HIPAA compliance home care rules are not optional and not abstract for a Minnesota agency. If your agency sends an electronic claim to Minnesota Health Care Programs (MHCP) or a managed care organization, you are a covered entity under the Health Insurance Portability and Accountability Act (HIPAA), and the Privacy Rule, Security Rule, and Breach Notification Rule in 45 CFR Part 164 apply to you in full.

The requirements come down to a short list: a written risk analysis, safeguards in three categories, a business associate agreement (BAA) with every vendor that handles protected health information (PHI), role-based access under the minimum necessary standard, audit logs, staff training, six-year retention of compliance records, and a 60-day breach process. Minnesota adds its own consent rules through the Minnesota Health Records Act.

This guide covers each requirement for a Minnesota care agency, with the citation you would show an auditor, as of September 2026.

Who is a covered entity and who is a business associate?

45 CFR 160.103 defines a covered entity as a health plan, a health care clearinghouse, or a health care provider that transmits any health information electronically in connection with a standard transaction. An 837P claim or an eligibility check is a standard transaction, so a home care agency that bills MHCP through MN-ITS or a clearinghouse is a covered entity.

A business associate is a person or company that creates, receives, maintains, or transmits PHI on the covered entity's behalf. For a care agency that includes electronic visit verification (EVV), scheduling, documentation, and billing software vendors; clearinghouses; and cloud hosting and email providers that store PHI.

The definition also covers subcontractors: your software vendor's cloud host is a business associate of the vendor and needs its own agreement. Ask the vendor to confirm that chain in writing.

What the Privacy Rule and Security Rule require

The Privacy Rule (45 CFR Part 164, Subpart E) governs how PHI is used and disclosed. The Security Rule (Subpart C) governs how electronic PHI (ePHI) is protected. The Security Rule sorts its requirements into three safeguard categories, each with "required" and "addressable" specifications. Addressable does not mean optional; it means you implement it or document why an alternative is reasonable.

Safeguard category Rule What it means for a care agency
Administrative 45 CFR 164.308 Risk analysis and management, a named security official, sanction policy, activity review, workforce security, training, incident procedures, contingency plan, BAAs
Physical 45 CFR 164.310 Facility access controls, workstation use and security, device and media controls (disposal, re-use, accountability, backup)
Technical 45 CFR 164.312 Unique user IDs, emergency access, automatic logoff, encryption, audit controls, integrity, authentication, transmission security

Risk analysis comes first

45 CFR 164.308(a)(1)(ii)(A) requires an accurate and thorough assessment of the risks to the confidentiality, integrity, and availability of ePHI. It is required, and it is the first document the Office for Civil Rights requests after a complaint or breach. A risk analysis for a home care agency inventories where ePHI lives (the EHR, caregiver phones, spreadsheets, email, paper), identifies threats to each location, and rates likelihood and impact. Risk management (164.308(a)(1)(ii)(B)) then documents what you did about each finding.

The business associate agreement and when a vendor needs one

45 CFR 164.308(b) requires a covered entity to obtain satisfactory assurances, in a written contract, that a business associate will appropriately safeguard ePHI. The required contract terms are in 45 CFR 164.314(a) and 164.504(e). If a vendor stores, processes, or transmits PHI for you and will not sign a BAA, you cannot lawfully give it PHI.

The test is simple: if the vendor's system ever holds a client name, address, diagnosis, service record, or claim, it needs a BAA. A caregiver EVV app that captures client name, GPS location, and visit times qualifies. A BAA should be part of vendor selection, not an afterthought; the PCA and CFSS software buyer's guide and the ARMHS software buyer's guide both list it as a gating requirement.

Compliance note: keep a BAA register. List every business associate, the date the agreement was signed, its term, and who at your agency owns the relationship. The register itself falls under the six-year retention rule.

Minimum necessary and role-based access

45 CFR 164.502(b) requires a covered entity to limit PHI to the minimum necessary to accomplish the purpose of a use, disclosure, or request. The standard does not apply to disclosures to a provider for treatment, to the individual, or where required by law, but it applies squarely to internal access by workforce members.

In practice that means role-based access. A caregiver should see only the clients on their own schedule and their care plan tasks. A biller needs service records and diagnoses but not the full assessment narrative. Field-level access, where a role sees specific fields rather than whole records, is the cleanest way to meet the standard.

Unique user identification (164.312(a)(2)(i)) and person or entity authentication (164.312(d)) are required safeguards that make this enforceable. Shared logins defeat both and make the audit log useless, because no entry can be attributed to a person.

Audit logs and how long to keep records

45 CFR 164.312(b) requires audit controls: mechanisms that record and examine activity in information systems that contain ePHI. The companion administrative requirement, 164.308(a)(1)(ii)(D), requires regular review of audit logs, access reports, and security incident reports. A log nobody reads does not satisfy the rule.

A useful audit log records who viewed, created, edited, or exported a record, when, and what changed. It is tamper-evident, so a deleted or altered note can be detected, and exportable for any date range.

Retention has two layers that agencies often confuse:

Record type Retention Source
HIPAA policies, procedures, risk analyses, training records, sanctions, complaints, BAAs 6 years from creation or last effective date, whichever is later 45 CFR 164.316(b)(2)(i) and 164.530(j)
MHCP service records and financial records supporting a claim At least 5 years after the initial date of billing Minn. R. 9505.2190, subp. 1
Program-specific client records (245D, 245I, EIDBI, adult day) Check Minn. R. 9505.2175, your license rule, and the DHS provider manual for your program Program rule

HIPAA does not set a retention period for the medical record itself; state law and program rules do. The DHS audit preparation checklist covers what a reviewer will pull.

The Minnesota Health Records Act as an extra layer

Minnesota's own law, the Minnesota Health Records Act at Minn. Stat. §§ 144.291 to 144.298, applies to providers including home care providers. Where it is stricter than HIPAA, it controls.

The biggest difference is consent. Under § 144.293, a provider may not release a patient's health records without a signed and dated consent from the patient or the patient's legally authorized representative, a specific authorization in law, or a representation from another provider that it holds a signed consent. HIPAA permits many treatment, payment, and operations disclosures without an authorization; Minnesota often does not. A consent is valid for one year or the period stated in it, except that a consent for consulting providers in current treatment, for insurers handling claims, or for welfare-system service coordination does not expire.

In practice: use a Minnesota-compliant consent at intake, check the consent date before each release, and record which consent covered each disclosure.

Mobile devices used by caregivers

An EVV app with GPS clock-in and client signatures is a workstation under 164.310(b) and a device under 164.310(d). The Security Rule does not ban personal phones, but it requires you to manage the risk. Minimum controls: app-level login with a unique user ID and a second factor; automatic logoff after inactivity (164.312(a)(2)(iii)); encryption on the device and in transit (164.312(a)(2)(iv) and 164.312(e)(2)(ii)); no PHI in text messages or personal email; same-day credential revocation for lost phones and departing staff; and a written mobile device policy acknowledged by every caregiver. Because the EVV mandate routes every PCA and CFSS visit through a mobile app, this policy is the agency's main exposure.

Breach notification: the 60-day rule

A breach is an impermissible use or disclosure of unsecured PHI that compromises its security or privacy, unless a documented risk assessment shows a low probability of compromise. When a breach happens:

  • Notify affected individuals without unreasonable delay and no later than 60 calendar days after discovery (45 CFR 164.404).
  • For breaches affecting 500 or more people, notify HHS at the same time as individuals and notify prominent media in the affected area (164.406 and 164.408).
  • For smaller breaches, keep a log and report them to HHS within 60 days after the end of the calendar year.
  • A business associate must notify the covered entity; the agency's discovery date is when it knew or should have known.

Encrypted data lost with the key intact is not "unsecured," which is one reason encryption on every device matters.

Staff training and sanctions

Two rules require training. The Privacy Rule, 45 CFR 164.530(b), requires every workforce member to be trained on PHI policies at hire and when policies change materially. The Security Rule, 164.308(a)(5), requires a security awareness program covering reminders, malware protection, login monitoring, and password management. Document who was trained, on what, and when, and keep those records six years.

Agencies licensed under 245D already run orientation and annual training (see the 245D staff training and orientation guide); adding HIPAA and the mobile device policy to that program is the efficient path. A sanction policy (164.308(a)(1)(ii)(C)) closes the loop: staff must know that snooping in a record is a disciplinary matter.

HIPAA compliance checklist for a home care agency

  1. Confirm covered entity status; name a privacy officer and a security officer.
  2. Complete and date a written risk analysis; repeat it annually and after any system change.
  3. Sign a BAA with every vendor and subcontractor that touches PHI; keep a register.
  4. Set role-based, field-level access; eliminate shared logins; turn on audit logging and review it monthly.
  5. Encrypt data at rest and in transit, including caregiver phones, under a written mobile device policy.
  6. Use a Minnesota Health Records Act consent at intake; track consent dates.
  7. Write a breach response procedure that can meet the 60-day deadline.
  8. Train all staff at hire and annually; keep compliance records six years and MHCP billing records at least five.

How Trustora helps

Trustora is built for Minnesota care agencies that are covered entities. A BAA is included with every agreement. The platform runs on HIPAA-eligible AWS with AES-256 encryption at rest, TLS 1.3 in transit, and a one-time code on every login. Access is role-based down to the field level, so a caregiver, scheduler, biller, and supervisor each see only what their role requires under the minimum necessary standard.

Every view, edit, and export is written to an append-only, SHA-256-chained audit log retained for seven years, which covers the six-year HIPAA documentation window and the five-year Minn. R. 9505.2190 window. The caregiver EVV app on iOS and Android keeps PHI inside the encrypted app rather than in texts or photos. Details are on the security page and the platform overview.