Medicaid audit defense

Adult day care Medicaid audit defense

An auditor asks you to prove twelve member-days from four months ago. AdultDayGenie documents adult day care attendance with face-verified check-in, digital signatures, and timestamped records that assemble into an audit packet — so the proof exists before anyone asks for it.

How an adult day care Medicaid audit sample works

Adult day care Medicaid audits are not hypothetical

UPIC, RAC, and MFCU auditors don't review every claim you've ever billed. They pull a sample and let the math do the rest.

A sample audit usually starts small — often thirty or more claims, drawn from your full billing history. The reviewer isn't trying to catch every problem; they're testing whether your recordkeeping holds up under scrutiny.

If a handful of those samples land on days you can't document, the finding doesn't stay contained to those few days. Auditors extrapolate the error rate they find across your entire billed population — so a handful of missing sign-in sheets can turn into a disallowance on claims you were never even asked to prove.

None of this means a center did something wrong. It means a paper sign-in sheet, kept in a binder, is being asked to answer for months of billing at once — and inadequate sign-in sheets are precisely what those disallowances were written over.

A typical sample request asks for, per member and per date:

  • Proof the member was present — a check-in and a check-out
  • The exact time of arrival and departure
  • A signature confirming the visit
  • Whatever device or method captured it

That's the artifact below — not reconstructed the week the letter arrives, assembled from records that already existed the day the visit happened.

The adult day care evidence packet

This is what comes back when the sample lands on your center. Every row already existed — captured the day it happened, not reconstructed the week the letter arrived.

Sample export

Response to Audit Sample #A-2026-0417

12 member-days requested · Feb 24 – Mar 19, 2026 · generated Jul 26, 2026, 10:14 AM

Riverside Adult Day Center · New York (fictional facility, for illustration only)

Append-only record
MemberDateCheck-inCheck-outSignatureDevice

Dorothy Hale

Client ID A-2291

Feb 24, 2026

Dorothy Hale

08:02 AMFace verified98.2% match

Dorothy Hale

03:47 PMFace verified97.7% match

Dorothy Hale

03:48 PMSignature

Signed at checkout

iPad · Front Lobby Kiosk

Dorothy Hale

Client ID A-2291

Mar 10, 2026

Dorothy Hale

07:58 AMFace verified98.0% match

Dorothy Hale

03:52 PMFace verified97.1% match

Dorothy Hale

03:53 PMSignature

Signed at checkout

iPad · Front Lobby Kiosk

Harold Jensen

Client ID A-2314

Feb 26, 2026

Harold Jensen

08:11 AMFace verified96.5% match

Harold Jensen

03:40 PMFace verified96.9% match

Harold Jensen

03:41 PMSignature

Signed at checkout

iPad · Front Lobby Kiosk

Harold Jensen

Client ID A-2314

Mar 12, 2026

Harold Jensen

08:14 AMStaff photo-confirm

Staff photo-confirm — consent on file, kiosk camera unavailable

Harold Jensen

03:44 PMStaff photo-confirm

Staff-confirmed

Harold Jensen

03:45 PMSignature

Signed at checkout

iPad · Front Lobby Kiosk

Miriam Castillo

Client ID A-2358

Mar 2, 2026

Miriam Castillo

07:55 AMFace verified99.0% match

Miriam Castillo

03:38 PMFace verified98.6% match

Miriam Castillo

03:39 PMSignature

Signed at checkout

Tablet · Kiosk 2, Activity Room

Miriam Castillo

Client ID A-2358

Mar 16, 2026

Miriam Castillo

08:07 AMFace verified97.9% match

Miriam Castillo

03:41 PMFace verified98.2% match

Miriam Castillo

03:42 PMSignature

Signed at checkout

Tablet · Kiosk 2, Activity Room

Walter Boone

Client ID A-2402

Mar 4, 2026

Walter Boone

08:20 AMFace verified97.1% match

Walter Boone

04:12 PMStaff photo-confirm

Corrected — kiosk offline at 3:58 PM, original attempt preserved

Walter Boone

04:13 PMSignature

Signed at checkout

iPad · Front Lobby Kiosk

Walter Boone

Client ID A-2402

Mar 18, 2026

Walter Boone

08:09 AMFace verified97.3% match

Walter Boone

03:49 PMFace verified97.0% match

Walter Boone

03:50 PMSignature

Signed at checkout

iPad · Front Lobby Kiosk

Esther Byrne

Client ID A-2447

Feb 27, 2026

Esther Byrne

07:49 AMFace verified98.7% match

Esther Byrne

03:35 PMFace verified98.0% match

Esther Byrne

03:36 PMSignature

Signed at checkout

Tablet · Kiosk 2, Activity Room

Esther Byrne

Client ID A-2447

Mar 13, 2026

Esther Byrne

08:02 AMFace verified97.8% match

Esther Byrne

03:44 PMFace verified97.5% match

Esther Byrne

03:45 PMSignature

Signed at checkout

Tablet · Kiosk 2, Activity Room

Leon Ackerman

Client ID A-2478

Mar 6, 2026

Leon Ackerman

08:16 AMFace verified96.5% match

Leon Ackerman

03:58 PMFace verified96.2% match

Leon Ackerman

03:59 PMSignature

Signed at checkout

iPad · Front Lobby Kiosk

Leon Ackerman

Client ID A-2478

Mar 19, 2026

Leon Ackerman

08:04 AMFace verified97.1% match

Leon Ackerman

03:41 PMFace verified97.0% match

Leon Ackerman

03:42 PMSignature

Signed at checkout

iPad · Front Lobby Kiosk

Every timestamp, score, and signature above was written at the moment of capture. None of it can be edited after the fact — corrections are appended as new, notated events.

The audit-sample workflow

From audit letter to submitted response

The one-click export a sample request actually needs.

  1. 01

    An auditor requests a sample

    UPIC, RAC, or MFCU pulls roughly thirty claims and asks you to prove a slice of them — say, twelve member-days from four months ago.

  2. 02

    You select the members and the dates

    Inside AdultDayGenie, pick the members and the date range named in the request. No binders, no asking staff to remember a Tuesday in March.

  3. 03

    The packet assembles itself

    Every check-in, check-out, face-match score, signature, and device record for that slice — already captured, already timestamped, already unable to be edited.

  4. 04

    You export and respond

    One file, formatted for an audit sample response, with member name and client ID intact on every line.

Attendance records that can't be edited after the fact

This is the part that makes the packet worth something to an auditor. A record that could have been changed after the visit proves nothing. This one can't be.

Not possible

Editing or deleting a saved check-in

The database itself refuses the request. It is not a permission setting someone could change — it is a rule that applies to every user, including our own application code.

System response

"attendance_events is append-only; insert a correcting event instead"

What happens instead

A new, notated event is appended

Example: Walter Boone's March 4 checkout kiosk went offline. Staff logged the real time from the sign-out log — the original attempt stayed on the record, and the correction sits right next to it with a note and a new timestamp.

03:58 PM — check-out attempt, device offline

04:12 PM — check-out appended, staff-confirmed, note attached

Exports stand on their own, years later

Member name and client ID are captured on every event the moment it happens, not looked up later. If a member's profile changes — a name, a discharge, a re-enrollment — an export from three years ago still reads correctly on its own.

Why this matters right now

Auditors are already disallowing claims for exactly this

New York State Comptroller, Feb 19, 2026

$672,147

disallowed at three social adult day centers — specifically because they lacked proper sign-in sheets.

$285M

in improper payments identified across New York's SADC program in the same audit. One Flushing center billed 530 participants in a day against a 323-person capacity.

A state auditor rarely disallows claims for a missing sign-in sheet. When it happens, it is the clearest signal available of what auditors are actually checking for.

NY MLTC Policy 25.05 · effective Sept 8, 2025

Managed long-term care plans are now required to collect and review SADC sign-in/sign-out records — member name, date, and start and end times — and retain them for audit.

That is the exact artifact described on this page. Every AdultDayGenie export already carries those fields.

Questions

Adult day care Medicaid audit questions owners ask

No. Congregate and center-based services — including adult day — are explicitly outside federal EVV scope under the Cures Act, and no state has been confirmed to extend EVV to adult day care. That's the gap AdultDayGenie fills voluntarily: EVV made home visits provable; nothing did the same for the building until a center chooses to add it.

Not reliably. New York's State Comptroller identified $285M in improper Social Adult Day Care payments and disallowed $672,147 at three facilities specifically because they lacked proper sign-in sheets — one Flushing center had billed 530 participants in a day against a 323-person capacity (NY State Comptroller, Feb 19, 2026). A paper sheet documents that a name and a time were written down; it doesn't independently verify who was present or when. AdultDayGenie's face match, signature, and timestamp attach to the same event automatically, producing a record with more to show if a sign-in is ever questioned.

It varies by state and program. In New York, MLTC Policy 25.05 (effective September 8, 2025) requires managed long-term care plans to collect and review Social Adult Day Care sign-in and sign-out records — member name, date, and start and end times — and retain them for audit. AdultDayGenie's records capture those fields on every check-in and check-out automatically, plus a signature and, where used, a face-match confidence score.

A sample audit — from UPIC, RAC, or MFCU — usually starts with a request for a slice of your billed claims, often thirty or more, asking you to prove specific member-days. Auditors don't need to review every claim: the error rate found in that sample can be extrapolated across your full billed population, so a handful of missing sign-in sheets can affect claims you were never directly asked about. What a sample request needs, per member and date, is proof of presence, an exact time, a signature, and the method that captured it.

Retention periods are set by each state's Medicaid program, not by us. New York's MLTC Policy 25.05 requires plans to retain SADC sign-in and sign-out records for audit review — check your state's specific rule for the exact duration. AdultDayGenie's attendance events are append-only and never deleted, so your records are already retained by default, ready whenever a state or program's retention rule applies.

No tool can guarantee an audit outcome, and we don't claim to. What AdultDayGenie provides is a defensible record — proof that a visit was verified, signed, and timestamped the day it happened, not reconstructed afterward.

No. The database blocks UPDATE and DELETE on every attendance event, and there is no setting that overrides it — not for staff, not for administrators, not for our own application. Corrections are new, notated events, never edits to history.

Every check-in has a non-biometric path: a staff photo-confirm plus signature. Declining biometric consent never blocks a member from receiving service.

As far back as your records exist. Because member name and client ID are captured on every event at the time it happens, an export from three years ago still stands on its own, even if the member's profile has since changed.

A per-member, per-date export with check-in and check-out timestamps, face-match confidence where biometric verification was used, a digital signature, and device information — formatted for an audit sample response.

No. AdultDayGenie is an attendance-evidence layer that runs alongside your existing billing or EHR system. It doesn't ask you to rip anything out.

Start building your evidence packet today

Every check-in from here forward adds one more provable day to your record.