Summer is when payer policy changes get announced and nobody reads them. Providers are on vacation, the billing team is short-staffed, and the newsletter from the payer goes into a folder. Then October arrives, remittances look different, and everyone asks when this was decided. This year the answer is June, July and August, and a few of the decisions are large enough that we want them in one place before the fourth quarter begins.
What follows is the list we have been walking through with the practices we support: four things that changed, one that did not, and what to do about each before October 1.
Key takeaways
- Cigna's E/M coding accuracy policy starts October 1: level four and five office visits and consultations can be paid one level lower based on claim data alone. Know your level distribution by provider before it does.
- The June 23 AHIP commitments are promises to verify, with one dated exception worth acting on: 90-day continuity of an existing authorization when a patient changes plans, from January 1, 2026.
- Comments on the CY 2026 fee schedule and OPPS proposed rules have closed; budget 2026 on the proposals and read the final rules in November.
- WISeR prior authorization in traditional Medicare starts January 1 in six states, and January procedures need December requests.
- The HIPAA Security Rule proposal from January is still a proposal. Treat its requirements as this year's security checklist anyway.
1. Cigna's E/M coding accuracy policy, effective October 1
Cigna Healthcare announced over the summer that a new reimbursement policy on evaluation and management coding accuracy takes effect October 1, 2025. Under the policy, claims for higher-level office and outpatient E/M visits (99204, 99205, 99214 and 99215) and for level four and five office consultations (99244 and 99245) may be adjusted down one level when Cigna's claim review concludes that the diagnosis codes and other claim data do not support the level billed. The provider is paid at the lower level and may submit medical records to request reconsideration.
The AMA and several state medical societies objected in August, and we share the objection. E/M level selection under the 2021 guidelines is based on medical decision making or time, neither of which is visible on a claim form, and a review that infers documentation from diagnosis codes is going to be wrong often. That said, the policy exists, and the practical response is in the practice's hands.
- Pull twelve months of Cigna claims for 99204, 99205, 99214 and 99215 and calculate the level distribution by provider. Compare it to the practice's distribution for other payers. A provider who bills 99215 on 40 percent of Cigna visits and 15 percent of everyone else's will be reviewed.
- Check that the diagnosis codes on level four and five claims reflect the complexity the note describes. A 99215 with a single acute uncomplicated diagnosis code invites downcoding even when the MDM supports it. Code every condition addressed.
- Decide in advance to dispute downcodes with records. A downcode paid at the lower level is a denial in everything but name, and practices that accept them quietly will see the review widen.
- Track downcoded claims from October as a separate denial category with its own dollar total.
2. The AHIP prior authorization commitments, June 23
On June 23, 2025, AHIP and a group of insurers covering roughly 257 million people announced a set of voluntary commitments, with the Secretary of Health and Human Services and the CMS Administrator standing beside them. The commitments: reduce the scope of services subject to prior authorization by January 1, 2026; honor an existing authorization for 90 days when a patient changes plans, also from January 1, 2026; have a licensed clinician review every denial based on medical necessity; give clearer explanations of denials and appeal rights; adopt a standardized electronic prior authorization process by January 1, 2027; and answer at least 80 percent of electronic requests in real time by 2027.
Honestly, most practices should treat this as a set of promises to verify rather than a change to plan around. The one exception is the 90-day continuity commitment, which is concrete and dated. Starting in January, when a patient with an active authorization switches plans, the practice should ask the new plan to honor it, in writing, citing the commitment. Keep a record of the answer. The industry-wide numbers that will tell us whether the scope reduction happened are the practice's own authorization volume by payer, which is why we keep saying to count them.
3. Two CMS payment rules closed for comment
The CY 2026 Physician Fee Schedule proposed rule closed for comment on September 12, and the OPPS and ASC proposed rule closed on September 15. If your practice or your specialty society submitted comments, the next event is the final rules, expected around the start of November. If not, the modeling advice stands: two conversion factors, a 2.5 percent efficiency adjustment on most non-time-based services, a cut to indirect practice expense in facility settings, and skin substitutes paid as supplies at a flat rate. The final rule will move some of these numbers, but the direction is set, and the 2026 budget should be built on the proposal rather than on 2025 rates.
4. WISeR and the return of Medicare prior authorization
CMS's WISeR model begins January 1, 2026 in Arizona, New Jersey, Ohio, Oklahoma, Texas and Washington, applying prior authorization or pre-payment review to a set of traditional Medicare services that includes skin substitutes, nerve stimulator implants and knee arthroscopy for osteoarthritis. We covered the mechanics in July. The point for this roundup is timing: procedures scheduled for the first week of January in those states need their requests in during December, and the practice's authorization owner should have the target list now.
5. The HIPAA Security Rule that has not arrived
The Office for Civil Rights published a proposed overhaul of the HIPAA Security Rule in the Federal Register on January 6, 2025, and the comment period closed on March 7. The proposal would remove the distinction between required and addressable specifications, mandate multifactor authentication and encryption of electronic protected health information at rest and in transit, require a written technology asset inventory and network map, require restoration of critical systems within 72 hours of an outage, and add annual compliance audits, vulnerability scans every six months and annual penetration testing, with compliance due 180 days after the final rule's effective date.
As of mid-September there is no final rule, no announced date for one, and considerable uncertainty about how much of the proposal will survive. Our view is that this changes nothing about what a practice should be doing. Every item in the proposal is already a recognized security practice, the current rule already requires a risk analysis that would identify the gaps, and enforcement actions in 2025 have continued to cite missing risk analyses above all else. A practice that implements MFA, keeps an asset inventory, tests its backups and documents its risk analysis this year is ready for whatever is finalized. A practice waiting for the final rule to start is betting on a delay it cannot control.
What to do before October 1
| Item | Action | Owner |
|---|---|---|
| Cigna E/M policy | Level distribution report by provider; diagnosis coding review on level 4 and 5 claims; downcode tracking category created | Billing lead, coding lead |
| AHIP commitments | Baseline authorization volume by payer for the last 90 days; script for 90-day continuity requests from January | Authorization owner |
| Fee schedule and OPPS | 2026 revenue model on the proposed rules; final rule review scheduled for November | Practice manager |
| WISeR | Target list of codes and volume for practices in the six states; documentation templates against LCD criteria | Authorization owner |
| HIPAA Security Rule | 2025 risk analysis completed and documented; MFA enabled on EHR, email and remote access; asset inventory started | Practice manager, IT vendor |
| Telehealth | Review October telehealth appointments for Medicare patients against the September 30 expiration of the statutory flexibilities | Scheduling lead |
Questions we hear
Is Cigna the only payer downcoding?
Cigna is the one with a published policy and an October 1 date. Other payers have run E/M level reviews through claim analytics for years without announcing them, and the level distribution report is useful against all of them. Watch remittances from every payer for paid amounts that do not match the billed level.
Should we comment on the HIPAA proposal even though the period closed?
No. The window closed March 7. What you can do is read the proposal's list of requirements as a free security checklist, which is what our RCM audit team does when reviewing a practice's vendor and access controls. Revelrex operates as a HIPAA compliant and SOC 2 compliant business associate, and we hold our own systems to the same list.
We missed the fee schedule comment deadline. Does it matter?
For the 2026 rule, yes, the window is closed. Your specialty society almost certainly commented. For the practice, the useful work now is modeling, not commenting, and if the model shows a problem, book a call and we will look at it with you.
What to do this week
- Run the E/M level distribution report for Cigna claims by provider for the last twelve months and compare it with the same report for all other payers.
- Create a downcode tracking category in the practice management system so that October remittances paid at a lower level than billed are counted separately from other adjustments.
- Write the one-paragraph records request the practice will send for every Cigna downcode, and decide who sends it and within how many days.
- Baseline authorization volume by payer for the last 90 days, so the AHIP scope reduction can be measured against something in January.
- Confirm the 2025 security risk analysis is done and documented, and that multifactor authentication is on for the EHR, email and remote access. If any of those is a no, that is this week's work.
