Prior Auth
MedBridge Health is a mid-size managed care organization operating across seven states with 1.4 million members. New federal regulations require MedBridge to overhaul its prior authorization processes, implement digital systems, and meet strict new turnaround and approval rate standards within 18 months or face penalties and potential loss of CMS contracts. Bain has been engaged to design a compliance strategy that meets requirements while minimizing cost and disruption.
Before reviewing any data, how would you structure the path to compliance?
Case Exhibit
Clarifying Questions
- What is MedBridge's current prior authorization turnaround time, and how far does it sit from the new regulatory requirement?
- Does MedBridge already have any digital infrastructure for authorization submissions, or is the current process largely manual or fax-based?
- What share of MedBridge's revenue comes from CMS contracts specifically, so we can size the penalty and revenue-at-risk?
Framework
Bucket 1: Compliance Gaps
Objective: Understand precisely where MedBridge falls short of the new requirements before designing any solution, since the cost and timeline of compliance depends entirely on the size and nature of the gaps.
- Turnaround Time: current average authorization turnaround vs. the new regulatory standard, broken down by request type and urgency
- Approval Rates: current denial rates for medically necessary care vs. the new benchmarks, and whether denials are concentrated in specific procedure categories
- Digital Infrastructure: current state of authorization submission systems vs. the interoperability and digital access requirements in the new regulation
Bucket 2: Compliance Solutions
Objective: Identify the specific operational and technology changes needed to close each gap, prioritized by the timeline and cost required to implement.
- Process Redesign: changes to the authorization review workflow to meet turnaround requirements, including automation of routine approvals and escalation protocols for complex cases
- Technology Implementation: build vs. buy vs. partner decision for the digital submission and tracking system, and integration requirements with provider EHR (electronic health record) systems
- Clinical Criteria: review and revision of the clinical criteria used to evaluate authorization requests to align with the new approval rate standards
Bucket 3: Risk and Cost Management
Objective: Ensure compliance is achieved within the 18-month window at an acceptable cost, and that the financial and operational risks of non-compliance are explicitly weighed against the investment required.
- Penalty Exposure: quantify the financial penalties and CMS contract revenue at risk if compliance is not achieved on time
- Implementation Cost: estimate the total cost of the compliance program, including technology, staffing, and process change management
- Operational Risk: identify where the transition to new processes could disrupt care management for existing members and how to mitigate that risk
