Is public Wi-Fi a HIPAA violation for home health clinicians? The question comes up in nearly every policy review, usually right after somebody notices that visit notes are being finished in a parking lot. The short answer is no. The useful answer is longer, because the things that actually create exposure on a borrowed network are mostly not the things a public Wi-Fi policy addresses. Below are the questions home health agencies across the Peninsula and South Bay ask most often.
1. Is Public Wi-Fi a HIPAA Violation for Home Health Clinicians?
No. Using public Wi-Fi is not by itself a HIPAA violation, and no provision of the Security Rule names it. The rule cares whether ePHI is protected while it moves, not who owns the router it passed through. A clinician on a coffee shop network with a properly protected connection is in a better position than one on the office network sending an unprotected attachment.
For nearly every home health workflow, the risk analysis lands on encrypting the traffic, which is why the practical expectation is that ePHI moves protected regardless of the network underneath it. The rule structure behind that sits in our piece on HIPAA encryption requirements for home health agencies.
2. Why Do Home Health Clinicians End Up on Public Wi-Fi at All?
Because the work happens where the signal does not. A clinician finishes visit notes from a coffee shop or a patient’s family Wi-Fi because the home itself has no usable signal and the note will lose accuracy if it waits until evening. Assessment documentation syncs from Axxess, WellSky, or Homecare Homebase on a phone between visits, often from a parked car, on whatever connection is available.
In the denser parts of San Mateo and Santa Clara counties, the nearest usable connection is almost always somebody else’s. A policy written as though clinicians only work from the office is a policy about a workflow the agency does not have.
3. Do EMR Apps Like Axxess and WellSky Protect the Connection on Their Own?
Largely, yes. EMR mobile apps from Axxess, WellSky, and Homecare Homebase transmit over TLS, which protects the session between the app and the platform regardless of the network underneath it. Someone else sitting on the same coffee shop network sees encrypted traffic rather than readable visit notes.
That protection covers the app’s own traffic and nothing beyond it. A browser tab, a file downloaded onto the phone, or a message sent outside the app is a separate question with a separate answer.
4. What Actually Creates Exposure on a Coffee Shop Network?
The device and the person holding it, far more than the network. The exposures worth worrying about are:
- A spoofed access point the phone joins automatically because it recognizes the network name
- An unpatched device carrying a known vulnerability that does not need the network’s help
- An unlocked screen left facing the room while the clinician orders coffee
- Somebody reading over a shoulder, which no amount of encryption addresses
IBM’s Cost of a Data Breach Report 2026 put the average healthcare breach at $6.64 million and the mean time to identify and contain a breach at 247 days. Those figures describe healthcare as a whole rather than home-based care specifically. The part that matters for a field clinician is the timeline: a compromised phone stays compromised for far longer than any coffee shop visit lasts.
5. Do Home Health Clinicians Need a VPN on Public Wi-Fi?
A VPN is worth having and is not required by rule. It adds a layer by tunneling traffic between the device and a network the agency controls, which helps for reaching internal resources and for traffic that is not already protected. What it does not do is fix an application that transmits insecurely, because a VPN protects the path rather than the contents.
Requiring one is an operational decision any agency can reasonably make. Presenting it as a HIPAA requirement is not accurate, and staff tend to notice when a policy overstates its own authority.
6. Is Cellular or a Personal Hotspot Safer Than Public Wi-Fi?
Generally yes, and preferring it is an operational choice rather than a compliance requirement. A cellular connection or a personal hotspot removes the shared-network exposures entirely, and for a clinician moving between visits it is usually the simpler default to standardize on.
No rule requires it, and that is worth saying plainly inside the agency. Make cellular the norm because it removes variables and costs a data plan, not because somebody said the Security Rule demands it.
7. Should a Home Health Agency Ban Public Wi-Fi in Its Policy?
Usually not, because the ban will not hold. Policy should govern the device and the application rather than banning a category of network that clinicians will use anyway when the alternative is not finishing the note. A blanket ban nobody follows is weaker evidence than a narrower rule that does hold, because an unfollowed rule documents the distance between what the agency required and what it actually manages.
The common failure pattern is a policy that bans public Wi-Fi while the EMR app, the device lock, and patching all go unmanaged. That agency has addressed the least important exposure and left the real ones untouched.
8. What Should the Agency’s Written Position on Public Wi-Fi Say?
It should describe what the agency actually controls. A workable written position covers:
- Which applications are approved for clinical documentation in the field
- That the device is managed, locked, and patched, with those settings enforced rather than requested
- What a clinician should do when no trusted connection is available
- Which connection type the agency prefers, stated as a preference rather than as a rule nobody can enforce
Document that position in the risk analysis rather than in a standalone policy file, so the answer is defensible rather than improvised on the day somebody asks.
9. What Can an IT Partner Do About This, and What Can It Not Do?
It can manage the device. It cannot make the determination on the agency’s behalf, because that decision belongs to the covered entity and lives in its risk analysis. What a partner supplies is enforcement and evidence: screen lock, passcode, and patch level enforced and reported across the phones clinicians actually use, through a management platform such as Intune, JumpCloud, or Apple Business Manager. Those are the exposures a borrowed network genuinely creates, and they sit inside the wider subject of endpoint protection for field devices.
Two claims deserve scrutiny along the way. A vendor telling you its platform makes your agency HIPAA compliant is making a claim no vendor can make. What to expect instead is a partner that helps support HIPAA compliance rather than certifying or assuming it.
10. What Should You Ask an IT Provider Before Signing?
Ask for evidence rather than assurances. Five questions separate a provider that produces proof from one that produces paperwork:
- Can you show device-level encryption status on demand, or only that a policy exists?
- How do you enforce encryption on personal phones running EMR apps?
- Do you test the external recipient experience for encrypted email, or only configure the rule?
- Will you produce encryption evidence in a form that goes straight into our risk analysis file?
- Do you work with home health agencies specifically, or with medical practices generally?
The third question points at a subject with its own answer, which is covered step by step in our guide to sending ePHI by encrypted email.
“Nine times out of ten the policy we inherit says no public Wi-Fi, and nine times out of ten the clinicians are on it anyway, because the alternative is driving back to the office to write a note. We would rather see a rule that says the phone is locked, patched, and managed, and the app is the one we gave you. That way things can be setup once and your team doesn’t have to think about it over and over.”
Brendan Duebner, President of IT Total Care
Still Asking: Is Public Wi-Fi a HIPAA Violation for Home Health Clinicians?
IT Total Care works with home health agencies across the San Francisco Bay Area on the part of this question an agency can actually control: managed field devices, enforced screen locks and patching, approved applications, and a written position that holds up when a surveyor reads it. Our home-based care IT support covers device management, documentation, and the reporting behind both. Learn more about our approach to healthcare IT.
Contact Us to talk through what your agency needs.




