Mobile devices are central to how home health, home care, and home hospice agencies operate. Caregivers and coordinators rely on smartphones and tablets every day to document visits, communicate, and access critical systems in the field. But without a formal process for managing and securing those devices, agencies face real risks to patient privacy, HIPAA compliance, and operational continuity. Below are answers to the most common questions home-based care agencies have about mobile device management.
1. What is mobile device management, and why does it matter for home-based care agencies?
Mobile device management (MDM) is a category of software that allows organizations to enroll, configure, monitor, and secure the smartphones and tablets their teams use for work. For home-based care agencies, MDM is especially important because caregivers and coordinators work entirely in the field, often accessing sensitive patient information from devices that are difficult to control without a formal system in place.
2. What are the biggest risks of not having an MDM solution in place?
Agencies without MDM commonly face several compounding risks, including:
- No visibility into which devices are accessing company systems or patient data
- Former employees retaining access to apps and data after leaving the organization
- Lost or stolen devices with no ability to remotely lock or wipe them
- HIPAA compliance exposure from unprotected devices accessing ePHI
3. Do home-based care agencies have HIPAA obligations related to mobile devices?
Yes. Home health and home hospice agencies that access electronic protected health information (ePHI) on mobile devices have specific obligations under the HIPAA Security Rule. Those obligations include implementing access controls, encrypting ePHI, and having the ability to remotely wipe devices if they are lost or compromised. Unmanaged devices accessing ePHI create direct compliance exposure and can result in reportable breaches under HIPAA’s Breach Notification Rule.
4. What is the difference between company-owned devices and BYOD, and which is better for home-based care agencies?
Company-owned devices give agencies maximum control over security configurations but come with higher upfront costs and asset management responsibilities. BYOD (Bring Your Own Device) reduces procurement costs but introduces complexity around separating personal and work data. Many MDM platforms address this through containerization, which creates a secure work environment on a personal device without accessing personal content. There is no single right answer. The best approach depends on your agency’s size, budget, and workflow. The most important step is documenting whatever policy you choose in writing.
5. Which MDM platforms are commonly used by small and mid-sized home-based care agencies?
Common MDM platforms suited to smaller organizations include Apple Business Manager, Microsoft Intune, and JumpCloud. The right platform for your agency will depend on the types of devices your team uses, your existing technology environment, and your budget. An experienced managed IT provider can help you evaluate options and implement the platform that best fits your needs.
6. How does MDM help home-based care agencies manage staff turnover?
High turnover is one of the most significant security risks in home-based care. MDM allows agencies to revoke device access and wipe company data immediately when an employee leaves, rather than relying on manual processes that are easy to overlook during a busy transition. Integrating MDM into a formal offboarding checklist ensures that no departing employee retains access to company systems, apps, or patient information after their last day.
“We regularly see that home-based care agencies who effectively utilize a mobile device management solution fare far better than their competitors in HIPAA inspections, reduced employee turnover, and in receiving high care scores. In today’s day and age taking the time to correctly configure and manage a MDM solution is a must for those in the home care, home health, and home hospice industries”.
Brendan Duebner, President of IT Total Care
7. What security policies should be configured on work mobile devices?
At a minimum, every work device should have screen lock enabled, full device encryption turned on, and a strong passcode required. Beyond those baseline controls, agencies should also establish an app management policy that defines which applications are approved for work use and restrict access to unauthorized apps where possible. These settings should be enforced through your MDM platform rather than relying on individual employees to configure their own devices.
8. What should a home-based care agency do if a device is lost or stolen?
If a device is lost or stolen and your agency has MDM in place, the immediate steps are to remotely lock the device to prevent unauthorized access and, if the device cannot be recovered, initiate a remote wipe to erase all company data. Your agency should also document the incident and assess whether any ePHI was potentially exposed, as this may trigger HIPAA breach notification requirements. Having a written response plan before an incident occurs significantly reduces confusion and response time.
9. How often should home-based care agencies audit their mobile device inventory?
At minimum, agencies should reconcile their MDM enrollment records against their full device inventory on a quarterly basis. This helps identify devices that may have been missed during an offboarding, flagged for replacement, or enrolled without proper documentation. Agencies with higher staff turnover or larger device fleets may benefit from more frequent reviews. Regular audits are also an important part of demonstrating operational controls during a HIPAA audit or compliance review.
10. How can an MSP help a home-based care agency manage and secure mobile devices?
A managed service provider (MSP) specializing in home-based care can help agencies assess their current device landscape, define a device policy, select and implement the right MDM platform, and handle all enrollment and security configuration. An experienced MSP will also integrate MDM into onboarding and offboarding workflows, provide ongoing monitoring to keep policies enforced, and serve as a dedicated point of contact when device issues arise in the field. For agencies without dedicated internal IT staff, an MSP makes it possible to maintain a professional-grade mobile device management program without the overhead of managing it internally.
IT Total Care helps home-based care agencies throughout the San Francisco Bay Area strengthen cybersecurity, improve HIPAA compliance readiness, and build reliable IT processes that support operational continuity. If your agency is ready to take control of its mobile devices, our team can help design and manage a program that protects your organization, your employees, and your patients. Contact Us today to get started.




