ShieldForce Colored Variance Logo
HIPAA and Electronic Visit Verification: Security Requirements for EVV Systems in Home Health
Compliance Guide

HIPAA and Electronic Visit Verification: Security Requirements for EVV Systems in Home Health

Electronic Visit Verification became a federal mandate through the 21st Century Cures Act, which required all states to implement EVV for Medicaid personal care and home health services. The mandate...

Electronic Visit Verification became a federal mandate through the 21st Century Cures Act, which required all states to implement EVV for Medicaid personal care and home health services. The mandate is now fully effective across all states, and virtually every home health agency serving Medicaid patients operates an EVV system that captures visit time, duration, location, and patient and caregiver identity through GPS-enabled mobile applications. This data is ePHI. It's also location data — a category that carries privacy sensitivities beyond standard HIPAA considerations. And it's a system that most home health HIPAA programs haven't fully integrated into their security framework.

Why EVV Data Is ePHI and What That Means

EVV data identifies a specific patient, at a specific location, receiving a specific service, at a specific time, from a specific caregiver. Each element individually may not be PHI. In combination — which is how EVV systems store it — it unambiguously constitutes protected health information under HIPAA. The home address captured in EVV isn't just location data — it's the patient's home address associated with their care episode, making it PHI with all the security protections that implies.

The HIPAA Security Rule applies to EVV systems exactly as it applies to EHR systems: the platform must be covered by a BAA with the vendor, data must be encrypted in transit and at rest, access must be controlled on a need-to-know basis, audit logs must be maintained and reviewed, and the platform must be included in the HIPAA Security Rule risk analysis as part of the ePHI inventory.

State-Managed EVV Systems and the BAA Question

Many states have implemented state-managed or state-contracted EVV systems — where the EVV vendor is contracted by the state Medicaid program rather than by the individual agency. This creates a nuanced BAA situation: the agency is disclosing patient information to an EVV system it did not select and cannot negotiate with directly. State guidance on whether the state EVV contract constitutes a BAA equivalent varies. Home health agencies should confirm with their state Medicaid program whether the state EVV contract includes BAA provisions — and if it does not, should seek guidance on how to document this disclosure in their compliance program. This BAA-management responsibility falls squarely within the Security Officer's vendor oversight duties — EVV vendors should be added to the same BAA inventory maintained for every other system touching ePHI.

Agency-Selected EVV Platforms: Security Assessment Requirements

For agencies that select their own EVV vendor rather than using a state-mandated system, the vendor security assessment process applies:

  • Request and review the EVV vendor's SOC 2 Type 2 report or equivalent security certification

  • Execute a signed BAA with the vendor before any patient data enters the system

  • Verify that the EVV vendor's BAA includes sub-contractor provisions covering any cloud infrastructure provider the vendor uses

  • Review the vendor's encryption standards for data in transit (GPS data transmitted from field devices) and at rest (stored visit records)

  • Confirm the vendor's breach notification timeline in the BAA aligns with HIPAA requirements

This is the same vendor assessment discipline already applied to EHR platforms — see Home Health EHR Security Compared for the equivalent process applied to clinical systems, since EVV and EHR platforms frequently integrate and should be evaluated with the same rigor.

Location Data Privacy Considerations

EVV GPS data captures the physical location of field staff during visit windows. This data — which shows where a staff member was at what time — has privacy implications for staff that extend beyond standard HIPAA patient data considerations. Agencies should address in their EVV policy: how long location data is retained beyond visit verification purposes, who within the agency can access location data and for what purposes, and whether the agency's acceptable use policy addresses staff expectations regarding location monitoring during work hours.

The intersection of EVV compliance and staff privacy is an area where legal counsel should review agency policy — particularly in states with stronger employee privacy protections than federal law requires. Since EVV runs on the same field devices already covered by the agency's mobile device management program, this is also worth reviewing alongside Mobile Device Management for Home Health Agencies: A Practical Deployment Guide to confirm EVV app data is properly contained and governed the same way EHR access is.

Frequently Asked Questions

Is EVV data actually PHI under HIPAA?

Yes. While individual data points like a timestamp might not be PHI on their own, EVV data combines patient identity, location, service type, and time in a way that unambiguously constitutes protected health information.

Does a state-mandated EVV system still require a BAA?

It depends on the state. Some state Medicaid EVV contracts include BAA-equivalent provisions; others don't, in which case the agency should seek state guidance on how to document the disclosure appropriately in its compliance program.

What security certifications should an agency request from an EVV vendor?

A SOC 2 Type 2 report or equivalent, along with confirmation of a signed BAA that includes sub-contractor provisions for any cloud infrastructure the vendor relies on.

Does EVV GPS tracking raise privacy concerns beyond HIPAA?

Yes — location data showing where field staff were at specific times has employee privacy implications separate from patient data protections, and agency policy on retention, access, and staff expectations around monitoring should be reviewed with legal counsel, especially in states with stronger employee privacy laws.


Closing

If you're serious about protecting your home health agency — and about having documentation that holds up when it needs to — the next step is a free HIPAA Risk Assessment.

→ Schedule Your Free HIPAA Risk Assessment — https://shieldforce.io/hipaa-assessment

→ Explore Home Healthcare Cybersecurity — https://shieldforce.io/hipaa-assessment

→ View Transparent Pricing from $35/user/month — https://shieldforce.io/home-healthcare/checkout

Share this post

Topics

#Compliance Guide
Free Security Assessment

Ready to Secure Your Business?

Don't let cyber threats put your business at risk. Discover how ShieldForce protects organizations like yours - 24/7.