Compliance

HIPAA Compliance for Home Health Agencies: The Complete MSP Guide for 2026

September 22, 2026 · 7 min read · Brett Coffin

TLDR: Home health agencies are HIPAA-covered entities whose caregivers carry protected health information into patient homes on mobile devices, across networks the agency doesn't own, every day. For MSPs, this creates a recurring compliance service opportunity — and serious personal liability if a signed Business Associate Agreement isn't in place. This guide covers the specific HIPAA obligations, the 2026 Security Rule changes, the BAA gaps that expose MSPs directly, and how to package ongoing compliance as a service for this fast-growing vertical.


More than 12,000 Medicare-certified home health agencies operate in the United States, and the sector is expanding rapidly ([U.S. News & World Report / The Advisory Board, Feb 2026](https://www.advisory.com/daily-briefing/2026/02/24/us-news-home-health)). The U.S. Bureau of Labor Statistics projects home health and personal care aide employment will add 847,300 new positions between 2025 and 2035 — more new jobs than any other U.S. occupation — as Americans aged 65 and older exceed one in five and nine out of ten seniors say they want to age in place rather than move to institutional care ([BLS projections, 2025](https://www.caremarketing.com/home-health-personal-care-aide-jobs/)).

Every one of those agencies is a HIPAA-covered entity. Every care visit generates protected health information. Every device a nurse or aide carries into a patient's home is a potential breach vector.

Healthcare data breaches have been the most expensive in any industry for 14 consecutive years, averaging $7.42 million per incident in IBM's 2025 Cost of a Data Breach Report ([HIPAA Journal, citing IBM 2025](https://www.hipaajournal.com/average-cost-of-a-healthcare-data-breach-2025/)). For a home health agency that lacks a hospital system's legal and IT resources, an OCR investigation or a breach notification obligation can be existential. The MSP managing their systems sits squarely in the middle of that risk.

Why Home Health Agencies Are HIPAA's Most Exposed Healthcare Client

Most covered entities — clinics, hospitals, behavioral health practices — operate from fixed physical locations where PHI handling can be controlled. Home health agencies operate in reverse: care comes to the patient, so PHI follows the caregiver into environments the agency cannot control.

A typical home health workflow involves visiting clinicians documenting patient assessments on tablets or smartphones at the bedside, care coordinators transmitting care plans over home or mobile networks the agency doesn't own, EHR systems and scheduling platforms accessible from personal devices, and paper-based wound care notes or medication logs transported in vehicles between visits.

This distributed model means a single HIPAA technical safeguard failure — an unencrypted device left in a car, a care plan emailed via a personal Gmail account, a tablet connected to an unsecured home WiFi network — can trigger an OCR investigation and breach notification.

OCR intensified enforcement in 2025, issuing 21 financial penalties compared to 16 in 2024, with inadequate risk analysis as the single most common finding across enforcement actions ([Ogletree, 2025](https://ogletree.com/insights-resources/blog-posts/2025-enforcement-trends-risk-analysis-failures-at-the-center-of-hhss-multimillion-dollar-hipaa-penalties/)). OCR collected more than $9 million in penalties in 2024, and its enforcement posture has explicitly expanded to pursue smaller covered entities — including home health agencies — that historically received less scrutiny than large health systems ([HIPAA Journal, 2024](https://www.hipaajournal.com/ocr-reports-congress-hipaa-compliance-data-breaches-2024/)).

What the HIPAA Security Rule Requires in a Home Health Setting

The HIPAA Security Rule (45 CFR Part 164) applies to all electronic PHI a covered entity creates, receives, maintains, or transmits. The requirements that produce the most OCR findings in home health settings are:

Device and media controls (§ 164.310(d)). Every device used to access or document PHI must be inventoried. Storage must be encrypted. Disposal procedures — wiping devices before retirement — must exist in writing.

Workstation use and security (§ 164.310(b) and (c)). Under HIPAA, "workstation" includes any mobile device. Every device used to create or transmit PHI must have screen-lock enabled, automatic logoff after inactivity, and access controls tied to individual user accounts — not shared logins.

Transmission security (§ 164.312(e)). PHI transmitted over networks must be encrypted. Care documentation apps must use TLS in transit, and clinical staff must not use SMS, unencrypted email, or consumer messaging apps to discuss patient care.

Audit controls (§ 164.312(b)). The agency must produce access logs showing who accessed which patient records and when. EHR audit logging must be enabled and logs retained per applicable record retention requirements (typically six years under HIPAA).

Risk analysis (§ 164.308(a)(1)). The most common OCR finding: the agency completed a risk analysis once at implementation and never updated it. Risk analysis must be ongoing, not a one-time project.

See the 2026 HIPAA Security Rule overhaul for the full set of changes under HHS's December 2024 proposed rule — including a new required annual risk analysis cycle and an asset inventory mandate.

The BAA Obligation That Puts MSPs at Risk

Every vendor that handles PHI on behalf of a covered entity must sign a Business Associate Agreement. For home health agencies, that list is long: the EHR vendor, the billing platform, the cloud backup provider, the scheduling software, and — critically — the MSP managing the agency's IT infrastructure.

MSPs that manage networks, endpoints, or cloud environments for home health agencies are business associates under HIPAA. Without a signed BAA in place:

  • The MSP is exposed to the same OCR enforcement risk as the covered entity
  • The agency is non-compliant for every year the BAA was absent
  • A breach triggers notification obligations that include disclosing the missing BAA

Missing BAAs remain one of the most frequently cited deficiencies in OCR enforcement actions, including against small covered entities. The HIPAA BAA management guide for MSPs covers the required contract language for IT providers, the subcontractor BAA chain that most MSPs miss, and how to audit your current client agreement portfolio.

2026 HIPAA Security Rule Changes That Directly Affect Home Health Agencies

HHS's December 2024 proposed Security Rule updates include provisions that change how home health agencies must manage compliance going forward:

Annual risk analysis (proposed required). The risk analysis standard shifts from "periodically" to annually. An agency maintaining a years-old risk analysis PDF will fail the new standard.

Technology asset inventory (proposed required). The proposed rule requires covered entities to inventory all technology assets that touch ePHI. For home health agencies, this means tracking every caregiver's tablet, the EHR installation, scheduling integrations, backup systems, and cloud platforms — with current status.

Contingency plan testing (proposed required). Currently an addressable specification, contingency plan testing is proposed to become required. Home health agencies managing their contingency plan as a document rather than a tested program will need to demonstrate annual exercise records.

Workforce training (proposed enhanced requirements). The proposed rule strengthens training by requiring role-specific content, individual completion records, and annual re-training.

These changes are proposed and subject to comment, but OCR has been enforcing to the spirit of these standards in existing actions. MSPs serving healthcare clients should treat the proposed rule as current requirements now. Visit hipaa-compliance-for-msps for the full landscape of HIPAA requirements for managed service providers.

Common OCR Findings at Home Health Agencies

Based on published enforcement actions and OCR audit patterns, these are the HIPAA gaps most frequently cited at home health organizations:

  • **No documented risk analysis** or a risk analysis older than three years
  • **Missing BAAs** with the EHR vendor, billing company, or IT provider
  • **Unencrypted mobile devices** used by field staff to document patient care
  • **Shared login credentials** on care documentation apps — no individual user accountability
  • **No workforce training records**, or training completed only at hire and never renewed
  • **Audit logging disabled** in the EHR, or logs not retained to the six-year standard

Each of these is detectable with a structured HIPAA assessment. Each is also billable recurring work: the risk analysis must be updated annually, the device inventory must be maintained, training records must stay current.

Packaging HIPAA Compliance as a Recurring Service for Home Health Clients

The home health HIPAA compliance service follows the same structure as any healthcare client, with a mobile-workforce overlay:

Year one (assessment). Conduct the Security Risk Analysis, identify gaps in device controls, BAA coverage, training, and contingency plan documentation. Deliver a prioritized remediation roadmap.

Ongoing monthly. Maintain the technology asset inventory, monitor for new devices onboarded by field staff, verify training completion rates, review EHR audit logs for access anomalies.

Annual cycle. Updated risk analysis, updated workforce training with completion certificates, contingency plan tabletop exercise.

Trigger events. Staff turnover (new-hire HIPAA orientation, offboarding checklist), EHR or software vendor changes (new BAA required), security incidents.

This program is recurring, documentation-intensive, and difficult for a home health agency to self-manage while running care operations. It fits exactly the Nuronus-backed compliance practice model — with the evidence pipeline, risk scoring, and white-label reports for every home health client in your portfolio under one multi-tenant dashboard.

Start free for up to two clients — no credit card required.

The Cyber Insurance Connection

Cyber insurance carriers have begun treating HIPAA compliance documentation as a material underwriting factor for healthcare accounts. An agency without a current risk analysis, documented device encryption, and a tested contingency plan may find itself uninsured for a breach or facing premium surcharges that make coverage impractical.

The cyber insurance compliance checklist for MSPs covers the specific controls carriers assess in healthcare accounts and how to build a documentation package that satisfies OCR and underwriters simultaneously. Serving home health clients well means making them both compliant and insurable.


More than 12,000 home health agencies are operating with mobile workforces, distributed PHI, and IT infrastructure managed by MSPs who may not have a signed BAA in the file. The HIPAA compliance program for a home health client is annual, billable, and self-renewing — because the Security Rule requirements never stop, and the consequences of ignoring them have never been higher.

Ready to Add Compliance Services to Your MSP?

Free forever for 2 clients. All features included. No credit card required.

Get Started Free
Brett Coffin, Founder and CEO of Nuronus

Brett Coffin

Founder, Nuronus

20+ years in IT infrastructure and security. Built Nuronus after watching MSPs leave compliance revenue on the table because the tooling made it impossible to deliver profitably.