This guide explains why an ePHI asset inventory for home health agencies matters, how to build and maintain one on your own, and how IT Total Care handles it for your agency. The inventory is the artifact the rest of the security program rests on, including the HIPAA risk assessment for home health agencies that federal regulators ask for first.
1. Why Does an ePHI Asset Inventory for Home Health Agencies Matter?
An ePHI asset inventory for home health agencies matters because an agency cannot protect, assess, or remove access to something it has never written down. The inventory is the documented list of every system, device, and third party that touches electronic protected health information, meaning patient data held in electronic form. It turns assumptions into a record.
The difficulty is structural rather than technical. ePHI leaves the office on every visit, so the boundary is not a building or a server room. It is a moving population of devices, logins, and access paths spread across the agency’s territory.
Where the exposure sits:
- The scope is wider than the EMR. The inventory covers all ePHI the agency creates, receives, maintains, or transmits: Axxess, WellSky, KanTime, Homecare Homebase, or MatrixCare, and also Microsoft 365, SharePoint, and email.
- Personal devices are ePHI locations. A clinician opening patient notes in an EMR mobile app between visits has put ePHI on a phone the agency never issued. So has a director of nursing reviewing documentation from a home network.
- Shared logins hide who actually has access. A scheduler working forty or more shifts from a credential three colleagues also use looks like one asset on a spreadsheet and behaves like four.
- Turnover makes the record decay quickly. Clinician turnover is high enough that a device and access list goes stale within weeks unless departures feed it. An inventory built once describes an agency that no longer exists.
- Undocumented assets stay undetected. The IBM Cost of a Data Breach Report 2026 put the mean time to identify and contain a breach at 247 days across all industries. That is an all-sector figure rather than one about agencies your size, but a device nobody recorded is the kind of exposure that sits open that long.
What the Proposed Security Rule Update Would Require
The proposed HIPAA Security Rule update would require a documented technology asset inventory and a current network map, both reviewed at least once every 12 months and on any change to the environment that affects ePHI. It remains proposed. HHS published it in the Federal Register on January 6, 2025, no final rule has been issued, and the regulatory agenda now points to July 2027 for final action.
That is an argument for building the inventory now rather than waiting. The artifact the proposal would require is the same artifact that improves the analysis an agency already owes under the rule in force today. Our walkthrough on preparing for the proposed Security Rule update separates what is enforceable now from what is still only a proposal.
2. How Can a Home Health Agency Build an ePHI Asset Inventory on Its Own?
A home health agency can build the inventory in six steps: define the boundary, discover the devices that have actually reached ePHI, record one row per asset, add the systems and third parties that are not devices, draw the network map, and assign ownership with a review routine. None of the six is technically difficult. Keeping the result true a month later is the part that takes discipline.
Start from system data rather than from a walk around the office. Bay Area agencies routinely cover territory across San Mateo and Santa Clara counties with field staff who reach the office twice a month at most, so there is no version of this exercise that involves counting laptops on desks.
Step 1: Define the Boundary Before You Open a Spreadsheet
Decide what counts as in scope before recording anything, because a boundary drawn afterward is really a boundary drawn around whatever you happened to find. The boundary is every system, device, and third party that creates, receives, maintains, or transmits ePHI, not just the EMR. Write that definition at the top of the document and use it to settle arguments later. A front-desk laptop that never touches patient data still belongs in a general IT asset list, but it does not need a row here, and being explicit about that is what keeps the inventory usable instead of bloated.
Step 2: Discover the Devices That Have Actually Reached ePHI
Build the device list from evidence rather than from memory. Pull the active user list from Axxess, WellSky, or ClearCare and reconcile it against current payroll, which immediately surfaces accounts belonging to people who have already left. Then pull device and sign-in data from Microsoft 365 or Entra ID to find every device that has actually authenticated to a system holding ePHI. That list is usually longer than the one the office keeps. Personal phones are the gap: they become enumerable only once they are enrolled in mobile device management. Our guide to building a device inventory list covers the device-level detail underneath this step.
Step 3: Record One Row Per Asset, With the Fields That Matter
Give every asset its own row and capture the same fields for all of them, because an inventory with inconsistent columns cannot be sorted, filtered, or handed to anyone else. For each asset, record:
- Asset name and type
- Agency-owned or personally owned
- Operating system and version
- The application or platform through which it reaches ePHI
- What ePHI it touches, and where that data rests
- Encryption status
- Multi-factor authentication status
- Responsible party
Encryption and multi-factor authentication belong in the record as observed status rather than as policy. “Our policy requires MFA” and “MFA is enforced on this account” are different statements, and only the second one is an inventory entry.
Step 4: Add the Systems and Third Parties That Are Not Devices
Extend the inventory beyond hardware, because a large share of ePHI in a home health agency never sits on a device the agency can see. Include SharePoint sites and shared mailboxes holding patient information, which get missed because nobody thinks of a folder as an asset. Include e-fax and scanned intake, which become ePHI the moment they land in a digital queue. Include the electronic visit verification system used to confirm visits as a system-level entry, since the agency generates records there without administering the platform. Include every third party with ePHI access: the billing service, the clearinghouse, the answering service, and any remote coders.
Step 5: Draw the Network Map That Shows How ePHI Moves
Build a companion map showing how ePHI moves between the EMR, Microsoft 365, billing, and field devices. The inventory tells you what exists. The map tells you how patient data gets from one entry to the next, which is where the interesting questions live, because a system that looks isolated on a list is often two hops from a personal phone. It does not need to be elegant. Boxes and arrows on a single page, dated and stored with the inventory, is enough to be useful and enough to be shown.
Step 6: Assign Responsible Parties, Store It Safely, and Keep It Current
Name a responsible party per asset class rather than handing the whole inventory to one person, because a single owner for everything is an owner for nothing in practice. Store the finished record somewhere access-controlled, since an unprotected spreadsheet listing every system that holds patient data is its own exposure. Tie updates to onboarding and offboarding rather than to a calendar date, because turnover is what makes the record drift: a documented offboarding workflow is what feeds the inventory when someone leaves without notice.
Record the review date and the reviewer on every pass. The free Security Risk Assessment Tool published by HHS includes reviewed-by tracking for exactly this purpose.
Limitations: An ePHI asset inventory is accurate the week it is built and drifts every week after, and the drift is not caused by carelessness. A per diem clinician installs the EMR app on a second phone. A scheduler is handed a shared login during a staffing crunch and it is never revisited. A billing vendor changes subcontractors. A device is reassigned during a high-volume hiring push and nobody updates the row. Personal phones that were never enrolled cannot be enumerated at all, so they never make it onto the list in the first place. Agencies rarely fail at building the inventory. They fail at reconciling it against live system data month after month while also staffing visits, which is a capacity problem rather than a knowledge problem.
3. How Does IT Total Care Build and Maintain an ePHI Asset Inventory for Home Health Agencies?
IT Total Care builds and maintains the ePHI asset inventory for home health agencies as a live record drawn from system data rather than a spreadsheet someone updates when they remember. Every entry is reconciled against what accounts and devices are actually doing, so the record stays true between reviews instead of decaying quietly until the next survey.
What Our ePHI Asset Inventory Process Includes
Our process includes:
- Automated asset discovery: We enumerate every endpoint, server, and cloud tenant touching ePHI from live data, then reconcile that list against your EMR user roster and current payroll so the spreadsheet stops being the source of truth.
- Mobile device enrollment: We enroll devices in Microsoft Intune, JumpCloud, or Apple Business Manager, which is what makes personal phones running EMR apps visible and inventoriable for the first time.
- Sign-in and audit log review: We review Entra ID sign-in and audit logs to establish who actually reached ePHI and from which device, which is what turns a user list into an access record.
- Encryption and MFA status per device: We report the observed state of each device rather than restating what a policy says should be true.
- Vulnerability scanning: We supply the technical evidence that sits behind each entry, so an asset row is backed by findings rather than assumptions.
- Named responsible parties: We document a responsible party for each asset class alongside the technical record, so accountability lives in the same place as the data.
- A living network map: We maintain the map of how ePHI moves between the EMR, Microsoft 365, billing, and field devices as an ongoing artifact rather than something redrawn before each survey.
- Inventory tied to joiners and leavers: Offboarding runs through a single workflow so a clinician who leaves without notice loses EMR and Microsoft 365 access the same day. Onboarding during a high-volume hiring push enrolls devices as part of setup, and shared scheduler logins get replaced with named accounts so access is attributable to a person.
How the Inventory Stays Reconciled Between Reviews
The reconciliation is the part that matters most. An inventory built from live system data and checked against the EMR roster catches the drift that a manual list cannot, which is the difference between a record your agency can produce on request and one it has to rebuild first.
“The inventory is the boring documentation few take time to build but that many other items depend on. From our experience, the first discovery run at an agency always turns up devices the list never had on it, and it is almost always phones. This isn’t out of negligence, there was just never anyone owning this foundational task.”
Brendan Duebner, President, IT Total Care
Ready to Build an ePHI Asset Inventory That Stays Current?
At IT Total Care, we work with home health and home hospice agencies throughout the San Francisco Bay Area, from the Peninsula to the South Bay, to build the asset record a security program depends on and keep it reconciled against live system data. Our IT support built for home health agencies covers discovery, device enrollment, access review, and the ownership structure that keeps an inventory from drifting. Learn more about our approach to healthcare IT.
Contact Us to talk through what your agency needs.




