TL;DR
CMS’s CCM rules aren’t just about billing rates, they’re operational requirements that determine whether a claim survives an audit. Eligibility (2+ chronic conditions) and medical necessity are separate documentation requirements, not one checkbox. Consent must be specific, dated before time logging starts, and retained for 10 years. Time logs need staff attribution and real (not rounded) durations, since rounded entries are a named leading cause of audit findings. CMS added CCM to the OIG’s 2026 Work Plan through FY2028, so these gaps are now under active federal review.
What CMS Actually Requires, Separate From the Rates
Most CCM content covers what the program pays. Fewer cover what CMS actually requires operationally to bill it defensibly, and that gap is exactly where audit risk lives. This piece covers the guidelines: eligibility, consent, documentation, and the specific rules that determine whether a claim survives a review.
Eligibility Guidelines
CMS requires two or more chronic conditions expected to last at least 12 months, or carrying significant risk of death, acute exacerbation, or functional decline. There’s no CMS-published approved condition list. But eligibility and medical necessity are two separate requirements, not one, and this is the distinction most CCM guides collapse into a single checkbox. Documenting that a patient has two qualifying conditions establishes eligibility. It does not, by itself, establish that CCM is clinically appropriate and necessary for that specific patient in that specific month. A program that treats “2+ conditions confirmed” as the complete eligibility test is documenting half the requirement.
A qualifying initiating visit (Annual Wellness Visit, comprehensive E/M, or Transitional Care Management visit) is required for new patients, or for patients the billing practitioner hasn’t seen in the past year. It’s a genuinely separate encounter, not folded into the same visit as the CCM enrollment conversation, but it isn’t a blanket requirement for every enrolled patient every year the way some internal guidance assumes.
Consent Guidelines
Patient consent for CCM can be verbal or written, but it has to be documented with real specificity: the date it was obtained, the method, and confirmation the patient understood the cost-sharing that applies (CCM carries the standard Part B 20% coinsurance unless supplemental coverage applies), and it has to be logged and dated before any CCM time gets recorded against that patient, not backfilled after the fact. Consent is obtained once and doesn’t need to be repeated monthly, but it does need to be re-confirmed if the billing practitioner changes. One requirement programs consistently underbuild for: CMS requires the consent record be retained for 10 years, which is a records-management commitment most CCM workflows aren’t actually built to honor, since it outlasts most EHR data-retention defaults and most staff turnover cycles.
Documentation Guidelines
The comprehensive care plan is the documentation backbone: patient conditions, goals, interventions, and a list of care team members and community services, updated as the patient’s status changes, not created once and left static. Time logging needs staff attribution (who performed the coordination activity), the specific activity type, and start/stop times or clear duration. Rounded or estimated time is one of the specific, named leading causes of CCM audit findings, not a generic “keep good records” warning; auditors are trained to look for the pattern of suspiciously round numbers (every entry logged at exactly 20 minutes) as a signal of reconstructed rather than contemporaneous logging. One practitioner bills CCM per patient per month; a second practitioner billing CCM for the same patient in the same month will have their claim denied, and CMS guidance places responsibility on providers to coordinate and avoid this rather than treating it as an acceptable error rate.
See How Audit-Ready CCM Workflows Actually Work
The Guideline Most Programs Get Wrong
It isn’t the care plan and it isn’t the time log, both of which most programs already know to build carefully. It’s the gap between eligibility and medical necessity described above: a patient chart can show two qualifying chronic conditions clearly, and still lack a documented clinical rationale for why CCM coordination is necessary for that patient specifically that month. CMS and OIG guidance treat these as two separate documentation requirements, and an audit that finds eligibility well-documented but medical necessity unaddressed doesn’t get a pass on the first half. CMS guidance doesn’t require perfection, it requires a documented, reconstructable process, but “reconstructable” has to cover both halves of the requirement, not just the easier one.
Why This Matters More in 2026
CMS added Chronic Care Management to the Office of Inspector General’s 2026 Work Plan, with eligibility documentation and the multiple-chronic-conditions requirement named specifically, running through fiscal year 2028. Guidelines that were previously enforced loosely are now the subject of active federal review focus, which changes the practical cost of a documentation gap from theoretical to real.
How Mindbowser Approaches This
We build CCM platforms where the guidelines above are structural features of the workflow, not a compliance checklist bolted on after the fact. Consent capture is structured with the specific fields an audit requires, timestamped before time logging opens for that patient, and retained on a schedule built for the 10-year requirement rather than the shorter defaults most EHR archival policies assume. Care plans are versioned monthly by design, not left static until someone remembers to update them. Time logging happens at the point of work with staff attribution built in, precisely to avoid the rounded-time pattern auditors are trained to flag. Medical necessity gets its own documented field, separate from the eligibility check, so a chart can’t pass the “2+ conditions” test and silently skip the clinical-rationale requirement. Concurrency checks (has another practitioner already billed this patient this month) run automatically before a claim is generated, rather than relying on staff to catch a conflict manually. Custom CCM billing and coding automation is where we build this specific workflow.
Conclusion
Eligibility ≠ medical necessity. CMS/OIG treat them as two separate documentation requirements. Passing one doesn’t cover the other. Consent must be logged and dated before any CCM time is recorded — never backfilled. Consent records must be retained 10 years longer than most EHR default retention and most staff tenure. Rounded/estimated time entries (e.g., every log at exactly 20 min) are a specifically named audit red flag. Only one practitioner can bill CCM per patient per month. CMS puts the coordination burden on providers, not on chance. CCM is on the OIG’s 2026 Work Plan through FY2028; enforcement focus is active, not theoretical.
No. Eligibility is a clinical judgment call based on two or more conditions expected to last 12 months or carrying significant risk of decline, documented specifically for that patient, not matched against a fixed list. Eligibility and medical necessity are separate requirements; documenting the former doesn’t satisfy the latter.
Consent is obtained once and doesn’t need monthly renewal, but should be re-confirmed if the billing practitioner changes. The consent record itself has to be retained for 10 years.
A structured consent record dated before time logging began, a care plan with evidence of monthly updates, a minute log with staff attribution and activity type (not rounded or estimated entries), a separately documented medical-necessity rationale distinct from bare eligibility, and confirmation that only one practitioner billed the patient in a given month.
Rounded or estimated time entries are a specifically named leading cause of audit findings. A close second is a care plan that hasn’t been meaningfully updated, or documenting eligibility without separately documenting medical necessity.








BLOGS
NEWSROOM
CASE STUDIES
WEBINARS
PODCASTS
ASSET HUB
EVENT CALENDAR 


















