How to Prepare for a Medicare Advantage Plan Cybersecurity Assessment as a Home Health Agency
How-To-Guide

How to Prepare for a Medicare Advantage Plan Cybersecurity Assessment as a Home Health Agency

Two years ago, a Medicare Advantage plan cybersecurity assessment of a preferred home health provider was a rarity. Today it's becoming standard practice among the larger MA plans — Humana,...

Two years ago, a Medicare Advantage plan cybersecurity assessment of a preferred home health provider was a rarity. Today it's becoming standard practice among the larger MA plans — Humana, UnitedHealthcare, Aetna, Cigna — as part of their network credentialing and preferred provider program management. The Change Healthcare breach in 2024, which disrupted claims processing for healthcare providers across the country through a single compromised supply chain partner, accelerated this shift dramatically. MA plans are no longer willing to accept "we are HIPAA compliant" as sufficient evidence that a provider's security posture doesn't represent a risk to the plan's data and operations.

What this means for home health agencies is that the security program that used to be evaluated solely by OCR — rarely, and only after a breach — is now being evaluated by the commercial partners whose preferred provider designation drives referral revenue. A failed or unsatisfactory MA plan security assessment can remove an agency from a preferred provider list, which can cost more in annual revenue than most HIPAA penalties. This is the same underlying dynamic covered in How Home Health Agencies Can Win More Hospital Referrals With Cybersecurity Certification — commercial partners, not just regulators, are increasingly the ones setting the bar. For agencies navigating New York's Medicaid managed care landscape at the same time, see Medicaid Managed Care and Cybersecurity: What NY Home Health Agencies Must Know for how that parallel payer-assessment process works.

What Medicare Advantage Plan Assessments Actually Examine

MA plan cybersecurity assessments range significantly in depth depending on the plan's sophistication and the nature of the provider relationship. The most common format is a vendor security questionnaire — typically a modified version of the SIG (Standardized Information Gathering questionnaire), the VSAQ (Vendor Security Assessment Questionnaire), or a proprietary questionnaire. These typically cover between 50 and 200 questions across the same domains as the HIPAA Security Rule: access control, encryption, network security, incident response, training, and vendor management.

For preferred provider arrangements involving data sharing — where the MA plan is sending patient attribution data to the agency or receiving clinical documentation from the agency — some plans conduct more rigorous assessments that include: a technical configuration review, a request for the agency's most recent HIPAA risk analysis, evidence of penetration testing, and a phone interview with the agency's Security Officer or an authorized representative.

The Documentation Package That Answers Assessment Questions

The home health agencies that complete MA plan security assessments quickly and successfully are the ones that maintain a standing compliance documentation file rather than building it in response to each assessment request. Here's what that file must contain:

  • Current HIPAA Security Rule risk analysis — completed within the past 12 months, with findings and remediation status documented

  • Written information security program — all required policies, including access control, incident response, remote access, acceptable use, and media disposal

  • Most recent vulnerability scan report — completed within the past six months, with findings and remediation actions documented

  • Most recent penetration test report — completed within the past 12 months (now a HIPAA mandatory requirement), with findings and remediation documentation

  • Annual security training completion records — documented evidence that all staff completed training in the past 12 months

  • Business associate agreement inventory — showing BAAs on file for all vendors with ePHI access

  • MFA implementation evidence — a configuration screenshot or attestation confirming MFA is enforced on all ePHI-accessible accounts

  • EDR deployment evidence — confirmation of behavioral EDR deployment across the device fleet with vendor platform identified

The Technical Controls That Pass Assessment Scoring

MA plan security questionnaires assign scores or ratings to individual responses, and the aggregate score determines whether the agency passes, requires remediation, or fails the assessment. The controls that most heavily weight the score — and that are most frequently missing at home health agencies — are: MFA enforcement (consistently the highest-weighted control in healthcare vendor assessments), EDR deployment beyond basic antivirus, documented incident response plan with breach notification procedures, and annual penetration testing evidence.

Agencies that are scoring poorly on MA plan assessments almost always have gaps in one or more of these four areas. An agency that can confirm all four — with documentation — typically passes the initial questionnaire phase of any MA plan assessment without requiring a remediation cycle.

The Security Officer Conversation

For assessments that include a phone interview, the Security Officer or their authorized representative will be asked questions about the agency's security program that require genuine knowledge to answer correctly. The assessor isn't looking for perfect answers. They're looking for evidence that the agency has a real program managed by people who understand it — not a compliance document produced by a consultant that no one internally can explain.

The most important preparation for this conversation is for the Security Officer to be familiar with the documentation package described above and to be able to speak to the agency's specific controls, not generic HIPAA requirements. "We use CrowdStrike for EDR" is a better answer than "we have behavioral antivirus." "Our MFA is Microsoft Authenticator with number matching, enforced through Conditional Access policies" is a better answer than "yes, we have MFA." Specificity demonstrates genuine implementation.


Closing

If you're ready to protect your home health agency with a cybersecurity partner that actually understands healthcare — not one that learned it from a brochure — start with a free HIPAA Risk Assessment. No obligation, no sales pressure. Thirty minutes with a healthcare cybersecurity expert.

→ Schedule Your Free HIPAA Risk Assessment — https://shieldforce.io/hipaa-assessment

→ Explore Home Healthcare Cybersecurity — https://shieldforce.io/home-healthcare

→ View Transparent Pricing from $35/user/month — https://shieldforce.io/home-healthcare/checkout

Share this post

Topics

#How-To-Guide#How-To Guide
Free Security Assessment

Ready to Secure Your Business?

Don't let cyber threats put your business at risk. Discover how ShieldForce protects organizations like yours - 24/7.