Skip to content
Nonprofit Management

The Dangerous Record Is the One That Looks Fine

Matt Angerer·September 10, 2026·13 min read
Written by Matt Angerer

A missing record announces itself — somebody opens a file, finds a blank, and deals with it. The record that causes harm in a health nonprofit is the one that is present, plausible and wrong: a green cell nobody has any reason to question, sitting on top of nothing. Six numbers that fail that way, and what makes each one true instead.

Screen for $5

FCRA-compliant volunteer background checks. No monthly fees.

A missing record announces itself. Somebody opens a file, finds a blank, and deals with it. The record that actually causes harm in a health nonprofit is the one that is present, plausible and wrong — a green cell nobody has any reason to question, sitting on top of nothing.

That is a different failure from the ones the rest of this sector's advice is about, and it needs a different habit. Six numbers that fail this way, why each one looks fine, and what makes it true instead. Every workbook mentioned is free and linked at the bottom.

Read this first. Nothing here is clinical, legal, insurance or compliance advice. VolunteerBadge is not affiliated with the Centers for Medicare & Medicaid Services, any accrediting organization or any state survey agency. And the most useful thing on this page may be the last section: a spreadsheet is a poor container for health information, and where you have a clinical system, that is where patient data belongs.

1. The credential that looks verified

Here is a row from a credentialing file. Nothing about it invites a second look.

Dr. A. Sample State licence #4471902 Expires 2028-06-30 Verified

Five fields, all filled, one of them green.

Now the two fields that would make it true:

Checked at the source on — blank — Checked by — blank —

The licence number came off the application form. Nobody has been to the board’s website.

This is the central distinction in credentialing and it is easy to state: a credential number an applicant supplied is an assertion. It becomes a verification when a named person checks it at the issuing board and records that they did. Primary source verification is the standard precisely because the intermediate steps — a photocopy, a scan, a number typed into a form — are all things a person can produce without the underlying credential being current, or real.

What most trackers record

Credential type, number, expiry date, and a status. Every field the applicant could fill in themselves, plus a status somebody set.

What makes it a verification

Two more columns: checked at the source on, and checked by. And a status that refuses to say verified until both are present — because the question at an audit is never whether the licence was valid. It is who checked, when, and against what.

2. The percentage that says compliant

A Medicare condition of participation requires hospice volunteers to provide day-to-day administrative or direct patient care services amounting to at least 5 percent of the total patient care hours of all paid hospice employees and contract staff. Fundraising and board service do not count toward it.

So a hospice computes a number, and the number says 5.4%, and everyone relaxes. The trouble is that both halves of that fraction are judgment calls, and a spreadsheet showing only the result hides both of them.

The numerator Which volunteer hours count Fundraising and board service are out. Bereavement support is a judgment call your compliance lead makes. A total that silently sweeps in every logged hour is the easiest way to produce a comfortable number that will not survive being asked about.
The denominator Which paid patient care hours belong The half that goes wrong more often, and in BOTH directions — some hospices sweep in paid hours that do not belong, inflating the denominator and understating themselves; others leave out contract staff who do belong, and overstate. Both are honest mistakes and both are visible only if the denominator is shown.
The result A ratio, not a verdict Which is why the workbook we built for this will not print the word “compliant”. At its most positive it says “at or above the required share on these figures”. The figures are yours; the interpretation is your surveyor’s.
The genuinely useful output is not the percentage at all. It is the shortfall in hours — because a hospice that is 118 hours short in July has a recruitment problem with months to solve it, and the same hospice 118 hours short in January has a finding. Same number, entirely different situation, and only one of them is actionable.

3. The figure that was right last year

This is the failure mode of every template that ships a number, and it is worse than an empty cell for one reason: nothing about a stale figure looks stale.

Two examples in this sector, and they behave identically:

  • Poverty guidelines. Issued annually, varying by household size, and different again for Alaska and Hawaii. A sliding fee worksheet downloaded in one year and used in the next quietly applies last year's figures to this year's patients. Every determination is defensible-looking and slightly wrong, in the same direction, for everybody.
  • Vaccination intervals. Set by a veterinarian in one part of the nonprofit world and by state law and occupational health policy in this one — differing by product, by age, by setting. A template supplying one is making a clinical decision at scale for organizations it has never met.

The fix is not to be more careful about updating. It is to make staleness visible. A single field recording which year's figures are in this table converts an invisible error into an obvious one, and costs nothing. Our sliding fee worksheet ships with an empty table and that field on the summary, so an out-of-date table announces itself instead of quietly mispricing every patient who walks in.

4. The safety net nobody is holding

Hospice companions, senior visitors and respite volunteers work alone, in private homes, often with nobody knowing precisely where they are. Plenty of organizations run a check-in log for exactly this, and the log is genuinely worth having.

But a log is not a system, and the difference matters at 8pm on a Thursday.

What the file can do

Record who went where, when they were due back, and compute who is past that. All of it useful, all of it available the moment somebody opens the file.

What it cannot do

Notice. Nothing in a spreadsheet escalates, calls anyone, or wakes anybody up. If a volunteer is overdue, a person has to be looking — which means a named person has to own the check and know they own it.

Which is why the workbook we built has a Settings cell for the name of the person who checks it, and a note calling that the most important cell in the file. If your volunteers routinely visit alone after dark or in unfamiliar settings, the honest recommendation is a lone-worker service that escalates without human attention — and we would rather say so than sell the spreadsheet as more than it is.

5. The access that outlives the volunteer

Onboarding a volunteer always gets done. Somebody wants the help, and there is a person waiting to start.

Offboarding is nobody's job in particular. The volunteer stops coming, there is no moment that forces the question, and six months later the shared drive is reachable by a dozen people who left. Nothing in the record looks wrong — their row is simply old.

The fix is to make the gap refuse to close on its own. Record a leaving date and an access-removed date as two separate fields, and let the status keep reporting ACCESS NOT REMOVED, left 14 March for as long as it takes. It is the only item on this page that is genuinely solved by a nagging cell, because the failure is not that anyone decided wrongly — it is that nobody was ever asked.

6. The field that should not exist

The last one is different in kind: a record that is wrong to have collected accurately.

Volunteer health requirements in a care setting are real — screenings, immunity status, sometimes exemptions. A tracker for them is a reasonable thing to build. The temptation, and it is a strong one because it feels like diligence, is to add a column for the result, or the condition, or the reason for the exemption.

A placement decision needs none of that. It needs to know whether a requirement is met and when it expires. And the general principle is worth stating plainly, because it applies well beyond this one tracker:

Data you collect becomes data you have to protect, retain, disclose correctly and eventually dispose of. A field that exists will be filled in — by somebody being helpful, at the moment it seems easiest — and from then on it is yours to look after. The cheapest privacy control available to any small organization is not a policy. It is declining to create the column.

What to do about all six

Three habits cover most of it, and none of them requires software:

  1. Make the derivation visible. A percentage with its numerator and denominator shown can be checked. A percentage on its own can only be believed. This is the difference between a figure that survives a hard question and one that produces a bad afternoon.
  2. Require the provenance, not the value. For anything verified, the useful columns are who checked and when — and a status that refuses to go green until both exist. The value alone is what the subject told you.
  3. Name the person, not the process. Every control on this page that works has a human attached: the compliance lead who owns the methodology, the coordinator who checks the visit log, the privacy officer who decides where the file lives. A control with no name against it is a hope.

The workbooks

Free, no account, no email gate. Every interval, threshold and requirement is a cell you fill in, and there are deliberately no array formulas anywhere.

All six sit on the health & wellness volunteer toolkit hub.

The thing worth saying last

A spreadsheet is a poor container for health information. It is easy to email, easy to copy, and it does not log who opened it. Where your organization has a clinical or case-management system, that system is the right home for anything identifying a patient — and a company giving away free spreadsheets should be the first to say so rather than the last.

These workbooks are for the jobs that sit outside that system: a volunteer-hours ratio, a credentialing file, an access register, a lone-worker check. Where one of them does touch identifiable information, four decisions are worth making before the file exists rather than after — where it lives, who can open it, how long you keep it, and how it is disposed of. If you store or sync it through a cloud service, that vendor may be a business associate and an agreement may be required. Ask whoever is responsible for privacy at your organization before you type a name.

Where screening fits

None of the six is a screening product. Where our own work is relevant here is narrower and specific: volunteers in this sector are frequently alone with people who are unwell, frail, sedated or cognitively impaired, sometimes in their own homes. That is a setting where identity matters more than usual, and where a name-only check clears a name rather than a person. VolunteerBadge screens volunteers for $5 per adult with photo-ID and biometric verification, and re-screens automatically on a schedule you set. See screening requirements in care settings.

Common questions

What is the hospice volunteer 5% requirement?

A Medicare condition of participation requires hospice volunteers to provide day-to-day administrative or direct patient care services amounting to at least 5 percent of the total patient care hours of all paid hospice employees and contract staff. Fundraising and board service do not count toward it, and the hospice must maintain records of volunteer use including the roles occupied and the time worked. Which hours belong in the numerator and which paid hours in the denominator are questions for your compliance lead and your surveyor rather than for any template.

What is primary source verification?

Confirming a credential directly with the body that issued it — the state board, the certifying body, the registry — rather than relying on a copy, a scan or a number supplied by the applicant. A tracker records that this happened; it never performs it. In practice the useful test is whether your file can answer who checked and on what date, because that is what an audit asks.

Can volunteer health information go in the same file as other volunteer records?

Many organizations keep it separate and visible to fewer people, and that is the safer default. More useful still is to limit what you record at all: a placement decision needs to know whether a requirement is met and when it expires, not the underlying medical detail. What applies to your organization depends on your setting and your state, so confirm it — but declining to create a column you do not need is available to everybody.

Does using a spreadsheet break HIPAA?

Not inherently, and that is the wrong question to organise around. The questions that matter are where the file lives, who can open it, how long you keep it, how it is disposed of, and whether any service you use to store or sync it needs a business associate agreement. A spreadsheet does not log access, which is a real disadvantage compared with a clinical system — so where such a system exists, patient information belongs there. Ask your privacy officer.

How should a small clinic run a sliding fee scale?

Enter the current guideline figures for your state, define your adopted discount tiers as continuous non-overlapping bands, and apply them the same way to every household. Two things prevent the common failures: recording which year's guidelines are in the table so a stale one is visible, and reporting a percentage that falls between bands as an error rather than letting whoever is at the desk decide.

What should a lone-worker check-in log actually do?

Record where each volunteer went, when they were due back, and compute who is overdue. Then accept what it cannot do: nothing in a file notices or escalates. Name the person who checks it and when, and if volunteers routinely visit alone after dark or in unfamiliar settings, use a service that escalates without human attention.

A note on sources

The hospice volunteer requirement reflects the Medicare hospice conditions of participation as published, read in September 2026; conditions and guidance change and your surveyor's and accrediting organization's interpretations govern. Credentialing practice reflects published guidance on primary source verification and periodic re-credentialing for health professionals, including in free clinic settings. Federal poverty guidelines are issued annually and vary by household size and state. VolunteerBadge and ScreenForge Labs, LLC are not affiliated with or endorsed by the Centers for Medicare & Medicaid Services, the Health Resources and Services Administration, any accrediting organization or any state survey agency. This article is not clinical, legal, insurance or compliance advice.

VolunteerBadge

Ready to stop overpaying for background checks?

Full national criminal checks at $5. Free address history. FCRA compliant from day one. No monthly fees, no contracts.

Create Free Account

Legal Disclaimer: The content on this page is for informational purposes only and does not constitute legal advice. VolunteerBadge and ScreenForge Labs, LLC are not law firms and do not provide legal counsel. FCRA requirements and applicable laws vary by jurisdiction and circumstances. For guidance specific to your organization, please consult a qualified attorney.

AI Content Transparency: We use AI tools to assist in the research and drafting of our blog content. That said, the opinions, perspectives, and editorial judgment in every article reflect the author's genuine views and real-world experience. We believe in full transparency about how content is created — because trust matters as much in publishing as it does in background screening.