Cybersecurity for home care agencies is governed by California law and private contracts far more often than it is governed by HIPAA. Most private-pay agencies are not HIPAA covered entities, and a great deal of published guidance stops at that sentence. It is the wrong place to stop. A Bay Area agency that never bills a payer electronically still holds client names, addresses, care plans, and shift notes, and California imposes both a security duty and a hard breach notification deadline on every business that holds that information.
This article maps what actually applies: the statutes that reach your agency regardless of HIPAA status, the obligations your own contracts quietly add, where risk concentrates in day-to-day home care operations, and the controls that reduce it.
Does HIPAA Apply to Your Home Care Agency?
For most private-pay home care agencies the answer is no, and the reason is narrower than competitors state. HIPAA coverage turns on transmitting health information electronically in connection with a HIPAA standard transaction, not on handling health information at all. Holding detailed client health information does not, by itself, make an agency a covered entity.
“HIPAA doesn’t apply” is where competitor content stops. It is not where your obligations stop, and everything below is what remains.
One exception matters before going further. An agency running a home health or hospice line alongside personal care is a covered entity for those lines and holds ePHI, meaning electronic protected health information, inside Axxess, WellSky, Homecare Homebase, KanTime, or MatrixCare. Different rules, different liability, and a different set of obligations from the ones this article covers.
Which California Laws Govern Cybersecurity for Home Care Agencies?
Two California statutes reach a home care agency whether or not HIPAA does. Civil Code section 1798.82 requires notice when personal information is breached. Civil Code section 1798.81.5 requires reasonable security procedures and practices for businesses that hold it. Neither contains a small-business exemption or an industry carve-out.
Section 1798.82 applies to any individual or business that conducts business in California and owns, licenses, or maintains computerized data containing personal information about California residents. It reaches out-of-state companies doing business here, and it does not scale its requirements to headcount or revenue. A twelve-caregiver agency in San Mateo County carries the same obligation as a national franchise.
Section 1798.81.5 operates before anything goes wrong. It requires a business holding personal information about a California resident to implement and maintain reasonable security procedures and practices appropriate to the nature of that information. No checklist is attached, which means the standard gets judged after an incident against what a reasonable operator in your position would have done.
What Does California’s Breach Notification Deadline Require?
What changed recently is the timing. SB 446, signed October 3, 2025 and effective January 1, 2026, replaced the old “most expedient time possible” standard with a fixed deadline: notice to affected California residents within 30 calendar days of discovery or notification of the breach.
Three details decide whether an agency can actually meet that deadline:
- Delay is permitted only for the legitimate needs of law enforcement, which requires a law enforcement agency to determine that notice would impede an investigation, or as necessary to determine the scope of the breach and restore the integrity of the data system. Internal deliberation is not a qualifying reason.
- A breach affecting more than 500 California residents requires a sample copy of the notice to be filed with the Attorney General within 15 calendar days of notifying those individuals. That second clock starts at consumer notice rather than at discovery, which is the single most misread part of the statute.
- Medical information is a triggering data element when combined with a client’s name. Care plans, shift notes, and diagnosis references living in ClearCare or WellSky Personal Care meet the statutory definition, so a breach of scheduling records is a notifiable breach.
Which Breaches Trigger the 12-Month Identity Theft Offer?
The 12-month identity theft prevention and mitigation offer under section 1798.82 attaches only where your agency was the source of the breach and the exposed data included a Social Security number or a government-issued identification number such as a driver’s license, California ID, passport, or military ID. A breach exposing client names and care plan content triggers notification without triggering that offer.
This one is worth getting right, because acting on the wrong version costs real money. Published summaries routinely state the trigger far more broadly than the statute does, and agencies end up buying twelve months of monitoring for every affected client on a breach that never required it.
Does the CMIA Apply to a Licensed Home Care Organization?
A licensed Home Care Organization is not a provider of health care under the Confidentiality of Medical Information Act by virtue of its license. The CMIA’s entity prong reaches clinics, health dispensaries, and health facilities licensed under Division 2 of the Health and Safety Code, and a Home Care Organization is none of those. That is also why it licenses through the California Department of Social Services rather than the Department of Public Health.
The CMIA can still reach an agency through its other defined categories, which cover contractors and certain businesses that receive medical information. Those are defined terms rather than a general rule about receiving records under contract, so an agency taking referrals from a home health agency, hospice, hospital, or Medi-Cal managed care plan should have counsel confirm where it lands. Where the CMIA does apply, it replaces section 1798.81.5 as the governing security standard, and it does not exempt the agency from breach notification.
Agencies that are HIPAA covered entities follow a different path entirely, combining HIPAA breach notification with Health and Safety Code section 1280.15.
What Do Your Contracts Add?
Contracts create security obligations that no statute imposes on you, and they are enforceable regardless of your HIPAA status. Business associate status in particular arrives by contract, not by license type. A referral relationship with a home health agency, hospice, or hospital can pull a non-covered home care agency directly into HIPAA obligations.
Once a business associate agreement is signed, its obligations are enforceable against your agency whether or not you would otherwise be covered. The document does the work, not your licensure. That is worth knowing before someone signs one to unlock a referral stream. See our breakdown of HIPAA business associate agreements and what OCR actually enforces.
A second channel is opening through Medi-Cal. CalAIM Community Supports contracts with Medi-Cal managed care plans can bring plan-imposed security terms to non-medical agencies. This is an emerging route rather than a universal obligation: Community Supports are elected plan by plan and county by county, and Personal Care and Homemaker Services is not offered by every plan in every county, so a Bay Area agency’s exposure depends on which plans in its service area have elected the benefit.
That channel does not depend on the CalAIM 1115 waiver. The Department of Health Care Services has confirmed that Community Supports covered as in-lieu-of services continue independent of the 1115 and 1915(b) approvals expiring December 31, 2026, so agencies should not treat the waiver’s expiration date as an expiration date for these contract terms.
Beyond payers, franchise agreements, hospital vendor addenda, and commercial payer contracts commonly impose multi-factor authentication, encryption, and incident reporting requirements that no statute would have imposed on you. Read what you signed before assuming what applies.
Where Does the Risk Actually Concentrate in Home Care Operations?
Home care operations concentrate risk in three places attackers already look: shared logins, personal mobile devices, and staff turnover. None of these is a technology failure. Each is a byproduct of how the work is scheduled and delivered, which is exactly why buying a product does not fix them.
Picture a scheduler covering forty or more shifts from a single ClearCare account that three other people in the office also use. When something goes wrong in that account, there is no way to attribute the access to a person, which means there is no way to scope the incident and no way to evidence what happened. The same login is also the one nobody wants to rotate, because half the office depends on it.
Around that sit two more openings. Caregivers clock in and view client information from personal phones between visits, on unmanaged devices the agency does not control and cannot wipe. And offboarding a caregiver who left without notice means credentials stay live until somebody remembers to disable them, which in most agencies is a person rather than a process.
How Common Are Phishing and Ransomware?
The threat data is not home-care-specific, and it should not be presented as if it were, but it points consistently in one direction. CISA reports that more than 90 percent of successful cyberattacks begin with a phishing email. IBM’s Cost of a Data Breach Report 2026, released July 29, 2026, attributes 17 percent of the breaches in its sample to phishing, the most common initial access vector for the fourth consecutive year. The two figures count different populations and are not two versions of the same number, but both name the inbox as the front door.
The same IBM report found that 39 percent of breached organizations experienced at least one ransomware attack in the prior year, up from 24 percent in 2023. For an agency whose scheduling system is also its documentation system, that is a continuity problem before it is a compliance problem.
Which Controls Matter Most in Cybersecurity for Home Care Agencies?
The controls below are the ones that measurably reduce risk in a distributed home care environment, and they map to the failure points above rather than to a generic security checklist. Each links to a full treatment. This section is the map, not the manual.
Access and the Human Layer
- Multi-factor authentication on every account holding client information, which is the single highest-value control in a shared-login environment.
- Password management, which is what replaces the shared scheduler login rather than simply documenting it.
- Security awareness training, given that phishing is the dominant entry point across every dataset above.
- Email security, since referral packets and care coordination arrive and leave by email all day.
Devices in the Field
- Endpoint protection on every device that touches client data.
- Endpoint detection and response, for what protection alone does not catch.
- A device inventory, because you cannot secure what you have never listed.
- Mobile device management for the caregiver phones running ClearCare or WellSky Personal Care.
- Device lifecycle management, so retired phones and laptops leave the organization without data on them.
Data, Access Lifecycle, and Availability
- Data backup, which is what makes a ransomware demand optional.
- SaaS backup for Microsoft 365 or Google Workspace, which the platform vendors do not provide for you.
- Onboarding that provisions access deliberately rather than by copying an existing caregiver’s permissions.
- Offboarding that removes access the day someone leaves, including the ones who leave without notice.
- Network stability, since availability is a security property and not only an operations one.
- Permission audits on shared document storage, whether SharePoint or Google Workspace.
The wider set of operational IT failures that create security exposure, including the ones that look like productivity problems first, sits in our overview of IT risks in home-based care.
Where Do Agencies Get This Wrong on Their Own?
The failures cluster, and they cluster in predictable places. In our experience none of them come from carelessness. They come from a reasonable decision made once and never revisited.
- The agency concludes HIPAA does not apply and stops there, never reaching section 1798.82 or section 1798.81.5.
- A business associate agreement gets signed by an operations manager to win a hospital referral relationship, and nobody tells the owner what it committed the agency to.
- Nobody wrote down the discovery date, so the 30-day clock cannot be evidenced even if it was met.
- The Attorney General filing is missed because the team assumed both clocks ran from discovery.
- Controls are bought as products without anyone deciding who the responsible party is for each one.
“The home care industry is incredibly complex even before adding HIPAA or California laws. Having a technical partner who can help your agency navigate these waters so you can focus on providing quality care is almost always a huge value add.”
Brendan Duebner, President of IT Total Care
What Can an IT Partner Do, and What Can It Not Do?
An IT partner supplies the controls, the detection, and the evidence. It does not supply the legal determinations. IT Total Care cannot decide whether HIPAA reaches your agency, cannot sign your business associate agreements on your behalf, and cannot make the breach determination that starts your 30-day clock. Those are yours, and any provider that claims otherwise is selling something it cannot deliver.
Two things follow from that. A home care agency that is not a covered entity still has an IT partner with access to client information, and that relationship carries its own contractual security terms in both directions. And where a business associate agreement does apply, IT Total Care signs as a business associate with its own direct obligations alongside yours. Agencies should expect an IT partner to help support compliance, not to hold it.
Standing Up the Controls
- Multi-factor authentication enforced across Microsoft 365 or Google Workspace and every platform holding client information, rather than offered as an option staff can decline.
- Named accounts replacing the shared scheduler login in ClearCare or WellSky Personal Care, so access is attributable to a person.
- Caregiver phones enrolled through Intune, JumpCloud, or Apple Business Manager, with encryption and screen lock enforced.
- Endpoint protection and detection deployed and monitored rather than installed and forgotten.
- Backup and SaaS backup configured and recovery tested, since an untested backup is a plan rather than a control.
- Provisioning and deprovisioning run as one workflow, so a caregiver who leaves without notice loses access the same day.
- Phishing simulation and awareness training delivered on a schedule, with completion records the agency keeps.
- Permission audits on shared storage, because a folder opened to everyone during a busy intake week stays open.
Being Ready for the Clock
- Monitoring that produces a defensible discovery timestamp rather than a recollection of when someone noticed.
- Evidence of whether data was encrypted at the time, since section 1798.82 turns on unencrypted personal information.
- Breach response rehearsed against both the 30-day consumer deadline and the 15-day Attorney General window, rather than filed as a plan nobody has read.
Handling What Your Contracts Added
- Business associate agreements and payer security addenda read for what they actually commit the agency to, before signature rather than after. Our guidance on verifying a business associate’s safeguards before signing covers what to ask for.
- Contract security terms mapped to controls, so an MFA or encryption clause becomes a configured setting rather than a promise.
- Agencies running both home care and home health lines supported on both sides of the boundary, with the covered-entity line held to the stricter standard and its HIPAA risk assessment kept current.
What Should You Ask an IT Provider Before Signing?
Five questions separate a provider who understands this landscape from one who will treat your agency like a medical practice. Ask them before the contract, not after the incident.
- Do you understand that we may not be a HIPAA covered entity and still have California obligations?
- Can you give us a defensible discovery timestamp and a scope reconstruction inside 30 days?
- Will you read our payer and referral contracts for the security terms they impose?
- How do you enforce controls on caregiver-owned phones?
- Do you work with home care agencies specifically, or with medical practices generally?
Where Should a Home Care Agency Start?
Start by separating the two questions that usually get merged. The first is what law reaches you, which is answered by reading your contracts and applying the California statutes above rather than by asking whether HIPAA applies. The second is what your operations actually expose, which is answered by looking at your shared logins, your caregivers’ phones, and what happens the day somebody stops answering the schedule.
Neither question requires a purchase to answer. Both are considerably cheaper to answer now than on day three of a 30-day notification clock.
Ready to Build Cybersecurity That Matches Your Actual Obligations?
IT Total Care works with home care, home health, and home hospice agencies across the San Francisco Bay Area, from the Peninsula through the South Bay, putting real controls behind client information and real evidence behind a breach timeline. Our approach to healthcare IT starts with what your contracts and California law already require of you, not with a product list.
Contact Us to talk through what your agency needs.




