99457 Work RVU 2023 Final Rule: An Admin's Playbook
A payer audit letter lands in January 2026 asking for supporting documentation on remote physiologic monitoring management claims from calendar year 2023. Your billing lead pulls the claims. Your compliance officer pulls the policies. Then someone asks the question that stalls the whole response: where are the minute-by-minute time logs? They are in a vendor platform you stopped paying for in 2024. That is the operational reality behind the 99457 work RVU 2023 final rule lookups your team keeps running — the RVU is the easy part, and the records behind it are the hard part.
This guide is written for practice administrators, billing managers, and privacy officers who own remote monitoring programs. It covers where the relative value actually lives, why the number in a vendor slide deck may not survive an audit, how to assign productivity credit when clinical staff performed the time, and what your business associate agreements need to say about the data that proves the claim.
Where the 99457 Work RVU in the 2023 Final Rule Actually Lives
There is exactly one authoritative source for a relative value in a given year: the CMS relative value files that accompany the Physician Fee Schedule final rule for that year. Not a webinar. Not a vendor ROI calculator. Not a spreadsheet a regional rep emailed your practice in 2022.
For CY 2023, that means the addenda published with the CY 2023 PFS final rule and the downloadable RVU files on the CMS Physician Fee Schedule page. Each line carries the work RVU, the facility and non-facility practice expense RVUs, the malpractice RVU, and the global period and status indicators that tell you how the code behaves.
Most practices carry 0.61 work RVUs for 99457 in their fee schedule master, unchanged across several rule cycles — but before you put a number in an audit response or a compensation true-up, pull it from the CY 2023 relative value file yourself. Auditors reconcile to the published file for the date of service, and "our vendor told us" is not a documentation standard.
Why 2023 Still Matters in 2026
Three reasons. Payer audit lookback periods routinely reach back multiple years. Physician compensation agreements written on wRVU tiers get trued up and disputed long after the fact. And overpayment identification obligations mean that if you discover a 2023 pattern problem now, the clock on refunding it starts when you identify it, not when it happened.
So keep a frozen copy of the relative value file for every year you have open claims. Store it with your fee schedule documentation, not on someone's desktop.
Featured Answer: What the 99457 Work RVU 2023 Final Rule Number Does and Doesn't Tell You
A work RVU is a measure of physician or qualified health professional work — time, intensity, technical skill, mental effort. It is not a payment amount. Medicare payment for a code is calculated as:
- Work RVU × work geographic practice cost index (GPCI)
- Plus practice expense RVU × PE GPCI (facility or non-facility, depending on setting)
- Plus malpractice RVU × MP GPCI
- Total × the annual conversion factor
Two practices in different states bill the same code with the same work RVU and receive different amounts. And a work RVU can sit unchanged for years while payment falls, because the conversion factor moves independently — CMS finalized a lower conversion factor for CY 2023 than CY 2022, and Congress then partially offset it through the Consolidated Appropriations Act, 2023. If your 2023 RPM revenue came in under model, look at the conversion factor and your locality's GPCIs before you assume someone entered the RVU wrong. Verify any specific rate through the CMS Physician Fee Schedule Look-Up Tool.
Who Actually Did the 20 Minutes? The Credit-Assignment Problem
Remote monitoring management is a time-based, calendar-month service that requires interactive communication with the patient or caregiver. In many practices, most of that time is logged by clinical staff, not by the billing practitioner — under whatever supervision arrangement your billing team has documented and can defend.
That creates a compensation mechanic your administrators need to make explicit. If your physician agreements pay on wRVUs credited to the rendering NPI, a practitioner who supervised but did not personally perform the minutes still accrues the work RVU. Some groups accept that. Others carve remote monitoring out of the productivity pool, or credit it at a reduced factor, or route it to a separate program P&L.
Pick one and write it into the compensation exhibit. Ambiguity here produces two failure modes: a physician who believes the program is padding a partner's numbers, and a program that quietly loses money because nobody owns the staffing cost.
The Documentation Your Time Entries Need
Whatever code your coding team selects, the underlying record should support it. Practically, that means each entry captures who performed the work (name and role), the date, start and stop times or duration, what was done, and evidence of the interactive communication when the code requires it. Cumulative totals should roll up by calendar month, and the log should show which patient month a claim maps to.
Code selection is your coding team's determination against current CPT descriptors, payer policy, and the documented record. Your job as an administrator is making sure the record exists, is retrievable, and is produced by a system whose timestamps you trust.
The Time Log Is a Record — and Your Vendor Is Holding It
Here is the part that gets skipped. In most remote monitoring programs, the device telemetry, the alert thresholds, the nurse's notes, and the minute counters all live in a third-party platform. Some of that data flows into your EHR. Much of it does not.
That platform vendor creates, receives, maintains, and transmits protected health information on your behalf. It is a business associate, and so is the cellular connectivity provider or device manufacturer if it touches identifiable data. If you are running a program without an executed agreement covering every entity in that chain, close that gap this quarter. If you need a clean, signature-ready document to start from, a six-step business associate agreement wizard will get you to a PDF faster than a redline cycle with a vendor's boilerplate.
Five Contract Clauses That Decide Whether You Survive an Audit
- Data export on demand. You can pull complete time logs, in a usable format, without a support ticket and without a fee.
- Termination export window. A defined period after contract end during which you can extract everything, and a defined destruction or return obligation after that.
- Retention floor. The vendor retains records at least as long as your state's medical record retention requirement and your payer audit exposure — whichever is longer.
- Audit cooperation. The vendor produces attestations, system-generated logs, and timestamp methodology if a payer challenges the minutes.
- Subcontractor disclosure. Named downstream entities, with flow-down obligations. Offshore staffing changes your risk profile and your notification analysis.
A vendor that resists the first two is telling you something about your position on the day you want to leave.
Right of Access Doesn't Stop at Your EHR
When a patient requests their record, the designated record set includes information used to make decisions about that patient — including data your business associate holds on your behalf. A patient enrolled in remote monitoring can ask for their readings and the management notes, and the general 30-day response timeline applies. Review the HHS individual right of access guidance and then test the workflow: hand your medical records clerk a hypothetical request and time how long it takes to get a complete monitoring history out of the vendor platform.
If the answer is "we email our account manager and wait," you do not have a compliant access workflow. You have a hope.
Every Device You Ship Expands Your Risk Analysis
A remote monitoring program adds asset classes most small practices never inventoried: cellular-enabled blood pressure cuffs, scales, pulse oximeters, hubs, a new SaaS platform, a new set of remote user accounts, and often a new group of staff logging in from home. The Security Rule requires an accurate and thorough risk analysis covering all ePHI your organization creates, receives, maintains, or transmits. Adding a device fleet without updating that analysis is one of the most common findings in any serious assessment.
Work through the practical questions: Who provisions and deprovisions platform accounts, and how fast after termination? Is the device wiped or retired when a patient disenrolls? Where do alert texts and after-hours notifications land? Does the platform support unique user IDs and audit logging, and has anyone reviewed those logs since go-live? NIST's SP 800-66r2 is a workable framework for structuring the assessment.
If your last risk analysis predates your monitoring program, it is out of date. Practices that would rather not rebuild the whole document set by hand use automated HIPAA risk analysis and policy generation to produce the assessment, the remediation plan, and the supporting policies as one package, then update it when a new vendor or device class enters the environment.
Enrollment Outreach, Remuneration, and the Marketing Line
Program growth targets create pressure to run enrollment campaigns. Two guardrails for your privacy officer.
First, communications about treatment sit differently under the Privacy Rule than communications that promote a product or service — and the analysis changes when a third party pays for the message. If your monitoring vendor funds, scripts, or executes patient outreach using your PHI, have counsel review it before the first message goes out.
Second, patients enrolled in these programs typically owe cost-sharing every month the service is billed. A patient who does not understand that will call your front desk angry, and angry patients file complaints. Script the enrollment conversation, document consent to participate, and give the patient a written way to stop.
A 2026 Reconciliation Checklist for Legacy RPM Claims
- Freeze the source data. Pull the CY 2023 relative value file and archive it with your fee schedule records. Confirm the work RVU your comp model used matches it.
- Map claims to logs. For a sample of 2023 monitoring management claims, confirm you can produce the underlying time entries within five business days. Note every claim where you cannot.
- Inventory dead vendors. List every monitoring platform you have used since 2022 and confirm whether you retained an export. If not, request one in writing now.
- Refresh the BAA file. Every current device, connectivity, and platform vendor, with dates and named subcontractors.
- Update the risk analysis. Include devices in patient homes, remote staff access, and the platform itself.
- Settle credit assignment. Put the productivity treatment of monitoring management in writing in the compensation exhibit before the next review cycle.
The 99457 work RVU 2023 final rule value takes ten minutes to verify. The records infrastructure behind three years of claims takes a quarter to rebuild — which is why the practices that handle these audits calmly built it before the letter arrived.
Start With the Documents You'd Have to Produce
Pick the three oldest remote monitoring claims still inside your audit exposure and try to assemble the full packet: the claim, the time log, the supervising practitioner, the executed BAA with the platform, and the risk analysis that covered the devices. If any piece is missing, that is your work plan for January. If the missing piece is the risk analysis or the policy set, generate the full compliance document set and get it dated before your next program expansion adds another vendor to the chain.