July 13, 2026
The five things OIG flagged about Medicare RPM billing — and how to audit-proof your program
Medicare paid $536 million for remote patient monitoring in 2024, up 31% in a year. The HHS Office of Inspector General looked closely at how it’s billed. Here’s what it found — and what a clean program looks like.
Share with others

Table of contents
Why OIG is looking at RPM
Remote patient monitoring is one of the fastest-growing lines in Medicare: $536 million in 2024, up 31% year over year, per the OIG’s August 2025 data report. Growth that fast always earns scrutiny, and the scrutiny is now structural — RPM has moved into recovery-audit scope, and Department of Justice False Claims Act activity around remote-monitoring billing has begun to appear.
This is not a reason to avoid RPM. It’s a reason to run it with documentation that survives a second reader. The OIG report is effectively a published audit checklist — here it is.
The five patterns OIG flagged
1. Incomplete delivery of RPM’s three components (~43% of enrollees). RPM is education and setup, device supply with data transmission, and treatment management. OIG found roughly 43% of Medicare RPM enrollees did not receive all three. A program that bills the monthly codes without evidence of the full service arc is the most common — and most visible — gap.
2. Missing ordering-provider linkage (~44%). In about 44% of cases, claims data lacked clear ordering-provider information. Every enrollment should trace to an identifiable ordering clinician with an established relationship to the patient.
3. Billing without a prior patient relationship. Enrollments with no preceding clinical relationship are a named red flag — RPM is a management service for a clinician’s own patients, not a standalone product attached to strangers. The OIG identified 45 practices that billed RPM for over 80% of their enrollees without any documented prior in-person or telehealth visit.
4. Enrollment spikes. Sudden surges in RPM enrollment are an audit trigger — the OIG flagged practices that grew their monthly billing rosters by more than 150% in a single month. Growth should follow clinical logic — a new program standing up, a new cohort onboarded — and the documentation should show it.
5. Thin device and monitoring data. The monthly device-supply code carries a hard floor: 16 or more days of readings in a 30-day period. Sparse transmission data behind a billed month is the easiest discrepancy for an auditor to find, because the device data doesn’t lie. The related pattern auditors call “box-shipping” — the OIG flagged 52 practices routinely billing for device supply month after month while submitting no treatment-management claims for most of their patients. (The RPM guide covers the 2026 code family in full, including the new shorter-duration codes.)
What audit-proof actually looks like
Every one of the five is a documentation-and-workflow problem, which means every one is preventable at the moment of service — and nearly impossible to fix at the moment of audit. A clean program captures, as the work happens:
- The order — an identifiable ordering clinician, an established relationship, a documented clinical rationale.
- The full arc — setup and education, transmission days, and the treatment-management minutes, each attached to the claim it supports.
- The trend, not just the total — enrollment growth that maps to a program story an auditor can follow.
- A plain-English trail — notes a second reader can reconstruct the month from, without asking anyone.
This is the unglamorous reason turnkey programs exist. When the workflow itself produces the documentation — every reading, every call, every escalation captured as it happens — audit-readiness stops being a quarterly scramble and becomes a byproduct. That is how CareAtlas runs monitoring for its partners: the full workflow, without adding staff, with billing-ready documentation as the default output.
The enforcement is no longer theoretical
Since the data report, the follow-through has been concrete. The OIG’s Fall 2025 Semiannual Report to Congress formally classified remote patient monitoring as a high-risk compliance area. In September 2025, a $29.8 million False Claims Act settlement resolved allegations of improper Medicare Part B claims tied to a diagnostic device (United States ex rel. v. Semler Scientific). RPM-specific actions followed: LiveCare Inc., a remote monitoring provider, agreed to pay $4.9 million to resolve allegations that referral-based marketing and enrollment arrangements violated the Anti-Kickback Statute and the False Claims Act.
Then came the big one. On June 23, 2026, the Department of Justice announced its National Health Care Fraud Takedown: criminal charges against 455 defendants — including 90 physicians and licensed professionals — involving more than $6.5 billion in false claims, with over $182 million in assets seized. Alongside the indictments, CMS executed 1,079 immediate provider suspensions and revoked billing privileges for 1,403 more. The government’s own analytics now flag outlier billing patterns in near-real time — the same patterns the OIG published a year earlier.
The bigger picture
CMS didn’t respond to RPM’s growth by cutting it — the 2026 fee schedule expanded the family with shorter-duration codes. The signal is consistent: Medicare wants this care delivered, and it wants the billing defensible. Programs that treat documentation as the product will do fine under scrutiny. Programs that treat it as paperwork will spend 2027 writing appeal letters.





