Back to articles
Healthcare Operations

Remote Patient Monitoring: Managing Vendors, Billing, and Medical Necessity

Dr. Jose I. Delgado
5 min read
Remote Monitoring Fraud

Remote Patient Monitoring (RPM) has transformed chronic care management by allowing clinicians to track patient health data between office visits. However, the rapid expansion of RPM has also attracted significant regulatory attention. Healthcare organizations offering these services must navigate a complex web of compliance responsibilities, spanning patient eligibility, clinical consent, device logistics, billing rules, and third-party vendor oversight. Understanding the distinction between current requirements and proposed regulatory updates is essential for maintaining a compliant RPM program.

Why the Issue Matters Now

Federal payors and enforcement agencies have intensified audits on RPM billing, focusing heavily on whether services meet strict medical necessity criteria and whether clinical monitoring time is accurately documented. Organizations often partner with third-party vendors to supply devices, software platforms, and monitoring support. While these partnerships expand operational capacity, the healthcare provider remains ultimately responsible for billing accuracy and patient care quality. Staying informed on Centers for Medicare & Medicaid Services (CMS) policy updates ensures your practice avoids improper billing and compliance penalties.

Key Warning Signs

Identifying vulnerabilities in an RPM program requires monitoring specific operational and clinical indicators:

  • High volumes of billed RPM codes with minimal accompanying physician documentation or evidence of clinical interpretation.

  • Ambiguous agreements with third-party RPM vendors that blur the lines between administrative support and clinical services.

  • Enrolling patients without securing documented informed consent or verifying that the patient is physically and cognitively capable of using the monitoring devices.

  • Inadequate tracking of the required number of days of data transmission per billing cycle.

Real-World Enforcement & Validity

Federal agencies—including the Department of Justice (DOJ), the Department of Health and Human Services Office of Inspector General (HHS-OIG), and the Centers for Medicare & Medicaid Services (CMS)—have significantly scaled up investigations into improper RPM practices. Between 2019 and 2025, Medicare payments for RPM surged from $15 million to over $500 million, leading federal regulators to establish targeted audit measures and enforce the False Claims Act (FCA).

Case 1: Billing Non-Compliant Devices & Illegal Kickback Schemes

  • What Happened: In United States ex rel. Chavous v. Health Wealth Safe, Inc., a Georgia-based RPM management company and its physician owner engaged in a multi-year scheme to bill Medicare for non-reimbursable RPM services. The company submitted claims without providing patients with FDA-approved devices capable of automatically transmitting physiologic data—a fundamental CMS coverage requirement. Additionally, the company offered medical practices free access to Electronic Health Record (EHR) software as an illegal kickback in exchange for patient records, which were then used to cold-call beneficiaries and generate unauthorized RPM billing.

  • Government Action: Initiated via a whistleblower (qui tam) action, the DOJ and HHS-OIG conducted an investigation into False Claims Act violations. In June 2025, the DOJ announced a $1.29 million civil settlement paid by the company and its owner to resolve allegations of submitting false claims and failing to return improper Medicare reimbursements.

Case 2: Marketing Portals and Upcoding Remote Cardiac Monitoring

  • What Happened: BioTelemetry Inc. and its subsidiary, LifeWatch Services Inc., utilized software portals and sales personnel to steer clinical staff toward ordering higher-cost Mobile Cardiovascular Telemetry (MCT) services. Even when ordering physicians intended to select less expensive Holter or cardiac event monitors, the company’s online portal and sales tactics were designed to default enrollment to the highest-reimbursing remote cardiac monitoring category without clinical necessity.

  • Government Action: The DOJ intervened under the False Claims Act to target improper billing for cardiac RPM services. In December 2023, the federal government secured a $14.7 million settlement against LifeWatch Services Inc. to resolve allegations of fraudulent upcoding and billing for services that lacked medical necessity.

Case 3: Federal Enforcement Playbook & Consumer Alerts

  • What Happened: Following an influx of beneficiary complaints regarding unsolicited cold calls and unauthorized delivery of monitoring devices, HHS-OIG published official Consumer Alerts and a formal Data Snapshot auditing framework.

  • Government Action: Federal regulators established standardized audit triggers targeting practices that exhibit:

    1. Sudden, disproportionate spikes in RPM enrollment.

    2. Billing RPM codes for patients with no established prior physician-patient relationship.

    3. Extended monthly device billing without documented clinical treatment management or interactive time.

Operational Impact

RPM compliance failures carry substantial operational risks. Billing for monitoring services that lack medical necessity or proper documentation can lead to severe audit findings, claim denials, and False Claims Act liability. On the vendor side, poor integration between third-party platforms and Electronic Health Records (EHR) can create data silos, delaying critical clinical interventions and exposing the organization to privacy and security vulnerabilities. Comprehensive governance is necessary to align clinical workflows with billing rules.

Practical Actions for Healthcare Organizations

To build a sustainable and compliant RPM program, organizations should implement these prioritized steps:

  1. Verify Patient Eligibility and Consent: Ensure every patient enrolled meets clinical criteria and signs a detailed consent form acknowledging out-of-pocket cost obligations.

  2. Audit Documentation and Billing Times: Routinely verify that data transmission days and interactive clinical communication times meet exact CMS billing thresholds.

  3. Vet Third-Party Vendors: Conduct thorough due diligence on all RPM technology and service partners, ensuring clear Business Associate Agreements (BAAs) and defined operational boundaries.

  4. Establish Clear Clinical Protocols: Define who reviews incoming patient data, how clinical alerts are triaged, and where actions are documented in the EHR.

Compliance Connection

Managing an effective RPM program requires robust policies, specialized staff training, and continuous monitoring. Administrators must integrate RPM billing reviews into their monthly compliance routines to catch documentation gaps early. Identifying these operational risks, maintaining updated security governance, and training staff are fundamental steps in protecting your practice. Utilizing a centralized compliance platform like EPI Compliance helps practices maintain up-to-date policies, track staff education requirements, and oversee third-party vendor performance effectively. Additionally, leadership accountability and comprehensive risk management can be reinforced through specialized education, such as the Certified HIPAA Security Officer (CHSO) program offered by Taino Consultants, alongside periodic HIPAA Security Risk Analyses.

Conclusion and Call to Action

Remote Patient Monitoring offers immense value for patient outcomes when managed with rigorous attention to compliance. Evaluate your RPM workflows, verify your documentation standards, and ensure your program aligns with current federal guidelines.

Call to Action: Explore the EPI Compliance platform to streamline your RPM policies, staff training, and monthly compliance oversight, or contact Taino Consultants to schedule a comprehensive Risk Analysis for your digital health programs.

Sources List

Educational Disclaimer: This article is intended solely for general educational purposes and does not constitute formal legal, financial, or billing advice. Healthcare organizations should consult with legal counsel or certified compliance experts regarding specific regulatory requirements.

About Dr. Jose I. Delgado

Dr. Jose I. Delgado is the founder and CEO of Taino Consultants, a veteran-owned, 8(a) graduate healthcare IT consulting firm based in St. Augustine, Florida. With over 30 years of experience in healthcare compliance and government contracting, Dr. Delgado has helped organizations navigate HIPAA, MACRA/MIPS, and federal IT security requirements.

Need help with healthcare compliance?

Taino Consultants provides HIPAA compliance consulting, MACRA/MIPS compliance support, and healthcare IT modernization services for government and private healthcare organizations.

Schedule a consultation