Skip to main content

Authorization and Referral Denials: Prevention First

Prior authorization approval being matched to a professional claim by service, date, provider, and units

TL;DR / Key takeaways

  • An authorization number can be valid and still fail to support the billed service.
  • Authorization should be matched to patient, payer, provider, service, date range, units or visits, and place of service when relevant.
  • Referral rules and authorization rules are payer- and product-specific; they should not be generalized from one health plan to another.
  • X12 CARC 284 specifically describes an authorization or precertification number that may be valid but does not apply to the billed services; CARC 288 identifies an absent referral.
  • Prevention must happen before the claim and, ideally, before the service when the payer requires prior approval.

Authorization and referral denials are among the most frustrating denials because they are often hardest to correct after the patient has already received care. A valid authorization number does not necessarily mean the eventual claim is protected. The authorization must correspond to the actual service billed under the payer’s rules.

For denial prevention, the right question is not “Do we have an authorization?” It is “Does the authorization we have apply to this patient, provider, service, date, quantity, and setting?”

What makes an authorization valid for a claim?

The exact requirements vary by payer and plan, but common matching elements include:

  • patient/member.
  • payer and product.
  • authorization or precertification number.
  • rendering provider.
  • billing entity when relevant.
  • authorized CPT/HCPCS service or service category.
  • authorized date range.
  • number of visits or units.
  • place or site of service.
  • diagnosis or level-of-care conditions when applicable.

A mismatch in any required element can create nonpayment.

X12 CARC 284 is especially instructive: it describes a situation in which the precertification, authorization, notification, or pretreatment number may be valid but does not apply to the billed services. That is a reminder that “number present” is not the same as “authorization matched.”

What is the difference between authorization and referral?

A prior authorization generally represents payer approval or review required before a service is performed or paid under the applicable policy. A referral may represent a required direction from one provider to another, depending on the plan design.

These are not interchangeable. Some plans require neither. Some require one or both. Rules can differ between Medicare fee-for-service, Medicare Advantage, commercial HMO/POS products, Medicaid managed care, and other products.

X12 CARC 288 identifies an absent referral. There are also authorization-related CARCs and RARCs that can further explain payer decisions.

Why do authorization denials still happen when staff obtained approval?

Common causes include:

Wrong date range

The service occurs before the authorization start date or after it expires.

Wrong service

The authorization covers one procedure or service family, but the claim contains a different code.

Units exhausted

The plan approved 10 visits, but the claim represents visit 11.

Provider mismatch

The authorization is tied to a specific clinician, group, or location that differs from the claim.

Payer/product mismatch

The authorization was obtained under one product, but the patient changed coverage or the claim was routed to another product.

Missing authorization on the claim

The practice obtained approval but failed to transmit the required authorization number or related data.

Referral absent or expired

The plan requires a referral and the referral was never obtained, expired, or was not linked to the correct provider/service.

These are workflow failures, not simply “payer denials.”

What should be checked before the service?

For services known to require prior authorization, the best control happens before care is delivered. A scheduling or authorization workflow should confirm:

  • current eligibility.
  • authorization requirement under the specific product.
  • request submitted.
  • approval received.
  • approved services.
  • valid date range.
  • units/visits available.
  • authorized provider/location.

This should not rely on memory or free-text notes. Use structured data where possible so the claim workflow can later compare the authorization to the actual billing data.

What should be checked again before claim submission?

Even when authorization was handled correctly in advance, the final claim can differ from the planned service. Before submission, compare:

  • billed CPT/HCPCS codes to approved services.
  • date of service to authorization dates.
  • rendering provider to authorized provider.
  • units billed to remaining approved units.
  • place of service to any location restriction.
  • authorization number to the claim field or electronic data element required by the payer.

This is the point where a claim validator can catch a mismatch before the payer does.

How should practices handle payer-specific rules?

Do not build one universal authorization rule for “Aetna,” “UHC,” or “Humana” as if every product works the same way. The same payer can offer commercial, Medicare Advantage, Medicaid, employer-specific, and other products with different authorization requirements.

Where possible, scope the rule to:

payer + product/network + service + date range + provider context

If the data are not specific enough to make a deterministic decision, the system should warn rather than block.

How do you work an authorization denial after it happens?

Start by comparing four things:

  1. the authorization approval or reference.
  2. the clinical service actually performed.
  3. the claim that was transmitted.
  4. the ERA denial and remark codes.

Determine whether the problem is:

  • authorization never obtained.
  • authorization present but mismatched.
  • claim omitted required authorization data.
  • payer record not reflecting the approval.
  • referral requirement; or
  • another policy issue mistakenly interpreted as authorization.

Then follow the payer’s correction, reconsideration, or appeal process. If the denial was preventable, add the root cause to the prospective workflow.

What metrics should you track?

Track authorization denials by:

  • payer and product.
  • service code.
  • rendering provider.
  • authorization number present/absent.
  • mismatch category.
  • units/visits exhausted.
  • referral vs. prior-authorization cause.
  • recoverable vs. nonrecoverable dollars.
  • recurrence after workflow changes.

A practice that tracks only total authorization denials cannot tell whether the real defect is scheduling, authorization staff, claim construction, or payer records.

How does authorization fit the ClaimsRevenue model?

Authorization is a good example of a problem that spans systems. ClaimsRevenue does not need to become the source of authorization itself to provide value. If the practice has structured authorization data, the Claims Validator can compare that data with the outgoing claim and surface obvious mismatches.

The ERA then closes the loop. If a payer denies an authorization-related claim, the ERA Analyzer can help classify the pattern and identify whether the same condition is recurring.

Related reading: eligibility and COB denials and CO-16 missing-information denials.

FAQ

Can an authorization number be valid and the claim still deny?

Yes. The authorization may not apply to the billed service, date, provider, units, or other required claim circumstances.

What is CARC 284?

It describes a situation where precertification, authorization, notification, or pretreatment information may be valid but does not apply to the billed services.

What is CARC 288?

It identifies an absent referral.

Does eligibility verification confirm authorization?

No. Active eligibility does not prove that prior authorization or referral requirements have been met.

When should authorization validation occur?

Ideally before the service and again before claim submission to confirm the final claim matches the approved service.

Authoritative sources