Patient: [Name]  |  DOS: [Date of Service]

Provider NPI: [NPI]  |  Denied Code: CO-170  |  Procedure: [CPT Code(s)]


RE: Appeal of CO-170 Denial — Prior Authorization Not Obtained


This claim was denied under CO-170 indicating prior authorization was not obtained before service was rendered on [DOS]. We respectfully appeal this determination on the following grounds:


Option A — Emergency/Urgent Presentation:
The patient presented on [DOS] with [presenting symptoms], which required immediate medical treatment. The patient's condition met the prudent layperson standard for emergency care as established by the Affordable Care Act (42 U.S.C. § 300gg-19a) and [state law citation if applicable]. Federal and state law prohibit health plans from requiring prior authorization for emergency services and from retroactively denying emergency care. We attach the emergency documentation: chief complaint, presenting vitals, and the treating physician's clinical determination. We respectfully request that this claim be reprocessed as an emergency service and paid at the in-network rate.


Option B — Service Met All Clinical Coverage Criteria:
While authorization was not obtained prospectively, the service met all of your plan's clinical coverage criteria for this procedure. We enclose the medical record, the treating physician's letter of medical necessity, and [payer coverage policy/LCD citation] demonstrating that this service was appropriate and covered. Had authorization been requested prospectively, it would have been approved. A full denial for an administratively missing authorization — when the service was clinically appropriate, medically necessary, and covered under the plan — is a disproportionate penalty that the member's contract does not require.


Option C — Administrative Error / Retroactive Requirement:
[Describe specific circumstance: auth obtained for wrong code / auth number not entered on claim / payer updated auth requirement after appointment was scheduled / etc.] We attach documentation of [auth correspondence / scheduling records / payer communication] demonstrating that [the auth was in process / the requirement was not in force at time of scheduling / etc.] and request that this claim be reprocessed accordingly.


Enclosed: Medical record, physician letter of medical necessity, coverage policy/LCD, [other supporting documentation].


Contact: [Name, Phone]  |  Practice: [Practice Name]

Building a pre-authorization workflow that prevents CO-170

  • Maintain a current, payer-specific prior-auth required list — and review it quarterly. Payer auth requirements change constantly. A procedure that didn't require auth last quarter may require it now. Assign someone to review each payer's auth-required list quarterly and update your internal reference. This list should be accessible to every staff member involved in scheduling.
  • Run a pre-scheduling auth check before any procedure on the auth-required list. Before any patient appointment is confirmed for an auth-required procedure, the scheduler must verify auth status. The appointment should not be finalized until either (a) the auth number is documented, or (b) auth is confirmed as not required for this patient's plan. This single step eliminates most CO-170 denials.
  • Verify all 4 auth parameters 24–48 hours before service — not the morning of. The day before the appointment, confirm that the auth number, the DOS range, the procedure codes, and the facility/provider all match what will be billed. If there is a discrepancy, you have time to amend the auth or notify the patient before they travel to the appointment.
  • Document the auth number in the claim at time of billing — never leave Box 23 blank on an auth-required claim. The single most common fixable cause of CO-170 is an auth that exists in the PM system but was never entered on the claim. Establish a billing rule: for any claim involving a procedure on the auth-required list, Box 23 must be populated before the claim is released. A blank Box 23 on an auth-required claim should never pass through your clearinghouse.
  • Track CO-170 denials by payer, procedure, and responsible staff — and use the data to close gaps. A CO-170 denial that happens once is a mistake. A CO-170 that happens three times on the same payer-procedure combination is a process failure. Track every CO-170 by payer and procedure code. When a pattern emerges, investigate and close the specific gap — whether it is a missing auth-required code on your list, a scheduling workflow shortcut, or a specific staff knowledge gap.

Frequently Asked Questions: CO-170

CO-170 means the payer denied or reduced payment because prior authorization (pre-certification) was not obtained before the service was rendered. The payer required advance approval for this procedure, and none was on file at the time of claim adjudication. Act immediately — contact the payer's retro-auth line the same day you receive CO-170, because retro-auth windows are time-limited (typically 30–60 days from DOS for non-emergency services).
Sometimes — most payers offer a retro-auth pathway for non-emergency services within 30–60 days of the date of service. For emergency services, federal law generally requires coverage regardless of prior auth. Call the payer's retro-auth department immediately to confirm whether a window is available and how long you have. The sooner you act, the more options remain open.
Generally no — CO is a Contractual Obligation group code, which means the balance is typically a provider write-off. Most payer contracts prohibit holding the patient responsible when the provider failed to obtain required authorization. The exception is if the patient was notified in advance that authorization would not be sought and they signed a financial responsibility agreement before the service.
CO-170 means no prior authorization was obtained at all. CO-15 means an authorization exists but doesn't match the claim — wrong date of service, wrong procedure code, wrong facility, or wrong provider. The fix for CO-15 is amending or correcting the existing auth and resubmitting. The fix for CO-170 is obtaining retro-auth from scratch or appealing.
Federal law (ACA Section 2719A) prohibits health plans from requiring prior authorization for emergency services and from retroactively denying emergency care that a "prudent layperson" would consider a medical emergency based on presenting symptoms. If the patient's presenting condition — regardless of final diagnosis — would cause a reasonable person to believe immediate care was needed, the payer must cover it. Document: presenting symptoms, vitals at presentation, and the physician's determination that immediate treatment was required.
Three controls prevent most CO-170 denials: (1) a current payer-specific auth-required list that is reviewed and updated quarterly; (2) a pre-scheduling auth check that fires before any appointment involving an auth-required procedure; (3) a pre-service verification step 24–48 hours before DOS confirming all 4 auth parameters match: auth number documented, DOS range valid, procedure codes match, facility and provider match.

Codes related to CO-170

Seeing CO-170 more than once from the same payer? Your auth workflow has a gap.

A single CO-170 is a mistake. Repeated CO-170 denials on the same payer or procedure are a process failure — and every one represents revenue your team worked to earn but can't collect. A free RCM audit identifies your specific auth workflow gaps, helps you build a payer-specific auth-required list, and implements the pre-service verification step that stops CO-170 before it starts.