top of page
the-boss-logo.png
  • Facebook
  • Instagram
  • X
  • LinkedIn
  • Youtube
  • TikTok

Fix 3 Audit Risks Now: Home Care Compliance Checklist for Owners

Writer: Alyana Cabayao
Alyana Cabayao
Sep 5
10 min read

Hands reviewing caregiver compliance records

Run this checklist and fix three things first: confirm every caregiver personnel file has current credentials, verify every plan of care matches its EVV visit data, and review and address EVV exceptions promptly before audit time. Pull five personnel files, five client charts, and five recent visits right now and check them against the standards below. If they pass, you’re in good shape. If they don’t, you have a punch list, not a crisis.

 

TL;DR:  
  • Regularly audit caregiver files for current credentials, training, and competency documentation to prevent lapses that could trigger systemic deficiencies.

  • Ensure client charts include signed plans of care, up-to-date supervisory notes, and verify EVV visit data matches billing claims to avoid audit flags.

  • Review EVV exception logs promptly within days of service to catch mismatches or manual entries before they compromise billing or compliance.

  • Maintain organized records of licenses, insurance, and contracts with clear retention timelines to meet federal and state regulations without guesswork.

  • Use a centralized compliance calendar with assigned owners, automated alerts, and documented corrective actions to build a sustainable audit-ready workflow.

 

Table of Contents

 

 

How to Use This Home Care Compliance Checklist

 

A workable checklist mirrors what an auditor actually samples: personnel files, client records and the plan of care, EVV data, billing documentation, policies and training logs, and administrative records like licenses and insurance. Auditors move through categories in roughly that order because each one feeds the next. A plan of care means nothing if the visit that fulfilled it was never verified, and an EVV record means nothing if the claim built on it doesn’t match.

 

The fastest way to know where you stand is a small self-audit you can run in an afternoon.

 

  1. Pull five active caregiver personnel files and check credential expiration dates, background check status, and training signoffs.

  2. Pull five client charts and compare the plan of care to the most recent EVV visit records for date, time, and service code alignment.

  3. Pull five recent EVV visits and check for open exceptions, manual entry justifications, and matching visit notes.

 

Record what you find in a simple missing-items log: file name, what’s missing, who owns the fix, and the deadline. That log becomes the seed of your corrective action plan and your first entries in a compliance calendar.

 

Pro Tip: Run this sample audit regularly and frequently. Small, frequent checks catch issues such as lapsed CPR cards early, avoiding problems at survey time.

 

Personnel and Caregiver Files: What Auditors Expect to Find

 

Auditors don’t read personnel files cover to cover. They pull a sample and check for specific items, and if two or three files are missing the same document, they widen the sample. That pattern, one gap repeated across files, is what turns a minor finding into a systemic one.

 

Every active caregiver file should contain:

 

  • Form I-9 and eligibility to work documentation

  • A completed criminal background check, dated and on file before the first shift

  • Current professional licensure or certification, where the role requires it

  • TB test results or other required health screenings, with renewal dates tracked

  • CPR and first-aid certification, current and not expired

  • Signed orientation and job description acknowledgment

  • Documented competency evaluations and periodic performance reviews

 

The competency piece gets skipped more than any other item on this list. A signature on an orientation form proves someone attended training. It doesn’t prove they can safely transfer a patient or recognize signs of skin breakdown. Auditors increasingly want to see a documented, dated competency check, not just a class roster.

 

Tracking expirations manually across a caregiver roster of any real size is where agencies lose the thread. A simple expiration dashboard, whether it’s a shared spreadsheet or dedicated software, needs an owner and automated reminders at 60 and 30 days out. Without an assigned owner, “someone will catch it” becomes the default plan, and that’s exactly the gap ACHC’s accreditation checklist flags most often in personnel file audits.

 

Pro Tip: Assign one person, not a team, to own credential tracking. Shared ownership of expiration dates is how CPR cards lapse for months without anyone noticing.

 

Client Records and the Plan of Care: What Belongs in Every Chart

 

A complete client chart holds the intake documentation, the initial assessment, the signed plan of care, physician orders tied to that plan, supervisory visit notes, and any incident reports on file. Missing supervisory visit documentation is one of the most frequently cited findings in small-agency surveys, according to industry audit resources, often because the visit happened but nobody wrote it down.

 

For Medicare-certified agencies, OASIS accuracy adds another layer. The CMS OASIS manual calls for regular data-quality audits, and the strongest method combines two checks: a record-to-record congruence review, where you compare OASIS codes against the chart narrative, and a supervisory observation audit, where a second clinician completes the OASIS independently during a visit and compares results against the original coding. Doing both catches the coding drift that a single-method review misses.

 

Retention and authentication rules aren’t optional guidance, they’re federal requirements. Under 42 CFR § 484.110, clinical records must be:

 

  • Accurate, legible, and complete

  • Authenticated with a signature and title, or a secured electronic entry

  • Dated and timed at the point of documentation

  • Retained for a federally required minimum duration after discharge, longer if state law requires it

  • Retrievable on request and protected under HIPAA’s privacy and security rules

 

Recommended OASIS audit frequency runs regularly throughout the year depending on agency size, per CMS guidance. Larger agencies with higher assessment volume lean toward monthly sampling. That single retrieval requirement, being able to produce a record on demand, is often the first thing a surveyor tests, before they ever read a word of clinical content.

 

EVV and Visit Verification: The Six Data Points and How to Manage Exceptions

 

Electronic Visit Verification isn’t optional documentation. It’s a federal requirement for personal care and home health services under Medicaid, and every visit record needs to capture six specific data points.

 

  1. The type of service performed

  2. The individual receiving the service

  3. The date of the service

  4. The location of the service

  5. The individual providing the service

  6. The time the service begins and ends

 

Many states layer on additional requirements, like GPS accuracy tolerances or specific reason codes for manual entries, so check your state Medicaid agency’s EVV policy on top of the federal baseline.

 

Exceptions, missed clock-ins, GPS mismatches, and manual entries, need to be reviewed and cleared close to the visit date, not batched at month’s end. A near-term review means a caregiver can still recall the details clearly if a note is missing. A month-old exception is a guess dressed up as documentation.

 

Reconciliation is where EVV audits usually fail. Visit times need to match the corresponding visit note narrative, and both need to match what actually gets billed. When a claim shows a two-hour visit but the EVV record shows ninety minutes, that mismatch is exactly what triggers a payer audit flag, and it’s one of the easiest things to catch internally before a payer catches it externally.

 

Billing and Financial Documentation Auditors Review

 

Every claim you submit should trace back cleanly to an EVV record before it goes out the door. Pre-bill quality checks should confirm the EVV clock-in and clock-out times, the provider identity, the service code, and the visit note all tell the same story. When one of those four doesn’t match, hold the claim.

 

Keep remittance advice and appeals correspondence organized by claim, not buried in a shared inbox, and reconcile explanation of benefits statements against what you billed on a monthly cycle rather than waiting for a denial to notice a discrepancy.

 

  • Match EVV times, provider identity, and service code against the visit note before submission

  • File and retain remittance advice for every processed claim

  • Reconcile EOBs monthly, not quarterly

  • Keep a running log of denials and the reason codes attached to each

 

Payer audits move faster and end better when your documentation is already organized this way. Agencies that scramble to reconstruct a claim’s paper trail after the fact are the ones that end up with recoupments they can’t successfully appeal.

 

Pro Tip: Treat a denial as a data point, not a one-off headache. Three denials with the same reason code in a month usually point to a process gap, not bad luck.

 

Policies, Training, and Competency: Turning Paperwork Into Practice

 

A policy manual that nobody follows is worse than no manual at all, because it gives an auditor a written standard your agency clearly isn’t meeting. Policy management guidance from OIG and HHS makes a distinction that matters here: a policy states intent, a procedure tells staff exactly what to do, and without the second piece, staff treat the first as paperwork.

 

At minimum, your policy manual needs to cover infection control, emergency preparedness, incident reporting, grievance handling, HIPAA and PHI protection, and supervision standards, each with a documented review date, not a one-time creation date.

 

  • Training logs should record the topic, the date, the trainer, and a caregiver signature confirming attendance

  • Competency evidence should go beyond a signature, capturing an observed skill check where the task allows it

  • QA sampling should run on a fixed schedule, not whenever someone has spare time

  • Every QA finding should convert into a tracked corrective action with a completion date, not a verbal reminder

 

The agencies that pass surveys smoothly aren’t the ones with the thickest policy binders. They’re the ones where the binder and the daily workflow actually match.

 

Administrative Records and Retention Rules You Can’t Guess At

 

Beyond clinical files, auditors expect current business licenses, active insurance certificates, signed managed care organization contracts, and surety bonds where your state requires them. Grievance logs, incident logs, and governance meeting minutes round out the administrative file, and they get requested more often than most owners expect.

 

  • Confirm business licenses and liability insurance are current, not expiring mid audit cycle

  • Keep signed MCO and payer contracts on file and easily retrievable

  • Maintain grievance and incident logs with resolution dates, not just intake dates

  • Track governance documentation if your agency has a board or advisory structure

 

Retention periods vary by document type and layer on top of each other. CMS sets a five-year baseline for clinical records under 42 CFR § 484.110. HIPAA documentation, like privacy policies and business associate agreements, generally needs six years under HHS guidance. Several states extend clinical retention well past five years, so check your state health department’s rule before you shred anything.

 

Building a Compliance Calendar That Actually Gets Followed

 

A checklist tells you what’s required. A calendar tells you when to check it, and that’s the piece most agencies skip until a survey forces the issue.

 

  1. Inventory every recurring obligation, credential renewals, OASIS submission deadlines, care plan review dates, insurance renewals, and license expirations, in one place.

  2. Set alert lead times of 30 to 60 days before each deadline, not the day it’s due.

  3. Assign a named owner to every category, not a department.

  4. Run daily EVV exception triage, weekly credential spot checks, monthly sample audits, and a deeper quarterly review across all categories.

  5. Document every audit finding with a deficiency statement, root cause, corrective action, and a verification date to confirm the fix actually held.

 

A centralized calendar with lead-time alerts is consistently identified as the single change that prevents the most common survey findings: expired credentials, stale care plans, and missing supervisory visit notes. The corrective action plan format matters too. A vague “we’ll fix it” doesn’t survive a follow-up survey. A documented root cause with a monitoring step does.

 

Pro Tip: Put the calendar owner’s name next to each deadline, not just the department. “Someone in scheduling” is not an owner; a person with a name is.


Building a Compliance Calendar That Actually Gets Followed — overview diagram

How Trained Coordinators Reduce Compliance Risk

 

Some agencies handle this entire rhythm internally. Others bring in trained coordinators who specialize in exactly this work, tracking credential expirations, clearing EVV exceptions daily, covering after-hours calls so nothing goes undocumented overnight, and keeping documentation current between internal audits.

 

  • Credential and license expiration tracking with proactive renewal reminders

  • Daily EVV exception review instead of a monthly backlog

  • After-hours call coverage that documents every call, not just the urgent ones

  • Support pulling and organizing documentation ahead of a scheduled or surprise audit

 

This isn’t the only path to audit readiness, a disciplined internal calendar and dedicated staff time can get you there too. It’s simply an alternative worth weighing against the cost of building that capacity from scratch.

 

What I’d Prioritize This Week and This Quarter

 

Run the five-file sample audit today. Clear every open EVV exception before it ages past a week. Confirm your license and insurance renewal dates aren’t hiding closer than you think.

 

Then look further out. Over the next ninety days, automate your compliance calendar instead of tracking it in your head, standardize your chart and policy templates so every file looks the same, and put a real training and audit cadence on the calendar, not just the wall.

 

Compliance isn’t a project you finish. It’s a habit you repeat until the next survey feels routine instead of terrifying.

 

— Ian Dwight Abejo

 

An Option to Outsource Your Compliance Operations

 

Building this rhythm internally works, but it takes a dedicated person watching credentials, clearing EVV exceptions, and answering the phone at 2 AM when a caregiver calls off. Hiring that role in-house means salary, payroll taxes, benefits, and the risk that coverage disappears the day that one employee calls in sick.


The BOSS System

The Command Center covers phones nights, weekends, and holidays, documenting every call and filling shifts before a family notices a gap, while a dedicated coordinator keeps credential tracking, EVV exception review, and documentation support running between your own internal audits. If you’re weighing whether to build this capacity yourself or bring in a team that’s already trained for it, see how The BOSS System works and request a conversation about what an outsourced compliance-support engagement would look like for your agency.

 

Sources

 

The clinical record standards above come from 42 CFR § 484.110 and the CMS OASIS manual. Compliance program structure follows OIG guidance, and accreditation checklist items reference ACHC’s annual compliance checklist. For form-level HIPAA compliance, Klyr Media’s practical guide is worth a read. Always confirm state-specific documentation rules with your own state health department, since retention and licensure requirements vary beyond the federal baseline.

 

This article is general information, not a substitute for advice from a qualified lawyer. Consult a qualified legal professional about your own circumstances before acting on anything here.

 

 

Recommended

 

 
 
 

Comments


footer-bg-01.png
footer-bg-01.png
the-boss-logo-white.png
footer-bg-01.png
the-boss-logo-white.png

Menu

  • Instagram
  • Facebook
  • TikTok
  • LinkedIn
  • Youtube

Talk to Us

332 S Michigan Ave Suite 900 Chicago,

IL 60604, USA

3rd Floor Dantess Building 236 Sto. Rosario St., Brgy. Sto Rosario, Angeles City, Pampanga

888-711-BOSS

Service Area Covered

map-white_Mesa de trabajo 1.png
footer-bg-01.png
the-boss-logo-white.png
footer-bg-01.png
the-boss-logo-white.png

Menu

  • Instagram
  • Facebook
  • TikTok
  • LinkedIn
  • Youtube

Talk to Us

332 S Michigan Ave Suite 900 Chicago,

IL 60604, USA

3rd Floor Dantess Building 236 Sto. Rosario St., Brgy. Sto Rosario, Angeles City, Pampanga

888-711-BOSS

Service Area Covered

map-white_Mesa de trabajo 1.png

Schedule

meeting

Schedule

a meeting

bottom of page