Ohio guides · glossary

The Ohio IDD glossary, with sources.

Every term an Ohio DODD provider meets on a shift, in a billing close or in a county-board email, defined in plain English with the rule or state page it comes from. Where Enmantle uses the term on a screen, we say so.

What is an ISP (individual service plan)?

An ISP, or individual service plan, is the written, person-centered plan describing the services, supports and activities a person with a developmental disability is authorized to receive, along with the outcomes those services aim to achieve. Ohio requires the person's service and support administrator to build it with the person's own participation, identify at least one outcome to reach within twelve months, and update the plan as circumstances change. Every team member, including the person's providers, must receive a copy at least fifteen days before it takes effect. The ISP also gates payment: a service must be named on an approved ISP before a claim for it can be reimbursed.

In Enmantle: Enmantle reads a standard Ohio DODD ISP PDF and drafts the client record — goals, authorizations and contacts — for review, in Import a client from an Ohio ISP PDF.

Source: OAC 5123-4-02 — Service and support administration

What is HPC (homemaker/personal care)?

HPC, or homemaker/personal care, is the core Ohio waiver service combining hands-on personal care, daily-living-skills training, health-related supports and community-access help so a person can keep living in their own or their family's home rather than a facility. It runs under the Individual Options and Level One waivers and bills in fifteen-minute units based on the actual minutes of support a worker provides, advancing goals like self-advocacy, emergency-response skills and community access along the way. Because HPC is meant to cover routine, hands-on support, Ohio's billing rules treat it as mutually exclusive with residential respite, adult day support, and employment or vocational habilitation services for the same hours, and it excludes time already billed as a transportation trip.

In Enmantle: HPC is a platform-managed rate-table service family, and the shift type staff log a trip against, in Logging HPC transportation vs. NMT.

Source: OAC 5123-9-30 — Homemaker/personal care under the individual options and level one waivers

What is participant-directed HPC?

Participant-directed HPC is the same homemaker/personal care service — personal care, daily-living-skills training, therapeutic support and community access — delivered under Ohio's participant-direction model, where the person receiving services, or their representative, acts as the employer of record for the worker instead of an agency. It is available under the Individual Options, Level One and SELF waivers, and it carries its own on-site/on-call provision for overnight coverage, written in parallel with the agency version of the rule. Choosing participant direction shifts hiring, scheduling and supervision responsibilities onto the person or their family, in exchange for more control over who provides the support and how it is delivered day to day.

Source: OAC 5123-9-32 — Participant-directed homemaker/personal care

What is ADS (adult day support)?

ADS, or adult day support, is a waiver service of regularly scheduled, non-residential activities that build or maintain a person's self-help, socialization and adaptive skills and support their participation in community life. It runs under the Individual Options, Level One and SELF waivers and bills either as a fifteen-minute unit or, when one provider delivers five to seven hours of in-person support to a single person in a calendar day, as a daily unit. ADS is meant to build skills and community connection during the day, which is why Ohio's billing rules generally treat it as mutually exclusive with HPC for the same hours rather than something delivered alongside it.

In Enmantle: ADS appears as its own rate-table family, ADS / VocHab, in Cost centers, rate tables, and the code library.

Source: OAC 5123-9-17 — Adult day support under the individual options, level one and self-empowered life funding waivers

What is NMT (non-medical transportation)?

NMT, or non-medical transportation, is a waiver service that gets a person to and from employment, adult day support, career planning, employment support, vocational habilitation, volunteer work, post-secondary education or an internship, using a personal or commercial vehicle or a county-board-purchased pass, token or voucher. It bills per trip between the person's residence and one of those specific destinations, or per mile for other qualifying routes. An HPC worker who also drives the person on a covered trip can bill NMT separately from the HPC visit itself, which is exactly why Ohio expects agencies to keep the two services, and their documentation, apart rather than folding one into the other.

In Enmantle: NMT is a distinct Trip Purpose, billed per trip or per mile, in the shift-based transportation log described in Logging HPC transportation vs. NMT.

Source: OAC 5123-9-18 — Non-medical transportation under the individual options, level one and self-empowered life funding waivers

What is HPC transportation?

HPC transportation is the everyday community-access transportation Ohio's waiver rule authorizes in addition to, not instead of, medical or state-plan transportation: the trips a support worker makes with the person to reach community activities and resources generally, rather than a specific destination like a job or day program. The Ohio Administrative Code rule that governs it is titled simply "Transportation," and it prices the trip per person, with the rate varying by the number of riders and whether a modified vehicle is used. It bills separately from the HPC visit itself and separately from non-medical transportation, whose covered destinations are limited to employment- and day-program-related trips.

In Enmantle: HPC transportation is one of two Trip Purpose choices, alongside NMT, in the shift's transportation log, described in Logging HPC transportation vs. NMT.

Source: OAC 5123-9-24 — Transportation under the individual options, level one and self-empowered life funding waivers

What is OSOC (on-site on-call)?

OSOC, or on-site on-call, is a reduced overnight billing rate for hours when a worker stays at the person's home but no active support is expected, because the person is asleep for at least five continuous hours; the worker must remain available to respond if something unexpected happens, without being required to stay awake. Ohio caps OSOC at eight hours in a twenty-four-hour period and excludes it from add-on rates for behavioral support, complex care or staff competency. If the person actually needs supervision or support during that window, the provider switches to, documents and bills the regular HPC rate for that portion of the shift instead.

In Enmantle: a location's On-Site On-Call toggle automatically splits an overnight shift into Regular and On-Call segments at the start and end times you set, in Creating locations and On-Site On-Call (OSOC).

Source: OAC 5123-9-30 — Homemaker/personal care under the individual options and level one waivers

What is a UI (unusual incident)?

A UI, or unusual incident, is an event involving a person with a developmental disability that does not follow routine operations, agency policy or the person's individual service plan, but does not rise to the level of a major unusual incident. Ohio requires every agency to keep a written UI policy, log each occurrence with its causes and a prevention plan, and review the log at least monthly, noting months with none to report. Unlike an MUI, a UI is handled inside the agency: staff report it to a designated person within twenty-four hours, and the provider investigates and closes it internally rather than filing it with the county board.

In Enmantle: staff file a UI through the same three-step incident wizard used for MUIs, in Report an incident: the 3-step wizard.

Source: OAC 5123-17-02 — Major unusual incidents and unusual incidents

What is an MUI (major unusual incident)?

An MUI, or major unusual incident, is the alleged, suspected or actual occurrence of one of the specific incidents Ohio's rule lists, sorted into Category A, B or C, whenever there is reason to believe it happened; proof is not required to trigger reporting. Depending on the category, the county board must be told as soon as possible, and for the incidents on the rule's four-hour list, within four hours of discovery. Every MUI's written incident report is due to the county board by 3 p.m. on the first working day after the provider becomes aware of it, and a certified county-board investigative agent then leads the administrative investigation.

In Enmantle: the incident wizard classifies a report as an MUI, assigns its category and type, and tracks it against its deadline in the review queue, per Report an incident: the 3-step wizard.

Source: OAC 5123-17-02 — Major unusual incidents and unusual incidents

What are MUI Categories A, B and C?

MUI Categories A, B and C are the three groups Ohio sorts a major unusual incident into, and the category decides who investigates and how fast. Category A covers abuse (emotional, physical, sexual), exploitation, neglect, misappropriation, a rights-code violation, failure to report, and an unexplained or unanticipated death. Category B covers medical emergencies, significant injury, attempted suicide, a missing individual, death by natural cause, and peer-to-peer acts. Category C covers law-enforcement involvement, an unanticipated hospitalization of forty-eight hours or more, and an unapproved behavioral support, meaning a restrictive or prohibited measure used without the required approval. Category A and B incidents get an administrative investigation; Category C gets an administrative review.

In Enmantle: choosing MUI (Major) on the incident wizard's Incident level control reveals the MUI category (A, B or C) and MUI type fields, per Report an incident: the 3-step wizard.

Source: OAC 5123-17-02 — Major unusual incidents and unusual incidents

What is OITMS?

OITMS, the Ohio Incident Tracking and Monitoring System, is the state database county boards use to record and monitor major unusual incidents. Once a provider files its written incident report, the county board enters the preliminary information into OITMS by 5 p.m. on the first working day after learning of the incident, and the assigned investigative agent's closure report is due in the system within forty-five working days of that report unless DODD grants an extension. Because every county board uses the same system, OITMS is also how the state watches for patterns across providers, not just the pattern inside a single agency's own incidents.

Source: OAC 5123-17-02 — Major unusual incidents and unusual incidents

What is an investigative agent?

An investigative agent is the county-board staff member certified to conduct the administrative investigation or review of a major unusual incident. For a Category A incident, the agent's investigation must start within twenty-four hours of the incident report; for Category B, within three working days; a Category C incident gets an administrative review starting within three working days of the review form. For an alleged physical or sexual abuse MUI, the agent works toward a preliminary finding within fourteen working days, or gives a status update every seven working days until reaching one. DODD itself investigates certain incidents instead, such as ones alleging a county board employee's involvement.

Source: OAC 5123-17-02 — Major unusual incidents and unusual incidents

What is a prevention plan?

A prevention plan is the set of actions a provider puts in place after a UI or MUI to reduce the chance the same thing happens again, and it is a required part of closing out either kind of incident. For a UI, the provider investigates the causes and contributing factors itself and documents the resulting prevention plan in its UI log. For an MUI, the county board's closure summary states whether the incident was substantiated and what prevention plan was put in place, and the person's team is expected to address the same risks in their individual service plan. A pattern of MUIs also feeds into the agency's required annual trends analysis, due every February 28.

Source: OAC 5123-17-02 — Major unusual incidents and unusual incidents

What is eMBS?

eMBS is DODD's electronic Medicaid Billing System, the portal where certified DODD providers, or a billing agent acting for them, submit claims for waiver services already authorized for payment in PAWS. DODD processes claims in weekly cycles and posts provider reports in eMBS showing what was paid, denied or adjusted for that cycle. A provider has up to 350 days from the date of service to submit a claim; miss that window and the claim goes unreimbursed, regardless of whether the service was properly authorized and actually delivered. Providers may submit claims themselves or contract a billing agent to submit on their behalf.

In Enmantle: a shift's clock data derives directly into billing rows, which are validated, invoiced and submitted as an eMBS file, in From clock-ins to a clean eMBS invoice.

Source: DODD — Waiver Billing

What is PAWS?

PAWS, the Payment Authorization for Waiver Services system, is where a county board records the services and units it has approved for a person to receive, using the cost projection from Ohio's Medicaid Services System. A DODD claim must match what PAWS has authorized for that person, service, provider and date of service, or it will not be reimbursed. Providers have read-only access to PAWS and are expected to check it before delivering a service, not only before billing for it; county boards separately receive weekly reports flagging claims that were paid without a matching or sufficient PAWS authorization behind them.

In Enmantle: each client's PAWS authorizations and budget lines live on their billing profile, with alerts for expiring, low-unit or stale authorizations, in Authorizations and units: keeping shifts billable.

Source: DODD — Billing and Claims

What is MSS (the Medicaid Services System)?

MSS, the Medicaid Services System, is the DODD application county boards use to project and authorize the cost of a person's waiver services before that authorization ever reaches a claim. Its output feeds both PAWS, which turns the projection into a service authorization providers can bill against, and the Daily Rate Application, which some providers use for daily-billed services. In a shared setting, MSS is also where the cost of homemaker/personal care delivered to more than one person is apportioned across the people who share it, rather than billed as though one person alone received the full cost.

Source: DODD — Medicaid Services System

What is the Daily Rate Application (DRA)?

The Daily Rate Application, or DRA, is the DODD tool providers use to turn a Medicaid Services System cost projection into a daily billing rate for certain waiver services, rather than billing in fifteen-minute units. It is most often used to apportion the cost of homemaker/personal care delivered to more than one Individual Options waiver enrollee sharing a home: each resident's share becomes a Daily Billing Unit, or DBU, so the cost of overnight or shared support is split across the people actually receiving it instead of being billed in full against each person's own authorization.

Source: DODD — Medicaid Services System

What is patient liability?

Patient liability is the portion of the cost of a waiver service that a person is responsible for paying directly, rather than having Medicaid cover in full, based on their own income under the Medicaid patient-liability calculation. When a person pays a provider directly for part of a waiver service, DODD requires the provider to report that patient-liability amount on the claim, rather than billing Medicaid for the full cost and receiving the person's contribution as a separate, unreported payment. Getting this wrong, either by not collecting it or not reporting it, is one of the recurring reasons a DODD claim comes back short-paid or flagged at reconciliation.

Source: DODD — Waiver Billing

What is a DSP (direct support professional)?

A DSP, or direct support professional, is Ohio's regulatory term for a person employed in a "direct services position," meaning a role with the opportunity to be alone with, or to supervise or control, one or more people receiving DODD services. Ohio requires every DSP to be at least eighteen, pass a BCII and, in most cases, an FBI background check, and complete initial and ongoing training, including in-person-assessed CPR and first aid certification, before and while working directly with people. The DSP designation is what triggers most of an agency's individual compliance obligations, from background checks through training and certification tracking, for that worker.

In Enmantle: DSP is a base role, the front-line default for clocking in, working assigned clients, and recording medications, described in Adding a staff member and choosing a role.

Source: OAC 5123-2-08 — Provider certification

What is a county board of developmental disabilities?

A county board of developmental disabilities is the local public agency, a separate administrative and service entity rather than a department of county government, that administers services for people with developmental disabilities in its county. Ohio law has each board run or arrange early-childhood and adult services, coordinate and monitor the services people receive, arrange for special education, ensure every eligible person has a service and support administrator, and carry out the state's employment-first policy. Every Ohio county has one, with seven members appointed by the county commissioners and probate judge, and it is the body a DODD provider reports incidents to and often bills alongside for waiver services.

In Enmantle: filed UI and MUI reports are sent to the county board, and the required annual trends analysis is generated for it, in Review, file, and track UIs/MUIs as an admin.

Source: ORC Chapter 5126 — County boards of developmental disabilities

What is an SSA (service and support administrator)?

An SSA, or service and support administrator, is the county-board employee responsible for a person's case: establishing their eligibility for county-board services, assessing their needs, developing their individual service plan with their own and their providers' input, setting their budget, helping them choose providers, and monitoring whether the plan is actually being carried out. An SSA also has to feed incident trends and outcomes back into plan changes over time, rather than treating the ISP as a document written once and filed away. Ohio law bars an SSA from also providing developmental disabilities services for another entity, or working independently as a provider, while employed by a board.

In Enmantle: an imported ISP's contacts include the person's SSA, drafted automatically in Import a client from an Ohio ISP PDF.

Source: ORC 5126.15 — Service and support administration

What is the IO waiver (Individual Options)?

The IO waiver, or Individual Options waiver, is one of Ohio's home-and-community-based Medicaid waivers for people with developmental disabilities, funded through an individualized budget calculated over a twelve-month period from the services a person is authorized to use, rather than a single fixed dollar cap. It covers a broad range of services, including some, like shared living, nutrition consultation and interpreter services, that are not available under Ohio's other DODD waivers, and it supports self-direction, letting a person manage a budget or act as employer of their own workers. It is the waiver most DODD agencies serve the largest share of their caseload under.

In Enmantle: Individual Options (IO) is one of the authorization programs on a client's billing profile, in Authorizations and units: keeping shifts billable.

Source: OAC 5123-9-06 — Home and community-based services waivers

What is the Level One waiver?

The Level One waiver is one of Ohio's DODD Medicaid waivers, distinguished from the Individual Options waiver mainly by its funding cap: Ohio sets an annual spending limit per waiver-eligibility span, currently $62,136 for an adult and $41,424 for a child. It covers most of the same day-to-day services as the IO waiver, plus clinical and therapeutic intervention, functional behavioral assessment, and participant-directed goods and services that the IO waiver does not list. Because its budget is capped rather than individualized, Level One is generally the fit for people whose assessed needs sit within that ceiling rather than exceed it.

In Enmantle: Level One (LV1) and Level One Emergency are authorization program choices on a client's billing profile, in Authorizations and units: keeping shifts billable.

Source: OAC 5123-9-06 — Home and community-based services waivers

What is the SELF waiver?

The SELF waiver, or Self-Empowered Life Funding waiver, is a Medicaid home-and-community-based services waiver built around self-direction: an enrollee, or their guardian, exercises budget authority, employer authority, or both, managing a dollar budget for self-directed services and, under employer authority, acting as the common-law or co-employer of their own direct support workers. It serves adults twenty-two and older, along with younger people no longer eligible for educational services, and enrollment requires the person or their guardian to be willing and able to carry out self-direction duties for at least one waiver service themselves, rather than delegating everything to an agency.

In Enmantle: SELF Waiver is one of the authorization programs on a client's billing profile, in Authorizations and units: keeping shifts billable.

Source: OAC 5123-9-40 — Self-empowered life funding waiver

What is an ICF/IID?

An ICF/IID, or intermediate care facility for individuals with intellectual disabilities, is a licensed, facility-based residential setting that provides comprehensive health care and active treatment, meaning sustained, coordinated training and health services aimed at functional independence, rather than the in-home support model of a waiver or supported living. It is an optional Medicaid benefit that every state, Ohio included, has chosen to offer, and unlike an HCBS waiver, a state cannot place someone who needs and is eligible for ICF/IID care on a waiting list. It is the facility-based alternative to Ohio's waivers and to supported living for the same population, distinguished mainly by where and how care is delivered.

Source: Medicaid.gov — Intermediate Care Facilities for Individuals with Intellectual Disability

What is EVV (electronic visit verification)?

EVV, or electronic visit verification, is the electronic capture of six facts about a home- or community-based Medicaid visit: the service, the person who received it, the date, the location, the worker who provided it, and the time it started and ended. The federal 21st Century Cures Act requires every state Medicaid program to use EVV for personal care and home health services, and Ohio's program has applied it to DODD waiver services since 2018. The point is simple: the visit billed to Medicaid has to be the visit that actually happened, and a clean, time-stamped EVV record protects a provider as much as it protects the payer.

In Enmantle: GPS is captured at exactly two moments, clock-in and clock-out, and nowhere in between, as described in Clocking in and out with GPS: what's captured, and when.

Source: Ohio Department of Medicaid — Electronic Visit Verification

What is an alternate EVV vendor?

An alternate EVV vendor is a software system, other than the state-provided Sandata application, that captures a visit in its own app and sends the required EVV data to Sandata, Ohio's aggregator, on the provider's behalf. Any DODD or other Ohio Medicaid provider may choose one instead of the state system, but the vendor has to meet the Ohio Department of Medicaid's technical specifications, pass certification testing with Sandata, and complete a demonstration with ODM before it can be used. The provider using it still has to notify ODM, complete alternate-system training, and take responsibility for the accuracy of the visit data the vendor sends.

In Enmantle: Enmantle is a DODD-approved alternate EVV vendor that submits directly to Sandata, as described in EVV readiness for a client.

Source: OAC 5160-32-03 — Alternate EVV vendor

What is Sandata (the EVV aggregator)?

Sandata is the company Ohio Medicaid contracts as its EVV aggregator, the system every DODD provider's visit data ends up in, whether it was captured in the state-provided Sandata app or sent over from an alternate EVV vendor. The aggregator stores each visit, checks it for the required data elements, and confirms that a submitted claim is actually supported by verified visit data before that claim can be paid. Because the same aggregator and the same claims checks apply across every Ohio Medicaid program that uses EVV, a DODD agency's visit data is held to the same standard as any other home-care provider's.

In Enmantle: once a client's EVV readiness checklist passes, their visits transmit to Sandata, described in EVV readiness for a client.

Source: Ohio Department of Medicaid — Electronic Visit Verification

What are the six EVV data elements?

The six EVV data elements are the facts Ohio's EVV rule requires every visit to capture: the type of service performed, the individual who received it, the date of service, the location where it was delivered, the worker who provided it, and the time the service began and ended. Location is recorded as "home" or "community" at both the start and the end of the visit, not as a raw GPS coordinate, and it can differ between the two if the visit moved. A visit missing one of these six has an incomplete record, which is exactly the kind of gap that turns into an EVV exception once billing tries to use it.

Source: OAC 5160-32-02 — EVV data collection

What is ODM 10375?

ODM 10375 is the Ohio Department of Medicaid's recommended consent form for using GPS to capture the location element of an EVV visit; a provider may use its own form instead as long as it collects the same information. Ohio's EVV rule allows GPS only with the signed, annually renewed consent of the person receiving the service, requires the provider to keep a copy, and lets the person revoke that consent at any time. Without an active consent on file, GPS cannot be turned on for that person's visits, and the location element has to be captured some other way, such as a home-or-community selection at clock-in and clock-out.

In Enmantle: a client's GPS consent (ODM-10375) is one of the four checks on the EVV readiness checklist, tracked with its expiration in EVV readiness for a client.

Source: OAC 5160-32-02 — EVV data collection

What is the live-in caregiver exemption?

The live-in caregiver exemption is an exception to Ohio's EVV requirement for a worker who lives in the same home as the person they support, once the Ohio Department of Medicaid has approved the exemption for that arrangement. Because the worker is already present in the home rather than traveling to and from a separate visit, the usual visit-by-visit location and time capture that EVV requires does not fit the same way, which is why the rule treats it as a distinct, approval-gated exception rather than a blanket carve-out. As Ohio's 2026 Medicaid fraud-prevention proposals move forward, this exemption is one of the areas providers have been told to expect to narrow.

Source: OAC 5160-32-01 — EVV program: services subject to EVV

What is claims matching (claims validation)?

Claims matching, or claims validation, is the check Ohio's EVV aggregator runs before a claim for an EVV-subject service can be paid: it confirms that the submitted claim is actually supported by a verified visit record carrying all of its required data elements. A claim billed for more units than the verified visit supports, billed before the visit verified, or tied to a visit that later loses its verification will not be substantiated for payment until the mismatch is resolved. Ohio Medicaid has committed to telling providers at least three months before it starts denying claims or applying penalties on EVV grounds, but an unresolved mismatch simply sits unpaid in the meantime.

In Enmantle: the EVV Status dashboard reconciles verified visits against billed rows and lists unit mismatches and "not verified but billed" claims before they reach eMBS, in Reading the EVV Status & Compliance dashboard.

Source: OAC 5160-32-02 — EVV data collection

What is an EVV exception?

An EVV exception is what Ohio's EVV rule calls a visit record that is missing a required data element or otherwise fails to match what claims matching expects, for example a visit with no verified location, or a claim billed for more units than the visit supports. A claim tied to an unresolved exception cannot be substantiated for payment, so the exception has to be cleared, by correcting the visit data or the claim, before that service can be paid. Exceptions sit behind nearly every EVV-related denial: the aggregator does not reject a claim outright so much as withhold confirmation until the underlying visit record is put right.

In Enmantle: unit mismatches and post-lock de-verifications, Enmantle's terms for an unresolved EVV exception, are worked from the same dashboard described in Reading the EVV Status & Compliance dashboard.

Source: OAC 5160-32-02 — EVV data collection

What is the 21st Century Cures Act?

The 21st Century Cures Act is the federal law, enacted in December 2016, whose Section 12006 requires every state Medicaid program to implement electronic visit verification for personal care services, and later for home health services, or face a reduction in federal Medicaid matching funds. It is the reason EVV exists nationally at all: before it, whether and how to verify a home visit was left entirely to each state. Ohio's own EVV program, and the rules built on top of it, including the aggregator, the six data elements, and alternate vendors, all exist to satisfy this one federal mandate.

Source: 21st Century Cures Act, Section 12006

What is a MAR (eMAR)?

A MAR, or Medication Administration Record, kept as an eMAR when it is electronic, is the record Ohio requires for every dose of prescribed medication or treatment a developmental disabilities worker administers: the person's name and allergies, the date, the drug or treatment, its dose, frequency and route, and the scheduled time, along with whether it was actually given, missed, held or declined. Ohio requires the certified staff member giving the dose to sign or initial the entry with the date and time, and only a licensed nurse or certified developmental disabilities staff may transcribe or verify what was recorded. A MAR left blank for a scheduled dose is treated as an incomplete record, not a harmless gap.

In Enmantle: the eMAR module keeps every dose timed and audited, and prints a monthly MAR, in Turning on the Medications (eMAR) module.

Source: OAC 5123-6-07 — General provisions and compliance for medication administration

What is a PRN medication?

A PRN medication is one given as needed rather than on a fixed schedule, and Ohio's rule specifically forbids developmental disabilities personnel from administering one unless the prescriber's order sets out the exact parameters for when to give it, the condition, dose and timing limits, so the worker is following the order rather than exercising independent clinical judgment about when it is warranted. Because a PRN dose is not scheduled, each time one is given is its own separate record rather than a single recurring entry, and the reason for giving it has to be documented alongside the dose itself.

In Enmantle: each PRN dose is recorded with its Reason * and an optional effectiveness follow-up, in PRNs, refusals, missed doses, and reading the MAR.

Source: OAC 5123-6-06 — Qualifications, training, and certification of developmental disabilities personnel

What are BCII and FBI background checks?

BCII and FBI background checks are the two criminal-records checks Ohio requires before someone can work in a "direct services position" with a DODD provider, a role with the opportunity to be alone with, or to supervise or control, a person receiving services. Ohio's Bureau of Criminal Identification and Investigation, or BCII, check is required for every applicant; an FBI check is also mandatory unless the applicant can show five continuous years of Ohio residency, in which case the provider may decide whether to require it anyway. Both checks must be refreshed at least once every five years for as long as the person stays in a direct services role.

In Enmantle: BCII Criminal Background Check and FBI Background Check are certification types with a five-year default expiry, tracked in Adding and tracking your certifications.

Source: OAC 5123-2-02 — Background investigations for employment

What is Rapback?

Rapback is Ohio's retained-applicant-fingerprint program, run by the state attorney general, that keeps monitoring a person's fingerprints against new criminal-record activity after their initial background check instead of relying on a single point-in-time result. DODD's background-check rule requires a provider to enroll every direct-services employee in Rapback within fourteen calendar days of receiving their background-check results or their hire date, whichever is later, and to keep that enrollment active for as long as the person works in that role. Because Rapback runs continuously, it is meant to surface a new arrest or conviction between an employee's scheduled five-year rechecks, not only at the recheck itself.

In Enmantle: Rapback Enrollment is a certification type that never expires, tracked alongside background checks in Adding and tracking your certifications.

Source: OAC 5123-2-02 — Background investigations for employment

What is CPR/First Aid certification?

CPR/First Aid certification is the Ohio requirement that a direct support professional hold a current American Red Cross certification, or an equivalent, in both cardiopulmonary resuscitation and first aid, earned through a course that includes an in-person skills assessment rather than an online-only class. The in-person requirement exists because CPR and first aid are physical skills: Ohio does not treat a certificate from a course with no hands-on evaluation as meeting the standard for someone who may need to respond to a real emergency alone with the person they support. Like other DSP credentials, it has to stay current for as long as the person works in a direct services role, not only at hire.

In Enmantle: CPR & First Aid is a certification type with a two-year default expiry, tracked with color-coded status in Adding and tracking your certifications.

Source: OAC 5123-2-08 — Provider certification

What is annual training (DSP training requirements)?

Annual training is the yearly refresher Ohio requires on top of a direct support professional's initial training, covering the topics DODD's provider-certification rule sets out for continued certification. An agency's director of operations has to complete the rule's specified training before initial certification and again every year after, and the same expectation of ongoing, dated training runs down through the DSPs an agency employs and supervises. Because this training requirement sits inside the same rule that certifies an agency to operate at all, letting it lapse for enough staff becomes a compliance problem for the agency's own certification, not only for an individual worker's record.

In Enmantle: Annual Training is a certification type, defaulting to the end of the following year, that flips a staff member to non_compliant if it lapses, in Monitoring team compliance and certification expiry.

Source: OAC 5123-2-08 — Provider certification

What is provider certification?

Provider certification is DODD's approval to bill Medicaid for a waiver service, issued under two different rules depending on how the provider is organized. An agency provider, an entity employing at least one person besides its director of operations, must hold a Medicaid provider agreement, show at least $10,000 in financial capacity, carry $1 million in general liability insurance, name a qualified director of operations, and run an internal compliance program. An independent provider, a self-employed person with no employees, is certified under a separate rule requiring a background check, Rapback enrollment, a high school diploma or equivalent, and a bar on serving their own spouse, minor child, or a person in their guardianship, absent a court-approved family exception.

In Enmantle: an onboarding task can be tagged with the DODD rule it satisfies, for example OAC 5123-2-08, in Building onboarding templates.

Source: OAC 5123-2-08 — Provider certification

What is the abuser registry?

The abuser registry is the list DODD maintains of people found to have abused or neglected a person with a developmental disability or misappropriated their property, and a person placed on it cannot be employed in a developmental-disabilities direct services position. Ohio law makes the registry a public record, open to inspection and copying like any other public record, and requires an employer to check it before hiring anyone into such a role. It sits alongside, but is legally distinct from, a background check: a clean criminal-record check does not mean someone is not on the abuser registry, so an agency has to check both before hiring.

Source: ORC 5123.52 — Abuser registry

What is remote support (remote supports)?

Remote support, also called remote supports, is a waiver service that replaces or supplements in-person staffing with continuous technology monitoring, such as motion sensors, RFID, or live two-way video or audio, plus staff at a monitoring base who are immediately available to respond to the person's assessed needs while they are at home, without necessarily watching a live video feed the whole time. Ohio requires every remote-support arrangement to have a designated backup support person or entity, whether an unpaid family member or friend or a paid HPC agency under written agreement, who can physically respond in person if there is an emergency, an equipment failure, or a need the technology cannot meet.

Source: OAC 5123-9-35 — Remote support under the individual options, level one and self-empowered life funding waivers

What is shared living?

Shared living is an Individual Options waiver service for an adult whose day-to-day personal care and support is provided, at least twenty percent of the time, by one or more adult caregivers who live in the same home as the person. It bills as a daily rate, priced by the person's support-need profile, the county's cost-of-doing-business category, the provider type, and how many people share the home, and it excludes room, board, comfort items, and the caregiver's own household upkeep. A person who would otherwise qualify for shared living can choose HPC instead if they need two-to-one staffing, awake overnight staff, or meet behavioral-support or complex-care criteria that shared living is not built for.

In Enmantle: Shared Living is one of Enmantle's platform-managed rate-table service families, alongside HPC and ADS, in Cost centers, rate tables, and the code library.

Source: OAC 5123-9-33 — Shared living under the individual options waiver

What is residential respite?

Residential respite is a waiver service that gives a person short-term care away from their usual caregiver, specifically because that caregiver is absent or needs relief, rather than as an ongoing arrangement. It bills as a daily unit for a stay of more than seven hours in twenty-four with an overnight stay, or, only for someone already in a shared-living arrangement, as a fifteen-minute unit on a day their shared-living caregiver also bills. Ohio treats it as mutually exclusive with HPC, participant-directed HPC and shared living on the same day, since its purpose is to substitute for a person's routine support rather than add to it.

Source: OAC 5123-9-34 — Residential respite under the individual options, level one and self-empowered life funding waivers

What is supported living?

Supported living is a certified service model, defined in Ohio law, where a provider delivers up to twenty-four hours a day of support, housing help, professional services and habilitation so a person can live in a home of their own choosing, alone, with people without a developmental disability, or with no more than three other people who do, unless related. It is funded through public and private resources, including the person's own money, and a provider must hold a supported-living certificate from DODD to deliver it. It differs from shared living, an IO-waiver service billed by the day to a live-in caregiver, and from an ICF/IID, which is facility-based rather than built around a home the person chose.

Source: ORC 5126.01 — Definitions

What is community transition?

Community transition is a one-time Individual Options waiver benefit that reimburses the non-recurring costs of setting up a household for someone who has lived in an ICF/IID or a nursing facility for at least ninety days and is moving into IO waiver enrollment. It covers costs like a security deposit, essential furnishings, utility connection fees, moving expenses, pre-transition trips to set up the new home, and initial cleaning supplies, but not groceries, ongoing rent or utilities, entertainment, tobacco or alcohol. Ohio caps the benefit at $2,000 per person over their lifetime, with pre-transition transportation separately capped at $500 within that total.

Source: OAC 5123-9-48 — Community transition under the individual options waiver

What is free choice of provider?

Free choice of provider is the Medicaid principle that a person eligible for services can get them from any qualified, willing provider rather than one the state assigns to them. States can set this requirement aside for specific populations through a Section 1915(b) "freedom of choice" waiver, the mechanism that lets a state require Medicaid managed-care enrollees to use a specific network of plans and providers instead of any willing one. Home-and-community-based waivers like Ohio's IO, Level One and SELF waivers sit alongside this principle rather than overriding it: a person on one of those waivers still generally chooses among the providers certified to deliver their authorized services.

Source: Medicaid.gov — Managed Care Authorities

What is a human rights committee?

A human rights committee is a standing committee a county board or intermediate care facility forms to safeguard the rights of the people it serves and protect them from physical, emotional and psychological harm. Ohio requires a human rights committee to approve any behavior-support strategy that involves a restrictive measure before that measure can be used, with a streamlined process available for a genuine emergency. Because a restrictive measure used without the required human rights committee approval turns an internally managed situation into a Category C major unusual incident whenever it puts someone's health or welfare at risk, the committee's approval is a real gate, not a formality to document afterward.

Source: OAC 5123-2-06 — Human rights

What are restrictive and prohibited measures?

Restrictive and prohibited measures are two different things under Ohio's rule, even though people often use the words loosely. A restrictive measure, meaning chemical restraint, manual restraint, mechanical restraint, a rights restriction, or a time-out, is a method of last resort Ohio allows only when necessary for someone's safety and only with human rights committee approval in advance. A prohibited measure is never permitted at all: examples include prone restraint, any restraint that restricts breathing or causes pain, disabling a person's communication device, denying food or drink outside narrow exceptions, a room with no light, using pain or shock as punishment, humiliating treatment, or using a restrictive measure for punishment or staff convenience rather than safety.

Source: OAC 5123-2-06 — Human rights

What is a Business Associate Agreement (BAA)?

A Business Associate Agreement, or BAA, is the written contract HIPAA requires between a covered entity, such as an agency delivering health care, and a business associate that performs a function involving protected health information on its behalf, such as a software vendor. Since 2013, federal rules make a business associate directly liable for complying with specific HIPAA privacy, security and breach-notification requirements, not only contractually bound to the covered entity that hired it; before that change, HIPAA's obligations ran mainly through covered entities themselves. A BAA sets out what the business associate may do with protected health information, how it protects it, how it reports an incident, and what happens to the data once the relationship ends.

Source: U.S. Department of Health and Human Services — Business associates under HIPAA

What is a passkey (WebAuthn)?

A passkey is a discoverable, phishing-resistant credential built on FIDO standards that lets someone sign in with device biometrics, a PIN or a pattern instead of a password. WebAuthn is the browser standard, finalized by the W3C and FIDO Alliance, that defines how a website creates and verifies these credentials. A passkey is a public-private key pair: the private key stays on the person's device, protected by its biometric sensor, and the website only ever stores the public key, so there is no shared secret for a breach to expose. Every passkey is a WebAuthn credential, but the term specifically means one that is discoverable and backed by user verification, so a username is not needed either.

In Enmantle: staff can turn on Biometric Login to sign in with Face ID or a fingerprint instead of a password, in Signing in with a passkey (Face ID or fingerprint).

Source: FIDO Alliance — Passkeys

What is RBAC (role-based access control)?

RBAC, or role-based access control, is a security model, formalized with NIST's involvement, that grants permissions to a role rather than to each person individually, so a user's access comes from the roles assigned to them rather than a list of permissions attached to their name. Role permissions can inherit through a hierarchy, and roles themselves are built around the functions an organization actually needs performed rather than around any one individual. RBAC became the dominant enterprise access-control model because it is cheaper to administer at scale: changing what a role can do changes access for everyone who holds it, instead of requiring an edit to every individual account.

In Enmantle: every user has a base role plus optional custom access roles that narrow permissions module by module, in Understanding roles and custom access roles.

Source: NIST — Role-based access control (RBAC)

What is an audit log?

An audit log is a chronological record of system activity, who did what, to which record, and when, kept as documentary evidence of specific events rather than as a report anyone can edit. NIST's definition treats it as a record of system accesses and operations over a given period, and the working standard is that it is written once and read many times: an audit log a normal user could alter would defeat its own purpose as evidence of what actually happened. In a regulated setting, an audit log is often what a reviewer or auditor asks for first when a record's accuracy is in question, precisely because it exists independently of the record it explains.

In Enmantle: an admin-only, tenant-scoped audit log records sign-ins and every content or administrative change, searchable by resource and time window, in Using the audit log to trace documentation errors.

Source: NIST — Audit log