Independent watchdog project. Not affiliated with the State of California, DHCS or Medi-Cal Dental.

Text size
I can't smile, California

Not the State of California

The letters that change what you are owed

An All Plan Letter is how the State tells your dental plan what to do. The name means the letter goes to all the plans. It does not mean we are going to work through all the letters. DHCS has issued more than a hundred of them, and most are plumbing. We read them and write up the ones that change what a member is entitled to. The rest are on the State's own list, linked below. First is the one that hands you your own prior authorization file.

APL 26-006, the short version, out loud

Prior Authorization Tracking

Read along

  1. Starting January first, 2027,
  2. California changes how you see your own dental care.
  3. If you are on a Medi-Cal dental managed care plan
  4. in Sacramento or Los Angeles County,
  5. this one is for you.
  6. Right now, when your dentist asks your plan
  7. to approve a procedure, you wait in the dark.
  8. Weeks, sometimes, with no idea where it stands.
  9. In 2027, that ends.
  10. Your plan must show that request on your phone,
  11. in the health app you choose,
  12. within one business day.
  13. Approved, or denied.
  14. Exactly which items.
  15. The date it expires.
  16. Every update, within one business day.
  17. You will even be able to read
  18. the clinical documentation your dentist sent in.
  19. And if you switch plans,
  20. your new plan has to go and get your history
  21. from the old one.
  22. Up to five years of claims and authorizations,
  23. within one week of you asking.
  24. No starting over.
  25. No guessing.
  26. This is All Plan Letter 26-006.
  27. California is requiring it.
  28. Your smile.
  29. Your data.
  30. In your hands.
  31. Not sponsored by the State of California
  32. or any managed care plan.
  33. I can't smile,
  34. CALIFORNIA.
  35. Maybe one day we will.

Under two minutes on one page of All Plan Letter 26-006: the part that puts your prior authorization in your own hands from 1 January 2027. Press play and read along, or tap any line to jump to it. Everything the track says is explained, sourced and expanded below.

An illustration of what the rules require. Not a real authorization record.

Prior Authorization Tracking. Written and produced by this project. Not sponsored by the State of California, DHCS, Medi-Cal Dental or any managed care plan. It is commentary, not advice, and no substitute for anything your plan sends you in writing.

Start here

What an All Plan Letter is, and what this one does

An All Plan Letter, or APL, is a letter from the California Department of Health Care Services to the plans it pays. It is not a law and it is not a press release. It is an instruction, and the plans have to follow it or explain themselves. DHCS publishes them all in one place, and almost nobody outside the industry reads them.

That is a shame, because the letters are where members find out what they are owed. This one is a good example. It is addressed to the plans, it is written in the language of federal rule numbers, and buried in it is a promise that from 1 January 2027 you can watch your own prior authorization move.

All Plan Letter 26-006 is dated 24 June 2026. Its subject line is “INTEROPERABILITY FINAL RULES REQUIREMENTS FOR DENTAL MANAGED CARE PLANS.” It replaces APL 22-013, which covered the older half of the same federal rules, and it carries the whole of the new half. It ends with the line that gives every APL its teeth: “Any failure to meet the requirements of this APL may result in a Corrective Action Plan (CAP) and/or monetary sanctions.”

Behind it sit two federal rules. The first, from May 2020, made plans open a door to your claims. The second, from January 2024, makes them open four more doors and put prior authorization behind one of them. California is not inventing any of this. What California is doing is telling its three dental plans, in writing, that it applies to them.

TO: ALL MEDI-CAL DENTAL MANAGED CARE PLANS
Source The address line of Dental All Plan Letter 26-006, issued 24 June 2026 and signed by the Chief of the Medi-Cal Dental Services Division. In Sacramento and Los Angeles counties that address line means three companies: Health Net, Liberty Dental Plan, and California Dental Network (DentaQuest). Between them they hold every Medi-Cal dental managed care contract there is.

Who this page is for. Dental managed care runs in two counties. In Sacramento, joining a plan is mandatory. In Los Angeles, it is voluntary and most members stay in fee-for-service. If you are in one of the other 55 counties, this letter is not addressed to your program. The county rules are here.

The part the track is about

What your plan must put in your hands

Section A of the letter covers the Patient Access API. Strip out the acronym and it is a socket on the side of your plan. You pick a health app, you give it permission, it plugs in, and your plan has to hand over what it holds about you.

Three things about that socket are worth knowing before the detail. It is your permission that opens it, and nobody else's. Your plan does not get to decide that the app you picked is the wrong one, except on a security ground it can defend. And the letter is explicit that using it must not be a chore.

The standard the plans are held to

“… through the use of common technologies and without special effort from the Member.”

APL 26-006, section A. The same sentence requires the plan to hand the data to a third party application acting “with the approval and at the direction of a Member,” or of someone the member has appointed in writing. A plan may cut off an app only when it reasonably determines, consistent with its own security risk analysis under the HIPAA Security Rule, that letting the app carry on is an unacceptable risk, judged by “objective verifiable criteria that are applied fairly and consistently across all applications and developers.”

What has to be there, and how fast

The plan must go back to dates of service on or after 1 January 2016. Three kinds of information are already covered. A fourth arrives on 1 January 2027, and that fourth one is the reason for the track.

Table 1 of APL 26-006, what the Patient Access API must carry and by when
What By when
Your claims, once they are settled Within one business day after the claim is processed. That includes claims you could appeal, claims you did appeal, what the plan paid your dentist, and anything you were charged.
Your clinical record, in the federal standard set Within one business day after the plan receives it. The standard set was USCDI version 1. From 1 January 2026 it is version 3, which is a longer list.
Encounter data Within one business day after the plan receives it from providers. This matters in dental managed care, where plans pay many dentists a flat monthly amount per member rather than per filling, so an encounter record may be the only trace that a visit happened.
Prior authorizations, from 1 January 2027 Visible no later than one business day after the plan receives the request, updated no later than one business day after any change of status, and kept visible for as long as the authorization is live and for at least one year after its last change of status.

The six things a prior authorization must show

This is the list from the letter. Every one of these has to be visible to you, in the app you chose, for every request your dentist sends on your behalf from 1 January 2027, drugs excepted.

  • The status. Where the request is right now.
  • The date it was approved or denied.
  • The date or the circumstance under which it ends. An approval is not open ended, and you get to see the expiry rather than discover it.
  • The items and services approved. Not the request in the round. Which items.
  • If denied, a specific reason why the request was denied. Those are the letter's words.
  • The documentation your dentist sent in. The letter calls it “related structured administrative and clinical documentation submitted by a Provider related to Prior Authorizations.” The X-rays, the charting and the note arguing your case.

Our read, clearly labeled

The sixth item is the one we did not expect. Today, a member who wants to know what their dentist actually told the plan has to ask the dentist, or ask the plan for the case file after a denial. From 2027 it is supposed to be sitting in the app, before the decision, not after it. If that works as written, the gap between what your dentist says and what your plan says it received stops being invisible.

Two footnotes worth reading

Drugs are out. The letter notes that information about covered outpatient drugs is no longer required on this socket at all. For a dental plan that is a narrow exclusion, but it is there.

And the plans have to count. From 2026, by 31 March each year, every dental plan must report to DHCS how many of its members moved data to a health app they chose, and how many did it more than once. The numbers go in aggregated and stripped of names. It is the first official measure of whether any of this gets used.

The rest of the letter

Five doors, and who is allowed through each one

The letter sets out five sockets. One is for you, one is for anybody, two are for your dentist and your next plan, and one is the pipe your dentist's software uses to ask in the first place. They have different opening dates and, importantly, different consent rules.

For you

Patient Access API

Required since 1 January 2021 for claims, encounters and your clinical record. From 1 January 2027 it must also carry prior authorizations. You open it by giving a health app permission. Covered in full above.

What it must carry
For anybody

Provider Directory API

Public, with no login, because it holds no personal information. It is the plan's list of dentists in a form that software can read and check. The plan must update the online directory at least weekly.

Why weekly, and not monthly
For your dentist, unless you say no

Provider Access API

By 1 January 2027. A dentist in the network can ask the plan for the record of a patient the plan has attributed to them, and the plan must answer within one business day. You can opt out, at any time, and the plan has to give you a way to do that before it shares anything at all.

The consent rules
Between plans, if you say yes

Payer-to-Payer API

By 1 January 2027. When you change plans, your new plan must go and fetch your history from the old one, up to five years of it, and put it in your record. This one is opt in. Once you have opted in, the plan must ask within one week of having enough information to ask, within one week of your asking, and at least quarterly after that.

The consent rules
For the request itself

Prior Authorization API

By 1 January 2027. This is the pipe your dentist's software uses. It has to be loaded with the plan's own list of what needs approval, it has to state every document the plan wants for each item, and it has to answer with one of three things: approved, with the date it ends; denied, with a specific reason; or a request for more information.

Why the third answer matters
Underneath all five

The plumbing

From 1 January 2026 the plans must run current versions of the shared standards, publish complete documentation for every socket so an app maker can connect, test them, and keep them working. A socket that exists but is undocumented is not compliance.

Where we will be looking

The weekly rule, and why it survived. Federal law says a provider directory must be updated no later than 30 calendar days after the plan gets new information. California's Health and Safety Code says weekly. The letter deals with the clash in a footnote, and it comes down on the side of the member: where both laws cover the same material, “DHCS must follow the shorter weekly requirement found in Health and Safety Code section 1367.27(e)(1).” Directory accuracy is the thing this site spends most of its time on, so we will take that in writing.

If you are a dentist reading this, three parts of the letter are aimed at your office rather than at members: pulling a patient's record from the plan, the published list of every document the plan requires for a prior authorization, and the plain language provider guides each plan has to write. What changes for your office.

Section G

Deadlines, and the reason for no

The letter does two things to the decision itself, as opposed to the record of it.

First, it notes that the federal rule changed the timeframe for a standard prior authorization, and that the decision and the specific reason for a denial must both be communicated inside that timeframe. A denial that arrives on time but says nothing useful is not the standard any more.

Second, it does not restate the numbers. It points the plans at the contract and at the other APLs on the subject. That is not evasion. The contract's own deadline for a routine request has not changed. What the federal rule moved is the outer limit sitting behind it, from 14 calendar days down to 7.

The number you actually need is 5 business days for a routine request and 72 hours for an urgent one, with a letter to you within 2 business days of the decision, and a missed deadline counting as a denial you can appeal. Those come from the contract and from APL 22-006, and we have them set out line by line, with the sources, on the prior authorization deadlines page.

The third answer the Prior Authorization API has to be able to give is the interesting one: a request for more information. Today that conversation happens by fax and phone and often stalls, and a stalled request is what eats the clock. Putting it in the pipe, with the plan's own list of required documents published in advance, is the part of this letter most likely to shorten a real wait.

The part we will be checking every March

The numbers every plan now has to publish

Starting in 2026, by 31 March each year, each dental plan must post the previous calendar year's prior authorization figures on its own website, covering all items and services except drugs. Not send to DHCS. Post, in public.

  • A list of every item and service that requires prior authorization
  • The percentage of standard requests approved
  • The percentage of standard requests denied
  • The percentage of standard requests approved after appeal
  • The percentage of requests where the plan took the extension, and then approved
  • The percentage of expedited requests approved
  • The percentage of expedited requests denied
  • The average and median time from request to decision, standard
  • The average and median time from request to decision, expedited

Our read, clearly labeled

Read that list again as a member of a mandatory program. Sacramento makes you choose one of three plans. Until now there has been no published number that would tell you which of the three says no most often, or which takes longest. That list is exactly that number, nine times over, and each plan has to publish it about itself. Whether it appears, where it appears and whether the three are comparable is the sort of thing this site exists to check.

The letter also puts the figures in front of the people who run the plan. Each plan must review its prior authorization metrics at least quarterly through its Quality Improvement Committee or an equivalent, and send DHCS an annual report analyzing the trends and systemic issues the figures show, what it is doing about them, and what came out of those committee reviews. The letter names one example of a fix: “implementing automated Prior Authorization approvals with high approval rates to streamline the process.” In plain words, if a plan approves a given treatment almost every time, it should stop making people wait for it.

Section F

The guides they owe you, in language you can read

None of the above is any use if nobody tells members it exists. The letter deals with that directly. Each plan must provide educational resources in an easily accessible place on its public website, or through the other ways it normally reaches members looking for their health information, in “non-technical, simple and easy-to-understand language.” They must cover, at a minimum:

  • How to protect your own privacy when you pick a health app, including what an app might do with your data afterwards
  • Which kinds of organization are and are not likely to be covered by HIPAA, what the Office for Civil Rights and the Federal Trade Commission are each responsible for, and how to complain to them
  • What the payer-to-payer and provider access exchanges are good for, your opt-in and opt-out rights, and exactly how to change your mind

The plans must tailor all of it to the people they actually serve, including literacy levels and the languages spoken, and they must combine the three explanations into one holistic account rather than three disconnected pages. Then comes the sentence we will be watching:

Who gets to review the wording

“Dental MCPs must engage their Community Advisory Committees to review and provide input on the cultural, linguistic, and outreach appropriateness of these materials.”

APL 26-006, section F. Community Advisory Committees meet in public and publish minutes. That makes this one of the few requirements in the letter whose performance a member can check without asking anybody's permission.

Dentists get their own version. Each plan must explain in plain language how a provider requests member data, including how the plan's attribution process works, which is the same process that decides whether your dentist can see you in the system at all.

If you read nothing else

What actually changes for you

Seven things in this letter are worth a member's attention. The rest is plumbing.

You can watch the request

From 1 January 2027, a prior authorization your dentist sends must appear in the health app you chose within one business day, and every change of status within one business day of the change.

A no has to say why

Not a code. A specific reason the request was denied, visible to you, inside the same deadline as the decision itself.

You can read your dentist's file

The documentation sent in on your behalf becomes something you can look at, rather than something you have to request after the fact.

Approvals show their expiry

The date, or the circumstance, on which an approval runs out has to be there in front of you. Losing an approval because it quietly expired should stop being a surprise.

Switching stops erasing you

Your new plan must fetch up to five years of claims and authorizations from the old one, within a week of your asking, once you have opted in.

You can compare the plans

Every March, each plan must publish how often it approves, how often it denies, how often an appeal overturns it, and how long it takes.

The directory has to be current

Weekly updates, and a public machine-readable copy anybody can check against. Including us.

And what it does not do. This letter changes what you can see, not what you can have. It does not add a covered benefit, it does not make an approval more likely, and it does not shorten the deadline your plan already has to answer your dentist. It also does not hand you an app. The plan has to open the socket; finding a health app you trust to plug into it is left to you, which is precisely why the letter makes the plans publish a guide about choosing one.

The calendar

When each piece is due

  1. 1 January 2021

    The first two sockets were already due: Patient Access and Provider Directory, with the policies, procedures and public documentation that go with them. This is the half of the rules that APL 22-013 carried, and it has been in force for five years.

  2. 1 January 2026

    Current standards, the longer USCDI version 3 data set, the changed prior authorization decision timeframe, the specific reason for a denial inside that timeframe, and the start of public reporting.

  3. 31 March, every year from 2026

    Each plan posts the previous year's prior authorization figures on its own website, and reports its Patient Access usage counts to DHCS.

  4. 24 June 2026

    APL 26-006 is issued, superseding APL 22-013 and putting all of it in one letter.

  5. 1 January 2027

    Prior authorization information appears on the Patient Access API. The Provider Access, Payer-to-Payer and Prior Authorization sockets all open. Member and provider education resources must be published.

  6. 90 days before each of those

    The plan has to send DHCS its updated policies and procedures, with and without track changes, or an email confirming that none were needed.

Being honest about it

What we still do not know

  • Whether the figures have been posted. The first set of prior authorization metrics fell due on 31 March 2026. We have not yet checked all three plan websites for that page, and we will not claim anything about it until we have.
  • Where the sockets are. Each plan has to publish complete documentation for every API it runs. We have not yet found and compared those pages for Health Net, Liberty and California Dental Network (DentaQuest).
  • Which apps can actually connect. A standards-based socket is not the same as a working app in a member's hand. We have not found a published list of health apps that connect to a Medi-Cal dental plan.
  • How a member opts out, or in. The letter requires a process. It does not say it must be a form, a phone call, or a checkbox, or that the plan has to tell you it exists before you go looking.
  • Who your plan thinks your dentist is. Attribution decides who can pull your record. We can find no requirement that a plan tell a member which provider it has attributed them to.

If you work at one of these plans, or you have tried to connect an app to one, we would like to hear how it went. Tell us what happened.

Read it yourself

Sources

Everything on this page comes from the letter itself and the rules it cites. The letter is 18 pages and it is not hard reading once you know what the acronyms stand for.

  1. California Department of Health Care Services, All Plan Letter 26-006: Interoperability Final Rules Requirements for Dental Managed Care Plans, 24 June 2026. The whole of this page. Section A and Table 1 for the Patient Access API and the six prior authorization items, section B for the provider directory and the weekly update footnote, section C for provider access and attribution, section D for payer to payer, section E for the prior authorization pipe, section F for the member and provider guides, section G for the decision timeframe and the nine published metrics, section H for oversight, and the closing page for policies, procedures and sanctions.
  2. DHCS, Dental Managed Care All Plan Letters. Every letter issued to the dental plans, including this one and the ones it points to. This is the page to bookmark if you want to see a rule change before your plan explains it.
  3. Centers for Medicare and Medicaid Services, Advancing Interoperability and Improving Prior Authorization Processes, CMS-0057-F, 8 February 2024. The federal rule behind the 2026 and 2027 dates.
  4. Centers for Medicare and Medicaid Services, Interoperability and Patient Access Final Rule, CMS-9115-F, 1 May 2020. The 2021 requirements that APL 22-013 carried and this letter absorbs.
  5. 42 CFR 431.60, patient access to data, including the 2027 list of prior authorization items at paragraph (b)(6) and the member education duty at paragraph (g). 42 CFR 431.61, the provider access and payer-to-payer exchanges, their consent rules and their timing. 42 CFR 431.70, the provider directory API.
  6. 42 CFR 438.210. Paragraph (d) for the decision timeframes, where the federal ceiling for a standard decision falls from 14 calendar days to 7 for rating periods starting on or after 1 January 2026, and paragraph (f) for the nine prior authorization metrics a plan must publish by 31 March. 42 CFR 438.242 is the health information system section that applies all of it to managed care plans.
  7. DHCS, All Plan Letter 25-010: Provider Directory, and the 2025 dental managed care contract. The directory requirements this letter points to, and the contract the letter sits on top of.
  8. California Health and Safety Code section 1367.27, the state provider directory law whose weekly update requirement beats the federal 30 days.

Waiting on an authorization right now?

The rules on this page start in 2027. The deadlines your plan has to meet today started a long time ago, and they are enforceable now. If yours were missed, we would like to know.

Check today's deadlines