A HIPAA shared responsibility matrix answers a question most home health agencies cannot answer on the spot: who owns each compliance function, the agency or the IT provider. Ask an administrator who approves the risk analysis and you will usually get a name. Ask where that is written down and the room goes quiet.
The same gap shows up in smaller places. A scheduler covering forty or more shifts a week works from a login that three other people also use. Everyone assumes the IT provider governs that access. Nobody has said so out loud, and nobody has written down who confirms it after a staffing change.
This guide covers why a HIPAA shared responsibility matrix matters for a home health agency, how to build one yourself in five steps, and how IT Total Care builds and maintains the document with the agencies we support.
1. Why Does a Home Health Agency Need a HIPAA Shared Responsibility Matrix?
A home health agency needs a HIPAA shared responsibility matrix because compliance work is split across two organizations and the split is almost never written down. The matrix records which functions the provider performs, which the agency performs, and which nobody has claimed, while there is still time to fix the third category.
Outside data supports treating the vendor relationship as part of the security picture rather than a way out of it. The Verizon 2026 Data Breach Investigations Report puts third-party involvement at 32 percent of breaches in its healthcare dataset, which describes healthcare as a whole rather than home-based care specifically. The report’s own conclusion is that security fundamentals have to be built into the contracts made with business associates and suppliers, not handled internally and assumed externally.
The pattern we see across home health clients is rarely a bad provider. The agency believed compliance was covered because the MSP said so, and nobody had ever written down who owned what. Our companion article on outsourcing HIPAA compliance for home health agencies covers what does and does not transfer. The practical question is not whether to outsource. It is which functions move and which stay, and the matrix is where that gets recorded.
Which Compliance Functions Usually Move to the Provider?
These are the functions that typically carry the provider in the performs column, and they are the natural place to start listing rows:
- Technical safeguard implementation. Access controls, encryption enforcement, audit logging, patching, and endpoint protection, meaning the software that secures individual laptops, tablets, and phones rather than the network around them.
- Device management for field clinicians. Enrollment of the phones and tablets clinicians carry between visits, with encryption status reported per device.
- Monitoring and alerting. Continuous watch on the systems holding ePHI, meaning electronic protected health information, which is what establishes a detection date when something goes wrong.
- Evidence production. The asset inventory, the network map, and encryption and MFA status per device, covered in our guide to building an ePHI asset inventory.
- Technical diligence on your other vendors. Reading a platform’s security attestations and reporting what they actually cover, as our guide to verifying a business associate’s safeguards walks through.
- Provisioning and deprovisioning. Access created and removed in step with onboarding and offboarding.
- Backup, recovery testing, and contingency plan execution. Restores run on a schedule and proven to work.
2. How Can a Home Health Agency Build a HIPAA Shared Responsibility Matrix on Its Own?
A home health agency can build a HIPAA shared responsibility matrix in five steps: write one row per compliance function, give every row four columns, assign each function row by row, put a named person in every agency cell, then walk the document with the provider and date it. Drafting takes an afternoon. Keeping it true takes discipline.
Step 1: Write One Row Per Compliance Function
Start from the Security Rule’s safeguard categories and give every compliance function its own row: risk analysis, risk management, access management, workforce training, incident response, contingency planning, business associate oversight, and the rest. Work from the agency’s obligations outward rather than from the provider’s proposal inward. A matrix built inward from a service catalog can only describe what the provider sells, and the rows that cause trouble are the ones nobody sells.
Step 2: Give Every Row Four Columns
Each row needs four columns: who performs the function, who approves it, who holds the evidence, and who is accountable if it fails. Four columns rather than one owner column exists for a specific reason. Performs and accountable are frequently different parties, and a single column hides that. The four-column layout makes the difference visible on the page, which is the only place it does any good.
Step 3: Assign Every Function, Row by Row
Work down the rows and write both sides of each one. Most rows split rather than land entirely with one party, and writing the split explicitly is what stops a function from drifting. A typical home health matrix assigns:
- Risk analysis. Provider produces the technical inputs, agency approves the scope and the conclusions, as covered in our guide to the HIPAA risk assessment for home health agencies.
- Risk management. Provider remediates, agency decides what gets remediated and accepts the residual risk.
- Asset inventory and network map. Provider generates them, agency owns and reconciles them against what it knows is in the field.
- Encryption. Provider enforces and reports status, agency makes and documents the addressable determination, which our guide to HIPAA encryption requirements for home health agencies covers in detail.
- Access provisioning. Provider executes, agency defines who gets what.
- Offboarding. Provider removes access, agency triggers the request and confirms completion.
- Workforce training. Provider may deliver it, agency owns the completion records and the sanctions.
- Business associate management. Provider performs the technical diligence, agency determines status and signs the agreement.
- Incident detection. Provider monitors and timestamps, agency owns the breach determination and the filings.
- Contingency planning. Provider runs backup and recovery testing, agency approves the plan and the recovery objectives.
- Policy set. Provider may supply templates, agency adopts, dates, and maintains them.
- Security Official designation. Agency only, with no provider column at all.
Step 4: Put a Named Person in Every Agency Cell
Every row needs a named person on the agency side, not a department. “Operations” is not an owner, and neither is “IT,” because no investigator has ever been satisfied by a job function. Rows the provider performs still need an agency approver; without one, that function has quietly moved regardless of what the contract says.
Expect to find rows neither party claims. That finding is the reason the exercise exists. Resist the urge to close the gap by assigning it to whoever is in the room, because an unowned row assigned under time pressure is still unowned in practice. Write it down as unowned, then fix it deliberately.
Step 5: Walk It With Your Provider, Then Date It and Set the Review
Walk the matrix with your provider line by line rather than emailing it over for comment. Sending it produces agreement. Walking it produces disagreement, which is what you want, because a disagreement surfaced in a conference room is cheaper than the same disagreement surfaced in response to an OCR request.
Where you and your provider read a row differently, write down both positions and resolve the difference in the contract rather than in the matrix. Attach the finished document to your HIPAA business associate agreement rather than filing it separately. Date it and version it, because its value in an investigation is showing what the split was at the time of the incident, not what it became afterward.
Then set the review. Review at contract renewal and whenever the service scope changes, since scope creep moves functions without anybody amending anything. Review after any incident as well, because incidents are what reveal which rows were aspirational.
Limitations: A HIPAA shared responsibility matrix is straightforward to draft and difficult to keep true, and the failures are consistent. The split ends up living in a sales conversation nobody wrote down. The provider’s service description gets treated as the matrix itself, so functions the provider never offered end up with no owner at all. Every row gets assigned to the provider, including the rows the rule places on the agency. And the document gets built once during an onboarding project and never revisited through two service expansions, by which point it describes a relationship that no longer exists. Agencies rarely fail at building the matrix. They fail at walking it again eighteen months later while short-staffed.
3. How Does IT Total Care Build a HIPAA Shared Responsibility Matrix With Home Health Agencies?
At IT Total Care, the matrix is built jointly at onboarding rather than inferred from a service agreement months afterward. We fill the rows we perform, name the rows we do not, and keep the document dated and attached to your business associate agreement so it still describes something real a year later.
Which Rows Does IT Total Care Fill?
- Technical safeguards implemented and reported rather than asserted. Access controls, encryption enforcement, audit logging, patching, and endpoint protection, with status you can pull rather than a claim you have to trust.
- Field devices enrolled and managed through Microsoft Intune, JumpCloud, or Apple Business Manager, with per-device encryption and MFA status produced on request.
- Monitoring that timestamps detection, so both notification clocks start from a date the agency can defend.
- Provisioning and deprovisioning executed against your access decisions, same-day on offboarding.
- Backup and recovery tested against your stated recovery objectives, rather than against a default nobody at the agency chose.
- Technical diligence on your other vendors, including what an attestation’s scope actually covers.
- Evidence assembled in the form your file needs: asset inventory, network map, encryption status, and access records.
How Does IT Total Care Keep the Matrix Honest?
Our process includes:
- A matrix built jointly at onboarding. The document is written with your team in the room, not reverse-engineered from a service agreement later.
- Rows we do not perform, named as such. That includes the rows no provider performs, which are the ones agencies are most likely to assume are handled.
- The matrix attached to the BAA, dated and versioned. One document, one date, one version history, so the split at the time of an incident is a matter of record.
- Review at renewal and after any service expansion. Scope creep then surfaces as an amendment rather than as an assumption nobody tested.
- Review after any incident. Incidents are when aspirational rows become visible, and that is the moment to correct them rather than restate them.
- A standing named contact on each side, per row. Escalation then does not depend on who happens to answer the phone.
“Clear communication is critical to any quality partnership. This is why we like to establish a clear understanding as early as possible with our clients. Once both sides understand what they other can/can’t do things tend to go smoothly.”
Brendan Duebner, President, IT Total Care
Ready to Find Out Which Rows Nobody Owns?
IT Total Care works with home health agencies from Santa Clara County to the East Bay on the compliance functions that can move and the evidence behind them. Our home-based care IT support covers managed field devices, access provisioning, monitoring, and the records your compliance file depends on. You can also read more about our approach to healthcare IT.
Contact Us to build the matrix with us, starting with the rows your current arrangement never assigned.




