CO-284 denial code
Authorization number may be valid but does not apply to the billed services
How to fix it
Compare the authorised procedures and dates against what was billed, and request an amended authorisation.
How to prevent it
Store authorisations against specific procedures and date ranges, not just against the patient.
In practice
A surgical authorisation names one procedure. During the operation a second, related procedure proves necessary and is performed. Both are billed and the claim returns CO-284 against the unauthorised line.
The authorisation is valid and covers something narrower than what happened. Authorisations are issued for specific procedures, dates and units, and anything outside those parameters is unauthorised.
Request an amended authorisation covering what was actually performed, supported by the operative note explaining why the additional work was necessary. Intraoperative findings are a recognised basis for amendment.
What sits behind it
The parameters that can fail are more numerous than practices expect: the procedure code, the date or date range, the number of units or visits, the facility, and the rendering provider. A mismatch on any one produces this code.
Storing authorisations against the patient rather than against the specific procedure and date range is what makes these easy to miss. A system that records an authorisation number without recording what it covers cannot warn anyone when a claim exceeds it.
The related codes narrow the failure further. CO-296 means the authorisation named a different provider, CO-302 means it had expired, and CO-287 means a referral's visit limit was exceeded. Each points at a different parameter of the same permission.
Related codes
Terms used here — Prior Authorization · Modifier · Appeal
How we handle it — Prior Authorization · Denial Management · Claims Management
Primary sources
The rules behind CO-284, at the bodies that publish them.
- CMS Interoperability and Prior Authorization Final Rule (CMS-0057-F) (opens in a new tab)
Centers for Medicare & Medicaid Services — The rule imposing prior authorization decision timelines and API requirements on impacted payers. It is the single largest scheduled change to authorization workflow this decade.
- Medicare Coverage Database (LCD/NCD) (opens in a new tab)
Centers for Medicare & Medicaid Services — Searchable national and local coverage determinations. The direct answer to whether a diagnosis supports medical necessity for a given procedure.
- Medicare Claims Processing Manual (opens in a new tab)
Centers for Medicare & Medicaid Services — The operative manual for how Medicare claims must be coded, submitted, adjusted and appealed. When a payer policy and a vendor's advice disagree, this settles it.
Looking for a different code? Search all 190 CARC and RARC codes
Questions about CO-284
Often, where intraoperative findings made additional work necessary. Requesting an amendment supported by the operative note explaining why is a recognised route, and plans generally accept that surgical necessity cannot always be predicted in advance.
The procedure code, the date or date range, the number of units or visits, the facility and the rendering provider. A mismatch on any single parameter produces this denial even where everything else about the authorisation is correct.
Against the specific procedures, dates and units they cover, not merely against the patient. A system recording only an authorisation number cannot warn anyone when a claim exceeds what was actually authorised.
Find out what your denials are costing you
A free billing audit reviews your denial rate, AR aging and clean claim rate against industry benchmarks. Takes about two minutes to request. No sales pitch.
No setup fees · You pay when we collect · Pricing from 3% of net collections