HIPAA in home health is harder than HIPAA in a clinic. Our clinicians open charts in their cars, in the patient's kitchen, and at home at night. Documentation happens on phones and laptops that leave the building every morning. Patient information rides over cellular networks and the patient's own Wi-Fi. The rules were written for all of health care, but the ways an agency breaks them are specific to the field.
This is the checklist I wish someone had handed me when I started. Every line names the rule it comes from, so you can tell what the regulation requires, what the proposed Security Rule would add, and what is simply good practice.
Three Kinds of Lines on This List
Compliance guides tend to blur these together, and that is how agencies end up calling a habit a law. Each line below is one of three things:
| Label | What it means | Example |
|---|---|---|
| Rule | The current regulation, with the paragraph cited | The risk analysis is required (45 CFR 164.308(a)(1)(ii)(A)) |
| Proposed | In the HIPAA Security Rule proposed on January 6, 2025, not yet final | Multi-factor authentication for every system that holds ePHI |
| Practice | A sensible target with no regulatory number behind it | A 5-minute screen lock on phones |
The current Security Rule also splits its own lines into required and addressable specifications. An addressable safeguard still has to be dealt with: you assess whether it is reasonable and appropriate for your agency, implement it if it is, and document why and what you did instead if it is not. Encryption, automatic logoff and access-termination procedures are all addressable today. The proposed rule would remove that distinction entirely.
What HIPAA Requires: The Quick Version
Three sets of rules apply to a home health agency.
The Privacy Rule
Controls who may see protected health information (PHI) and how it may be used and shared.
- You may use and share PHI for treatment, payment and health care operations without the patient's written authorization (45 CFR 164.506). Most other uses need a valid authorization (164.508).
- Limit PHI to the minimum necessary for the task when you use it, share it, or ask another provider for it (164.502(b)). Treatment disclosures between providers are exempt from that limit.
- Give every patient a Notice of Privacy Practices (164.520).
- Act on a patient's request for their records within 30 days. One extension of up to 30 more days is allowed if you tell the patient in writing why and when (164.524(b)(2)).
- Designate a privacy official and a contact for complaints (164.530(a)).
- Train every member of the workforce on your privacy policies, train new hires within a reasonable period after they join, retrain when a policy materially changes, and document it (164.530(b)).
- Have and apply sanctions for staff who break the rules (164.530(e)), and mitigate the harm from any improper disclosure you learn of (164.530(f)).
- Keep the required documentation for six years from the date it was created or last in effect, whichever is later (164.530(j)(2)).
The Security Rule
Controls how electronic PHI (ePHI) is protected. Field-based agencies carry most of their risk here.
- Conduct an accurate and thorough risk analysis of the risks to the confidentiality, integrity and availability of your ePHI, and implement risk management measures that bring those risks to a reasonable and appropriate level. Both are required (164.308(a)(1)(ii)(A) and (B)).
- Regularly review audit logs, access reports and security incident reports. Required (164.308(a)(1)(ii)(D)).
- Name a security official (164.308(a)(2)). It can be the same person as the privacy official.
- Run a security awareness and training program for the whole workforce, including management (164.308(a)(5)).
- Keep a contingency plan with a data backup plan and a disaster recovery plan, both required (164.308(a)(7)).
- Evaluate your safeguards periodically and whenever your environment changes (164.308(a)(8)).
- Assign every user a unique identifier. Required (164.312(a)(2)(i)).
- Keep audit controls that record and examine activity in systems that hold ePHI (164.312(b)).
- Verify that a person seeking access is who they claim to be (164.312(d)), and guard ePHI in transit over networks (164.312(e)).
- Keep your policies and the records of required actions for six years (164.316(b)(2)(i)).
The Breach Notification Rule
Defines a breach, when encryption spares you from reporting one, and the deadlines. Covered in its own section below.
The Home Health HIPAA Checklist
Administrative safeguards
Policies and people
- Written HIPAA policies and procedures. Rule (164.316(a), 164.530(i)).
- A named privacy official and a complaints contact. Rule (164.530(a)).
- A named security official. Rule (164.308(a)(2)). One person can hold both roles in a small agency.
- A Business Associate Agreement with every vendor that creates, receives, maintains or transmits PHI for you. Rule (164.502(e), 164.308(b), contract terms in 164.504(e)).
- A written incident response and breach procedure. Rule (164.308(a)(6) for security incidents; subpart D for breach notification).
- A sanctions policy that is actually applied. Rule (164.308(a)(1)(ii)(C), 164.530(e)).
Training
- Every new hire trained before they touch PHI, or within a reasonable period after joining. Rule (164.530(b)(2)(i)(B)).
- Retraining when a policy materially changes. Rule (164.530(b)(2)(i)(C)).
- A security awareness program with periodic reminders. Rule, with the reminders addressable (164.308(a)(5)).
- Sign-off sheets or a training log. Rule (164.530(b)(2)(ii)).
- An annual refresher. Practice. The rule does not set a yearly interval, but a year without a reminder is a long time for people who work alone in patients' homes.
- Scenarios from the field, not just slides. Practice. The violations list below is a good start.
Risk analysis
- A documented risk analysis covering every system that touches ePHI, including personal phones under a BYOD policy. Rule (164.308(a)(1)(ii)(A)).
- A remediation plan with owners and dates for each risk found. Rule (164.308(a)(1)(ii)(B)).
- The analysis repeated after any change to your systems and at least yearly. Rule for "periodic" and "in response to environmental or operational changes" (164.308(a)(8)); Proposed for the 12-month interval.
- Analysis and plan retained for six years. Rule (164.316(b)(2)(i)).
If you have never done one, start with the free Security Risk Assessment Tool built by ONC with OCR for small and medium providers. It runs on Windows or as an Excel workbook. OCR's audit report on 2016 and 2017 audits found that most audited entities failed the risk analysis and risk management requirements. It is also the first document OCR requests when it investigates a breach.
Physical safeguards
Devices that leave the office
- Full-disk encryption on every laptop. Rule for the decision (164.312(a)(2)(iv), addressable); Practice for "every". A lost encrypted laptop is not a reportable breach, which is the whole case for "every".
- Device encryption and a screen lock on every phone and tablet that opens a chart. Same basis.
- Automatic lock after inactivity. Rule for having a timeout (164.312(a)(2)(iii), addressable); Practice for 5 minutes on a phone and 15 on a laptop.
- Remote wipe for lost or stolen devices. Practice. It turns a stolen phone into a lost phone.
- Either agency-owned devices or a written BYOD policy that the risk analysis covers. Practice.
- A disposal procedure for old devices and media, so PHI cannot be recovered. Rule (164.310(d)(2)(i), required).
Physical spaces
- Office areas and servers that hold PHI are physically restricted. Rule (164.310(a)).
- Workstations positioned and secured so only authorized users can see them. Rule (164.310(b) and (c)).
- Paper charts in locked cabinets, a shredding policy, and printouts retrieved promptly from shared printers. Rule for the standard of reasonable safeguards (164.530(c)); Practice for the specifics.
Technical safeguards
Access
- A unique login for every user, including per-diem staff and the office temp. Rule (164.312(a)(2)(i), required). Shared logins also destroy your audit trail.
- Role-based access: clinicians see their caseload, not the whole census. Rule (164.308(a)(4) information access management; 164.502(b) minimum necessary).
- An emergency access procedure for when the usual path is down. Rule (164.312(a)(2)(ii), required).
- Access removed when someone leaves. Rule for having a procedure (164.308(a)(3)(ii)(C), addressable); Practice for same-day; Proposed for within one hour of the end of employment.
- Multi-factor authentication on anything that opens a chart from outside the office. Proposed (the draft rule would require it for all systems holding ePHI, with limited exceptions); Practice today, and cheap.
Encryption
- Every web application your staff use for PHI runs over HTTPS. Rule (164.312(e)(1) transmission security); the encryption specification under it is addressable (164.312(e)(2)(ii)), but there is no reasonable argument for plain HTTP in 2026.
- Databases and backups encrypted at rest. Rule for the decision (164.312(a)(2)(iv), addressable); Proposed as required.
- Email that carries PHI is encrypted or replaced by a secure portal. Same basis.
- Staff-to-staff messages about patients go through a secure messaging tool, not plain SMS. Rule for the standard (164.312(e)); Practice for the specific channel.
Audit
- Logs that show who opened which patient's record and when. Rule (164.312(b)).
- Logs reviewed regularly. Rule (164.308(a)(1)(ii)(D)); Practice for a quarterly cadence, plus a look at any clinician who opens charts outside their caseload.
- Log retention set long enough to support an investigation. Practice. The six-year rule in 164.316 covers your policies and documentation, not the raw logs. Set a retention period in your policy and keep it.
The Most Common HIPAA Violations in Home Health
1. Texting PHI on personal phones
"Can you see Mrs. Johnson at 123 Oak Street? She's the diabetic with the wound on her left foot." That text put a name, an address and a diagnosis on an unencrypted channel, on a device that may not be encrypted, with no audit trail.
Fix: use the secure messaging built into your scheduling or documentation platform. If it has none, that is a gap to close.
2. Patient information visible in cars
Printed schedules with names and addresses on the passenger seat. A tablet left logged in. A folder of intake paperwork in the back.
Fix: minimize paper. Keep what you must carry in a locked bag out of sight. A stolen encrypted tablet is a lost device. A stolen folder is a breach.
3. Caseload talk in public
Two clinicians catch up over coffee and anyone at the next table hears a patient's name and diagnosis.
Fix: training with real scenarios. Use initials in public and save the details for a private room or the secure channel.
4. No BAA with a vendor
An agency uses an EHR, a scheduling app, a fax service, cloud storage, a transcription tool and a billing service. Each one that touches PHI needs a signed BAA. The ones that get missed are the small ones: the e-fax account, the AI note tool a clinician signed up for on her own, the IT contractor with admin rights to every laptop.
Fix: list every vendor that could see PHI and check each for a signed BAA. If a vendor will not sign one, they are telling you they will not take on HIPAA's obligations for your patients' data. Find another vendor.
5. No risk analysis
OCR's audits of 2016 and 2017 found that most audited entities failed the risk analysis and risk management requirements, and the Security Rule marks both as required.
Fix: run one with the free SRA Tool, document the findings and the remediation plan, and keep both for six years.
6. Shared logins
"Everyone uses the same login for the scheduling system." Now you cannot tell who looked at what, and you have failed a required specification.
Fix: a unique login for every person. No exceptions, not even for the weekend on-call phone.
What to Do When a Breach Happens
A clinician loses a phone. A laptop is stolen from a car. An OASIS summary goes to the wrong fax number.
First 24 hours
- Contain it. Remote-wipe the device, reset the account, ask the wrong recipient to delete and confirm.
- Document everything. What happened, when, what PHI was involved, how many patients.
- Check whether the data was encrypted. The answer decides whether you have a breach to report at all.
- Tell your privacy official. The clock for notification runs from the day the breach was known, or should have been known with reasonable diligence (164.404(a)(2)).
The encryption safe harbor
A breach is an impermissible use or disclosure of unsecured PHI (164.402). Unsecured means PHI that has not been made unusable, unreadable or indecipherable to unauthorized people by a method HHS has specified. HHS's guidance names two methods: encryption and destruction. For data at rest, that is encryption consistent with NIST Special Publication 800-111. For data in motion, a FIPS 140-2 validated process such as TLS under NIST 800-52. For disposal, destruction consistent with NIST 800-88.
A lost laptop with full-disk encryption and an intact passphrase is a lost laptop. The same laptop without encryption is a reportable breach for every patient on it.
Is it a breach at all?
If the PHI was unsecured, the incident is presumed to be a breach unless you can show a low probability that the PHI was compromised, based on at least four factors: the nature and extent of the PHI, who received it, whether it was actually viewed, and how far the risk has been mitigated (164.402). Document that assessment whichever way it comes out.
Notification deadlines
| Who | When | Rule |
|---|---|---|
| Each affected individual | Without unreasonable delay, no later than 60 calendar days after discovery | 164.404(b) |
| HHS, 500 or more individuals | At the same time as the individual notices | 164.408(b) |
| HHS, fewer than 500 individuals | Logged, then reported within 60 days after the end of the calendar year of discovery | 164.408(c) |
| Prominent media in a state | Only when more than 500 residents of that state or jurisdiction are affected, same 60-day limit | 164.406 |
| You, by a business associate | Your vendor must tell you without unreasonable delay, no later than 60 calendar days after they discover a breach | 164.410 |
Treat 60 days as the outer limit. The standard is "without unreasonable delay", and waiting out the full window with no reason is its own failure.
Afterwards
- Find the root cause and fix it.
- Update the policy and the training that failed.
- Document the investigation and the corrective action, and keep it for six years.
- For larger breaches, consider credit monitoring for the affected patients.
What the Proposed Security Rule Would Change
HHS published a proposed rewrite of the Security Rule on January 6, 2025 (Federal Register document 2024-30983). As of the day this was written, no final rule has been published. Nothing in it is binding yet, and the proposal gives regulated entities 180 days after the final rule's effective date to comply. Agencies that plan a year ahead should know what is in it:
- No more addressable specifications. Every implementation specification would be required, with narrow exceptions.
- Encryption of all ePHI at rest and in transit, with limited exceptions.
- Multi-factor authentication for systems that hold ePHI.
- Access terminated within one hour of a workforce member's employment ending, and other covered entities notified within 24 hours when a shared user's access changes.
- The risk analysis reviewed at least every 12 months, along with a written technology asset inventory and network map.
- A Security Rule compliance audit at least every 12 months.
- Vulnerability scans at least every six months and penetration tests at least annually.
- Critical systems and data restored within 72 hours of a loss.
Most of the lines on this checklist labelled Practice or Proposed would become Rule if the proposal is finalized as written. An agency that does them now has nothing to change later.
HIPAA and Your Software Choices
When you evaluate a scheduling, documentation or messaging platform, these are the questions, and "we take security seriously" is not an answer to any of them.
- Will the vendor sign a BAA? If not, stop here.
- Is data encrypted in transit and at rest? Ask for the specifics: TLS for the connection, encrypted storage and backups.
- Does every user get a unique login, and can you set roles?
- Is there multi-factor authentication?
- Does the session lock after inactivity?
- Are there audit logs you can read? Who opened which patient, and when.
- Where is the data hosted, and does that host have a BAA with the vendor? The vendor's own cloud provider is a business associate too.
- What happens when you leave? You need to be able to export your records and have the vendor delete its copy.
Built for the field
Logicly gives every user their own login and role, supports multi-factor authentication, locks an idle session after 15 minutes, and keeps an audit log of who opened which patient's record.
Key Takeaways
- Know which lines are the regulation, which are the proposed rule, and which are practice. Cite the first, plan for the second, and do not call the third a law.
- The risk analysis is required, and it is the first thing OCR asks for. Do it, document it, keep it six years.
- Get a BAA from every vendor that touches PHI, including the small ones.
- Give every person their own login. Shared accounts fail a required specification and erase your audit trail.
- Encrypt every device that leaves the office. A lost encrypted laptop is a lost laptop; a lost unencrypted one is a reportable breach.
- Sixty days is the outer limit for breach notification. The standard is without unreasonable delay.
- Train with scenarios from the field, because that is where home health breaks the rules.
Frequently asked questions
Does HIPAA require a home health agency to encrypt patient data?
Not in so many words, today. Encryption is an addressable specification in the current Security Rule, which means you must assess whether it is reasonable and appropriate, implement it if it is, and document why if you decide it is not. In practice almost every agency should encrypt, because encrypted data that is lost is not a reportable breach. The proposed Security Rule would make encryption at rest and in transit required, with limited exceptions. That rule has not been finalized.
How often does HIPAA require a risk analysis?
The current rule says the risk analysis is required and that the evaluation of your safeguards must be periodic. It does not name a number of months. Most agencies run one every year and after any change that touches patient data, such as a new EHR or a move to a new scheduling tool. The proposed Security Rule would require the risk analysis to be reviewed at least once every 12 months.
Is texting a patient's name and address to a clinician a HIPAA violation?
HIPAA does not name text messaging or any other channel. It requires technical safeguards against unauthorized access to ePHI in transit, and it makes you decide, through your risk analysis, whether a channel is reasonable and appropriate. Unencrypted SMS between staff is hard to defend under that standard, and a lost phone with those messages on it is a breach of unsecured PHI. Use the secure messaging inside your scheduling or documentation system.
How long do we have to report a breach?
Individuals must be notified without unreasonable delay and no later than 60 calendar days after discovery. If 500 or more people are affected, HHS is notified at the same time and, if more than 500 residents of one state are affected, prominent media in that state as well. Breaches of fewer than 500 people go on a log and are reported to HHS within 60 days after the end of the calendar year in which they were discovered.
Which vendors need a Business Associate Agreement?
Any vendor that creates, receives, maintains, or transmits protected health information on your behalf. For a home health agency that usually means the EHR, the scheduling and documentation platform, the billing service or clearinghouse, the fax service, cloud storage, any transcription or AI documentation tool, and the IT company that manages your devices. A vendor that will not sign one cannot lawfully hold your patients' data.
Sources
- 45 CFR 164.502: (b) minimum necessary; (e) disclosures to business associates.
- 45 CFR 164.506 and 164.508: treatment, payment and operations without authorization; authorization for other uses.
- 45 CFR 164.520: notice of privacy practices.
- 45 CFR 164.524(b)(2): act on an access request within 30 days, one extension of up to 30 days.
- 45 CFR 164.530: (a) privacy official; (b) training and its timing; (e) sanctions; (f) mitigation; (j)(2) six-year retention.
- 45 CFR 164.308: (a)(1)(ii)(A) risk analysis, (B) risk management, (C) sanction policy, (D) information system activity review, all required; (a)(2) security official; (a)(3)(ii)(C) termination procedures, addressable; (a)(5) security awareness and training; (a)(7) contingency plan; (a)(8) periodic evaluation; (b) business associate contracts.
- 45 CFR 164.310: facility access, workstation use and security, device and media controls (disposal required).
- 45 CFR 164.312: (a)(2)(i) unique user identification, required; (a)(2)(iii) automatic logoff and (a)(2)(iv) encryption, addressable; (b) audit controls; (d) person or entity authentication; (e) transmission security.
- 45 CFR 164.316(b)(2)(i): retain documentation six years.
- 45 CFR 164.402: definitions of breach and unsecured PHI, the four-factor assessment.
- 45 CFR 164.404, 164.406, 164.408, 164.410: notification to individuals, the media, HHS, and by business associates.
- HHS, Guidance Specifying the Technologies and Methodologies That Render PHI Unusable, Unreadable, or Indecipherable, 74 FR 19006 (April 27, 2009): NIST SP 800-111 for data at rest, FIPS 140-2 and NIST SP 800-52 for data in motion, NIST SP 800-88 for media destruction.
- HHS, HIPAA Security Rule To Strengthen the Cybersecurity of Electronic Protected Health Information, proposed rule, 90 FR 898 (January 6, 2025). No final rule published as of October 1, 2026.
- HHS Office for Civil Rights, 2016-2017 HIPAA Audits Industry Report (December 2020).
- ONC and OCR, Security Risk Assessment Tool, version 3.7.
- Related on this site: the referral-to-first-visit checklist (the notices due at start of care), how to start a home health agency, best home health software 2026.