Now, do not let the title fool you. We are not trying to say that HIPAA compliance matters more for Home Health agencies. HIPAA is still a federal regulation, which all organizations within the healthcare space must adhere to. The reason why I am choosing to focus on home healthcare today is due to the nuances of the law which agencies of this type encounter and how to deal with them.

Home Health Agencies face the unique challenge of having a broad amount of employees who do not necessarily remain tied down to a single desk in a day. Employees bolt from house to house to assist those in need. So, how do you ensure the confidentiality, integrity and availability of patient PHI is upheld? First, you want to make sure that all representatives of your organization sign a Confidentiality Agreement, which states they will not inappropriately utilize PHI they come across throughout the course of their workday.  

Aside from having a mobile workforce, modern technology provides unique challenges for these agencies as well.  How is one to ensure the integrity of the data has not been compromised?

Since their people are always on-the-go, Home Health Agencies need to take extra care in regards to the technology they use to assist someone, while still preventing unauthorized disclosures of PHI.  Technological safeguards are your best bet for maintaining integrity of PHI utilized. You need to make sure that your device that accesses PHI is fully encrypted, password protected, and that you have mechanisms in place to ensure encryption of data in transit.  

Now, what about availability of PHI? To ensure the health information is available when necessary, the WiFi network you are on is also a larger issue than one might not realize from looking only at the surface. Being that Home Health Agencies tend to float around to assist their patients, it’s easy to let this important factor fall by the wayside.  Not being in a traditional brick and mortar building means you are not safely positioned behind a firewall, leaving your device accessible and vulnerable to those with malintent. So, what is one to do? One resolution worth considering, is providing your employees with WiFi hotspots. That way they are on a dedicated network, which can have the correct controls in place for what the Agency requires. As a result, there will be no gap or lapse in your delivery of PHI to ‘home-base’.

