Medicare's proposed 2027 physician fee schedule would pay for remote monitoring management only when the billing practice's own employees do the work. Contracted clinical staff would not qualify.[1]
The intent is defensible. Oversight is easier when the person doing the work reports to the practice, and the rulemaking follows federal findings that a large share of remote monitoring enrollees never received all three components of the service they were enrolled in. In 2024 the HHS Inspector General found that 43 percent did not.[2]
The effect is something else.
Two details are worth correcting before anyone argues about this rule, because both are widely misread. The supervision standard does not change. Clinical staff would continue to work under general supervision, and they would still not need to be physically present in the practice. And the proposed initiating visit may be conducted in person or by telehealth.[1] This is an employment test, not a supervision test and not a geography test.
Which is what makes it consequential. The work does not disappear when contractors can no longer bill for it. Every hour billed today by contracted monitoring labor becomes an hour a practice's own staff has to absorb, in exactly the roles the market fills slowest. Nearly half of medical group leaders name medical assistants the single hardest role to fill, roughly three times the share who name nurses.[3] In primary care, support-staffing ratios per ten thousand work RVUs fell 4.8 percent in a single survey year even as patient visits rose.[4] Federal projections have the licensed practical nurse pool, the classic remote monitoring hire, moving toward seventy percent adequacy by 2038.[5]
So the work moves. It moves onto payroll, or it moves into software.
Most of it will move into software. Which means a rule written to keep the work inside the practice will, in practice, put a language model closer to the patient than it has ever been.
Healthcare already solved this problem once
There is a mature accountability regime for the human version of this work, and it is easy to overlook precisely because it is so familiar.
A person who talks to a patient holds a license. That license carries a defined scope of practice, and stepping outside it is a disciplinable act. It requires continuing education on a schedule. The conversation produces notes, and those notes are discoverable years later, in a form that records what was decided, when, and by whom. Retention periods are set in federal regulation. When something goes wrong, an investigator can reconstruct the encounter from records that were created as the encounter happened, not assembled afterward by people trying to remember.
None of that regime is about competence. It is about evidence. It exists so that the question can be answered later.
For the software version of the same work, almost none of it exists yet.
Ten states, five frameworks, and one thing none of them asks for
The rule that starts this is about physiological monitoring, not behavioral health. But behavioral health is where the law on what an AI may say to a patient has moved fastest, so it is the honest place to look. And even there, the record is not required.
In roughly a year, ten states have passed laws governing what an AI may say to a patient about mental or behavioral health, in four genuinely different regulatory architectures. Illinois bars any individual, corporation or entity from providing therapy unless a licensed professional conducts it.[6] Utah takes the opposite approach and permits the same conduct subject to disclosure, data use limits, and an affirmative defense for suppliers who file a written policy with the state.[7] New York and California regulate companion chatbots through crisis protocols and periodic disclosure.[8] Colorado now conditions therapeutic communication on synchronous, real time interaction between the professional, the system and the client.[9] Penalties run from twenty five hundred to fifteen thousand dollars per violation, and New York's companion chatbot law reaches fifteen thousand dollars per day.[7][8] At least one carries a private right of action. No two are alike, and several bind any entity rather than only licensed professionals.
Above the statutes sit the voluntary frameworks: joint guidance from the Joint Commission and the Coalition for Health AI, the NIST AI Risk Management Framework and its generative AI profile, the ONC transparency requirements at HTI-1, and URAC's health care AI accreditation.[10]
Those five were read clause by clause for this article. Not one of them requires an organization to keep a record of what its AI actually said to a patient. Not one sets a retention period for such a record. The closest any of them comes is a recommended action in NIST's generative profile to maintain provenance and logging of generated content, which is voluntary and specifies no period.[10] The Joint Commission and Coalition guidance does call for regular auditing of logs, and those are access logs, meaning who opened a record rather than what a model said. HTI-1's transparency requirements bind certified health IT developers for the predictive interventions they supply, which does not reach a standalone AI vendor operating outside a certified system.
The obligations exist. The evidence does not.
That gap is not theoretical for long. Enforcement has already started, though not yet under the new AI statutes. In May, Pennsylvania sued a chatbot developer for the unauthorized practice of medicine after a chatbot claimed to be a psychiatrist and produced an invalid state medical license number. The state described it as the first action of its kind in the country.[11] It was brought under practice of medicine law, which is decades old, and which has never needed an AI statute to reach a party who acts like a clinician.
Review before send is doing more work than anyone admits
The industry's current answer to all of this is a person in the loop, and it is a good answer. In the clinical monitoring deployments we could find, AI-drafted patient messages do not send themselves. A clinician reads the draft and decides. The autonomous exceptions are mostly consumer companion bots operating with no clinical oversight, which is exactly where the enforcement above is landing. CMS has now named the review pattern in a proposed rule of its own: a 2027 improvement activity that credits clinicians for responsible AI use, including AI-drafted responses to patient questions.[12]
It is worth being clear about what that review is actually accomplishing. Part of it is quality. But part of it is evidentiary. A licensed person reading and releasing the message is the only mechanism currently available for producing an accountable record of what reached the patient and who decided it should. Human review is standing in for infrastructure that has not been built.
Which is why it does not scale to the volume the labor arithmetic is about to demand. If the work moves into software because there is no one to hire, and the safety mechanism is a person reading every message, the bottleneck simply relocates.
The number most teams have not picked
One concrete illustration of how early this is. Most organizations shipping patient-facing AI have not chosen a retention period for their interaction records. The ones that have usually say five years.
Five years comes from the Medicare condition of participation for hospital medical records.[13] It is a floor, and it is the wrong floor for many deployments. The HIPAA Security Rule's number is six years, and it covers documentation of required activities rather than the medical record itself, since HIPAA sets no medical record retention period at all.[13] Medicare Advantage runs to ten years, and the audit rights provision flows down to first tier, downstream and related entities, which is the one most likely to bind a vendor without anyone noticing.[13]
A defensible position is the longer of six years, the applicable state medical record period, or ten years wherever a Medicare Advantage contract sits anywhere in the chain. Whatever number an organization picks, retention is the one governance decision that cannot be made later. It has to be made before the records exist.
What this asks of operators
Handing work to AI is a reasonable answer to the labor arithmetic, and for many programs it will be the only available one. It is not a complete answer until the software can be held to account the same way the person it replaced could.
That is a specific and buildable list rather than a philosophy. The patient should know when a communication is AI generated. The message should be checked against the program's rules before it is sent, and stoppable. Every check should trace to a named policy and the version of it that was in force. There should be a record separating what the model proposed from what was actually sent, with the rule that fired and the person who released it. Escalation should alert in real time and name an owner. And the whole record should survive long enough to answer for itself.
At AnyBio we build the governed layer patient-facing agents run on. Messages are checked against the program's rules before they cross the wire, out-of-bounds output is blocked rather than merely scored, and every action is written down as it happens in exactly the separations described above. We are an early company. We built for this standard before it arrived, on the view that the record would turn out to be the product.
The rule moving through CMS this year is about who employs the person doing the work. The question underneath it is what happens when the answer is nobody.
Sources
- Centers for Medicare & Medicaid Services, CY2027 Medicare Physician Fee Schedule proposed rule (CMS-1848-P), July 2026 - direct-employee restriction on RPM/RTM management, general supervision unchanged, initiating visit permitted in person or by telehealth.
- HHS Office of Inspector General, "Billing for Remote Patient Monitoring in Medicare" (OEI-02-23-00261), September 2024 - 43 percent of enrollees did not receive at least one of the three required components.
- Medical Group Management Association, MGMA Stat poll, May 2025 - 47 percent named medical assistants the hardest role to fill versus 15 percent for nurses.
- American Medical Group Association, 2025 Medical Clinic Staffing Survey, November 2025: a 4.8 percent decrease in support-staffing ratios per 10,000 work RVUs within primary care, alongside a 2.3 percent rise in patient visits.
- Health Resources and Services Administration, Nurse Workforce Projections, 2023-2038 - projected licensed practical nurse supply adequacy near 70 percent.
- Illinois Wellness and Oversight for Psychological Resources (WOPR) Act, 2025.
- Utah H.B. 452, Artificial Intelligence Amendments (mental health chatbots), 2025 - affirmative defense via a policy filed with the Division of Consumer Protection; penalties up to $2,500 per violation.
- New York AI companion safeguard law (2025), penalties up to $15,000 per day; California S.B. 243 companion chatbot law (private right of action).
- Colorado H.B. 25-1195 (psychotherapy AI restrictions) - synchronous, real-time clinician involvement.
- The Joint Commission and Coalition for Health AI, "Responsible Use of AI in Healthcare" guidance (2025); NIST AI 600-1 Generative AI Profile; ONC HTI-1 final rule (predictive decision support transparency); URAC Health Care AI Accreditation.
- Commonwealth of Pennsylvania (State Board of Medicine) petition against an AI chatbot developer for the unlicensed practice of medicine, May 2026 - described by the state as the first action of its kind.
- CMS, CY2027 Medicare Physician Fee Schedule proposed rule - new MIPS improvement activity crediting responsible clinician use of AI, including AI-drafted responses to patient questions.
- Medicare Conditions of Participation, 42 CFR 482.24(b)(1) (five-year hospital medical record floor); HIPAA Security Rule, 45 CFR 164.316(b)(2) (six-year documentation retention); Medicare Advantage, 42 CFR 422.504(i) (ten-year record retention flowing to first tier, downstream and related entities).
