A HIPAA business associate agreement for home health agencies is the written contract that allows an agency to disclose patient information to an outside vendor. Under 45 CFR 164.502(e), a covered entity may hand protected health information, or PHI, to a business associate only after it obtains satisfactory assurances that the information will be safeguarded, and 164.504(e) sets out the clauses that assurance has to contain. Without that contract in place, the disclosure itself is the violation.
What trips up home health and home hospice agencies across the San Francisco Bay Area is not the rule. It is the two questions sitting on either side of it: which vendors actually need an agreement, and what happens after everyone signs. Most compliance content answers the first question wrong and skips the second entirely. This article covers both, along with what federal regulators are actually penalizing.
What Triggers a HIPAA Business Associate Agreement for Home Health Agencies?
A HIPAA business associate agreement for home health agencies is triggered by function, not by vendor category. The test is whether an outside party creates, receives, maintains, or transmits PHI on your agency’s behalf. If it performs a service for the agency and that service involves patient information, it is a business associate, whatever the contract happens to be called.
Disclosing PHI with no agreement in place is a standalone violation. No breach has to follow, no data has to be lost, and the vendor does not have to do anything wrong. Handing the information over is the act the rule prohibits.
Does Every Vendor Need a BAA?
No, and the belief that every vendor does is the most common error agencies inherit from generic compliance content. OCR’s own position is that no agreement is required where a vendor’s work does not involve PHI and any exposure would be incidental. A cleaning crew that empties a bin is not performing a service that involves patient information, even though it stands next to patient information every night.
Treatment disclosures between covered entities are the second exception people miss. Sending a patient’s chart to a referring physician is a permitted disclosure under the Privacy Rule, not a business associate relationship. That physician is not doing work on your agency’s behalf. They are treating the patient.
Why This Article Says PHI and Not ePHI
The terminology inverts on this topic, and the inversion causes real confusion. The business associate agreement requirement sits in the Privacy Rule, so PHI is the operative term throughout this discussion. ePHI, meaning electronic protected health information, applies to the Security Rule safeguard provisions at 164.314(a) and to the proposed rule discussed further down. Treating the two terms as interchangeable is how agencies end up applying the wrong standard to the wrong obligation.
Which Vendors Are Business Associates of a Home Health Agency?
A home health agency’s business associates are the outside parties that handle patient information as part of doing work for the agency. In practice the list is shorter than most agencies fear and longer than most agencies have written down. Six categories cover nearly every agency.
- The EMR or scheduling vendor: the platform hosting clinical records, whether that is Axxess, WellSky, KanTime, Homecare Homebase, or MatrixCare.
- The billing service or outsourced coder: anyone working claims from your visit documentation.
- The clearinghouse: the party transmitting those claims onward to payers.
- The answering service: after-hours calls routinely carry patient names and conditions, which makes this a business associate even though nothing about it feels like a data vendor.
- The IT provider: any firm holding administrative access to systems that contain PHI.
- The shredding or record storage vendor: handling charts is handling PHI, whether or not anyone reads a page.
The list is only useful if it comes from somewhere other than memory. Three sources between them catch nearly everything: accounts payable, the integration list inside your EMR, and the admin console of your email and file-sharing tenant, whether that is Microsoft 365 or Google Workspace. Run the functional test against every name on the combined list and write down the answer, including the ones that come back no. The noes are the part agencies skip and the part that shows the determination was made rather than assumed. Where the answer is unclear, record the reasoning, because OCR looks at how a relationship actually works rather than at what either party called it.
Which Vendors Are Not Business Associates?
The cleaning service, the landlord, and the courier who never opens the envelope are not business associates. Each may sit physically close to patient information without ever using or disclosing it, and incidental access does not create the relationship. Drawing that line deliberately matters, because an agency that signs agreements indiscriminately ends up with a binder it cannot maintain and no clearer picture of where its exposure actually sits.
One case turns on the facts rather than on the category, and that is the staffing agency. The answer depends on control rather than on what the contract is labeled, and it carries enough detail to deserve separate treatment.
What Does a HIPAA Business Associate Agreement for Home Health Agencies Have to Contain?
Section 164.504(e) sets the required elements of a HIPAA business associate agreement for home health agencies, and an agreement missing any of them does not satisfy the rule even with signatures on it. These are the floor rather than a best-practice checklist.
- Establish the permitted and required uses and disclosures of PHI by the business associate
- Require appropriate safeguards to prevent any use or disclosure the contract does not provide for
- Require the business associate to report uses and disclosures not provided for by the contract, including breaches of unsecured PHI
- Require it to bind its own subcontractors to the same restrictions and conditions
- Require it to make PHI available for individual access, for amendment, and for an accounting of disclosures
- Require it to make its internal records available to HHS for a compliance determination
- Require return or destruction of PHI at termination, where that is feasible
- Authorize your agency to terminate the agreement if the business associate materially breaches it
That last element is not decoration. It is the mechanism the rule expects your agency to have available when the obligation described in the next section is triggered.
What Does OCR Actually Enforce?
OCR enforces the disclosure, not the paperwork. Three things draw enforcement: sending PHI to a vendor with no agreement in place, failing to act on a vendor problem the agency already knew about, and the security failures underneath both. Signatures alone have never been the point.
The rule requires assurances in a contract, not verification, which is exactly why the paperwork so often exists while the safeguards behind it do not. Nothing in the Privacy Rule obliges an agency to audit a vendor’s controls. That gap between what the rule requires and what actually protects patients is where the practical risk lives.
The exposure has also shifted toward vendors over the past decade. HIPAA Journal’s analysis of the HHS Office for Civil Rights breach portal found business associate involvement in an average of 20 percent of large healthcare breaches between 2009 and 2017, 34 percent from 2018 through 2026, and 43 percent in the first half of 2026. That figure is healthcare-wide rather than home-health-specific, but the mechanism is identical at any size: one billing service or scheduling platform serves many agencies, so a single compromise cascades to all of them at once.
What Happens When PHI Goes Out With No Agreement?
The clearest covered-entity case on this point is a decade old and still the one to know. In April 2016, Raleigh Orthopaedic Clinic agreed to pay $750,000 after handing the X-ray films and PHI of roughly 17,300 patients to a vendor before executing an agreement. OCR did not allege that the vendor’s systems were breached. The disclosure was the violation.
What followed is the useful part. The corrective action plan required the clinic to build a process for assessing whether an entity is a business associate, to designate a responsible party for executing agreements before PHI goes out the door, and to retain the documentation for six years past the end of the relationship. That is a fair description of what a working program looks like.
What Is the Known-Pattern Duty at 164.504(e)(1)(ii)?
Section 164.504(e)(1)(ii) is the obligation agencies most often do not know they carry. Once your agency knows of a pattern of activity or practice by a business associate that amounts to a material breach of its contract, you must take reasonable steps to cure the breach or end the violation, and if those steps fail, terminate the contract if termination is feasible.
Failing to act on a vendor problem you already know about is itself a violation, independent of anything the vendor did. The rule does not ask you to monitor your vendors. It asks you to respond once you know.
One correction is worth carrying, because a great deal of compliance material still gets it wrong. The older version of this provision let a covered entity report the problem to the Secretary when termination was not feasible. The 2013 Omnibus Rule removed that alternative, and it is not in the current text. If a vendor or consultant tells you reporting is still an option, they are reading a version of the rule that has not existed for more than a decade.
Are Business Associates Directly Liable?
Yes. Since the HITECH Act and OCR’s 2013 final rule, business associates are directly liable for Security Rule compliance, impermissible uses and disclosures, breach notification to the covered entity, and executing agreements with their own subcontractors, among other obligations. Two recent settlements show what that looks like in practice.
- BST & Co. CPAs, $175,000, August 2025. An accounting firm acting as a business associate to a physician group. Ransomware reached its network through a phishing email in December 2019 and exposed the PHI of 170,000 individuals. OCR’s finding was a failure to conduct an accurate and thorough risk analysis.
- USR Holdings, $337,750, January 2025. A Florida business associate. Intruders reached a database holding the records of 2,903 people and deleted information, undetected from late August to early December 2018. The breach was small. The enforcement was not.
Direct liability on the vendor does not move your agency’s obligations anywhere. Both sides answer for their own compliance, and signing an agreement is not a transfer of risk.
What About the Penalty Numbers?
The flat $1.5 million annual cap still quoted across compliance content has not been current for years. HIPAA civil monetary penalties adjust annually for inflation, and for penalties assessed on or after January 28, 2026, the top-tier annual cap stands at $2,190,294. OCR has also applied lower annual caps to the less culpable tiers since 2019, so there is no single number to quote. Treat any vendor pitch built on the $1.5 million figure as information about the vendor.
“Most of the agencies that come to us have a folder of agreements but no list of vendors and no one who owns keeping the agreements up to date. In a survey they are going to want to know who your vendors are, what they do, and the relevant BAAs. Having an employee or partner who builds and maintains this list is a huge value add.”
Brendan Duebner, President of IT Total Care
Where Do Home Care Agencies Fit?
Non-medical home care agencies are not HIPAA covered entities by default, so the question reaches them from the opposite direction. A home care agency usually is not obtaining agreements from its vendors. It is signing one, as the business associate, because a covered entity asked it to.
That happens when the home care agency performs a function involving PHI on behalf of a covered entity: a hospital discharge program, a health plan contract, a hospice partnership. Under that path the home care agency is the vendor in the relationship, carrying the obligations the agreement imposes rather than imposing them on someone else. Participating in a Medicaid waiver program does not by itself establish the relationship. The specific contractual arrangement does.
The situation is more common in California than almost anywhere else, because the state splits oversight between two departments. The California Department of Public Health licenses home health agencies under Health and Safety Code section 1725 and following. The Department of Social Services licenses non-medical Home Care Organizations under the Home Care Services Consumer Protection Act at Health and Safety Code section 1796.10 and following. Peninsula and South Bay operators frequently hold both, often through separate legal entities sharing an office and a phone system. That puts one organization on both sides of the business associate question at the same time, and the boundary has to be drawn per line of business rather than per company.
Would the Proposed Security Rule Update Change This?
Not yet, and not the agreement requirement itself. The proposed Security Rule update published in the Federal Register on January 6, 2025 would layer a verification duty on top of the existing contract. Business associates would have to supply annual written confirmation that Security Rule technical safeguards are deployed, backed by a subject matter expert’s written analysis and certification.
The detail most coverage collapses is where the burden lands. It falls on the vendor to certify, not on the agency to audit. That is a materially different obligation from diligence an agency chooses to perform on its own, and agencies being sold an audit product on the strength of this proposal are being sold the wrong thing.
It also remains a proposal. No final rule has been issued, the comment period closed in March 2025, and the Office of Management and Budget’s Unified Agenda now carries the rulemaking on its long-term actions list with a projected July 2027 target for final action. That is a planning estimate, not a binding date. Our fuller breakdown of where the HIPAA Security Rule update stands covers what it would change and what it would not.
Agencies adding verification language to their agreements at renewal are building toward the proposed requirement rather than waiting for it, which costs nothing if the rule never lands.
Where Do These Agreements Break Down in Practice?
Business associate programs fail in a small number of predictable ways, and none of them involve anyone being careless. They are structural gaps: no list, no owner, no trigger. Six failures account for most of what we find.
- The binder becomes the work. Agreements are collected, filed, and never examined again. Nothing behind the signature is ever tested.
- Nobody can produce the signed copy. A surveyor or an insurer asks, and three people go looking. Knowing an agreement was signed at some point is not the same as being able to produce it.
- A vendor is added mid-year. An operations manager signs up a transcription service or a scheduling add-on, and the agreement never happens because nothing in the process required it first.
- Pre-Omnibus agreements sit unamended. The 2013 Omnibus Rule changed what a compliant agreement contains. Anything signed before then is very likely missing required elements.
- A staffing relationship is papered the wrong way. An agreement is executed over a relationship that contradicts how the clinicians actually work day to day, creating a written record that undercuts the agency’s own position if anyone examines it.
- A known vendor problem goes nowhere. Someone notes it internally. Nothing is cured, terminated, or documented, which is the 164.504(e)(1)(ii) failure described above.
The relationships that go missing are almost never the new ones. In our experience with home health clients, the gap shows up in what the agency inherited. An answering service has been taking after-hours calls since before the current administrator arrived. A billing service has been working claims for six years. Somebody signed an agreement at the start. Nobody can produce it now, and nobody is certain it contained what it needed to contain.
What Can an IT Partner Do, and What Can It Not Do?
An IT partner cannot tell you which of your vendors are business associates. That determination belongs to the agency and rests on how each relationship actually works, not on what either party calls it. An IT partner also cannot assume your HIPAA obligations, and signing an agreement with your MSP does not move liability off the agency.
What an IT partner supplies is the technical diligence on your vendors and the access controls sitting behind your own determinations. Expect a provider to help support HIPAA compliance. Do not expect one to certify it, for your agency or for your vendors, because no provider is in a position to do that.
What Technical Diligence Can an IT Partner Run on Your Vendors?
- Security attestations and assessment reports reviewed on your behalf, starting with scope rather than findings, since a clean report covering the wrong systems tells you nothing.
- Vendor claims tested where testing is possible: whether multi-factor authentication is actually enforced on administrative access, and whether encryption is actually in force on the connection carrying your PHI.
- Notification commitments compared against your clock. A vendor promising notice without unreasonable delay is not aligned to the Breach Notification Rule deadline your agency is actually working against.
How Should Staffed and Contracted Clinicians Be Provisioned?
Access control is where a workforce determination either holds up or falls apart. If your agency treats a clinician as a member of its own workforce, the access has to be controlled by your agency in fact, and the system records have to show it.
- Named accounts for staffed clinicians, never a shared login
- Access scoped to assigned patients and time-limited to the assignment period
- Same-day deprovisioning when an assignment ends, which is the control most often missing when clinicians rotate through.
- Device enrollment covering staffed clinicians’ phones running EMR apps, so ePHI on a personal device is managed rather than assumed. Our guide to mobile device management for field staff covers what enrollment actually gives you.
- Contracted therapy companies supplying physical, occupational, or speech services handled as business associates on the access side too, with their own accounts rather than borrowed credentials
- Access records that evidence the control you claimed, so the position rests on system data rather than on the contract alone
What Should You Ask an IT Provider Before Signing?
- Will you sign a business associate agreement, and will you accept the same annual verification clause you would tell us to require of everyone else?
- Will you review our vendors’ security attestations, or does that sit outside your scope?
- How do you provision and deprovision staffed clinicians who rotate through on short assignments?
The answers are informative either way. A provider that will not accept the clause it recommends to you is telling you something worth hearing.
Ready to Find Out Which of Your Vendors Actually Needs an Agreement?
Every question on this page comes back to the same two disciplines: deciding deliberately who is a business associate, and being able to show the work. Agencies that do both stop having this problem, and the contracts become the easy part.
IT Total Care helps home health and home hospice agencies throughout the San Francisco Bay Area build the vendor inventory, run the technical diligence behind each determination, and put in place the access controls that make a workforce position hold up. Our home-based care IT support covers vendor security review, access provisioning, device enrollment, and the documentation surveyors ask to see. You can also read more about our approach to healthcare IT or how we support home health agencies specifically.
Contact Us to talk through which of your vendor relationships need an agreement, and which ones do not.




