tags: [workforce, gps, biometrics, hrtech]
A Healthcare Client Asked Us to Prove Their Staff Were Where They Said They Were — Here's How We Did It
The call came on a Tuesday morning. A regional home-care provider — about 140 field staff visiting elderly patients across three counties — had just received notice of a compliance audit. Their state regulator wanted documented proof that caregivers were physically present at patient locations during the hours billed. Not just timesheets. Not just supervisor sign-offs. Verified location data tied to clock-in events.
Their existing system was a mix of paper logs and a basic mobile app that let staff clock in from anywhere. Anywhere. As in, from a parking lot two miles away. From home. From wherever they happened to be when they remembered to tap the button.
Nobody wanted to believe the worst. But the data gap was real, and a compliance failure would mean lost Medicaid contracts. They had about six weeks to show an auditor something defensible.
We'd been through similar deployments before, but this one had specific pressure points that made it more than a technical lift.
First: Understanding What "Proof" Actually Means to a Regulator
Before touching any tooling, we sat with their compliance officer and mapped what the auditor actually needed to see. The answer was a verifiable chain: employee identity → physical location → timestamp → patient visit record.
Each link in that chain had to be tamper-resistant and exportable. Verbal attestations and handwritten logs wouldn't cut it. What they needed was:
- Biometric clock-in — to confirm identity at point of entry (not just a PIN or badge someone else could use)
- GPS geofencing — to enforce that clock-ins only registered within a defined radius of the patient's address
- Immutable audit logs — timestamped, exportable, not editable by field supervisors
This is where the tool selection mattered. We landed on TimeClock 365 because it handled all three natively — biometric verification, GPS geofencing, and full audit trail — within a single platform, rather than stitching together three separate systems that would create data reconciliation headaches under audit.
The Awkward Conversations With Staff
Here's the part nobody writes about in product documentation.
When you tell a workforce that clock-ins will now require a biometric selfie and will only register if they're within 150 meters of the patient's home — you get pushback. Not because people are doing something wrong, but because it feels like surveillance. It feels like you don't trust them.
We recommended the client hold small group briefings, not a single all-hands email. The framing mattered: this is about protecting you as much as the organization. If a patient ever claims a caregiver didn't show up, that GPS-verified clock-in is the caregiver's defense too.
A few staff members flagged real concerns — rural addresses where GPS accuracy degraded, patients in apartment buildings where geofence polygons were tricky to calibrate. Those were legitimate technical issues, not resistance. We adjusted the geofence tolerances in those cases and documented the exceptions with rationale. Audit-ready from day one.
What the Deployment Actually Looked Like
The technical rollout took about two weeks. TimeClock 365's mobile app handled the field staff side — staff downloaded it, completed a one-time facial biometric enrollment, and were live. For the few patients in assisted living facilities with controlled entry points, we configured tighter geofences around the building perimeter rather than a single address point.
On the admin side, we set up:
- Geofence zones for each patient location, configurable per visit type
- Biometric clock-in enforcement — the app wouldn't register a shift start without facial verification
- Real-time alerts for any clock-in attempt outside the geofence, routed to the scheduling team
- Automated shift reports exportable as CSV and PDF for the audit package
The GDPR and ISO 27001 compliance built into TimeClock 365 also mattered here — the client's DPO needed assurance that biometric data wasn't being stored in a way that created a secondary liability.
What the Data Revealed
When the first week of clean data came back, it was mostly good news — the vast majority of staff were exactly where they were supposed to be, when they were supposed to be there.
But there were anomalies. A small number of clock-ins that had previously appeared legitimate showed location mismatches in the historical comparison. Not necessarily fraud — some were explainable by GPS drift, one was a caregiver who had clocked in at a nearby pharmacy during an emergency supply run. But without the data, those edge cases would have been invisible to a regulator, and invisible edge cases become assumed fraud.
Having the data let the client explain each anomaly rather than just assert it didn't happen. That's the difference between a compliance review that ends badly and one that ends with a clean finding.
The auditor closed the review without issue.
The Lesson We Took From This
Workforce verification in field-based care isn't about distrust — it's about building a data layer that protects everyone in the chain. The organizations that struggle with compliance audits aren't usually hiding wrongdoing; they're just running on attestation-based systems in a world that now demands verification-based ones.
If you're managing a distributed or field-based workforce and your time tracking still relies on self-reported data with no location enforcement, it's worth closing that gap before an audit forces you to.
TimeClock 365 offers a free trial — it's worth standing up the geofencing configuration in a test environment to see what your current data gaps actually look like before someone external asks the same question.

Top comments (0)