Skip to content
ITAS Health

Compliance & audit trail

We did not add compliance later.
It is the shape of the product.

Care management is a program-integrity target, and the enforcement is retrospective — the claim you submit today is reviewed against a standard applied years from now. So the gates are not reminders someone can dismiss. They are conditions the software will not advance without.

The landscape

What regulators have already found

This is not a hypothetical risk being used to sell software. It is a documented finding with an open recommendation attached to it.

43%
Of RPM enrollees did not receive all three components billed
HHS-OIG, Additional Oversight of Remote Patient Monitoring in Medicare Is Needed (OEI-02-23-00260), September 2024.
10×
Growth in RPM enrollees between 2019 and 2022
From roughly 55,000 to roughly 570,000 beneficiaries, against about $300 million in payments — the growth curve that attracted the review.

OIG also found that Medicare frequently could not identify the ordering provider for monitoring services at all, and recommended tracking monitoring companies as entities in their own right. That recommendation remains open, which means the enforcement runway extends well past today — and separate care-management audit activity is scheduled into 2028.

Anything you cannot reconstruct from your own records in two years, you should assume you cannot defend.
What that means in practice
An open labelled binder and a squared stack of documents on a bright desk

The gates

Five conditions. Any one of them fails, the month is held.

A held month is a visible state in the product with a named reason attached, not silence. Your team can see exactly what is missing and go get it — or decide the month genuinely is not billable and move on.

Signed order

A valid practitioner order exists in the record, attributable to a named clinician with a timestamp, before anything is dispatched or enrolled.

Order on file

Program-specific consent

Dated, documented, and specific to the program being billed — with the cost-sharing disclosure, the single-biller rule, and the right to stop. An inherited CCM consent does not satisfy APCM.

Consent datedCost-sharing disclosed

Reconciled day count

Distinct transmission days counted from the device feed, never estimated, resolving the period to the code the count actually supports.

9945499445

Interactive communication

Management codes stay locked until a synchronous audio or video conversation is logged for the period. Texts, voicemails, and portal replies do not release the lock.

9945799458

Single biller, no double-dip

Eligibility and claims cross-checks confirm no other practitioner is billing the program this month, and that no minute of clinical time is counted twice across stacked programs.

APCM ⊕ CCMOne RPM biller

Complete evidence file

The month does not close as billable until every artifact behind it exists and is retrievable as a single document.

Audit-ready

How we are structured

The arrangement itself has to be defensible

Plenty of audit exposure in this category has nothing to do with clinical documentation. It comes from what the vendor does and what the vendor is allowed to touch. Ours is deliberately narrow.

We are not the biller

ITAS does not bill Medicare, does not take reassignment of benefits, and never sits between your practice and its money. You submit claims under your own NPI. We prepare them and the evidence behind them.

We employ no clinical staff

Your people furnish the services under your supervision. This is why the CY2027 proposal on remote-monitoring staffing does not threaten the model — there are no vendor nurses in the arrangement to remove.

The sentence we put in every contract

ITAS is the technology and operations engine. The practice orders the services, owns all clinical decisions, supervises its own staff, and submits its own claims. ITAS does not bill Medicare and does not practise medicine.

This is a description of our contracting posture, not legal advice to you. Every practice should have its own counsel review any vendor arrangement touching federally reimbursable services, and we expect that review rather than resisting it.

If the auditor calls

One document per patient-month

Not a data export you would have to interpret under pressure. A record that reads, in order, as the story of why this month was billable.

  1. 01

    Signed practitioner order

    With qualifying diagnoses attached, the signing clinician named, and a timestamp.

  2. 02

    Program-specific consent

    Dated, documented, including cost-sharing, single-biller, and opt-out disclosures.

  3. 03

    Eligibility verification

    Coverage and beneficiary tier checked at enrollment and re-checked monthly.

  4. 04

    Transmission logs

    Every distinct day with a valid reading, from the device feed, establishing the code tier.

  5. 05

    Time logs

    Date, duration, and clinical description for each increment of billed time.

  6. 06

    Interactive-communication record

    Evidence of the synchronous conversation that unlocked management codes.

  7. 07

    Clinical documentation

    Notes and care-plan versions as they existed during the month, not as reconstructed after.

  8. 08

    Append-only audit trail

    Every PHI access and every action, by whom and when. Updates and deletes are rejected at the data layer.

Records are retained for ten years to support retrospective review and the sixty-day overpayment obligation. Related reading: what the OIG report actually says.

Compliance questions

What compliance officers ask

Do you employ the nurses who do the monitoring?
No. We employ zero clinical staff, on purpose. Your people furnish the care under your supervision, and we supply the software they use. It is also the reason the CY2027 proposed rule on remote-monitoring staffing does not disturb our model.
What is in the evidence file?
The signed order with signer and timestamp, the dated program-specific consent, transmission logs establishing the distinct-day count, time logs with date and duration and clinical description, the interactive-communication record for each management code, and an append-only audit trail of every PHI access and action. Retrievable as one document per patient-month.
How long do you keep records?
Ten years, which is longer than most retention requirements and short of nobody's. Audits look backwards, and the sixty-day overpayment obligation means you may need to reconstruct a month years after you billed it.
Are you a HIPAA business associate?
Yes, and we execute a business associate agreement before any protected health information moves. Our own subcontractors — hosting, model access, devices, and fax delivery — sit under downstream agreements. Our security page names every one of them.
Who is responsible if a claim is wrong?
The practice submits the claim and owns it, which is precisely why we would rather hold a month than let it through. We are not the biller and we do not take reassignment of benefits. Our job is to make sure that what you submit is something you can defend, and to make it obvious when a month is not.

Bring the person who is most sceptical

The panel scan is a better conversation with your compliance lead in the room. We would rather answer the hard questions before a contract than after a claim.

No EHR change. No commitment.