Key takeaways
A medical prior authorization form asks a health plan to approve a service, drug, or device before you deliver it.
Every request needs patient and plan details, prescriber details, the service codes, a clinical justification, and records that back it up.
Most denials trace back to a blank field, thin documentation, unmet step therapy, or the wrong payer portal.
Medical requests run on the HIPAA X12 278 transaction, while pharmacy requests run on the NCPDP SCRIPT standard.
Practice management software like Pabau keeps the notes, forms, and follow-up tasks behind each request in one patient record.
Download your free medical prior authorization form
A ready-to-fill form covering patient and plan details, prescriber information, the requested service or drug with its codes, clinical justification, and an attachment checklist. Print it for the chart or complete it on screen before you submit.
Download templateYour patient needs an MRI on Thursday. The health plan wants a form before it will cover anything, and that form has to be right the first time.
Prior authorization already costs practices around 13 hours of physician and staff time a week, according to AMA survey data. One blank field adds a week to that, plus a phone call and a patient who now doubts you.
So grab the form above. Then walk through what each field needs, where requests fall over, and how to chase a decision using the payer’s own deadline.
What this form asks a plan to do
A medical prior authorization form is a written request asking a health plan to approve a service before you provide it. It names the patient, the service, the diagnosis, and the clinical reason the service is necessary now.
Payers read it to answer two questions. Is this medically necessary for this patient? Is it covered under this plan? Your job is to make both answers obvious without a follow-up call.
Do not confuse an approval with a price quote. It is a coverage decision on one specific service, tied to a date range and often to a set number of visits or units. Miss that window and you start again.

What to put in each field
Payers label and reorder these sections, but they all want the same five things. Here is what belongs in each one, and the detail reviewers look for first.
Patient and plan details
Copy these straight from the card, not from memory. A transposed member ID routes your request to the wrong plan, and nobody calls to tell you.
- Full legal name, exactly as it appears on the insurance card
- Date of birth and contact phone number
- Member ID and group number
- Plan name and type, such as HMO, PPO, Medicare Advantage, or Medicaid
- Secondary coverage, if the patient has any
Pulling these from a completed intake form beats retyping them, because the patient already checked them once.
Prescriber and practice details
The plan uses this block to route the request and confirm your network status. Use the individual NPI of the treating clinician, not the group number, unless the form asks for both.
- Individual NPI, and the group NPI where requested, per the split between Type 1 and Type 2 numbers
- DEA number, only when you are prescribing a controlled substance
- Practice name, address, phone, and a fax line that someone actually watches
- Specialty and, on some forms, your taxonomy code
- A named contact for questions, so the plan does not call the main line
The service or drug you are requesting
Name the thing precisely and quantify it. Vague requests get returned, and a rounded quantity is treated as a guess.
- Primary ICD-10 diagnosis code, such as M54.16 for lumbar radiculopathy
- CPT code for a procedure or scan, such as 72148 for an MRI of the lumbar spine
- HCPCS code for an injected drug or a device, such as J1322
- For drugs: name, NDC, dose, frequency, and the number of doses you want approved
- Site of service, units or visits requested, and the date you plan to start
Routine office visits rarely need authorization. Imaging, surgery, infusions, specialty drugs, and extended therapy courses are where the requests pile up.
Clinical justification and attachments
This is the part a reviewer actually reads, so write it for a clinician who has never met your patient. Four short sentences beat two pages.
- The story: diagnosis, how long it has run, what you have already tried, and what changed
- The evidence: exam findings, lab values, and imaging that support the diagnosis
- Step therapy proof: the cheaper treatments tried, with dates, doses, and why each one failed
- A letter of medical necessity, when the case sits outside the usual criteria
Attach the office notes that show all of the above. A strong narrative with no chart behind it still gets denied. Keep the patient record and the form in the same place.

Medical or pharmacy? Know which lane you are in
Requests split into two lanes, and they do not share a mailbox. Send a drug request down the medical lane and it sits there until someone notices.
Most practices meet the medical lane far more often. If you also prescribe, keep both routes in your workflow, because prescription management is usually where a pharmacy request starts.

How a request moves from your desk to a decision
Five steps, in this order. Skipping the first one is how practices lose an afternoon to a form nobody needed.
- Confirm it is required. Check the plan’s portal or provider line for this exact code on this plan. Plenty of services need nothing at all.
- Get the current form. Download it from that plan’s provider portal on the day you use it. Generic forms and last year’s version both get bounced.
- Fill every field. Verify the member ID, diagnosis code, and procedure code against the source. Transcription slips cause more denials than clinical disagreement.
- Attach the clinical proof. Office notes, failed treatments with dates, labs, and imaging. Add a letter of medical necessity for anything unusual.
- Submit, then log it. Use the portal or an electronic request rather than fax, and record the reference number, date, and the name of whoever confirmed receipt.
Then set a reminder to chase it. An automated task assigned to a named person beats a sticky note on a monitor, especially when the person who submitted it is on vacation.
Run this checklist before you hit send
Two minutes here saves a week later. Read the list out loud with the completed form in front of you.
- Is the patient still eligible on the planned date of service?
- Does the member ID match the card, digit for digit?
- Is this the correct plan, including any secondary or workers’ compensation coverage?
- Does the diagnosis code support the service you asked for?
- Are the units, visits, or doses stated, rather than left open?
- Have you named the failed treatments with dates and outcomes?
- Are the office notes attached, and do they say what your narrative says?
- Is the request signed by the clinician the plan expects to see?
- Have you flagged it as urgent, if it genuinely is?
- Do you have the reference number and the follow-up date written down?
Practices that run this as a shared step, rather than a personal habit, see fewer resubmissions. A short documented workflow also holds up better when an auditor asks how you decide what gets submitted.
Electronic requests beat fax, when the plan supports them
Electronic prior authorization sends the request straight from your system to the plan, with no cover sheet in between. Two standards sit underneath it, and mixing them up is why teams think their software handles everything when it only handles drugs.
Pharmacy requests travel on the NCPDP SCRIPT standard, which is why that side feels mature. Medical services run on the HIPAA X12 278 transaction instead, and adoption there is thinner.
That is changing. The CMS Interoperability and Prior Authorization Final Rule covers Medicare Advantage, Medicaid, CHIP, and marketplace plans. Those plans must run FHIR-based prior authorization APIs by January 1, 2027. The APIs use the Da Vinci PAS profile, so your system can ask what is required and submit in one session.
What you get either way:
- Decisions in hours or days, instead of waiting on a fax queue
- Status you can check yourself, without sitting on hold
- Fewer typos, because the data comes from your own records
- A timestamped trail of what you sent and when
Here is the part worth putting on your wall. Since January 1, 2026, those same plans must decide urgent requests within 72 hours. Standard requests get seven calendar days. A denial must also come with a specific reason. Treat day eight as your escalation trigger rather than a day to keep waiting.
Where each payer keeps its form
There is no single national form. These are the routes practices use most.
Two things to note. TRICARE covers service members, retirees, and their families. Veterans’ care runs through the separate VA system, so do not send a VA patient down this route.
Also, Medicare’s Appropriate Use Criteria program for advanced imaging has been paused since January 2024, so there is no consultation number to document. Pull a fresh copy of every payer form each year, because the fields and fax lines change quietly.
A worked example: The MRI request that got approved
A 47-year-old patient presents with eight weeks of low back pain and numbness down the left leg. Six weeks of physical therapy and a trial of anti-inflammatories have not helped. The plan requires authorization for lumbar MRI.
The request was approved in four days. Nothing clever happened here. The plan’s own criteria asked for six weeks of conservative care, and the packet proved it on the first page.
Why requests get denied, and how to stop it
Most denials come down to administration rather than clinical disagreement. These are the ones you can design out of your process.
- A blank field. Reviewers return the form instead of guessing, and the clock restarts.
- Missing documentation. A strong narrative with no notes behind it reads as an opinion.
- Step therapy not met. The cheaper option has to be tried and documented, or the request stalls there.
- Codes that do not match. A chronic migraine drug submitted with a cosmetic diagnosis gets denied on sight.
- The wrong payer. Workers’ compensation and secondary plans catch teams out constantly.
- An excluded service. If the benefit does not exist, no amount of evidence creates it. Tell the patient early.
- Timing. An expired approval, or a form sent after the service, both fail.
So make prevention somebody’s job. Give one person the checklist for the week. Ask the plan about step therapy before you write the narrative. Then use staff scheduling so cover is obvious when that person is out.
Pro Tip
Call the plan before you fill anything in and ask three questions. Is authorization required for this code on this plan? What clinical evidence do you want to see? How long does a decision take? Write down the reference number and the name of the person who answered. That call takes five minutes and it settles most arguments later.
Which practices deal with this most
Any practice that bills insurance meets authorization eventually. Some meet it every day.
- Physical and occupational therapy, where extended visit counts need approval and renewal, which is why physical therapy practices track visits so closely
- Mental health and psychiatry practices, for specialty medications and longer treatment courses
- Dermatology, for biologics and treatments with a cosmetic lookalike
- Primary care, for imaging, referrals, and high-cost prescriptions
- Orthopedics and sports medicine, for imaging, injections, and surgical planning
The bigger the team, the more the process leaks. Requests get submitted twice, or not at all, because two people assumed the other one had it.
Why a standard template beats a blank page
A template does not make a plan say yes. It removes the small decisions that slow your team down and let errors in.
- Fewer blanks left behind. The fields are already there, so nobody has to remember them at 6pm.
- Faster reading. A reviewer who finds the justification in the same place every time decides sooner.
- An easier handover. New staff fill blanks instead of inventing a format.
- A cleaner audit trail. One repeatable process is much easier to explain than a folder of one-offs.
Customize the downloaded form for your payer mix and keep one version in circulation. If you run more than one site, multi-location settings keep the same version and the same steps in front of every team.
How Pabau keeps authorization paperwork in one place
Right now the evidence for a single request probably lives in four places. Notes sit in your records. Intake answers sit in an email thread. The signed form is in a scanner folder, and the reference number is on a sticky note.
Practice management software like Pabau pulls those pieces onto the patient record. Digital forms capture the intake and consent detail. Treatment notes and photos attach to the same file. You can also set a task with a due date, so the submission and the follow-up land with a named person. When the answer comes back, it goes on the record instead of a shared inbox.
Billing lives there too, so an approved service moves into claims and billing without retyping the patient’s details. The outcome is simple. Less hunting, fewer resubmissions, and an answer you can find when a patient calls to ask where their scan is. Compare that with front-desk time spent chasing paper.

Keep every authorization record in one place
Pabau brings patient records, digital forms, treatment notes, and billing into one system, so the documentation behind each request is ready before you submit it.
Conclusion
Prior authorization is not going to get simpler this year, so the win is in your setup rather than your persistence. Confirm the requirement, use the plan’s current form, and send the notes with it the first time.
Do that and the change shows up quickly. Fewer requests come back, patients hear a date instead of an apology, and your team stops rebuilding the same packet twice. The trade-off worth remembering is that five minutes on the phone with the plan almost always beats a week of silence.
The form above gives you the structure. Book a demo to see how Pabau keeps the notes, forms, and billing behind each authorization in one patient record.
Continue your research
Need the diagnosis documented before you request anything? Medical diagnosis form gives you a structure that feeds straight into a clinical justification.
Are your office notes strong enough to attach? Medical notes template shows what a reviewer expects to find in the chart you send.
Writing a psychiatric case for a plan? Psychiatric evaluation template covers the assessment detail that supports longer treatment courses.
Chasing immunization records for a request? Immunization record form keeps dates and lot numbers in one place, ready to attach.
Treating a minor and unsure who signs? Medical consent form for minors sets out the consent you need on file first.
Frequently asked questions
Does prior authorization guarantee payment?
No. An approval says the plan accepts the service as medically necessary. Payment still depends on the patient’s eligibility on the day, the benefit limits, and clean claim coding.
What is a peer-to-peer review?
It is a call between your clinician and the plan’s reviewer, usually after a denial. Bring the chart, the treatments that failed, and the guideline you relied on. Many denials are overturned on that call.
How long does an approval stay valid?
Most approvals cover a set date range, often 30 to 90 days, plus a fixed number of visits or units. Record the authorization number and expiry date, then deliver and bill inside that window.
Do emergency services need prior authorization?
No. Emergency care is never held up for approval. Plans do expect notification afterwards, often within a day or two, and some ask for a retroactive authorization to cover the admission.
How fast must plans decide in 2026?
Medicare Advantage, Medicaid, CHIP, and marketplace plans must answer urgent requests within 72 hours and standard requests within seven calendar days. Employer-sponsored plans sit outside that rule.