tunzly
Start free trial
Guide

HIPAA compliance for home care agencies

Home care agencies handle protected health information (PHI), which makes them HIPAA covered entities. Compliance means safeguarding client information under HIPAA’s Privacy and Security Rules, signing Business Associate Agreements with vendors who touch PHI, limiting access to those who need it, and being able to account for how data is used. This is general guidance — confirm specifics with qualified compliance counsel.
Updated July 2026

What HIPAA requires, in brief

  • Privacy Rule — sets limits on how PHI can be used and disclosed, and gives clients rights over their information.
  • Security Rule — requires administrative, physical and technical safeguards for electronic PHI (access controls, encryption, audit logging).
  • Breach Notification Rule — requires notifying affected individuals (and authorities) if PHI is breached.
  • Business Associate Agreements — contracts with vendors who handle PHI on your behalf, binding them to protect it.

What this means for a home care agency

  • Limit who can see client information to the minimum necessary for their role.
  • Keep an audit trail of access to PHI.
  • Sign BAAs with software vendors, billing partners and anyone else who touches PHI.
  • Train staff on privacy practices and safe handling of client information.
  • Have a plan to detect, respond to and report breaches.

HIPAA and AI features

As agencies adopt AI tools, a new question arises: does the AI expose PHI? Responsible platforms keep AI features PHI-safe — designed so protected health information is not leaked to or retained by third-party models inappropriately. When evaluating any software with AI, ask how it handles PHI and whether that handling is covered by your BAA.

How software supports compliance

Software can’t make an agency compliant on its own, but the right platform makes it easier: role-based access, audit logging, secure storage of documents and PHI, a BAA from the vendor, and PHI-safe AI. Tunzly is built for HIPAA-regulated home care data with these safeguards in mind. For your specific obligations, consult qualified compliance counsel.

Frequently asked questions

Do home care agencies have to comply with HIPAA?

Yes. Home care agencies handle protected health information and are HIPAA covered entities, so they must comply with HIPAA’s Privacy, Security and Breach Notification Rules.

What is a Business Associate Agreement (BAA)?

A BAA is a contract between a covered entity (like a home care agency) and a vendor that handles PHI on its behalf, binding the vendor to protect that information under HIPAA. Software and billing vendors that touch PHI need a BAA.

Is Tunzly HIPAA compliant?

Tunzly is built for HIPAA-regulated home care data, with safeguards such as role-based access, audit logging, secure storage and PHI-safe AI. For your specific compliance obligations, consult qualified compliance counsel.

Can AI features be HIPAA compliant?

AI features can be used with PHI when designed to be PHI-safe — so protected health information is not inappropriately exposed to or retained by third-party models — and when that handling is covered by a Business Associate Agreement.

Run a home care agency on PHI-safe software

Tunzly is built for HIPAA-regulated data, including PHI-safe AI. Start a free trial.

Start free trial

Keep reading

Family portal softwareSecure, scoped access to client care.Home care CRM softwareThe full platform for running an agency.Tunzly privacy policyHow Tunzly handles data.