Audit & Enforcement · Updated August 2026

The short answer: the OIG audit of remote patient monitoring in Medicare Part B is not coming, it is already underway. In December 2024, HHS OIG announced the Work Plan item Audit of Medicare Part B Remote Patient Monitoring Services (oig.hhs.gov/reports/work-plan), and the audit remains ongoing in the FY2026 Work Plan. OIG's Fall 2025 Semiannual Report to Congress separately flagged RPM growth as requiring enhanced oversight, and the Work Plan adds items on kickback risk in vendor-driven RPM arrangements. Layer on CMS's CY2027 proposal to bar outsourced RPM staffing, and every RPM biller should be self-auditing the four elements OIG tests, before a records request forces the issue.

LOW HIGH RPM ENFORCEMENT PRESSURE

The needle has moved into the red zone

An open OIG audit, a Semiannual Report calling for enhanced oversight, kickback-focused Work Plan additions, and a CMS staffing proposal all point at the same billing line. That convergence is what separates routine program scrutiny from an enforcement cycle.

DEC 2024 audit announced FALL 2025 SAR flags RPM FY2026 audit still open CY2027 CMS staffing proposal

The four dials OIG reads on every RPM claim

OIG audits are not mysterious. For remote patient monitoring, the reviewers test a short list of objective requirements, and each one is binary: the chart either supports it or it does not. These are the same four dials your self-audit should sweep first.

16DAYS OF DATA
Device supply (99454)

16 days of device data in the 30-day period. Enrollment alone is not transmission, and gaps here are the easiest finding an auditor can make.

20MINUTES / MONTH
Management time (99457)

20 minutes of documented treatment management time, with who did it, when, and the interactive communication that occurred. Round-number time logs invite scrutiny.

ON FILE, DATED
Patient consent

Consent obtained and documented before services are billed. If a vendor collected it, you need to be able to produce it, not point at the vendor.

WHOFURNISHED IT
The furnisher question

Who actually performed the monitoring: your clinical staff under proper supervision, or a third-party vendor's? This is the dial CMS's CY2027 proposal turns hardest.

How the oversight cycle built, step by step

  1. December 2024

    OIG opens the audit

    OIG announces the Work Plan item Audit of Medicare Part B Remote Patient Monitoring Services (oig.hhs.gov/reports/work-plan).

  2. Fall 2025

    Report to Congress raises the flag

    OIG's Fall 2025 Semiannual Report to Congress flags RPM growth as requiring enhanced oversight, elevating RPM from a line item to a named priority.

  3. FY2026

    Audit stays open, kickback focus added

    The audit remains ongoing in the FY2026 Work Plan, which adds items on kickback risk in vendor-driven RPM arrangements.

  4. CY2027 rulemaking

    CMS moves on staffing

    CMS proposes to bar outsourced RPM staffing in the CY2027 proposal, converging payment policy with OIG's integrity concerns.

Why findings hurt more than the sample

6Year lookback

OIG audit findings in this space typically become overpayment demands with six-year lookbacks. A reviewer does not need to find fraud. A pattern of 30-day periods with fewer than 16 days of device data, or time logs that cannot support 20 minutes, is enough to extrapolate a repayment demand across years of claims. The economics of RPM programs, recurring monthly billing on a large enrolled panel, are exactly what makes extrapolation painful: a small per-claim defect multiplied across every enrolled patient, every month, for six years.

The vendor-driven model deserves its own risk review. Where a turnkey RPM company supplies the devices, enrolls the patients, performs the monitoring, and charges per enrolled patient, the FY2026 Work Plan's kickback-risk items ask whether those arrangements induce referrals or billing that would not otherwise occur. The practice, as the billing provider, holds the overpayment liability either way. If your vendor contract pays on enrollment volume or a share of collections, have counsel look at it now, not after a subpoena.

The operator self-audit: run this before OIG does

  1. Pull a device-data sample. For a recent sample of 99454 billing periods, verify 16 days of transmitted device data per 30-day period from the platform's raw logs, not the vendor's summary dashboard.
  2. Reconcile time logs. For 99457 and any add-on time, confirm 20 minutes of documented management time per month with staff name, dates, activity, and the interactive communication noted.
  3. Produce every consent. Sample enrolled patients and physically retrieve the dated consent for each. If any live only in a vendor system, export them into your record now.
  4. Map who furnishes the monitoring. Document, in writing, whether monitoring is performed by your employed or contracted clinical staff under required supervision, or by vendor personnel, and reassess the model against CMS's CY2027 proposal to bar outsourced RPM staffing.
  5. Re-read the vendor contract. Flag per-enrollment fees, percentage-of-collections pricing, free devices, or marketing support, the fact patterns behind the Work Plan's kickback-risk items on vendor-driven RPM arrangements.
  6. Check medical necessity at enrollment. Each enrolled patient should have an ordering practitioner, a condition the monitoring manages, and evidence the data is actually used in care.
  7. Quantify and act on what you find. Defects you identify carry refund obligations. Sizing the exposure yourself is dramatically cheaper than an extrapolated demand across a six-year lookback.
  8. Stage your audit response. Name an owner, know where every artifact lives, and rehearse producing a complete claim file, data logs, time records, consent, and order, within a records-request deadline.

Sources

  • HHS Office of Inspector General, Work Plan: Audit of Medicare Part B Remote Patient Monitoring Services, oig.hhs.gov/reports/work-plan, announced December 2024, ongoing in the FY2026 Work Plan, with FY2026 additions on kickback risk in vendor-driven RPM arrangements.
  • HHS Office of Inspector General: Fall 2025 Semiannual Report to Congress, flagging remote patient monitoring growth as requiring enhanced oversight.
  • Centers for Medicare & Medicaid Services: CY2027 proposal to bar outsourced RPM staffing.

Get audit-ready before the records request

ASP-RCM Solutions runs RPM compliance self-audits built around the exact elements OIG tests: device-day reconciliation from raw logs, time-log substantiation, consent retrieval, and furnisher mapping against the CY2027 proposal. Our coding and documentation review teams operate at 95%+ coding accuracy, and we deliver a defensible claim file for every sampled encounter, plus a remediation plan for anything that falls short. If RPM is on your Part B claims, the time to gauge your exposure is before OIG does.

Request an RPM Self-Audit →