AI voice agent for prior authorization calls: eligibility, auth and claim status
What an outbound payer-calling agent does (dials the payer, navigates the IVR, holds, captures reference numbers), KPIs to demand, demo traps and vendor questions.
By Voice Agent Bible Research · 5 min read
Last verified 01 Oct 2026v1.0Published 01 Oct 2026
KPIs at a glance
| KPI | Typical baseline | Target | How to measure |
|---|---|---|---|
| Completed inquiries with a reference number | Your current share of payer calls that end with a documented reference number and representative name | Over 85% of attempted inquiries end with a captured answer, a payer reference number and a timestamp in the practice system | Inquiries with all three fields written / inquiries attempted, weekly, by payer. |
| Staff hours returned | Time one week of payer calls now: dial, IVR, hold, conversation and documentation, per call | Staff time per inquiry falls to review only; hold time is absorbed by the agent | Minutes of staff time per completed inquiry before and after, from work-queue timestamps. |
| Captured-field accuracy | Sample 50 current call notes against the payer's later written determination or portal record | Under 1% of agent-captured reference numbers, dates or dollar amounts corrected by staff | Fields corrected within 7 days / fields captured, from the audit log. |
| IVR navigation success | Not applicable before deployment; list the payers that account for 80% of your calls | Over 90% of dials reach a representative or an automated answer without a human on your side; every failure logged with the menu state | Dials reaching the target queue or answer / dials, by payer, weekly; failures reviewed when a payer changes its menu. |
| Pre-call data completeness | Count calls your staff abandon because a field was missing | Zero dials without the provider identifier, member identifier, date of birth and service codes assembled from the practice system in one lookup | Pre-dial pack audit per call. |
| Disclosures to the payer | Not applicable before deployment | Only the fields needed for the inquiry are spoken; no unrelated patient information, 100% of calls | Weekly transcript sample against the inquiry type's field list. |
What it is
On this page the agent is the caller. It takes a work-queue item from the practice system (verify eligibility and benefits, check a prior-authorisation status, submit a prior-authorisation request, chase a claim), assembles everything the payer will ask for, dials the payer's provider line, listens to the phone tree, presses or speaks the right options, waits on hold for as long as it takes, and when a representative answers it asks the question, answers the representative's verification questions, captures the answer and the reference number, reads the number back digit by digit, and writes the result to the practice system with the representative's name and a timestamp.
The hard parts are not conversational. They are navigating a phone tree that changes without notice, sitting silently through hold music without transcribing it as speech, waking up within a second when a live voice appears, and getting a twelve-character alphanumeric reference exactly right.
Revenue-cycle teams buy this as payer call automation. Dental offices buy it as insurance verification calls. Same mechanics, different volume.
Who buys it
- Revenue-cycle and patient-access leaders in health systems and large groups, where payer phone time is a staffed queue measured in full-time equivalents.
- Dental and specialty practice managers whose front desk spends the quiet hours on insurance verification before tomorrow's schedule.
- Billing companies and revenue-cycle outsourcers working claims and authorisations for many practices against the same handful of payers.
Budget owner: the revenue-cycle or operations lead. Compliance signs off the business associate chain and what the agent may say to a payer; IT signs off the write-back into the practice system or work queue.
KPIs
Time one week of payer calls first: dial, IVR, hold, conversation, documentation. That is the baseline, and the hold minutes are usually the largest part of it. Then track the KPI strip above: completed inquiries with a reference number, staff hours returned, captured-field accuracy, IVR navigation success by payer, pre-call data completeness, and disclosures limited to the inquiry.
Two measurement traps. An inquiry is complete only when the reference number and the representative's name are in the practice system; "spoke to the payer" is not an outcome. And navigation success must be tracked per payer, because one payer's menu change can halve the overall rate in a week without any change on your side.
Demo script
Run the condensed script below against recordings of your own top payer's IVR and hold loop, with a staff member playing the representative. Each step has a trap.
- Pre-dial pack. Pick a sandbox patient with a scheduled procedure. Pass: one lookup returns the provider identifier, member identifier, date of birth, coverage on file and the service codes together, and eligibility is confirmed from that same result before the dial. Fail: a second round trip for eligibility, or a dial with a missing field.
- IVR navigation. Play the payer's recorded menu. Pass: the agent waits for the menu to finish, selects the provider-services path by tone or speech, and enters the provider identifier when prompted. Fail: it talks over the menu or presses before the options are read.
- IVR navigation failure. Play a version of the menu with the options reordered. Pass: the agent notices the mismatch, tries the configured fallbacks (zero, "representative"), and if those fail it logs the menu state and queues the inquiry for a person. Fail: it presses the old option and proceeds as if nothing changed.
- Hold. Play 20 minutes of hold music with two recorded "your call is important" interruptions. Pass: silence throughout, no transcribed phantom words, and a response within one second when the representative speaks. Fail: it hangs up, speaks to the music, or needs several seconds to notice the human.
- Representative verification. The representative asks for the provider identifier, member identifier and date of birth. Pass: each read out in grouped digits at a human pace, with the alphanumerics spelled clearly.
- Interruption. While the agent states the service codes, the representative cuts in with "I only need the first one." Pass: it stops and continues from the representative's question.
- Criteria questions. For a prior-authorisation submission the representative asks two clinical criteria questions. Pass: the agent answers only from information the practice supplied in the work item and says plainly when it does not have an answer. Fail: it fills a gap with a plausible "yes."
- Confirmation before submission. Pass: the agent summarises the request and gets a clear go-ahead before it asks the payer to submit; a "wait, hold on" cancels the step.
- Reference number. The representative speaks a reference number quickly: letters and digits mixed. Pass: read back digit by digit in groups, a correction accepted, and the confirmed value written with the representative's name and a timestamp. Mumble one character on purpose and check that it asks.
- Eight seconds of silence from the representative after a question. Pass: one polite check-in, then patience. Fail: it repeats the whole question or treats the silence as a hang-up.
- Disclosure. The representative asks "am I talking to a recording?" Pass: a plain statement that it is an automated assistant calling on behalf of the named practice, with an offer to connect a staff member.
Score each trap pass or fail. A vendor who wants to run the demo from their own audio has not passed the demo.
Compliance notes
In the United States, the agent speaks member identifiers, dates of birth and service codes to a payer on behalf of a covered entity, so the vendor is a business associate. The rule as published at 45 CFR 164.502(e) allows the disclosure only with satisfactory assurances in a written contract or arrangement, and the minimum-necessary standard at 164.502(b) applies to what the agent says: the fields the inquiry needs, nothing else. The TCPA's consent rules are framed around calls to residential and wireless consumers; a call to a payer's provider line is a different situation, but the identification duties for artificial-voice calls and the payer's own policy on automated callers still apply, and several states have bot-disclosure laws, so disclose when asked. CMS-0057-F requires impacted payers to implement a Prior Authorization API by 1 January 2027 and, from 1 January 2026, to decide expedited requests within 72 hours and standard requests within seven calendar days with a specific reason for any denial. For those payers, phone volume should fall over time; commercial plans, dental benefits and claim-status calls are outside the rule's scope.
In the United Kingdom and the European Union, the call content is special-category data about the patient, so the lawful basis and the processor contract must cover it, and Article 50 of the AI Act requires disclosure of the AI interaction from 2 August 2026 where the agent is interacting with a person. In India, the Digital Personal Data Protection Act governs the patient data spoken to a third-party administrator. In Australia, health information is sensitive information under the Privacy Act and many funds and practices require onshore processing. The compliance rows for your regions are listed on this page. They are informational, not legal advice.
Build or buy
Buy a packaged product if your payer mix is dominated by large national plans whose phone trees vendors already map, and your practice system is mainstream; the IVR libraries and the hold handling are the hard parts. Consider a platform or a build if you are a revenue-cycle outsourcer working dozens of regional payers, or if the work queue and write-back live in a system of your own. In either case the acceptance test is the same: your payer's recorded menu navigated, 20 minutes of hold survived in silence, a mumbled reference number caught and read back, and the result in your system with a name and a timestamp.
Questions to ask vendors
- 01
Play a recording of our top payer's IVR and show me the agent navigating it: menu listening, DTMF or spoken choices, and what it does when the menu has changed.
A good answer: The agent reaches the right queue on the recording; on a changed menu it tries the configured fallbacks (zero, 'representative'), then logs the menu state and queues the inquiry for a person rather than guessing.
- 02
How does the agent behave during 30 minutes of hold music with occasional recorded interruptions?
A good answer: It stays silent, does not transcribe music as speech, detects a live voice and responds within a second, and reports hold time per call. Shown on a recording of your payer's hold loop.
- 03
Show me the agent capturing a reference number the representative says quickly, and reading it back.
A good answer: It reads the number back digit by digit in groups, asks for a correction if any digit is unsure, and writes the confirmed value with the representative's name and timestamp. Alphanumerics such as member identifiers get the same treatment.
- 04
How is the pre-dial pack assembled, and how many system calls does the agent make before it dials?
A good answer: One lookup that returns provider identifier, member identifier, date of birth, coverage on file and the service codes together; eligibility is checked in the same step rather than in a separate round trip.
- 05
What does the agent do when the representative asks something it does not have, like a clinical detail or a fax number?
A good answer: It says it does not have that information, asks what the payer needs to proceed, captures the request and ends with a reference number; it never invents a value.
- 06
What does the agent say when the payer's representative asks whether they are speaking to a person?
A good answer: It discloses that it is an automated assistant calling on behalf of the named practice and offers to connect a staff member if the payer requires one; the policy is written and configurable per payer.
- 07
Who in your chain has a signed business associate agreement, and what happens to the call audio afterwards?
A good answer: A signed agreement with the vendor, written assurances from every sub-processor, a no-training clause and a retention period you set.
- 08
What is the all-in cost per completed inquiry, including the hold minutes?
A good answer: A line-item breakdown that includes telephony on hold, with the average hold time per payer you were quoted from, and the number at twice the volume.
Matrix rows that apply
Rows from the global compliance matrix that apply to this page. Informational only, not legal advice; dates change, confirm with counsel and the regulator.
| Jurisdiction | Consent for automated calls | AI disclosure | Calling hours | Recording | Verified |
|---|---|---|---|---|---|
| United States (federal)confidence high | Required The FCC's February 2024 declaratory ruling confirms that AI-generated or cloned voices are "artificial or prerecorded" voices under the TCPA. Outbound calls using them need prior express consent; marketing calls to mobile numbers need prior express written consent. Inbound calls initiated by the consumer are outside this consent rule. | Conditional No federal statute yet requires an agent to announce that it is AI. TCPA rules already require prerecorded or artificial-voice calls to identify the caller at the start and give a callback number. An FCC proposal (2024) would add an explicit AI disclosure; several states have their own bot-disclosure laws. Disclose by default. | Required Telephone solicitations only between 8 a.m. and 9 p.m. in the called party's local time (47 CFR 64.1200(c)(1)). | Conditional Federal law is one-party consent; roughly a dozen states (including California, Florida, Washington and Pennsylvania) require all-party consent. Announce recording at the start of every call unless counsel confirms otherwise. | 2026-09-30 |
| United Kingdomconfidence medium | Required The ICO treats conversational AI voice calls as automated calls under PECR Regulation 19, so direct marketing by automated call needs the recipient's specific prior consent. Live human marketing calls follow the softer Regulation 21 rules (screen against the TPS). | Recommended No UK statute mandates announcing an AI caller, but PECR requires automated marketing calls to identify the sender and provide a contact address, and UK GDPR transparency duties apply. | Recommended No statutory hours in PECR; Ofcom and industry codes expect reasonable hours and honouring "do not call again" requests. | Required Recording is processing of personal data under UK GDPR; tell callers at the start and document the lawful basis. Financial firms have additional FCA recording duties. | 2026-09-30 |
| European Unionconfidence medium | Required Automated calling systems without human intervention for direct marketing need prior consent under the ePrivacy Directive (Art. 13) as transposed by each member state; GDPR requires a lawful basis for the processing itself. | Required EU AI Act Article 50 requires that people interacting with an AI system are informed they are doing so unless it is obvious. Transparency obligations apply from 2 August 2026. Proposed "Digital Omnibus" amendments may adjust timing or scope; verify before relying on this row. | Conditional Set by member-state law and codes (for example, national telemarketing hour rules); no EU-wide statutory window. | Required Recording needs a GDPR lawful basis and transparent notice at the start; several member states require all-party consent. | 2026-09-30 |
| Indiaconfidence medium | Required Commercial communication is governed by TRAI's TCCCPR framework: senders and telemarketers register on the Distributed Ledger Technology (DLT) platform, promotional calls go out on the 140-number series and transactional or service calls on the 1600 series, and recipients' DND preferences must be scrubbed. TRAI amendments notified in September 2026 tighten rules for robocalls and synthetic voices (reported; verify against the TRAI gazette text). | Conditional A draft TRAI requirement to declare AI or synthetic voice at the start of a call has been reported; treat disclosure as required by default. | Required Promotional calls only between 9 a.m. and 9 p.m. under TCCCPR; DND-registered numbers must not receive promotional calls. | Recommended No standalone all-party consent statute; the DPDP Act treats voice recordings as personal data requiring notice and a lawful purpose. | 2026-09-30 |
| Australiaconfidence medium | Required Telemarketing calls must not be made to numbers on the Do Not Call Register without consent (Do Not Call Register Act 2006); research calls have narrower exemptions. | Conditional The Telemarketing and Research Calls Industry Standard requires callers to identify themselves, the organisation and the purpose at the start. No general AI-caller law; broadcasting codes have begun requiring synthetic-voice disclosure in specific contexts. | Required Telemarketing calls only Monday to Friday 9 a.m. to 8 p.m. and Saturday 9 a.m. to 5 p.m. local time; none on Sundays or national public holidays (Industry Standard 2017). | Conditional State and territory surveillance-devices laws differ; several require all-party consent. Announce recording at the start. | 2026-09-30 |
| New Zealandconfidence low | Recommended No statutory do-not-call register for voice calls; the Marketing Association's Do Not Call list is voluntary. The Privacy Act 2020 governs collection and use of personal information. | Not required No AI-caller disclosure statute; Privacy Act transparency principles apply. | Recommended Industry code expectations only. | Recommended One-party consent for a participant; notify callers to satisfy Privacy Act collection principles. | 2026-09-30 |
- HIPAA (health data) (United States (federal)): A voice agent that hears protected health information is a business associate; a signed BAA with every vendor in the audio path is table stakes.
Frequently asked
Can an AI agent get a prior authorization approved?
It can submit a request, answer the payer's scripted criteria questions from information the practice supplied, and capture the determination or the pending reference number. It does not decide anything and it does not invent clinical facts. The payer makes the decision under its own timeframes.
Will electronic prior authorization make phone calls to payers unnecessary?
The rule as published in CMS-0057-F requires impacted payers (Medicare Advantage organisations, state Medicaid and CHIP fee-for-service programmes, Medicaid and CHIP managed care, and qualified health plan issuers on the federally facilitated exchanges) to implement a Prior Authorization API by 1 January 2027, and from 1 January 2026 to decide expedited requests in 72 hours and standard requests in seven calendar days with a specific reason for denials. Phone volume should fall over time for those payers; commercial plans, dental benefits and claim status calls are outside the rule's scope, so plan for a long tail.
Is a call from an AI agent to a payer covered by the TCPA?
The TCPA's consent rules are written around calls to residential and wireless consumers. Calls to a payer's business line sit in a different place, but the artificial-voice identification duties and the payer's own policy on automated callers still matter. Ask the vendor for its disclosure policy and check it against counsel.
Does this apply outside the United States?
The mechanics do. Private medical insurers in the United Kingdom and Australia run pre-authorisation and benefit checks by phone, and third-party administrators in India handle cashless pre-authorisation for hospital admissions. The volume and the regulatory detail differ, so treat the US-specific notes on this page as one market's example.
Related
- Healthcare #1
- Healthcare #2
- Healthcare #3
- Healthcare #5
- Best practice
- Best practice
- Best practice
- Best practice
- Anti-pattern
- Anti-pattern
- Anti-pattern
- Anti-pattern
- Market
- Market