At 7:15 on a weekday morning a home health nurse loads a tablet, a printed route sheet with six names and six addresses, and a folder of signed orders into the passenger seat of a Honda. The Honda stops for coffee. The tablet stays on the seat. That car is now a branch office of a covered entity.
The HHS Office for Civil Rights (OCR) has priced this failure before. Its enforcement listing shows a $3 million settlement over a failure to encrypt mobile devices (November 2019) and a $1,040,000 settlement over an unencrypted stolen laptop (July 2020). Neither entity was a home health agency. The failure they paid for, protected health information on a device that left the building, is the one home health agencies live with every shift.
This guide covers why HIPAA applies to a home health agency, what protected health information looks like in a living room, the violations that show up in field-based care, how to build the program, and which vendors need a Business Associate Agreement.
HIPAA for Home Health Agencies: Why the Rules Follow the Visit
Why HIPAA Applies to a Home Health Agency
The test is in the definitions at 45 CFR 160.103. A covered entity includes "a health care provider who transmits any health information in electronic form in connection with a transaction covered by this subchapter." The covered transactions are listed in the same section, and the first one on the list is "health care claims or equivalent encounter information."
Every Medicare-certified home health agency submits claims to Medicare electronically. That is the transaction. That makes the agency a covered entity, subject to the Privacy Rule, the Security Rule, and the Breach Notification Rule in full. Medicaid billing, Medicare Advantage billing, and electronic eligibility checks each trigger the same result on their own. A private-duty agency that is truly private-pay-only has to run the test honestly: one electronic claim, one electronic eligibility inquiry, or one electronic prior authorization request, and the agency is covered. More on the definition is in what is a covered entity under HIPAA.
One more definition matters here. 160.103 defines workforce as "employees, volunteers, trainees, and other persons whose conduct, in the performance of work for a covered entity or business associate, is under the direct control of such covered entity or business associate, whether or not they are paid." A per-visit aide, a contract therapist, and a nurse placed by a staffing company are all workforce while the agency directs their work. The agency owns their training, their access, and their mistakes.
What P.H.I. Looks Like in Home Health
P.H.I. (Protected Health Information) is individually identifiable health information in any form: electronic, paper, or spoken. In a home health agency it lives in places a hospital never has to think about.
- OASIS assessments. The Outcome and Assessment Information Set is the standardized assessment Medicare-certified agencies complete and submit to CMS at start of care, resumption of care, follow-up, transfer, and discharge. CMS lists the OASIS-E2 instrument as effective April 1, 2026. Every OASIS is a dense P.H.I. record: diagnoses, functional status, medications, living situation, and caregiver details.
- Plans of care and physician orders. The plan of care, face-to-face documentation, and interim orders, which still arrive by fax and sit in a tray until someone scans them.
- Visit notes and wound photos. Point-of-care documentation, and wound photographs that end up in a clinician's personal camera roll when the agency app is slow.
- Electronic Visit Verification (EVV) records. Clock-in and clock-out data tied to a patient's home address, which state Medicaid programs require for Medicaid-funded home health and personal care visits. A patient's street address is one of the 18 identifiers, so an EVV log is P.H.I. even without a diagnosis attached.
- Route sheets and schedules. A printed daily schedule is a list of names, addresses, and visit types, and a breach waiting for a broken car window.
- The home folder. The aide care plan, medication list, and visit log kept in the patient's home, readable by anyone who opens it.
Common Violations in Home Health Settings
Unencrypted devices in vehicles. The two settlements above are the pattern: a device holding ePHI (electronic P.H.I.) leaves the office, is lost or stolen, and was not encrypted. Encryption is an Addressable specification under 45 CFR 164.312(a)(2)(iv), and "addressable" means the agency must implement it or document why an equivalent measure is more reasonable. For a fleet of tablets that ride in cars, there is no equivalent measure. Full-disk encryption plus remote wipe is the baseline, and the day-one response when a device goes missing is in the lost device incident guide.
Texting between aides and schedulers. "Mrs. R fell again, BP 88/50, going to ER" sent by standard SMS from a personal phone is a disclosure over an unsecured channel, stored on two carriers and two handsets the agency does not control. The rules and the workable alternatives are in the HIPAA texting guide.
The daughter in the kitchen. 45 CFR 164.510(b) permits disclosure to "a family member, other relative, or a close personal friend of the individual" of the information "directly relevant to such person's involvement with the individual's health care," when the patient agrees, does not object after being given the chance, or when the clinician "reasonably infers from the circumstances" that the patient does not object. The violation is skipping the chance to object: discussing the wound or the prognosis in front of whoever is home without asking the patient first.
Shared logins and dead accounts. Home health turnover is high, and access removal lags. 164.312(a)(2)(i) requires a unique user ID for every person, and 164.308(a)(3)(ii)(C) calls for procedures to terminate access when employment ends. An aide who left in March and can still open the scheduling app in June is an open door. A same-day access-removal checklist belongs in the termination procedure.
Missing Business Associate Agreements. The EVV vendor, the outsourced coder, the cloud fax service, and the IT company that manages the tablets all handle P.H.I. on the agency's behalf. Each is a business associate under 160.103, and each needs a B.A.A. (Business Associate Agreement) before the first byte moves.
Building the Program
Start with a risk analysis that includes the cars. 45 CFR 164.308(a)(1)(ii)(A) requires "an accurate and thorough assessment of the potential risks and vulnerabilities to the confidentiality, integrity, and availability of electronic protected health information." For a home health agency, "accurate and thorough" means the analysis lists the tablets, the personal phones that run the EVV app, the home Wi-Fi networks clinicians connect through, and the paper that travels. An analysis that only covers the office server is not accurate. The method is in the risk assessment guide.
Write the field into the policies. The workstation use standard at 164.310(b) requires policies covering "the physical attributes of the surroundings of a specific workstation or class of workstation." The class of workstation here is "tablet in a vehicle or a patient's home." The device and media controls standard at 164.310(d) governs "the receipt and removal of hardware and electronic media that contain electronic protected health information into and out of a facility." The policy should say: encrypted device, carried in or locked in the trunk, never on a seat; no paper P.H.I. left in a vehicle overnight; wound photos only in the agency app; personal phones only with mobile device management installed. The remote-work version of the same rules is in HIPAA remote work rules.
Train the aide before the first visit. The Privacy Rule at 164.530(b)(2)(i)(B) requires training for each new workforce member "within a reasonable period of time after the person joins," and the Security Rule at 164.308(a)(5) requires a security awareness program for the whole workforce, "including management." For home health, training has to be concrete: what to say when a relative asks a question, where the route sheet goes, what to do in the first hour after a tablet disappears. Document who was trained, on what, and when, and keep that record for six years per 164.530(j)(2).
Plan for the EHR being down in the field. 164.308(a)(7) requires a contingency plan with data backup, disaster recovery, and emergency mode operation plans. In home health, emergency mode means clinicians keep visiting while the system is unreachable, so downtime visit forms belong in every bag. The plan has five components, and all three Required ones have to be written down.
Vendor B.A.A. Checklist for Home Health Agencies
The business associate definition at 160.103 covers any person who, on the agency's behalf, "creates, receives, maintains, or transmits protected health information" for a regulated function, "including claims processing or administration ... billing, benefit management, practice management." The agency's obligation, under 164.308(b) and 164.502(e), is a written contract before the vendor touches P.H.I.
| Vendor category | Typical examples | B.A.A. required? |
|---|---|---|
| Agency management and EHR platform | Homecare Homebase, WellSky, Axxess, MatrixCare | Yes |
| EVV vendor | HHAeXchange, Sandata, or the EVV module inside the EHR | Yes. A state Medicaid aggregator is a government function; confirm the arrangement with the state program. |
| Outsourced coding, OASIS review, or billing | Any third-party coding or revenue cycle firm | Yes. Billing services are named in the definition. |
| Clearinghouse | The claims clearinghouse between the agency and payers | Yes. A covered entity may be a business associate of another covered entity (160.103). |
| Cloud fax and secure messaging | Any e-fax or clinician messaging service | Yes |
| IT managed services and device management | The MSP that images and manages the tablets | Yes |
| Answering service or after-hours triage line | Any service that takes patient calls for the agency | Yes |
| Shredding and record storage | Any document destruction or off-site storage company | Yes |
| Staffing agency | Nurse and aide staffing firms | Depends. A placed clinician under the agency's direct control is workforce. A firm that keeps its own patient assignment records is a business associate. Decide, then document. |
| Referring hospital, physician, DME supplier, pharmacy | Providers the agency exchanges information with for treatment | No. 160.103 excludes "a health care provider, with respect to disclosures by a covered entity to the health care provider concerning the treatment of the individual." |
| Route or mileage app | Any navigation or mileage tracker | Only if patient names or addresses are entered into it. If so, yes, or stop entering them. |
The agreement itself must carry the terms in 164.504(e)(2) and 164.314(a)(2), including breach reporting and return or destruction of P.H.I. at termination.
The Proposed Security Rule Update (Proposed, Not Final)
HHS published a Notice of Proposed Rulemaking on January 6, 2025 that would rewrite much of the Security Rule. As of this writing it is proposed, not final, and OCR is not enforcing it. The proposal would make encryption and multifactor authentication required rather than addressable, add a written asset inventory and network map, require restoration of critical systems within 72 hours, and require automated vulnerability scans "at least once every six months." The current status and the practical read is in HIPAA Security Rule delayed to 2027.
For a home health agency the useful part is the asset inventory. An agency that cannot list every tablet and phone holding ePHI cannot do the risk analysis the current rule already requires. Build the inventory now, and the proposed rule becomes a formality if it lands.
---
FAQ
Are home health agencies covered entities under HIPAA?
Yes, if the agency transmits any health information electronically in connection with a covered transaction such as a claim. Every Medicare-certified agency bills electronically, so every Medicare-certified agency is a covered entity under 45 CFR 160.103. A private-pay agency must apply the same test to its own transactions.
Can a home health nurse discuss the patient's condition with family members in the home?
Yes, within limits. 45 CFR 164.510(b) permits disclosure to family or close friends of information directly relevant to their involvement in the patient's care, when the patient agrees, does not object after being given the opportunity, or when the clinician reasonably infers no objection. The patient gets the chance to say no first.
Do home health aides need HIPAA training?
Yes. Aides are workforce members under 160.103, and 164.530(b) requires training within a reasonable period after joining, with documentation retained for six years. The Security Rule at 164.308(a)(5) separately requires security awareness training for the entire workforce.
Can aides and schedulers text about patients?
Not by standard SMS on personal phones. Patient details sent that way sit unencrypted on carriers and handsets the agency does not control. Use a secure messaging tool covered by a Business Associate Agreement, and write the rule into policy.
Does a home health agency need a BAA with its EVV vendor?
Yes. An EVV vendor receives and maintains patient names, addresses, and visit data on the agency's behalf, which makes it a business associate under 160.103. A written contract meeting 164.504(e) and 164.314(a) is required before the vendor handles that data.
Conclusion
A home health agency does not need a hospital-sized program. It needs a risk analysis that includes the cars, a device rule everyone follows, and a vendor list with a signed B.A.A. behind every name. One Guy Consulting's Full-Scope plan covers the risk analysis, the policy set, workforce training, and B.A.A. tracking for agencies of any size. Start with a free 30-minute compliance review. No obligation, no pressure.
Sources
- 45 CFR 160.103 (definitions: covered entity, business associate, workforce)
- 45 CFR 164.308 (administrative safeguards)
- 45 CFR 164.310 (physical safeguards)
- 45 CFR 164.312 (technical safeguards)
- 45 CFR 164.510 (involvement in the individual's care)
- 45 CFR 164.530 (administrative requirements: training, documentation)
- CMS: OASIS Data Sets
- HHS OCR: Resolution Agreements and Civil Money Penalties
- Federal Register: HIPAA Security Rule NPRM (January 6, 2025)
Related Reading