Utilization review management breaks down outside a behavioral health EHR because the information a reviewer needs, authorization status, level of care, clinical justification, and consent scope, lives in systems that do not talk to each other. A biller sees the claim. A clinician writes the note. A UR specialist tracks the review date, often in a spreadsheet nobody else opens. None of those three views update each other automatically, so a level-of-care change made in a clinical note does not reach the authorization record, and an authorization that lapses does not stop a claim from going out at the old rate. For a compliance or finance leader evaluating a behavioral health EHR, the practical question isn’t whether the system can store an authorization number: it’s whether utilization review management runs inside the same record as clinical documentation and billing, so a review deadline, a Part 2 consent expiration, or a level-of-care mismatch surfaces before it becomes a denial instead of after.
What does utilization review management actually cover in behavioral health?
Utilization review management covers four connected activities: initial authorization at admission, concurrent review while the patient is still in care, step-down authorization when the level of care changes, and denial or appeal support when a payer pushes back. Prior authorization is one piece of that, the initial approval, not the whole workflow.
- Initial authorization: confirm the requested level of care, benefits, and clinical justification before or at admission.
- Concurrent review: re-justify medical necessity on a cadence the payer sets, tied to how the patient is actually progressing.
- Step-down authorization: move the authorization with the patient when they step from residential to PHP, PHP to IOP, or IOP to outpatient.
- Denial and appeal support: track why a request was denied and whether the same reason is repeating across other claims.
Each of the four pulls on a different part of the organization: clinical staff for the justification, UR or a designated staff member for the payer submission, and billing for making sure the claim reflects what was actually authorized. For clinical staff and UR specialists specifically, that justification work often happens twice: once in the chart, for the treatment plan and progress notes, and again for a reviewer or a payer portal that doesn’t pull from the same record, turning routine documentation into a second write-up every review cycle.
Why does utilization review management break down on generic systems or spreadsheets?

It breaks down because a spreadsheet does not know when a clinical note changes, and a billing system does not know when an authorization is about to expire. Each team works from its own version of the truth, and none of them update when the underlying case changes.
Nationally, the administrative load behind prior authorization is well documented. The American Medical Association’s 2025 physician survey found that 95% of physicians report prior authorization delays access to care, and 79% report it can lead a patient to abandon treatment altogether[1]. Physicians in the survey also reported significant weekly time spent on the process, and 94% said it contributes to burnout.
Part of what drives that is clinical, not just administrative. In general medicine, a diagnosis typically carries the treatment plan forward, and individual visits draw comparatively little scrutiny. In behavioral health, every session has to independently support its own medical necessity, which is why concurrent review cadence runs so aggressive at certain levels of care, and why a single documentation gap compounds denial risk instead of just delaying a claim. That also means a single episode of care can require authorization not just once at admission, but again at every level-of-care transition, on a review cadence set by clinical acuity rather than a fixed calendar date. That is a different tracking problem than a single annual authorization, and it is the reason a shared spreadsheet or a generic task list stops being reliable past a handful of active cases.
In practice, that shows up in a handful of recurring ways:
- The expired authorization: care continues past the authorized end date because no one owned the renewal, and those days are usually unrecoverable.
- The level-of-care mismatch: the patient stepped down clinically but billing continued at the higher level, or the authorization was for one level while a different one was delivered.
- Stale documentation at review: the reviewer hears information from intake while the concurrent review call is happening three weeks later.
- The missed handoff: clinical, UR, and billing each assume someone else is tracking the next review date.
- The audit trail gap: CARF and Joint Commission both expect documented medical necessity behind every continued-stay decision, and when that connection lives outside the clinical record, it’s missing exactly when a chart review goes looking for it.
None of these failures are exotic. They are the ordinary result of authorization, clinical documentation, and billing living in three different tools that were never designed to update each other, and the fix is rarely about hiring more staff to check spreadsheets more often. It is about removing the manual handoff between clinical and administrative teams so it stops being possible to lose track in the first place.
How does CMS-0057-F change utilization management timelines starting in 2026?
It puts a hard clock on most payer decisions. Since January 1, 2026, impacted payers, Medicare Advantage organizations, Medicaid and CHIP managed care plans, and state Medicaid fee-for-service programs, must decide urgent prior authorization requests within 72 hours and standard requests within 7 calendar days. Qualified health plan issuers on the federal exchanges are impacted payers under the rule too, but CMS specifically excluded them from this 72-hour and 7-day decision clock, so they remain subject to the rule’s other requirements. Every impacted payer, including QHP issuers, must give a specific reason for every denial[2].
Two more milestones follow. Payers must also begin publicly reporting prior authorization approval and denial metrics in 2026, and by January 1, 2027, they must support electronic prior authorization through FHIR-based APIs, replacing fax and portal submission with a standardized electronic request and response. The rule sets requirements for payers, not providers, so the operational question for a behavioral health program is whether its own authorization tracking can keep pace with a payer that is now required to respond in days rather than weeks.
What makes SUD authorization a two-track process?
For patients receiving both mental health and substance use disorder treatment, that two-track structure often starts before Part 2 ever enters the picture. SUD services are commonly billed under a separate H-code series, H0015 for IOP, for example[3], while mental health services run through standard behavioral health CPT codes, and many payers route each set of codes to a different benefits administrator through a carve-out arrangement. A single patient in a co-occurring program can end up with two authorization numbers, two review cadences, and two payer contacts for what is clinically one episode of care.
Layered on top of that administrative split is a consent requirement unique to the SUD side. The clinical documentation that supports a continued-stay request, progress notes, dimensional assessments, diagnosis, is protected under 42 CFR Part 2, and disclosing it to a payer for utilization review requires the patient’s consent, tracked separately from the authorization itself.
A 2024 update to Part 2 aligned it more closely with HIPAA: instead of a new consent for every individual disclosure, a Part 2 program can now use a single patient consent to cover future disclosures for treatment, payment, and healthcare operations, which includes sending documentation to a payer for a UR determination[4]. Compliance with the updated rule has been required since February 16, 2026. The simplification does not remove the consent requirement, it changes how many times a program has to obtain it. A UM workflow for an SUD program still needs to track two dates for the same episode: when the payer’s authorization expires, and when the patient’s consent to disclose the underlying record expires or needs reconfirming. A generic EHR built for general medical or non-SUD behavioral health rarely tracks the second one at all.
How does level-of-care-specific reauthorization actually work?
Level-of-care reauthorization is not a fixed renewal date, it is a clinical reassessment. For SUD treatment, payers and state Medicaid programs largely use the ASAM Criteria’s six dimensions, covering withdrawal risk, biomedical status, and recovery environment among others, to decide whether the current level of care is still justified, and the assessment has to be redone at every continued-stay review, not just at admission.
The higher the intensity of care, the tighter the review cycle tends to run, since a payer authorizing residential or medically monitored withdrawal management wants more frequent evidence that the level of care is still necessary than a payer authorizing outpatient sessions. Our breakdown of the ASAM Criteria covers how those dimensions map to billing and where documentation gaps tend to show up.
Consider a patient moving from residential to a partial hospitalization program. The clinical team documents the step-down rationale using the ASAM dimensions, and PHP carries a different review cadence than residential. If the authorization record does not move with that transition, two things can go wrong: billing may keep submitting claims at the residential level after the clinical record shows PHP, or the new PHP authorization may not exist yet, leaving days unauthorized between the step-down and the payer’s approval. Either error is avoidable if the level-of-care change entered by the clinician is the same data point the authorization and the claim are built from.
Still tracking reviews in three places?
Authorization status, review cadence, and, for SUD patients, consent scope often live in three different places: a spreadsheet, a payer portal, and a clinician’s memory. blueBriX’s behavioral health team can walk through what utilization review management looks like when it runs inside your clinical and billing record instead of around it. Book a walkthrough to see it against your own program’s authorization mix.
Schedule a demoWhere does utilization management intersect with mental health parity compliance?
It intersects directly. Prior authorization and concurrent review are both named as nonquantitative treatment limitations, or NQTLs, under the federal parity law, which means a health plan generally cannot apply UM more strictly to behavioral health or SUD benefits than it applies to comparable medical and surgical benefits[5].
The Mental Health Parity and Addiction Equity Act has required this since 2008, and a 2021 law added a specific requirement that plans document a comparative analysis showing their UM processes for behavioral health are no more restrictive than for medical and surgical care[6]. A 2024 update expanded what that analysis has to contain, but in May 2025, the federal departments that enforce the law paused enforcement of the new provisions in that 2024 update while a legal challenge proceeds[7]. The underlying obligation, that a comparative analysis exists and that UM is not more restrictive for behavioral health, comes from the 2013 rule and the 2021 law, and neither of those has been paused. For a compliance leader, that distinction matters: the newer documentation standard is on hold, not the obligation itself.
In practice, the comparison plans have to be able to defend is process-level: if a payer requires concurrent review every two weeks for a behavioral health level of care but only requires it quarterly for a comparable medical or surgical level of care, that is the kind of disparity the comparative analysis requirement is built to catch. Utilization management data, how often reviews are required, how often they are denied, and for what stated reason, is also the evidence a compliance team needs on hand if a plan’s UM practices are ever questioned.
What does utilization review management need to do differently inside a behavioral health EHR?
It needs to read from the same record everyone else already uses. A UM workflow that lives in a separate authorization tool still requires someone to manually reconcile it against the clinical note and the claim, which is the same handoff gap that causes most of the problems described above.
In practice, that means authorization and level of care tied directly to the treatment plan rather than tracked in a parallel document, review dates that surface as a task inside the clinician’s or biller’s existing workflow rather than a separate calendar, and, for SUD programs, Part 2 consent status tracked alongside, but distinct from, the payer authorization for that same episode. Authorization mismatches are a documented and recurring cause of behavioral health denials, particularly for patients enrolled in more than one program or level of care at once, where the authorization tied to one payer and plan ID does not automatically reconcile with a second. blueBriX’s behavioral health EHR is designed to tie authorization to the treatment plan for this reason, rather than running utilization management as a separate module. The evaluation question worth asking a vendor isn’t whether the system can store an authorization number: it’s whether a level-of-care change entered by a clinician updates the authorization record without a second person re-entering it.
The same principle applies to the documentation feeding a continued-stay request. blueBriX’s standardized assessment library, PHQ-9, GAD-7, Columbia C-SSRS, and others, is designed to auto-score and trend over time as part of the clinical record, drawing the medical necessity narrative a reviewer needs from data already captured during the session rather than a separate write-up assembled after the fact.
This is not a hypothetical fix. Fair Oaks Psychiatric Associates, a psychiatric practice previously losing claims to missed pre-authorizations and unresolved payer credentialing gaps, worked with blueBriX on a broader billing overhaul that included rebuilding its pre-authorization workflow and expanding credentialing. Within 90 business days, the practice recovered $120,000 in aged receivables, grew revenue 33%, and cut denials 4%.
blueBriX also separates the software layer from a staffed one: its revenue cycle management services team is available to track authorization windows, initiate renewals, and manage the appeal process as a service, distinct from and in addition to the software automation described above.
There is also a compliance angle worth building in from the start: since CMS-0057-F now requires payers to state a specific reason for every denial, a UM workflow that captures and categorizes those reasons systematically turns a new payer obligation into usable internal data, rather than another line item in a denial letter nobody reviews in aggregate.
What should a self-check cover before your next utilization review cycle?
- Before the review: confirm the current authorization end date, the level of care it covers, and whether a step-down happened since the last review.
- Before you disclose documentation: for SUD patients, confirm the Part 2 consent on file actually covers disclosure to this payer for this purpose.
- After a denial: log whether the cause was a missed date, a level-of-care mismatch, a documentation gap, or a parity-related restriction, before resubmitting or appealing.
What should you look for when evaluating a BH EHR's utilization management capability?
- Authorization tied to the treatment plan: a level-of-care change should update the authorization record automatically, not through a second manual entry.
- Level-of-care-aware reauthorization logic: the system should recognize that concurrent review cadence differs by level of care and trigger the right review window automatically at each transition, rather than run one fixed reminder cycle across residential, PHP, IOP, and outpatient.
- Documentation-to-authorization linkage: progress notes, treatment plan updates, and assessment scores should feed the medical necessity narrative a reviewer needs directly, without re-typing clinical detail into a second system.
- Separate tracking for Part 2 consent: for SUD programs, consent status should be visible alongside, but not merged with, payer authorization status.
- Review-date visibility across roles: clinical, UR, and billing staff should see the same upcoming review date instead of three different ones.
- Pre-submission authorization checking: authorization status should be checked automatically before a claim generates, flagging a mismatch for review instead of letting an expired or missing authorization reach the payer as a denial.
- Denial-reason categorization: the system should let you tell, at a glance across your payer mix, whether a denial pattern is a date, a documentation gap, or a level-of-care mismatch.
Our guide to questions worth asking a behavioral health EHR vendor goes deeper on this evaluation, including how to test FHIR-readiness ahead of CMS-0057-F’s 2027 deadline.


