Hospice care is, at its core, about accompanying people through the most profound human experience — the dying process. The information that hospice organisations collect and manage to provide that care is correspondingly profound: terminal diagnoses, end-of-life wishes, family dynamics, spiritual beliefs, final conversations, and the intimate details of a person's last days. The HIPAA Security Rule applies to this information with the same force it applies to any other covered entity's ePHI. But the moral weight of that application is different at a hospice — because a breach of hospice patient information violates not just privacy rights but the sacred trust that every hospice patient and family extends when they invite care into their most vulnerable moments.
This guide provides the complete 2026 HIPAA Security Rule compliance framework for hospice agencies, adapted for the specific operational characteristics that distinguish hospice from other home health care settings: the interdisciplinary team model, the volunteer workforce, the bereavement programme, and the end-of-life care context that shapes every clinical and administrative decision.
The 2026 HIPAA Mandatory Requirements for Hospice Agencies
The six new mandatory requirements introduced by the 2026 HIPAA Security Rule update apply to hospice agencies in full, without exception or accommodation for organisational size or care setting:
• Multi-factor authentication: enforced on all accounts with access to ePHI — which at a hospice includes the EHR accounts of nurses, aides, social workers, chaplains, and bereavement coordinators; the email accounts that receive clinical notifications; and any administrative accounts that handle patient financial or scheduling information. The MFA requirement applies to volunteer accounts if volunteers access electronic systems containing patient information.
• Encryption at rest and in transit: every device that stores hospice patient information must have full disk encryption enabled and verified. Every electronic transmission of patient information — clinical notes, medication orders, care plan updates, family communication through digital channels — must use encryption in transit.
• Biannual vulnerability scanning: the technology environment used to deliver and document hospice care must be scanned for security vulnerabilities at least twice per year, with findings documented and remediated within defined timelines.
• Annual penetration testing: by a qualified third party, with a written report and documented remediation of findings.
• Technology asset inventory: a documented inventory of all hardware and software that creates, receives, maintains, or transmits ePHI — which at a hospice includes the EHR, the scheduling system, the volunteer management platform if it stores patient information, and the telehealth platform if used for virtual visits.
• Documented incident response plan: with hospice-specific elements including clinical downtime procedures, family communication protocols, and RHIO notification requirements for New York hospices participating in SHIN-NY.
The Hospice Workforce HIPAA Challenge: Volunteers
Hospice volunteers are workforce members under HIPAA — a classification that most hospice volunteer programme coordinators understand in principle but have not always operationalised in practice. The practical implications: every volunteer who accesses patient information (even the patient's name and visit schedule) must complete HIPAA privacy and security training before beginning volunteer service; every volunteer who accesses electronic systems must have individual credentials and must be subject to the same access control standards as paid staff; and every volunteer's access must be terminated when they leave the volunteer programme.
The operational challenge is that volunteer programmes are designed around relationship and mission, not regulatory compliance infrastructure. The solution is integration: build HIPAA compliance requirements into the volunteer onboarding process as a standard element rather than a regulatory overlay. The volunteer orientation that every new hospice volunteer completes should include a 30-45 minute HIPAA module as a standard, documented component. The signed volunteer agreement should include a confidentiality provision with HIPAA-specific language. The volunteer access provisioning should use the same role-based access framework as paid staff access.
The Interdisciplinary Group: Access Controls for Multi-Disciplinary Documentation
The IDG model creates access management complexity that home-health-only agencies do not face. When a team of eight clinicians — physician, nurse, social worker, chaplain, aide, bereavement coordinator, music therapist, and volunteer coordinator — each document their interactions with the same patient in the EHR, access controls must be configured to allow each clinician access to the information their role requires while protecting the most sensitive information (chaplaincy notes, social work assessments, mental health referrals) with more restrictive access profiles.
Configure the EHR to support role-based access profiles that reflect the minimum necessary standard for each IDG role. The physician and nurse need access to the full clinical record. The chaplain needs access to spiritual care notes and the care plan but not necessarily to detailed billing records or medication administration records. The volunteer coordinator needs access to volunteer assignment scheduling but not to detailed clinical documentation. These distinctions are achievable in every major hospice EHR platform — but they require deliberate configuration, not default settings.
Protecting your hospice agency is not optional — and it does not have to be overwhelming. ShieldForce delivers everything described in this article as a fully managed service, starting at $35/user/month. No IT department needed. BAA signed on day one. Core controls live within 72 hours. Start with a free assessment and see exactly where you stand.
→ Schedule Your Free HIPAA Risk Assessment — shieldforce.io/hipaa-assessment
→ Explore Hospice Cybersecurity — shieldforce.io/hospice-cybersecurity
→ View Transparent Pricing from $35/user/month — shieldforce.io/pricing-comparison

