Compliance
Audit-ready by default.
An append-only record of who did what, reason codes on manual entries, reports you can export, and access limited by role. The evidence is there before anyone asks for it.
Audit trail
A record that can't be rewritten.
Every access to client and visit data is recorded by the platform, not left to anyone's memory. Entries are added and never changed.
Append-only, enforced by the database
Edits and deletions are blocked in the database itself, for everyone, including Garnet staff.
Who, what, and when
Each entry records the person, the action, the record it touched, the time, and the network address.
Retained six years
Kept for six years and exportable when you need it.
Audit log
- 10:51 AM
Garnet · Platform
Visit accepted by the aggregator
- 10:44 AM
Garnet · Platform
Transmitted the corrected visit to the aggregator
- 10:42 AM
S. Patel · Supervisor
Edited clock-out time on a visit for E. Johnson
Reason: caregiver did not clock out - 10:40 AM
S. Patel · Supervisor
Viewed client record for E. Johnson
Entries are never edited or removed · retained six years
Manual entries
Every exception to the rule has a reason.
When a visit can't be captured the usual way, the entry carries your state's approved reason code and the caregiver's attestation.
Your state's reason codes
Choose from the codes your state approves, such as a mobile device issue or a client who wasn't available.
Notes where the state requires them
Some codes need a written explanation. Garnet won't save the entry without one.
Every change logged
Each manual entry is recorded with who made it and what changed.
Built for the obligations HIPAA places on you.
Compliance takes policies and training too, so we won't hand you a badge. These are the specific safeguards Garnet provides.
Roles and access
| Admin | Supervisor | Caregiver | |
|---|---|---|---|
| Agency settings | |||
| All visits and clients | |||
| Own visits and assigned clients |
Role-based access
Everyone sees only what their role requires.
Administrators, supervisors, and caregivers have separate permissions. Caregivers see only their own visits and assigned clients.
Reporting
Reports you can hand to an auditor.
Eight standard visit and compliance reports, each exportable as CSV.
Visit exports
The Full Visit Export and Visit Log, for billing and payroll from verified data.
Verification status
Detail Visit Status and Visit Verification Activity show where each visit stands.
How visits were verified
The EVV Compliance and Capture Methodology reports show how visits were captured: by GPS, manually, or otherwise.
Late, missed, and no-show visits
The Late & Missed Visit Detail and No Show reports surface visits that didn't happen as scheduled.
Authorizations
Visits stay inside what's authorized.
Each authorization is tracked with its units, dates, service code, and payer, so the schedule knows what's left.
Warned before it runs out
An authorization ending within seven days, or with 90% of its units used, is flagged.
Stopped before it's exceeded
A shift that needs more units than remain, or has no active authorization, can't be scheduled.
Questions about compliance.
More of Garnet.
See it with your state in mind.
We'll walk you through visit capture, transmission, and the exception queue, and answer your compliance lead's questions directly.
Garnet is invite-only. Every agency starts here.