HIPAA breach notification for home health agencies has one federal deadline: 60 calendar days from the day a breach is discovered. That is the outer limit, not a target. An agency that sends notice on day 55 can still be found…
Do Home Health Agencies Need a BAA With a Staffing Agency?
Do home health agencies need a BAA with a staffing agency? Not always, and not never. The answer turns on who controls the clinician’s work, which means two agencies using the same staffing firm can land in different places and both…
How to Verify a Business Associate’s Safeguards Before You Sign a BAA
Your agency is switching billing services. The new vendor sends over a signed business associate agreement, a one-page PDF with the words HIPAA compliant across the top, and a request for a data export so they can start working claims on…
HIPAA Business Associate Agreements for Home Health Agencies: What OCR Actually Enforces
A HIPAA business associate agreement for home health agencies is the written contract that allows an agency to disclose patient information to an outside vendor. Under 45 CFR 164.502(e), a covered entity may hand protected health information, or PHI, to a…
Is Public Wi-Fi a HIPAA Violation for Home Health Clinicians?
Is public Wi-Fi a HIPAA violation for home health clinicians? The question comes up in nearly every policy review, usually right after somebody notices that visit notes are being finished in a parking lot. The short answer is no. The useful…
How Bridge Home Health & Hospice Scaled from 25 to 250+ Employees in 3 Years with IT Total Care
By Brendan Duebner, President, IT Total Care IT Total Care helped Bridge Home Health & Hospice grow its Bay Area operations from 25 employees in 1 location to more than 250 employees across 11 locations in three years (2017 to 2020)…
How to Send ePHI by Encrypted Email in a Home Health Agency
This guide covers why encrypted email matters specifically for home health agencies, how to set it up and run it yourself in five steps, and how IT Total Care manages the whole path for agencies that would rather not own it….
HIPAA Encryption Requirements for Home Health Agencies: Addressable, Not Required
The HIPAA encryption requirements for home health agencies rest on a distinction that most published guidance gets wrong. Protecting electronic protected health information, or ePHI, while it moves across a network is required. Encrypting it is addressable, which is a much…
How Often Do Home Health Agencies Need a HIPAA Risk Assessment?
How often do home health agencies need a HIPAA risk assessment is one of the questions San Francisco Bay Area agencies ask most, and the honest answer is that the regulation never gives a number. What it gives is an expectation…
How to Build an ePHI Asset Inventory for a Home Health Agency
This guide explains why an ePHI asset inventory for home health agencies matters, how to build and maintain one on your own, and how IT Total Care handles it for your agency. The inventory is the artifact the rest of the…










