CO-197 is the most expensive preventable denial in healthcare billing. The retro-authorization window to recover it is 24–72 hours. After that it is usually a permanent write-off. Speed and knowing which of the five CO-197 types you have are the only two things that matter when this denial arrives.
CO-197 means the payer required prior authorization for this service and it was either not obtained, has expired, or does not match what was billed. Unlike CO-45 (routine write-off) or CO-16 (data fix), CO-197 frequently becomes a permanent, uncollectable write-off — because the retro-authorization window closes within 24–72 hours and most payers will not reverse it after that. The single most important thing when you receive CO-197 is to identify which of the five types it is and act immediately. The wrong action — or any delay — permanently forfeits the revenue.
Most commercial payers close the retro-authorization window 24–48 hours after the date of service. Medicaid MCOs allow up to 72 hours in most states. After the window closes, the denial is typically a permanent write-off that cannot be billed to the patient. Do not queue CO-197 for weekly work. Flag it for same-day action the moment it appears on your ERA.
CO-197 looks the same on every ERA. The root cause is not. Pull the claim, the auth record, and the clinical documentation before deciding which path to take.
Auth-required service was scheduled and rendered without anyone obtaining prior approval from the payer. Most common cause: the auth requirement was unknown, overlooked at scheduling, or the auth process was started but not completed before the service date.
Fix: Retro-auth request — act within 24–48 hrsAuthorization was approved, but the auth number was never entered into Box 23 (CMS-1500) or the 837P REF*G1 segment. The payer has the approval on file — the claim just didn't reference it. This is functionally a CO-16 data error masquerading as CO-197.
Fix: Corrected claim with auth number — same dayAn auth exists and was referenced on the claim, but something does not match: the CPT code billed differs from the authorized code, more units were rendered than approved, the date of service falls outside the auth validity period, or the rendering provider is different from the provider named on the auth.
Fix: Request auth amendment from UM — then resubmitAuth was obtained but the service was not rendered within the auth's validity period (typically 30–90 days from approval). The auth expired before the appointment was kept. Common for elective surgical procedures with scheduling delays or for patients who reschedule.
Fix: Request new auth or retro-auth extension — act fastAuth was not obtained because the service was an emergency or urgent situation where obtaining prior approval was not feasible before care was delivered. Federal law (EMTALA, No Surprises Act) and most commercial contracts exempt emergent services from PA requirements.
Fix: Formal appeal with emergent documentationEvery minute matters. Identify your type and take the corresponding action immediately.
When you call utilization management for retro-auth, record: the agent's name, call date and time, reference number for the call, and what was said about the retro-auth decision. If the payer later denies the retro-auth request or claims no request was made, your call documentation is your appeal evidence. This note goes in the patient account, not just the biller's memory.
These are general windows. Your specific contract or plan document may allow more or less time. Always verify with the payer's provider manual or a UM call for high-dollar claims.
| Payer / Program | Retro-Auth Window (Non-Emergent) | Emergent Services | Key notes |
|---|---|---|---|
| Medicare (Original FFS) | Rarely required | Not applicable | Original Medicare does not require PA for most physician services. CO-197 is uncommon. Certain DME, imaging under PA model, and select Part B drugs require auth — check CMS PA model by MAC region. |
| Medicare Advantage | 24–72 hours | 72 hrs from stabilization (federal requirement) | Each MA plan sets its own auth list and retro-auth policy. Humana MA and UHC MA typically allow 24–48 hrs. Aetna MA up to 72 hrs. Retro-auth for MA is via the plan's UM department, not CMS. |
| UnitedHealthcare (Commercial) | 24–48 hours | Generally exempt with documentation | UHC has one of the broadest auth requirement lists in commercial insurance. Auth list updates quarterly — subscribers to UHC's provider portal receive notifications. Retro-auth requests go through the UHC Prior Authorization portal or 1-866-892-5395. |
| Aetna (Commercial) | 24–48 hours | Generally exempt with documentation | Aetna uses Evicore for many imaging and specialty procedure auths. Retro-auth for Evicore-managed services goes through Evicore (not Aetna claims). Call Evicore first; then Aetna if Evicore says the service is not in their scope. |
| Cigna (Commercial) | 24–48 hours | Generally exempt with documentation | Cigna also uses Evicore for certain specialty services (PT, OT, ST beyond initial visits; certain imaging). Check Cigna's auth lookup tool before assuming Cigna UM is the right contact — Evicore handles the retro-auth for delegated services. |
| BCBS (varies by state plan) | 48–72 hours | Generally exempt with documentation | BCBS plans are independent by state — retro-auth policies vary significantly. BCBS TX, BCBS IL, and Anthem-affiliated plans tend to have stricter windows. Always call the local plan's UM line; BlueCard claims route to the member's home plan for auth. |
| Humana (Commercial) | 24–48 hours | Generally exempt with documentation | Humana exited the employer group commercial market in 2024 — Humana CO-197 today is primarily Medicare Advantage. Humana MA retro-auth is through MyHumana provider portal or 1-800-457-4708 UM line. |
| Medicaid FFS (state) | 48–72 hours | 72 hrs from stabilization (EMTALA) | State-specific. Many states have implemented PA reform laws (2024–2026) shortening payer decision timelines and expanding emergent service exemptions. Retro-auth for state Medicaid goes through the state's MMIS portal or Medicaid PA phone line. |
| Medicaid MCOs | 48–72 hours | 72 hrs from stabilization | Each MCO within a state has its own UM department and retro-auth process. Some MCOs (e.g., Centene/WellCare plans) have specific retro-auth portals. Do not call the state Medicaid office — call the MCO's UM line directly for the enrolled member. |
| Tricare / VA | 72 hours–7 days | Generally exempt for emergency care | Tricare retro-auth windows are generally more generous than commercial. Emergency care outside network is generally covered without PA under the "point of service" rule. Contact Tricare regional contractor (Health Net Federal Services or Humana Military) for retro-auth requests. |
Windows are representative based on 2026 payer policies. Verify the specific window in your provider manual or with the payer's UM department before the service date — not after the denial.
All elective inpatient admissions and most urgent admissions require prior authorization. The auth must be obtained before admission, not after. Auth is for the admission itself — additional clinical days beyond the authorized length of stay require a concurrent review call to UM.
Orthopedic surgery (joint replacement, spine), bariatric, cardiac procedures, and most major outpatient surgical codes require auth for every major commercial payer and Medicare Advantage plan. Auth must specify the CPT code — a mismatch between authorized and billed code generates Type 3 CO-197.
MRI, CT, PET, and nuclear medicine studies are heavily PA-managed, often through a radiology benefit manager (Evicore, NIA, RadNet) rather than the payer directly. Ordering physicians or their staff must initiate the auth before scheduling — not on the day of the study.
Infused biologics (adalimumab, rituximab, trastuzumab), specialty injectables, and high-cost Part B drugs require auth that specifies the drug, dose, frequency, and diagnosis. Auth for specialty drugs is often managed by the payer's pharmacy benefit manager — the clinical and medical benefit sides are separate.
Power wheelchairs, CPAP/BiPAP, home oxygen, complex rehab equipment, and certain orthotic/prosthetic devices require auth and a signed Certificate of Medical Necessity (CMN). CMS has also implemented a prior authorization model for certain DME categories in specific states.
Inpatient psychiatric admissions, residential treatment, and intensive outpatient programs (IOP) require both admission auth and concurrent daily reviews. Auth for behavioral health is often managed through a separate behavioral health carve-out plan — verify whether the patient's medical and behavioral benefits are with the same or different payers.
Every CO-197 denial is a workflow failure that occurred days or weeks before the service date. Prevention happens at scheduling, not at billing.
Use the correct template for your CO-197 type. Replace [bracketed fields] with your specifics.
Template A — Retro-authorization request (Types 1 & 4)
VIA: Utilization Management / Prior Authorization Department — Urgent
Date: [Date — same day as denial]
Payer: [Payer Name] | Member ID: [Member ID]
Provider NPI: [NPI] | Facility NPI: [Facility NPI if applicable]
Date of Service: [DOS] | Procedure Code(s): [CPT/HCPCS]
Diagnosis: [ICD-10 codes]
RE: Urgent Retro-Authorization Request — CO-197 Denial
We are requesting retrospective authorization for the above-referenced service, denied under CO-197 on ERA dated [ERA date].
[Select applicable reason:]
— The prior authorization process was initiated on [date] but was not completed before the date of service due to [specific reason: scheduling urgency / payer processing delay / administrative oversight].
— OR: The original authorization (number: [auth #]) expired on [expiration date] before the service could be rendered due to [reason: patient rescheduled / surgical delay].
Clinical justification for medical necessity: [2–3 sentence summary: diagnosis, why this specific service was indicated, relevant clinical history].
We are requesting an urgent retrospective review. Clinical documentation (including physician notes, relevant labs/imaging, and referring provider documentation) is attached.
Please contact [Auth Coordinator Name] at [Phone] within [payer's stated response window] to confirm retro-auth status.
Sincerely, [Provider / Practice Administrator Name], [Practice Name]
Template B — Emergent service appeal (Type 5)
VIA: Formal Claims Appeal / Grievance Department
Date: [Date]
Payer: [Payer Name] | Original Claim: [Claim #]
Member ID: [Member ID] | DOS: [DOS]
Procedure Code(s): [CPT/HCPCS] | Denial Code: CO-197
RE: Appeal of CO-197 Denial — Emergent Service Exempt from Prior Authorization
We are appealing the denial of the above-referenced claim under CO-197 (prior authorization not obtained). The service rendered on [DOS] was an emergent/urgent service for which prior authorization was not obtainable before care was delivered.
Clinical basis for emergent nature: [Describe: chief complaint, acuity, vital signs, timeline, why delay would have caused harm]. Supporting documentation (ED record / treating physician note / triage record) is attached.
Prior authorization is not required for this service under:
— [Select applicable: Section 2719A of the Public Health Service Act (No Surprises Act) / EMTALA / Your plan's provider agreement Section [X] / State law [cite specific statute if applicable]]
We request that this claim be reprocessed as an emergent service exempt from prior authorization requirements and that payment be issued at the contracted rate.
If this appeal is denied at the first level, we request a peer-to-peer review between the treating physician, [Physician Name, MD, Specialty], and the plan's medical director. Contact [Physician's office contact] to schedule.
Sincerely, [Practice Administrator], [Practice Name]
Prior auth denials at that level signal a broken scheduling or auth workflow — not a billing problem. A free RCM audit maps exactly where auth requests are failing and what workflow change recovers the most revenue fastest.