Microsoft SharePoint is one of the most widely used platforms for document storage and collaboration in home health, home hospice, and home care agencies. But having SharePoint is not the same as using it well. Without a clear organizational structure, thoughtful access controls, and a process for reviewing permissions over time, a shared drive can quietly become one of the biggest security and compliance risks in your organization. Below are answers to the most common questions home-based care agencies have about SharePoint best practices.
1. Why does SharePoint organization matter for home-based care agencies?
A disorganized SharePoint environment makes it difficult for staff to find documents quickly, which slows down care coordination and increases the likelihood of errors. More importantly, when files are scattered without a clear structure, sensitive client information including care plans, financial records, and ePHI can end up stored in locations that were never intended to hold that type of content. A well-organized SharePoint environment improves efficiency and reduces compliance risk at the same time.
2. What is the principle of least privilege and why does it apply to SharePoint?
Least privilege is a security principle that means every user should have access only to the information required to perform their specific job. Applied to SharePoint, it means caregivers should not have access to HR files, billing staff should not have access to clinical records outside their scope, and no one should have broad access to folders simply because it was easier to grant it that way. Least privilege limits the damage that can result from a compromised account and reduces the risk of accidental data exposure.
3. What is a role-based access group and how should home-based care agencies set one up?
A role-based access group is a group of users who share the same job function and are assigned the same SharePoint permissions as a group rather than as individuals. Common groups for home-based care agencies include Caregivers, Schedulers, Billing, Clinical Leadership, and Administration. When permissions are managed at the group level, adding a new employee or changing someone’s role requires updating their group membership rather than adjusting permissions folder by folder. This approach keeps permission management consistent and scalable.
4. Which folders should be restricted to a limited group of users?
Any folder containing sensitive or regulated information should have restricted access limited to specifically authorized users. For home-based care agencies, this typically includes:
- Client records and care plans containing ePHI
- Human resources files including personnel records and performance documentation
- Financial records, billing data, and banking information
- Compliance documentation and audit materials
These folders should never use open sharing settings and should be reviewed during every permission audit.
5. What is a SharePoint permission audit and how often should one be conducted?
A permission audit is a scheduled review of who currently has access to each folder or document library in SharePoint. The goal is to confirm that access still aligns with current job roles, identify permissions that are outdated or no longer needed, and revoke access for any former employees or contractors. Most home-based care agencies should conduct a full permission audit at least twice per year, with additional reviews triggered by significant staff changes such as terminations, role changes, or departmental restructuring.
6. How does SharePoint access control relate to HIPAA compliance?
HIPAA’s Security Rule requires covered entities to implement access controls that limit access to ePHI to authorized users only. It also requires that those controls be regularly reviewed and updated. For home health and home hospice agencies using SharePoint to store or access patient information, this means having a documented permission structure, restricting sensitive folders appropriately, revocking access promptly when staff depart, and maintaining records that demonstrate these controls are in place and working. Uncontrolled SharePoint access can constitute a direct Security Rule violation.
7. What are the risks of using open or “Anyone with the link” sharing settings?
Open sharing settings allow anyone who receives a link to access a file or folder, regardless of whether they are an authorized user or even an employee of the agency. For folders containing client records, financial data, or any other sensitive information, this creates significant security and compliance exposure. If a link is forwarded, shared accidentally, or intercepted, the agency loses all control over who can view that content. Home-based care agencies should never use open sharing settings for anything other than fully public, non-sensitive materials.
8. How should SharePoint access be handled when an employee leaves?
SharePoint access should be revoked as part of a formal offboarding process and should happen as soon as a departure is confirmed. Former employees who retain access to shared drives containing client records, scheduling data, or internal communications represent an ongoing security and compliance risk. Agencies should maintain a documented offboarding checklist that includes SharePoint and all other cloud platforms as required steps, not optional follow-ups.
9. How does SharePoint security affect cyber insurance coverage?
Cyber insurance applications increasingly ask detailed questions about access controls, permission management, and how quickly access is revoked for departing employees. Agencies that cannot demonstrate role-based access, least privilege configuration, or a regular audit process may face higher premiums, reduced coverage limits, or difficulty obtainning coverage at all. A well-documented SharePoint permission structure is one of the most practical steps an agency can take to strengthen its cyber insurance position.
“Approximately half of the home-based care agencies we work with have SharePoint setup incorrectly when we start working with them. This incorrect setup via confusing folder structures, inaccurate permissions, and lack of clean-up have a significant negative effect on the team. Fortunately, by taking the time to correctly setup and regularly review their SharePoint we see home care, home health, and home hospice companies significantly improve their efficiency and provide better care.”
Brendan Duebner, President of IT Total Care
10. How can an MSP help home-based care agencies manage SharePoint permissions?
A managed service provider with experience in home-based care can design and implement a SharePoint environment that is organized, properly secured, and built for HIPAA compliance from the start. This includes building a role-based folder structure tailored to your agency’s workflow, configuring least-privilege access controls, enabling audit logging, conducting scheduled permission reviews, and ensuring access is revoked immediately when staff depart. An MSP also documents the permission structure so it remains consistent as your agency grows and your team changes.
Need Help Getting SharePoint Organized and Secured?
IT Total Care helps home-based care agencies throughout the San Francisco Bay Area build SharePoint environments that are organized, properly permissioned, and designed to support HIPAA compliance. From folder structure and role-based access controls to audit logging and scheduled permission reviews, our team manages the details so your agency can stay focused on patient care. Contact Us today to learn how we can help.




