HIPAA Compliance Checklist for Home Hospice Charting Software

Product Pricing
Ready to get started? Book a demo with our team
Talk to an expert

HIPAA Compliance Checklist for Home Hospice Charting Software

Kevin Henry

HIPAA

October 01, 2026

6 minutes read
Share this article
HIPAA Compliance Checklist for Home Hospice Charting Software

Use this practical checklist to align your home hospice charting software and workflows with HIPAA requirements. The focus is protecting Electronic Protected Health Information (ePHI) across mobile teams, in-home visits, and cloud-based systems while keeping documentation accurate, timely, and survey-ready.

Administrative Safeguards Implementation

Start with a comprehensive risk analysis tailored to home hospice operations, then maintain a living Risk Management Plan that maps threats to controls in your charting software and field routines. Assign a privacy officer and security officer to own decisions, approvals, and oversight.

Formalize policies for workforce access, onboarding/offboarding, training, and sanctions. Define a Security Incident Procedure for detection, reporting, triage, and post-incident reviews. Build a tested Contingency Plan that covers backups, disaster recovery, and emergency-mode operations.

Checklist

  • Complete an enterprise risk analysis and update the Risk Management Plan at least annually.
  • Designate privacy and security officers; document roles and meeting cadences.
  • Publish policies for access control, minimum necessary, sanctions, and remote work.
  • Implement a Security Incident Procedure with 24/7 reporting channels and evidence preservation.
  • Create and test a Contingency Plan: data backup, disaster recovery, and downtime charting.
  • Provide role-based HIPAA training with attestations and retrain upon policy changes.

Physical Safeguards Management

Protect workstations and mobile devices used during home visits. Control office and storage access, and ensure devices are locked, encrypted, and never left unattended in vehicles. Establish secure transport for any printed materials and proper disposal after scanning into the charting system.

Maintain an asset inventory with chain-of-custody records. Standardize secure storage, return, and destruction for laptops, tablets, phones, removable media, and home monitoring peripherals issued to staff or patients.

Checklist

  • Restrict facility access (locks, visitor logs) and secure areas storing ePHI-capable devices.
  • Harden workstations: privacy screens, automatic logoff, cable locks, and clean-desk rules.
  • Encrypt all portable devices; enable remote locate, lock, and wipe.
  • Document device and media controls, including transfer, reuse, and certified destruction.
  • Minimize paper; if used, transport in locked bags and cross-cut shred after upload.

Technical Safeguards Integration

Enforce least-privilege, role-based access within your charting software and require Multi-factor Authentication for all remote and privileged access. Assign unique user IDs, use strong authentication policies, and configure automatic session timeouts.

Encrypt ePHI in transit and at rest, and retain immutable audit logs for logins, access, edits, e-prescribing, and disclosures. Implement integrity controls to prevent unauthorized alteration, and monitor events with alerts for anomalous behavior.

Checklist

  • Enable role-based access, unique IDs, and Multi-factor Authentication across apps and VPNs.
  • Use modern encryption for data in transit and at rest; protect keys and backups.
  • Activate audit logging with regular reviews and defined retention periods.
  • Apply integrity controls: version history, checksums, and tamper-evident records.
  • Secure APIs and data exchanges; de-identify ePHI in testing and analytics.

Privacy Rule Compliance

Deliver and document a Notice of Privacy Practices at admission and upon request. Configure the charting software to support the minimum necessary standard, limit sharing to authorized caregivers, and capture patient authorizations where required.

Operationalize patient rights: timely access to designated record sets, amendments, restrictions, confidential communications, and an accounting of disclosures. Verify identities before releases and use secure channels that align with patient preferences and risk.

Ready to simplify HIPAA compliance?

Join thousands of organizations that trust Accountable to manage their compliance needs.

Checklist

  • Provide, explain, and log receipt of the Notice of Privacy Practices.
  • Enforce minimum necessary via roles, templates, and disclosure workflows.
  • Track requests for access, amendments, restrictions, and confidential communications.
  • Verify identity before disclosure; record purpose and method of release.

Breach Notification Procedures

Differentiate security incidents from breaches and perform a documented risk assessment for any impermissible use or disclosure. If a breach is likely, notify affected individuals without unreasonable delay and within HIPAA timelines, and report to regulators as required.

Coordinate with vendors through contractual terms so Business Associates notify you promptly. Ensure notification content explains what happened, what information was involved, recommended protective steps, and your remediation actions with clear contact information.

Checklist

  • Run your Security Incident Procedure: contain, preserve logs, investigate, and assess risk.
  • Document the four-factor breach risk assessment and decision rationale.
  • Issue individual notices within required timeframes; escalate media/HHS notices when applicable.
  • Offer appropriate mitigation (e.g., monitoring) and track remediation tasks to closure.

Documentation and Record Keeping

Maintain policies, risk analyses, the Risk Management Plan, training rosters, incident and breach logs, audit reviews, device inventories, BAAs, and disclosure logs. Keep Contingency Plan tests, backup/restore evidence, and downtime procedures current and accessible.

Apply consistent retention rules, version control, and owner assignments. Your charting software should export complete audit trails and designated record sets to support patient requests, legal holds, and surveys.

Checklist

  • Centralize policy/procedure documents with versioning and six-year minimum retention.
  • Archive risk analyses, Risk Management Plan updates, and training attestations.
  • Retain incident records, breach assessments, and notification proofs.
  • Keep device inventory, encryption status, and destruction certificates.
  • Store BAAs, NPP acknowledgments, and accounting-of-disclosures reports.

Organizational and Vendor Responsibilities

Clarify responsibilities for your hospice, software provider, and other partners. Execute a Business Associate Agreement with each vendor that handles ePHI, and require subcontractor flow-down terms. Validate controls through security questionnaires, independent reports, or onsite reviews.

Operationalize onboarding/offboarding with rapid provisioning and deprovisioning of accounts, devices, and access keys. Align your cloud or hosting model to a shared-responsibility matrix so no security gap exists between your team and vendors.

Checklist

  • Assign accountable owners for privacy, security, compliance, and IT operations.
  • Execute and periodically review each Business Associate Agreement, including breach notice SLAs.
  • Perform vendor due diligence and track remediation of identified gaps.
  • Automate user lifecycle and device return/destruction processes.
  • Define a shared-responsibility model with each hosting or SaaS provider.

Conclusion

This checklist turns HIPAA requirements into concrete actions for home hospice charting software. Anchor your program in risk management, strengthen technical and physical controls, document everything, and hold vendors accountable to keep ePHI protected across every visit and workflow.

FAQs

What are the key administrative safeguards for HIPAA compliance?

Conduct a tailored risk analysis, maintain a Risk Management Plan, assign privacy and security officers, train your workforce with attestations, enforce minimum necessary access, and implement a documented Security Incident Procedure plus a tested Contingency Plan.

How should a home hospice implement physical safeguards?

Control facility access, secure workstations and field devices with locks and auto-logoff, encrypt and inventory all portable hardware, manage chain of custody, minimize paper during visits, and ensure certified destruction when devices or media are retired.

What technical controls are required for ePHI protection?

Use role-based access with unique IDs, require Multi-factor Authentication, encrypt ePHI in transit and at rest, retain and review audit logs, apply integrity controls and secure APIs, and segregate or de-identify data in non-production environments.

When must a breach be reported under HIPAA?

After an impermissible use or disclosure, perform a risk assessment. If a breach is likely, notify affected individuals without unreasonable delay and within HIPAA’s deadlines, and submit required reports to regulators and, when applicable, the media.

Share this article

Ready to simplify HIPAA compliance?

Join thousands of organizations that trust Accountable to manage their compliance needs.

Related Articles