CO-198 means prior authorization was obtained and is valid — but the number of approved visits, units, or the authorized date range was exceeded. Unlike CO-197 (no auth at all), the auth exists. The fix is requesting additional authorization from the payer's Utilization Management department before resubmitting the denied claims.
CO-198 means you have a valid prior authorization, but you delivered more services than it approved. The authorization approved a specific number of visits, units, or a date range — and the service on the denied claim goes beyond that limit. The fix is going back to the payer's Utilization Management department and requesting additional authorization for the over-limit services. CO-198 is entirely preventable if you track remaining auth units before scheduling each additional visit. Every CO-198 is a tracking failure, not a clinical failure.
When an auth is at its limit, stop scheduling new visits under that auth. Contact UM immediately to request additional units. If you continue delivering services while the additional auth request is pending and UM ultimately denies it, those services become a write-off. The only safe sequence is: request more auth → receive approval → then schedule the additional visit.
| Limit Type | What It Means | Common Specialty | What to Request from UM |
|---|---|---|---|
| Visit limit exceeded | Auth approved N visits (e.g., 12 PT sessions). The denied claim is for visit N+1 or beyond. | PT, OT, ST, Chiropractic, Behavioral Health outpatient | Additional visits (e.g., "requesting 8 additional PT visits for continued rehabilitation"). Provide updated functional status and clinical rationale. |
| Unit limit exceeded | Auth approved a specific number of units per claim (e.g., 4 units of a timed therapy code). The claim billed more units than the auth allows. | Physical therapy (timed codes), infusion, DME, home health aide hours | Additional units per session, or a revised auth that increases the per-visit unit limit. Document why the additional time was clinically required. |
| Date range exceeded | Auth was valid through a specific end date (e.g., valid 6/1–8/31). A service was rendered after the auth's expiration date but within the policy period. | All specialties with time-limited auths — especially post-surgical rehab, SNF, home health | Auth renewal or extension for the additional date range. This is a new auth request, not an amendment to the original. |
UM processing typically takes 3–5 business days for non-urgent requests. If you wait until the auth is exhausted to request more, you'll deliver services in the gap between the old auth and new approval — and those services will generate CO-198. The rule: request additional auth when 2 visits or 20% of units remain, whichever comes first. This provides a buffer for UM processing time.
Every CO-198 denial means a visit was scheduled after an auth limit was reached. A free RCM audit identifies where your auth tracking breaks down and what workflow change stops CO-198 before it starts.