Back to the Compliance Toolkit
GuideAll states

Electronic Visit Verification (EVV) Readiness Guide

What EVV is, the six data elements federal law requires you to capture, and a step-by-step path to getting your agency compliant and your claims clean.

11 min readUpdated June 5, 2026

Electronic Visit Verification (EVV) is a federal requirement, not a vendor product. Under the 21st Century Cures Act, state Medicaid programs must require EVV for Medicaid-funded personal care services and home health care services. States that don't enforce it face reduced federal funding, which is why every state now has an EVV program, even though the details differ.

This guide covers what's federally fixed, what varies by state, and how to get ready.

What EVV must capture: the six data elements

Federal law requires every EVV-verified visit to electronically capture six things:

  1. Type of service performed
  2. Individual receiving the service
  3. Date of the service
  4. Location of service delivery
  5. Individual providing the service
  6. Time the service begins and ends

If any of the six is missing or can't be verified, the visit isn't compliant, and the claim built on it is at risk.

What's federal vs. what's up to your state

Federal (the same everywhere): the mandate itself, the six data elements, and the services covered (personal care and home health).

State-specific (confirm yours): the EVV model your state uses, whether you must use the state's chosen system or may bring your own compliant system, accepted verification methods (mobile GPS, telephony, fixed device), how manual edits and exceptions are handled, and the reason codes you must use. Always confirm these with your state Medicaid agency.

EVV models states choose from

  • State Mandated In-House, you must use the system the state provides.
  • State Mandated External Vendor, the state contracts a single vendor everyone uses.
  • Provider Choice / Open Model, you may use any system that meets the state's requirements and submits data to the state aggregator.
  • MCO Choice, managed care organizations select the system for their networks.

A step-by-step readiness path

Step 1, Confirm scope

Identify exactly which of your services are subject to EVV in your state. Personal care and home health are federally required; some states extend EVV to additional waiver services.

Step 2, Confirm your state's model

Find out whether you must use a state system, an MCO system, or may use your own compliant system. This determines everything downstream.

Step 3, Choose verification methods that fit real life

Mobile GPS is the most common, but plan for the field: spotty rural connectivity, members without smartphones, and shared living settings. Make sure your method has an offline mode and a clean exception process.

Step 4, Train DSPs on clock-in/clock-out discipline

The most common EVV failures are human: forgetting to clock in, clocking in from the wrong location, or fixing it later without a reason. Train staff to verify at the point of care, every time.

Step 5, Build a manual-edit policy

Edits will happen. Define who may edit, what reason codes are valid, and how every edit is logged. Unexplained edits are an audit magnet.

Step 6, Reconcile EVV to claims before you bill

No claim should go out without a matching verified visit. Reconcile daily or weekly so you catch missing or unmatched visits while they're still fixable.

Common pitfalls

  • Treating EVV as a payroll tool instead of a billing-integrity tool.
  • Letting clock-in/out drift from the actual service time.
  • High volumes of manual edits with vague or missing reasons.
  • No reconciliation step, so EVV gaps surface only at audit.
  • Choosing a system that can't operate offline in the field.

This guide provides general, federal/CMS-level information about EVV and is not legal advice. EVV models, accepted verification methods, covered services, and edit rules vary by state and may differ across managed care organizations, verify the specific requirements of your state Medicaid agency before acting.

See how Cura OS handles this automatically

Cura OS builds these safeguards into everyday workflows, so compliance is a byproduct of doing the work, not a separate scramble.