Specializing in Creating Customized IVRs, Voice, SMS, Chat and HIPAA Compliant Secure Message Applications

Where EVV compliance breaks down under audit

Healthcare Solutions

If you're in healthcare, you owe it to yourself to learn how you can make your everyday business processes more efficient and save money at the same time. We can help in automating many of your routine and repetitive tasks, including Patient Engagement surveys.

Contact us to learn more

Transportation Solutions

If you're in the transportation business, you can automate many of your routine tasks like package notifications, surveys, collection calls and more. Improve your customer satisfaction by extending your service hours without extending your costs.

Connect with us to learn more

Three recurring gaps in electronic visit verification that federal reviewers find, and the operational checks that close them

Electronic visit verification (EVV) records whether a caregiver logged in and out. It does not, by itself, prove that the visit was authorized, that the units billed match what was approved, or that the attendant was eligible to provide the service. Those are the questions a federal Medicaid audit asks, and they are the questions that trip programs up.

Recent reporting that Colorado faced a federal audit and an $8 million repayment demand is a reminder that the technology alone does not create audit-ready records. What matters is the everyday process around edits, documentation, and exception review. When a regulator asks for proof that visits were rendered and paid correctly, the program needs clear, attributable evidence and a defensible oversight process.

Three patterns audits routinely find

Federal reviews and their contractors focus on a small sample of claims, and they look for the same gaps. First, visits are recorded but not documented in a way an auditor can link to an approved service. A logged check-in with no associated visit type, or a manual entry that lacks corroborating paperwork, creates a gap between “the system says the visit happened” and “the record shows what was authorized.”

Second, payment and unit controls are often weak. Systems without basic edits can allow claims that collectively exceed feasible hours for a single day, or that pay at the wrong rate. When state systems do not validate units against approved authorizations and schedules, outliers slip through and become the focus of an audit sample.

Third, background-screening documentation is treated as a personnel record separate from the EVV flow. If screening proofs are kept in a different filing system without cross-reference to the attendant ID used at the point of service, it is very hard to demonstrate that the person who worked the visit was eligible to be paid.

Why sample errors extrapolate

Auditors typically work from a sample. A handful of mismatches in a reviewed sample can be extrapolated to a large number of claims if the sampling frame and the underlying data have the gaps described above. The defensibility of each reviewed record matters because it lowers the risk that a small error becomes a large repayment demand.

What auditors ask for in visit records

Federal reviewers focus on a few core questions: was the service authorized, did the visit actually occur as recorded, and was the attendant eligible? These sound straightforward, but they translate into specific expectations for program data and process. Programs with strong oversight can answer these three questions reliably:

  • Can you show the approved service authorization and the corresponding EVV entry for the same date and timeframe?
  • Is there corroborating evidence that ties the attendant to that visit, such as a logged phone verification or a linked check-in method that is auditable?
  • Do personnel records confirm required background screenings were completed and retained for the attendant who provided the service?

When these three items are easy to produce, an auditor’s job is straightforward and favorable conclusions are more likely. When those links require chasing across multiple systems or paper files, the program looks administratively weak even if services were actually provided.

Designing oversight that produces auditable evidence automatically

The shift is not about buying a new EVV product. It is about designing the oversight and the system edits so that daily operations produce auditable evidence automatically. A few practical checks make a big difference.

Start with the records the state expects to show. Require visit entries to include the service type and an authorization reference that can be matched to what the payer approved. Add simple edits that prevent more units or paid hours than an approved authorization allows. Those edits do not have to block every exceptional case, but they should flag the exceptions for immediate review.

Next, make background-screening documentation part of the same lifecycle. Whether the proof is scanned, linked, or stored in an encrypted personnel repository, the oversight process needs to refer back to an attendant identifier used in the EVV record. If personnel verification is manual today, plan for a cross-reference field and a weekly reconciliation process so missing paperwork gets caught before an audit sample is drawn.

Exception handling needs a documented workflow. An attestation that a provider will review flagged mismatches is not enough. The program needs named contacts, a review log, and retention rules so an auditor can trace what was reviewed and why a payment was allowed or recouped. That documentation is what separates an administrative error from a systemic compliance problem.

Think about the channel mix for verification. Voice-based phone verification and recorded check-ins are useful alternatives for caregivers or enrollees who lack smartphones or who object to location sensors. A program that supports multiple, auditable verification channels reduces access barriers and leaves a stronger record trail. For more on visit verification options, see electronic visit verification tools.

When the record includes a recorded phone verification or a linked supervisor sign-off, an auditor has something tangible to review. Call retention and recording policies should match the state’s retention window, and the team needs to be able to retrieve recordings tied to a specific claim. For a checklist of what operations must check, see call recording compliance.

Pre-audit reconciliation is an operational change many programs overlook. Running a regular, program-level reconciliation that compares authorized schedules, EVV entries, and payroll or claims lets teams spot outlier providers and close issues quickly. When outliers appear in a random sample, you want to be able to show the auditor that you flagged and corrected similar issues proactively.

The tradeoff is real: overly strict automatic denials can harm access for vulnerable enrollees, and overly lax edits create audit exposure. The defensible posture is to tune the system to catch implausible entries automatically, flag reasonable exceptions for quick review, and keep a documented trail of the review decision.

The Centers for Medicare and Medicaid Services has guidance and program expectations that most states use as a reference. Linking your technical and policy checks to those expectations makes your decision logic easier to explain during a review.

Making EVV audit-defensible is mostly governance and process design, applied to the data the system already collects. It is not a single product feature. Procurement and program managers often ask vendors about edit rules, exception workflows, personnel-document linkage, and retrieval time for records. Those are the questions a federal audit will ask next.

Related coverage: Colorado faces $8M repayment demand after federal Medicaid audit — Colorado Springs Gazette