Healthcare Integrations — Taction Software

Payer API Integration: CMS Interoperability Rule Compliance

Payer API integration helps health plans meet CMS interoperability requirements while giving members, providers and other payers secure access to data. Taction Software builds FHIR-based Patient Access, Provider Directory, Provider Access and Payer-to-Payer APIs for payers, using CARIN and Da Vinci implementation guides. Requirements come from the CMS Interoperability and Patient Access Final Rule, CMS-9115-F, and the Interoperability and Prior Authorization Final Rule, CMS-0057-F. This page reflects our understanding as of September 2026. Talk to our payer API team about compliance.

View All Services

CMS Rules Behind Payer APIs

Two CMS rules drive most payer API requirements. CMS-9115-F, finalized in 2020, required Patient Access and Provider Directory APIs for many payers, with enforcement beginning in 2021. CMS-0057-F, finalized in January 2024, expanded Patient Access requirements and added Provider Access, Payer-to-Payer and Prior Authorization APIs, generally by January 2027. Our healthcare interoperability consulting team helps payers map these requirements to practical delivery plans. Each rule is summarized below with key dates.

Impacted Payers

Impacted payers generally include Medicare Advantage organizations, state Medicaid and CHIP programs, Medicaid and CHIP managed care plans and certain qualified health plan issuers. Requirements differ by payer type and API.

CMS-9115-F Requirements

The 2020 rule required Patient Access and Provider Directory APIs using FHIR, supporting member access to claims and clinical data and public access to provider directory information. Many payers already comply.

CMS-0057-F Requirements

The 2024 rule adds Provider Access, Payer-to-Payer and Prior Authorization APIs, expands Patient Access content with prior authorization information and adds reporting requirements, generally due January 2027. Timelines vary by payer.

Standards Referenced by CMS

CMS requires HL7 FHIR R4, SMART on FHIR, OpenID Connect and US Core, and recommends implementation guides from CARIN and Da Vinci for specific payer data exchange use cases. Check current versions.

Date-Stamped Compliance

Regulatory timelines, enforcement policies and recommended guides can change. Record when you verified requirements, and review CMS guidance regularly as deadlines approach, because stale assumptions create compliance risk. Review guidance quarterly.

Patient Access and Provider Directory APIs

The Patient Access API lets members use third-party apps to access their claims, encounters, clinical data and, under newer requirements, prior authorization information. The Provider Directory API publishes provider network information publicly. Both have been required for many payers since 2021 and remain foundations for later APIs. Our FHIR integration team builds these APIs using CARIN, Da Vinci and US Core implementation guides. Each component is explained below in more detail.

Patient Access API

Members authorize apps through SMART on FHIR to retrieve claims, encounters and clinical data. The API must handle member identity, consent, app registration and secure access at scale. Scalability matters here.

CARIN Blue Button Guide

The CARIN Blue Button implementation guide defines how claims and encounter data are shared through ExplanationOfBenefit resources, giving members consistent access across payers and consumer applications. Validate resources against the guide.

Clinical Data With US Core and PDex

Clinical data shared through Patient Access uses US Core profiles, with Da Vinci PDex guidance for payer clinical data exchange, helping apps interpret information consistently. Validation keeps shared data consistent.

Provider Directory API

The Provider Directory API publishes provider names, locations, specialties and network participation publicly. The Da Vinci PDex Plan-Net guide defines structures commonly used for directory data. Keep directory data current.

Formulary Information

Some payers must share formulary data through APIs. The Da Vinci US Drug Formulary guide supports structured drug coverage information that apps and members can use during care decisions. Confirm requirements.

Provider Access and Payer-to-Payer APIs

CMS-0057-F adds APIs that connect payers with providers and other payers. The Provider Access API lets in-network providers access member data for treatment, while the Payer-to-Payer API transfers member data when people change plans. Both depend on accurate attribution, consent handling and member matching. These APIs also connect with prior authorization data. Our healthcare API development team builds the services, matching logic and monitoring they require. Our EHR/EMR integration team supports the provider side.

Provider Access API

The Provider Access API lets in-network providers retrieve data for attributed patients, including claims, clinical data and prior authorization information, supporting care coordination and treatment decisions. Access must follow attribution rules.

Attribution and Opt-Out

Provider Access depends on attributing members to providers, and members may opt out under the rule. Accurate attribution and opt-out handling are essential for compliant and useful data sharing. Audit these regularly.

Payer-to-Payer API

The Payer-to-Payer API exchanges member data between payers when members change plans, with member permission, supporting continuity of care and reducing repeated prior authorizations. Consent and timelines must be tracked carefully.

Member Matching

Payer-to-payer exchange requires matching members across organizations. The Da Vinci member matching approach supports consistent identification, reducing mismatches that could expose data to the wrong person. Test matching logic thoroughly.

Bulk Data Considerations

Provider Access and Payer-to-Payer exchanges can involve large data volumes. FHIR Bulk Data approaches support efficient transfers, but require careful authorization, performance testing and error handling. Plan capacity and throughput carefully.

Our Payer API Integration Services

Payer API compliance involves more than publishing endpoints. Data must be mapped from claims, clinical and utilization management systems, members must be matched and consent managed, and APIs must perform reliably at scale. We help payers plan, build, test and operate compliant APIs, connecting them with existing data platforms. Security matters throughout, following HIPAA technical safeguards and CMS security expectations for member data. Each service is described below in more detail.

Data Mapping From Payer Systems

We map claims, encounters, clinical data, provider directories and authorization records into FHIR resources, validating output against CARIN, Da Vinci and US Core profiles. Mapping gaps are documented and resolved.

API Build and Hosting

We build and host FHIR APIs with SMART authorization, app registration, rate limiting and monitoring, using HIPAA-eligible cloud services configured for security and performance. Load testing confirms performance at scale.

Consent, Identity and Matching

We implement member identity verification, consent and opt-out handling, and member matching workflows, protecting data while supporting the access CMS requires. Every access decision is logged for audit and member inquiries.

Testing and Conformance

We test APIs against implementation guides using automated validators and partner testing, preparing evidence that APIs meet required standards and perform reliably. Test evidence supports internal compliance reviews and audits.

Compliance Monitoring

We track API readiness, usage, errors and regulatory deadlines, helping payers report progress to leadership and respond quickly when CMS guidance changes. Monthly reports summarize status clearly for executive stakeholders.

Frequently Asked Questions

What is payer API integration?

Payer API integration is building and connecting FHIR-based APIs that let health plans share data with members, providers and other payers. It covers Patient Access, Provider Directory, Provider Access, Payer-to-Payer and Prior Authorization APIs required by CMS interoperability rules for impacted payers.

What is the CMS Patient Access API?

The Patient Access API lets health plan members use third-party apps to access their claims, encounters, clinical data and prior authorization information. It uses FHIR R4, SMART on FHIR and implementation guides such as CARIN Blue Button, and has been required for many payers since 2021.

What is the Provider Directory API?

The Provider Directory API publishes provider network information, such as names, locations, specialties and network participation, through a public FHIR API. The Da Vinci PDex Plan-Net guide is commonly used for directory data, helping apps and members find in-network providers accurately.

What APIs does CMS-0057-F require?

CMS-0057-F requires impacted payers to implement Provider Access, Payer-to-Payer and Prior Authorization APIs and expand Patient Access API content, generally by January 2027. It also sets prior authorization decision timeframes and reporting requirements. Confirm current details and deadlines with CMS guidance.

What is the CARIN Blue Button implementation guide?

The CARIN Blue Button implementation guide defines how payers share claims and encounter data with consumers using FHIR ExplanationOfBenefit resources. It helps apps display consistent claims information across different health plans, supporting CMS Patient Access API requirements. Adoption is broad.

How long does payer API implementation take?

Payer API projects often take several months, depending on data sources, number of APIs, existing FHIR infrastructure and testing needs. Data mapping, member matching and conformance testing usually take the most time. Starting early helps payers meet January 2027 deadlines without rushed implementations.

Preparing for CMS Payer API Deadlines?

Our integration engineers are ready to help. Free consultation, no obligation.