Contact Us
IT Total Care

Blog

Clinician in scrubs reviewing patient notes beside an older adult on a couch, the documentation routine behind how often home health agencies need a HIPAA risk assessment.

How Often Do Home Health Agencies Need a HIPAA Risk Assessment?

How often do home health agencies need a HIPAA risk assessment is one of the questions San Francisco Bay Area agencies ask most, and the honest answer is that the regulation never gives a number. What it gives is an expectation of currency. What federal investigators cite is an analysis that is absent, stale, or too narrow to describe the agency it belongs to.

Below are the questions home health and home hospice agencies ask most often about timing: how often, what starts the clock over, what counts as a significant change, and what the proposed Security Rule update would do to all of it.

1. How often do home health agencies need a HIPAA risk assessment?

At least once a year in practice, plus any time something significant changes in the environment. The HIPAA Security Rule sets no interval, so annual is a working expectation rather than a stated requirement, and for a growing agency the event-driven triggers matter considerably more than the date on the calendar.

Both halves have to be true at once. An agency that runs an analysis every January and then migrates to a new EMR in June is carrying a document that is six months old and already wrong. What a current analysis has to contain is a separate question, answered in our post on the HIPAA risk assessment for home health agencies.

2. Does the HIPAA Security Rule state a required frequency?

No. The current Security Rule names no interval for risk analysis anywhere in its text. The related Evaluation standard at 45 CFR § 164.308(a)(8) requires a periodic technical and nontechnical evaluation, performed initially against the standards and afterward in response to environmental or operational changes affecting the security of ePHI, without specifying how often periodic means.

That silence is deliberate, and it is also where agencies get into difficulty. The flexibility was written in so a small agency and a hospital system could both comply, but it puts the burden on the agency to justify whatever interval it chose. An agency that can explain why its cadence is reasonable is in a far better position than one that simply never picked one.

3. Why is annual the working expectation if the rule does not require it?

Annual is the shortest interval that reliably survives scrutiny, and currency is what actually gets examined rather than cadence. No agency has been penalized for choosing fourteen months instead of twelve. Agencies are penalized for analyses that are absent, stale, or incomplete, and a yearly rhythm is the simplest way to avoid all three.

The gap is long-standing rather than new. In its 2016-2017 HIPAA Audits Industry Report, published in December 2020, the HHS Office for Civil Rights found that only 14 percent of audited covered entities substantially fulfilled their risk analysis responsibilities, and only 6 percent did so for risk management. Those figures cover covered entities of every kind rather than home health agencies specifically, but they explain why the analysis is the first document anyone asks to see.

4. What events should trigger a new risk assessment?

Any change that moves ePHI, changes who can reach it, or changes how it travels should trigger a new assessment. For an agency that is growing, these events arrive far more often than the anniversary does, and each one resets how current the existing analysis really is.

The triggers worth writing into your own policy:

  • An EMR migration, or a switch between platforms such as Axxess, WellSky, or Homecare Homebase
  • A cloud migration, including a move into Microsoft 365 or a change in where files are stored
  • Opening a new branch or expanding into a new county, which for Bay Area agencies usually brings a new set of referral partners and payer portals with it
  • Adopting or switching electronic visit verification systems
  • A change to the personal-device policy, including allowing or restricting clinician-owned phones
  • An acquisition, in either direction
  • Any security incident, whether or not it became a reportable breach

The last one deserves emphasis. An incident that turned out to be nothing still told you something true about your environment, and the analysis should reflect what you learned from it.

5. What counts as a significant change?

Operationally, a significant change is anything that alters where ePHI lives, who can reach it, or how it moves. That three-part test is more useful than any list, because it catches the changes nobody thought to write down at the time.

  • Where it lives: a new platform, a new storage location, or a new type of device in the field
  • Who can reach it: a new role, a new third party, or a shared login handed to one more person
  • How it moves: a new integration, a new remote access path, or a new referral portal

By that test, contracting a billing vendor is a significant change even though nothing was installed. So is handing a scheduler a colleague’s login to cover a staffing gap, because it altered who can reach patient data without altering a single system.

6. How often do home health agencies need a HIPAA risk assessment redone from scratch rather than updated?

An update is defensible only when the environment genuinely has not changed, which is rarer than it sounds. The pattern investigators specifically penalize is one analysis followed by light annual edits, because it reads as a document being maintained rather than a security program being run.

The practical test is whether the current version describes the systems and the people the agency has today. If the platforms, the headcount, or the device mix have moved, the analysis needs real work rather than a refreshed date field, and it needs an accurate ePHI asset inventory for home health agencies underneath it to be worth anything.

Record the review date and the person who performed the review on every pass. HHS and the Office for Civil Rights publish a free Security Risk Assessment Tool, now at version 3.7 as of September 2026, and one of its features exists precisely for this problem: it tracks who signed off on each part of an assessment and when. That record is what separates a reviewed analysis from an edited one.

7. Would the proposed HIPAA Security Rule update change how often an analysis is required?

Yes, if it is finalized as proposed. The proposal would require the risk analysis to be reviewed, verified, and updated at least once every 12 months and in response to any change in the environment or operations that may affect ePHI, which converts today’s working expectation into an express requirement with a number attached.

It is not law. HHS published the proposal in the Federal Register on January 6, 2025, no final rule has been issued, and the Office of Management and Budget’s regulatory agenda now shows July 2027 for final action after an earlier May 2026 target passed with nothing published. Agenda dates are planning projections, not deadlines, and the proposal could still be finalized as written, narrowed, delayed again, or withdrawn.

Treat any vendor describing these requirements as already in force with caution, because several are. Our walkthrough on preparing for the proposed Security Rule update separates what is enforceable today from what is still only a proposal.

8. Do these timing expectations apply to home care agencies as well?

Not directly. Home health and home hospice agencies are HIPAA covered entities, so the Security Rule applies to them by default.

That distinction does not make the exercise optional for a home care agency. Client information, payer data, and contractual privacy terms create real exposure on their own. It means the governing authority is different, and the answer to how often depends on what the agency’s contracts actually commit it to rather than on the Security Rule.

9. Can an IT provider run the risk assessment on our behalf?

A provider can perform the work. It cannot assume the liability.

What that means for timing is straightforward. Outsourcing the work does not outsource the calendar, and an agency that has not heard from its provider in eighteen months still owns the stale document. Agencies should expect an IT partner to help support HIPAA compliance rather than to certify it. Certification does not exist under the Security Rule, and a provider offering it is describing something nobody can deliver.

10. What should we ask an IT provider before signing?

Ask for evidence rather than assurances, and ask before a contract rather than after an incident. Five questions separate a provider that can genuinely keep an analysis current from one that will produce a document once and then move on.

  • Will you sign a business associate agreement, and what does it actually commit you to?
  • Can you produce a current ePHI asset inventory on demand, or only at project time?
  • How do you enumerate personal devices running EMR mobile apps?
  • Do you track remediation to closure, and can you show me the record?
  • Do you work with home health agencies specifically, or with medical practices generally?

Any answer that arrives as a general description rather than as a document is the one worth pressing on.

“The question we get is always how often should we get an assessment done. Most agencies have an old assessment document from whenever they last had a reason to get one done. Then they switched EMRs, opened a second branch, and hired thirty people. Generally speaking we think an annual assessment is best practice, however the real trigger should be we when a material system change occurs.”

Brendan Duebner, President of IT Total Care

Not Sure Whether Your Agency’s Risk Assessment Is Still Current?

IT Total Care works with home health and home hospice agencies throughout the San Francisco Bay Area, from San Mateo County to the East Bay, to keep the technical record behind a risk analysis accurate between reviews rather than rebuilt before each one. Our IT support built for home health agencies covers asset discovery, device enrollment, access review, and remediation tracked to closure. Learn more about our approach to healthcare IT.

Contact Us to talk through what your agency needs.