Fix 3 Audit Risks Now: Home Care Compliance Checklist for Owners

Run this checklist and fix three things first: confirm every caregiver personnel file has current credentials, verify every plan of care matches its EVV visit data, and review and address EVV exceptions promptly before audit time. Pull five personnel files, five client charts, and five recent visits right now and check them against the standards below. If they pass, you’re in good shape. If they don’t, you have a punch list, not a crisis.
TL;DR:
Regularly audit caregiver files for current credentials, training, and competency documentation to prevent lapses that could trigger systemic deficiencies.
Ensure client charts include signed plans of care, up-to-date supervisory notes, and verify EVV visit data matches billing claims to avoid audit flags.
Review EVV exception logs promptly within days of service to catch mismatches or manual entries before they compromise billing or compliance.
Maintain organized records of licenses, insurance, and contracts with clear retention timelines to meet federal and state regulations without guesswork.
Use a centralized compliance calendar with assigned owners, automated alerts, and documented corrective actions to build a sustainable audit-ready workflow.
Table of Contents
How to Use This Home Care Compliance Checklist
A workable checklist mirrors what an auditor actually samples: personnel files, client records and the plan of care, EVV data, billing documentation, policies and training logs, and administrative records like licenses and insurance. Auditors move through categories in roughly that order because each one feeds the next. A plan of care means nothing if the visit that fulfilled it was never verified, and an EVV record means nothing if the claim built on it doesn’t match.
The fastest way to know where you stand is a small self-audit you can run in an afternoon.
Pull five active caregiver personnel files and check credential expiration dates, background check status, and training signoffs.
Pull five client charts and compare the plan of care to the most recent EVV visit records for date, time, and service code alignment.
Pull five recent EVV visits and check for open exceptions, manual entry justifications, and matching visit notes.
Record what you find in a simple missing-items log: file name, what’s missing, who owns the fix, and the deadline. That log becomes the seed of your corrective action plan and your first entries in a compliance calendar.
Pro Tip: Run this sample audit regularly and frequently. Small, frequent checks catch issues such as lapsed CPR cards early, avoiding problems at survey time.
Personnel and Caregiver Files: What Auditors Expect to Find
Auditors don’t read personnel files cover to cover. They pull a sample and check for specific items, and if two or three files are missing the same document, they widen the sample. That pattern, one gap repeated across files, is what turns a minor finding into a systemic one.
Every active caregiver file should contain:
Form I-9 and eligibility to work documentation
A completed criminal background check, dated and on file before the first shift
Current professional licensure or certification, where the role requires it
TB test results or other required health screenings, with renewal dates tracked
CPR and first-aid certification, current and not expired
Signed orientation and job description acknowledgment
Documented competency evaluations and periodic performance reviews
The competency piece gets skipped more than any other item on this list. A signature on an orientation form proves someone attended training. It doesn’t prove they can safely transfer a patient or recognize signs of skin breakdown. Auditors increasingly want to see a documented, dated competency check, not just a class roster.
Tracking expirations manually across a caregiver roster of any real size is where agencies lose the thread. A simple expiration dashboard, whether it’s a shared spreadsheet or dedicated software, needs an owner and automated reminders at 60 and 30 days out. Without an assigned owner, “someone will catch it” becomes the default plan, and that’s exactly the gap ACHC’s accreditation checklist flags most often in personnel file audits.
Pro Tip: Assign one person, not a team, to own credential tracking. Shared ownership of expiration dates is how CPR cards lapse for months without anyone noticing.
Client Records and the Plan of Care: What Belongs in Every Chart
A complete client chart holds the intake documentation, the initial assessment, the signed plan of care, physician orders tied to that plan, supervisory visit notes, and any incident reports on file. Missing supervisory visit documentation is one of the most frequently cited findings in small-agency surveys, according to industry audit resources, often because the visit happened but nobody wrote it down.
For Medicare-certified agencies, OASIS accuracy adds another layer. The CMS OASIS manual calls for regular data-quality audits, and the strongest method combines two checks: a record-to-record congruence review, where you compare OASIS codes against the chart narrative, and a supervisory observation audit, where a second clinician completes the OASIS independently during a visit and compares results against the original coding. Doing both catches the coding drift that a single-method review misses.
Retention and authentication rules aren’t optional guidance, they’re federal requirements. Under 42 CFR § 484.110, clinical records must be:
Accurate, legible, and complete
Authenticated with a signature and title, or a secured electronic entry
Dated and timed at the point of documentation
Retained for a federally required minimum duration after discharge, longer if state law requires it
Retrievable on request and protected under HIPAA’s privacy and security rules
Recommended OASIS audit frequency runs regularly throughout the year depending on agency size, per CMS guidance. Larger agencies with higher assessment volume lean toward monthly sampling. That single retrieval requirement, being able to produce a record on demand, is often the first thing a surveyor tests, before they ever read a word of clinical content.
EVV and Visit Verification: The Six Data Points and How to Manage Exceptions
Electronic Visit Verification isn’t optional documentation. It’s a federal requirement for personal care and home health services under Medicaid, and every visit record needs to capture six specific data points.
The type of service performed
The individual receiving the service
The date of the service
The location of the service
The individual providing the service
The time the service begins and ends
Many states layer on additional requirements, like GPS accuracy tolerances or specific reason codes for manual entries, so check your state Medicaid agency’s EVV policy on top of the federal baseline.
Exceptions, missed clock-ins, GPS mismatches, and manual entries, need to be reviewed and cleared close to the visit date, not batched at month’s end. A near-term review means a caregiver can still recall the details clearly if a note is missing. A month-old exception is a guess dressed up as documentation.
Reconciliation is where EVV audits usually fail. Visit times need to match the corresponding visit note narrative, and both need to match what actually gets billed. When a claim shows a two-hour visit but the EVV record shows ninety minutes, that mismatch is exactly what triggers a payer audit flag, and it’s one of the easiest things to catch internally before a payer catches it externally.
Billing and Financial Documentation Auditors Review
Every claim you submit should trace back cleanly to an EVV record before it goes out the door. Pre-bill quality checks should confirm the EVV clock-in and clock-out times, the provider identity, the service code, and the visit note all tell the same story. When one of those four doesn’t match, hold the claim.
Keep remittance advice and appeals correspondence organized by claim, not buried in a shared inbox, and reconcile explanation of benefits statements against what you billed on a monthly cycle rather than waiting for a denial to notice a discrepancy.
Match EVV times, provider identity, and service code against the visit note before submission
File and retain remittance advice for every processed claim
Reconcile EOBs monthly, not quarterly
Keep a running log of denials and the reason codes attached to each
Payer audits move faster and end better when your documentation is already organized this way. Agencies that scramble to reconstruct a claim’s paper trail after the fact are the ones that end up with recoupments they can’t successfully appeal.
Pro Tip: Treat a denial as a data point, not a one-off headache. Three denials with the same reason code in a month usually point to a process gap, not bad luck.
Policies, Training, and Competency: Turning Paperwork Into Practice
A policy manual that nobody follows is worse than no manual at all, because it gives an auditor a written standard your agency clearly isn’t meeting. Policy management guidance from OIG and HHS makes a distinction that matters here: a policy states intent, a procedure tells staff exactly what to do, and without the second piece, staff treat the first as paperwork.
At minimum, your policy manual needs to cover infection control, emergency preparedness, incident reporting, grievance handling, HIPAA and PHI protection, and supervision standards, each with a documented review date, not a one-time creation date.
Training logs should record the topic, the date, the trainer, and a caregiver signature confirming attendance
Competency evidence should go beyond a signature, capturing an observed skill check where the task allows it
QA sampling should run on a fixed schedule, not whenever someone has spare time
Every QA finding should convert into a tracked corrective action with a completion date, not a verbal reminder
The agencies that pass surveys smoothly aren’t the ones with the thickest policy binders. They’re the ones where the binder and the daily workflow actually match.
Administrative Records and Retention Rules You Can’t Guess At
Beyond clinical files, auditors expect current business licenses, active insurance certificates, signed managed care organization contracts, and surety bonds where your state requires them. Grievance logs, incident logs, and governance meeting minutes round out the administrative file, and they get requested more often than most owners expect.
Confirm business licenses and liability insurance are current, not expiring mid audit cycle
Keep signed MCO and payer contracts on file and easily retrievable
Maintain grievance and incident logs with resolution dates, not just intake dates
Track governance documentation if your agency has a board or advisory structure
Retention periods vary by document type and layer on top of each other. CMS sets a five-year baseline for clinical records under 42 CFR § 484.110. HIPAA documentation, like privacy policies and business associate agreements, generally needs six years under HHS guidance. Several states extend clinical retention well past five years, so check your state health department’s rule before you shred anything.
Building a Compliance Calendar That Actually Gets Followed
A checklist tells you what’s required. A calendar tells you when to check it, and that’s the piece most agencies skip until a survey forces the issue.
Inventory every recurring obligation, credential renewals, OASIS submission deadlines, care plan review dates, insurance renewals, and license expirations, in one place.
Set alert lead times of 30 to 60 days before each deadline, not the day it’s due.
Assign a named owner to every category, not a department.
Run daily EVV exception triage, weekly credential spot checks, monthly sample audits, and a deeper quarterly review across all categories.
Document every audit finding with a deficiency statement, root cause, corrective action, and a verification date to confirm the fix actually held.
A centralized calendar with lead-time alerts is consistently identified as the single change that prevents the most common survey findings: expired credentials, stale care plans, and missing supervisory visit notes. The corrective action plan format matters too. A vague “we’ll fix it” doesn’t survive a follow-up survey. A documented root cause with a monitoring step does.
Pro Tip: Put the calendar owner’s name next to each deadline, not just the department. “Someone in scheduling” is not an owner; a person with a name is.

How Trained Coordinators Reduce Compliance Risk
Some agencies handle this entire rhythm internally. Others bring in trained coordinators who specialize in exactly this work, tracking credential expirations, clearing EVV exceptions daily, covering after-hours calls so nothing goes undocumented overnight, and keeping documentation current between internal audits.
Credential and license expiration tracking with proactive renewal reminders
Daily EVV exception review instead of a monthly backlog
After-hours call coverage that documents every call, not just the urgent ones
Support pulling and organizing documentation ahead of a scheduled or surprise audit
This isn’t the only path to audit readiness, a disciplined internal calendar and dedicated staff time can get you there too. It’s simply an alternative worth weighing against the cost of building that capacity from scratch.
What I’d Prioritize This Week and This Quarter
Run the five-file sample audit today. Clear every open EVV exception before it ages past a week. Confirm your license and insurance renewal dates aren’t hiding closer than you think.
Then look further out. Over the next ninety days, automate your compliance calendar instead of tracking it in your head, standardize your chart and policy templates so every file looks the same, and put a real training and audit cadence on the calendar, not just the wall.
Compliance isn’t a project you finish. It’s a habit you repeat until the next survey feels routine instead of terrifying.
— Ian Dwight Abejo
An Option to Outsource Your Compliance Operations
Building this rhythm internally works, but it takes a dedicated person watching credentials, clearing EVV exceptions, and answering the phone at 2 AM when a caregiver calls off. Hiring that role in-house means salary, payroll taxes, benefits, and the risk that coverage disappears the day that one employee calls in sick.

The Command Center covers phones nights, weekends, and holidays, documenting every call and filling shifts before a family notices a gap, while a dedicated coordinator keeps credential tracking, EVV exception review, and documentation support running between your own internal audits. If you’re weighing whether to build this capacity yourself or bring in a team that’s already trained for it, see how The BOSS System works and request a conversation about what an outsourced compliance-support engagement would look like for your agency.
Sources
The clinical record standards above come from 42 CFR § 484.110 and the CMS OASIS manual. Compliance program structure follows OIG guidance, and accreditation checklist items reference ACHC’s annual compliance checklist. For form-level HIPAA compliance, Klyr Media’s practical guide is worth a read. Always confirm state-specific documentation rules with your own state health department, since retention and licensure requirements vary beyond the federal baseline.
This article is general information, not a substitute for advice from a qualified lawyer. Consult a qualified legal professional about your own circumstances before acting on anything here.
Recommended







Comments