An authorisation number is permission to bill, not a promise to pay
Prior authorisation is the payer deciding in advance that a service is likely to be medically necessary. It is not a coverage guarantee, it does not survive a documentation failure, and in behavioral health it attaches to services in a pattern that is not obvious until it costs you.
Routine outpatient psychotherapy is frequently exempt from authorisation, which lulls practices into treating it as a non-issue. The exposure sits elsewhere, and it concentrates in the services that are most expensive to deliver.
What typically requires authorisation
| Service | Usually required? | Notes |
|---|---|---|
| Routine outpatient therapy | Often not | Some plans authorise after a visit threshold |
| Intensive outpatient (IOP) | Usually | With concurrent review throughout |
| Partial hospitalisation (PHP) | Usually | Frequent review intervals |
| Inpatient and residential | Almost always | Often reviewed every few days |
| Psychological and neuropsychological testing | Frequently | Hours are commonly authorised, not just the service |
| Applied behaviour analysis | Almost always | Assessment and treatment authorised separately |
| Certain medications | Varies | Pharmacy benefit, separate process |
The visit-threshold trap
The pattern that catches outpatient practices is the plan that authorises the first block of sessions automatically and requires authorisation beyond it — commonly after eight, twelve or twenty visits.
Nothing announces the threshold. Sessions process normally, then one denies for absent authorisation, and by the time that denial arrives several further sessions have been delivered against an authorisation that does not exist. The recovery is a retroactive authorisation request, which some payers grant and others refuse on principle.
The one operational control that prevents this. Track authorised visit counts per client, not just authorisation dates, and set the alert several sessions before the limit rather than at it. Authorisation requests take days to weeks; discovering the limit on the session that exceeds it leaves no time to act.
Concurrent review
For higher levels of care, authorisation is not granted once. The payer authorises an initial period and then reviews continued stay at intervals — sometimes daily for inpatient, every few days to weekly for PHP and IOP.
Each review is a clinical conversation in which a reviewer decides whether the client still meets criteria for this level of care. What the payer wants is specific: current symptoms and their severity, risk status, what has been tried, response to treatment, why a lower level of care would be insufficient right now, and the discharge plan.
Programmes that document to this shape routinely fare better at review than programmes with equally good clinical care and narrative documentation, because the reviewer is working from a criteria checklist and needs to find the criteria.
Peer-to-peer review
When a reviewer denies continued authorisation, you can usually request a peer-to-peer — a conversation with a physician reviewer, typically within a short window that can be as little as 24 hours.
Two things make these go better. First, prepare against the plan's own medical-necessity criteria, using their language rather than yours. Second, be concrete about risk and function: "client remains unable to maintain safety without daily contact, following two attempts in the past month" is a different conversation from "client is not ready for discharge."
Why an authorisation still does not guarantee payment
This surprises people and is worth being clear about. Authorisation states that the service is expected to be medically necessary. A claim can still deny afterwards because:
- Coverage lapsed between authorisation and service.
- The service delivered differed from the service authorised.
- Documentation does not support what was billed — see the golden thread.
- Another plan is primary.
- The claim exceeded the authorised units or dates.
- Timely filing lapsed.
Authorisation removes one reason for denial. It does not remove the others, and post-payment review can still recover money later — see recoupment.
Retroactive authorisation
Where a service was delivered without authorisation — an emergency admission, an unnoticed threshold, a coverage change nobody caught — retroactive requests are sometimes possible. Payers differ substantially on whether they entertain them and within what window.
What helps: request immediately rather than after the denial, document precisely why prospective authorisation was not obtained, and show that the clinical criteria were met at the time. What does not help is a request submitted three months later with no explanation.
Keeping the record
Every authorisation should be recorded with the number, the authorised date range, the authorised units or visits, the specific services covered, and the name and reference of whoever issued it. An authorisation you cannot produce is, functionally, an authorisation you do not have — and the requests most likely to be disputed are the ones granted verbally.
Parity, and why it is worth knowing about
Federal mental health parity law requires that treatment limitations applied to mental health and substance use benefits be no more restrictive than those applied to comparable medical benefits. That covers not only visit limits and cost sharing but non-quantitative limitations — which is the category authorisation requirements fall into.
The practical relevance is narrow but real: a plan requiring authorisation after eight psychotherapy sessions while imposing no comparable requirement on analogous medical services may be applying a non-comparable limitation. That is an argument for an appeal or a complaint to a state insurance regulator rather than something to raise on a routine call, but it is worth knowing the argument exists.
Testing authorisations specifically
Psychological and neuropsychological testing deserves separate treatment because it is authorised differently from everything else. Payers commonly authorise a number of hours or units rather than a service, and those hours cover a defined scope — administration, scoring, interpretation and report writing may be treated separately or bundled depending on the plan.
Two failure modes follow. Exceeding authorised units mid-battery leaves unbillable work already performed. And authorising the assessment without authorising interpretation and report time leaves the most time-consuming component uncovered. Requesting explicitly by code and by hours, and confirming what is included, avoids both.
Building the tracking
Authorisation tracking fails in the same way denial management does — it is nobody's job until it is urgent. What makes it survivable is small.
- Record authorised units and dates in a field the scheduling system can see, not in a note.
- Alert at a threshold before exhaustion, measured in sessions rather than days.
- Assign one owner for renewals rather than expecting each clinician to track their own.
- Reconcile monthly: authorised units against units actually billed, which surfaces both overruns and unused authorisations.
Telling the client
Authorisation problems land on clients even though they are payer-provider matters. A client who learns mid-course that their sessions are no longer covered experiences that as a rupture in treatment, not as an administrative issue.
Where an authorisation is pending, expiring or denied, say so early and say what happens next — whether sessions continue while an appeal runs, what the self-pay rate would be if coverage ends, and who is doing what. Clinically this matters more than it sounds: an unexplained interruption in treatment is its own event, and clients frequently interpret it as rejection.
Authorisation is not a clinical judgement
A distinction worth holding onto. A payer declining to authorise a level of care has decided what it will fund. It has not decided what the client needs, and the two are frequently different.
The clinical record should reflect your judgement, not the payer's. Where you believe a client requires a level of care the payer will not fund, document that assessment and the reasoning — both because it is true and because it is the basis of any appeal. A chart that quietly conforms to what was authorised loses the argument before it starts.
Verified 29 July 2026. Transaction standards (X12 270/271, 835, 837) are set federally under HIPAA; coverage, authorisation requirements, timely-filing windows and appeal rights are set by individual payers and by state law, and vary by contract. Figures described as typical are illustrative, not guarantees. Primary references: CMS billing guidance; X12 code lists; HHS HIPAA. This page is billing reference, not legal or coding advice.