The short answer: the OIG audit of remote patient monitoring in Medicare Part B is not coming, it is already underway. In December 2024, HHS OIG announced the Work Plan item Audit of Medicare Part B Remote Patient Monitoring Services (oig.hhs.gov/reports/work-plan), and the audit remains ongoing in the FY2026 Work Plan. OIG's Fall 2025 Semiannual Report to Congress separately flagged RPM growth as requiring enhanced oversight, and the Work Plan adds items on kickback risk in vendor-driven RPM arrangements. Layer on CMS's CY2027 proposal to bar outsourced RPM staffing, and every RPM biller should be self-auditing the four elements OIG tests, before a records request forces the issue.
The needle has moved into the red zone
An open OIG audit, a Semiannual Report calling for enhanced oversight, kickback-focused Work Plan additions, and a CMS staffing proposal all point at the same billing line. That convergence is what separates routine program scrutiny from an enforcement cycle.
The four dials OIG reads on every RPM claim
OIG audits are not mysterious. For remote patient monitoring, the reviewers test a short list of objective requirements, and each one is binary: the chart either supports it or it does not. These are the same four dials your self-audit should sweep first.
16 days of device data in the 30-day period. Enrollment alone is not transmission, and gaps here are the easiest finding an auditor can make.
20 minutes of documented treatment management time, with who did it, when, and the interactive communication that occurred. Round-number time logs invite scrutiny.
Consent obtained and documented before services are billed. If a vendor collected it, you need to be able to produce it, not point at the vendor.
Who actually performed the monitoring: your clinical staff under proper supervision, or a third-party vendor's? This is the dial CMS's CY2027 proposal turns hardest.
How the oversight cycle built, step by step
- December 2024
OIG opens the audit
OIG announces the Work Plan item Audit of Medicare Part B Remote Patient Monitoring Services (oig.hhs.gov/reports/work-plan).
- Fall 2025
Report to Congress raises the flag
OIG's Fall 2025 Semiannual Report to Congress flags RPM growth as requiring enhanced oversight, elevating RPM from a line item to a named priority.
- FY2026
Audit stays open, kickback focus added
The audit remains ongoing in the FY2026 Work Plan, which adds items on kickback risk in vendor-driven RPM arrangements.
- CY2027 rulemaking
CMS moves on staffing
CMS proposes to bar outsourced RPM staffing in the CY2027 proposal, converging payment policy with OIG's integrity concerns.
Why findings hurt more than the sample
OIG audit findings in this space typically become overpayment demands with six-year lookbacks. A reviewer does not need to find fraud. A pattern of 30-day periods with fewer than 16 days of device data, or time logs that cannot support 20 minutes, is enough to extrapolate a repayment demand across years of claims. The economics of RPM programs, recurring monthly billing on a large enrolled panel, are exactly what makes extrapolation painful: a small per-claim defect multiplied across every enrolled patient, every month, for six years.
The vendor-driven model deserves its own risk review. Where a turnkey RPM company supplies the devices, enrolls the patients, performs the monitoring, and charges per enrolled patient, the FY2026 Work Plan's kickback-risk items ask whether those arrangements induce referrals or billing that would not otherwise occur. The practice, as the billing provider, holds the overpayment liability either way. If your vendor contract pays on enrollment volume or a share of collections, have counsel look at it now, not after a subpoena.
The operator self-audit: run this before OIG does
- Pull a device-data sample. For a recent sample of 99454 billing periods, verify 16 days of transmitted device data per 30-day period from the platform's raw logs, not the vendor's summary dashboard.
- Reconcile time logs. For 99457 and any add-on time, confirm 20 minutes of documented management time per month with staff name, dates, activity, and the interactive communication noted.
- Produce every consent. Sample enrolled patients and physically retrieve the dated consent for each. If any live only in a vendor system, export them into your record now.
- Map who furnishes the monitoring. Document, in writing, whether monitoring is performed by your employed or contracted clinical staff under required supervision, or by vendor personnel, and reassess the model against CMS's CY2027 proposal to bar outsourced RPM staffing.
- Re-read the vendor contract. Flag per-enrollment fees, percentage-of-collections pricing, free devices, or marketing support, the fact patterns behind the Work Plan's kickback-risk items on vendor-driven RPM arrangements.
- Check medical necessity at enrollment. Each enrolled patient should have an ordering practitioner, a condition the monitoring manages, and evidence the data is actually used in care.
- Quantify and act on what you find. Defects you identify carry refund obligations. Sizing the exposure yourself is dramatically cheaper than an extrapolated demand across a six-year lookback.
- Stage your audit response. Name an owner, know where every artifact lives, and rehearse producing a complete claim file, data logs, time records, consent, and order, within a records-request deadline.
Sources
- HHS Office of Inspector General, Work Plan: Audit of Medicare Part B Remote Patient Monitoring Services, oig.hhs.gov/reports/work-plan, announced December 2024, ongoing in the FY2026 Work Plan, with FY2026 additions on kickback risk in vendor-driven RPM arrangements.
- HHS Office of Inspector General: Fall 2025 Semiannual Report to Congress, flagging remote patient monitoring growth as requiring enhanced oversight.
- Centers for Medicare & Medicaid Services: CY2027 proposal to bar outsourced RPM staffing.
Get audit-ready before the records request
ASP-RCM Solutions runs RPM compliance self-audits built around the exact elements OIG tests: device-day reconciliation from raw logs, time-log substantiation, consent retrieval, and furnisher mapping against the CY2027 proposal. Our coding and documentation review teams operate at 95%+ coding accuracy, and we deliver a defensible claim file for every sampled encounter, plus a remediation plan for anything that falls short. If RPM is on your Part B claims, the time to gauge your exposure is before OIG does.
Request an RPM Self-Audit →Related reading
The drug you throw away is still revenue, if you tag it right.
How single-dose-vial wastage reporting under modifier JW and the mandatory JZ zero-wastage attestation drive b
Read →Field noteThe same well-child visit is coded differently across state lines.
The same pediatric well-child visit is coded differently across Medicaid programs. A state-grid view of VFC va
Read →InsightOne drug. Two benefits. The split decides the margin.
How a single provider-administered drug lands on the medical or pharmacy benefit, why the split decides margin
Read →