CO Contractual Obligation · CARC Code 197
CO-197

Prior Authorization Missing, Expired, or Mismatched

CO-197 is the most expensive preventable denial in healthcare billing. The retro-authorization window to recover it is 24–72 hours. After that it is usually a permanent write-off. Speed and knowing which of the five CO-197 types you have are the only two things that matter when this denial arrives.

Updated July 2026 · Group code: CO (provider write-off if unrecovered) · Recovery window: 24–72 hours from date of service · Preventability: ~75% with front-end auth workflow
#1Most Expensive Preventable Denial
24–72 hrsRetro-Auth Window
5 typesDifferent Fix for Each
~75%Preventable at Scheduling
CO-197 in plain English

CO-197 means the payer required prior authorization for this service and it was either not obtained, has expired, or does not match what was billed. Unlike CO-45 (routine write-off) or CO-16 (data fix), CO-197 frequently becomes a permanent, uncollectable write-off — because the retro-authorization window closes within 24–72 hours and most payers will not reverse it after that. The single most important thing when you receive CO-197 is to identify which of the five types it is and act immediately. The wrong action — or any delay — permanently forfeits the revenue.

🚨
CO-197 is time-critical — act the same day the denial arrives

Most commercial payers close the retro-authorization window 24–48 hours after the date of service. Medicaid MCOs allow up to 72 hours in most states. After the window closes, the denial is typically a permanent write-off that cannot be billed to the patient. Do not queue CO-197 for weekly work. Flag it for same-day action the moment it appears on your ERA.

Identify your type first — the fix is different for each

CO-197 looks the same on every ERA. The root cause is not. Pull the claim, the auth record, and the clinical documentation before deciding which path to take.

1

No authorization obtained

Auth-required service was scheduled and rendered without anyone obtaining prior approval from the payer. Most common cause: the auth requirement was unknown, overlooked at scheduling, or the auth process was started but not completed before the service date.

Fix: Retro-auth request — act within 24–48 hrs
2

Auth obtained but number missing from claim

Authorization was approved, but the auth number was never entered into Box 23 (CMS-1500) or the 837P REF*G1 segment. The payer has the approval on file — the claim just didn't reference it. This is functionally a CO-16 data error masquerading as CO-197.

Fix: Corrected claim with auth number — same day
3

Auth mismatch — code, units, dates, or provider

An auth exists and was referenced on the claim, but something does not match: the CPT code billed differs from the authorized code, more units were rendered than approved, the date of service falls outside the auth validity period, or the rendering provider is different from the provider named on the auth.

Fix: Request auth amendment from UM — then resubmit
4

Authorization expired

Auth was obtained but the service was not rendered within the auth's validity period (typically 30–90 days from approval). The auth expired before the appointment was kept. Common for elective surgical procedures with scheduling delays or for patients who reschedule.

Fix: Request new auth or retro-auth extension — act fast
5

Emergent or urgent service — auth not possible

Auth was not obtained because the service was an emergency or urgent situation where obtaining prior approval was not feasible before care was delivered. Federal law (EMTALA, No Surprises Act) and most commercial contracts exempt emergent services from PA requirements.

Fix: Formal appeal with emergent documentation

What to do when you see CO-197

Every minute matters. Identify your type and take the corresponding action immediately.

  1. Identify the CO-197 type — pull the auth record first
    Before calling anyone: (a) check your auth tracking system for a record for this patient, procedure, and date of service. If an auth record exists → you have Type 2 (missing from claim) or Type 3 (mismatch). If no auth record → you have Type 1 (never obtained) or Type 4 (expired). Review the clinical notes to assess whether the service was emergent → Type 5. This diagnosis takes 5 minutes and determines everything that follows.
  2. Type 2 — add auth number and resubmit corrected claim
    If auth was obtained but not on the claim: locate the auth approval number from your tracking system or payer portal. Add it to Box 23 on the CMS-1500 or the REF*G1 segment in the 837P. Resubmit as a corrected claim (frequency code 7). This resolves in 7–14 days. No retro-auth call needed — the auth already exists.
  3. Type 1 or 4 — call utilization management for retro-auth now
    Do not call the claims department — call the payer's utilization management (UM) or prior authorization line. Have ready: member ID, date of service, procedure code(s), diagnosis codes, rendering provider NPI, facility NPI (if applicable), and your clinical rationale for medical necessity. Ask specifically for "retro-authorization" or "retrospective review." If approved, get the auth number in writing (or via payer portal confirmation) and resubmit the claim immediately.
  4. Type 3 — request auth amendment from utilization management
    Contact UM (not claims). Explain the specific mismatch: "We have auth [number] approved for CPT [X] but the service rendered was CPT [Y]" or "Auth was for [N] units but [N+2] were clinically required." Request an amendment to the existing auth to align with the service actually rendered. Once UM confirms the amendment, resubmit the original claim with a note referencing the amended auth. Do not file a new claim — reference the original claim number.
  5. Type 5 — file a formal appeal with emergent documentation
    Gather: (a) the treating provider's documentation of the emergent/urgent nature of the presentation — chief complaint, vital signs, timeline of deterioration, or acuity level from triage, (b) the specific contract language or statute that exempts emergent services from PA requirements, (c) any applicable state law (many states now have explicit PA reform laws protecting emergent care). Submit through the payer's standard appeal process. Request a peer-to-peer review with the payer's medical director if the first-level appeal is denied. Emergent CO-197 appeals succeed at high rates when clinical documentation is clear.
💡
Document every retro-auth call — name, time, reference number

When you call utilization management for retro-auth, record: the agent's name, call date and time, reference number for the call, and what was said about the retro-auth decision. If the payer later denies the retro-auth request or claims no request was made, your call documentation is your appeal evidence. This note goes in the patient account, not just the biller's memory.

Retro-authorization windows by payer — 2026

These are general windows. Your specific contract or plan document may allow more or less time. Always verify with the payer's provider manual or a UM call for high-dollar claims.

Payer / Program Retro-Auth Window (Non-Emergent) Emergent Services Key notes
Medicare (Original FFS) Rarely required Not applicable Original Medicare does not require PA for most physician services. CO-197 is uncommon. Certain DME, imaging under PA model, and select Part B drugs require auth — check CMS PA model by MAC region.
Medicare Advantage 24–72 hours 72 hrs from stabilization (federal requirement) Each MA plan sets its own auth list and retro-auth policy. Humana MA and UHC MA typically allow 24–48 hrs. Aetna MA up to 72 hrs. Retro-auth for MA is via the plan's UM department, not CMS.
UnitedHealthcare (Commercial) 24–48 hours Generally exempt with documentation UHC has one of the broadest auth requirement lists in commercial insurance. Auth list updates quarterly — subscribers to UHC's provider portal receive notifications. Retro-auth requests go through the UHC Prior Authorization portal or 1-866-892-5395.
Aetna (Commercial) 24–48 hours Generally exempt with documentation Aetna uses Evicore for many imaging and specialty procedure auths. Retro-auth for Evicore-managed services goes through Evicore (not Aetna claims). Call Evicore first; then Aetna if Evicore says the service is not in their scope.
Cigna (Commercial) 24–48 hours Generally exempt with documentation Cigna also uses Evicore for certain specialty services (PT, OT, ST beyond initial visits; certain imaging). Check Cigna's auth lookup tool before assuming Cigna UM is the right contact — Evicore handles the retro-auth for delegated services.
BCBS (varies by state plan) 48–72 hours Generally exempt with documentation BCBS plans are independent by state — retro-auth policies vary significantly. BCBS TX, BCBS IL, and Anthem-affiliated plans tend to have stricter windows. Always call the local plan's UM line; BlueCard claims route to the member's home plan for auth.
Humana (Commercial) 24–48 hours Generally exempt with documentation Humana exited the employer group commercial market in 2024 — Humana CO-197 today is primarily Medicare Advantage. Humana MA retro-auth is through MyHumana provider portal or 1-800-457-4708 UM line.
Medicaid FFS (state) 48–72 hours 72 hrs from stabilization (EMTALA) State-specific. Many states have implemented PA reform laws (2024–2026) shortening payer decision timelines and expanding emergent service exemptions. Retro-auth for state Medicaid goes through the state's MMIS portal or Medicaid PA phone line.
Medicaid MCOs 48–72 hours 72 hrs from stabilization Each MCO within a state has its own UM department and retro-auth process. Some MCOs (e.g., Centene/WellCare plans) have specific retro-auth portals. Do not call the state Medicaid office — call the MCO's UM line directly for the enrolled member.
Tricare / VA 72 hours–7 days Generally exempt for emergency care Tricare retro-auth windows are generally more generous than commercial. Emergency care outside network is generally covered without PA under the "point of service" rule. Contact Tricare regional contractor (Health Net Federal Services or Humana Military) for retro-auth requests.

Windows are representative based on 2026 payer policies. Verify the specific window in your provider manual or with the payer's UM department before the service date — not after the denial.

High-risk services by category

Inpatient admissions

All elective inpatient admissions and most urgent admissions require prior authorization. The auth must be obtained before admission, not after. Auth is for the admission itself — additional clinical days beyond the authorized length of stay require a concurrent review call to UM.

Outpatient surgery

Orthopedic surgery (joint replacement, spine), bariatric, cardiac procedures, and most major outpatient surgical codes require auth for every major commercial payer and Medicare Advantage plan. Auth must specify the CPT code — a mismatch between authorized and billed code generates Type 3 CO-197.

Advanced imaging

MRI, CT, PET, and nuclear medicine studies are heavily PA-managed, often through a radiology benefit manager (Evicore, NIA, RadNet) rather than the payer directly. Ordering physicians or their staff must initiate the auth before scheduling — not on the day of the study.

Specialty drugs & biologics

Infused biologics (adalimumab, rituximab, trastuzumab), specialty injectables, and high-cost Part B drugs require auth that specifies the drug, dose, frequency, and diagnosis. Auth for specialty drugs is often managed by the payer's pharmacy benefit manager — the clinical and medical benefit sides are separate.

DME / DMEPOS

Power wheelchairs, CPAP/BiPAP, home oxygen, complex rehab equipment, and certain orthotic/prosthetic devices require auth and a signed Certificate of Medical Necessity (CMN). CMS has also implemented a prior authorization model for certain DME categories in specific states.

Behavioral health inpatient & IOP

Inpatient psychiatric admissions, residential treatment, and intensive outpatient programs (IOP) require both admission auth and concurrent daily reviews. Auth for behavioral health is often managed through a separate behavioral health carve-out plan — verify whether the patient's medical and behavioral benefits are with the same or different payers.

Prevention checklist: building an auth workflow that eliminates CO-197

Every CO-197 denial is a workflow failure that occurred days or weeks before the service date. Prevention happens at scheduling, not at billing.

  • Check auth requirements at the time of scheduling — not at the time of billing. Every scheduled procedure should trigger an automatic auth requirement check against the patient's specific plan. Use your payer's auth lookup tool or the NaviNet/Availity auth requirement database. If auth is required, the auth request should be submitted before the appointment is confirmed.
  • Assign a dedicated auth coordinator for high-volume specialties. Practices billing for surgery, imaging, infusion, behavioral health, or DME should have staff whose primary role is prior authorization management. Billing staff managing auth as a secondary task is the #1 structural cause of CO-197 volume.
  • Build auth validity period tracking into your scheduling system. When an auth is obtained, record the expiration date in both your auth tracking system and the scheduling system. Any appointment within 7 days of auth expiration should auto-flag for auth renewal before the visit.
  • Verify auth covers the exact CPT code to be billed. Auth mismatches (Type 3) are most common when the planned procedure changes after auth was obtained. Build a workflow requiring coding review of any procedure change — if the CPT code changes, the auth must be amended before the service date.
  • Include auth number on every claim at submission. Box 23 (CMS-1500) or REF*G1 (837P) must be populated for every service with a prior authorization on file. Build this as a required field in your charge-entry template for auth-required procedures — a blank field becomes a Type 2 CO-197 automatically.
  • Track CO-197 by service type, payer, and provider monthly. Run a monthly denial report filtering for CO-197, grouped by CPT code and payer. A spike in CO-197 on specific code-payer combinations reveals a broken auth workflow for that service type — address the process, not just the claims.
  • Subscribe to payer auth requirement update notifications. UHC, Aetna, and Cigna publish auth requirement updates quarterly. A service that did not require auth last quarter may require it this quarter. Set up payer portal notifications or assign someone to check quarterly updates — auth requirement changes cause sudden CO-197 spikes the month they take effect.

CO-197 appeal letters — two scenarios

Use the correct template for your CO-197 type. Replace [bracketed fields] with your specifics.

Template A — Retro-authorization request (Types 1 & 4)

VIA: Utilization Management / Prior Authorization Department — Urgent

Date: [Date — same day as denial]

Payer: [Payer Name]  |  Member ID: [Member ID]

Provider NPI: [NPI]  |  Facility NPI: [Facility NPI if applicable]

Date of Service: [DOS]  |  Procedure Code(s): [CPT/HCPCS]

Diagnosis: [ICD-10 codes]


RE: Urgent Retro-Authorization Request — CO-197 Denial


We are requesting retrospective authorization for the above-referenced service, denied under CO-197 on ERA dated [ERA date].


[Select applicable reason:]
— The prior authorization process was initiated on [date] but was not completed before the date of service due to [specific reason: scheduling urgency / payer processing delay / administrative oversight].
— OR: The original authorization (number: [auth #]) expired on [expiration date] before the service could be rendered due to [reason: patient rescheduled / surgical delay].


Clinical justification for medical necessity: [2–3 sentence summary: diagnosis, why this specific service was indicated, relevant clinical history].


We are requesting an urgent retrospective review. Clinical documentation (including physician notes, relevant labs/imaging, and referring provider documentation) is attached.


Please contact [Auth Coordinator Name] at [Phone] within [payer's stated response window] to confirm retro-auth status.


Sincerely, [Provider / Practice Administrator Name], [Practice Name]

Template B — Emergent service appeal (Type 5)

VIA: Formal Claims Appeal / Grievance Department

Date: [Date]

Payer: [Payer Name]  |  Original Claim: [Claim #]

Member ID: [Member ID]  |  DOS: [DOS]

Procedure Code(s): [CPT/HCPCS]  |  Denial Code: CO-197


RE: Appeal of CO-197 Denial — Emergent Service Exempt from Prior Authorization


We are appealing the denial of the above-referenced claim under CO-197 (prior authorization not obtained). The service rendered on [DOS] was an emergent/urgent service for which prior authorization was not obtainable before care was delivered.


Clinical basis for emergent nature: [Describe: chief complaint, acuity, vital signs, timeline, why delay would have caused harm]. Supporting documentation (ED record / treating physician note / triage record) is attached.


Prior authorization is not required for this service under:

[Select applicable: Section 2719A of the Public Health Service Act (No Surprises Act) / EMTALA / Your plan's provider agreement Section [X] / State law [cite specific statute if applicable]]


We request that this claim be reprocessed as an emergent service exempt from prior authorization requirements and that payment be issued at the contracted rate.


If this appeal is denied at the first level, we request a peer-to-peer review between the treating physician, [Physician Name, MD, Specialty], and the plan's medical director. Contact [Physician's office contact] to schedule.


Sincerely, [Practice Administrator], [Practice Name]

Frequently Asked Questions: CO-197

CO-197 means the service required prior authorization and the authorization was missing, expired, or mismatched with the service billed. It is the most expensive preventable denial category because retro-authorization windows are typically just 24–72 hours — after that, the denial usually becomes a permanent write-off. CO-197 has five distinct types, each requiring a different fix: no auth obtained, auth not on the claim, auth mismatch, expired auth, or emergent service without auth.
Retro-authorization windows vary by payer but are always narrow. Most commercial payers (UHC, Aetna, Cigna) allow 24–48 hours from the date of service. Medicare Advantage plans generally allow 24–72 hours. Medicaid MCOs typically allow 48–72 hours. Tricare is more generous at up to 7 days for some situations. Emergent services have broader windows, often 72 hours from stabilization with federal backing. Always verify the specific window with the payer before the service date — never after the denial arrives.
Payers can issue CO-197 on emergent services, but these denials are generally not sustainable. Federal law — the No Surprises Act, EMTALA, and Medicare/Medicaid regulations — prohibits requiring prior authorization for emergency services. Most commercial contracts have similar emergency exemptions. Appeal with the treating provider's documentation of the emergent nature, the relevant statutory exemption, and a peer-to-peer request if the first appeal fails. Emergent CO-197 appeals succeed at high rates with strong clinical documentation.
CO-197 means prior authorization was not obtained at all, or the auth on file does not match the service billed. CO-198 means authorization was obtained and referenced, but its limits were exceeded — more visits were delivered than approved, more units were used than authorized, or services were rendered beyond the approved date range. CO-197 requires obtaining a new or retro-authorization. CO-198 requires requesting additional units, a visit extension, or a new auth period. Both are auth-related but require completely different remediation pathways.
Generally no, unless the patient received advance written notice that the service might not be covered and accepted financial responsibility in writing before the service was rendered. For Medicare, this requires a valid Advance Beneficiary Notice (ABN). For commercial insurance, balance billing for CO-197 without advance notice violates most provider contracts and, in states with balance billing laws, may violate state law. If retro-authorization is denied and no advance notice was given, the provider typically absorbs the write-off — which is why prevention at the front end is essential.
Original Medicare (FFS) does not require prior authorization for most physician services. CO-197 from Original Medicare is uncommon and limited to: certain high-cost DME under CMS's DMEPOS prior authorization program, select high-cost imaging in states participating in the Medicare Imaging Prior Authorization Model, and specific Part B drugs. Medicare Advantage is entirely different — each MA plan has its own prior authorization list that can differ significantly from Original Medicare's requirements and changes annually. Always check the specific MA plan's current authorization requirements, not just CMS rules.

Denial codes commonly seen alongside CO-197

CO-197 volume above 5% of your denials?

Prior auth denials at that level signal a broken scheduling or auth workflow — not a billing problem. A free RCM audit maps exactly where auth requests are failing and what workflow change recovers the most revenue fastest.