How Home Care, Home Health, and Home Hospice Agencies Can Use SharePoint to Protect Patient Data, Reduce Security Risk, and Stay HIPAA Compliant
For home health, home hospice, and home care agencies, Microsoft SharePoint has become one of the most widely used platforms for storing and sharing documents. Care plans, HR files, billing records, client intake forms, and internal policies all end up living somewhere on a shared drive. The question is whether that drive is working for your agency or quietly creating risk.
Most agencies that come to us have a SharePoint environment that grew organically over time. Folders were created when someone needed them, access was granted when someone asked for it, and no one was ever formally put in charge of keeping things organized. The result is a shared drive that is difficult to navigate, hard to secure, and increasingly difficult to trust.
This post covers why SharePoint organization and access control matter for home-based care agencies, what good practices look like, and how to start making practical improvements regardless of where your agency is today.
Why SharePoint Organization Matters More Than Most Home-Based Care Agencies Realize
Disorganized shared drives are not just a productivity problem. For agencies handling protected health information (PHI), a poorly structured SharePoint environment creates real compliance and security exposure.
When files and folders lack a clear structure, sensitive client information, including financial records, care plans, and ePHI, can end up scattered, duplicated, or stored in locations that were never intended to hold that type of content. Staff waste time searching for documents when they should be focused on care coordination. And because no one knows exactly where everything lives, it becomes nearly impossible to control who has access to what.
The risks are not theoreticall. A few of the most common issues we see include:
- Overly broad permissions where most staff can access everything, regardless of their role
- Former employees or contractors who retain access after offboarding
- Folders shared via “Anyone with the link” settings that bypass all permission controls
- No audit logging to track who accessed or changed sensitive files
For agencies subject to HIPAA, these gaps are not just operational inconveniences. Uncontrolled access to ePHI can constitute a Security Rule violation. And as cyber insurance applications increasingly ask about access controls and permission management, gaps in this area can affect coverage eligibility or policy premiums.
The Foundation: A Logical Folder Structure
A well-organized SharePoint environment starts with a folder structure that reflects how your agency actually operates. The goal is not perfection. It is consistency. When every person on your team knows where to find files and where to save them, your shared drive starts working the way it should.
Most home-based care agencies benefit from a structure organized around a combination of department and function. Common top-level folders might include areas like clinical operations, human resources, finance and billing, compliance, and administration. Beneath each top-level folder, subfolders should be organized in a way that matches your team’s daily workflow rather than an arbitrary system someone built years ago.
Equally important is a clear file naming convention. When staff members use different formats for naming documents, version confusion and duplicate files become unavoidable. A standardized naming convention, applied consistently across the organization, eliminates the guesswork and makes audits significantly easier.
Access Control: Giving Home-Based Care Staff Only What They Need
One of the most important principles in information security is the concept of least privilege: every user should have access only to the information required to do their specific job. In practice, many home-based care agencies operate in the opposite direction, granting broad access because it is easier than building a thoughtful permission structure.
Implementing role-based access groups is the most practical approach for agencies of any size. Instead of managing permissions for individual users, you create groups that align to job roles, such as caregivers, schedulers, billing staff, and clinical leadership, and assign permissions at the group level. When someone changes roles or leaves the organization, you adjust their group membership rather than hunting down every folder they were individually granted access to.
Sensitive folders containing financial records, HR files, and client ePHI should always be restricted to a limited, specifically authorized group of users. These are not folders where “when in doubt, share it” is an acceptable approach.
A few additional access control practices worth building into your standard operations:
- Never use “Anyone with the link” sharing settings for folders containing client or business-sensitive data
- Enable activity and audit logging so you have a record of who accessed or modified sensitive files
- Immediately revoke access for departed employees or contractors as part of your offboarding process
- Document who is responsible for approving access requests so it never becomes an informal process
“Approximately half of the home-based care agencies we work with have SharePoint setup incorrectly when we start working with them. This incorrect setup via confusing folder structures, inaccurate permissions, and lack of clean-up have a significant negative effect on the team. Fortunately, by taking the time to correctly setup and regularly review their SharePoint we see home care, home health, and home hospice companies significantly improve their efficiency and provide better care.”
Brendan Duebner, President of IT Total Care
Permission Audits: Why Ongoing Review Is Non-Negotiable
Setting up a good permission structure is only half the work. The other half is maintaining it over time. Roles change, staff members come and go, contractors complete their engagements, and new folders get created. Without a regular review process, even a well-configured SharePoint environment can drift back into a state of uncontrolled access.
A scheduled permissions audit, conducted quarterly or at a minimum twice per year, should review who currently has access to each folder or document library, confirm that access levels still align with current job roles, identify and revoke permissions that are no longer needed, and flag any sharing settings that may have been opened up outside of normal policy.
Assigning a responsible owner for this audit is critical. Permissions reviews that are nobody’s job quickly become nobody’s priority. One named person, whether in HR, operations, or IT, should be accountable for ensuring the audit happens on schedule and that findings are acted on.
It is also worth noting that a clean, well-permissioned SharePoint environment provides meaningful protection in the event of an account compromise. If an attacker gains access to a staff member’s credentials, the damage they can do is limited by how much that account can actually see and touch. Least privilege is not just an organizational principle. It is a security control.
HIPAA Compliance and Cyber Insurance: The Stakes Are Getting Higher
Regulators and cyber insurers are paying closer attention to access control than they were even a few years ago. HIPAA’s Security Rule requires covered entities to implement access controls that limit system access to authorized users and ensure those controls are regularly reviewed. For home health and home hospice agencies, this applies directly to SharePoint environments where ePHI is stored or accessed.
On the insurance side, cyber liability applications now routinely include questions about whether access to sensitive data is role-based, whether former employees are promptly removed from systems, and whether access is periodically reviewed and documented. Agencies that cannot demonstrate these controls may face higher premiums, reduced coverage limits, or denial of coverage altogether.
The good news is that building a well-organized, properly permissioned SharePoint environment addresses both sets of requirements simultaneously. Agencies that invest in this work are not just improving their day-to-day operations. They are building a defensible compliance posture that holds up under audit and scrutiny.
How IT Total Care Helps Home-Based Care Agencies Get This Right
IT Total Care works with home health, home hospice, and home care agencies throughout the San Francisco Bay Area to design and implement SharePoint environments that are organized, secure, and built to support compliance. Our approach is practical and tailored to the way home-based care organizations actually operate.
Our SharePoint services for home-based care agencies include:
- Designing and implementing a standardized, role-based folder structure tailored to your agency’s workflow
- Setting up access groups aligned to job roles so permissions are easy to manage and assign consistently
- Configuring least-privilege access controls and locking down sensitive folders containing financial, HR, and ePHI data
- Enabling and monitoring audit logging across your SharePoint environment
- Conducting scheduled permissions audits and removing outdated or unnecessary access on your behalf
- Documenting your folder structure and permission policies so your system stays organized as your team grows
Building a SharePoint Environment That Supports Your Home-Based Care Agency’s Mission
A well-configured SharePoint environment does more than keep files organized. It protects your patients, limits your liability, and gives your team a reliable foundation for doing their work. For home-based care agencies managing sensitive data across a distributed workforce, that foundation is not optional.
Whether your agency is starting from scratch or looking to clean up a shared drive that has grown out of control, the right structure and permission framework makes every part of your operation easier: faster documentation, stronger security, cleaner audits, and a smaller attack surface if something ever goes wrong.
Ready to Improve Your SharePoint Organization and Security?
IT Total Care helps home-based care agencies throughout the San Francisco Bay Area build secure, compliant SharePoint environments designed around the way your agency works. From folder structure and role-based permissions to audit logging and scheduled access reviews, our team manages the details so your staff can focus on patient care.
Contact Us today to learn how we can help your agency get SharePoint right.




