OIG found 43% of RPM enrollees didn't get what was billed. Read it before you scale.
The September 2024 HHS-OIG review of Medicare remote patient monitoring is the single most important document for any practice billing this program. What it found, what it recommended, why the recommendation still being open matters, and what a defensible month looks like.

If you bill remote patient monitoring, or you are about to, there is one document worth reading in full: Additional Oversight of Remote Patient Monitoring in Medicare Is Needed, HHS Office of Inspector General, report OEI-02-23-00260, published September 2024.
It is not long and it is not written to frighten anyone. It is also the clearest available statement of how a regulator understands this program, which makes it the standard your claims will eventually be read against.
What it found
Enrollment grew roughly tenfold in three years. From about 55,000 Medicare beneficiaries receiving remote monitoring in 2019 to about 570,000 in 2022, against roughly $300 million in payments.
43% of enrollees did not receive all three components being billed. RPM is built from three pieces: the device and its setup, the data transmission, and the treatment management. In nearly half of cases, at least one of the three was billed without being delivered.
Medicare often could not identify the ordering provider. For a program that requires a practitioner order for every enrollment, the ordering practitioner frequently could not be determined from the claims data at all.
What it recommended
OIG made a set of recommendations to CMS, and the one that should hold a practice's attention is the recommendation to identify and monitor the companies that provide remote monitoring services as entities in their own right — not merely to review the practices submitting claims.
That recommendation remains open. Separately, care-management audit activity is scheduled to run into 2028.
An open recommendation is not a dormant one. It means the oversight mechanism is still being built, and it will be applied to claims already submitted. Enforcement in this category is retrospective by nature: the claim you file this month will be reviewed against a standard applied years from now, using whatever records you kept at the time.
Which component actually goes missing
In our reading, the gap is concentrated in treatment management, and specifically in the interactive-communication requirement.
Device supply generates evidence automatically — the device transmitted or it did not, and there is a log. Data transmission is the same. Treatment management is the component that depends on a human doing something, and it is the only one whose absence is invisible in the data.
CMS requires at least one synchronous, real-time audio or video conversation with the patient during the billing period before management time is billable. Texts do not count. Voicemails do not count. Portal messages do not count. It is the single most common reason a month that looks fine is not defensible.
A practice can review readings diligently, document real clinical time, and still be part of the 43% — because reviewing data without a patient conversation is exactly the pattern the finding describes.
What a defensible month contains
The useful way to read the OIG report is as a specification. For each billed patient-month, you should be able to produce, without reconstruction:
- A valid practitioner order, attributable to a named clinician with a date. The finding about unidentifiable ordering providers means this is being looked at.
- Documented consent, specific to the program, dated, including the cost-sharing disclosure.
- Transmission logs establishing the count of distinct days with valid readings — which determines which device-supply code the period supports.
- Time logs with date, duration, and a description of the clinical activity. Not "reviewed readings, 22 min."
- The interactive-communication record for each management code billed.
- An audit trail of who accessed what and who did what, ideally append-only so that it cannot be tidied up later.
If any of those cannot be produced for a month you billed, that is a month you cannot defend. The sixty-day overpayment obligation means discovering it yourself starts a clock — which is genuinely unpleasant, and considerably better than the alternative.
The vendor question
The recommendation to monitor monitoring companies as entities is worth reading alongside the CY2027 Physician Fee Schedule proposed rule, which would require that RPM treatment management be furnished by staff the billing practice itself employs. We wrote about that proposal here.
Those two documents point the same direction. The arrangement where a vendor's call centre generates the clinical minutes and the practice submits the claim is the specific structure under scrutiny — and it is the structure that made the tenfold enrollment growth possible.
If you currently use a vendor of that shape, this is worth a direct conversation with them, in writing, before December.
Our stake in this
We build software for practices whose own staff furnishes the care, and we employ no clinical staff. So we benefit if you find this concerning, and you should read everything above with that in mind.
Which is also why the more useful action is not to believe us. Pull three months you have already billed and try to assemble the six artifacts above from your existing records. Either you can, in which case you are in better shape than most, or you cannot, in which case you have learned something considerably more valuable than anything a vendor could tell you.
Source: HHS Office of Inspector General, Additional Oversight of Remote Patient Monitoring in Medicare Is Needed, OEI-02-23-00260, September 2024. Available at oig.hhs.gov.
Written by ITAS Health. Everything here is general information about published rules, not legal, regulatory, coding, or billing advice, and rules change. Verify against current CMS guidance and your own compliance counsel before acting. Corrections are genuinely welcome — tell us what we got wrong.