Skip to content

For home health agencies

Care happens in the home. Your security has to travel with it.

Device, account and vendor security for agencies whose staff work everywhere but the office.

What we hear

Sound familiar?

Data moves with your clinicians

Visit notes, EVV check-ins and photos live on phones and tablets that leave the building every day.

Accounts outlive employees

High turnover means accounts that stay open long after someone leaves — the most common gap we find.

Every vendor is a door

Scheduling, EVV, billing and EHR vendors all hold PHI, and few agencies review them after the BAA is signed.

Proof is scattered

When an insurer, payer or surveyor asks, the evidence lives in five systems and three people’s heads.

Why it matters now

What’s different for you

You’ve already certified it to Medicare

Agencies that bill Medicare electronically signed CMS’s EDI enrollment agreement committing to HIPAA security compliance. We keep the evidence behind it current.

CMS-10164B, EDI Enrollment Agreement

Texas adds its own rules

The Texas Medical Records Privacy Act reaches further than HIPAA and requires staff privacy training within 90 days of hire. Since January 2026, Texas patients’ electronic health records must be stored in the U.S. — including by your vendors.

Tex. Health & Safety Code ch. 181; SB 1188 (2025)

Questions

Common questions

We already have an IT company.+

Good — we work alongside them. They run your systems; we independently check them and keep the evidence. The person running IT shouldn’t be the only one checking it.

What does the monthly work look like for us?+

A short set of drafted reviews and one prioritized issue list. Most months it’s about a 30-minute sign-off.

Start with what you already have.

Send us your current policies and get a free gap analysis — or grab 30 minutes with Griffin to talk through where you stand.