Compliance & audit trail
We did not add compliance later.
It is the shape of the product.
Care management is a program-integrity target, and the enforcement is retrospective — the claim you submit today is reviewed against a standard applied years from now. So the gates are not reminders someone can dismiss. They are conditions the software will not advance without.
The landscape
What regulators have already found
This is not a hypothetical risk being used to sell software. It is a documented finding with an open recommendation attached to it.
OIG also found that Medicare frequently could not identify the ordering provider for monitoring services at all, and recommended tracking monitoring companies as entities in their own right. That recommendation remains open, which means the enforcement runway extends well past today — and separate care-management audit activity is scheduled into 2028.
Anything you cannot reconstruct from your own records in two years, you should assume you cannot defend.

The gates
Five conditions. Any one of them fails, the month is held.
A held month is a visible state in the product with a named reason attached, not silence. Your team can see exactly what is missing and go get it — or decide the month genuinely is not billable and move on.
Signed order
A valid practitioner order exists in the record, attributable to a named clinician with a timestamp, before anything is dispatched or enrolled.
Program-specific consent
Dated, documented, and specific to the program being billed — with the cost-sharing disclosure, the single-biller rule, and the right to stop. An inherited CCM consent does not satisfy APCM.
Reconciled day count
Distinct transmission days counted from the device feed, never estimated, resolving the period to the code the count actually supports.
Interactive communication
Management codes stay locked until a synchronous audio or video conversation is logged for the period. Texts, voicemails, and portal replies do not release the lock.
Single biller, no double-dip
Eligibility and claims cross-checks confirm no other practitioner is billing the program this month, and that no minute of clinical time is counted twice across stacked programs.
Complete evidence file
The month does not close as billable until every artifact behind it exists and is retrievable as a single document.
How we are structured
The arrangement itself has to be defensible
Plenty of audit exposure in this category has nothing to do with clinical documentation. It comes from what the vendor does and what the vendor is allowed to touch. Ours is deliberately narrow.
We are not the biller
ITAS does not bill Medicare, does not take reassignment of benefits, and never sits between your practice and its money. You submit claims under your own NPI. We prepare them and the evidence behind them.
We employ no clinical staff
Your people furnish the services under your supervision. This is why the CY2027 proposal on remote-monitoring staffing does not threaten the model — there are no vendor nurses in the arrangement to remove.
The sentence we put in every contract
ITAS is the technology and operations engine. The practice orders the services, owns all clinical decisions, supervises its own staff, and submits its own claims. ITAS does not bill Medicare and does not practise medicine.
This is a description of our contracting posture, not legal advice to you. Every practice should have its own counsel review any vendor arrangement touching federally reimbursable services, and we expect that review rather than resisting it.
If the auditor calls
One document per patient-month
Not a data export you would have to interpret under pressure. A record that reads, in order, as the story of why this month was billable.
- 01
Signed practitioner order
With qualifying diagnoses attached, the signing clinician named, and a timestamp.
- 02
Program-specific consent
Dated, documented, including cost-sharing, single-biller, and opt-out disclosures.
- 03
Eligibility verification
Coverage and beneficiary tier checked at enrollment and re-checked monthly.
- 04
Transmission logs
Every distinct day with a valid reading, from the device feed, establishing the code tier.
- 05
Time logs
Date, duration, and clinical description for each increment of billed time.
- 06
Interactive-communication record
Evidence of the synchronous conversation that unlocked management codes.
- 07
Clinical documentation
Notes and care-plan versions as they existed during the month, not as reconstructed after.
- 08
Append-only audit trail
Every PHI access and every action, by whom and when. Updates and deletes are rejected at the data layer.
Records are retained for ten years to support retrospective review and the sixty-day overpayment obligation. Related reading: what the OIG report actually says.
Compliance questions
What compliance officers ask
Do you employ the nurses who do the monitoring?
What is in the evidence file?
How long do you keep records?
Are you a HIPAA business associate?
Who is responsible if a claim is wrong?
Bring the person who is most sceptical
The panel scan is a better conversation with your compliance lead in the room. We would rather answer the hard questions before a contract than after a claim.
No EHR change. No commitment.