What Healthcare Providers Need to Know About Remote Patient Monitoring
Remote Patient Monitoring (RPM) can be a valuable tool for healthcare providers, enabling them to stay connected with patients and monitor their health between visits. However, there are risks associated with RPM. Providers should understand these risks to protect patients and their organization. Here is what healthcare providers should consider about RPM.
Why Offer RPM?
RPM gives healthcare providers a practical way to stay connected with patients between office visits. Instead of waiting for a patient’s next appointment, providers can use home-collected health data to identify changes and respond as needed. RPM can also make it easier for patients with chronic conditions to stay engaged in their care.
Healthcare organizations may consider RPM because it can:
- Improve patient care: Providers can keep track of important health information between appointments.
- Catch problems earlier: Changes in a patient’s condition may be noticed before they become more serious.
- Help manage chronic conditions: RPM can support patients managing conditions such as diabetes or high blood pressure.
- Keep patients engaged: Patients can play a more active role in tracking their health.
- Reduce unnecessary visits: Some issues can be addressed remotely rather than requiring an in-person appointment.
What are Some of the Risks that Can Arise from RPM?
RPM can expose healthcare providers to risk. Here are some risks that providers should be cognizant of:
Billing and coding errors: Providers may face problems if they bill for services that do not meet applicable requirements, use incorrect codes, or lack the documentation needed to support a claim. For example, billing for RPM services when the required monitoring or patient interaction did not actually occur could create a compliance problem.
Insufficient documentation: Medical records should support the medical necessity of RPM and show that the required services were actually provided. If a provider bills for RPM but the patient’s record does not show why monitoring was medically necessary or what services were provided, the claim could be scrutinized.
HIPAA and privacy concerns: RPM involves collecting and transmitting patient health information, so providers need appropriate safeguards to protect that information. Using an RPM platform that does not adequately protect patient information could raise HIPAA concerns.
Vendor relationships: Many providers work with outside RPM companies, making it important to clearly define responsibilities, compensation, data handling, and compliance obligations. A poorly structured payment arrangement with an RPM vendor could raise concerns about fraud and abuse.
Fraud and abuse concerns: Compensation arrangements, referrals, and other financial relationships connected to RPM should be reviewed carefully. For example, paying a third party based on the number of patients referred to an RPM program could create potential legal concerns.
Medicare and payer requirements: Providers must understand the requirements that apply to the specific services they are billing. Submitting a Medicare claim without meeting the applicable RPM requirements could result in a denied claim or repayment demand.
Staff compliance: Employees need to understand how RPM services should be provided, documented, and billed. If staff members do not understand the documentation requirements, the practice could submit claims that are missing important information.
Frequently Asked Questions
How is RPM done?
Patients may use wearable devices or connected medical equipment, such as blood pressure monitors, glucose monitors, pulse oximeters, or weight scales, to collect health information at home. The device sends the information electronically to the healthcare provider or RPM platform. Providers can then review the data and follow up when the information shows a potential concern. RPM may also work alongside telehealth, allowing providers to communicate with patients through phone or video visits when needed.
How can organizations offering RPM comply with HIPAA?
RPM can create HIPAA concerns because patient health information is being collected, transmitted, stored, and reviewed outside the traditional medical office. Providers should make sure the technology and devices used in their RPM program have appropriate security measures in place. They should also understand who can access the information and how it is being shared. If an outside RPM company is involved, the provider should determine whether the company is acting as a business associate and whether a Business Associate Agreement is required. Staff should also be trained on properly handling patient information.
What sort of RPM compliance review should healthcare organizations do?
If your healthcare organization offers RPM, it is a good idea to regularly check that the program is being run correctly. A compliance review can look at:
- Billing and coding: Make sure you are billing for services that were actually provided and using the correct codes.
- Documentation: Make sure patient records support the services billed.
- Vendor contracts: Review agreements with RPM companies to make sure responsibilities and payment arrangements are clear.
- HIPAA and privacy: Make sure patient information is being handled and protected properly.
- Fraud and abuse: Look for problems with referrals, payments, or billing that could raise legal concerns.
- Staff procedures: Ensure employees know how to handle RPM and follow the organization’s policies.
What sort of documentation should healthcare organizations offering RPM keep?
Healthcare organizations offering RPM should maintain records that clearly support the services they provide and bill for. Important documentation can include:
- Medical necessity: Records explaining why RPM is appropriate for the patient.
- Patient participation: Documentation showing the patient agreed to participate and received the appropriate services.
- Health data: Records of the information collected through RPM devices.
- Patient communications: Notes showing relevant calls, messages, or other communications with the patient.
- Clinical follow-up: Documentation of how the provider responded to health information or changes in the patient’s condition.
- Billing records: Documentation supporting the codes and services billed to the payer.
Contact an Experienced Telemedicine Attorney
RPM is great for providers and patients, but it’s not without risks. An experienced telemedicine attorney can help your organization review its RPM program and identify potential compliance concerns. Whether you are starting an RPM program or reviewing an existing one, nuanced legal guidance can help you structure your program properly and reduce unnecessary risk. Contact our office for immediate assistance.