The audit · document 05 of 07
Boundaries & risks
A care record is a legal document: every rule here comes with the mechanism that enforces it, and every risk with what contains it.
The boundaries — rules and their enforcement
The worker's attestation stays the worker's
A reviewer never edits a submission into approval. A problem goes back to the person who attested.
Reviewer actions are two: return with a named reason, or approve. The submitted record is append-only — who wrote what, and when, cannot be rewritten by anyone.
Nothing becomes official without a person
No official PDF, no filing, no pay or billing export from an unapproved packet.
Generation, filing, and exports run only from the approve action, behind the reviewer’s login, one packet at a time. Batch-approve does not exist.
Care judgment stays human
The system checks completeness and arithmetic — never the quality of care. Nothing writes or rewrites an outcome note.
Every validation is a deterministic rule the agency can read in plain language. The drafted AI-assist layer ships switched off; turning it on is a separate, written compliance decision (document 06).
The agency's data stays the agency's
Participant records isolated to the agency’s workspace; files in the agency’s own SharePoint; exports theirs. Nothing trains anything.
A single-tenant workspace in the agency’s Azure tenancy, under a business-associate agreement and designed around HIPAA obligations: role-scoped access, encryption in transit and at rest, access revocable by the agency in one place.
Everything is logged
Submission, check results, returns, approvals, generation, filing, exports — who, what, when.
An append-only audit trail that cannot be edited from inside the app. The agency can export it any day, in full.
The risk register
Named during the audit, reviewed with the agency. Likelihood × impact, and the control that contains each.
| Risk | Severity | Control |
|---|---|---|
| The generated form drifts from the state's format | low × high | The layout is pinned to the state revision and accepted field-for-field at build; the parallel run compares outputs before cutover; a format change is a versioned, human act in one place. |
| A worker can't — or won't — use it | medium × high | No passwords: magic links and text codes on the phones workers already carry. Rollout in two waves, the senior DSP’s cohort first; paper stays accepted through the transition — and remains the outage fallback forever. |
| Authorized-hours ceiling wrong, or overridden casually | low × high | Ceilings come from the plan data and are shown with their arithmetic; entry flags, approval blocks; overrides are supervisor-only and logged with a reason. |
| Late submissions persist despite reminders | medium × low | Reminders land before the deadline; the overdue view opens Monday 08:00; repeat lateness surfaces per worker, with its record, for a human conversation — not an automated sanction. |
| A Sunday-night outage at the submission peak | low × medium | The fallback is today’s process: paper is always accepted late; drafts autosave on the phone; nothing about the week is locked behind the system. |
| Over-trust — returns fall to zero because nobody reads | medium × medium | The return rate is one of the four weekly numbers (document 07). A stretch with no returns triggers a sampled re-review, not a celebration. |
| Participant data exposed through the filing path | low × high | Files land only inside the agency’s own SharePoint permissions, named by the agency’s own convention; access is role-scoped end to end; the audit itself read how documentation moves and never copied contents. |
open daily · 24/7 · +1 (786) 370-9416 · hello@slashanalog.com · privacy notice