HIPAA and Home Health Monitoring: A Vendor Checklist
A US guide to when HIPAA applies to home health monitoring, when sensor data becomes PHI, when a vendor needs a BAA, and what to ask before a pilot.
An agency director we spoke with was two signatures from a monitoring pilot when she asked the vendor for a BAA. Back came a glossy PDF, “HIPAA compliant” in the header, no contract attached. She put the pilot on hold — rightly: HIPAA and home health monitoring connect through data flows and signed roles, not badges on a landing page.
When HIPAA applies to home health monitoring
Monitoring is arriving in home care fast. The CDC counts one in four adults 65+ falling each year, and in one study 97% of worn emergency buttons went unpressed in real falls. Agencies are swapping buttons for passive sensors — so health-shaped data now runs through your operation, classified or not.
HHS defines three kinds of covered entity: health plans, clearinghouses, and providers that conduct certain electronic transactions. The last clause does the work: billing. File an electronic claim — an 837 to Medicare, an eligibility check to a payer — and HIPAA attaches. A Medicare-certified home health agency is covered. A private-pay companion-care agency that invoices families by card and never touches a payer is not.
Falling outside HIPAA is not falling outside the law. Washington’s My Health My Data Act, its state imitators, and the FTC’s Health Breach Notification Rule reach health data HIPAA never touches. Different statute, same headline when it leaks.
Map one alert before you classify anything
Follow one event. The bedroom radar in a client’s apartment reports no movement by mid-morning. That signal makes seven hops: sensor, gateway, vendor cloud, SMS provider, coordinator’s phone, your client record, the daughter’s app. Four or five companies sit in that chain — and only one has signed anything with you.
For every hop, write down five things:
- what moves — the alert, or the raw sensor stream behind it;
- who it points to — name, address, device ID, or pattern;
- which company holds it, and in which country;
- why it is there, and what else it gets used for;
- how long it lives, and which contract covers it.
A name is the least of the identifiers. “Movement stopped in the bathroom at unit 4B” points at exactly one person. A camera-free event stream carries far less than video — but “no camera” has never meant “not identifiable.”
When monitoring data becomes PHI
PHI is identifiable health information held by a covered entity or its business associate. Notice what is missing: the sensor. Our alert is PHI at hop six, in the covered agency’s client record. The identical alert inside a retail app the family bought on Amazon is not. The data never changed — the holder did.
Stop asking whether radar data “counts as medical.” The modality never decides the question; the relationship does — who holds this copy, on whose behalf.
When the vendor is a business associate
Walk back to hop three: the vendor’s cloud, storing your clients’ alert history and hosting the dashboard your coordinators log into. That is a service performed for a covered entity involving PHI — the textbook business associate. The BAA belongs in place before the first live client, not after the pilot “proves value.”
Vendors love the conduit exception. It exists for couriers — HHS compares it to the postal service and ISPs, which move data without keeping it. A vendor that retains your alert archive for one night is not a conduit.
And a BAA is a contract, not a certificate. It names permitted uses, safeguards, breach reporting with deadlines, subcontractor flow-downs, and what happens at termination: export, return, or documented destruction. If “send me your BAA” produces a brochure — like the one our director got — you have your answer about the vendor.
HIPAA Security Rule questions
The Security Rule sorts safeguards into administrative, physical, and technical. Skip the taxonomy; ask six concrete things:
- logins — MFA on every account, plus role-based views: a caregiver sees her clients, not your roster;
- audit logs — who opened which client’s history, and when;
- encryption in transit and at rest, plus a named person who knows where the keys live;
- offboarding — a caregiver quits Friday; who kills her access that same Friday;
- incidents — detection, response, and a contractual notice deadline in hours or days, not “promptly”;
- patching — how fast a gateway vulnerability gets fixed in the field.
Ask for evidence — a SOC 2 report, a pentest summary — and remember what it proves: the vendor’s process, not your configuration. The duty stays with you. HHS runs a public portal listing every breach that hits 500 or more people, searchable by name; nobody there planned to be.
Don’t call data “de-identified” casually
HIPAA recognizes exactly two de-identification methods: Expert Determination and Safe Harbor. Safe Harbor strips eighteen identifier categories — not just names but device IDs, dates more precise than the year, and geography below the state level. A vendor that “anonymizes” analytics data by dropping the name has completed step one of eighteen.
“Aggregated,” “anonymized,” and “de-identified” are three different claims. Make the vendor pick one and document the method against the HHS de-identification guidance. Rare patterns are the monitoring trap: a distinctive nightly routine in a one-resident apartment de-identifies nobody.
Family sharing and authorization
The scene that trips agencies: the daughter found the vendor, pays the invoice, and now wants dashboard access to her mother’s nights. Paying is not authority. Staff access for treatment and operations is one lane; disclosure to family is another, and it runs through the client’s authorization or personal-representative status under state law. The most involved relative is not automatically the legal one.
Involve the client first — who sees your own nights is the client’s call for as long as they are able to make it. When you share, share the minimum: last night’s summary, not three years of history.
Vendor diligence checklist
| Topic | Question |
|---|---|
| Role | Who is covered entity, business associate, and subcontractor — per data flow, in writing? |
| Collection | Does any mode capture audio, images, location, or raw waveforms — even in debug logs? |
| Use | Is client data used for model training or analytics, and is there an off switch? |
| Access | Who opens a client’s history — your staff, the vendor’s support team, the family? |
| Subcontractors | Which cloud, SMS, and analytics companies sit in the chain, and do BAAs flow down? |
| Retention | What is kept, for how long, and what does deletion actually delete — backups included? |
| Security | MFA, encryption, audit logs, offboarding — shown with evidence, not asserted? |
| Incidents | What is the contractual notice deadline — in hours or days, not adverbs? |
| Exit | At contract end, do you get a full export and documented destruction? |
How this differs from UK and EU rules
GDPR has no covered-entity gate. It reaches nearly any organization processing an EU or UK resident’s data, health data sits in Article 9’s special category, and the roles change names — controller and processor instead of covered entity and business associate. If you operate in those markets, work through the GDPR monitoring guide and the UK CQC and data-protection guide — and do not port your HIPAA paperwork across the Atlantic.
Put the contract in place before the data flows
Camera-free architecture shrinks the problem; it does not erase it. Radar events tied to a named client in your record are PHI. Business-associate status is decided by role, not by a badge. And order matters: no contract signed in October covers a disclosure that happened in June.
Where OdeCare sits: we build radar monitoring with no cameras, no microphones, and no wearables. What leaves a home is an event stream — “movement stopped in the bathroom” — not footage. Three things we do not do: we do not record audio or video, so there is no footage to secure, subpoena, or breach; we do not decide your covered-entity status for you; and we do not start a pilot before the role and contract analysis is finished. If that order matches how you run your agency, start with the agency overview.