Your agency is switching billing services. The new vendor sends over a signed business associate agreement, a one-page PDF with the words HIPAA compliant across the top, and a request for a data export so they can start working claims on the first of the month. The agreement is real, and everything in it is required by the rule. It also tells you nothing about whether the company on the other end can protect the visit documentation you are about to hand over. Knowing how to verify business associate safeguards before you sign is what closes that gap.
Start with the floor, because it explains why this work exists at all. HIPAA requires a covered entity to obtain satisfactory assurances in a written contract. It does not require the agency to confirm those assurances are true. Everything in this guide is risk management beyond what the rule obligates, which is exactly why it gets skipped, and exactly why the proposed Security Rule update would shift the burden of proof onto the vendor. This guide covers why verification matters for home health and home hospice agencies in the Bay Area, how to run the diligence yourself, and how IT Total Care handles it for agencies that would rather not.
1. Why Does It Matter to Verify Business Associate Safeguards in Home Health?
Verifying business associate safeguards matters because an agreement transfers obligations, not risk. When a vendor holding your patient data is breached, your agency is the one notifying patients, answering the surveyor, and explaining to referral sources what happened. The signed contract changes none of that.
Home health agencies also concentrate an unusual amount of patient information outside their own walls. Clinical records sit with the EMR vendor. Claims move through a billing service and a clearinghouse. After-hours calls run through an answering service. The Verizon 2026 Data Breach Investigations Report found third parties involved in roughly 32 percent of healthcare breaches across the 1,492 healthcare incidents it tracked, with third-party involvement across all industries rising 60 percent year over year. Those figures are healthcare-wide rather than home-health-specific, but an agency with six vendors holding patient data carries the same structural exposure a hospital system does, with none of the staff to watch it.
What Makes This Worth the Effort?
- The rule stops at assurances. 45 CFR 164.502(e) requires satisfactory assurances in a written contract. It does not require you to confirm the safeguards behind them exist. That gap is deliberate, and closing it is voluntary.
- The notification lands on your agency. A vendor breach becomes your patient notification and your survey exposure. Diligence is the only step that happens while that is still hypothetical.
- Scope is where attestations mislead. A vendor’s assessment report can be clean and irrelevant at the same time, because it covered a different environment than the one holding your data. Reading scope before findings is most of the skill.
- The proposed rule would move the burden. The Security Rule update published January 6, 2025 would require business associates to supply annual written verification that technical safeguards are deployed, backed by a subject matter expert’s written analysis and certification. It remains a proposal, with no final rule issued and a projected July 2027 target for final action. Our breakdown of where the HIPAA Security Rule update stands has the current status.
- Renewal is the cheap moment. Adding verification language when an agreement comes up for renewal costs nothing and positions the contract for the proposed requirement. Reopening a live agreement mid-term costs leverage you may not have.
This guide assumes you have already decided a vendor is a business associate. If you have not, start with what a HIPAA business associate agreement for home health agencies requires and which vendors trigger one.
2. How Can a Home Health Agency Verify Business Associate Safeguards on Its Own?
A home health agency can verify business associate safeguards in five steps: build the vendor list and confirm what is already on file, ask the diligence questions before any patient data moves, build the contract past the 164.504(e) minimum, require subcontractor flow-down in writing, and maintain a register with a review cadence attached to it. None of the five require technical expertise. The last two are where most agencies stop.
Step 1: Build the Vendor List and Confirm What Is Already on File
Start with a complete vendor list, because diligence performed on a list built from memory only protects the vendors you happened to remember. Three sources between them catch nearly everything. Accounts payable catches anyone you pay. The integration list inside your EMR catches anything connected to your clinical records, whether that platform is Axxess, WellSky, KanTime, Homecare Homebase, or MatrixCare. The admin console of your email and file-sharing tenant, Microsoft 365 or Google Workspace, catches the applications staff have granted access to without telling anyone.
- Apply the on-behalf-of test to every name on the combined list and record the answer, including the names that come back no
- Document your reasoning wherever the answer is unclear, since OCR looks at how a relationship actually works rather than at what either party called it
- Reconcile the list against your ePHI asset inventory so the two records do not drift apart
- Flag inherited relationships first. Vendors in place before current leadership arrived are where missing agreements concentrate
- Confirm a signed copy exists and can actually be produced, rather than confirming that one was signed at some point
Step 2: Ask the Diligence Questions Before Patient Data Moves
Ask while you still have leverage, which means before the contract is signed and before any patient data moves. A vendor competing for your business answers questions that a vendor already holding your records will not. Send them in writing and keep the replies, because those replies are the only record that diligence happened at all.
- Where does our PHI live, and who can reach it? Which systems hold it, in what regions, and which roles at the vendor have access to those systems.
- Is multi-factor authentication enforced on administrative access? Not offered. Enforced, on the accounts that can reach your data.
- How is our data encrypted at rest and in transit? Get the answer in writing rather than in a sales call.
- How quickly will you notify us of a security incident? Then compare the answer against the clocks your agency is actually working against.
- Who are your subcontractors? Your vendor’s subcontractors may touch your patients’ data, and you will not learn their names any other way.
- What supports the HIPAA compliant claim? Treat that phrase as a marketing statement until a document, an assessment, or a named control stands behind it.
Then weigh the answers against what the vendor actually does. An EMR host storing years of clinical documentation warrants scrutiny a shredding service does not, and applying identical diligence to both wastes effort you do not have. Proportion the work to the exposure.
Step 3: Build the Contract Past the 164.504(e) Minimum
The required elements at 164.504(e) are the starting point rather than the finish. They make an agreement valid. They do not give you notice you can act on, proof that data was destroyed, or any way to confirm safeguards exist. Five additions close most of that gap.
- Set an incident notification window in hours. Without unreasonable delay is not a deadline. Name a number.
- Require annual written verification that technical safeguards are deployed. This positions the agreement for the proposed rule and gives you something to ask for every year.
- Specify return or destruction of PHI at termination, and what proof you receive. A certificate of destruction naming what was destroyed and when, not an assurance in an email.
- Preserve your right to terminate for material breach. Section 164.504(e)(1)(ii) expects that mechanism to be available when a vendor problem surfaces. An agreement without it leaves you holding an obligation and no lever.
- Keep indemnification and cyber insurance terms separate from the HIPAA clauses. They are commercial protections rather than compliance ones, and mixing them in makes both harder to enforce.
The notification window matters more in California, where home health agencies and hospices answer to two clocks. The federal Breach Notification Rule allows up to 60 days. California Health and Safety Code section 1280.15 requires a home health agency or hospice licensed under sections 1725 or 1745 to report unlawful or unauthorized access to a patient’s medical information to the California Department of Public Health and to the affected patient no later than 15 business days after the agency detects it. A vendor that takes three weeks to tell you about an incident has consumed your entire state window before you knew there was anything to report.
Step 4: Require Subcontractor Flow-Down in Writing
Require in writing that your vendor imposes the same restrictions and conditions on any subcontractor that touches your patients’ data. The rule already obliges business associates to do this, and OCR enforces it directly. In May 2023 the agency announced a $350,000 settlement with MedEvolve, a practice management software vendor, after an exposed server disclosed the ePHI of 230,572 individuals and investigators found the company had never executed an agreement with a subcontractor.
Writing the requirement into your own contract gives your agency a contractual claim rather than only a regulatory complaint, and it pairs with the subcontractor question from step 2. Knowing the clause is in the document is not the same as knowing who is downstream. The two together are what make flow-down real rather than boilerplate.
Step 5: Maintain the BAA Register and Attach a Review Cadence
A register is one row per vendor, and it turns scattered diligence into a program. Build it once and maintain it, because a register accurate the week it was created and untouched for three years is the one that fails a survey. Each row carries the same fields.
- Service provided, and whether PHI is involved
- Agreement on file, with version and execution date
- Subcontractor flow-down present, yes or no
- Date of last review
- Responsible party
The cadence keeps the register alive, and it has to be written down rather than intended.
- Review annually, and additionally whenever a vendor changes its services, adds a subcontractor, or is acquired
- Re-paper any agreement signed before 2013, since the Omnibus Rule changed what a compliant agreement contains
- Route new vendor onboarding through the register, so an agreement becomes a prerequisite to sending PHI rather than a catch-up item
- Record what you did when a vendor could not or would not answer a diligence question, because proceeding anyway is itself a decision worth documenting
What Makes This Hard to Sustain Internally?
Limitations: Verifying business associate safeguards is not technically difficult, and almost no agency fails at the first pass. Agencies fail in the second year. The register is accurate the week it is built and drifts every week after. A new billing service gets added during a busy stretch and the questions never get asked, because nothing in the process forced them. Assessment reports arrive as forty-page PDFs and go unread, because nobody in the building can tell a clean report from a clean report covering the wrong systems. The renewal that was supposed to be the moment for adding verification language passes quietly and the agreement rolls over unchanged. None of that is carelessness. It is what happens when a recurring technical review has no owner and competes with delivering care.
3. How Does IT Total Care Verify Business Associate Safeguards for Home Health Agencies?
IT Total Care runs the technical side of vendor diligence for home health and home hospice agencies, so the questions get asked, the answers get tested where testing is possible, and the record exists when a surveyor or an insurer asks for it. Deciding which vendors are business associates stays with the agency, because that rests on how each relationship actually works. What we supply is the diligence behind those decisions and the access controls sitting underneath them.
What Does Our Process Include?
- Vendor claims tested where testing is possible. Whether multi-factor authentication is actually enforced on administrative access, and whether encryption is actually in force on the connection carrying your PHI, rather than whether a questionnaire says so.
- Notification commitments compared against your real clocks. We line a vendor’s promised window up against the Breach Notification Rule deadline and the state reporting deadline your agency is actually working against.
- Same-day deprovisioning when an assignment ends. The control most often missing when clinicians rotate through on short assignments.
- Device enrollment for staffed clinicians’ phones running EMR apps. So ePHI on a personal device is managed rather than assumed. Our guide to mobile device management for field staff covers what enrollment actually gives you.
“We have read clean assessments that were completely accurate but had nothing to do with the systems holding our client’s patient records. An agency that learns to check scope before findings catches more in ten minutes than most vendor questionnaires catch in forty pages.”
Brendan Duebner, President, IT Total Care
Ready to Put Real Diligence Behind Your Vendor Agreements?
IT Total Care works with home health and home hospice agencies across the San Francisco Bay Area to review vendor security documentation, test the claims that can be tested, and build the register that keeps the work from drifting. Our home-based care IT support covers vendor diligence, access provisioning, device enrollment, and the documentation surveyors ask to see. You can read more about our approach to healthcare IT.
Contact Us to talk through the vendors your agency is about to sign with, and the ones already in place.




