Hospice M&A activity has accelerated significantly over the past three years, driven by private equity consolidation, regional health system acquisitions, and the operational pressure that smaller independent hospices face competing against scaled organisations with centralised support infrastructure. Cybersecurity due diligence has not kept pace with this transactional activity. I have reviewed acquisition targets where the LOI was signed before anyone had asked a cybersecurity question, and where the post-close integration team discovered HIPAA violations so fundamental that the regulatory exposure absorbed a material portion of the acquisition price through remediation cost and investigation risk.
This article provides the cybersecurity due diligence framework for both buyers (organisations acquiring hospice agencies) and sellers (hospice agencies approaching a transaction). The framework is not exhaustive — a full cybersecurity assessment in the context of M&A requires specialist expertise — but it covers the items most commonly missed in hospice transactions and most costly when discovered post-close.
The Buyer's Due Diligence Framework
Phase 1: Pre-LOI Screening (30 Minutes, High Value)
Before signing a letter of intent, conduct a 30-minute public information scan that identifies the most significant red flags: check the HHS breach portal for prior breach notifications (available publicly at ocrportal.hhs.gov); search OCR enforcement actions for any actions or settlements involving the target; review publicly available information about the organisation's technology environment (job postings, LinkedIn profiles of IT staff, vendor references on the website). A prior breach notification or OCR enforcement action is not necessarily a disqualifying factor — but it requires deeper investigation into what happened, how it was remediated, and whether the remediation was adequate.
Phase 2: Post-LOI Technical Assessment (Days 1–30)
The post-LOI cybersecurity assessment should be conducted by a qualified cybersecurity firm engaged by the buyer, with access to the target organisation's systems and documentation under a confidentiality agreement. The assessment should cover:
• HIPAA compliance programme review: risk analysis currency and completeness, written security programme documentation, training records, BAA inventory and completeness, incident response plan
• Technical control verification: MFA enforcement status (configuration evidence, not attestation), device fleet encryption verification, EDR deployment and coverage, vulnerability scan results from the past 12 months, penetration test results from the past 12 months
• Breach and incident history: documented incidents for the past three years including near-misses, the four-factor risk assessments conducted for each, and the remediation actions taken
• Vendor and third-party risk: BAA inventory review, identification of any vendors without BAAs that should have them, SOC 2 reports for Tier 1 vendors
Specific Hospice Issues That Generic Diligence Misses
• Volunteer system access: does the target have documented HIPAA access controls for volunteers? Have volunteer accounts been properly managed through enrollment and departure? Undocumented volunteer access is a consistent gap.
• IDG documentation access controls: are access controls configured to reflect role-appropriate access to sensitive clinical documentation categories?
• Bereavement programme data governance: is bereavement family data properly classified as PHI and managed with appropriate controls?
• CMS CoP alignment: does the organisation's security programme address the CoP clinical records and patient rights provisions, or only the HIPAA Security Rule requirements?
The Seller's Preparation Framework
Hospice agencies approaching a transaction should conduct a self-assessment against the buyer's likely due diligence framework before the process begins. Gaps identified and remediated before the process start in a position of strength; gaps identified by the buyer's assessment team create negotiating leverage that is used against the seller. The three items that most reliably create post-close liability for hospice sellers: missing or outdated BAAs with current vendors; absence of MFA enforcement evidence (not the MFA setting, but the enforcement mechanism); and no documented penetration test in the past 12 months (now a HIPAA mandatory requirement that was likely required before the transaction period began).
Protecting your hospice agency is not optional — and it does not have to be overwhelming. ShieldForce delivers everything described in this article as a fully managed service, starting at $35/user/month. No IT department needed. BAA signed on day one. Core controls live within 72 hours. Start with a free assessment and see exactly where you stand.
→ Schedule Your Free HIPAA Risk Assessment — shieldforce.io/hipaa-assessment
→ Explore Hospice Cybersecurity — shieldforce.io/hospice-cybersecurity
→ View Transparent Pricing from $35/user/month — shieldforce.io/pricing-comparison

