
Home care agencies carry hospital-grade compliance obligations on a small-business IT budget, and the work happens in other people's houses on phones you don't own. That combination is what makes agency IT different from any other small business we support.
Here are the questions owners and administrators actually ask us.
Are we a HIPAA covered entity, or just a business associate?
If you provide health care and transmit information electronically for a transaction HHS has adopted a standard for, you're a covered entity in your own right. Most agencies are. The full Security Rule then applies to you directly, not just through your software vendor's contract. Agencies providing only non-medical companion care may fall outside it, but the line is narrower than owners usually assume.
Our scheduling software is HIPAA compliant. Doesn't that cover us?
No. Vendor compliance covers the vendor's platform. It says nothing about the laptop in your office, the caregiver's phone, your email, or your backups. A signed business associate agreement protects you if the vendor causes a breach. It does nothing if the breach starts on your side, which is where most of them start.
Do we really need a written risk analysis?
Yes, and it's the single most enforced requirement in the rule. In four ransomware settlements announced April 23, 2026, totaling $1,165,000, OCR found every one of the four organizations "failed to conduct an accurate and thorough risk analysis." Not weak passwords. The missing paperwork that would have found the weak passwords.
What does EVV require from our IT?
The 21st Century Cures Act requires states to implement electronic visit verification for all Medicaid personal care services and home health services that need an in-home visit, with deadlines of January 1, 2020 and January 1, 2023 respectively. Practically, it means caregivers carry a device that must have working connectivity, a current app, and a way to recover when it doesn't.
Caregivers use their own phones. Is that allowed?
It's allowed and it's normal. It's also where agencies get hurt. Personal devices holding client schedules, addresses, and care notes need enrollment, a screen lock requirement, and the ability to wipe agency data without touching the caregiver's photos. That's what mobile device management does. A written BYOD policy makes it enforceable.
A caregiver quit last month and still has the app. How bad is that?
Bad. Turnover in home care runs high, and every departure that doesn't trigger an access removal leaves client data on a phone you can't see. The fix is process, not technology: offboarding starts the same day employment ends, and it removes app access, email, and scheduling in one step. Our IT offboarding checklist covers the sequence.
What's the most common way agencies actually get breached?
Email. Someone signs in to a fake Microsoft page, an attacker reads the mailbox for a few weeks, then redirects a payment or emails clients from a real address. Ransomware gets the headlines, but credential theft through email is what we see most. Phishing-resistant MFA and conditional access stop the majority of it.
How fast do we have to report a breach?
Individuals must be notified "without unreasonable delay and in no case later than 60 days following the discovery of a breach," per HHS. Breaches affecting 500 or more people also go to HHS and the media within 60 days. Smaller ones are reported to HHS annually, within 60 days of the year's end.
Our office has five people. Is this overkill?
Your headcount isn't what regulators look at. A 12-caregiver agency holds diagnoses, addresses, and Medicaid numbers for a few hundred people. The Security Rule applies the same way it applies to a hospital, and the enforcement actions above turned on a missing risk analysis rather than on how big the organization was. The controls scale down. The obligation doesn't.
What does managed IT cost for an agency our size?
Most agencies land in the normal per-user range for managed IT, with the usual add-ons for compliance documentation and device management. The number moves most with caregiver count and whether their devices are agency-owned. Our managed IT cost breakdown has the current ranges.
Where should we start if we've never done any of this?
The risk analysis, because it tells you what everything else should be. Then email security and device management, in that order, because that's where the actual incidents come from. Compliance documentation follows the fixes rather than replacing them.
Talk to someone who's done this before
We support home care and home health agencies across NY, NJ, CT, PA, and Southwest Florida: HIPAA compliance, caregiver device management, and the risk analysis OCR asks for first. Book a complimentary risk assessment and we'll tell you where you stand before anyone else does.
Related reading
FAQNY SHIELD Act for Small Business: 8 Questions Owners Ask
Read Article
FAQIT Support for Insurance Agencies: 13 Questions Owners Ask
Read Article
FAQSetting Up IT for a New Business: 10 Questions Owners Ask
Read ArticleAlso on this topic: Managed IT for Medical and Dental Practices in 2026 · HIPAA IT Compliance Checklist for Small Medical and Dental Practices
Discuss managed it services for your business.
Tell us about your current systems, the result you need and your timeline. We will discuss the work, responsibilities and pricing before you decide on an engagement.
