How Outsourced Prior Authorization and Payer Administration Is Priced
Quotes for the same work arrive in different shapes: a rate per case, a weekly or monthly price per person, a flat monthly fee, a share of what is recovered, or a managed scope priced in writing. The shape says as much about what is being bought as the number does.
Five ways the same work is priced
Payer-facing administrative work, whether it is a prior authorization, an eligibility and benefits verification, a credentialing application, a claim follow-up, or an appeal, is sold under a small number of pricing models. Each one draws the line between what the vendor owns and what stays with the practice in a different place, and the line matters more than the headline number.
- Per case or per transaction: a unit price for each authorization, verification, application, or appeal. The practice pays for volume. The questions are what counts as one unit, whether renewals, resubmissions, and additional-information requests are new units, and how much follow-up each unit includes.
- Per seat: an hourly, weekly, or monthly price for a named person or a full-time equivalent. The practice is buying time. Supervision, training, quality review, coverage for absence, and the follow-up tail are the practice’s to manage unless the agreement assigns them to the vendor.
- Flat monthly capacity: a monthly fee that covers a stated volume of routine work. The questions are what happens above and below that volume, whether unused volume carries forward, and which case types fall outside the routine definition.
- Contingency: a share of what is recovered, common for underpayment and denial projects. The questions are how the base is measured, what counts as recovered, how long the vendor’s claim on a recovery lasts, and what happens to work that produces no recovery.
- Managed scope: a documented scope that names the services, expected volume, responsibilities, reporting, escalation, and exclusions, priced in writing. The vendor is accountable for delivering the scope rather than for hours worked, and changes to the scope change the price.
What a unit price usually leaves out
A prior authorization is not a single touch. It begins with a requirement check, moves through documentation review and submission, and then waits on the payer through status checks, requests for additional information, and, when the request is refused, a hand-off to reconsideration or appeal. The approved authorization then has to be recorded where the claim will be reconciled against it, and its expiration tracked. A unit price that covers submission but not the tail leaves the tail with the practice.
The same is true of the work around the work: training on the practice’s payers and systems, supervision and quality review, coverage when a person is out, escalation when a payer stalls, routing of clinical questions to the right clinician, and reporting the practice can act on. Under a seat model these are the practice’s responsibilities by default. Under a managed scope they should be named in the scope. Under any model, a quote that does not say who owns them is not yet comparable to one that does.
Why regulation sets a floor under a legitimate price
Any vendor that performs payer-facing work on a practice’s behalf will handle protected health information and is a business associate. Federal privacy rules do not allow the practice to disclose that information to a vendor until it has satisfactory assurance, documented in a written contract, that the vendor will safeguard it. The contract has required contents: the permitted uses and disclosures, safeguards, reporting of breaches and other unauthorized uses, flow-down of the same terms to any subcontractor, return or destruction of the information when the arrangement ends, and the practice’s right to terminate for a material violation.
The security rules also require the vendor to manage its own workforce’s access: authorizing and supervising the people who work with electronic protected health information, confirming that each person’s access is appropriate, establishing and documenting each user’s right of access, reviewing and modifying it, and ending it when the person leaves. The minimum necessary standard applies to what is accessed and disclosed in the first place.
Doing this properly costs money: onboarding, access provisioning, training, access reviews, and documented termination procedures. A price that leaves no room for them is a price that omits required work, or shifts it to the practice without saying so. Where work is performed by subcontractors or outside the United States, the same contract terms have to flow down, and the practice should ask how.
Turnaround belongs to the payer
A vendor controls the completeness of what it submits, the cadence of its follow-up, the quality of its documentation, and how quickly it escalates. It does not control the payer’s clock. For the payers covered by the federal interoperability and prior authorization rule, decisions on expedited requests are due within 72 hours and on standard requests within seven calendar days beginning January 1, 2026, and a denial must carry a specific reason. Commercial plans outside that rule follow their own timeframes and any applicable state law.
That is why a quote priced against a promised approval rate or turnaround should be read carefully. Ask what is actually within the vendor’s control, how the figure is defined and measured, and what the agreement says when the payer, not the vendor, is the reason a case is late.
Questions that make quotes comparable
Put the same questions to every vendor, and ask for the answers in writing.
- What is the unit of pricing, and exactly what counts as one?
- What happens above or below the volume in the price, and does unused volume carry forward?
- Which touches are included: requirement check, submission, follow-up, additional-information requests, renewals, expiration tracking, documentation in the practice’s system?
- Who trains, supervises, reviews quality, and covers absences?
- Where is the work performed, by whom, and in whose systems?
- What is reported, how often, at what level of detail, and does the report contain protected health information?
- What is excluded and priced separately: appeals, projects, complex or specialty cases?
- How are clinical questions, including peer-to-peer requests, routed back to the practice?
- Is the business associate agreement, access provisioning, and training in the onboarding plan?
- How does the engagement end, and how are open cases and access transitioned?
What this is not
None of this says which model is right. A practice with a stable, well-defined workload may be well served by a unit price. A practice that needs someone else to own the workflow, not just the keystrokes, is buying something different and should expect the price to reflect the difference. The point is to know which one is on the table.
Ellery Health Partners prices managed engagements around a written scope: the service lines included, expected monthly volume, payer mix, workflow complexity, and operating requirements, with responsibilities, capacity, exclusions, reporting, and price documented before delivery begins. The work is performed inside the practice’s authorized systems by a U.S.-based team, and payer decisions remain the payer’s.
Related services
- Prior Authorization
- Eligibility, Benefits & Financial Clearance
- Denials & Appeals
- Claims & A/R Administration
Sources
- 45 CFR § 164.502, Uses and disclosures of protected health information: general rules, via Cornell Legal Information Institute. A covered entity may disclose protected health information to a business associate only after obtaining satisfactory assurance, documented in a written contract or other written arrangement, that the business associate will appropriately safeguard the information; and a covered entity or business associate must make reasonable efforts to limit protected health information to the minimum necessary to accomplish the intended purpose.
- 45 CFR § 164.504(e), Business associate contracts, via Cornell Legal Information Institute. The contract must establish the permitted and required uses and disclosures, require appropriate safeguards, require reporting of any use or disclosure not provided for by the contract including breaches, require that subcontractors agree to the same restrictions, require return or destruction of protected health information at termination where feasible, and authorize termination by the covered entity for a material violation.
- 45 CFR § 164.308, Administrative safeguards, via Cornell Legal Information Institute. Workforce security requires procedures for the authorization and supervision of workforce members who work with electronic protected health information, for determining that a workforce member’s access is appropriate, and for terminating access when the arrangement ends; information access management requires policies for granting access and for establishing, documenting, reviewing, and modifying a user’s right of access.
- CMS, CMS Interoperability and Prior Authorization Final Rule (CMS-0057-F) fact sheet. Beginning January 1, 2026, impacted payers (Medicare Advantage organizations, state Medicaid and CHIP fee-for-service programs, Medicaid managed care plans, CHIP managed care entities, and, for some provisions, qualified health plan issuers on the federally facilitated exchanges) must send prior authorization decisions within 72 hours for expedited requests and seven calendar days for standard requests, and must provide a specific reason for denied requests.
Sources are cited for the substantive factual statements above. Payer-specific rules vary by plan, product, contract, and state.
Last updated September 2026. Educational reference, not legal or clinical advice.
Get started with Ellery Health Partners
Tell us about your practice, your approximate monthly volume, and the support you need. We review your workflow, confirm the scope, and send the agreement and onboarding documents. No patient information is requested or accepted.
