FHIR Prior Authorization for Behavioral Health: CRD, DTR, and PAS
Understand FHIR prior authorization for behavioral health through CRD, DTR, PAS, provider workflow, clinical evidence, human review, security, testing, fallback, and 2027 implementation planning.

On this page: Direct answer
Direct answer
FHIR prior authorization behavioral health: what operators need to know
Understand FHIR prior authorization for behavioral health through CRD, DTR, PAS, provider workflow, clinical evidence, human review, security, testing, fallback, and 2027 implementation planning. CRD asks what coverage or documentation requirements apply in context. DTR supports computable questionnaires and rules for documentation work.
FHIR prior authorization for behavioral health can connect three related jobs: discover payer requirements through Coverage Requirements Discovery, gather and review required documentation through Documentation Templates and Rules, and submit or inquire about the authorization through Prior Authorization Support. The guides do not eliminate payer variation, source-data gaps, clinical judgment, human review, privacy duties, or operational fallback.
For provider organizations, the useful unit is the full journey from an order or planned service to a reconciled decision and next action. Build a versioned standards architecture, keep payer and service scope explicit, map every material field to an authoritative source, protect sensitive records, test exceptions, and compare the electronic path with existing work before expanding.
Key takeaways
The short version
- CRD asks what coverage or documentation requirements apply in context.
- DTR supports computable questionnaires and rules for documentation work.
- PAS supports prior-authorization requests, inquiries, and responses using FHIR structures.
- FHIR exchange still requires identity, source, terminology, review, reconciliation, and failure controls.
- Treat guide versions and payer deviations as governed production dependencies.
1. FHIR prior authorization behavioral health workflow
| Stage | Standards role | Provider operating question |
|---|---|---|
| Plan care | Clinical and administrative context exists in provider systems | Are patient, coverage, provider, location, service, and intended action correctly identified? |
| Discover | CRD uses CDS Hooks and FHIR interactions to return coverage guidance | Is authorization required, what documentation is needed, and how current is the response? |
| Document | DTR can retrieve questionnaires and rules, prepopulate data, and support completion | Which facts came from which source, what is missing, and who must review? |
| Submit | PAS packages FHIR resources for a request and supports responses and inquiries | Was the correct request accepted, what proves it, and how are mappings handled? |
| Reconcile | Provider systems consume the response and update workflow | What exact service, site, dates, units, conditions, reason, deadline, or action was returned? |
| Continue | Inquiry, update, follow-up, renewal, or appeal proceeds | How will changed evidence, partial decisions, expiration, or downtime remain controlled? |
2. Understand CRD, DTR, and PAS without collapsing them
- CRD surfaces payer-specific coverage expectations during a provider workflow, including authorization or documentation needs
- DTR addresses documentation using FHIR questionnaires, rules, prepopulation, user interaction, storage, and downstream transfer
- PAS uses FHIR resources and operations for request, response, inquiry, and related interactions with X12 mapping considerations
- The guides depend on broader FHIR, US Core, SMART, CDS Hooks, terminology, security, payer, EHR, and transaction architecture
- Implementation guides can have trial-use status and multiple versions; implement the version required for the actual program
- A syntactically valid resource does not prove a response is complete, current, clinically appropriate, or reconciled
3. Map behavioral-health data and confidentiality boundaries
- 01
Scope the minimum context
Identify which member, coverage, practitioner, organization, facility, location, service, diagnosis, medication, encounter, plan, and document fields are needed.
- 02
Preserve provenance
Record source, author, observation or effective date, version, retrieval, transform, terminology mapping, missingness, conflict, and reviewer.
- 03
Protect sensitive records
Apply HIPAA, minimum necessary, Part 2, state law, consent, contract, access, segmentation, retention, disclosure, and audit requirements to the actual flow.
- 04
Require human authority
Keep clinical statements, uncertain interpretations, final packet approval, treatment decisions, and high-consequence actions with qualified people.
- 05
Reconcile downstream
Write back the exact payer response, source, conditions, limitations, and next work without implying approval beyond the written scope.

4. Test more than happy-path conformance
| Test family | Example | Required result |
|---|---|---|
| Identity | Duplicate member, changed coverage, multiple facilities, or ambiguous provider | No wrong-context request; correction is traceable |
| Requirements | No requirement, changed criteria, unsupported hook, or unavailable service | Current source and uncertainty remain visible; fallback opens |
| Documentation | Missing note, conflicting values, stale measure, or failed prepopulation | No fabricated answer; review and provenance are preserved |
| Transport | Timeout after submit, lost response, repeated message, or partial attachment | Idempotent recovery, inquiry, duplicate prevention, and reconciliation |
| Decision | Partial approval, denial, additional-information request, correction, or expiration | Exact scope, reason, clock, owner, and next workflow |
| Security | Expired token, excessive scope, compromised credential, or tenant-boundary attempt | Access denied or contained, logged, investigated, and recoverable |
5. Build a provider implementation roadmap
- Scope impacted payers, products, services, sites, providers, systems, channels, standards versions, and owners
- Baseline current work, wait, errors, requests, decisions, denials, access delays, and operating cost
- Choose a bounded cohort, complete architecture and risk review, configure sources and roles, train staff, and validate fallback
- Run conformance, integration, operational, usability, accessibility, privacy, security, failure, recovery, and reconciliation tests
- Launch with case reconciliation and monitor eligible use, usable responses, handling, rework, outcomes, safety, and communication
- Expand one payer, service, site, provider group, or workflow condition at a time under regression gates
Common questions
Answers before you build.
What is FHIR prior authorization?+
It is an approach to exchanging prior-authorization requirements, documentation, requests, inquiries, and responses using HL7 FHIR and related implementation guides, security patterns, and workflow standards. The exact architecture depends on the payer and use case.
What are CRD, DTR, and PAS?+
Coverage Requirements Discovery retrieves payer guidance; Documentation Templates and Rules supports documentation gathering; Prior Authorization Support handles FHIR request, inquiry, and response interactions. They address different stages of a connected workflow.
Does FHIR automate clinical documentation?+
DTR can support questionnaires, rules, and prepopulation, but organizations still need authoritative sources, provenance, missing-data handling, qualified authorship and review, correction, and safeguards against unsupported or stale answers.
Why is behavioral health implementation different?+
The standards are not behavioral-health-only, but workflows may involve level transitions, concurrent review, sensitive records, Part 2, multiple settings, limited capacity, payer variation, and high-consequence clinical or access boundaries.
Practical closeout
Use this operator checklist.
- CRD asks what coverage or documentation requirements apply in context.
- DTR supports computable questionnaires and rules for documentation work.
- PAS supports prior-authorization requests, inquiries, and responses using FHIR structures.
- FHIR exchange still requires identity, source, terminology, review, reconciliation, and failure controls.
- Treat guide versions and payer deviations as governed production dependencies.
Continue through the cluster
Verified customer case studies are added only with customer permission and supporting evidence; none is implied by these operational examples.
Sources & methodology
Trace the operational claims.
Marsa Health Editorial reviewed the primary and research sources below on July 22, 2026. We translate them into workflow controls, distinguish proposals from final rules, and flag where plan, program, state, contract, or clinical requirements vary.
- 01CMS Interoperability and Prior Authorization Final Rule CMS-0057-F Centers for Medicare & Medicaid ServicesCurrent implementation dates, decision timeframes, denial-reason requirements, metrics, and API provisions for impacted payers.Accessed or rechecked July 22, 2026
- 02Electronic Prior Authorization Centers for Medicare & Medicaid ServicesCurrent CMS provider-readiness guidance for 2027 electronic prior authorization, EHR questions, FHIR testing, and workflow preparation.Accessed or rechecked July 22, 2026
- 03Prior Authorization API Workflow Centers for Medicare & Medicaid ServicesCMS workflow overview for coverage requirements discovery, documentation templates and rules, and prior authorization support APIs.Accessed or rechecked July 22, 2026
- 04Provider prior authorization API: prior authorization support ASTP/Office of the National Coordinator for Health ITCurrent health IT certification test method and standards references for provider prior authorization API capabilities.Accessed or rechecked July 22, 2026
- 05Da Vinci Coverage Requirements Discovery FHIR Implementation Guide Health Level Seven InternationalOfficial HL7 implementation guide for discovering payer-specific coverage and documentation requirements within a provider workflow. Implementers must verify the current published version and CMS-required standards.Accessed or rechecked July 22, 2026
- 06Da Vinci Documentation Templates and Rules FHIR Implementation Guide Health Level Seven InternationalOfficial HL7 implementation guide for expressing, retrieving, populating, and reviewing payer documentation requirements using FHIR questionnaires and related rules.Accessed or rechecked July 22, 2026
- 07Da Vinci Prior Authorization Support FHIR Implementation Guide Health Level Seven InternationalCurrent official HL7 guide for FHIR prior-authorization submission, inquiry, and response workflows, including mappings and implementation considerations related to X12 transactions.Accessed or rechecked July 22, 2026
- 08Understanding Confidentiality of Substance Use Disorder Patient Records or Part 2 U.S. Department of Health and Human ServicesCurrent OCR overview of Part 2 scope, the 2024 final rule, the February 16, 2026 compliance date, enforcement, breach reporting, and model notices.Accessed or rechecked July 22, 2026
Organizational author. Editorial review covers source accuracy, search intent, workflow boundaries, and human-oversight requirements. This material is educational and does not provide clinical, legal, coding, or coverage advice.
No named clinical or legal expert reviewer is attributed to this version. Marsa Health does not invent reviewer credentials.
Read our editorial methodRevision history
What changed and when
July 22, 2026
Initial publication, source review, and operational editing.