Skip to main contentSkip to footer

    Top Rated & Verified

    Top Clutch App Development Company Black Owned United StatesTop Clutch Java Developers France 2026Top Clutch Service Line Blind Company Black Owned 2026Top Clutch App Development Company Minority Owned 2026Top Clutch Web Developers Black Owned 2026Top Clutch App Development Company Black Owned 2026Top Clutch Flutter Developers France 2026Top Clutch Health & Wellness App Developers France 2026Top Clutch Swift Company France 2026Top Clutch Machine Learning Company France 2026Top Clutch Chatbot Company France 2026Top Clutch Artificial Intelligence Company France 2026Top Clutch App Development Company Minority Owned Los Angeles
    Back to Blog
    Vertical Engineering Guide
    September 28, 2026
    28 min read

    Senior Care & Home Health App Development:The 2026 Electronic Visit Verification Guide

    A home health or senior care app lives or dies on one requirement most generic mobile-development advice never mentions: Electronic Visit Verification. What the federal mandate actually requires, how state models differ, and why GPS alone is both weak engineering and a live political fight in 2026.

    Senior care and home health app development in 2026 — Electronic Visit Verification, caregiver check-in, and state Medicaid aggregator integration
    Jan. 1, 2023
    Federal deadline for Home Health Care Services EVV compliance under the 21st Century Cures Act (personal care services: Jan. 1, 2020)
    21st Century Cures Act §12006(a); Medicaid.gov EVV guidance
    6
    Data elements every EVV visit record must capture: service type, recipient, provider, date, location, and time begun/ended
    21st Century Cures Act §12006(a)
    Up to 1%
    FMAP reduction a state can face for failing a 'good faith effort' toward EVV compliance without unavoidable delays
    Medicaid.gov EVV guidance, 2026
    $28k–$70k
    Single-platform EVV-compliant caregiver app build, 4–9 weeks
    Frenchy Digital scoping bands, 2026

    Key Takeaways

    • Electronic Visit Verification isn't optional for any app serving Medicaid-funded personal care or home health visits — the 21st Century Cures Act's §12006(a) mandate is fully in force nationwide, with the personal-care deadline (Jan. 1, 2020) and home-health deadline (Jan. 1, 2023) both long past.
    • Every EVV record needs six specific data elements: service type, who received care, who provided it, the date, the location, and the time begun and ended. States implement the technical details differently, but none can drop an element.
    • Whether a custom app can be your system of record depends on your state's model: open-model states let you build or buy your own EVV solution as long as it feeds the state's aggregator (commonly Sandata, via JSON over secure FTP or REST API); closed-model states mandate one system directly.
    • GPS-only verification is both the weakest common method and the one under the most active political pressure — Ohio's 2026 HB 795 debate specifically fought over expanding GPS tracking into live-in caregiver and family settings, with disability-rights advocates opposing it. Build telephony and, where appropriate, biometric fallback rather than GPS alone.
    • Offline-first architecture is a compliance requirement here, not a nice-to-have: a caregiver visiting a low-signal area still has to log a compliant visit, and a missing record from a failed sync is exactly what triggers the 'hard edit' claim denials several states moved toward in 2026.
    • 'Cures 2.0' is industry shorthand for an unresolved policy debate, not enacted law — the actual 2021-2022 bill (H.R. 6000) never passed. Don't build compliance assumptions around proposals that haven't taken effect.
    • 42 CFR Part 2's stricter confidentiality rules for substance-use-disorder records mean behavioral health visits often need separate, more restrictive handling than standard EVV data flows — confirm your state's specific carve-out before assuming one data pipeline covers your whole caseload.
    • Frenchy Digital cost bands: discovery/audit $9k–$22k; single-platform build $28k–$70k; multi-platform (caregiver app + family portal + agency dashboard) $70k–$180k; enterprise/multi-state build $180k–$420k+.

    What EVV Actually Requires, and Why a Home Health App Can't Skip It

    Most vertical app development guides start with the workflow — scheduling, notes, communication — and treat compliance as a section near the end. A home health or senior care app has to be built the other way around, because one requirement sits underneath almost every other design decision: Electronic Visit Verification, a federal mandate that determines how your app has to capture, timestamp, and transmit the fact that a caregiver actually showed up.

    EVV requires that any Medicaid-funded personal care service or home health service visit be electronically confirmed — not written on a paper timesheet and reconciled later — with six specific pieces of information attached to every visit before it can be billed. Get this wrong, or bolt it on as an afterthought, and an otherwise well-built app produces claim denials, compliance findings, and caregivers who quietly work around a system that doesn't function in the actual conditions of a home visit.

    The one fact worth internalizing before any wireframe:EVV isn't a feature you add to a home health app. For any agency billing Medicaid, it's the specification your entire visit-logging architecture has to satisfy — and the specification is different from state to state underneath a federally fixed core.

    The Federal Mandate: the Cures Act's Deadlines and Where Enforcement Stands

    The mandate itself is old enough to be settled law, not a live dispute: Section 12006(a) of the 21st Century Cures Act, signed into law in December 2016, required states to implement EVV for all Medicaid personal care services (PCS) by January 1, 2020, and for home health care services (HHCS) by January 1, 2023. Both deadlines have passed, and the federal mandate is now fully operational nationwide — every state has some EVV system in force for both service categories.

    States that failed to make a documented "good faith effort" toward compliance, without "unavoidable delays" excusing the gap, faced a reduction in their federal medical assistance percentage (FMAP) of up to 1% — a real financial penalty that pushed even slow-moving states to stand up some form of EVV rather than accept the funding cut. What's shifted more recently, and what agencies building or buying software in 2026 are actually navigating day to day, is enforcement posture rather than the underlying mandate: several states have moved from "soft edits," where a visit record with a minor data error still gets paid, to "hard edits," where the same error triggers an automatic claim denial. We're naming this enforcement-tightening trend as reported by industry compliance vendors rather than as a verified national policy, since it varies by state and by specific edit rule — confirm your own state's current edit posture directly with your state Medicaid agency or aggregator rather than assuming a uniform national shift.

    The practical upshot for anyone scoping an app: "EVV is required" has been true and settled since 2023. "How strictly a specific data gap gets penalized" is the part actively getting stricter in 2026, which raises the cost of a sloppy implementation even where the mandate itself hasn't changed.

    The Six Data Elements Every Visit Record Must Capture

    The Cures Act fixes six data elements at the federal level, and every EVV-compliant visit record has to include all six before it can be submitted: the type of service performed, the individual receiving the service, the individual providing the service, the date of the service, the location where the service was delivered, and the time the service begins and ends.

    • Type of service: Which specific service was delivered — personal care, home health aide services, skilled nursing, and so on, mapped to the codes your state's Medicaid program recognizes.
    • Individual receiving the service: The Medicaid recipient — captured through a client ID that ties back to their eligibility record, not just a name your app stores locally.
    • Individual providing the service: The specific caregiver, authenticated at check-in through whatever method your state accepts (see the verification-methods section below), not just whoever's account is logged in on the device.
    • Date of the service: The calendar date, which sounds trivial until you're reconciling a visit that started before and ended after midnight.
    • Location of the service: Where the visit happened — typically the client's address, verified against GPS or another accepted method rather than simply typed in by the caregiver.
    • Time the service begins and ends: Timestamped check-in and check-out, which is what actually determines the billable duration of the visit.

    States implement the technical details of each element differently — how location gets verified, what format the timestamp takes, which service-type code set applies — but none can legally drop an element from the requirement. Any app claiming EVV compliance that's missing one of the six, or capturing it inconsistently, is not actually compliant regardless of how polished the rest of the product is.

    Open Model vs. Closed Model: What It Means for Your App's Architecture

    The single most consequential early decision in scoping a home health app isn't a technology choice — it's confirming which EVV model your state runs, because it determines whether a custom app can be your system of record at all.

    Closed modelOpen model
    Who chooses the EVV systemThe state, for all providersEach individual provider agency
    Can a custom-built app be the system of recordNo — it must feed data into the state's mandated systemYes, if it meets the state aggregator's data and transmission spec
    Integration burdenLower for the provider (the state's system is fixed), but less flexibility to match your workflowHigher for the provider (you build or buy an aggregator-compliant system), but full flexibility over UX and workflow
    Typical fit for a custom appA companion app for scheduling, care notes, and family communication that separately reports required visit data to the state systemA single caregiver-facing app that is both the operational tool and the EVV system of record

    In a closed-model state, the state itself selects a single EVV system — either a state-run platform or one state-designated vendor — that every provider must use, directly or through integration. A custom-built app in that environment is still worth building for scheduling, care documentation, payroll, and family communication, but it has to be architected to feed required visit data into the state's mandated system rather than to serve as the EVV record of truth on its own. In an open-model state, providers can choose their own EVV solution — a custom app, a purchased platform, or a hybrid — as long as it transmits the required data to the state's designated aggregator in that aggregator's specified format. Confirm your specific state's model before a single line of architecture gets written; it changes what "done" looks like for the entire build.

    Integrating With a State Aggregator: the Sandata / Open EVV Pattern

    Sandatais the largest state-aggregator vendor in this space and, notably, chose to operate as an open-model-friendly aggregator rather than a closed one — a design decision that gives provider agencies interoperability with third-party systems instead of locking them into Sandata's own front-end. States using Sandata's Open EVV Series of Interfaces accept visit data as JSON submissions over secure FTP or a REST API, which is the concrete technical target a custom-built caregiver app needs to hit: your app's backend has to assemble each visit's six data elements into the exact schema Sandata's Real Time Interface expects, authenticate the submission correctly, and handle the acknowledgment or rejection response the aggregator sends back.

    Other states designate different aggregators or run state-built systems entirely, each with its own submission format, authentication scheme, and error-handling behavior — there is no single national API a custom app can integrate against once and expect to work everywhere. If your agency operates across multiple states, budget for a genuinely separate integration effort per state's aggregator, not a single integration with minor per-state configuration on top.

    A rejected submission from a state aggregator is not a minor error to log and move past — in a hard-edit enforcement environment, an unresolved rejection is a visit that won't get paid. Build your integration to surface rejection reasons clearly to an agency's back-office staff, not just to your own engineering team's logs.

    GPS, Telephony, and Biometric Check-In: Choosing a Verification Method

    States generally accept some combination of three verification methods, and the right choice for a given visit depends on connectivity, caregiver setting, and the specific fraud-risk profile of the caseload — not a single default every visit should use.

    MethodBest forWeaknessRecommendation
    GPS check-in/outReliable connectivity, urban/suburban visitsFails in dead zones; the method drawing the most privacy and political pushback in 2026Base method — pair with a fallback, don't rely on it alone
    Telephony (landline/registered number call)Rural visits, clients without reliable client-side connectivity, live-in or family caregiver settingsNo location precision beyond the phone number's registered address; less useful for mobile caregivers visiting multiple homesStrongest fallback for connectivity dead zones
    Biometric check-in (fingerprint/face match)Fraud-risk caseloads, agencies with documented identity-verification concernsAdds device/hardware requirements; raises its own privacy considerations, especially amid active 'Cures 2.0'-adjacent debate over biometrics in EVV specificallyHighest assurance, highest sensitivity — confirm your state accepts it before building around it

    The practical pattern we build toward: GPS as the default for caregivers visiting multiple client homes with reliable connectivity, telephony as an automatic fallback the app triggers when GPS or network signal isn't available, and biometric check-in reserved for caseloads or agencies where a state accepts it and a documented fraud-risk justifies the added sensitivity. Relying on GPS as the sole method is both weaker engineering — it produces missing visit records in exactly the low-signal areas where home health visits are common — and, as the next section covers, the specific method drawing the most political and disability-rights scrutiny in 2026.

    Why Offline-First Isn't Optional for a Caregiver-Facing App

    A caregiver's phone losing signal inside a client's home doesn't excuse the visit from EVV requirements — it just means your app's architecture has to handle the gap instead of failing at exactly the moment it matters most. The correct pattern queues the visit record locally the instant it's captured (check-in time, check-out time, GPS coordinates if available, any care notes) and treats the on-device record as the source of truth until a background sync confirms it reached your backend and, from there, the state aggregator.

    This is a genuinely different engineering discipline from a typical connected mobile app, with its own failure modes — conflict resolution when a device syncs a batch of records after being offline for days, ensuring a caregiver can't accidentally submit the same visit twice once connectivity returns, and giving the caregiver clear on-device confirmation that a record queued successfully even with zero bars of signal. We cover the general architecture — local-first data models, sync engines, and the tradeoffs between rolling your own and using an existing sync framework — in detail in our offline-first mobile architecture guide; treat it as required reading before scoping a caregiver app's data layer, not optional background.

    The Privacy Backlash: GPS Surveillance, Live-In Caregivers, and 'Cures 2.0'

    EVV's location-tracking requirement has drawn sustained criticism from disability-rights advocates, and it's worth building with that criticism in mind rather than treating GPS check-in as a purely technical, uncontested requirement. The Center for Democracy & Technologyhas argued that EVV's geographic tracking threatens the privacy and dignity of both the disabled people receiving care and the professional caregivers providing it, since the same GPS data that verifies a visit also creates a detailed, ongoing location record of activity inside a private home.

    That tension surfaced concretely in Ohio's 2026 legislative session, where House Bill 795 proposed extending standard GPS-based EVV to previously-exempt live-in caregivers — family members or others who reside with the person they care for full-time. Opponents argued, in testimony before the state's House Medicaid Committee, that tracking a caregiver who never leaves the home produces no fraud-prevention signal EVV is meant to catch, while extending location surveillance into a private residence where a family lives, sleeps, and (in the specific framing used in that testimony) worships. Whatever the ultimate outcome in a given state's legislature, the underlying disagreement — whether GPS-based verification is a proportionate fraud safeguard or a surveillance overreach into family caregiving specifically — is unresolved and worth designing around rather than dismissing.

    "Cures 2.0" comes up constantly in industry commentary on this topic, and it's worth being precise about what that phrase actually refers to: the original Cures 2.0 Act was introduced in the 117th Congress as H.R. 6000in 2021 and did not become law. What people mean by "EVV after Cures 2.0" today is an unresolved policy conversation, not a change already in effect — one line of proposals in that conversation would prohibit geographic tracking and biometric data collection within Medicaid EVV systems specifically on privacy grounds, while a separate line pushes toward more consistent national technical standards, including biometric identity confirmation, to address visit-verification fraud. Neither direction is current law. Build against your state's actual current requirements, and revisit this section's premise periodically rather than assuming it's settled.

    A Design Implication Worth Taking Seriously

    If your app's UX or marketing frames GPS tracking as purely a fraud-prevention feature with no acknowledgment of the caregiver or family's privacy interest, you're building into a live political fight, not a settled requirement. A caregiver-facing app that's transparent about what's tracked, why, and for how long it's retained — and that supports the least-invasive verification method a given state actually accepts, rather than defaulting to the most data-hungry one — will age better as this debate continues to move.

    HIPAA, 42 CFR Part 2, and the Behavioral Health Carve-Out

    A home health or senior care app handling protected health information for a HIPAA-covered agency needs the standard control set: encryption in transit and at rest, role-based access control, comprehensive audit logging of who accessed which patient's data and when, and a signed Business Associate Agreement between your development team or platform and the agency if you're building as a vendor rather than as the agency's own internal team.

    One layer specific to this vertical is worth knowing before it surprises a build: behavioral health and substance-use-disorder services often need meaningfully different handling than standard personal-care visits, because 42 CFR Part 2's confidentiality protections for substance-use-disorder treatment records are stricter than HIPAA's general rule and don't automatically authorize the same location and visit data sharing with a state Medicaid aggregator that a standard EVV submission assumes. A number of states exclude behavioral health visits from standard EVV data flows, or route them through separate, more restrictive handling, for exactly this reason. If any part of your caseload touches behavioral health or substance-use treatment, confirm your specific state's carve-out directly rather than assuming one data pipeline correctly serves your entire caseload — this is a common gap between an app that's "HIPAA compliant" in the general sense and one that's correctly compliant for this specific service category.

    Buy vs. Build: Platform Vendors vs. a Custom EVV-Compliant App

    Established home care platforms — AlayaCare, WellSky Personal Care, HHAeXchange, AxisCare, MatrixCare, and several others in the same space — already bundle scheduling, EVV, billing, payroll, and caregiver management into one system, and for an agency whose workflow fits a fairly standard shape, buying is very often the right call. Building a custom app makes sense when your care model genuinely doesn't fit that standard shape — a specialized clinical protocol, a distinctive family-communication or care-coordination workflow a generic platform can't replicate, or integration with proprietary remote-monitoring or medical-device hardware — or when the app itself is the product you intend to sell to other agencies rather than internal tooling for your own.

    Pricing across the established platforms varies enormously and is rarely published directly by the vendors themselves. Third-party comparison sites have reported figures from roughly $99 a month at the low end to enterprise implementations with $20,000 to $400,000 in setup fees alone, and one comparison cited AlayaCare specifically at around $1,650 a month plus a $5,000 one-time fee — we're naming these as third-party-reported figures rather than independently verified list prices, since none of the major vendors in this category publish a public rate card, and actual pricing depends on caseload size, module selection, and negotiated terms you'd only get from a direct quote.

    A middle path worth considering seriously: buy an established platform for the back-office functions (billing, payroll, HR) where a generic, mature system genuinely is better than anything worth building from scratch, and build a custom caregiver-facing mobile app only for the specific visit-verification and care-documentation workflow where your agency's actual field conditions — connectivity, caseload type, verification method mix — don't fit what a one-size-fits-all platform assumes.

    A Worked Scenario: A 40-Caregiver Agency Weighing a Custom App

    Consider, as an illustrative scenario rather than a claimed client outcome, a personal care agency with 40 caregivers serving a mixed Medicaid and private-pay caseload across one open-model state, currently on a generic scheduling app with no built-in EVV and a separate, manual process for submitting visit data to the state's Sandata aggregator.

    The agency's actual pain isn't scheduling — it's that manual EVV submission, done by two back-office staff re-keying visit data from paper and app-exported spreadsheets, produces enough transcription errors and late submissions to generate real claim-denial volume every month, on top of the staff time itself. A single-platform custom build in the $28,000–$70,000 band — a caregiver app with GPS check-in, telephony fallback for the agency's several rural clients, offline queuing, and a direct API integration to the state's Sandata aggregator — replaces both the manual re-keying step and the current app's gaps in one build. Worked arithmetic on the actual tradeoff: if two staff members currently spend a combined 15 hours a week on manual EVV data entry and denial follow-up at a fully loaded cost of roughly $35/hour, that's roughly $27,000 a year in labor cost alone, before counting the revenue actually lost to denied claims that never get corrected and resubmitted — a build in the $28k–$70k range pays for itself inside two to three years on the labor savings alone, before any reduction in claim denials is counted, which is exactly the kind of arithmetic worth doing with your own numbers before committing to either a platform subscription or a custom build.

    Common Mistakes We See in Home Health App Builds

    MistakeWhy it matters
    Building only GPS-based check-in with no offline queue or telephony fallbackA caregiver in a signal dead zone produces no visit record at all, which is exactly the failure states' 2026 'hard edit' enforcement shift is built to catch and deny payment for.
    Assuming EVV requirements are federally uniform beyond the six data elementsThe six elements are fixed; the model (open/closed), aggregator, accepted verification methods, and behavioral-health carve-outs are all set state by state. A build scoped against one state's spec can fail another state's requirements outright.
    Treating 'Cures 2.0' coverage in industry blogs as describing current lawIt's an unenacted 2021–2022 bill that never passed, referenced today mainly as shorthand for an ongoing policy debate. Confirm your state's actual current requirements, not a federal proposal.
    Skipping a Business Associate Agreement because 'the app vendor isn't a covered entity'If your app touches protected health information on behalf of a HIPAA-covered home health or personal-care agency, you are very likely a business associate under HIPAA regardless of how the commercial relationship is framed, and need a BAA in place before handling real patient data.
    Quoting a home care platform's price from a third-party comparison site as the price you'll payMost established vendors in this space don't publish pricing; third-party figures are estimates from sales conversations, not list prices. Get a direct quote before budgeting around any number, including the ones in this guide.

    What This Costs, and Its Limits

    EngagementPriceTimelineScope
    Discovery + compliance audit$9k–$22k2–4 weeksMap your state's EVV model, aggregator, and data requirements against your current workflow
    Single-platform caregiver app$28k–$70k4–9 weeksVisit check-in/out with GPS and telephony fallback, offline queuing, and aggregator integration for one state
    Multi-platform build$70k–$180k9–16 weeksCaregiver mobile app, family/client portal, and agency-facing scheduling and billing dashboard
    Enterprise / multi-state build$180k–$420k+14–24 weeksHIPAA-audited architecture, multiple state aggregator integrations, documented compliance posture across payer types

    Limitations of this guide, stated plainly.EVV requirements are set and enforced state by state on top of a fixed federal core, and several of the specific claims here — the 2026 shift toward "hard edit" enforcement, the exact current status of Ohio's HB 795, and third-party-reported platform pricing — are drawn from industry commentary and vendor comparison sites rather than a single authoritative national source, because no such single source exists for state-by-state EVV implementation detail. We named every place a figure or claim came from a secondary or vendor source rather than a state Medicaid agency directly. Confirm your own state's current EVV model, aggregator, and accepted verification methods directly with your state Medicaid agency before finalizing any build's technical scope — this guide is a map of the terrain, not a substitute for your specific state's current published requirements. Nothing here is legal advice; a qualified healthcare compliance attorney should review your specific data flows before you handle real patient information.

    If you're weighing a custom build against an established platform, the same logic from our healthcare and HIPAA app development guide generally applies: understanding your specific compliance surface before any code gets written is worth doing carefully, and the engineering work that follows — a correctly architected offline-first sync layer, a state aggregator integration that surfaces rejections clearly, and privacy-transparent handling of location and biometric data — is where a team that has built this before earns its fee.

    Get Your EVV Compliance Path Scoped Before You Build

    Book a free 60-minute discovery call with Frenchy Digital, a senior-led Black-owned Los Angeles agency. We map your state's EVV model and aggregator requirements against your workflow and send a written, fixed-price phased proposal within 5 business days.

    1517 S Bentley Ave Apt 204, Los Angeles CA 90025

    Frequently Asked Questions

    Sources & References

    1. 1Medicaid.gov — Electronic Visit Verification (EVV) Guidance and Resources↗
    2. 2Congress.gov — 21st Century Cures Act, Public Law 114-255, Section 12006↗
    3. 3Sandata — EVV Services and the Open EVV Series of Interfaces↗
    4. 4Washington State DSHS — Electronic Visit Verification (state EVV program page)↗
    5. 5Illinois Department of Healthcare and Family Services — Electronic Visit Verification (EVV)↗
    6. 6Ohio Department of Medicaid — Electronic Visit Verification↗
    7. 7California Department of Developmental Services — Electronic Visit Verification (EVV)↗
    8. 8Center for Democracy & Technology — EVV Threatens Disabled People's Privacy and Dignity, Whether We Need Care or Work as Professional Caregivers↗
    9. 9Ohio General Assembly — Opposition Testimony on HB 795 (SHIELD Act), House Medicaid Committee↗
    10. 10Congress.gov — Cures 2.0 Act, H.R. 6000, 117th Congress (2021–2022), Bill Text↗
    11. 11U.S. Department of Health & Human Services — 42 CFR Part 2, Confidentiality of Substance Use Disorder Patient Records↗
    12. 12HHS.gov — HIPAA for Professionals, Business Associate Agreements↗
    13. 13AxisCare — The Best Home Care Software for Agencies in 2026↗
    14. 14Alora Health — Top 8 Best Home Care Software in 2026↗
    15. 15SelectHub — WellSky Personal Care vs. AlayaCare Comparison, 2026↗
    16. 16Home Health Care News — Why Eliminating GPS From EVV Could Cost Millions, Force a 'Massive' Step Backward↗
    17. 17New York State Department of Health — Electronic Visit Verification Program Guidelines and Requirements (PDF)↗
    18. 18Arizona AHCCCS — Open EVV / Alt-EVV Program Guidance (PDF)↗
    19. 19California Department of Health Care Services — EVV Implementation, CCS Program Notice (PDF)↗
    Chris Machetto - CEO & Founder of Frenchy Digital

    Chris Machetto

    CEO & Founder of Frenchy Digital, a senior-led Black-owned Los Angeles agency building custom mobile apps and the compliance architecture behind them.