The HIPAA encryption requirements for home health agencies rest on a distinction that most published guidance gets wrong. Protecting electronic protected health information, or ePHI, while it moves across a network is required. Encrypting it is addressable, which is a much narrower thing than optional.
Addressable means the agency has to make a decision and be able to show it. Implement encryption, or document why an equivalent alternative safeguard is reasonable and appropriate in your environment. What an agency cannot do is leave the question unanswered, because an unanswered question is exactly what an investigator finds after something goes wrong.
For home health agencies from the Peninsula to the East Bay, that decision is already being made by default every day, in every referral packet that arrives by email and every visit note that syncs from a clinician’s phone. What follows is what the Security Rule actually says, what the January 2025 proposal would change, and what belongs in the file.
What Do the HIPAA Encryption Requirements for Home Health Agencies Actually Say?
The HIPAA Security Rule requires home health agencies to protect ePHI moving across a network, and it leaves the method partly to the agency. Transmission security is a required standard. Encryption is an addressable implementation specification sitting underneath that standard. Those are two different obligations, and conflating them is where most agencies go wrong.
What Is the Difference Between a Required Standard and an Addressable Specification?
A standard is not optional. Transmission security at 45 CFR 164.312(e)(1) obligates covered entities to implement technical security measures that guard against unauthorized access to ePHI transmitted over an electronic communications network. For a home health agency, that obligation attaches to every transmission, with no exceptions and no discretion.
An implementation specification is the method underneath a standard, and it is marked either required or addressable. Encryption in transit at 164.312(e)(2)(ii) is addressable. So is encryption of stored ePHI at 164.312(a)(2)(iv), under Access Control. The shorthand in this article’s title describes the specification, not the standard above it. The duty to protect the transmission never becomes discretionary. Only the choice of mechanism does.
What Does Addressable Actually Obligate a Home Health Agency to Do?
Addressable gives an agency three paths and requires it to walk one of them deliberately:
- Implement encryption, and record what is encrypted, where, and to what standard.
- Determine that encryption is not reasonable and appropriate in this environment, document that determination, and implement an equivalent alternative safeguard where one is reasonable and appropriate.
- Where the standard is otherwise satisfied, implement neither, and document the rationale for that decision.
HHS says as much in its own published FAQ, which states that the final Security Rule made encryption an addressable implementation specification and that its use is not mandatory. That is the primary source almost no vendor content cites, and the burden it creates runs in one direction. The agency that encrypts has a short file. The agency that declines carries the documentation, and that record has to survive a request years after the person who made the call has left.
In practice, for nearly every home health workflow, a risk analysis will not support declining. That is why addressable functions as required for most agencies, and why the honest version of this discussion is that you are almost certainly going to encrypt. Understanding the rule is not about finding an exit. It is about knowing what the file has to contain.
Is Encryption Already Required Under the January 2025 HIPAA Update?
No. Encryption is not required by rule today. The Notice of Proposed Rulemaking that HHS published in the Federal Register on January 6, 2025 would remove the addressable designation and make encryption of ePHI required both at rest and in transit. It remains a proposal, and no final rule has been issued.
Several published guides now describe that change as though it already happened. It did not. The comment period closed on March 7, 2025, and the entry for this rulemaking in the federal Unified Agenda, RIN 0945-AA22, now lists July 2027 for final action and sits on the long-term actions list. That date is a projection rather than a deadline, and it has already moved once.
An agency acting on the wrong premise gets hurt in one of two directions. It either spends against a compliance deadline that does not exist, or it assumes the rule already settles the question and quietly stops documenting the determination the current rule requires. We covered what the proposal would and would not change in our breakdown of the proposed HIPAA Security Rule update.
Getting the standard versus specification distinction right is the difference between a defensible file and a guess.
Where Does ePHI Actually Move in a Home Health Agency?
ePHI leaves a home health agency through more channels than most encryption policies account for, and a policy written around office email covers only a fraction of them. Before any determination can be made, the agency needs a plain list of the transmissions that actually happen during a normal week.
- Referral packets and face-to-face documentation arriving by email from physician offices and hospital discharge planners
- Assessment documentation syncing from Axxess, WellSky, or Homecare Homebase on a clinician’s phone between visits
- Visit notes finished from a coffee shop or a patient’s family Wi-Fi because the home has no usable signal
- Billing files moving to a clearinghouse or an outsourced coder
- A chart excerpt emailed to a physician to clarify a verbal order
- Scheduling and visit data crossing to your state-mandated electronic visit verification system
The verbal order is the one that tends to surprise people. A director of nursing clarifying an order at four in the afternoon is not thinking about transmission security. She is thinking about getting an answer before the physician’s office closes, and the fastest path is a short email with the relevant page attached. Every one of those moments is a transmission the agency has to be able to describe and defend.
What Has Unencrypted ePHI Actually Cost Providers?
Unencrypted devices produced two of the clearest HIPAA settlements on record, and in both cases the penalty was driven less by the loss itself than by what the organization had already decided and failed to act on.
In July 2020, the HHS Office for Civil Rights announced a $1,040,000 settlement with Lifespan Health System Affiliated Covered Entity after an unencrypted laptop was stolen from an employee’s vehicle, exposing the ePHI of 20,431 individuals. The detail that matters here is that Lifespan had already determined encryption was reasonable and appropriate, and then did not implement it. The determination existed. The control did not.
In November 2019, the University of Rochester Medical Center paid $3,000,000 over a flash drive lost in 2013 and a laptop stolen in 2017. OCR had investigated a similar lost flash drive at the same organization in 2010 and provided technical assistance at the time. Repeat exposure of a gap the organization already knew about is what moves OCR from technical assistance to a financial penalty.
That posture has not softened with time. OCR’s Risk Analysis Initiative remained active through 2026, and the agency announced four further Security Rule settlements on April 23, 2026, bringing the initiative to thirteen completed investigations. Encryption determinations live inside the risk analysis, which is the document those investigations keep finding missing or years out of date.
Which Transmissions Do Agencies Miss Most Often?
In our experience with home health clients across the Bay Area, the gap almost never shows up where the settlements did.
The second gap is quieter. Standard email sent without enforced TLS moves ePHI across the internet in plaintext, and it is the single most common unexamined transmission in a small agency.
The third is an assumption rather than a gap. Public Wi-Fi is widely believed to be the problem, and the more precise answer is narrower than most policies assume.
How Should a Home Health Agency Document the Encryption Decision?
Encryption decisions belong inside the risk analysis rather than in a separate policy binder, and they are made per data flow rather than once for the whole agency.
What Goes in the File for Each Data Flow?
- What is encrypted, where it is encrypted, and to what standard
- Where encryption was declined, the alternative safeguard, why it is equivalent, and who approved it
- The date of the determination and the specific system it was made about
- Evidence that encryption actually applied, not only that a policy required it
That last item separates a file from a folder. A policy proves intent. A report proves outcome, and outcome is what gets asked for.
When Does a Determination Need to Be Revisited?
Revisit a determination when the system changes, not when the calendar says it is time. An alternative safeguard that was reasonable on an old platform rarely survives a migration, and an annual review scheduled for March will miss the billing path that changed in June. The triggers worth writing down are an EMR change, an email platform change, and a change in how billing files leave the building.
Two boundaries belong in the same file. A vendor asserting that its product is HIPAA compliant is not a substitute for the agency’s own documented determination, because the determination is about your environment and the vendor has never seen it. Your written position on public Wi-Fi belongs here too, governing the device and the application rather than banning a category of network, so the answer is defensible rather than improvised.
One exception is worth recording rather than arguing about. Patients have a right to receive their own PHI by unencrypted email if they ask for it. The agency gives a brief warning about the risk, confirms the patient still wants it that way, sends it, and keeps the record of that exchange. The Privacy Rule is the operative authority there, and the choice is the patient’s to make.
Do California Laws Add to What HIPAA Requires?
California home health agencies answer to a second body of law covering the same patient data. The Confidentiality of Medical Information Act, at California Civil Code section 56 and following, obligates providers to maintain medical information in a manner that preserves its confidentiality, and it reaches conduct that federal enforcement never touches.
The practical difference is who can sue. HIPAA gives patients no private right of action, so enforcement runs through OCR and state attorneys general. The state act gives an individual whose information was negligently released a direct claim, with nominal damages of $1,000 available without any showing of actual harm, plus actual damages and fees. For an agency in San Mateo or Santa Clara County, a single unencrypted transmission can create two separate exposures, and only one of them arrives as a letter from Washington.
Where Do Agencies Get Encryption Wrong When They Handle It Alone?
Agencies rarely get encryption wrong by deciding wrongly. They get it wrong by leaving the decision in somebody’s memory and by encrypting whatever is easiest to reach. Five patterns account for most of what turns up on a first review.
- Encryption is enabled on office desktops and never on the phones where most field ePHI actually lives
- Staff move a referral packet through personal email because the encrypted path added friction
- Nobody has tested what an external recipient sees, so encrypted messages go unopened and then get resent in the clear
- The addressable determination exists in someone’s memory rather than in a document
- Policy bans public Wi-Fi while the EMR app, the device lock, and patching all go unmanaged
The third one is the most expensive, because it turns a control into its opposite. A message that was encrypted, came back unreadable, and was then resent in plaintext is worse than one that was never encrypted, because now there is a record of the agency knowing better.
“Most often agencies that get in trouble for lack of encryption didn’t decide against encrypting something. They simply never discussed it at all.”
Brendan Duebner, President of IT Total Care
What Can an IT Partner Do About HIPAA Encryption Requirements for Home Health Agencies?
An IT provider cannot make the addressable determination on your behalf. That decision belongs to the covered entity and lives in its risk analysis. What a partner supplies is the technical evidence the determination rests on, and the controls that make encryption the easy answer rather than the inconvenient one.
Two claims are worth listening for. A vendor telling you that its platform makes your agency HIPAA compliant is making a claim no vendor can make. What to expect instead is a partner that helps support HIPAA compliance, not one that certifies or assumes it, because the liability does not transfer no matter what the contract says.
What Encryption in Transit Looks Like When It Is Managed
- TLS enforced on connectors to referring physician offices, hospital discharge planning, and the clearinghouse, then monitored rather than assumed
- Mail flow rules that apply encryption automatically by recipient domain and detected content, with no staff step left to forget
- Data loss prevention rules that stop ePHI leaving in plaintext rather than logging it after the fact
- Personal email and consumer file-sharing blocked as an exfiltration path, so the friction workaround stops being available
The through line is that none of it depends on anyone remembering.
What Encryption Looks Like on Field Devices
- Device encryption enforced and reported per device through Intune, JumpCloud, or Apple Business Manager rather than assumed from policy
- Enrollment covering the personal phones running Axxess, WellSky, or Homecare Homebase apps, which is where most field ePHI actually sits
- Screen lock, passcode, and patch level enforced on those same devices, since those are the exposures a borrowed network actually creates
- Remote wipe of agency data on a lost device, or on a clinician who leaves without notice, which is where device recovery meets your employee offboarding process
- Encryption status produced as a report for the risk analysis file rather than reconstructed from memory during a survey
What Should You Ask a Provider to Show You?
These are not vendor selection questions so much as a fast way to find out whether a provider produces evidence or produces policy. The answers are usually clear within a minute.
- Can you show device-level encryption status on demand, or only that a policy exists?
- How do you enforce encryption on personal phones running EMR apps?
- Do you test the external recipient experience for encrypted email, or only configure the rule?
- Will you produce encryption evidence in a form that goes straight into our risk analysis file?
- Do you work with home health agencies specifically, or with medical practices generally?
What a Defensible Encryption Position Looks Like
A defensible position on the HIPAA encryption requirements for home health agencies has three parts, and none of them are exotic. The transmissions are listed. Each one has a determination attached, with a date and a name on it. The controls implementing those determinations report their own status, so the file shows what happened rather than what was intended.
Agencies that build that once stop rebuilding it under pressure. If the proposal is eventually finalized and the choice disappears, the agency that already encrypts and already documents will have very little left to change.
Ready to Put Your Encryption Decisions in Writing?
IT Total Care works with home health agencies across the San Francisco Bay Area on the controls behind these determinations: enforced encryption in transit, managed field devices, and evidence that goes straight into the risk analysis file. Our home-based care IT support covers device enrollment, email protection, and the reporting that makes an encryption position defensible. Learn more about our approach to healthcare IT.
Contact Us to talk through what your agency needs.




