For home health agencies
Care happens in the home. Your security has to travel with it.
Device, account and vendor security for agencies whose staff work everywhere but the office.
What we hear
Sound familiar?
Data moves with your clinicians
Visit notes, EVV check-ins and photos live on phones and tablets that leave the building every day.
Accounts outlive employees
High turnover means accounts that stay open long after someone leaves — the most common gap we find.
Every vendor is a door
Scheduling, EVV, billing and EHR vendors all hold PHI, and few agencies review them after the BAA is signed.
Proof is scattered
When an insurer, payer or surveyor asks, the evidence lives in five systems and three people’s heads.
Why it matters now
What’s different for you
You’ve already certified it to Medicare
Agencies that bill Medicare electronically signed CMS’s EDI enrollment agreement committing to HIPAA security compliance. We keep the evidence behind it current.
CMS-10164B, EDI Enrollment Agreement
Texas adds its own rules
The Texas Medical Records Privacy Act reaches further than HIPAA and requires staff privacy training within 90 days of hire. Since January 2026, Texas patients’ electronic health records must be stored in the U.S. — including by your vendors.
Tex. Health & Safety Code ch. 181; SB 1188 (2025)
How we help
Where to start
For providers & vendors
FreePolicy gap analysis
Send us the policies you have today. You get back a plain-English report of what’s missing against the HIPAA Security Rule.
- Works with whatever you have — a binder, a template pack, or nothing
- Each gap ranked by risk, with the fix spelled out
- Yours to keep, whether or not we work together
For providers
Vendor risk, done for you
We track every business associate, collect their security evidence and BAAs, chase what’s missing, and flag what changes.
- A complete vendor and BAA inventory
- Annual reviews sent, chased and filed for you
- Vendor findings land on your issue list, not in an inbox
For providers
CoreSecurity officer program
A named HIPAA security officer backed by our engine. Your inventory, monitoring, monthly reviews and annual risk analysis — with evidence for every one.
- Automated asset inventory across devices, accounts and cloud systems
- Monthly access, device, vendor, log and policy reviews, drafted for you and signed by a person
- Annual risk analysis and an evidence locker kept for six years
- One short issue list — what to fix, in what order
For providers & vendors
Trust site
A public security page backed by live evidence. Answer the next questionnaire with a link instead of a weekend.
- Shows the controls you actually run, not boilerplate
- Updates itself as your evidence changes
- Share sensitive documents only with approved requesters
Questions
Common questions
We already have an IT company.+
Good — we work alongside them. They run your systems; we independently check them and keep the evidence. The person running IT shouldn’t be the only one checking it.
What does the monthly work look like for us?+
A short set of drafted reviews and one prioritized issue list. Most months it’s about a 30-minute sign-off.
Start with what you already have.
Send us your current policies and get a free gap analysis — or grab 30 minutes with Griffin to talk through where you stand.