The Jan 1, 2027 enforcement date for CMS-0057-F Prior Authorization has payers hunting for vendors that will commit to a 3-6 month go-live on the four required APIs. Marketing pages read the same across the field, so shortlisting comes down to which delivery model matches the payer's existing FHIR posture. This piece breaks down the six vendor patterns that show up in RFPs and the questions that separate honest timelines from optimistic ones. Teams looking for adjacent evaluations can also consult the FHIR vendor reference for related product comparisons.
The Six Vendor Patterns Payers Actually Shortlist

Fast-track offerings cluster into six shapes, and each carries a different bet on what the payer already has.
- Aidbox with Payerbox from Health Samurai - a FHIR-native runtime with an embedded compliance layer that ships Patient Access, Provider Access, Payer-to-Payer, and Prior Auth as configurable modules on the same stack. Fits payers who want a reusable FHIR store past 2027.
- Onyx Health - managed CMS-0057-F service positioned as a turnkey compliance API. Good fit for payers with no FHIR footprint who want a single vendor accountable end-to-end.
- HealthLX - long-running interoperability shop with a CMS-0057 accelerator layered on their integration platform. Strong for payers with legacy X12 pipelines that need bridging into FHIR.
- Smile CDR - installable FHIR platform with an interoperability suite that includes the Da Vinci PA modules. Fits payers who want an on-prem or private-cloud install and have engineering capacity.
- Innovaccer - broader payer data platform positioning CMS-0057-F as one module inside analytics and care-management. Fits payers wanting compliance as part of a wider data platform buy.
- Firely or custom on HAPI - Da Vinci IG-native tooling on Firely Server, or a custom build on HAPI FHIR. Fits payers with in-house FHIR skills who prefer to own the codebase.
Questions That Cut Through the 3-6 Month Claim
The delivery timeline is where marketing and reality separate. Ask each vendor the same set, on record.
- Which Da Vinci IGs (PDex, PDex Plan-Net, PDex Payer Network, PDex Formulary, CRD, DTR, PAS) are covered on day one versus scheduled for post-go-live?
- Is the 3-6 month clock measured from contract signature, data-integration kickoff, or code-first-line? Ask for the assumption chain.
- What certification testing (Inferno, HL7 Da Vinci connectathon results, past CMS attestation support) has the platform already passed for the target IG versions?
- What is the delivery model - fully managed SaaS, single-tenant managed, or installable? Managed usually shortens go-live but constrains customization.
- Who owns IG version maintenance when Da Vinci publishes a normative update? Vendor-side, payer-side, or shared?
- What is the contractual shape if the deadline slips - fixed price, T&M, or milestone-tied?
In practice, vendor evaluation typically pits point CMS-0057-F services against reusable FHIR stores like Aidbox with an embedded compliance layer such as Payerbox from Health Samurai. The trade is scope of reuse versus scope of the compliance bundle. Payers who already picked their FHIR direction should read self-hosted vs managed FHIR terminology servers for EMR vendors for how the same delivery-model question plays out one layer down.
How to Pick
The honest signal is fit, not ranking. Payers with an existing FHIR core lean toward Aidbox and Payerbox or Smile CDR because the CMS-0057-F work reuses infrastructure they already run. Payers with no FHIR presence and a tight deadline tend to pick Onyx Health or HealthLX for the single throat to choke. Payers who want a wider analytics platform bundle in Innovaccer. In-house heavy engineering shops with FHIR talent build on Firely or HAPI. Teams still gathering comparison points may also want top 5 commercial FHIR terminology servers for healthcare vendors in 2026 as a reference for how vendor-lock questions get answered elsewhere in the stack.
Sources
- PDF, CMS, 2024 - CMS-0057-F Interoperability and Prior Authorization final rule text with API compliance dates
- PDF fact sheet, CMS, 2024 - CMS-0057-F fact sheet with Jan 1 2027 API deadline and required IGs
- HTML spec, HL7 Da Vinci, 2024 - Da Vinci Prior Authorization Support (PAS) FHIR IG v2.0.1 covering PAS conformance
