Guide

RPM: the 99453–99457 stack and the staffing it assumes

Summary

Remote patient monitoring pays through a small family of codes — a setup code, a device-supply code, and time-based monthly management codes — not a single fee. The catch for a solo practice is staffing: the management codes assume dedicated clinical minutes each patient, each month. With no staff, you furnish that time yourself, so RPM is worth it only when its monthly return beats the visits that time displaces.

By Gale Editorial · Updated 2026-07-27. Every figure cited to a dated source. How we write.

Is RPM worth it for a solo practice?

For most solo practices, remote patient monitoring is worth it only when the recurring revenue clears the cost of the time it consumes. Remote patient monitoring bills through several codes, and the ones that pay the most each month are time-based: they assume someone spends dedicated management minutes per patient. In a practice of one, that someone is you, competing against billable visits.

That is the whole decision in a sentence, but it earns the detail underneath it — the code stack, the staffing it quietly assumes, the compliance wrapper a device adds, and the monthly math that tells you whether to start at all.

The code family: setup, device, and monthly management

RPM pays through a short stack of codes, each covering a different piece of the service, and HHS's telehealth billing guidance lays out how the pieces fit 1. One code covers the initial setup and patient education; one covers supplying the device and its data transmission over the monitoring period; and two are time-based, covering the treatment-management minutes you spend reviewing data and adjusting the plan each month.

The stack, at a glance:

CodeWhat it covers
99453Initial device setup and patient education
99454Device supply and data transmission across the monitoring period
99457The first block of treatment-management time in a calendar month
99458Each additional block of management time in the same month

The exact day counts and time thresholds behind these codes are set in their Medicare definitions and have moved through rulemaking, so confirm the current values in CMS's published billing materials before you build a workflow around them 1.

The staffing RPM quietly assumes

The management codes are where a solo practice feels the weight. They pay for interactive treatment-management time — minutes spent each month reviewing readings, contacting the patient, and adjusting the plan. In a group, that time is often furnished by clinical staff under general supervision, billed much like incident-to services. A practice of one has no such staff, so every one of those minutes comes out of the clinician's own week.

Before committing, price the time honestly:

  • Count the minutes per patient per month, not per visit — RPM revenue scales with your attention, and your attention is the scarcest input in a solo practice.
  • Compare against the displaced visit. If the monthly management time equals an hour you could have billed as visits, RPM only wins when its net clears that hour's collections.
  • Decide who watches the data between your touches. Concerning readings do not wait for your calendar, so someone has to see them as they arrive.

RPM is not on the telehealth list

RPM is not a telehealth-list service, and that distinction matters for a solo practice. Medicare's telehealth list governs which encounter codes may be furnished by video; RPM codes sit outside it, billed as remote physiologic monitoring regardless of where the patient is located. So the originating-site and geographic limits that shape telehealth billing do not constrain RPM the same way — but always confirm a given code's telehealth status against CMS's published list 2.

Monitoring patients who live in other states still raises the same cross-border questions any remote service does — the licensure rule keyed to where the patient sits 3, and the telehealth nexus that a book of out-of-state patients can create for state tax purposes. RPM's freedom from the telehealth list is a billing fact, not a licensure or tax exemption.

The device adds to your HIPAA risk analysis

Adding a monitoring device adds a new stream of ePHI, which expands the risk analysis the HIPAA Security Rule already requires of you. The rule asks for administrative, physical, and technical safeguards scaled to the size of your practice, all anchored in a documented risk analysis 4. A device, its vendor, and its data path are new assets to inventory, so the analysis has to be revisited, not assumed unchanged.

You do not have to build that analysis from scratch. ONC and OCR publish a free Security Risk Assessment Tool sized for small practices, which walks a solo through the same inventory a compliance team would run 5. Sign a business associate agreement with the device vendor before any patient data flows, and record the device in your asset inventory the day it ships.

Self-pay RPM and the good-faith estimate

If you bill RPM to self-pay or uninsured patients, the No Surprises Act's good-faith-estimate duty applies to the recurring charges, not just a one-time visit. The Act requires a good-faith estimate of expected charges for uninsured and self-pay patients, and it creates a patient-provider dispute process when the final bill substantially exceeds the estimate 6. Because RPM recurs monthly, the estimate has to describe the ongoing device and management charges, not a single line.

The operative content and timing requirements live in the regulation text at 45 CFR Part 149, which spells out what the estimate must contain 7. Give the estimate before the service begins, keep a copy in the record, and refresh it whenever the monitoring plan changes.

Running the worth-it math

Run the decision as a monthly ledger, not a one-time setup fee. On the revenue side, the setup and device codes bill roughly once per enrollment, while the management codes recur every month a patient stays enrolled and you furnish the time. On the cost side, count your own management minutes, the device and data platform, the expanded risk analysis, the vendor agreement, and the estimate you owe self-pay patients.

Two operational facts belong in the math before you enroll a single patient:

  • You need an escalation plan for concerning readings. The remote emergency — a reading that signals danger while the patient is miles away — is a foreseeable event, and a solo needs a written protocol for who is contacted and how, not an improvised response in the moment.
  • Watch the clock on the management minutes. The revenue depends on documented time; if you cannot reliably capture and note it, the code you bill is the code you cannot defend.

RPM rewards a practice that already has a monitoring rhythm and a panel that benefits from between-visit data. For a solo still filling the schedule, the honest answer is often to wait until the time it demands is time you can spare.

Common questions

RPM bills through a short family: a setup-and-education code, a device-supply code that covers transmitting data over the monitoring period, and two time-based codes for the treatment-management minutes you spend each month. The setup and device codes bill roughly once per enrollment; the management codes recur monthly while the patient stays enrolled and you furnish the time. Confirm the current thresholds in CMS's published materials before you rely on them.

No. RPM is billed as remote physiologic monitoring, a separate category from the Medicare telehealth list. That means the originating-site and geographic limits that shape telehealth encounter billing do not constrain RPM the same way. It does not, however, exempt you from the licensure rule keyed to where your patient is located, or from state tax questions when you monitor patients across state lines.

You can, but you personally furnish the monthly management time the time-based codes require, since there is no clinical staff to do it under general supervision. That is the core constraint for a practice of one: RPM revenue scales with your attention, and your attention already has a market price in billable visits. Price the management minutes against the visits they displace before enrolling patients.

A monitoring device introduces a new stream of ePHI and a new vendor, so your Security Rule risk analysis has to be revisited to cover them. Sign a business associate agreement with the device vendor before any data flows, and add the device to your asset inventory. The free Security Risk Assessment Tool from ONC and OCR walks a small practice through the same review a compliance team would run.

Yes, for uninsured and self-pay patients. The No Surprises Act requires a good-faith estimate of expected charges before the service begins, and RPM's monthly recurrence means the estimate should describe the ongoing device and management charges, not a single line. Deliver it before monitoring starts, keep a copy in the record, and refresh it whenever the monitoring plan changes.

Run your practice on Gale

The software is free. Gale earns one flat 3.5% all-in per paid transaction — only on transactions that actually pay. No subscription, no setup fee, no network cut.

Start or manage a practice →

References

  1. 1.U.S. Department of Health and Human Services (2026). Billing for telehealth. Telehealth.HHS.gov. linkThe structure of Medicare's remote patient monitoring billing — the setup, device-supply, and time-based management codes, and where to confirm current values.
  2. 2.Centers for Medicare & Medicaid Services (2026). List of Telehealth Services. Centers for Medicare & Medicaid Services (CMS). linkConfirming whether a given code is payable as Medicare telehealth, and that RPM is billed outside that list.
  3. 3.U.S. Department of Health and Human Services (2026). Licensure — Telehealth policy. Telehealth.HHS.gov. linkThat telehealth licensure is keyed to the state where the patient is located, which applies to monitoring out-of-state patients.
  4. 4.HHS Office for Civil Rights (2026). Summary of the HIPAA Security Rule. U.S. Department of Health and Human Services. linkThat the Security Rule requires safeguards scaled to the practice and anchored in a documented risk analysis when a device adds ePHI.
  5. 5.Office of the National Coordinator / ASTP (2026). Security Risk Assessment Tool. HealthIT.gov. linkThat ONC and OCR publish a free Security Risk Assessment Tool sized for small practices to run the required risk analysis.
  6. 6.Centers for Medicare & Medicaid Services (2026). No Surprise Billing. Centers for Medicare & Medicaid Services (CMS). linkThat the No Surprises Act requires good-faith estimates for uninsured and self-pay patients and creates the patient-provider dispute process.
  7. 7.Office of the Federal Register (2026). 45 CFR Part 149 — Surprise Billing and Transparency Requirements. eCFR. linkThe operative regulation text for good-faith-estimate content and timing under the No Surprises Act.

https://www.gale.care/for-providers/th-rpm-for-solo · 7 sources. Competitor details are cited to dated public sources and maintained as they change; figures are estimates, not commitments. Synthetic demonstration.

Findability, by specialty

How practices like yours get found in local search and AI answers — the honest playbook, per specialty.

SEO for private practices · SEO for AI search / answer engines (all verticals)