Remote patient monitoring has grown from a Medicare experiment into a core care-delivery model — and with that growth has come scrutiny. Payers, health-system partners, and investors increasingly ask RPM companies one question early in diligence: are you accredited?
Two organizations dominate RPM accreditation in 2026: URAC and The Joint Commission. Here's what each requires, how the programs differ, and how accreditation intersects with your entity structure.
Why RPM accreditation matters now
Accreditation is voluntary — no federal law requires it. But three forces are making it a de facto requirement:
- Payer credentialing. Health plans use accreditation as a proxy for quality when contracting with virtual-care vendors.
- Enterprise sales. Hospitals and health systems increasingly require accreditation before signing RPM partnership agreements.
- Regulatory posture. With OIG attention on RPM billing (CPT 99453, 99454, 99457/99458), a documented quality program is your best defense in an audit.
URAC Remote Patient Monitoring Accreditation
URAC launched the first accreditation program built specifically for RPM. It evaluates five domains:
- Operations — governance, staffing, policies, and vendor oversight
- Clinical oversight — evidence-based monitoring protocols, escalation pathways, and clinician credentialing
- Quality management — measurable quality benchmarks with annual reporting
- Technology — hardware and software functionality, data integrity, and device management
- Risk management — data privacy and security, patient consent, and disclosure practices
The program is open to providers, health plans, specialty care organizations, and telehealth companies. The review process typically takes about four months, and accreditation lasts three years with annual quality-measure reporting.
Joint Commission Telehealth Accreditation
The Joint Commission's telehealth accreditation covers organizations delivering care via telehealth or remote patient monitoring. Eligibility extends to organizations that are exclusively virtual, freestanding entities with no in-person visits, or organizations providing telehealth services under written agreements with other providers.
Expect standards spanning patient safety, clinical documentation, credentialing and privileging, emergency escalation, and information management. If your RPM program sits inside a broader virtual-care platform — or you sell into hospitals that already hold Joint Commission accreditation — this pathway often aligns better with what your customers' compliance teams expect.
URAC vs. Joint Commission: how to choose
| Factor | URAC RPM | Joint Commission Telehealth |
|---|---|---|
| RPM-specific standards | Purpose-built RPM program | RPM covered within telehealth standards |
| Typical buyer signal | Health plans, payers | Hospitals, health systems |
| Cycle | 3 years, annual reporting | 3 years |
| Best fit | Standalone RPM companies, device-plus-service models | Virtual-first providers selling into health systems |
Many mature RPM companies eventually hold both. If you're choosing one first, follow your revenue: payer-driven models tend to start with URAC; health-system channel models tend to start with the Joint Commission.
What accreditors will ask about your entity structure
This is the piece RPM founders consistently underestimate. Both programs probe clinical oversight and credentialing — who employs the monitoring clinicians, who supervises them, and who is accountable for clinical decisions.
If your RPM company is lay-owned and directly employs nurses or physicians who exercise clinical judgment, you have a Corporate Practice of Medicine problem and an accreditation problem. Surveyors expect a clean line: a physician-owned professional entity responsible for clinical protocols, supervision, and escalation decisions, with the MSO running technology, devices, staffing logistics, and billing.
Getting the MSO-PC structure right before you apply makes the clinical-oversight sections of either survey dramatically easier — and it's far cheaper than restructuring mid-application.
Pre-application checklist
- Written, evidence-based monitoring protocols with defined escalation thresholds
- Credentialing files for every monitoring clinician
- Physician-owned PC responsible for clinical oversight (state-by-state where required)
- BAA and security documentation for every device and data vendor
- Patient consent and disclosure workflow (including billing consent for RPM CPT codes)
- Quality measures you can actually report annually
- Documented supervision model that satisfies both accreditor standards and state supervision laws
How Foundry PC helps
Foundry PC builds the compliance foundation accreditors look for: a Friendly PC Owner, a properly documented MSO-PC structure, and clean clinical-governance lines between your business and the professional entity.