A practical RPM audit checklist covering the 16-day rule, consent documentation, and time tracking to help practices avoid Medicare recoupments.
Remote Patient Monitoring billing has grown fast enough that CMS scrutiny has grown with it. When auditors review non-compliant RPM claims, the outcome isn't just a denial - it's recoupment of payments already received, and in serious cases, referral for further investigation.
The good news: RPM compliance rules are well defined. The challenge is applying them consistently across every patient, every month. This checklist covers exactly what to verify before an audit ever arrives.
Why RPM Programs Draw Audit Attention
A few patterns consistently attract scrutiny from Medicare Administrative Contractors and Recovery Audit Contractors (RACs):
- Consistent billing at maximum thresholds every single month, with little natural variation
- High billing volume relative to peer practices of similar size
- Documentation gaps flagged during routine post-payment review
- Patient complaints about services they don't recall receiving or unclear consent
RACs specifically conduct post-payment reviews to identify improper payments, and are financially incentivized to find them - which makes clean documentation the strongest available defense.
The 16-Day Rule: The Most Commonly Violated Requirement
CPT 99454, the RPM device supply code, requires the patient to transmit data on at least 16 of 30 days in the billing period. Billing this code without meeting the threshold is one of the single most common RPM compliance failures.
For patients who transmit fewer days, CPT 99445 now provides a legitimate 2026 billing pathway for the 2–15 day window - but the two codes are mutually exclusive for the same period, and billing both is a compliance violation, not a workaround.
Patient Consent Documentation
Consent isn't optional paperwork - it's a required, auditable record. Before any RPM billing begins, documentation should confirm the patient understood:
- That only one practitioner can bill RPM services per calendar month
- Potential cost-sharing obligations under their specific plan
- The nature of the RPM services being provided and how their data will be used
- Their right to decline the service without it affecting other care
Missing or vague consent documentation is consistently cited as a top reason RPM claims fail audit review, regardless of whether the clinical service itself was appropriate.
Time Tracking for Treatment Management Codes
CPT 99457 and 99458 require documented clinical time spent reviewing data and managing the patient's care - and CMS has specifically flagged concern around what it calls "micro-fragmentation," or artificially breaking time into short increments to maximize billing improperly.
Clean documentation for these codes requires time-stamped clinical notes tied to specific actions, not rounded estimates applied uniformly across a patient panel. Using connected health devices for RPM, with data flowing automatically into the clinical record, significantly reduces the risk of documentation gaps that can lead to audit exposure.
Device and Data Requirements
Beyond time and consent, device-level documentation matters during a review:
- FDA-cleared devices - non-cleared consumer devices generally don't qualify for RPM billing
- Automatic digital transmission - manually entered patient-reported data doesn't meet the technical requirement for most RPM codes
- Detailed setup records - documentation of device distribution, patient education, and initial configuration
Per official CMS guidance, RPM coverage depends on meeting these specific technical and clinical requirements - reviewing this directly is worthwhile before assuming a device or workflow automatically qualifies.
Complete Audit-Readiness Checklist
Pulling this together, a defensible RPM program should be able to produce, on demand:
- Documented informed consent, dated and specific to RPM services
- Evidence the correct device-supply code (99454 or 99445) matches actual transmission days
- Time-stamped clinical notes supporting every minute billed under treatment management codes
- Records confirming only one billing provider per patient per month
- Clear separation of RPM time from any concurrent CCM, TCM, or other program billing for the same patient
Practices using a comprehensive RPM solution for medical providers with audit-ready reporting built into the platform can generate this documentation automatically, rather than reconstructing it manually when an audit request arrives.
Common Reasons RPM Claims Get Recouped

A handful of recurring issues account for most negative findings:
- Billing 99454 without meeting the 16-day threshold, often due to inconsistent device transmission
- Manually entered readings billed as if they were automatic digital transmissions
- Estimated rather than logged time for treatment management codes
- Missing or generic consent language that doesn't address plan-specific cost-sharing
- Concurrent billing overlap between RPM and another care management program for the same time period
CMS proposed rule to simplify RPM billing, combined with its continued emphasis on documentation compliance, signals that regulatory scrutiny is increasing-not easing-as RPM billing volumes continue to grow nationwide.
If an Audit Notice Arrives
A structured response protects the practice as much as the underlying documentation does:
- Review the request carefully and confirm the specific date range and codes under review
- Pull only the requested records - avoid submitting unrelated documentation that could broaden scope
- Reconcile findings internally before responding, so any discrepancies are understood in advance
- Know the appeal process and applicable deadlines if a recoupment determination seems incorrect
Conclusion
RPM audit risk comes down to a small number of well-defined requirements: correct device-supply code selection, documented consent, accurately logged clinical time, and clean separation between concurrent programs. Practices that build these checks into routine workflow - rather than reconstructing documentation after a claim is questioned - consistently avoid the recoupments that catch less prepared programs off guard.
FAQs
What is the 16-day rule in RPM billing?
Under CPT 99454, the patient must transmit Remote Patient Monitoring (RPM) device data for at least 16 days during a 30-day billing period. Billing this code without meeting the required transmission threshold is one of the most common reasons for RPM audit findings.
Can RPM device supply codes 99454 and 99445 be billed together?
No. CPT 99454 and CPT 99445 are mutually exclusive for the same 30-day billing period. 99454 applies when data is transmitted for 16–30 days, while 99445 applies when transmission occurs for 2–15 days. Reporting both codes for the same patient during the same billing period is not permitted.
What consent documentation does RPM billing require?
Providers should document that the patient was informed about the RPM service, understood the single-provider billing requirement, any applicable cost-sharing responsibilities, and their right to decline participation. This consent should be dated and recorded before RPM services begin.
What happens if Medicare determines an RPM claim was overpaid?
If Medicare identifies an overpayment, the provider is generally required to repay the amount. This may occur through a direct payment, an offset against future Medicare reimbursements, or an approved extended repayment plan. Providers also have the right to appeal the determination if they disagree with the findings.
What is "micro-fragmentation" in RPM billing, and why does CMS flag it?
Micro-fragmentation refers to improperly splitting clinical management time into multiple small increments to maximize reimbursement. CMS has cautioned against this practice because it can result in inaccurate billing and does not reflect legitimate clinical workflow.
Does using RPM software reduce audit risk?
Yes. RPM platforms with automated time tracking, verified device transmission records, digital consent management, and comprehensive audit trails help reduce documentation gaps and improve compliance compared with manual recordkeeping.
How long should RPM documentation be retained for audit purposes?
Although retention requirements may vary, providers should generally keep RPM documentation for several years beyond the billing period. Recovery Audit Contractors (RACs) and other Medicare reviewers may request records from multiple prior years during an audit.
