
ABA Prior Authorization Tracking: How to Stop Losing Units, Missing Deadlines, and Eating Denials
Authorization problems drive a huge share of ABA claim denials. Learn how to track authorized units by CPT code, prevent billing past authorization
Ask any ABA billing team where their denials come from, and authorization problems will be at or near the top of the list: services delivered after an auth expired, units billed beyond what was approved, sessions rendered under the wrong code's allocation, reauth packets submitted late.
What makes auth denials uniquely painful is that they're usually unrecoverable. A coding error can be corrected and resubmitted. Care delivered outside an authorization often simply doesn't get paid — and in over-utilization cases, payers can claw back what they already paid and flag your practice for audit.
Here's a system for making that a non-event.
Why ABA Authorizations Are Harder Than Other Specialties
Units are allocated per CPT code, not per client. A typical ABA auth grants separate unit pools — say, direct treatment (97153), protocol modification (97155), caregiver training (97156) — each with its own limit over the auth period. Tracking "hours remaining" per client isn't enough; you need remaining units per code, per auth period.
Multiple providers draw from the same pool. Three technicians and a BCBA all deliver sessions against one client's 97153 allocation. Without a shared, live counter, nobody sees the pool draining until it's gone.
Auth periods and treatment plans move on different clocks. Reauthorization typically requires an updated assessment and treatment plan — which means the clinical work has to start weeks before the auth expires, not when the front desk notices the date.
Payer-specific quirks everywhere. Retro-auth grace windows, concurrent-code rules, assessment-code (97151) limits per year, differing definitions of the auth start date — each contract behaves differently.
The Five Failure Modes (and the Control for Each)
1. Billing Past the Expiration Date
Control: Auth end-dates visible at scheduling time. If a session is booked beyond the active auth window, the scheduler — not the biller, weeks later — should see the warning.
2. Exceeding Authorized Units on a Code
Control: Live unit countdown per CPT code that decrements as sessions are scheduled (not just as they're billed). Scheduling against remaining units prevents over-delivery; tracking only billed units catches it after the care is already given away.
3. Rendering Under a Code That Isn't Authorized
Control: The session type → CPT code mapping should validate against the auth at booking. If 97156 caregiver training isn't on this auth, the appointment type shouldn't be bookable without a flag.
4. Missing the Reauthorization Runway
Control: Automatic alerts at 60/45/30 days before expiration — routed to the clinical team (who must produce the updated plan), not just billing. Track the reauth as a mini-project: assessment scheduled → plan updated → packet submitted → auth received.
5. Believing the Auth Instead of Verifying It
Control: Re-verify benefits and auth status when anything changes — new plan year, MCO transition, employer plan switch. January is denial season for exactly this reason.
What "Good" Looks Like in Practice
A well-run auth workflow has one property above all: nobody has to remember anything. The system knows every client's active auths, per-code unit balances, and expiration dates — and surfaces them where decisions happen:
- At scheduling: "This booking will exceed remaining 97153 units" / "Auth expires before this recurring series ends."
- At documentation: Session codes validated against the active auth.
- At billing: Claims blocked or flagged when units or dates don't reconcile.
- On a dashboard: Every auth expiring in the next 60 days, with reauth status.
This is precisely what TherapyPM's Authorization module does — unit tracking by CPT code tied directly into scheduling, documentation, and claims, so over-utilization gets stopped at the calendar instead of discovered on the EOB.
A Note on Over-Utilization Risk
Billing beyond authorized units isn't just a denial risk — payers treat patterns of over-utilization as a program-integrity issue. Recoupments, prepayment review, and audits follow. The financially and clinically safe posture is the same one: deliver exactly what's authorized, and when clinical need exceeds the auth, request a modification before delivering the additional care.
Frequently Asked Questions
Can We Bill While a Reauthorization Is Pending?
Payer-dependent. Some allow continuity-of-care grace periods or backdate to the request date; many don't. Know each contract's rule before the gap, not during it.
Do Assessments (97151) Need Prior Auth Too?
Frequently yes, with annual or per-episode limits. Treat 97151 units as their own tracked pool.
What If a Payer's Portal Shows Different Remaining Units Than Our System?
Reconcile monthly. Discrepancies usually mean denied/adjusted claims you haven't posted — which means your "remaining units" are wrong in the dangerous direction.
Never Eat an Auth Denial Again
The TherapyPM RCM team sees the same story constantly: strong clinical practices losing five figures a year to authorization gaps that software should have caught. TherapyPM tracks every unit of every auth by CPT code and warns you at scheduling — and our RCM team can audit your current auth exposure and clean up in-flight reauthorizations.
See Authorization Tracking in TherapyPM · Request an Auth-Exposure Review
Ready to simplify your therapy practice?
Join 500+ clinics already using TherapyPM to streamline billing, documentation, credentialing, and more.


