Prior Authorization

Update prior authorization

Updates editable prior authorization fields for an organization-scoped case. The route uses PUT because generated Wasp public API routes do not support PATCH.

PUTNeeds publication reviewLocal writePrior AuthorizationoperationId: updatePriorAuthhttps://dev-api.quickintell.com/api/v1/prior-auth/authorizations/{priorAuthId}
Needs publication reviewLocal writePrior auth and clinical

Route status

Needs publication review

The endpoint contract is visible, but QuickRCM has not approved it yet for normal production API use.

Publication status

Needs publication review

Requires product, security/compliance, tenancy, side-effect, or module-owner approval before production public API use. Also requires E2 side-effect policy before production recipes, SDK inclusion, or try-out access.

Authentication

Bearer API key declared

OpenAPI declares bearer API-key security for this operation.

Tenant context

API-key organization

API-key organization context is authoritative; request organizationId is not a public tenant selector.

Side-effect summary

Local write

May mutate QuickRCM records. It does not prove live payer, EHR, clearinghouse, payment, or communication execution.

Source artifact

docs/openapi/openapi.json

OpenAPI 3.1.0; API 1.0.0.

When to use this endpoint

Use this page as an internal baseline for the prior auth and clinical contract generated for PUT /api/v1/prior-auth/authorizations/{priorAuthId}. External use still depends on route classification, release evidence, and endpoint-specific side-effect approval.

What this does now

Shows the generated OpenAPI shape for PUT /api/v1/prior-auth/authorizations/{priorAuthId}, but keeps the route out of ordinary production API positioning until review is complete.

What this does not do

Does not prove external GA readiness, SDK readiness, live production execution, or complete module behavior. Mutating behavior still needs side-effect and retry evidence.

Not public from this page

Do not publish this endpoint as an ordinary developer API until its unresolved decisions are closed.

Headers and tenancy

Current headers and tenant authority. Target headers stay labeled as future until OpenAPI and release evidence declare them.

HeaderRequiredCurrent statusNotes
AuthorizationYesCurrentBearer <QUICKRCM_API_KEY>. OpenAPI security: bearerAuth.
Idempotency-KeyNoTarget/futureDo not claim universal header support until E3 and OpenAPI metadata exist.
X-Request-IdNoTarget/futureUse for support correlation only after approved; not declared as a standard OpenAPI header today.

Required scopes

Unclassified until E6 route metadata exists; do not infer scopes from route names.

Wrong-org behavior

Tenant-safe 404, empty list, or 403 is endpoint-specific and remains an evidence gap until E1 is closed.

Actor and audit

No public actor, audit, or correlation contract is published from OpenAPI alone.

Idempotency and retries

Retry behavior is documented conservatively because universal idempotency headers are not declared.

TopicStatusGuidance
Current idempotencyNo idempotency mechanism is declared.Do not retry blindly. Check resource, status, batch, or job state before repeating the request.
Universal headerNot declaredDo not document universal Idempotency-Key support until OpenAPI and E3 evidence declare it.
Conflict behaviorUnresolvedSame-key changed-payload, in-flight retry, fingerprint scope, and TTL behavior remain endpoint-specific evidence gaps.

Async jobs and polling

Queued work is accepted work, not proof of completed workflow execution.

TopicStatusGuidance
Immediate responseNo 202 response declaredOpenAPI does not declare HTTP 202 for this operation.
Polling and terminal statesNot indicated by OpenAPINo generic polling contract is published from this page.
Later side effectsNot provenDo not infer background execution beyond the documented response.

Files and artifacts

File-like routes need content-class, ownership, scanning, retention, and URL policy evidence before public recipes.

TopicStatusGuidance
Content classNo file/artifact class inferredOpenAPI text does not indicate file or artifact handling for this endpoint.
Ownership and storage keysNot applicable unless a file field is presentTenant ownership must be proven before retrieval or upload docs. Never expose storage keys as public identifiers.
URLs, scanning, and retentionUnresolved unless endpoint-specific evidence existsShort-lived URLs, MIME limits, checksums, scanner status, retention, expiration, and legal hold behavior are not implied by OpenAPI examples.

Publication warnings

  • This endpoint needs explicit product, security/compliance, tenancy, or side-effect approval before publication.
  • Universal Idempotency-Key header support is not declared; retry only after checking endpoint-specific state.

Evidence

EvidenceStatusCaveat
OpenAPI artifactdocs/openapi/openapi.json; OpenAPI 3.1.0; API 1.0.0.Generated baseline contract only.
Route registryNeeds publication review from documentation classification overlay.E6 route registry evidence is still required before external publication.
Example validationGenerated examples are internal baseline aids.No external publication claim; examples must pass no-PHI/no-secret/no-raw-payload/no-storage-key checks.
Last reviewedImplementation run 20260619T-docs-impl; source boardroom packet 20260619T064820Z.Refresh this evidence for release workspaces.
Release evidenceE9 required.No SDK readiness, production readiness, or expanded external docs claim from this endpoint page.

Prior Authorization public API.

Prior Authorization APIs expose organization-scoped requirement checks, case creation and maintenance, draft saves, status transitions, renewals, local appeal tracking, bulk workflow queueing, bulk-upload batch status, and supporting-document upload setup for the tenant selected by the bearer API key. The public reference should be explicit about side effects. Requirement checks return decision-support fields and do not create authorization cases. Case create/update/status/submit endpoints return sanitized QuickRCM prior authorization summaries, not payer approvals or denials. Renewal and appeal endpoints create or update local workflow records. Bulk authorization submissions and bulk-upload batches are queue-oriented public workflows. Document submission endpoints are public validation surfaces that require `dryRun: true`; the OpenAPI descriptions state vendor submission is skipped. The current draft-save OpenAPI request schema is an `allOf` body with the create-case request fields plus optional `priorAuthId`; documentation should not imply that draft save has an empty or undocumented body. If the final docs want partial-draft behavior, the public schema must be expanded or clarified first. These endpoints can carry PHI or sensitive operational data in patient names, dates of birth, MRNs, member IDs, clinical indications, medical-necessity letters, appeal letters, document metadata, presigned upload URLs, and storage object keys. Public examples should be synthetic, and docs should tell callers not to log raw request bodies, upload URLs, S3 keys, payer portal credentials, raw EDI, transcripts, tokens, or vendor payloads. For `createPriorAuth` and `savePriorAuthDraft`, the generated OpenAPI body shows `payerId` and `payerName` as individually optional, but the public contract enforces a cross-field rule: callers must provide at least one of them. The handler uses `payerName` when supplied, attempts to resolve known payer IDs, and can return 400 asking for an explicit `payerName` when a supplied `payerId` cannot be resolved.

What this endpoint does

Use case
Use this to correct service, diagnosis, payer/member, urgency, clinical evidence, medical-necessity, lifecycle, or authorization-number fields on an existing local case.
Before calling
Read the current case and decide which supported fields should change. Include `expectedVersion` when your client tracks optimistic concurrency and wants stale-write protection.

Request and response behavior

Request guidance
All body fields are optional in the public schema, but clients should send only intended updates. Clinical/service fields include `serviceType`, `specificService`, `cptCode`, `diagnosisCode`, `diagnosisDescription`, `clinicalIndication`, `requirements`, and `medicalNecessityLetter`. Provider and payer/member fields include ordering physician values, payer id/name, and member id. Workflow fields include `urgency`, `status`, prediction score, lifecycle dates, denial reason, and authorization number. `metadata` is for sanitized integration metadata. Include `expectedVersion` only when the client has a current version marker for optimistic locking.
  • This is a PUT route with partial editable fields, not a JSON Patch document.
  • `medicalNecessityLetter` is capped at 50000 characters and can contain clinical PHI.
  • `approvalPrediction` is numeric and capped at 100 by the public schema.
Response semantics
HTTP 200 returns the updated local `data.priorAuth` summary. This endpoint mutates QuickRCM case state; it does not itself prove payer approval, denial, submission receipt, or document acceptance.
  • Returned status is local QuickRCM case state.
  • Lifecycle timestamp fields can remain null.
  • The response does not include raw external payer content.

Errors and retries

Treat 409 as the optimistic-locking conflict declared by OpenAPI, typically requiring a fresh read before another update attempt. Treat 400 as invalid field values, 404 as missing or wrong-tenant case context, 429 as a backoff signal, and 5xx as transient only with bounded retries. Re-read the case after timeouts before retrying to avoid overwriting newer edits.
  • 409 is declared as an optimistic locking conflict, not a generic case-state conflict.
  • 404 can mean the case is outside the API key organization.
  • Retry only after re-reading current state when stale writes are possible.

Template boundary before examples

The route class, authentication state, tenancy rule, side-effect mode, idempotency status, async behavior, file policy, warnings, links, and evidence above are part of the endpoint contract. Treat generated examples below as internal baseline aids until release evidence closes.

Path parameters

NameLocationRequiredTypeDescriptionValidation and safety notes
priorAuthIdpathYesstringQuickRCM prior authorization case identifier in the path. It must resolve inside the authenticated organization.Minimum length: 1.

Query parameters

This endpoint does not define query parameters.

OpenAPI-declared header parameters

Standard platform header guidance appears in the governance panel. This table only lists operation-specific headers declared in OpenAPI.

This endpoint does not define operation-specific header parameters.

Request body

JSON fields from the generated OpenAPI schema with pilot enrichment applied where available. Nested object fields are shown with dotted paths.

NameLocationRequiredTypeDescriptionValidation and safety notes
expectedVersionbodyNointegerOptional optimistic-concurrency version marker. Use it when the client has a current version and wants stale-write conflict detection.OpenAPI does not declare additional validation metadata.
serviceTypebodyNoIMAGING | SURGERY | THERAPY | DME | MEDICATION | imaging | surgery | therapy | dme | medication | imaging-xray | imaging-lab | imaging-mri | imaging-pet | surgery-oral | surgery-periodontal | surgery-anesthesia | surgery-assistance | therapy-radiation | therapy-inhalation | therapy-chemotherapy | therapy-dialysis | dme-purchased | dme-rental | dme-prosthetics | dme-hearing | dme-oxygen | medication-brand | medication-generic | medication-mail-orderOptional replacement service category or detailed service-family enum from the public schema.Enum values are declared in the Type column.
specificServicebodyNostringOptional replacement service description, capped at 250 characters.Minimum length: 1. Maximum length: 250.
cptCodebodyNostringOptional replacement CPT or procedure code, capped at 40 characters.Minimum length: 1. Maximum length: 40.
diagnosisCodebodyNostringOptional replacement diagnosis code, capped at 40 characters.Minimum length: 1. Maximum length: 40. Potential PHI; use synthetic examples and avoid logging raw values.
diagnosisDescriptionbodyNostringOptional replacement diagnosis description, capped at 500 characters.Minimum length: 1. Maximum length: 500. Potential PHI; use synthetic examples and avoid logging raw values.
orderingPhysicianbodyNostringOptional ordering physician name or display label, capped at 200 characters.Minimum length: 1. Maximum length: 200.
orderingPhysicianNPIbodyNostringOptional ordering physician National Provider Identifier, capped at 20 characters.Minimum length: 1. Maximum length: 20.
clinicalIndicationbodyNostringOptional clinical rationale, capped at 5000 characters. Avoid raw transcripts or unnecessary PHI.Minimum length: 1. Maximum length: 5000. Potential PHI; use synthetic examples and avoid logging raw values.
payerIdbodyNostringOptional payer identifier associated with the case, capped at 120 characters.Minimum length: 1. Maximum length: 120.
payerNamebodyNostringOptional payer display name, capped at 200 characters.Minimum length: 1. Maximum length: 200.
memberIdbodyNostringOptional payer member or subscriber identifier, capped at 120 characters. Treat as PHI-adjacent.Minimum length: 1. Maximum length: 120. Potential PHI; use synthetic examples and avoid logging raw values.
urgencybodyNobooleanOptional boolean urgent-workflow marker for the local prior authorization case.OpenAPI does not declare additional validation metadata.
requirementsbodyNounknownOptional structured requirements object for local case tracking. Do not include raw vendor payloads.OpenAPI does not declare additional validation metadata.
metadatabodyNoobjectOptional sanitized integration metadata object; never store credentials, tokens, raw EDI, upload URLs, or storage secrets.Sensitive credential or storage-adjacent value; use placeholders only.
statusbodyNopending_submission | submitted | approved | denied | more_info_required | draft | in_review | partially_approved | expired | appealed | appeal_approved | appeal_denied | cancelled | voidedOptional local prior authorization workflow status from the public status enum.Enum values are declared in the Type column.
approvalPredictionbodyNonumberOptional numeric prediction score capped at 100. Do not present it as a payer decision.Minimum value: 0. Maximum value: 100. File, artifact, or raw-payload adjacent; keep examples metadata-only.
medicalNecessityLetterbodyNostringOptional clinical letter text, capped at 50000 characters. Do not include transcripts, raw payer payloads, or credentials.Minimum length: 1. Maximum length: 50000. Sensitive credential or storage-adjacent value; use placeholders only.
submittedAtbodyNostring (date-time)Optional ISO datetime recording when the case was submitted in local workflow state.Format: date-time. File, artifact, or raw-payload adjacent; keep examples metadata-only.
approvedAtbodyNostring (date-time)Optional ISO datetime recording local approval state evidence.Format: date-time. File, artifact, or raw-payload adjacent; keep examples metadata-only.
deniedAtbodyNostring (date-time)Optional ISO datetime recording local denial state evidence.Format: date-time. File, artifact, or raw-payload adjacent; keep examples metadata-only.
expirationDatebodyNostring (date-time)Optional ISO datetime for authorization expiration when known.Format: date-time.
denialReasonbodyNostringOptional denial reason text capped at 2000 characters. Keep it sanitized.Minimum length: 1. Maximum length: 2000.
authorizationNumberbodyNostringOptional payer-facing authorization number when captured.Minimum length: 1. Maximum length: 100.

Generated request example

Generated examples are baseline contract aids only. They are not external publication evidence and must not include real PHI, credentials, raw vendor payloads, raw EDI, transcripts, storage keys, or signed URLs.

{
  "expectedVersion": 1,
  "serviceType": "IMAGING",
  "specificService": "example-specificservice",
  "cptCode": "example-cptcode",
  "diagnosisCode": "example-diagnosiscode",
  "diagnosisDescription": "Example prior_auth note",
  "orderingPhysician": "example-orderingphysician",
  "orderingPhysicianNPI": "1234567893"
}

Successful responses

Generated response examples show the baseline OpenAPI contract. Tenant identifier echo, PHI redaction, pagination, money, date/time, and enum semantics remain endpoint-specific publication checks.

200
Updated prior authorization.
Generated from the OpenAPI response schema.
{
  "success": true,
  "data": {
    "priorAuth": {
      "id": "00000000-0000-4000-8000-000000000001",
      "organizationId": "00000000-0000-4000-8000-000000000001",
      "caseId": "00000000-0000-4000-8000-000000000001",
      "status": "active",
      "patientId": "00000000-0000-4000-8000-000000000001",
      "appointmentId": "00000000-0000-4000-8000-000000000001",
      "urgency": true,
      "serviceType": "30",
      "specificService": "example-specificservice",
      "cptCode": "example-cptcode",
      "diagnosisCode": "example-diagnosiscode",
      "diagnosisDescription": "Example prior_auth note",
      "orderingPhysician": "example-orderingphysician",
      "orderingPhysicianNPI": "1234567893",
      "payerId": "87726",
      "payerName": "Example prior_auth",
      "memberId": "W123456789",
      "authorizationNumber": "example-authorizationnumber",
      "submittedAt": "2026-06-08T10:15:30Z",
      "approvedAt": "2026-06-08T10:15:30Z",
      "deniedAt": "2026-06-08T10:15:30Z",
      "denialReason": "example-denialreason",
      "expirationDate": "2026-06-08T10:15:30Z",
      "createdAt": "2026-06-08T10:15:30Z",
      "updatedAt": "2026-06-08T10:15:30Z"
    }
  },
  "meta": {
    "organizationId": "00000000-0000-4000-8000-000000000001"
  }
}

Error responses

Errors must remain sanitized. Do not include raw payer, EHR, SFTP, SMTP, Stripe, LLM/OCR, browser automation, file, transcript, EDI, worker, or vendor payloads.

400
Invalid request.
Handle this response as normal integration control flow.
{
  "error": "Request validation failed",
  "statusCode": 400
}
401
Authentication required or invalid credentials.
Handle this response as normal integration control flow.
{
  "error": "Authentication required",
  "statusCode": 401
}
403
The requested organization does not match the authenticated caller.
Handle this response as normal integration control flow.
{
  "error": "Forbidden",
  "statusCode": 403
}
404
Prior authorization not found in the authenticated organization.
Handle this response as normal integration control flow.
{
  "error": "Resource not found",
  "statusCode": 404
}
409
Optimistic locking conflict.
Handle this response as normal integration control flow.
{
  "error": "Resource conflict",
  "statusCode": 409
}
429
API key rate limit exceeded.
Handle this response as normal integration control flow.
{
  "error": "Rate limit exceeded",
  "statusCode": 429
}
500
Internal server error.
Handle this response as normal integration control flow.
{
  "error": "Internal server error",
  "statusCode": 500
}

Adjacent endpoints

Nearby generated endpoints in the same OpenAPI tag. Route class and side-effect labels still apply per endpoint.

Update prior authorization | QuickRCM API Docs | QuickRCM API Docs