HIPAA rules for deceased hospice patients do not end when the patient dies. Under 45 CFR 164.502(f), a hospice must keep protecting a decedent’s protected health information for 50 years following the date of death, and during those 50 years only…
Does HIPAA Apply to Home Care Agencies?
Whether HIPAA applies to home care agencies is decided by a two-part test, and most published guidance only runs the first half of it. That matters because the answer changes what an agency has to document, who can enforce against it,…
How to Meet California’s 30-Day Breach Notification Deadline
At 4:40 on a Friday afternoon, an office coordinator at a home care agency in the East Bay opens the shared drive to pull the weekend’s care plans and finds every file renamed. She calls the owner, who calls the person…
Cybersecurity for Home Care Agencies: What the Law Requires Even Without HIPAA
Cybersecurity for home care agencies is governed by California law and private contracts far more often than it is governed by HIPAA. Most private-pay agencies are not HIPAA covered entities, and a great deal of published guidance stops at that sentence….
Can You Outsource the HIPAA Security Officer Role to Your IT Provider?
Can you outsource the HIPAA security officer role along with the rest of your technology? It is the question that produces the longest pause when a surveyor asks a home health administrator to name the agency’s Security Official. Agencies that handed…
How to Build a HIPAA Shared Responsibility Matrix With Your IT Provider
A HIPAA shared responsibility matrix answers a question most home health agencies cannot answer on the spot: who owns each compliance function, the agency or the IT provider. Ask an administrator who approves the risk analysis and you will usually get…
Outsourcing HIPAA Compliance for Home Health Agencies: What You Can’t Hand Over
Outsourcing HIPAA compliance for home health agencies moves the work of compliance, not the accountability for it. An IT provider can implement the safeguards, run the monitoring, and produce the evidence. Your agency still answers for the decisions underneath all of…
Is a Stolen Encrypted Laptop a Reportable HIPAA Breach?
Is a stolen encrypted laptop a reportable HIPAA breach? Usually not under federal law, and that answer holds only if the agency can prove three specific things about the device after it is already gone. For a California home health agency…
How to Report a Medical Information Breach to CDPH in 15 Business Days
This guide explains why reporting a medical information breach to CDPH matters for a California licensed agency, how to work through the filing step by step on your own, and how IT Total Care builds the detection and evidence the filing…
HIPAA Breach Notification for Home Health Agencies: 60 Days Is the Outer Limit
HIPAA breach notification for home health agencies has one federal deadline: 60 calendar days from the day a breach is discovered. That is the outer limit, not a target. An agency that sends notice on day 55 can still be found…










