Do you want more ideas about this?

Schedule a Consultation

Utilization review management breaks down outside a behavioral health EHR because the information a reviewer needs, authorization status, level of care, clinical justification, and consent scope, lives in systems that do not talk to each other. A biller sees the claim. A clinician writes the note. A UR specialist tracks the review date, often in a spreadsheet nobody else opens. None of those three views update each other automatically, so a level-of-care change made in a clinical note does not reach the authorization record, and an authorization that lapses does not stop a claim from going out at the old rate. For a compliance or finance leader evaluating a behavioral health EHR, the practical question isn’t whether the system can store an authorization number: it’s whether utilization review management runs inside the same record as clinical documentation and billing, so a review deadline, a Part 2 consent expiration, or a level-of-care mismatch surfaces before it becomes a denial instead of after.

What does utilization review management actually cover in behavioral health?

Utilization review management covers four connected activities: initial authorization at admission, concurrent review while the patient is still in care, step-down authorization when the level of care changes, and denial or appeal support when a payer pushes back. Prior authorization is one piece of that, the initial approval, not the whole workflow.

  • Initial authorization: confirm the requested level of care, benefits, and clinical justification before or at admission.
  • Concurrent review: re-justify medical necessity on a cadence the payer sets, tied to how the patient is actually progressing.
  • Step-down authorization: move the authorization with the patient when they step from residential to PHP, PHP to IOP, or IOP to outpatient.
  • Denial and appeal support: track why a request was denied and whether the same reason is repeating across other claims.

Each of the four pulls on a different part of the organization: clinical staff for the justification, UR or a designated staff member for the payer submission, and billing for making sure the claim reflects what was actually authorized. For clinical staff and UR specialists specifically, that justification work often happens twice: once in the chart, for the treatment plan and progress notes, and again for a reviewer or a payer portal that doesn’t pull from the same record, turning routine documentation into a second write-up every review cycle.

Why does utilization review management break down on generic systems or spreadsheets?

UR breakdown

It breaks down because a spreadsheet does not know when a clinical note changes, and a billing system does not know when an authorization is about to expire. Each team works from its own version of the truth, and none of them update when the underlying case changes.

Nationally, the administrative load behind prior authorization is well documented. The American Medical Association’s 2025 physician survey found that 95% of physicians report prior authorization delays access to care, and 79% report it can lead a patient to abandon treatment altogether[1]. Physicians in the survey also reported significant weekly time spent on the process, and 94% said it contributes to burnout.

Part of what drives that is clinical, not just administrative. In general medicine, a diagnosis typically carries the treatment plan forward, and individual visits draw comparatively little scrutiny. In behavioral health, every session has to independently support its own medical necessity, which is why concurrent review cadence runs so aggressive at certain levels of care, and why a single documentation gap compounds denial risk instead of just delaying a claim. That also means a single episode of care can require authorization not just once at admission, but again at every level-of-care transition, on a review cadence set by clinical acuity rather than a fixed calendar date. That is a different tracking problem than a single annual authorization, and it is the reason a shared spreadsheet or a generic task list stops being reliable past a handful of active cases.

In practice, that shows up in a handful of recurring ways:

  • The expired authorization: care continues past the authorized end date because no one owned the renewal, and those days are usually unrecoverable.
  • The level-of-care mismatch: the patient stepped down clinically but billing continued at the higher level, or the authorization was for one level while a different one was delivered.
  • Stale documentation at review: the reviewer hears information from intake while the concurrent review call is happening three weeks later.
  • The missed handoff: clinical, UR, and billing each assume someone else is tracking the next review date.
  • The audit trail gap: CARF and Joint Commission both expect documented medical necessity behind every continued-stay decision, and when that connection lives outside the clinical record, it’s missing exactly when a chart review goes looking for it.

None of these failures are exotic. They are the ordinary result of authorization, clinical documentation, and billing living in three different tools that were never designed to update each other, and the fix is rarely about hiring more staff to check spreadsheets more often. It is about removing the manual handoff between clinical and administrative teams so it stops being possible to lose track in the first place.

How does CMS-0057-F change utilization management timelines starting in 2026?

It puts a hard clock on most payer decisions. Since January 1, 2026, impacted payers, Medicare Advantage organizations, Medicaid and CHIP managed care plans, and state Medicaid fee-for-service programs, must decide urgent prior authorization requests within 72 hours and standard requests within 7 calendar days. Qualified health plan issuers on the federal exchanges are impacted payers under the rule too, but CMS specifically excluded them from this 72-hour and 7-day decision clock, so they remain subject to the rule’s other requirements. Every impacted payer, including QHP issuers, must give a specific reason for every denial[2].

Two more milestones follow. Payers must also begin publicly reporting prior authorization approval and denial metrics in 2026, and by January 1, 2027, they must support electronic prior authorization through FHIR-based APIs, replacing fax and portal submission with a standardized electronic request and response. The rule sets requirements for payers, not providers, so the operational question for a behavioral health program is whether its own authorization tracking can keep pace with a payer that is now required to respond in days rather than weeks.

What makes SUD authorization a two-track process?

For patients receiving both mental health and substance use disorder treatment, that two-track structure often starts before Part 2 ever enters the picture. SUD services are commonly billed under a separate H-code series, H0015 for IOP, for example[3], while mental health services run through standard behavioral health CPT codes, and many payers route each set of codes to a different benefits administrator through a carve-out arrangement. A single patient in a co-occurring program can end up with two authorization numbers, two review cadences, and two payer contacts for what is clinically one episode of care.

Layered on top of that administrative split is a consent requirement unique to the SUD side. The clinical documentation that supports a continued-stay request, progress notes, dimensional assessments, diagnosis, is protected under 42 CFR Part 2, and disclosing it to a payer for utilization review requires the patient’s consent, tracked separately from the authorization itself.

A 2024 update to Part 2 aligned it more closely with HIPAA: instead of a new consent for every individual disclosure, a Part 2 program can now use a single patient consent to cover future disclosures for treatment, payment, and healthcare operations, which includes sending documentation to a payer for a UR determination[4]. Compliance with the updated rule has been required since February 16, 2026. The simplification does not remove the consent requirement, it changes how many times a program has to obtain it. A UM workflow for an SUD program still needs to track two dates for the same episode: when the payer’s authorization expires, and when the patient’s consent to disclose the underlying record expires or needs reconfirming. A generic EHR built for general medical or non-SUD behavioral health rarely tracks the second one at all.

How does level-of-care-specific reauthorization actually work?

Level-of-care reauthorization is not a fixed renewal date, it is a clinical reassessment. For SUD treatment, payers and state Medicaid programs largely use the ASAM Criteria’s six dimensions, covering withdrawal risk, biomedical status, and recovery environment among others, to decide whether the current level of care is still justified, and the assessment has to be redone at every continued-stay review, not just at admission.

The higher the intensity of care, the tighter the review cycle tends to run, since a payer authorizing residential or medically monitored withdrawal management wants more frequent evidence that the level of care is still necessary than a payer authorizing outpatient sessions. Our breakdown of the ASAM Criteria covers how those dimensions map to billing and where documentation gaps tend to show up.

Consider a patient moving from residential to a partial hospitalization program. The clinical team documents the step-down rationale using the ASAM dimensions, and PHP carries a different review cadence than residential. If the authorization record does not move with that transition, two things can go wrong: billing may keep submitting claims at the residential level after the clinical record shows PHP, or the new PHP authorization may not exist yet, leaving days unauthorized between the step-down and the payer’s approval. Either error is avoidable if the level-of-care change entered by the clinician is the same data point the authorization and the claim are built from.

Still tracking reviews in three places?

Authorization status, review cadence, and, for SUD patients, consent scope often live in three different places: a spreadsheet, a payer portal, and a clinician’s memory. blueBriX’s behavioral health team can walk through what utilization review management looks like when it runs inside your clinical and billing record instead of around it. Book a walkthrough to see it against your own program’s authorization mix.

Schedule a demo

Where does utilization management intersect with mental health parity compliance?

It intersects directly. Prior authorization and concurrent review are both named as nonquantitative treatment limitations, or NQTLs, under the federal parity law, which means a health plan generally cannot apply UM more strictly to behavioral health or SUD benefits than it applies to comparable medical and surgical benefits[5].

The Mental Health Parity and Addiction Equity Act has required this since 2008, and a 2021 law added a specific requirement that plans document a comparative analysis showing their UM processes for behavioral health are no more restrictive than for medical and surgical care[6]. A 2024 update expanded what that analysis has to contain, but in May 2025, the federal departments that enforce the law paused enforcement of the new provisions in that 2024 update while a legal challenge proceeds[7]. The underlying obligation, that a comparative analysis exists and that UM is not more restrictive for behavioral health, comes from the 2013 rule and the 2021 law, and neither of those has been paused. For a compliance leader, that distinction matters: the newer documentation standard is on hold, not the obligation itself.

In practice, the comparison plans have to be able to defend is process-level: if a payer requires concurrent review every two weeks for a behavioral health level of care but only requires it quarterly for a comparable medical or surgical level of care, that is the kind of disparity the comparative analysis requirement is built to catch. Utilization management data, how often reviews are required, how often they are denied, and for what stated reason, is also the evidence a compliance team needs on hand if a plan’s UM practices are ever questioned.

What does utilization review management need to do differently inside a behavioral health EHR?

It needs to read from the same record everyone else already uses. A UM workflow that lives in a separate authorization tool still requires someone to manually reconcile it against the clinical note and the claim, which is the same handoff gap that causes most of the problems described above.

In practice, that means authorization and level of care tied directly to the treatment plan rather than tracked in a parallel document, review dates that surface as a task inside the clinician’s or biller’s existing workflow rather than a separate calendar, and, for SUD programs, Part 2 consent status tracked alongside, but distinct from, the payer authorization for that same episode. Authorization mismatches are a documented and recurring cause of behavioral health denials, particularly for patients enrolled in more than one program or level of care at once, where the authorization tied to one payer and plan ID does not automatically reconcile with a second. blueBriX’s behavioral health EHR is designed to tie authorization to the treatment plan for this reason, rather than running utilization management as a separate module. The evaluation question worth asking a vendor isn’t whether the system can store an authorization number: it’s whether a level-of-care change entered by a clinician updates the authorization record without a second person re-entering it.

The same principle applies to the documentation feeding a continued-stay request. blueBriX’s standardized assessment library, PHQ-9, GAD-7, Columbia C-SSRS, and others, is designed to auto-score and trend over time as part of the clinical record, drawing the medical necessity narrative a reviewer needs from data already captured during the session rather than a separate write-up assembled after the fact.

This is not a hypothetical fix. Fair Oaks Psychiatric Associates, a psychiatric practice previously losing claims to missed pre-authorizations and unresolved payer credentialing gaps, worked with blueBriX on a broader billing overhaul that included rebuilding its pre-authorization workflow and expanding credentialing. Within 90 business days, the practice recovered $120,000 in aged receivables, grew revenue 33%, and cut denials 4%.

blueBriX also separates the software layer from a staffed one: its revenue cycle management services team is available to track authorization windows, initiate renewals, and manage the appeal process as a service, distinct from and in addition to the software automation described above.

There is also a compliance angle worth building in from the start: since CMS-0057-F now requires payers to state a specific reason for every denial, a UM workflow that captures and categorizes those reasons systematically turns a new payer obligation into usable internal data, rather than another line item in a denial letter nobody reviews in aggregate.

What should a self-check cover before your next utilization review cycle?

  • Before the review: confirm the current authorization end date, the level of care it covers, and whether a step-down happened since the last review.
  • Before you disclose documentation: for SUD patients, confirm the Part 2 consent on file actually covers disclosure to this payer for this purpose.
  • After a denial: log whether the cause was a missed date, a level-of-care mismatch, a documentation gap, or a parity-related restriction, before resubmitting or appealing.

What should you look for when evaluating a BH EHR's utilization management capability?

  • Authorization tied to the treatment plan: a level-of-care change should update the authorization record automatically, not through a second manual entry.
  • Level-of-care-aware reauthorization logic: the system should recognize that concurrent review cadence differs by level of care and trigger the right review window automatically at each transition, rather than run one fixed reminder cycle across residential, PHP, IOP, and outpatient.
  • Documentation-to-authorization linkage: progress notes, treatment plan updates, and assessment scores should feed the medical necessity narrative a reviewer needs directly, without re-typing clinical detail into a second system.
  • Separate tracking for Part 2 consent: for SUD programs, consent status should be visible alongside, but not merged with, payer authorization status.
  • Review-date visibility across roles: clinical, UR, and billing staff should see the same upcoming review date instead of three different ones.
  • Pre-submission authorization checking: authorization status should be checked automatically before a claim generates, flagging a mismatch for review instead of letting an expired or missing authorization reach the payer as a denial.
  • Denial-reason categorization: the system should let you tell, at a glance across your payer mix, whether a denial pattern is a date, a documentation gap, or a level-of-care mismatch.

Our guide to questions worth asking a behavioral health EHR vendor goes deeper on this evaluation, including how to test FHIR-readiness ahead of CMS-0057-F’s 2027 deadline.

Conclusion: utilization management as infrastructure, not a side process

Utilization management in behavioral health carries more moving parts than a single prior authorization: level-of-care-specific reauthorization, a faster federal decision clock under CMS-0057-F, and, for SUD programs, a consent track running alongside the payer authorization track. None of that is manageable indefinitely from a spreadsheet. The programs that hold up under it are the ones where authorization, clinical documentation, and billing already live in the same record, so a review deadline or a consent expiration surfaces as part of the workflow clinicians and billers are already in, not as a separate list someone has to remember to check.

See how utilization management works when it is built into your behavioral health EHR instead of managed around it.

About the author

Kapil Nandakumar

Kapil Nandakumar is a Product Owner and Marketing Leader at blueBriX, where he drives product strategy and go-to-market execution for a platform purpose-built for US behavioral health and integrated care. With over 13 years of experience across product ownership and digital marketing, he specializes in translating the operational complexity of payer requirements, value-based care models, and behavioral health workflows into structured, adaptable product capabilities. At blueBriX, he has contributed to workflow-driven capabilities that support revenue integrity, documentation accuracy, and care coordination for behavioral health organizations. He is a Certified Scrum Product Owner (CSPO), applying that product discipline to how behavioral health organizations adopt and scale technology.

Contributor

Suresh Kumar

Suresh Kumar M is Vice President of Revenue Cycle Strategy at blueBriX, where he leads revenue cycle strategy for organizations navigating complex billing and reimbursement operations. He holds an MBA and earned his AAPC Certified Professional Biller (CPB) certification, building on more than 18 years in healthcare revenue cycle management across physician practices, specialty clinics, behavioral health organizations, and hospitals. Under the RCM strategy he leads at blueBriX, client engagements have delivered measurable results: reducing accounts receivable days from over 120 to 35 within three weeks for one specialty practice and driving a 6% revenue increase alongside a 15% reduction in coding-related denials within 60 days for a 140-bed hospital. His work spans billing operations, denial management, accounts receivable, and credentialing, applying EHR, EDI, and AI-driven automation to modernize how that work gets done.

References

  1. American Medical Association (AMA). (2026). 2025 AMA Prior Authorization Physician Survey. Nationwide survey of 1,000 practicing physicians on prior authorization’s effect on patient care and physician burden. https://www.ama-assn.org/system/files/prior-authorization-survey.pdf
  2. Centers for Medicare & Medicaid Services (CMS). (2024, updated 2026). CMS Interoperability and Prior Authorization Final Rule (CMS-0057-F). Sets payer decision timelines and denial-reason requirements for prior authorization. https://www.cms.gov/cms-interoperability-and-prior-authorization-final-rule-cms-0057-f
  3. Centers for Medicare & Medicaid Services (CMS). Healthcare Common Procedure Coding System (HCPCS). CMS establishes and maintains the national HCPCS Level II code set, the alpha-numeric codes (including the H-code series used for substance use disorder services) that sit alongside CPT codes. https://www.cms.gov/medicare/coding-billing/healthcare-common-procedure-system
  4. U.S. Department of Health and Human Services (HHS). (2024, updated 2026). Understanding Confidentiality of Substance Use Disorder (SUD) Patient Records, or “Part 2.” Describes the 2024 final rule aligning Part 2 consent and disclosure requirements with HIPAA. https://www.hhs.gov/hipaa/part-2/index.html
  5. Centers for Medicare & Medicaid Services (CMS). The Mental Health Parity and Addiction Equity Act (MHPAEA). Defines nonquantitative treatment limitations, including prior authorization and concurrent review, subject to parity requirements. https://www.cms.gov/marketplace/private-health-insurance/mental-health-parity-addiction-equity
  6. U.S. Department of Labor (DOL), Employee Benefits Security Administration. Fact Sheet: Final Rules under MHPAEA. Describes the 2024 final rule’s comparative analysis requirements for NQTLs. https://www.dol.gov/agencies/ebsa/about-ebsa/our-activities/resource-center/fact-sheets/final-rules-under-the-mental-health-parity-and-addiction-equity-act-mhpaea
  7. U.S. Departments of Labor, Health and Human Services, and the Treasury. (2025, May 15). Statement Regarding Enforcement of the Final Rule on Requirements Related to MHPAEA. Official statement on the scope of non-enforcement of the 2024 rule’s new provisions. https://www.dol.gov/sites/dolgov/files/ebsa/laws-and-regulations/laws/mental-health-parity/statement-regarding-enforcement-of-the-final-rule-on-requirements-related-to-mhpaea.pdf

Frequently asked questions

Utilization review is the payer-facing part: submitting a case for approval and responding to a payer’s request for more information. Utilization management is the broader internal workflow, including tracking review dates, coordinating between clinical and billing teams, and managing step-down authorizations, that makes utilization review possible.

It depends on the level of care and the payer, not a fixed schedule. Higher-intensity levels of care, such as residential treatment or medically monitored withdrawal management, generally require more frequent continued-stay review than outpatient or intensive outpatient care, and the specific cadence is set by the payer or state Medicaid program.

CMS-0057-F requires impacted payers to issue urgent decisions within 72 hours and standard decisions within 7 calendar days starting in 2026, and to publicly report their prior authorization metrics. The rule creates federal compliance obligations for the payer; it does not change a provider’s own responsibility to track and follow up on outstanding requests.

Utilization management is part of blueBriX’s behavioral health EHR rather than a separate product. Authorization and level of care are tied directly to the treatment plan, so a clinical update is designed to flow through without manual re-entry into a separate authorization record.

blueBriX supports program-level data partitioning and 42 CFR Part 2 consent workflow management, designed to help ensure substance use disorder records are disclosed to a payer only with the required patient consent on file, with that consent documentation maintained within the EHR for audit purposes.

Related articles & blogs

ASAM criteria levels of care: what behavioral health organizations need to know

A practical guide to how ASAM criteria work, what each level of care means for clinical and operational teams, and why the Fourth Edition matters for your program's documentation, authorization,…

Read blog
Prior authorization software for behavioral health programs

Prior authorization for behavioral health does not work like prior authorization anywhere else in healthcare: it recurs throughout treatment instead of once at the start. That is why a single…

Read blog
What the CMS 2027 prior authorization rule CMS-0057-F means for billing teams

CMS-0057-F is usually filed under β€œ2027 deadline.” That’s only half the rule. Operational requirements, faster decisions, specific denial reasons, and public metrics, have already been binding since January 1, 2026.…

Read blog