The visit was billed. Nobody came.
Electronic visit verification was mandated to stop Medicaid paying for home care visits that never happened. It records a phone call, or a phone's location, or a code read from a device on a wall. None of those is a caregiver, and that gap is the whole story.
Six clients, one Tuesday, ninety miles
Picture a home care aide starting her day at 7:15 in the morning. She has six clients scheduled, spread across a county, in a car she is still paying off. Her first client needs help with a shower and a shave, which takes longer than the authorised time because he has good days and bad days and this is a bad one. She stays anyway. She will not be paid for the extra nineteen minutes.
Before she leaves, she picks up his landline and dials a toll-free number, punches in her worker code, the client code, and the service code. That call is her electronic visit verification. It is the artifact that will eventually become a line on a Medicaid claim. She has done it four thousand times.
At the same moment, somewhere else in the same state, a different call is being placed to the same toll-free number, with a different worker code and a different client code. Nobody is in that client's home. The person dialling is at a kitchen table with a list of numbers. The call takes forty seconds. It will produce a claim that is, as far as the system is concerned, indistinguishable in kind from the one the first aide just generated after an hour of genuine, physically demanding, underpaid work.
That is the problem in one image. Both events produced identical evidence. One of them was care.
Here is the part that should bother you most: when the fraud is eventually found, and it is found, through claims analytics, whistleblowers or a prosecutor's subpoena, the policy response is almost always another layer of verification aimed at the aide. More check-ins. Tighter GPS. A device in the client's living room. The honest aide, who was already staying nineteen unpaid minutes, absorbs the cost of a control designed for someone she has never met.
Electronic visit verification fails to stop phantom home care visits because it verifies a telephone call, a phone's GPS position, or a code read from a fixed device. None of those binds a specific caregiver to a specific visit. The Cures Act requires systems to record the individual providing the service, but the deployed implementations record a device and infer the person. Closing that gap requires a presence receipt signed by the aide's own enrolled device.
What is electronic visit verification, and why does it exist?
Section 12006 of the 21st Century Cures Act required state Medicaid programmes to implement electronic visit verification for personal care services and, later, for home health services, with the home health deadline landing on 1 January 2023 after Congress moved the earlier personal care deadline to 1 January 2020. States that failed to comply faced reductions in federal matching funds, which is why every state has an EVV system whether or not it wanted one.
The statute is specific about what an EVV system must capture. Six elements: the type of service performed, the individual receiving the service, the date of the service, the location of service delivery, the individual providing the service, and the time the service begins and ends.
Read the fifth element again. The individual providing the service. The law asked for the person. What got built, almost universally, records a proxy for the person and infers the rest.
That is not a drafting failure. In 2016, binding a human to a moment at scale meant either a biometric reader in every client's home, which was neither affordable nor acceptable, or a credential the worker carried, which is what everyone chose. A worker code punched into a phone is a credential. So is a login on an agency app. The system verifies the credential and writes down that the individual associated with it provided the service.
Credentials are transferable. That is their defining property, and it is the entire gap. It is the same gap that lets an attacker reroute a paycheck by changing a bank detail behind a session that passed every check, which we cover in the direct deposit change is the whole attack.
Why does EVV fail to stop phantom visits?
Go through the deployed methods one at a time, because each fails differently and the differences matter to anyone designing the replacement.
Telephony EVV
The aide calls a toll-free number from the client's landline. The system captures the calling number, which establishes the location, plus the codes entered, which establish who and what. Its virtue is that it needs no smartphone and no data plan, which matters enormously for a low-wage workforce and for rural clients.
What it proves is that somebody called from that line and knew the codes. Caller ID can be spoofed, call forwarding can relay, and in the simplest version the client's own phone is used by whoever is in the house, including a family member or the agency itself. Reporting in 2026, including in the Philadelphia Inquirer, described criminal cases in which visits were logged for services that were not provided, and the law firm Rivkin Radler has described enforcement matters where EVV calls attested to services when nobody from the agency was present with the client at all.
GPS app EVV
The aide checks in and out on a smartphone app that stamps coordinates. This is the modern default and it is a genuine improvement over telephony, because it captures both ends of the visit and works away from a landline.
It proves a phone was near a location at a time. It does not prove a person was, and it does not prove that person stayed. An aide can check in at the door and leave. A phone can be handed to someone else, or left in a car, or carried by a relative who is genuinely providing the care while the credentialed worker is elsewhere. Location spoofing on a personal device is a solved problem for anyone motivated, and the app runs on hardware the agency does not control.
Fixed object devices
A small device is installed in the client's home. The aide reads a rotating code from it and enters that code, proving proximity to the device at that time. It removes the phone from the trust chain, which is a real gain.
It proves somebody read the device. The code can be photographed, relayed by text message, or read by a household member. And it puts a piece of monitoring hardware permanently in a disabled person's living space, which is a cost that falls on someone who committed no fraud.
Claims analytics after the fact
Cross-referencing visit records against other data catches impossible patterns: two visits ninety miles apart within ten minutes, visits logged while a client was hospitalised, aides billing more hours than exist in a day. Investigators have used exactly this method, including cross-referencing billing against clinic records to expose phantom services.
Analytics work, and they work after the money has left. They are also, and this is the objection that deserves weight, a probabilistic instrument pointed at individuals. Writing in Health Affairs, commentators have argued that unfounded fraud allegations against home and community based services threaten the programmes themselves and the people who depend on them. An analytics flag is a suspicion, and suspicion applied to a workforce of low-wage carers and a client population of disabled and elderly people is not a neutral act.
Notice the pattern across all four. Each verifies an artifact that stands in for a person: a phone line, a device location, a code, a billing pattern. This is the enrollment binding gap in its purest form, paired with identity discontinuity, because even where an aide was correctly identified at hire, nothing re-establishes that it is still her on visit four thousand.
What does the enforcement record actually show?
Be careful with numbers here, because this is an area where advocacy on all sides reaches for figures that do not survive scrutiny, and where an inflated fraud statistic does real harm to people who need care.
What can be said with confidence is that enforcement activity is substantial and continuing. The Department of Justice's Fraud Division has announced charges against multiple defendants in home health aide schemes in single coordinated announcements, spanning agency owners, aides and in some matters recipients. The HHS Office of Inspector General maintains active work plan items examining whether EVV data is complete and whether in-home personal care claims are properly recorded and verified, including recommendations to specific state programmes. The New York State Comptroller has audited Medicaid personal care and home health payments covering more than 31 billion dollars over a 26 month period, as described in published analysis of the audit.
What cannot responsibly be said is a precise national phantom visit rate. The improper payment figures that exist bundle fraud with documentation errors and eligibility problems, categories that are morally and practically distinct. A missing signature on a form is not a fabricated visit. Anyone quoting a single percentage for home care fraud is either citing an improper payment rate as though it were fraud, or extrapolating from enforcement actions, which are by definition a sample of what got caught.
The honest framing is this: home and community based services are one of Medicaid's largest and fastest growing spending areas, enforcement has been sustained for years across multiple states, and the specific evasion described in the case record is repeatedly the same one, which is that verification was satisfied without the caregiver being present. That is enough to justify fixing the mechanism without inventing a number.
The objection that deserves a serious answer
Before proposing anything, it is necessary to take seriously the two constituencies who have the strongest reasons to distrust a new verification requirement, because both have been badly served by the last decade of technology in this sector.
What disability advocates have said, and why they are right
EVV has been opposed by disability rights organisations since before it was implemented, and the objection is not a misunderstanding of the technology. It is that a person receiving home care in their own home is subject to a level of monitoring that no other recipient of a public service experiences. The location being verified is their bedroom. The schedule being enforced is their body's. A device on the wall of a living room, or a GPS trace of who entered a home and when, is surveillance of a disabled person's private life justified by the possibility that somebody else might commit fraud.
There is a second, quieter harm. EVV enforces a model of care in which visits are discrete, scheduled, and located, and a great deal of good home care is not. Someone who takes a client to an appointment, or shops for them, or stays late because the day went badly, generates data that looks like an exception and triggers a review. The technology encodes a bureaucratic fiction of care and then penalises the reality.
Any proposal that does not begin by conceding these points is not serious. The design implication is direct and constraining: whatever verifies the visit must attach to the worker, not to the home. No device in the living space. No location trail of the client. Nothing that streams. The client should be able to receive care without being an instrument of somebody else's compliance obligation.
What home care workers have said, and why they are also right
Home care aides are among the lowest paid workers in healthcare, are frequently unpaid for travel time between clients, and have absorbed successive waves of monitoring technology that made their day harder without visibly reducing fraud. A worker who is docked because an app lost GPS in a basement apartment, or flagged because traffic made her late to client four, experiences EVV as a mechanism that assumes she is stealing.
Ask who actually benefits from the current arrangement. Not the aide, who is monitored. Not the client, who is monitored in their own home. The agency owner running a fraudulent operation is the one person for whom the existing controls are trivially satisfiable, because they are satisfied by codes and devices the operator controls. The system inverted: it constrains the people with the least power and barely inconveniences the people with the most.
That inversion is also the strongest argument for changing the mechanism. A check that binds a visit to the specific human who performed it is the first control in this sector that an agency owner cannot satisfy from an office. And it produces something the honest aide has never had: her own portable evidence that she did the work, which she can use when an agency disputes her hours, when a claim is questioned, or when she moves to a new employer. That portability is the point of the verified work passport.
What would binding a human to a visit look like?
Start from the constraints that the previous section imposes, because a design that violates them will be rejected and should be.
Nothing may live in the client's home. Nothing may track the worker between visits. No image may leave the device. No template may be stored anywhere. The check must complete in seconds, on a cheap phone, and must work when the signal does not. And the worker, not the agency, must hold the resulting record.
Here is a construction that satisfies all of those.
At hire, the aide enrols once on her own phone. A face match runs entirely in the browser, on the device, and produces a vector that never leaves it. From that vector the device derives a one way key and binds it to a passkey held in the phone's secure hardware. Nothing that can reconstruct her face exists anywhere afterwards, including on her own phone. The agency stores a key, which is an opaque value, and nothing else.
At the visit, she opens the app and signs the visit start. Depending on the assurance the state requires, the check is one of three modes. A brief on-device face check, taking a couple of seconds, for a first visit with a new client or a randomised sample. A trusted device shortcut when a known aide is at a known client on her own enrolled phone, which is the common case and requires nothing but a tap. Or a companion device flow for the case where her phone is unavailable and she needs to prove presence using the client's device, without that device ever learning who she is.
What the visit produces is a signed receipt. It contains the visit, not the person.
{
"v": 1,
"visit_id": "v_2026-09-10_c4417_a221",
"client_ref": "c4417", // the state's identifier, not a name
"worker_key": "wk_38fa10c7b9e2", // opaque, derived on device
"service_code": "T1019",
"start": "2026-09-10T07:22:04Z",
"end": "2026-09-10T08:31:47Z",
"presence": { "mode": "glance", "liveness": true },
"sig": "ed25519:MEQCIF9k...",
"key_id": "manav-2026-03"
}
Notice what is absent. No coordinates. No photograph. No biometric template. No record of where the aide was before or after. The client appears as the identifier the state already uses. The aide appears as an opaque key that means nothing outside this programme.
Verification is arithmetic, not a database query, which is the property that matters for an investigator:
from nacl.signing import VerifyKey
import json, base64
def verify_visit(receipt, published_key_b64, enrolled_worker_key):
# 1. is this receipt for the worker the agency claims performed the visit?
if receipt["worker_key"] != enrolled_worker_key:
return False, "receipt was signed by a different enrolled worker"
# 2. did a live presence check happen at the visit?
if not receipt["presence"]["liveness"]:
return False, "no liveness at visit start"
# 3. is the signature genuine? no callback, no vendor, no network
signed = json.dumps({k: receipt[k] for k in
("v","visit_id","client_ref","worker_key",
"service_code","start","end","presence")},
sort_keys=True, separators=(",",":")).encode()
VerifyKey(base64.b64decode(published_key_b64)).verify(
signed, base64.b64decode(receipt["sig"].split(":")[1]))
return True, "this enrolled human was present for this visit"
The third step is the one that changes investigations. A Medicaid Fraud Control Unit investigator, or a state auditor, or a defence attorney representing an aide accused of billing a visit she actually made, can check that signature against a published key without asking a vendor for access, without a subpoena, and years later. Today an investigator asking about a visit is asking an EVV aggregator to attest to its own records. The presence tracker demo shows the shape of the check, and the phantom shift demo applies the identical primitive to unworked shifts in other sectors. The integration details are in the developer documentation.
How do the verification methods compare?
The column that usually goes missing from vendor comparisons is the last one. It is the one the people being verified care about most.
| Method | What it proves | How it is evaded | What it costs the client | What it costs the aide |
|---|---|---|---|---|
| Telephony EVV | A call was placed from a number, by someone knowing the codes | Spoofing, forwarding, anyone in the home, codes shared | Their landline becomes a compliance instrument | Nothing, which is its one real virtue |
| GPS app EVV | A phone was near a place at a time | Phone left behind or handed over, location spoofing, check in at the door | Their address becomes a tracked location | Battery, data, flags for signal loss, implicit distrust |
| Fixed object device | Somebody read a code near the device | Photographed or relayed code, household member reads it | Monitoring hardware permanently in their living space | One more thing to do that can fail |
| Claims analytics | A billing pattern is statistically improbable | Nothing, but it operates after payment | Being the subject of a fraud model | Suspicion from a probabilistic flag |
| Biometric time clock | A face or finger matched a stored template | Harder to evade, but creates a biometric database | Depends on deployment | Permanent template held by an employer, legal exposure |
| Presence receipt | This enrolled human was present at this visit | Enrolment compromise, a substitute working under the enrolled aide's supervision | Nothing in the home, no location trail | Seconds per visit, and portable proof of work she owns |
The biometric time clock row is worth pausing on, because it is the obvious alternative and it is the one to avoid. Storing face or fingerprint templates for a workforce creates exactly the asset that regulators and litigants pursue, and it has produced substantial liability for employers under state biometric privacy statutes. The distinction between storing a template and deriving a one way key on a device that keeps the biometric is not a technicality. It is the difference between holding a permanent record of somebody's body and holding a number that cannot be turned back into one.
What this cannot do
Five limits, stated plainly, because a control sold without them will be sold to the wrong problems.
It does not stop agency-level billing fraud. This is the most important limit and it is often the larger category. If an agency fabricates authorisations, bills for clients who were never eligible, upcodes services, or pays kickbacks for referrals, no amount of proving that a real aide attended a real visit touches it. A presence receipt closes the phantom visit route specifically. Some fraud will simply move to routes it does not cover, and honest analysis should expect that.
An aide can still hand her phone to a substitute. If she performs the check herself and then a friend or family member does the visit, the receipt is valid and wrong. The check raises the cost of substitution from free to requiring the enrolled worker's physical presence at the start of every visit, and randomised mid-visit checks raise it further, at a privacy cost that has to be weighed. It does not reduce that cost to zero.
Collusion with the client defeats it. Where a client and a worker agree to log visits that did not occur, the receipt records a genuine presence check by a genuine aide and proves nothing useful. Client co-signature makes this harder, but it also asks something of a person who may have cognitive impairment, and that trade should be made programme by programme rather than assumed.
Enrolment is the trust bottleneck. Everything rests on the first check binding the right person to the key. An agency that controls enrolment can enrol whoever it likes. The mitigation is that enrolment happens against the same identity evidence the state already requires at hire, and that the enrolment event itself produces a receipt an auditor can inspect.
Nothing here is shipped as an EVV product. We do not have a connector to Sandata, HHAeXchange or Netsmart, and there is no CMS format export. The primitives are in production for other workflows and the mapping to EVV described here is a design, not a deployed integration. Anyone evaluating this should treat it as a proposal to pilot rather than a product to buy.
What to do this week
- Ask your EVV vendor, in writing, which of the six Cures Act data elements their system verifies cryptographically and which it infers from a device. The answer to element five, the individual providing the service, is the one to read closely.
- Pull a sample of visits and ask what evidence exists that the credentialed aide was physically present, separate from evidence that a device was. If the answer is the same artifact for both, you have found the gap.
- Count what your agency spends on EVV compliance per aide per year, including device costs, app support, and the staff time spent reconciling failed check-ins. That is the budget you are already paying for the current level of assurance.
- Review how many aides were flagged, disciplined or docked in the last year for EVV exceptions that turned out to be signal loss, address errors or schedule changes. That number is the honest cost of the present system to your workforce.
- If you are a state programme, ask whether an investigator can verify a visit record without the aggregator's cooperation. If not, your evidence depends on a vendor relationship surviving.
- Talk to your aides and to a client advocacy group before piloting anything. A control introduced without them will be resisted, and the resistance will be legitimate.
- If you pilot a presence check, measure aide acceptance and visit completion by device type before and after. A verification step that quietly excludes workers with old phones has moved a cost rather than removed one.
Frequently asked questions
Why does electronic visit verification fail to stop home care fraud? Because it verifies an artifact that stands in for a person rather than the person. Telephony EVV proves a call was placed from a number. GPS EVV proves a phone was near a location. A fixed device proves a code was read. The Cures Act asks systems to record the individual providing the service, and deployed implementations record a credential and infer the individual from it.
What is EVV under the 21st Century Cures Act? Section 12006 required state Medicaid programmes to implement electronic visit verification for personal care services and home health services, with the home health deadline on 1 January 2023, backed by reductions in federal matching funds for non-compliance. Systems must capture six elements: service type, recipient, date, location, the individual providing the service, and the start and end times.
Can EVV GPS be faked? Location spoofing on a personal device is straightforward for anyone motivated, but it is rarely the weakest link. Simpler evasions dominate: checking in at the door and leaving, handing the phone to someone else, or leaving the phone at the address. GPS establishes where a device was, and the question that matters is who was there.
Does verifying the aide mean building a biometric database of care workers? It should not, and a design that does is the wrong one. The construction described here runs the face match on the worker's own device, keeps the image and the vector there, and derives a one way key that cannot be reversed. The employer stores an opaque key. Storing templates centrally creates precisely the liability that state biometric privacy statutes target.
Do disability advocates object to EVV, and are those objections reasonable? Yes and yes. EVV subjects people receiving care in their own homes to monitoring no other recipient of a public service experiences, and it encodes a rigid model of care that penalises the flexible reality. Any replacement should attach verification to the worker rather than the home, with no device in the living space and no location trail of the client.
Would this stop all home care fraud? No. It addresses the phantom visit specifically, where a visit is billed and nobody attended. Agency-level schemes involving fabricated authorisations, ineligible clients, upcoding or kickbacks are unaffected, and worker and client collusion defeats it. Expect displacement toward the routes it does not cover, and plan analytics accordingly.
Sources
- 21st Century Cures Act, Public Law 114-255, Section 12006, establishing the electronic visit verification requirement and its six data elements.
- Centers for Medicare and Medicaid Services, Electronic Visit Verification guidance, including state compliance requirements and deadlines.
- HHS Office of Inspector General, Work Plan, including active items on EVV system completeness and in-home personal care services claims.
- United States Department of Justice, Office of Public Affairs press releases, including Fraud Division announcements charging defendants in Medicaid home health aide schemes.
- Office of the New York State Comptroller, audits of Medicaid personal care and home health payments, covering more than 31 billion dollars over a 26 month period.
- Rivkin Radler, Electronic Visit Verification: the new frontier in home health fraud enforcement.
- Health Affairs, Unfounded fraud allegations threaten vital Medicaid home and community based services.
- KFF, Medicaid home care research, on programme scale and the current federal focus on fraud and abuse.
- The Philadelphia Inquirer, 2026 reporting on criminal cases in which electronic visit verification was evaded. Cited by publication; see inquirer.com.
The law asked systems to record the individual providing the service. We built systems that record a phone and hope.