FTC Safeguards Rule and Home Health Agencies: Does It Apply and What Does It Require?
Regulatory

FTC Safeguards Rule and Home Health Agencies: Does It Apply and What Does It Require?

The FTC Safeguards Rule isn't the first regulation that comes to mind for home health administrators thinking about data security. It's primarily associated with financial institutions — banks, mortgage lenders,...

The FTC Safeguards Rule isn't the first regulation that comes to mind for home health administrators thinking about data security. It's primarily associated with financial institutions — banks, mortgage lenders, auto dealerships, credit unions. Yet the 2023 amendments to the Safeguards Rule significantly broadened the definition of "financial institution" under the Gramm-Leach-Bliley Act in ways that may capture certain home health agency activities. This is an area worth understanding clearly before assuming an agency is out of scope — because being wrong about scope is a compliance exposure that adds to HIPAA risk rather than replacing it.

What the FTC Safeguards Rule Is and Who It Covers

The FTC Safeguards Rule, issued under the Gramm-Leach-Bliley Act, requires "financial institutions" to implement an information security program protecting "customer financial information." The 2023 amendments (effective June 9, 2023) expanded the definition of activities that qualify an organization as a financial institution to include entities "significantly engaged" in financial activities, including activities "incidental to financial operations." The FTC has interpreted this broadly to include organizations that provide financial planning services, process consumer financing, or handle billing and payment processing in ways that go beyond standard commercial billing.

The Scope Question for Home Health Agencies

The direct HIPAA-covered activities of a home health agency — clinical care delivery, care documentation, Medicare and Medicaid billing — are generally not the activities that trigger Safeguards Rule coverage. However, certain activities that some home health agencies engage in may bring them within scope:

  • Patient financing arrangements — home health agencies that offer payment plans, financing arrangements, or that partner with consumer financing companies for patient out-of-pocket balances may qualify as engaged in financial activities under the expanded definition

  • Subsidiary or affiliated financial services — agencies affiliated with organizations providing financial services, including certain PACE programs, may inherit Safeguards Rule obligations through the affiliated entity relationship

  • Third-party billing with consumer data — agencies whose billing operations collect and process consumer financial data (credit card numbers, bank account information for payment collection) may have Safeguards Rule exposure for the financial data specifically, separate from HIPAA coverage of the clinical data

What the Safeguards Rule Requires If You're in Scope

The 2023 amended Safeguards Rule requirements closely parallel the 2026 HIPAA Security Rule updates — which is both fortunate and deliberate, as the FTC explicitly aligned the Safeguards Rule with NIST cybersecurity framework guidance that also underpins the HIPAA update. The core requirements: a written information security program, a designated Qualified Individual responsible for overseeing the program (analogous to the HIPAA Security Officer), a risk assessment, implementation of safeguards to manage identified risks, regular testing and monitoring of safeguards, and an incident response plan.

The technical requirements include: encryption of customer financial information in transit and at rest, MFA for any individual accessing customer financial information, penetration testing and vulnerability assessments on a regular schedule, and audit logs of access to customer financial information. These requirements are substantively similar to the 2026 HIPAA mandatory technical safeguards — meaning an organization with a strong HIPAA compliance program satisfies most Safeguards Rule technical requirements with minimal additional work.

A Separate Notification Obligation Most Agencies Don't Know About

The 2023 amendments also added a distinct breach notification requirement that's easy to miss because it runs alongside, not instead of, HIPAA's own notification rules. Covered institutions must report a "notification event" — defined as unauthorized acquisition of unencrypted customer information involving at least 500 customers — directly to the FTC within 30 days, separate from and in addition to any HIPAA breach notification obligations to HHS OCR and affected patients. For an agency determined to be in scope, this means an incident involving patient financial data could trigger two parallel notification tracks — HIPAA's process (see HIPAA Breach Notification: A Step-by-Step Guide for that timeline) and the FTC's, on a shorter 30-day clock, to a different agency entirely.

The Key Difference: The Qualified Individual Requirement

The Safeguards Rule requires a designated "Qualified Individual" to oversee the information security program — and unlike the HIPAA Security Officer designation, the Safeguards Rule specifies that this individual must have sufficient expertise to manage the program effectively, and their qualifications must be documented. Smaller organizations can use a service provider to fulfill this role, provided that oversight of the service provider is documented — this is worth confirming with counsel against the current customer-count thresholds in the rule, since those thresholds are periodically revisited.

The Practical Recommendation

If a home health agency engages in any form of patient financing, processes consumer financial data beyond standard insurance billing, or operates under a corporate structure that includes financial services subsidiaries, have legal counsel evaluate Safeguards Rule scope. The evaluation is straightforward, and the cost of getting it wrong — FTC enforcement action in addition to OCR exposure — is disproportionate to the effort of the scope determination. This overlap with existing security infrastructure is also why agencies already investing in strong technical controls tend to satisfy multiple regulatory frameworks with the same underlying program — see Cyber Insurance for Home Health Agencies: What Carriers Now Require for another example of the same controls satisfying a different external requirement. ShieldForce's HIPAA compliance program provides the technical infrastructure that satisfies Safeguards Rule requirements for any agency determined to be in scope.

Frequently Asked Questions

Does the FTC Safeguards Rule apply to a typical home health agency?

Not usually, for standard clinical care delivery and Medicare/Medicaid billing. It may apply if the agency offers patient financing arrangements, processes consumer financial data beyond standard insurance billing, or is affiliated with a financial services entity.

How is the FTC Safeguards Rule different from HIPAA?

They're separate regulatory frameworks enforced by different agencies (FTC vs. HHS OCR) covering different data (customer financial information vs. protected health information), though their technical requirements — encryption, MFA, risk assessments, penetration testing — are closely aligned. An agency in scope for both must satisfy each independently, even though a single strong security program typically covers most of both.

What's the breach notification timeline under the FTC Safeguards Rule?

Covered institutions must report a notification event — unauthorized acquisition of unencrypted customer information affecting 500 or more customers — to the FTC within 30 days. This runs separately from, and in addition to, HIPAA's own breach notification requirements.

Who can serve as the "Qualified Individual" required under the Safeguards Rule?

An employee of the institution, an affiliate, or a service provider — but if the Qualified Individual is an affiliate or service provider employee, the institution must still designate a senior staff member to provide oversight and direction, and remains responsible for the program overall.


Closing

If you're serious about protecting your home health agency — and about having documentation that holds up when it needs to — the next step is a free HIPAA Risk Assessment.

→ Schedule Your Free HIPAA Risk Assessment — https://shieldforce.io/hipaa-assessment

→ Explore Home Healthcare Cybersecurity — https://shieldforce.io/home-healthcare

→ View Transparent Pricing from $35/user/month — https://shieldforce.io/home-healthcare/checkout

Share this post

Topics

#Regulatory#Regulatory Guide
Free Security Assessment

Ready to Secure Your Business?

Don't let cyber threats put your business at risk. Discover how ShieldForce protects organizations like yours - 24/7.