Contact Us
IT Total Care

Blog

Nurse in blue scrubs settling a blanket around a seated senior client at home, the daily work behind the proposed HIPAA Security Rule for home health agencies.

How to Prepare for the HIPAA Security Rule Update: A Practical Guide for Home Health Agencies

Three vendor emails landed in your agency inbox this quarter, each one explaining that encryption of patient data is now mandatory and that the deadline has already passed. A fourth attached a compliance package with a price. Meanwhile your director of nursing wants a straight answer about whether the agency actually has to do anything differently this year, and nobody in the building can give her one.

That confusion is the problem and it is expensive in both directions. Some home health and home hospice agencies in the San Francisco Bay Area are buying against requirements that are not law yet. Others have concluded the whole thing is noise and are ignoring safeguards that federal regulators are already enforcing. Both groups are reacting to the same proposed rule, and both are reading it wrong.

This guide explains why the proposed HIPAA Security Rule update matters for home health and home hospice agencies, how to prepare for it on your own, and how IT Total Care takes the work off your plate.

1. Why Does the HIPAA Security Rule Update Matter for Home Health Agencies?

The proposed HIPAA Security Rule update matters because it would convert a set of flexible expectations into hard requirements for every home health and home hospice agency that handles ePHI, meaning electronic protected health information. It is not law today. It is also not going away quietly, and the safeguards it would mandate are already showing up in federal enforcement under the current rule.

Where the significance actually sits:

  • Removal of the addressable designation: Today an agency can decline to implement certain safeguards as written if it documents a reasonable alternative. The proposal would make every implementation specification required, including ePHI encryption at rest and in transit and multi-factor authentication on systems that reach ePHI. That is the largest single change in the package.
  • Proposed status, not current law: HHS published the proposal in the Federal Register on January 6, 2025 and the comment period closed on March 7, 2025. No final rule has been issued. The Security Rule already on the books remains in full effect and fully enforceable in the meantime.
  • A timeline that has already moved: Federal regulators originally targeted May 2026 for final action. That date passed with nothing published, and the Office of Management and Budget now shows July 2027. Agenda dates are projections rather than binding deadlines, and the proposal could still be finalized as written, narrowed, delayed again, or withdrawn.
  • A short runway if it lands: As proposed, the rule would take effect 60 days after publication with compliance required 180 days after that, roughly 240 days end to end. For an agency with no internal IT staff and thin operating margins, that is a compressed window to encrypt data, deploy MFA across field staff, and build an asset inventory from scratch.
  • Active enforcement under the current rule: The HHS Office for Civil Rights has brought twelve enforcement actions under its Risk Analysis Initiative as of early 2026, and expanded the initiative this year to cover risk management as well. Almost every one turned on the same finding: no accurate, thorough, current risk analysis. That obligation exists today and is not waiting on any rulemaking.
  • A quantified cost of getting it wrong: The IBM Cost of a Data Breach Report 2026 put the average healthcare breach at $6.64 million and the average time to identify and contain a breach at 247 days across all industries. The dollar figure describes healthcare as a whole rather than agencies your size. The 247 days is the number that should worry a distributed workforce, because an unmonitored account can stay open that long without anyone noticing.

The practical conclusion for a home health or hospice agency is narrow and worth stating plainly: do not over-invest in requirements that have not been finalized, and do not use the delay as a reason to skip safeguards that are enforceable right now. Most of the preparation below falls in the second category.

2. How Can a Home Health Agency Prepare for the HIPAA Security Rule Update on Its Own?

A home health agency can prepare internally in seven steps: run a current risk analysis, turn on multi-factor authentication, inventory the devices that reach ePHI, verify encryption, review access and name a responsible party, tighten incident response, and close out with business associate agreements, documentation, and a person assigned to monitor the rule. None of the seven requires new technology. All of them require someone to own the work while the agency is also delivering care.

Step 1: Run a Current Risk Analysis and Map Where ePHI Lives

A risk analysis is a documented assessment of where ePHI exists across the agency, what could realistically go wrong with each location, and how serious the consequences would be. Begin by listing the places ePHI actually sits rather than the places you assume it sits: your EMR, whether that is Axxess, WellSky, or Homecare Homebase, the visit records generated through your state-mandated EVV system, email and file storage in Microsoft 365 or Google Workspace, and every device or portal a staff member uses to reach any of it. Rank what you find by likelihood and impact, write down the decisions you made and why, and put a date on the document. This step is required under the current rule, it is the most commonly cited failure in HIPAA enforcement, and it is the foundation the entire proposal is built on, which makes it the one piece of preparation that cannot be wasted effort regardless of what happens to the rulemaking.

Step 2: Turn On Multi-Factor Authentication Everywhere ePHI Is Reachable

Multi-factor authentication requires a second proof of identity beyond a password, usually a code or a prompt on a phone, so that a stolen password on its own is not enough to open a patient record. Apply it to EMR logins, Microsoft 365 or Google Workspace, remote access, and any third-party portal used for referrals or payer coordination. The obstacle here is almost never technical. It is that a clinician running late asks for an exception before a 7 AM visit, gets one as a courtesy, and the exception quietly becomes permanent. Decide in advance who is allowed to grant an exception, in what circumstances, and for how many days, then review that list monthly. Our walkthrough for rolling out MFA at an agency covers the sequence that keeps field staff working through the change. MFA is low cost, available today, and already proposed to become mandatory, which makes it the highest-value item on this list after the risk analysis.

Step 3: Inventory Every Device That Touches ePHI

Build a list of every device that can reach ePHI, including personally owned phones, which in home-based care are the majority of them. For each entry capture the assigned user, the platform, whether a screen lock is enforced, and whether the work profile can be removed remotely without touching the employee’s personal photos and messages. The scenario this protects against is ordinary: a field clinician opens the EMR app on a personal phone between visits to check a medication list, and that phone then spends the afternoon in a car. If it was never enrolled in a management platform such as Intune, JumpCloud, or Apple Business Manager, the agency has no mechanism at all once it goes missing. Our guide to building a device inventory list covers what to capture and how to keep the record from going stale. The proposal would require a documented technology asset inventory outright, so this work carries forward either way.

Step 4: Confirm ePHI Encryption Is Enabled at Rest and in Transit

Encryption scrambles patient data so it is unreadable without a key, both while it is stored and while it moves between systems. The task at this stage is verification rather than configuration. Most cloud EMR platforms and most Microsoft 365 and Google Workspace tiers support encryption at rest and in transit, but it is not always switched on by default and coverage varies by license tier, so an assumption is not an answer. Ask each vendor to confirm in writing which of your data is encrypted, where, and under which tier of your contract. Keep that confirmation with your risk analysis. This guide deliberately stops at verification depth; the configuration work behind it is substantial enough to deserve its own treatment.

Step 5: Review Access and Name a Responsible Party for Permissions

List every person who can reach ePHI, what each one can see, and whether that level of access still matches the job. Then name one responsible party who owns the permission list and confirms every change to it. Shared credentials are where this breaks down in practice. A scheduler covering forty or more shifts often works from a login that two or three other people also use, which means removing one person’s access requires rotating a password half the office depends on, and that rotation is exactly the task that gets deferred. The proposal would compress access termination to one hour after employment ends and add a 24-hour notification when a workforce member’s access changes. Neither timeline is achievable without a named owner and a written sequence, which is why this step belongs on the list now rather than after a final rule.

Step 6: Tighten Your Incident Response Plan

Write down who has authority to declare a security incident, who they contact, which systems get restored first, and how the agency documents what happened. California home health agencies and hospices are already working against a tighter clock than the federal one: under California Health and Safety Code Section 1280.15, a licensed agency must report unauthorized access to a patient’s medical information to the California Department of Public Health and to the affected patient within 15 business days of detecting it, while the federal Breach Notification Rule allows up to 60 days. The proposal would add a 72-hour target for restoring critical systems and data after a loss, plus a 24-hour notice from any business associate that activates its contingency plan. Note that the 72-hour figure is a restoration target and not a breach reporting deadline, despite how often it is described that way. Test the plan once a year against something realistic, such as ransomware locking the EMR on a Monday morning with forty visits already scheduled.

Step 7: Confirm Business Associate Agreements, Document the Program, and Assign a Monitor

Three closing tasks make the rest of the work durable. First, keep a short and current list of every business associate that handles ePHI on your behalf, including billing companies, EMR vendors, answering services, and your IT provider, and confirm a signed agreement exists for each. Keep it at that depth for now, because the proposal would layer written verification and vendor certification on top of the agreements themselves and that deserves separate treatment. Second, document what the agency actually does rather than what a policy says it does. Federal regulators expect a living, continuous risk management program, and dated evidence that a control was reviewed carries more weight in an investigation than a polished binder nobody opens. Third, task one person with checking the rule’s status quarterly. Fifteen minutes every three months is enough to keep the agency from being surprised in either direction.

Limitations: Preparing for a proposed rule is harder than preparing for a final one, because there is no deadline to organize the work around and no obvious moment when the job is done. The risk analysis is accurate the week it is written and drifts with every new hire, new platform, and reassigned phone. MFA exceptions accumulate one sympathetic decision at a time. The device list falls behind within a single high-volume hiring cycle. Business associate agreements get signed and never revisited. And the person assigned to watch the Federal Register is the same person covering a call-out on a Tuesday. Agencies rarely fail at understanding what the proposal would require. They fail at maintaining seven ongoing disciplines against a moving regulatory target while short-staffed, which is a capacity problem rather than a knowledge problem.

3. How Does IT Total Care Help Home Health Agencies Prepare for the HIPAA Security Rule Update?

IT Total Care builds and maintains the security program behind these requirements for home health and home hospice agencies across the Bay Area, so the risk analysis stays current, the controls stay enforced, and someone other than your administrator is tracking what happens to the proposal. Your team stays focused on patient care rather than on regulatory monitoring.

Our process includes:

  • HIPAA-Focused Risk Analysis: We map where ePHI actually flows across Axxess, WellSky, or Homecare Homebase, your EVV records, email, and field devices, and produce the living documentation federal regulators expect rather than a one-time report.
  • MFA Deployment and Enforcement: We roll out multi-factor authentication across every system that touches ePHI, including EMR logins and Microsoft 365 or Google Workspace, sequenced so a caregiver’s 7 AM visit is not the first place a problem shows up.
  • Mobile Device Management: We enroll devices in Intune, JumpCloud, or Apple Business Manager so personal phones running an EMR app are screen-locked and remotely wipeable, which is what turns a lost phone from a reportable event into an inconvenience.
  • Encryption Verification: We confirm that ePHI encryption is properly enabled at rest and in transit across your core platforms and flag the gaps in writing, with deeper encryption work handled as a dedicated engagement.
  • Access and Offboarding Management: We manage permissions and departures so a caregiver or scheduler who leaves loses ePHI access the same day, with a clear responsible party attached to every permission and a record of who approved it.
  • Incident Response Planning and Testing: We build and exercise a plan that lets your agency detect, contain, and restore quickly, sized against the 15-business-day California reporting requirement and the restoration timelines the proposal would introduce.
  • Regulatory Monitoring and Translation: We track the proposal’s progress on your behalf and turn any movement into a plain-English action plan, so your agency is neither spending early against requirements that may change nor caught flat-footed if they finalize.
  • Ongoing Managed Security: We help support HIPAA compliance through a monitored, continuously maintained program rather than an annual project, which is the posture federal regulators are already enforcing under the current rule.

“The agencies that come through this well are not the ones that spent the most. They are the ones who did a real risk analysis and then actually fixed what it found. Most of the agencies we onboard have never had an assessment or hand us an assessment from two years ago with a list of gaps nobody ever closed, In an investigation that document is worse than having nothing, because it proves you knew. The best way to prepare for the current proposed rule is simply doing the current rule properly.”

Brendan Duebner, President, IT Total Care

Ready to Get Ahead of the HIPAA Security Rule Update?

At IT Total Care, we work with home health, home hospice, and home care agencies throughout the San Francisco Bay Area, from the Peninsula to the East Bay, to build security programs that hold up under the rule in force today and absorb whatever the proposal becomes. Our home-based care IT support covers risk analysis, MFA, device management, access control, and incident response planning. Learn more about our approach to healthcare IT.

Contact Us to talk through what your agency needs.

Leave a Comment

Your email address will not be published. Required fields are marked *