A New Jersey home-care agency

The audit · document 05 of 07

Boundaries & risks

A care record is a legal document: every rule here comes with the mechanism that enforces it, and every risk with what contains it.

The boundaries — rules and their enforcement

The worker's attestation stays the worker's

A reviewer never edits a submission into approval. A problem goes back to the person who attested.

enforced by

Reviewer actions are two: return with a named reason, or approve. The submitted record is append-only — who wrote what, and when, cannot be rewritten by anyone.

Nothing becomes official without a person

No official PDF, no filing, no pay or billing export from an unapproved packet.

enforced by

Generation, filing, and exports run only from the approve action, behind the reviewer’s login, one packet at a time. Batch-approve does not exist.

Care judgment stays human

The system checks completeness and arithmetic — never the quality of care. Nothing writes or rewrites an outcome note.

enforced by

Every validation is a deterministic rule the agency can read in plain language. The drafted AI-assist layer ships switched off; turning it on is a separate, written compliance decision (document 06).

The agency's data stays the agency's

Participant records isolated to the agency’s workspace; files in the agency’s own SharePoint; exports theirs. Nothing trains anything.

enforced by

A single-tenant workspace in the agency’s Azure tenancy, under a business-associate agreement and designed around HIPAA obligations: role-scoped access, encryption in transit and at rest, access revocable by the agency in one place.

Everything is logged

Submission, check results, returns, approvals, generation, filing, exports — who, what, when.

enforced by

An append-only audit trail that cannot be edited from inside the app. The agency can export it any day, in full.

The risk register

Named during the audit, reviewed with the agency. Likelihood × impact, and the control that contains each.

RiskSeverityControl
The generated form drifts from the state's format low × high The layout is pinned to the state revision and accepted field-for-field at build; the parallel run compares outputs before cutover; a format change is a versioned, human act in one place.
A worker can't — or won't — use it medium × high No passwords: magic links and text codes on the phones workers already carry. Rollout in two waves, the senior DSP’s cohort first; paper stays accepted through the transition — and remains the outage fallback forever.
Authorized-hours ceiling wrong, or overridden casually low × high Ceilings come from the plan data and are shown with their arithmetic; entry flags, approval blocks; overrides are supervisor-only and logged with a reason.
Late submissions persist despite reminders medium × low Reminders land before the deadline; the overdue view opens Monday 08:00; repeat lateness surfaces per worker, with its record, for a human conversation — not an automated sanction.
A Sunday-night outage at the submission peak low × medium The fallback is today’s process: paper is always accepted late; drafts autosave on the phone; nothing about the week is locked behind the system.
Over-trust — returns fall to zero because nobody reads medium × medium The return rate is one of the four weekly numbers (document 07). A stretch with no returns triggers a sampled re-review, not a celebration.
Participant data exposed through the filing path low × high Files land only inside the agency’s own SharePoint permissions, named by the agency’s own convention; access is role-scoped end to end; the audit itself read how documentation moves and never copied contents.
Prepared by /analog · part of the home-care case study.
open daily · 24/7 · +1 (786) 370-9416 · hello@slashanalog.com · privacy notice