The CMS Conditions of Participation for Hospice Providers (42 CFR Part 418) do not contain a cybersecurity section. There is no condition titled "Information Security" and no explicit requirement to deploy endpoint detection or implement multi-factor authentication.
And yet, in 2025 and 2026, hospice surveyors are increasingly citing data management deficiencies, inadequate patient record protection, and insufficient care plan accessibility as survey findings — all of which have a cybersecurity dimension that the original CoP language never anticipated.
The practical reality is this: a ransomware attack that locks your hospice's patient records during an active patient census is a care delivery failure under the CoP — specifically under the clinical records, patient rights, and comprehensive assessment conditions. A cybersecurity failure is not just an IT problem. It is a patient care problem and a regulatory survey problem.
This guide explains how the CMS Conditions of Participation relate to cybersecurity for hospice agencies, what documentation surveyors are increasingly requesting, and how to protect your agency against both care delivery failures and survey deficiencies.
The CoP Conditions That Have Cybersecurity Implications
Condition: Clinical Records (§418.104)
The Clinical Records condition requires hospice agencies to maintain clinical records on every patient served, and to ensure those records are:
- Complete and accurate — records must reflect the current care plan, medications, physician orders, and clinical assessments
- Accessible — records must be available to the clinical team when and where needed
- Protected against unauthorized access — patient information must be protected from unauthorized disclosure
- Retained — records must be retained for a minimum of six years (or longer per state law)
The cybersecurity implications are direct:
Accessibility: A ransomware attack that locks clinical records violates the accessibility requirement. If a hospice nurse cannot access a patient's medication list, care plan, or emergency contact information because the EHR has been encrypted, that is a failure to maintain accessible clinical records for an active patient.
Protection: Inadequate security controls that result in unauthorized access to clinical records — a phishing attack that exposes patient data, an unencrypted laptop that is stolen — is a failure to protect patient information from unauthorized disclosure.
Retention: If ransomware destroys clinical records that are not backed up, the six-year retention requirement cannot be met.
What surveyors may ask: Do you have documented procedures for accessing clinical records if your EHR system is unavailable? What backup and disaster recovery systems are in place? Who has access to clinical records and how is that access controlled?
Condition: Patient Rights (§418.52)
The Patient Rights condition requires hospice agencies to protect and promote patient rights, including the right to:
- Confidentiality of all clinical records and personal information
- Privacy in treatment and care planning
A data breach exposing a hospice patient's end-of-life wishes, diagnoses, or care preferences to unauthorized parties is a direct violation of the privacy and confidentiality rights this condition protects. Hospice patient data — which includes diagnoses, prognosis, advance directives, and family dynamics — is among the most sensitive PHI in healthcare.
What surveyors may ask: How do you protect patient information accessed by field staff? What is your policy for staff use of personal devices containing patient information? Have there been any unauthorized disclosures of patient information in the past 36 months?

