Good RPM Vendors vs. Bad RPM Vendors: Five Questions to Ask Before You Outsource

9/10/2026 Justin Brochetti , CEO
Five questions to ask before outsourcing RPM vendor work

An industry fighting for survival will tell you why you cannot live without it.

That is worth remembering as remote patient monitoring companies push back against CMS’s proposal to restrict Medicare payment for RPM furnished with third-party clinical staff.

In September 8 reporting from Digital Health Insights, more than 200 organizations had signed a letter warning that the proposal could force providers to reduce enrollment, terminate programs, or stop offering monitoring. The Alliance for Connected Care highlighted the debate the following day.

This is a proposal, not final policy. If finalized as described, providers would face bringing RPM in-house or dropping it by January 1, 2027.

The operational objections are real. Hiring, training, investment, and internal approvals take time. Stakeholders are arguing for enforceable clinical-integration guardrails instead of a direct-employment rule.

But the response also exposes how dependent parts of the outsourced-RPM industry are on third-party labor and Medicare reimbursement architecture.

Defending that business model is not the same as proving it deserves your patients.

The question for a practice is not whether every RPM vendor is bad. It is whether yours can demonstrate that its workforce, clinical service, data access, and financial incentives deserve your trust.

Good vendors should welcome that examination. Bad vendors would rather discuss enrollment and projected revenue.

Before you outsource, ask these five questions.

1. Do you use offshore personnel anywhere in my RPM program, and exactly what do they do?

Do not stop at “Where is your call center?”

Ask where every touch occurs: patient contact, chart review, documentation, escalation, billing support, and data handling. Ask whether the people doing that work are employees, contractors, or another company’s subcontractors.

Offshore work is not automatically illegal or poor quality. The problem is work that is undisclosed, weakly supervised, over-permissioned, or disconnected from the treating practice.

A good answer: A written workforce map identifying countries, functions, employers, supervision, and access boundaries. The vendor explains what patients are told, how clinical concerns reach your team, and how you are notified before arrangements change.

A bad answer: “We have a global team,” followed by vague assurances, or a sales representative who cannot tell you where charts are reviewed.

If the arrangement was not clearly disclosed before you signed, ask why.

Patients should not have to discover your operating model for you.

2. What evidence proves your billing reflects necessary, documented care?

Ask the vendor directly: How do you prevent the kinds of conduct that attract OIG scrutiny?

Do not accept “We are compliant” as evidence.

Require the vendor to show how it establishes medical necessity, records patient consent, validates applicable device and data requirements, documents actual interactive communication, and maintains accurate time logs without duplicate time. Ask how it documents escalation and prevents billing detached from real clinical service.

This is a buyer’s audit framework, not a claim that OIG has endorsed this exact checklist.

A good answer: Written controls and appropriately de-identified sample audit evidence connecting the patient’s need, monitoring data, communication, staff activity, escalation, and claim. The vendor can explain what happens when a requirement is not met, including when it does not bill.

A bad answer: A revenue spreadsheet, a compliance badge, and reassurance that “everyone bills this way.”

The revealing question is simple: Can you trace a billed service back to the care actually delivered?

If the vendor cannot show the work, do not buy the promise.

3. Who contacts my patients, and what are they qualified and authorized to do?

“Clinical team” is a marketing phrase until somebody attaches names, titles, credentials, and responsibilities to it.

Ask whether everyone contacting patients or accessing clinical records is a medical professional. Where the answer is no, ask what function that person performs and why that access is necessary.

Not every administrative, technical, or billing role needs to be a licensed clinician. But those roles must be distinguishable from clinical work, not blurred into a reassuring label.

A good answer: A role-by-role roster showing credentials where applicable, scope, training, supervision, and escalation authority. Administrative staff handle administrative matters. Technical support handles device problems. Clinical questions reach appropriately qualified personnel through a clear process.

A bad answer: “Our care specialists handle everything,” with no explanation of who can assess symptoms, interpret readings, give guidance, or escalate a concern.

Test the answer with a scenario: A patient reports dizziness and an abnormal reading. Who receives that information? What may that person do? Who takes responsibility next?

A workflow that ends at “someone sends a message” is not an adequate answer.

4. How many people and companies can access my patients’ records?

Your contract may name one vendor. Your data may pass through several organizations.

Ask for the full access footprint: employees, contractors, subcontractors, offshore teams, device suppliers, software vendors, and support engineers. Ask whether investors or affiliates have access and, if so, why and under what controls. Ownership alone is not a clinical reason to access patient records.

A good answer: An access map showing who can see what, for which purpose, and for how long. It documents role-based access, least privilege, audit logging, applicable BAAs and subcontractor controls, breach handling, and retention and deletion practices. Your practice can obtain meaningful access reports.

A bad answer: “We are HIPAA compliant,” offered as though that answers every workforce, security, and governance question.

It does not.

Ask what happens when an employee leaves, a subcontractor changes, or your contract ends. Who removes access? What is retained? What is deleted? How is completion demonstrated?

If nobody can explain the access footprint, nobody has given you a convincing account of how it is controlled.

5. Who controls the company, and can clinical judgment override its revenue targets?

Investor backing does not make a vendor bad. Hidden incentives make a vendor difficult to evaluate.

Ask who ultimately owns and controls the company. Ask about private equity ownership, venture debt, growth quotas, utilization and billing targets, staffing ratios, employee and customer churn, and complaint escalation.

Then ask the question that matters most: What happens when appropriate care conflicts with a financial target?

A good answer: Transparent ownership and operating expectations, measurable service standards, and a documented ability for clinical judgment to override revenue goals. The vendor explains how unnecessary enrollment, questionable billing, excessive workloads, and unresolved complaints are challenged, and who is accountable.

A bad answer: Detailed revenue projections paired with evasive answers about staffing, turnover, or the authority to stop inappropriate activity.

A vendor should be able to explain how it handles a decision that reduces revenue because it is right for the patient.

If the answers are weak, change the operating model

Satisfactory answers have a recognizable shape: named roles, written policies, sample audit evidence, measurable service standards, clear escalation paths, transparent subcontractors and ownership, and contractual accountability.

Documents, not slogans.

Outsourcing work does not outsource your patients’ trust. Your practice still faces the calls, complaints, disrupted workflows, and reputational consequences when the arrangement fails.

If a vendor cannot answer these questions satisfactorily, seriously consider running RPM in-house.

FairPath.ai makes that model practical and easier to operate, so outsourced complexity does not have to be your default. Implementation takes work. That is not a reason to accept a vendor you cannot adequately scrutinize.

If fully in-house is not the right fit, consider a trusted local independent pharmacy to operate or support the program. Start with a partner connected to your community, then apply the same five-question test.

A good vendor can withstand scrutiny. A bad vendor wants you dependent before you understand the arrangement.

Ask the five questions. Demand evidence. If the answers do not hold up, bring the program closer to home.