Outsourcing HIPAA compliance for home health agencies moves the work of compliance, not the accountability for it. An IT provider can implement the safeguards, run the monitoring, and produce the evidence. Your agency still answers for the decisions underneath all of it.
For agency owners and administrators across the San Francisco Bay Area, that turns a broad buying question into a specific one. Not whether to outsource, but which functions actually move to the provider, which stay with the agency, and which quietly end up with nobody because both sides assumed the other had them.
One moment makes the split concrete. A field clinician parks outside a client’s home in San Mateo County and opens the day’s visit notes in Axxess or WellSky on a personal phone. Encryption on that device, the access rules behind that login, and the record of who reached what and when are three different responsibilities, and they do not all sit in the same place. What follows is where each one lands.
What Does Outsourcing HIPAA Compliance for Home Health Agencies Actually Move?
Outsourcing HIPAA compliance for home health agencies moves execution and evidence, not exposure. HHS guidance on cloud services sets the structure plainly. A vendor that creates, receives, maintains, or transmits ePHI, meaning electronic protected health information, is a business associate with its own direct obligations under the HIPAA Rules, and the covered entity keeps its own.
Both positions exist at once and neither absorbs the other. The same HHS guidance adds the corollary that rarely comes up in a sales meeting: a vendor is not responsible for compliance failures traceable solely to the customer’s own actions or inactions.
Enforcement follows that structure. When the HHS Office for Civil Rights announced four ransomware settlements on April 23, 2026, it counted 13 completed investigations under its Risk Analysis Initiative, and a number of those actions were brought against business associates rather than the providers they served. A vendor can be penalized for its own failures without a single one of your agency’s obligations moving across.
A business associate agreement documents that split. It does not transfer it, which is the most expensive misreading in this category. Our guide to the HIPAA business associate agreements for home health agencies covers what the document does and does not do.
So the practical question for an agency owner is not whether to outsource. It is which functions move and which stay.
Which Compliance Functions Can a Home Health Agency Delegate?
A home health agency can delegate the technical execution of the Security Rule: the safeguards themselves, the systems that run them, and the records proving they ran. These are the functions where an outside team with the right tooling will outperform an administrator managing technology between other responsibilities.
The work that genuinely moves to an IT provider includes:
- Technical safeguard implementation. Access controls, encryption enforcement, audit logging, patching, and endpoint protection, meaning the software that secures individual laptops, tablets, and phones rather than the network around them.
- Device management for field clinicians. Enrolling the phones and tablets that travel to client homes, then reporting encryption status per device
- Monitoring and alerting. Continuous watch on the systems holding ePHI, which is what establishes a defensible detection date when something goes wrong
- Evidence production. The asset inventory, the network map, and encryption and MFA status per device, assembled in the form your file needs. Our guide to building an ePHI asset inventory covers what that record has to contain.
- Technical diligence on your other vendors. Reading an EMR or billing platform’s security attestations and telling you what they actually cover, which we walk through in our guide to verifying a business associate’s safeguards.
- Provisioning and deprovisioning. Creating and removing access in step with onboarding and offboarding, so a departing caregiver’s account closes when the departure is confirmed rather than weeks later.
- Backup, recovery testing, and contingency plan execution. Running the restores, and proving they worked.
Every item on that list is work. None of it is a decision.
Which HIPAA Functions Cannot Be Delegated, No Matter What You Sign?
Eight functions stay with the agency under every arrangement, because each one is a decision rather than a task. A provider can prepare the inputs, draft the language, and hand you the analysis. It cannot make the call, and it cannot be the party held to account when the call turns out to be wrong.
- Designating the Security Official. 45 CFR 164.308(a)(2) requires the agency to identify the person responsible for developing and implementing its Security Rule policies, and that person is yours to name
- Approving the risk analysis and the risk management plan that follows from it. A vendor can run the scans. Only the agency can accept the scope and the conclusions, as our guide to the HIPAA risk assessment for home health agencies explains.
- Determining which encryption decisions are reasonable and appropriate, and documenting why. Encryption is addressable, which makes the written determination the agency’s own, covered in our guide to HIPAA encryption requirements for home health agencies.
- Deciding which of your vendors are business associates and executing the agreements. Your IT partner can tell you what a vendor touches. Whether that relationship needs a signed agreement is your agency’s determination.
- Making the breach determination and filing the notifications.
- Sanctioning workforce members who violate policy. No outside company can discipline your staff.
- Adopting the policies themselves. A vendor’s template is not your agency’s policy until your agency adopts it, dates it, and stands behind it.
- Training the workforce. A partner can deliver the training. It cannot own whether your staff completed it.
Why Is the Security Official Designation the Hard Case?
The Security Official designation is the hard case because the title sounds technical and the duties are not. Section 164.308(a)(2) asks for the person responsible for developing and implementing the Security Rule policies and procedures, which describes an accountability role rather than an engineering one.
Enumerate what sits underneath it and the mismatch becomes obvious: risk analysis and risk management, workforce security and sanctions, security awareness training, contingency planning, periodic evaluation, business associate oversight, facility access controls, and incident response. Technical safeguards are one of three safeguard categories in the rule, and the administrative category is the largest by a wide margin.
Agencies still default to naming the IT manager or the MSP account contact, because ePHI reads as a technology problem. The person who can be sanctioned by your agency, sit through a survey, and answer to the owner is not the same person who patches the servers.
What Is a Vendor’s HIPAA Compliance Claim Actually Worth?
There is no HIPAA certification, so no vendor holds one. HHS states in its own guidance that nothing in the Security Rule requires a covered entity to certify its compliance, that HHS does not endorse or otherwise recognize private organizations’ certifications regarding the Security Rule, and that holding one does not absolve a covered entity of its legal obligations.
HHS goes one step further, and this is the line worth carrying into a vendor meeting: obtaining a certification does not prevent HHS from later finding a violation. “HIPAA certified” describes a purchase, not a regulatory status.
What About SOC 2, HITRUST, and ISO 27001?
SOC 2, HITRUST, and ISO 27001 are real attestations, and a provider holding one has submitted to outside scrutiny against a defined framework. None of them is HIPAA compliance, yours or theirs. Read an attestation as evidence about a vendor’s own controls, then read its scope, because scope is where these documents usually stop short of what an agency assumed they covered.
Two claims should slow a signature rather than speed it. A provider offering to be your compliance department is describing a role the rule does not permit it to hold. A provider guaranteeing compliance is promising an outcome it does not control.
The pattern we see across home health clients is quieter than either of those. The agency believed compliance was covered because the MSP said so, and nobody had ever written down who owned what.
“Unfortunately there are a number of IT and cybersecurity providers who advertise that they handle HIPAA without disclosing what that actually means. They take the time to setup their systems but don’t explain what responsibilities still live with their client. Their clients have no idea the risk they’re unknowingly assuming until things go south.”
Brendan Duebner, President, IT Total Care
Where Does Outsourcing HIPAA Compliance for Home Health Agencies Go Wrong?
Outsourcing HIPAA compliance for home health agencies goes wrong in a predictable way. Nobody writes the split down, so each side acts on a version of it that exists only in memory, and the gaps stay invisible until somebody outside the relationship asks a direct question.
The recurring failures:
- The split lives in a sales conversation nobody documented.
- The vendor’s service description is treated as the division of labor, so functions the vendor never offered end up with no owner at all.
- Every line is assigned to the vendor, including the lines the rule places on the agency.
- The Security Official is the MSP’s account manager, named in a policy the agency has never read.
- A certification logo on the vendor’s website is accepted as evidence of the agency’s own compliance.
- The division of labor was agreed once during an onboarding project and never revisited through two service expansions.
None of these look like negligence from inside the agency. They look like a working relationship, right up until an investigator asks who approved the risk analysis.
Does California Law Change the Calculation?
California adds a second obligation that outsourcing does not touch. Under the Confidentiality of Medical Information Act, a provider of health care that creates, maintains, stores, or disposes of medical information must do so in a manner that preserves confidentiality, and negligent handling carries remedies under Civil Code section 56.36. The statute names the provider.
There is no business associate construct in that sentence. Where HIPAA gives patients no private right of action, the CMIA gives them one, with nominal damages of $1,000 available without proof of actual harm. A May 2026 California Supreme Court decision made those claims easier to bring, holding that a plaintiff does not have to show the data was actually viewed.
For a home health agency in this market, the practical translation is short. A contract can move who configures the encryption. It cannot move who a California plaintiff names.
What Should a Home Health Agency Expect From an IT Partner?
Expect an IT partner to help support HIPAA compliance, not to hold it. A MSP cannot hold your Security Official designation, approve your risk analysis, or make your breach determinations, and any provider offering to do those things is offering something the rule does not permit.
IT Total Care is a business associate with its own direct obligations under the HIPAA Rules, and those sit alongside your agency’s rather than in place of them. We do not sell a HIPAA certification, because there is none to sell. What we supply is execution on the functions that can move, and the evidence behind them.
Which Functions Can an IT Partner Actually Fill?
- Technical safeguards implemented and reported rather than asserted. Access controls, encryption enforcement, audit logging, patching, and endpoint protection, with status you can see instead of a claim you have to trust.
- Field devices enrolled and managed through Microsoft Intune, JumpCloud, or Apple Business Manager, with per-device encryption and MFA status produced on request
- Monitoring that timestamps detection, so both the federal and the California notification clocks start from a date you can defend
- Provisioning and deprovisioning executed against your access decisions, same-day on offboarding.
- Backup and recovery tested against your stated recovery objectives, rather than against a vendor default nobody at the agency chose.
- Technical diligence on your other vendors, including what an attestation’s scope actually covers.
- Evidence assembled in the form your file needs: asset inventory, network map, encryption status, and access records.
How Does the Split Get Written Down?
- It is built jointly at onboarding, rather than inferred from a service agreement months afterward.
- The functions we do not perform are named as such, including the ones no vendor performs.
- It is reviewed at renewal and after any service expansion, so scope creep surfaces as an amendment instead of an assumption.
How Does a Partner Support the Security Official Without Holding the Role?
Your designated official gets the technical reporting the role requires without having to generate it: risk analysis inputs, remediation status, and access records, delivered in language a DON or an administrator can act on rather than raw tooling output. Training can be delivered by IT Total Care while completion records stay with the agency, because the records are what an auditor asks for. At survey or audit, we produce the technical evidence while your official answers for your agency’s decisions, which is the only version of this arrangement that holds together when someone asks who decided.
What Should You Ask an IT Provider Before You Sign?
Ask these four before signing anything. The answers show whether a provider intends to put the division of labor in writing or leave it to assumption.
- Will you build a written shared responsibility matrix with us, or only a service agreement?
- Which functions will you not perform, and will you say so in writing?
- Will you hold our Security Official designation, and if you say yes, what happens at survey?
- Are home health agencies a core part of your client base, or do you mostly serve outpatient medical practices?
The second question is the one that separates them. A provider comfortable naming what it will not do is usually the provider worth hiring.
Ready to Put the Split in Writing?
IT Total Care works with home health agencies from our Foster City office across the wider Bay Area, filling the compliance functions that can move and naming the ones that cannot. Our home-based care IT support covers technical safeguards, managed field devices, access provisioning, and the evidence your compliance file depends on. You can also read more about our approach to healthcare IT.
Contact Us to talk through which parts of your HIPAA workload can actually move, and which parts are staying with you no matter who you hire.




