Category: Home Health Care

  • HIPAA and Home Health Care Providers

    by Jay Hodes, President – Colington Consulting

    Over the last few months, I attended a number of events with geriatric care managers and home health agency owners. It was extremely insightful learning about the tremendous services these professionals provide to our aging population. As more and more seniors consider aging in place and remain in their homes, the need for home health services is exploding.

    After speaking with some care managers, I subtly brought up the subject of HIPAA and how it may be applicable to certain aspects of the services they provide. Most those who provide non-medical care said that they were unaware of specific HIPAA requirements and admittedly did not know if it applied to what they do. I asked if they or their staff were maintaining client files that contained any protected health information (PHI). Most said yes, as this type of information is vital to the type of services provided to their clients.

    When I asked about taking the proper safeguards to protect client health information and other personally identifiable information (PII) they maintain, most if not all said they had no formal safeguards in place. What was even more unsettling was very few of these companies even had an employee policy and procedure manual that covered protecting client health information. From what I was told, a great deal of client health information is passed through unsecured means, including unsecured texting and email exchanges, along with the use of file sharing services.

    The HIPAA Privacy Rule requires healthcare providers, regardless of size, provide the proper safeguards of individually identifiable health information. Technically, a home health or geriatric care manager that does not provide skilled medical care does not meet the regulatory definition of a covered entity or business associate under this rule unless they are filing health insurance claims for clients. That poses a significant grey area in terms of mandating specific requirements for this category of professional caregiver. If a breach of client records did occur, the government would have no idea it happened. There are no notification requirements and no mandates to inform clients their health and personal information may have been compromised.

    Professional caregivers must be bound to protecting the confidentiality of client health information. Although there may not be a regulatory requirement, caregivers must be attentive to HIPAA regulations and use this guidance as a model to safeguard records. After all, they are dealing with and managing client health concerns every day on the job.

    I am usually asked, โ€œWhere do I start?โ€ Here are some suggestions to follow:

    1. Develop a Privacy Policy and Procedure Manual that is distributed to all staff. The manual needs to cover areas such as:
    • Notice of Privacy Practices
    • Uses and Disclosures of Protected Health Information Requiring Client Authorization
    • โ€œMinimum Necessaryโ€ Use and Disclosure of Protected Health Information
    • Uses and Disclosures of Protected Health Information where the Client has an Opportunity to Agree or Object
    • Access of Individuals to Protected Health Information
    • Accounting for Disclosure of Protected Health Information
    • Business Associate Agreements
    • How to Safeguard Protected Health and Personal Information
    • Complaints to Your Company or Business; Mitigation
    1. Require some type of security awareness training be conducted for all staff, regardless of their job function, on an annual basis and any time you take on a new employee.
    2. If you are currently using smartphones to text client health information, I would recommend against it. I know this may pose an inconvenience, but it is a prudent security measure. There are secure texting services available. If phones need to be used, it is best to call each other and discuss client health information in a private setting.
    3. From an IT perspective, the following safeguards should be in place:
    • Ensure there is full disc encryption on all laptops/computers used by the company staff. This includes all BYOD.
    • Implement a secure email service for exchanges between staff, providers and others who may need to view PHI and PII. This service includes the ability to securely upload attachments.
    • Ensure all computers/laptops have appropriate anti-malware and anti-virus software that is updated often.
    • Set auto log-off if the device is left unattended for a certain period of time, such as 10 or 15 minutes.

    Need Help with Your HIPAA Compliance Program?

    At Colington Consulting, we specialize in helping healthcare organizations and business associates build proactive compliance programs. Contact us at 844-740-7100 or schedule a free 30-minute HIPAA risk review to evaluate your current policies and protect your organization.

    Updated on June 21, 2026 and Reviewed By: Jay Hodes, President – Colington Consulting, HIPAA Compliance Expert

    Regulatory Sources: The HIPAA Privacy Rule (45 CFR ยง 164.524): This is the core federal regulation that establishes a set of national standards for the protection of certain health information. The U.S. Department of Health and Human Services (HHS) Office for Civil Rights (OCR) provides official regulatory guidance and actively enforces these timelines under its ongoing Right of Access Initiative, which targets covered entities that fail to provide timely access to records. 45 CFR 164.502(e), 164.504(e), 164.532(d) and (e), address Business Associates and when Business Associate Agreements are required.

    Disclaimer: The information provided in this article is for educational and informational purposes only and does not constitute formal legal advice or an official regulatory determination. For specific guidance regarding your organization’s unique operational workflows, consult directly with a HIPAA compliance specialist or legal counsel.