A HIPAA risk assessment for home health agencies is a documented analysis of the risks and vulnerabilities affecting every piece of electronic protected health information, or ePHI, that the agency creates, receives, maintains, or transmits. The requirement sits at 45 CFR § 164.308(a)(1)(ii)(A). It applies to Medicare-certified home health and home hospice agencies across the San Francisco Bay Area regardless of headcount, revenue, or whether the agency has anyone on staff who works in IT.
One point is worth settling before anything else. The regulation says risk analysis. The search bar and most vendor marketing say risk assessment. They are the same obligation, nothing turns on which word an agency uses, and a vendor who insists otherwise is selling a distinction that does not exist.
What does turn on something is when the obligation is breached. A missing or stale analysis is itself the violation, independent of whether patient data is ever exposed.
What Does the Security Rule Require, and Which Agencies Does It Apply To?
The HIPAA Security Rule requires every covered entity to conduct an accurate and thorough assessment of the potential risks and vulnerabilities to the confidentiality, integrity, and availability of its ePHI. The requirement is not conditional on size, sophistication, or budget, and it applies to a 40-clinician home health agency exactly as it applies to a hospital system.
Scope matters here, and getting it wrong in either direction creates problems. Home health and home hospice agencies are covered entities, so the obligation is direct.
The most commonly misunderstood part of the requirement is the trigger. Federal investigators do not need a breach to cite a missing analysis. A breach is simply what causes them to look, and when they do, the analysis is the first document they ask to see.
What ePHI Does a HIPAA Risk Assessment for Home Health Agencies Have to Cover?
A HIPAA risk assessment for home health agencies has to cover all ePHI the agency creates, receives, maintains, or transmits, not only the records held inside the EMR. Scope is the single most common place an analysis falls apart, because the EMR is the obvious system and almost everything else is not.
Where ePHI actually lives in a working agency:
- Clinical documentation and scheduling platforms: Axxess, WellSky, KanTime, Homecare Homebase, or MatrixCare
- Email, file storage, and collaboration: Microsoft 365, SharePoint, and any mailbox or shared folder holding patient information
- The state-mandated electronic visit verification system, which generates and stores visit records the agency does not administer itself
- Clinician-owned phones and tablets running EMR mobile apps, which are ePHI locations whether or not the agency issued the device
- Remote access paths: VPN, remote desktop, and third-party portals used for referrals and payer coordination
The EVV line is where California agencies get caught. Medi-Cal requires electronic visit verification, which means most Bay Area home health agencies are generating ePHI inside a state system that no one in the building manages. That system and the data moving into it belong in the analysis by name, with the flow described rather than assumed.
Why Is OCR Penalizing Risk Analysis Failures?
The HHS Office for Civil Rights penalizes risk analysis failures because risk analysis failure is the most frequently cited Security Rule deficiency in its breach investigations. The pattern is consistent enough to plan around: an incident opens the file, and the finding that follows is about the missing document rather than the attack that exposed it.
What the April 2026 Settlements Found
On April 23, 2026, the HHS Office for Civil Rights announced settlements with four regulated entities following separate ransomware investigations, totaling $1,165,000 across breaches that affected more than 427,000 individuals. All four settlements cited the same root finding: no accurate and thorough risk analysis had been completed before the breach.
Each of the four also agreed to a corrective action plan under OCR monitoring for two years. The payment is the part that gets reported. The two years of oversight is the part that changes how an agency operates day to day, because it converts a one-time cost into two years of documentation, reporting, and scheduled proof that specific gaps were closed.
The four entities were not large health systems. They included a third-party administrator and a self-funded employer health plan alongside a multi-state women’s health network. Agency size has not been a shield in this initiative, and there is no reading of the record in which a mid-sized Bay Area agency is too small to be worth an investigator’s time.
Why 2026 Raised the Bar From Analysis to Risk Management
OCR confirmed in its January 2026 cybersecurity newsletter that the risk analysis enforcement initiative is expanding to cover risk management, which means agencies are now expected to show that identified risks were actually reduced rather than simply documented. The distinction is narrow on paper and significant in practice.
Under the older posture, producing an analysis was most of the defense. Under the current one, an analysis that lists a gap and stops is worse than useless in an investigation, because it establishes that the agency knew. The remediation record, dated and tied to specific findings, is what the document is now measured against.
Why Is a HIPAA Risk Assessment for Home Health Agencies Harder Than It Looks?
A HIPAA risk assessment for home health agencies is harder than the same exercise in a clinic because the asset boundary is not a building. ePHI leaves the office on every visit. What has to be assessed is a moving population of devices, logins, and access paths, most of which the agency never formally issued to anyone.
The Asset Boundary Is a Fleet of Personal Devices
The hardest assets to assess are the ones the agency does not own. A clinician who opens patient notes in an EMR app on a personal phone between two visits has created a live ePHI data flow, and that flow has to appear in the analysis by name. So does a director of nursing reviewing compliance documentation remotely from a home network, which is an access path most agencies have never inventoried at all.
Neither path is visible without tooling. Enrolling devices in Intune, JumpCloud, or Apple Business Manager through mobile device management for field devices is what makes personal-device ePHI inventoriable in the first place. Without it, an agency is describing a device population it has no mechanism to enumerate, which is exactly the kind of gap an investigator finds in an afternoon.
Shared Logins and Turnover Break the Access Picture
Shared credentials and clinician turnover are what make an access picture go stale fastest. A scheduler managing forty or more shifts from a login that three other people also use makes it impossible to attribute access to an individual. The analysis has to flag that as a risk rather than record it as one well-behaved account.
Turnover compounds it. Device and access records are stale within weeks unless departures feed them, which is why a documented offboarding workflow belongs inside the security program rather than beside it. A clinician who left without notice and still has EMR access on a personal phone is a recurring pattern in our home health client base, not an unusual finding.
What Must a Compliant Risk Analysis Contain?
A compliant risk analysis contains six elements: a defined scope, documented threats, evidenced vulnerabilities, a record of current safeguards, rated likelihood and impact, and a written risk management plan that carries those ratings forward. The list below is the overview. The difficulty is not in knowing the six, it is in doing each one against the agency’s real environment.
- Define scope first. Every system, device, and third party that touches ePHI, not just the EMR.
- Identify and document threats specific to your environment. Generic threat lists are a documented OCR deficiency rather than a shortcut.
- Identify vulnerabilities with evidence behind them. Scan output, gap assessments, and policy reviews, not assertions.
- Record the safeguards already in place, including what is intentionally not implemented and the reasoning behind that decision.
- Rate likelihood and impact for each risk, then carry those ratings into a written risk management plan.
- Treat the analysis as unfinished when it is written. Investigators now look for evidence that identified risks were actually reduced.
Where Agencies Get This Wrong on Their Own
Risk analyses fail in five predictable ways, and none of them require anyone at the agency to have been careless. Each is a consequence of running a security program part-time while also delivering care.
- The asset inventory is built once during a survey push and never reconciled against actual device sign-ins
- Personal devices running EMR mobile apps are left out entirely, because nobody can enumerate them without device management in place
- Shared scheduler logins are recorded as one asset when they represent uncontrolled access by several people
- Risks are documented and rated, and then nothing is remediated, which is the exact gap the 2026 expansion into risk management targets
- A vendor security questionnaire is mistaken for a risk analysis, and the agency ends up holding neither
There is a sixth pattern worth naming because investigators name it: one analysis, followed by light annual edits. That reads as a document being maintained rather than a program being run, and it is the specific shape OCR penalizes.
“We have seen multiple times where an agency bought a risk analysis that was little more than a template with their name on the front. An investigator can tell the difference because the threats listed are threats to a medical office with a server closet, not to forty clinicians carrying patient notes around on their own phones. The assessment has to describe your agency or it provides little value.”
Brendan Duebner, President of IT Total Care
Is the Proposed HIPAA Security Rule Update in Force Yet?
The proposed HIPAA Security Rule update is not in force. HHS published the proposal in the Federal Register on January 6, 2025, the comment period closed, and no final rule has been issued. The Security Rule already on the books remains fully enforceable in the meantime, and every obligation described above comes from that existing rule rather than the proposal.
The timeline has already moved once. The Office of Management and Budget’s regulatory agenda now shows July 2027 for final action, after an earlier May 2026 target passed with nothing published. Agenda dates are planning projections rather than binding deadlines, and the proposal could still be finalized as written, narrowed, delayed again, or withdrawn.
What the Proposal Would Change
If finalized as proposed, the rule would make explicit several things the current rule leaves to agency judgment.
The proposal would also require a documented ePHI asset inventory and a current network map, both reviewed at least once every 12 months and on any change to the environment that affects ePHI. That is the practical argument against waiting.
One caution, because it is currently costing agencies money. Some vendors are marketing the proposed rule as though it were already law, particularly the removal of the addressable designation on encryption. It is not law, and any compliance package sold on that basis deserves a harder look. Our walkthrough on preparing for the proposed Security Rule update separates what is enforceable today from what is still only a proposal.
What Can an IT Partner Do, and What Can It Not Do?
An IT provider cannot assume HIPAA liability for a covered entity.
What a partner can do is generate the technical evidence the analysis has to rest on, and then remediate what that evidence exposes. Agencies should expect an IT partner to help support HIPAA compliance, not to certify it. Certification is not a thing that exists under the Security Rule, and a provider offering it is describing something no one can deliver.
Where IT Total Care Plugs Into the Analysis
IT Total Care supplies the technical record behind a home health agency’s risk analysis and then closes what that record exposes. The work is deliberately evidence-first, because an assertion in a policy document is not what an investigator asks for.
- Automated asset discovery that replaces the manual spreadsheet, enumerating every endpoint, server, and cloud tenant touching ePHI from live data
- Device enrollment in Microsoft Intune, JumpCloud, or Apple Business Manager, which makes personal phones running EMR apps visible and inventoriable for the first time
- Entra ID sign-in and audit log review, which is what turns a user list into an access record of who actually reached ePHI
- Vulnerability scanning, which supplies the evidence layer expected behind every identified vulnerability
- Encryption and MFA status reported per device rather than asserted as policy
- A network map maintained as a living artifact rather than redrawn from memory before each survey
- Remediation tracked to closure, which is what the 2026 expansion into risk management now expects an agency to be able to show
Keeping the picture current between analyses is a separate discipline. Offboarding runs through a single workflow, so a clinician who leaves without notice loses EMR and Microsoft 365 access the same day. Onboarding during a high-volume hiring push enrolls devices as part of setup, so the record never falls behind headcount. Shared scheduler logins get replaced with named accounts, so access is attributable to a person rather than to a password three people know.
What to Ask an IT Provider Before Signing
Five questions separate a provider that can genuinely support a risk analysis from one that cannot, and each asks for evidence rather than a claim. They are worth asking before a contract, not after an incident.
- Will you sign a business associate agreement, and what does it actually commit you to?
- Can you produce a current ePHI asset inventory on demand, or only at project time?
- How do you enumerate personal devices running EMR mobile apps?
- Do you track remediation to closure, and can you show me the record?
- Do you work with home health agencies specifically, or with medical practices generally?
The value is in what a provider can show rather than what it says. Any of the five that produces a general answer instead of a document is the one worth pressing on.
The Analysis Is the First Document Investigators Ask For
A HIPAA risk assessment for home health agencies is not a compliance artifact an agency produces once and files. It is the document federal investigators request first, the foundation every other Security Rule obligation is built on, and the one most often found missing, stale, or borrowed from a template written for a very different kind of provider.
None of the work described here requires new technology. It requires someone to define the scope honestly, describe the agency’s actual environment rather than a generic one, and close what the analysis finds. Agencies that do those three things stop being the easy finding in an investigation.
Ready to Put a Current HIPAA Risk Assessment in Place?
At IT Total Care, we work with home health and home hospice agencies throughout the San Francisco Bay Area, from the Peninsula to the East Bay, to build and maintain the technical record a risk analysis rests on. Our IT support built for home health agencies covers asset discovery, device management, access review, vulnerability scanning, and remediation tracked to closure. Learn more about our approach to healthcare IT.
Contact Us to talk through what your agency needs.




