Brightree is a cloud-based hospice EHR and billing platform used by thousands of hospice agencies across the United States. Its hospice-specific clinical documentation, billing, and care management tools are purpose-built for the hospice workflow. Like all major EHR platforms, Brightree maintains a Business Associate Agreement with your agency and provides security at the application and infrastructure level.
And like all EHR platforms, the security Brightree provides stops at the application boundary. What your nurses access Brightree on, where they access it from, how their credentials are protected, and what happens to Brightree-exported data in your broader environment — all of that is your agency's security responsibility, not Brightree's.
Understanding the Brightree Security Boundary
Brightree's responsibility (covered by their BAA):
- Hosted infrastructure security (physical security of data centers, network security of Brightree's cloud environment)
- Encryption of data in transit between Brightree's servers and your browser or application
- Application-level user authentication and role-based access within Brightree
- Audit logging within Brightree — access records, clinical documentation events
- Brightree's own incident response and breach notification obligations as a business associate
Your agency's responsibility (not covered by Brightree):
- Device security for every device used to access Brightree
- Network security for the environments from which Brightree is accessed
- Email security for communications related to Brightree workflows
- MFA configuration at the identity provider level (Brightree supports SSO/SAML integration)
- Backup of clinical and billing data exported from or supplementary to Brightree
- Physical security of devices containing Brightree data
- Staff training and behavior
The Five Security Layers Your Agency Must Add
Layer 1: Device Security
Brightree is accessed from laptops, tablets, and smartphones across your agency — from office workstations to field nurses' personal phones. Every device in that set is an attack surface.
Required controls:
- Encryption at rest on all devices (BitLocker for Windows, FileVault for Mac, verified encryption for iOS/Android)
- MDM deployment enabling remote wipe if a device is lost or stolen
- EDR (behavioral threat detection) on all endpoints
- Automated patch management ensuring current OS and browser versions
A hospice aide using an unencrypted personal tablet to access Brightree from a patient's home is a HIPAA compliance risk. An encrypted, MDM-managed device with EDR is not.
Layer 2: Authentication and MFA
Brightree supports integration with SAML 2.0 identity providers for single sign-on (SSO), enabling your agency to enforce MFA at the identity provider level — meaning every Brightree login is protected by your agency's MFA policy.
Configuring Brightree with Microsoft Entra ID or Okta SSO integration is the recommended approach. This provides:

