HIPAA Compliance for IDD and Home Care Providers: What OCR Is Enforcing in 2026

home care agency administrator reviewing a compliance checklist on a laptop

HIPAA applies to every IDD and home care agency that creates, stores, or transmits protected health information. OCR’s Phase 3 compliance audits launched in March 2025, the proposed HIPAA Security Rule update is moving toward finalization, and penalties have reached $2.1 million per violation category for willful neglect. This guide covers what the 2026 compliance environment requires from IDD and home care providers specifically.

 

PHI in IDD and home care settings moves through more touchpoints than in clinical environments. Mobile devices in participants’ homes, DSP scheduling apps, EVV systems, billing platforms, and care management software all process participant data simultaneously. Each one is a potential enforcement gap if it isn’t documented, secured, and covered by a Business Associate Agreement.

 

Who HIPAA Covers in IDD and Home Care Settings

 

Any provider that transmits health information electronically in connection with a covered transaction is a covered entity under HIPAA. Every IDD and home care agency accepting government funding qualifies.

 

Business associates create the more common exposure. Any vendor that creates, receives, maintains, or transmits PHI on your behalf requires a signed Business Associate Agreement before accessing that data. In IDD and home care operations, that list is longer than most agencies recognize:

 

  • Care management and scheduling software
  • EVV systems and their state data aggregators
  • Billing platforms and clearinghouses
  • Payroll software processing employee health information
  • Cloud storage providers holding participant records
  • Telehealth platforms used for remote participant check-ins
  • IT support vendors with system access

 

Missing BAAs with any of these vendors is among the most consistently cited findings in OCR enforcement actions. Agencies add vendors, launch new systems, and negotiate contracts without running a BAA checklist against every vendor touching PHI. The gap surfaces when a breach triggers an OCR investigation.

 

Healthcare data security and privacy compliance concept, ShiftCare.

 

What OCR Is Actually Enforcing in 2026

 

OCR launched Phase 3 of its HIPAA compliance audit program in March 2025, initially targeting 50 covered entities and business associates. Two areas are under the most active scrutiny.

 

Security Risk Analysis and Risk Management

 

No risk analysis or inadequate risk analysis is the single most common finding across OCR enforcement actions. The requirement has existed since 2005, and OCR’s patience for organizations that haven’t completed one has run out.

 

The 2026 enforcement posture added a specific wrinkle. An organization that completed a risk analysis, identified that field devices were unencrypted and MFA was not enforced, and then did nothing about those findings for three years is now in a worse position than one that never completed an analysis. Documented awareness of a gap with no remediation demonstrates willful neglect, which is the highest penalty tier.

 

OCR now evaluates whether organizations acted on their findings, not just whether an analysis exists. Risk management must be documented as an ongoing process, with identified vulnerabilities tied to specific remediation steps and tracked to completion.

 

Right of Access Enforcement

 

HIPAA’s Privacy Rule requires covered entities to provide individuals with access to their protected health information within 30 days of a request. A single 30-day extension is permitted with written explanation. OCR completed more than 50 enforcement actions under its Right of Access Initiative and continues actively pursuing delays. For IDD agencies, this applies to participant records including care plans, progress notes, and incident reports.

 

Where IDD and Home Care Providers Fail HIPAA Audits

 

No current risk analysis. An analysis that doesn’t cover mobile devices, DSP scheduling apps, EVV systems, and cloud-based care management platforms is incomplete by 2026 standards. OCR’s January 2026 Cybersecurity Newsletter specifically requires risk analysis to identify vulnerabilities including unpatched software and device firmware gaps.

 

Missing or unsigned BAAs. EHR vendors, billing companies, EVV aggregators, and IT providers without current BAAs create enforcement exposure regardless of how underlying data is handled. BAAs must be in place before a vendor accesses PHI, not after a breach triggers an investigation.

 

Inadequate workforce training records. Annual HIPAA training with documented completion records for every employee is required. Records showing only that a policy was distributed do not satisfy the workforce training requirement.

 

Unsecured PHI on personal devices. DSPs using personal phones to receive participant information, share progress notes, or communicate with families create PHI exposure no BAA can cover. Personal devices sit outside the agency’s security controls and cannot be remotely wiped if lost or stolen.

 

HIPAA compliant logo used on ShiftCare platform.

 

What a HIPAA Compliance Program Requires Operationally

 

Documented Risk Analysis Updated When the Environment Changes

 

The risk analysis must identify every location where PHI exists: electronic health records, scheduling software, EVV systems, billing platforms, email threads, and physical files. It must assess the likelihood and potential impact of threats to each. Updating it annually and whenever the organization adds new software, devices, or vendor relationships satisfies OCR’s current expectation. Filing it once and revisiting it three years later does not.

 

Role-Based Access Controls With Audit Logs

 

Staff access to PHI must be limited to what their role requires. A DSP needs access to care plans for participants they serve. A billing coordinator needs access to billing records. Role-based access implemented at the system level, with an audit log tracking every access event, satisfies both the minimum necessary standard and the audit controls requirement under the Security Rule.

 

Breach Notification Procedures Staff Can Execute

 

Unauthorized PHI access triggers mandatory breach notification. Breaches affecting 500 or more individuals in a state require notification to OCR and prominent local media within 60 days. Smaller breaches go into the annual log submitted to OCR each March. Agencies without a documented breach response procedure that staff can execute without waiting for supervisory sign-off create the response delays that increase penalty exposure.

 

Business Associate Agreement Inventory Reviewed Annually

 

Maintaining a current inventory of every vendor with PHI access and confirming each has a signed BAA is an ongoing task. Vendor relationships change, platforms update, and new tools get added without formal BAA review. An inventory reviewed at least annually catches gaps before an OCR investigation does.

 

How Technology Choices Affect HIPAA Exposure in HCBS Settings

 

The platforms an agency uses determine a significant portion of its HIPAA risk profile. Four technology decisions carry the most compliance weight for IDD and home care providers.

 

  • Care management software. The platform where participant records, care plans, and progress notes live holds the highest concentration of PHI in the operation. It must provide role-based access, encrypted storage, audit trails, and a signed BAA as part of its standard service agreement.
  • EVV systems. EVV data includes participant location, identity, and service type — all PHI. State EVV aggregators require BAAs. Alternate vendor EVV systems require BAAs. Both need confirmation before the system goes live.
  • Communication tools. Staff sharing participant information through personal messaging apps or unencrypted email creates PHI exposure no organizational control can close. Secure in-platform messaging replaces that risk without requiring staff to manage separate applications.
  • Billing software. Billing platforms process PHI with every Medicaid claim submission. They require BAAs and must be included in the risk analysis as a PHI processing environment with their own access controls and encryption requirements.

 

 

Build a HIPAA Compliance Program That Holds Up Under OCR Audit

 

HIPAA compliance in IDD and home care requires a risk analysis that drives real remediation, BAAs with every vendor touching PHI, training records for every staff member, and platforms that implement access controls and encryption by design.

 

ShiftCare’s care management platform provides role-based access controls, encrypted data storage, and full audit trails across participant records, scheduling, and billing. BAA coverage is included as standard. EVV integration connects visit verification directly to care records without creating separate PHI repositories, and staff management tools track HIPAA training completion across your workforce with records accessible for OCR audit response.

 

Start your free trial today. See how ShiftCare helps IDD and home care agencies build the HIPAA compliance infrastructure that holds up under OCR scrutiny in 2026.

Like this story? Share it with others.