Onyx Blog

The CMS-0057 API Health Plans Are Already Using for Value-Based Care

CMS-0057 / Compliance

The CMS-0057 API Health Plans Are Already Using for Value-Based Care

  • Home
  • /
  • The CMS-0057 API Health Plans Are Already Using for Value-Based Care

CMS-0057 requires health plans to make claims, encounter, clinical, and prior authorization information available to providers through standardized APIs.

But Provider Access does not have to be built for compliance alone.

Health plans are already implementing the API in production to support value-based care contracts—extending the same interoperability foundation to give at-risk providers the information they need to manage quality, utilization, and cost.

In this latest video in our series with Availity, Mark Scrimshire, Chief Interoperability Officer at Onyx, discusses how health plans can add the right access controls to get more value from the APIs they are already required to implement.

“We’re already seeing that the Provider Access API is being implemented in production today, but it’s being done largely for value-based care contracts.”

Mark Scrimshire, speaking with Availity

The Difference Is in the Data That Can Be Shared

Under CMS-0057, Provider Access allows an eligible provider to see where a member received care, which services were delivered, and other relevant claims and clinical information.

The financial details associated with the claim are redacted.

That makes sense for the required Provider Access use case. But value-based care arrangements create a different need.

Providers participating in at-risk contracts are accountable for both patient outcomes and the financial performance of the populations they manage. As Mark notes, they need a fuller profit-and-loss view of what is happening across that care.

That may require access to the complete explanation of benefits, including the financial information that would otherwise be withheld.

Use the Same Foundation With Different Access Controls

The opportunity is not to build a separate exchange environment for value-based care.

Health plans can extend the Provider Access infrastructure they are already implementing by introducing an additional API input or applying different controls around access to the endpoint.

Those controls can account for:

  • Who is requesting the information
  • The provider’s relationship with the health plan
  • Whether an at-risk contract is in place
  • The information the provider is authorized to receive
  • The purpose for which the data will be used

For the standard Provider Access workflow, financial details remain redacted.

For a provider operating under an authorized value-based care arrangement, the same API foundation can support access to the unredacted EOB.

“It’s a real example of how you can get more value out of the investment that you’ve made in pure interoperability compliance.”

One API Investment, More Than One Use Case

CMS-0057 is often treated as a defined set of technical requirements to complete by a deadline.

Mark’s example shows why health plans should think more broadly about what they are building.

When the infrastructure is designed with flexible identity, authorization, and access controls, the same APIs can support different users, relationships, and business needs without requiring the plan to rebuild connectivity for every use case.

That creates a practical path to extend the CMS-0057 investment across:

  • Value-based care
  • Provider collaboration
  • Care management
  • Population health
  • Additional payer-provider workflows

The API is the foundation. The access policy determines how far its value can extend.

Is Your CMS-0057 Program Ready?

Onyx helps health plans build the data foundation that powers continuous compliance—so every new CMS mandate strengthens rather than strains operations.

Our CMS Readiness Check identifies gaps across APIs, data readiness, workflow alignment, vendor handoffs, governance, testing, and operational execution.

Request Your CMS Readiness Check
Onyx Insights

Onyx Insights