Drug prior authorization is the next exchange with a proposed electronic destination. CMS-0062 would put it on FHIR APIs for medical benefit drugs and NCPDP standards for pharmacy benefit drugs, with a proposed compliance date of 1 October 2027. It is still a proposal. Meanwhile a large share of clinical paperwork has no named replacement at all, and that is the part your fax server software has to get right.
If you run a fax server in healthcare, the pattern of the last two years should be familiar by now. A rule names one specific exchange, gives it a structured electronic format and a date, and says nothing about everything else. The fax queue does not empty. It gets narrower and, oddly, more sensitive.
What CMS-0062 would actually move
The proposed rule extends electronic prior authorization to drugs, which the 2024 interoperability rule deliberately left out. It splits along the benefit:
- Medical benefit drugs would ride the same FHIR prior authorization API that payers built for CMS-0057, using the Da Vinci Coverage Requirements Discovery, Documentation Templates and Rules, and Prior Authorization Support implementation guides.
- Pharmacy benefit drugs would use NCPDP standards, including SCRIPT for electronic prior authorization requests and decisions.
Both carry a proposed compliance date of 1 October 2027, and the payers in scope are the usual list: state Medicaid and CHIP fee for service, Medicaid and CHIP managed care, and qualified health plan issuers on the federal exchanges. Separately, the FY2027 inpatient payment final rule published on 4 August 2026 locked in updated versions of the data exchange standards behind those APIs, which is dull plumbing news that nonetheless tells you the direction is holding.
Worth repeating because it changes how you should plan: CMS-0062 is a proposed rule. Dates in proposals move, and this one has drawn plenty of comment. Build for the direction, not the calendar.

Two rules, two clocks, and a third column that nobody has scheduled.
The third column is the interesting one
Look at what has a date now. Claims attachments, final, compliance 26 May 2028. Drug prior authorization, proposed, 1 October 2027. Both are transactional exchanges between a provider and a payer, both have a standards body behind them, and both were expensive enough to justify the rulemaking.
Now look at what does not. Records requests from attorneys and auditors. Referrals between a specialist and a two-doctor practice with no interface budget. Long term care and skilled nursing handoffs. Signed patient consents. Appeals. Anything crossing to a partner who has no API and no plan to build one. None of that is going anywhere in this decade, and I would be sceptical of any vendor who tells you otherwise.
So the honest planning assumption is not “fax ends.” It is “fax stops being the default and becomes the exception channel.” That sounds like a demotion. In compliance terms it is closer to a promotion, because exception channels get audited.
Why a narrower fax queue is a riskier one
When everything arrives by fax, nobody is surprised that a stack of paper sits in a tray. When only the sensitive residue arrives by fax, the same tray looks very different to an auditor.
The Security Rule has always covered this. Any component that stores, transmits or processes electronic protected health information sits inside scope, and a fax server storing inbound TIFFs on disk is squarely inside it. What changes is proportion. A queue that used to be 80 percent routine confirmations and 20 percent sensitive material starts running the other way around, because the routine traffic is the part with a structured replacement.

The difference between a machine that answers and a system that can account for itself.
Four things to switch on regardless of which rule finalises first
A per page audit trail you can export yourself. Who received it, which queue it landed in, who opened it, when it was deleted. If producing that takes a support ticket to your vendor, you do not really have one.
Routing rules instead of a shared inbox. Sender number, OCR of the header, document type, patient match. Anything that keeps protected health information out of a general mailbox that six people watch. This is also the single biggest time saver, which makes it an easy sell internally.
Encryption end to end, in the boring sense. TLS on the transport, T.38 where your carrier supports it, encryption at rest on the store, and a signed business associate agreement with anyone whose infrastructure the traffic crosses. On premises deployments have an advantage here that is worth stating plainly: fewer third parties in the path means fewer agreements to chase.
A retention schedule that actually deletes. Most fax stores I have seen keep everything forever because nobody wrote the policy. Every extra year of retained records is extra breach surface with no clinical value.
We covered the wider version of this in what actually makes a fax server HIPAA compliant, and the attachments rule specifically in the claims attachment rule and your 2028 workflow.
What to do this quarter
Pull a month of fax logs and sort by document type. Most organisations find three or four categories make up the bulk of the volume, and usually at least one of them already has an electronic path that nobody switched on. That is free volume reduction before any deadline arrives.
Then check which of your inbound senders are small practices with no interface capability, because those relationships define your floor. However good the standards get, you will be receiving faxes for as long as your referral network includes people who send them, and the sensible response is to make that channel measurable rather than to pretend it is temporary.
The organisations that will struggle in 2028 are not the ones still running fax. They are the ones running it the way they ran it in 2015, on a shared machine nobody can produce a log for. That gap is fixable now, cheaply, and it does not depend on a single comment period.
Frequently asked questions
Is CMS-0062 final?
No. It is a proposed rule, published for comment in April 2026 and still proposed at the time of writing. Its dates and details can change before finalisation.
Does any rule actually ban healthcare fax?
No. The rules adopt standards for specific transactions and set compliance dates for those. They do not prohibit fax, and none of them names a replacement for records requests, referrals or patient consents.
What is the difference between CMS-0057 and CMS-0062?
CMS-0057 is the finalised interoperability and prior authorization rule that covers items and services. CMS-0062 is the proposal that would extend electronic prior authorization to drugs, split between FHIR for medical benefit and NCPDP standards for pharmacy benefit.
Does fax fall under the HIPAA Security Rule?
Yes, whenever it stores, transmits or processes electronic protected health information. That includes the fax server, its document store, its logs and any third party carrying the traffic, which is why the business associate agreement matters.
Should we keep investing in fax infrastructure at all?
Invest in the controls rather than the capacity. Audit trails, routing and retention keep their value whether your volume grows or halves, and they are what an auditor asks for.
Related resources
- The claims attachment rule is final: what changes by 2028
- The 2026 prior authorization rule and your fax server
- What actually makes a fax server HIPAA compliant
- HIPAA compliant fax in 2026: encryption, BAA and audit trails
- TEFCA and the fax server as interoperability fallback
Where ICTFax fits
ICTFax is fax server software you run on your own infrastructure, with per page logging, rule based routing into your existing workflow, and T.38 support, which keeps the number of outside parties in the path small. If you are working out what your fax queue will look like after these rules land, or you want the audit trail sorted before anyone asks for it, open a support ticket and we will walk through your document mix.
