What health plans must change across workflows, people and governance.
With Kim Ingram, SVP of Clinical Innovation, and Michelle Heckman, SVP of Change Management, Excell Healthcare Advisors
Every health plan we talk to is focused on the same January 1, 2027 deadline: being technically compliant with CMS-0057-F.
But increasingly, the more important question is different: Will the organization be operationally ready when those APIs start working at scale?
Technical compliance is the starting line—not the finish line. The API can move the data. The organization still has to know what to do with it.
We sat down to discuss what health plans should be doing now to close that gap.
If payers expect to be technically compliant, what is the concern?
Kim Ingram, SVP of Clinical Innovation: Compliance means the APIs exist and meet the technical requirements. Readiness means the organization can absorb what happens when those APIs are used—at volume, under real operating conditions, and across the people and processes that ultimately have to act on the information.
Those are not the same bar.
The question we encourage health plans to ask is not simply, “Will our API work?” It is, “What happens inside our organization when it does?”
Where does that gap show up most?
Michelle Heckman, SVP of Change Management: The Payer-to-Payer API is one of the clearest examples because it changes more than how data moves—it changes what the organization must do with that information once it arrives, and creates an opportunity to leverage new data.
Most organizations understandably focus on electronic prior authorization because it has been a visible source of friction for years. But Payer-to-Payer creates a different operational challenge and opportunity.
With member permission, a payer can receive historical information from a member’s previous plan shortly after coverage begins. That creates new questions: Who owns the incoming information? How is it integrated into existing systems and workflows? What requires clinical action? What gets escalated? And how do we know something important hasn’t been missed?
What does that disruption actually look like?
Kim: It can show up in places leaders may not initially associate with interoperability.
You could see increased manual reconciliation, incomplete or delayed member histories, duplicate outreach, missed opportunities to identify care needs, provider frustration, additional compliance escalations, and increased workload for clinical and operational teams.
The technology may be functioning exactly as designed. The problem is that the organization around the technology is not ready to absorb the resulting work.
Can health plans do anything about the timing?
Michelle: Health plans have raised concerns with CMS and ONC about the time needed for coordinated testing and operational readiness. Additional runway would certainly help.
But regulatory uncertainty cannot become an operational strategy. Organizations should work backward from the compliance date and ask what must be true for the business—not just the technology—to be ready. That includes leadership alignment, workflow ownership, testing, workforce preparation, governance, and clear measures of success.
Our advice to clients is straightforward: plan for January 1 as the deadline and treat any additional runway as a bonus—not the strategy.
If additional time becomes available, use it to mature the operating model.
What about testing? Is the industry ready?
Michelle: This is one of the biggest readiness gaps we see.
Testing cannot stop when the API successfully exchanges data. That’s technical testing. Operational readiness requires proving that the organization can successfully act on what happens next. It is building the bridge to ensure the technology is supporting the people, processes, and data requirements.
Health plans should test realistic end-to-end scenarios: What happens when information is incomplete? Who owns the exception? When does clinical staff become involved? How are providers or members engaged? Can decisions be traced and audited?
The goal isn’t simply to prove that the technology works. It’s to prove that the new way of working works.
What role does change management play?
Michelle: Obviously, a significant one since you are asking me. Change management is what bridges the technical change to the operating model, and to the telemetry of the organization.
The question isn’t simply, “Do people know a new API is coming?” It’s whether leaders are aligned around the change, workflows have been redesigned, ownership is clear, employees understand what is expected of them, and organizations can measure whether the new process is delivering the intended outcome.
That’s increasingly what modern change management looks like. We aren’t just preparing people for a go-live. We’re building a data-driven organization that can absorb change, adapt its ways of working, and continue to evolve as technology and regulatory expectations change.
So what should a health plan do right now?
Kim: We would focus on three areas.
First: Align the organization around the change. Establish accountable cross-functional governance—bring IT, clinical operations, compliance, legal, provider relations, and other impacted functions together under a defined governance structure. Make sure everyone understands what success looks like beyond technical compliance.
Second: Test the operating model—not just the API technology. Identify key trading partners and begin testing now. Walk real scenarios end to end and identify where ownership, workflow, capacity, or escalation breaks down.
Third: Prepare the workforce. People need to understand what is changing, why it matters, what they will do differently, and how their actions affect the member, provider, and compliance experience.
What about consent?
Michelle: Consent is a great example of why implementation decisions can’t be viewed only through a technology lens.
Clinical, legal, compliance, privacy, operations, and member-experience leaders need a shared understanding of how consent works. What does the member experience? What happens downstream? Who owns exceptions?
That’s the difference between implementing technical functionality and implementing organizational change: we are designing the technology, process, accountability, and the human experience together.
What role does technology play?
Kim: Technology is foundational, but it cannot operate in isolation. The strongest organizations will align infrastructure with the operating model around it. The API needs to work, but so do the workflows, people, governance, testing, monitoring, and escalation processes.
That is where the combination of technology and change management becomes important.
Excell became part of Medecision. Why does that matter?
Michelle: Because technology alone does not create operational readiness, and change management without an understanding of the technology can only go so far.
The opportunity is to connect the technology to the operating model around it: the people, workflows, governance, adoption, data, measurement, and continuous improvement needed to translate a new capability into business results.
That’s particularly important as healthcare is an industry of continuous change. Organizations need more than successful implementations; they need the ability to adopt, sustain, and evolve as new capabilities and requirements emerge.
If a health plan is reading this in August and hasn’t started, what is the honest assessment?
Kim: Behind, but not out of time.
There is still time to establish governance, identify critical trading partners, conduct meaningful testing, address consent workflows, and prepare the workforce.
But the window is narrowing.
Health plans do not have five months simply to complete an API project. They have five months to make sure the organization is ready to operate differently.
Is Payer-to-Payer the only place health plans should be thinking about operational change?
Michelle: Not at all. Provider Access is another good example. Giving providers greater access to payer-held clinical, claims, and prior auth information changes the relationship between the payer and provider—not just the technology connecting them. Plans should be asking what providers will do differently with that information, what new questions or expectations it creates, and how payer teams will support those workflows. That’s why we encourage clients to look beyond each individual API and think about the operating model these requirements are collectively creating.
The Executive Takeaway
CMS-0057-F is not simply an interoperability implementation. It is an operating-model change.
The health plans that will be best positioned for 2027 will look beyond technical compliance and align their technology, people, processes, governance, information, and workforce around new ways of working.
Readiness should not stop with this regulation. CMS-0057-F is one of many changes reshaping healthcare operations.
Compliance is the floor. Organizational readiness is the differentiator.
Excell Healthcare Advisors, a Medecision company, helps health plans and provider organizations translate regulatory requirements into accountable governance, testing protocols, workforce readiness, and operating models designed to perform in production.

