Back to all insights
Care Management 9 min readLast reviewed

CCM & RPM Audit Readiness 2026: What OIG and DOJ Have Found

OIG is auditing 2019-2024 CCM claims for the two-chronic-condition rule. What audits and settlements found, and the billing controls software can enforce.

The Short Answer

OIG is actively auditing Medicare chronic care management (CCM) payments for 2019 through 2024, focused on whether patients actually had the two or more qualifying chronic conditions CCM requires (OAS-26-09-007, announced March 16, 2026). Earlier OIG work found CCM billed more than once for the same month and billed alongside overlapping care management, and a separate OIG audit of remote patient monitoring (RPM) billing is open. Being audit-ready means proving eligibility, consent, the initiating visit, one billing practitioner per month, no overlapping codes, and minutes logged when they happened and never reused.

I build these controls into care-management software; the care management operations software page covers what that involves, and the CCM/PCM operations platform case study shows them in a real operation.

This is engineering and operations guidance, not legal or billing advice. Confirm billing rules with your compliance advisor or healthcare counsel before changing workflows or claims.

What Enforcement Has Actually Found

Each item below was checked against its primary source on 2026-09-28, except where noted.

  • Active CCM eligibility audit (OIG OAS-26-09-007). Announced March 16, 2026, this OIG Work Plan project examines Medicare Part B payments for CCM services furnished from 2019 through 2024 that may not meet the multiple-chronic-conditions requirement: two or more chronic conditions expected to last at least 12 months or until death that place the patient at significant risk. OIG points to substantial growth in CCM payments over that period. OIG listed the project as active on 2026-09-28.
  • Duplicate and overlapping CCM claims (OIG A-07-19-05122, August 2021, historical). Reviewing CCM claims from calendar years 2017 and 2018, OIG identified about $1.9 million in overpayments on 50,192 claims. That included $1.4 million on 38,447 claims where CCM was billed more than once for the same beneficiary and service period, and $438,262 on 10,882 claims where the same provider billed CCM and overlapping care management services for the same period. OIG attributed the errors to missing claim-system edits; CMS said it had since implemented edits. These claims predate the current code set and APCM, but the failure patterns are the ones a billing system should block.
  • Bluestone Physician Services settlement (June 5, 2024). Bluestone entities agreed to pay $14.9 million to resolve allegations that they submitted claims for domiciliary rest home visits for established patients (99337) and chronic care management (99490) that did not meet program requirements, for patients in assisted living and other care facilities. They also entered a five-year Corporate Integrity Agreement with OIG. These were allegations resolved by settlement, not a court finding. The DOJ press release blocks automated access, so the amount, codes and date were verified through news reports of the announcement and the five-year term through OIG's published agreement.
  • RPM components not delivered (OIG OEI-02-23-00260, September 2024). About 43 percent of Medicare enrollees who received RPM did not receive all three components of the service, and OIG found Medicare lacks key oversight information, including who ordered the monitoring.
  • RPM spending (OIG OEI-02-23-00261, August 2025). Medicare RPM payments exceeded $500 million in 2024. OIG published measures that payers and others can use to flag questionable RPM billing patterns.
  • Active RPM billing audit (OIG OAS-25-05-008). Announced December 16, 2024, this project examines whether providers furnished and billed Medicare Part B RPM services in accordance with Medicare requirements. OIG lists it as active.

The common thread: eligibility, duplicate billing and overlapping services are questions an auditor can answer from claims data at scale. They are also rules a billing system can check before the claim goes out.

Controls a Platform Can Enforce

Per CMS MLN909188 (Chronic Care Management Services, June 2025) unless noted; confirm each with your compliance advisor.

  • Eligibility documented. Two or more chronic conditions, expected to last at least 12 months or until death and placing the patient at significant risk, recorded before enrollment.
  • Consent captured with its elements. Written or verbal consent recorded before billing, documenting that the patient was told CCM is available, about possible cost sharing, that only one practitioner can provide and bill CCM in a calendar month, and that they can stop at any time (effective at the end of the calendar month), plus whether they accepted or declined.
  • Initiating visit on file. For new patients or patients not seen within the previous year, a face-to-face E/M visit, annual wellness visit or initial preventive physical exam at which CCM was discussed, before CCM starts.
  • One billing practitioner per patient per calendar month.
  • Overlap flags. No non-complex and complex CCM for the same patient in the same month. No CCM in the same service period as G0181, G0182 or CPT 90951–90970. RPM or RTM, not both, alongside CCM. A practitioner billing APCM (G0556–G0558) does not also bill CCM, PCM or TCM for that patient in that month (this last rule comes from the CY 2025 PFS final rule, 89 FR 97896, not MLN909188).
  • Append-only time log. Minutes are written once, attributed and timestamped, and time counted toward a CCM code is never counted toward any other billed code.
  • Care plan exists and is shared. An electronic comprehensive care plan is in place, available promptly inside and outside the practice, with a copy given to the patient or caregiver when necessary.

The rest of this article is how I built the time-log part of that list, and why it matters most when an auditor asks for records.

The One Question a CMS Audit Actually Asks

Chronic Care Management billing looks simple on paper: document at least 20 minutes of non-face-to-face care coordination per patient per month, bill CPT 99490, add 99439 for each additional 20 minutes, and use 99426/99427 for Principal Care Management, which has its own threshold of at least 30 minutes per calendar month. The codes are clear. The audit is not about the codes.

When CMS or a Medicare Administrative Contractor reviews a CCM program, the question underneath every record request is: can you prove these minutes happened when you say they happened? Not "do you have a spreadsheet with minutes in it" — anyone can have that the night before an audit. The question is whether your documentation was created contemporaneously, attributed to a specific care coordinator, and never silently altered afterward.

This is where spreadsheet-run CCM programs are structurally exposed, no matter how honest the operation is.

Why Spreadsheets Fail This Test by Construction

I spent years building and evolving the operations platform for a US care-coordination company that ran CCM/PCM for thousands of patients — an operation that started, like most, on Excel. The spreadsheet era had a documentation problem that nobody inside the operation could see, because everyone was acting in good faith:

  • Every cell is editable, forever. A minutes entry typed on the 28th is indistinguishable from one typed on the 3rd. There is no way to demonstrate contemporaneous documentation.
  • There is no attribution. A shared workbook cannot prove which coordinator performed the care activity — only whose computer last saved the file.
  • Totals are derived by hand. When the monthly billing summary is assembled manually from per-coordinator tabs, transcription errors flow silently into claims. An error rate of even 1% across thousands of patient-months is a systematic overbilling pattern waiting to be sampled.
  • Deletion leaves no trace. If a row disappears, nothing records that it ever existed.

None of this means the billing was wrong. It means the operation cannot prove the billing was right — and in an audit, the burden of proof runs against the biller.

What an Audit-Proof Time Log Looks Like

The engineering answer is an append-only time log: care activity entries that are written once, attributed to an authenticated user, timestamped by the server (not the client), and never updated in place. Corrections are new entries that reference the original — the same principle accountants have used for centuries. Ledger entries are never erased; they are reversed.

The schema-level rules that matter:

  • Server-side timestamps. The moment of documentation is recorded by the system, not typed by the user. Late entries are visible as late.
  • Authenticated attribution. Every entry is bound to the logged-in coordinator through role-based access control — coordinators can only log time against patients actually assigned to them.
  • No UPDATE, no DELETE. The application layer exposes no path to modify a historical entry. Adjustments are compensating entries with a reason field.
  • Billing derives from the log. Monthly CPT paycode counts (99490, 99439, 99426, 99427) are computed from the time log by the system — never assembled by hand. The invoice and the audit trail are, by construction, the same data.

When this is in place, the audit conversation changes completely. "Show me documentation for these 40 patient-months" becomes a query, not a scramble. Every minute traces to a person, a patient, a timestamp, and a care activity.

The Operational Bonus Nobody Expects

Here is the part that surprises operators: the audit trail is also a management instrument. Once every care minute is structured data, you can see — in real time — which patients are short of their monthly threshold, which coordinators are behind their targets, and what the projected end-of-month billing coverage looks like. In the platform I built, this became a predictive scoring system that flags at-risk coordinators before month-end, while there is still time to reassign patients and protect both care quality and billing compliance.

A spreadsheet tells you what happened last month. An audit-grade time log tells you what is about to happen this month.

When to Fix This

The honest threshold: if your CCM/PCM program bills more than a few hundred patient-months per month from spreadsheets, the audit exposure and the manual-assembly cost are already larger than the cost of fixing the foundation. The CCM/PCM Operations Platform case study documents what that transition looked like for a real operation — from 3,200 patients on Excel to 8,000+ on a platform where the time log, the billing, and the audit trail are one system. For the broader engineering requirements — RBAC, multi-tenancy, CMS documentation — see Building CCM/PCM Software: Technical Requirements.

Free 30-minute workflow review (no patient data needed)

Sources

Last reviewed 2026-09-28.

Related Service

Custom CCM, PCM & RPM Operations Software

Deep-dive into our engineering approach, capabilities, and technical specifications.

View Engineering Specs →
SA

Written by Sheharyar Amin

Founder & Lead Engineer, Opexia