Brightree and MatrixCare serve significant portions of the hospice EHR market alongside Axxess — each with genuine clinical capability and legitimate security programmes at the application level. The pattern I encounter consistently when assessing hospice agencies using these platforms is the same pattern I encounter with every hospice EHR: the agency assumes that the vendor's security programme extends further than it does, and has not built the security architecture around the platform that the HIPAA Security Rule requires.
Understanding precisely where each platform's security responsibility ends allows hospice organisations to build the right security layer around each platform — not too much, not too little, but exactly what the HIPAA regulatory environment requires and what genuine threat protection demands.
Brightree: Security Posture Analysis
Brightree is a cloud-based hospice and home health platform with a strong market position among mid-size to large hospice organisations. Brightree is now part of the ResMed group, which has invested in enterprise-grade cloud infrastructure and security operations. Brightree maintains SOC 2 Type 2 certification and provides a Business Associate Agreement as a standard element of the platform contract. Request Brightree's current SOC 2 Type 2 report at contract renewal and review the exceptions section — any operational exceptions from the prior review period should be evaluated for their relevance to the hospice data your organisation entrusts to the platform.
The Brightree BAA covers the Brightree application and the ResMed cloud infrastructure that supports it. It does not cover: the devices your hospice clinical and administrative staff use to access Brightree; the email accounts through which Brightree notifications travel; the network connections between your staff's locations and the Brightree servers; or the credentials your staff choose for their Brightree logins. These are the elements of your environment where hospice security incidents originate — not in the Brightree application itself.
Brightree-Specific Security Considerations
Brightree's mobile application for clinical staff is widely used for hospice visit documentation. The mobile app accesses patient care data from the devices of nurses, aides, and social workers in patient homes — environments the hospice cannot control and cannot inspect. Every device running the Brightree mobile app must be enrolled in MDM with compliance policies enforcing encryption, EDR, and the container architecture that isolates clinical data from personal device content. An MDM compliance report confirming the Brightree mobile app is only accessible from enrolled, compliant devices is the evidence that HIPAA and RHIO reviewers will ask for.
Brightree supports SSO integration with external identity providers. The integration requires configuration by a Brightree implementation specialist — it is not self-service — but produces a significantly more secure and more manageable authentication architecture than standalone Brightree authentication. With SSO integration, MFA enforcement, access provisioning, and account deactivation are all managed through the identity provider, giving the hospice consistent access lifecycle management across Brightree and all other connected applications.
MatrixCare: Security Posture Analysis
MatrixCare is the market-leading EHR for senior living and skilled nursing, with significant hospice market share among organisations that also operate SNF and assisted living facilities. Its hospice module is deeply integrated with its post-acute continuum capabilities, making it particularly attractive for organisations managing multiple care settings. MatrixCare maintains SOC 2 Type 2 certification and a BAA programme consistent with enterprise healthcare software standards.
MatrixCare's multi-setting deployment is both its clinical advantage and its security complexity. Hospice staff accessing MatrixCare may use the same credentials as SNF staff in a multi-setting organisation — which means the access control configuration must explicitly differentiate hospice data access from SNF data access, preventing staff in one care setting from inadvertently accessing records in another. This cross-setting access segregation is a configuration task that MatrixCare supports but that the hospice organisation must implement deliberately.
The Security Layer Both Platforms Require
Regardless of whether your hospice uses Brightree, MatrixCare, Axxess, Homecare Homebase, or any other EHR, the security architecture around the platform is the same: behavioral EDR on all devices, MFA enforced through SSO integration or identity provider connection, MDM container management for mobile devices, advanced email security with anti-impersonation protection against EHR vendor phishing, immutable backup for any data held outside the EHR, and 24/7 SOC monitoring that covers the complete device and identity environment. ShieldForce delivers this architecture as a managed service around whichever hospice EHR your organisation uses.
Protecting your hospice agency is not optional — and it does not have to be overwhelming. ShieldForce delivers everything described in this article as a fully managed service, starting at $35/user/month. No IT department needed. BAA signed on day one. Core controls live within 72 hours. Start with a free assessment and see exactly where you stand.
→ Schedule Your Free HIPAA Risk Assessment — shieldforce.io/hipaa-assessment
→ Explore Hospice Cybersecurity — shieldforce.io/hospice-cybersecurity
→ View Transparent Pricing from $35/user/month — shieldforce.io/pricing-comparison

