Byline: Reviewed by Dee and Shirley, Founders, Home Care Success Consulting. Dee: Connecticut agency operator, 13+ years as a nurse. Shirley: Massachusetts agency operator, Master's degree in Healthcare Administration.
HIPAA compliance is one of the more misunderstood areas of home care operations -- some owners assume it doesn't apply to them because they're not a traditional medical provider, while others over-apply hospital-grade protocols that aren't proportional to a small agency's actual risk.
This guide walks through what HIPAA actually requires of home care and home health agencies, what counts as protected health information in a home care context, and practical steps for building genuine, sustainable compliance rather than a compliance theater.
Does HIPAA Apply to Your Home Care Agency?
Whether HIPAA applies directly to your agency depends on whether you meet the definition of a covered entity or business associate under the law. Home health agencies that bill Medicare or Medicaid electronically for skilled services are generally covered entities.
Non-medical home care agencies that don't bill insurance in the same way may not always meet the strict legal definition of a covered entity, but many still handle protected health information as a business associate of a covered entity, or choose to follow HIPAA-consistent practices as a matter of client trust.
What Counts as Protected Health Information
Protected health information (PHI) includes any individually identifiable health information -- not just formal medical records, but also information like a client's diagnosis, medications, care plan details, appointment schedules, and even basic facts like the fact that someone is receiving home care services at all.
In a home care context, this extends beyond paper files to text messages between caregivers and supervisors, voicemails, photos taken for care documentation purposes, and electronic visit verification systems.
Core Requirements Your Agency Should Meet
- Written privacy policy: Describing how client health information is collected, used, stored, and shared.
- Access controls: Limiting who can view client health information to staff who genuinely need it.
- Secure storage: Locked cabinets for physical records and encrypted storage/transmission for electronic records.
- Business associate agreements: Executed with any third-party vendor handling client health info (e.g., scheduling software).
- Breach notification process: Documented procedures for identifying and responding to privacy incidents.
- Staff training: Provided at hiring and on a recurring basis.
Common HIPAA Mistakes at Home Care Agencies
| Common Mistake | Correct Practice |
|---|---|
| Assuming HIPAA doesn't apply | Evaluate specific covered entity or business associate status |
| Using unsecured personal messaging apps | Use secure, encrypted messaging platforms designed for healthcare |
| Discussing client info in shared spaces | Ensure conversations happen in private settings out of earshot |
| Skipping Business Associate Agreements | Execute BAAs with all relevant software and service vendors |
Frequently Asked Questions
Does HIPAA apply to non-medical home care agencies?
It depends on whether the agency meets the legal definition of a covered entity or business associate. Many non-medical agencies choose to follow HIPAA-consistent practices regardless, given client trust expectations.
What counts as protected health information in home care?
Any individually identifiable health information, including diagnoses, medications, care plan details, and even the fact that someone receives home care services when combined with identifying details.
Do we need a business associate agreement with our scheduling software vendor?
Generally yes, if that vendor has access to client health information as part of providing services to your agency. This is a commonly overlooked requirement.
Can caregivers text family members about a client's condition?
Only through a secure, agency-approved communication channel. Standard personal texting or messaging apps are not inherently secure and create real privacy risks.
Ready to Get Started?
Building genuine, sustainable HIPAA compliance protects both your clients and your agency. Dee and Shirley can help you assess your current practices and close any real gaps. Book a free consultation.

