COMPLIANCE & OPERATING DISCIPLINE

Be ready to explain
the whole story.

Which order? Which evidence? Which delivery? Which decision? Compliance becomes more useful when those answers are connected to the daily work.

WHY THIS MATTERS NOW · REVIEWED OCTOBER 4, 2026

DME oversight is active.
Requirements keep changing.

CMS has announced additional prior-authorization requirements for selected items beginning October 28, 2026, including phased requirements by state. These are scheduled changes, not a blanket rule for every item. Read the CMS update ↗

A March 2026 federal DME sentencing involved kickbacks and claims for medically unnecessary equipment. It reinforces why an opportunity must pass through legitimate need, documentation and human review. Read the DOJ release ↗

EVIDENCE THROUGH THE JOURNEY

The control has a purpose.

The right requirement depends on the item, payer, jurisdiction, service date and supplier. Your team remains responsible for applying the current rules.

INTAKE & ORDERS

See the gap before the handoff.

Preserve the incoming record and make missing order elements, signatures and item-specific documentation visible.

DELIVERY & BILLING

Connect the event to the claim.

Keep actual delivery evidence, service dates and billing decisions distinguishable. Follow rejections and denials back to the supporting record.

QUALITY & TRAINING

Make the operating review visible.

Connect policy versions, acknowledgement, quality findings, complaints, corrective action and staff learning.

ACCESS & OVERSIGHT

Match access to the work.

Agree named staff permissions, review the access matrix and validate critical boundaries before activation.

HIPAA & THE PILOT

BAA first.
Patient data after setup.

The public demonstration uses synthetic records. Before any pilot handles PHI, the required Business Associate Agreement must be executed and the approved environment, users, data scope and safeguards must be ready.

A BAA is one part of the program. Risk analysis, workforce practices, security, recovery and the relevant service agreements also matter.

HHS guidance on cloud services and HIPAA ↗
Standards and guidance behind these workflows

HHS: Security Rule guidance ↗

Risk analysis and administrative, physical and technical safeguards explain the need for verified access, audit, recovery and operational review.

FCC: AI voices and the TCPA (FCC 24-17) ↗

AI-generated voices fall within artificial/prerecorded-voice restrictions. Consent, exemptions, identification and opt-outs must be evaluated for the actual call; a DME relationship alone is not the full analysis.

Reference review: October 4, 2026. Verify the current version and requirements applicable to your business.

Your operation. Your scope.

See what changes
at your desk.

Start with a guided demo. Explore a free 14-day pilot built around the workflows you want to evaluate.

Request your free pilot

Selected modalities · agreed AI allowance
BAA and setup before patient data