
Remote Patient Monitoring (RPM) has transformed chronic care management by allowing clinicians to track patient health data between office visits. However, the rapid expansion of RPM has also attracted significant regulatory attention. Healthcare organizations offering these services must navigate a complex web of compliance responsibilities, spanning patient eligibility, clinical consent, device logistics, billing rules, and third-party vendor oversight. Understanding the distinction between current requirements and proposed regulatory updates is essential for maintaining a compliant RPM program.
Why the Issue Matters Now
Federal payors and enforcement agencies have intensified audits on RPM billing, focusing heavily on whether services meet strict medical necessity criteria and whether clinical monitoring time is accurately documented. Organizations often partner with third-party vendors to supply devices, software platforms, and monitoring support. While these partnerships expand operational capacity, the healthcare provider remains ultimately responsible for billing accuracy and patient care quality. Staying informed on Centers for Medicare & Medicaid Services (CMS) policy updates ensures your practice avoids improper billing and compliance penalties.
Key Warning Signs
Identifying vulnerabilities in an RPM program requires monitoring specific operational and clinical indicators:
High volumes of billed RPM codes with minimal accompanying physician documentation or evidence of clinical interpretation.
Ambiguous agreements with third-party RPM vendors that blur the lines between administrative support and clinical services.
Enrolling patients without securing documented informed consent or verifying that the patient is physically and cognitively capable of using the monitoring devices.
Inadequate tracking of the required number of days of data transmission per billing cycle.
Real-World Enforcement & Validity
Federal agencies—including the Department of Justice (DOJ), the Department of Health and Human Services Office of Inspector General (HHS-OIG), and the Centers for Medicare & Medicaid Services (CMS)—have significantly scaled up investigations into improper RPM practices. Between 2019 and 2025, Medicare payments for RPM surged from $15 million to over $500 million, leading federal regulators to establish targeted audit measures and enforce the False Claims Act (FCA).
Case 1: Billing Non-Compliant Devices & Illegal Kickback Schemes
What Happened: In United States ex rel. Chavous v. Health Wealth Safe, Inc., a Georgia-based RPM management company and its physician owner engaged in a multi-year scheme to bill Medicare for non-reimbursable RPM services. The company submitted claims without providing patients with FDA-approved devices capable of automatically transmitting physiologic data—a fundamental CMS coverage requirement. Additionally, the company offered medical practices free access to Electronic Health Record (EHR) software as an illegal kickback in exchange for patient records, which were then used to cold-call beneficiaries and generate unauthorized RPM billing.
Government Action: Initiated via a whistleblower (qui tam) action, the DOJ and HHS-OIG conducted an investigation into False Claims Act violations. In June 2025, the DOJ announced a $1.29 million civil settlement paid by the company and its owner to resolve allegations of submitting false claims and failing to return improper Medicare reimbursements.
Case 2: Marketing Portals and Upcoding Remote Cardiac Monitoring
What Happened: BioTelemetry Inc. and its subsidiary, LifeWatch Services Inc., utilized software portals and sales personnel to steer clinical staff toward ordering higher-cost Mobile Cardiovascular Telemetry (MCT) services. Even when ordering physicians intended to select less expensive Holter or cardiac event monitors, the company’s online portal and sales tactics were designed to default enrollment to the highest-reimbursing remote cardiac monitoring category without clinical necessity.
Government Action: The DOJ intervened under the False Claims Act to target improper billing for cardiac RPM services. In December 2023, the federal government secured a $14.7 million settlement against LifeWatch Services Inc. to resolve allegations of fraudulent upcoding and billing for services that lacked medical necessity.
Case 3: Federal Enforcement Playbook & Consumer Alerts
What Happened: Following an influx of beneficiary complaints regarding unsolicited cold calls and unauthorized delivery of monitoring devices, HHS-OIG published official Consumer Alerts and a formal Data Snapshot auditing framework.
Government Action: Federal regulators established standardized audit triggers targeting practices that exhibit:
Sudden, disproportionate spikes in RPM enrollment.
Billing RPM codes for patients with no established prior physician-patient relationship.
Extended monthly device billing without documented clinical treatment management or interactive time.
Operational Impact
RPM compliance failures carry substantial operational risks. Billing for monitoring services that lack medical necessity or proper documentation can lead to severe audit findings, claim denials, and False Claims Act liability. On the vendor side, poor integration between third-party platforms and Electronic Health Records (EHR) can create data silos, delaying critical clinical interventions and exposing the organization to privacy and security vulnerabilities. Comprehensive governance is necessary to align clinical workflows with billing rules.
Practical Actions for Healthcare Organizations
To build a sustainable and compliant RPM program, organizations should implement these prioritized steps:
Verify Patient Eligibility and Consent: Ensure every patient enrolled meets clinical criteria and signs a detailed consent form acknowledging out-of-pocket cost obligations.
Audit Documentation and Billing Times: Routinely verify that data transmission days and interactive clinical communication times meet exact CMS billing thresholds.
Vet Third-Party Vendors: Conduct thorough due diligence on all RPM technology and service partners, ensuring clear Business Associate Agreements (BAAs) and defined operational boundaries.
Establish Clear Clinical Protocols: Define who reviews incoming patient data, how clinical alerts are triaged, and where actions are documented in the EHR.
Compliance Connection
Managing an effective RPM program requires robust policies, specialized staff training, and continuous monitoring. Administrators must integrate RPM billing reviews into their monthly compliance routines to catch documentation gaps early. Identifying these operational risks, maintaining updated security governance, and training staff are fundamental steps in protecting your practice. Utilizing a centralized compliance platform like EPI Compliance helps practices maintain up-to-date policies, track staff education requirements, and oversee third-party vendor performance effectively. Additionally, leadership accountability and comprehensive risk management can be reinforced through specialized education, such as the Certified HIPAA Security Officer (CHSO) program offered by Taino Consultants, alongside periodic HIPAA Security Risk Analyses.
Conclusion and Call to Action
Remote Patient Monitoring offers immense value for patient outcomes when managed with rigorous attention to compliance. Evaluate your RPM workflows, verify your documentation standards, and ensure your program aligns with current federal guidelines.
Call to Action: Explore the EPI Compliance platform to streamline your RPM policies, staff training, and monthly compliance oversight, or contact Taino Consultants to schedule a comprehensive Risk Analysis for your digital health programs.
Sources List
U.S. Department of Justice (DOJ) - Remote Patient Monitoring Company Settles False Claims Act Lawsuit for $1.29 Million: https://www.justice.gov/usao-ndga/pr/remote-patient-monitoring-company-settles-false-claims-act-lawsuit-129-million
U.S. Department of Health and Human Services Office of Inspector General (HHS-OIG) - Billing for Remote Patient Monitoring in Medicare: https://oig.hhs.gov/reports/all/2025/billing-for-remote-patient-monitoring/
U.S. Department of Justice (DOJ) - LifeWatch Services False Claims Settlement: https://www.mcdonaldhopkins.com/insights/news/remote-patient-monitoring-false-claims-settlement-highlight-a-medical-necessity
Becker's Hospital Review: https://www.beckershospitalreview.com
MedCity News: https://medcitynews.com
Educational Disclaimer: This article is intended solely for general educational purposes and does not constitute formal legal, financial, or billing advice. Healthcare organizations should consult with legal counsel or certified compliance experts regarding specific regulatory requirements.
About Dr. Jose I. Delgado
Dr. Jose I. Delgado is the founder and CEO of Taino Consultants, a veteran-owned, 8(a) graduate healthcare IT consulting firm based in St. Augustine, Florida. With over 30 years of experience in healthcare compliance and government contracting, Dr. Delgado has helped organizations navigate HIPAA, MACRA/MIPS, and federal IT security requirements.
Need help with healthcare compliance?
Taino Consultants provides HIPAA compliance consulting, MACRA/MIPS compliance support, and healthcare IT modernization services for government and private healthcare organizations.
Schedule a consultationRelated articles

Demystifying the HIPAA Workforce Member: Are Your Subcontractors Covered or Are They Business Associates?

Navigation Guide for Healthcare Leaders: Medicare Provider Categories, Cash-Based Practices, and HIPAA Compliance
