Across home health HIPAA compliance programs, the Acceptable Use Policy is one of the most commonly mishandled required documents — either missing entirely, written in language no field nurse could interpret, or so outdated it references technology the agency stopped using years ago. The AUP is often treated as the document you produce to check the compliance box — not as the governance instrument that actually shapes how your workforce interacts with patient data every day. Written correctly, an AUP does both. Written incorrectly — or not at all — it's a liability waiting to become an exhibit in an OCR investigation.
What HIPAA Requires and Why the AUP Matters
The HIPAA Security Rule requires covered entities to implement "policies and procedures that specify the proper functions to be performed, the manner in which those functions are to be performed, and the physical attributes of the surroundings of a specific workstation or class of workstation that can access electronic protected health information." The AUP is the primary vehicle through which this requirement is met at the workforce level. It defines the line between acceptable and unacceptable use of organizational systems and data — and that line must exist in writing before you can enforce it, before you can apply sanctions for violations, and before you can defend your security program to OCR.
The Eight Essential Sections of a Home Health AUP
Section 1: Scope — Who This Policy Applies To
The AUP must explicitly state that it applies to every workforce member — employees, contractors, volunteers, and vendors — who accesses organizational systems, devices, or data. In home health, this means clinical staff, the administrative team, the billing company, the scheduling software vendor's support personnel, and any volunteer who touches patient scheduling or communication. This is where many agencies fail: they write a policy for employees and forget that HIPAA defines "workforce" to include contractors and volunteers.
Section 2: Permitted Uses of Organizational Systems
This section defines what workforce members are authorized to do with agency systems, devices, and data. Permitted uses in a home health context include: documenting patient care in the EHR, communicating with clinical team members about patient care through agency-approved channels, accessing scheduling and billing systems for legitimate care coordination and administrative functions, and using agency-approved email for professional communication. Being explicit about what's permitted removes ambiguity and makes the prohibited uses section more enforceable.
Section 3: Prohibited Uses — The Non-Negotiables
This is the section that requires specificity. Generic prohibited use statements ("do not misuse company systems") are unenforceable. Specific prohibited use statements create clear, documentable standards:
Sharing login credentials with any other person for any system, for any reason, under any circumstances — including sharing with a colleague during a device emergency
Accessing patient records for any reason other than a direct care, administrative, or legitimate operational need related to that specific patient
Transmitting ePHI via personal email, personal text messaging, consumer messaging applications (WhatsApp, iMessage to personal numbers, Signal, Facebook Messenger), or any platform not designated by the agency as HIPAA-compliant — see HIPAA and Texting: Can Home Health Staff Text Patient Information? for the full policy language and compliant messaging platform options this prohibition should point staff toward
Storing ePHI on personal devices, personal cloud storage accounts, USB drives, or any storage medium not authorized and managed by the agency
Installing unapproved software or applications on agency-owned devices without IT authorization
Using agency-owned devices for personal activities that could expose the device to malware — including visiting personal social media, online gaming, or adult content sites
Section 4: Device Requirements by Category
The AUP must address each device category in your environment because the requirements differ meaningfully. Agency-owned laptops and workstations must remain enrolled in MDM, must not be used by non-employees, and must never leave the control of the assigned workforce member. Field nurse tablets must use cellular data rather than patient home WiFi for EHR access wherever coverage is available. Personal smartphones used to access work email or the EHR mobile app must have the MDM work container installed before any work system access is permitted — personal devices without the MDM container must not access ePHI under any circumstances. For the fuller picture of why this specific gap is so common and how the MDM container model works in practice, see Personal Devices on Home Wi-Fi: The Security Gap Killing HIPAA Compliance for Home Health Agencies.
Section 5: Remote Access Requirements
Remote access — any access to organizational systems from outside the office — must require MFA on every session without exception. The policy should explicitly state that no exception to MFA is available for remote access regardless of urgency, device type, or individual role. The policy should also prohibit accessing ePHI over public WiFi networks (coffee shops, airports, hotels) without an active VPN connection, and should address the patient home WiFi restriction for field staff specifically.
Section 6: Data Handling and Transmission
This section governs how ePHI is handled, transmitted, and disposed of. Key provisions: ePHI transmitted electronically must use only agency-approved, HIPAA-compliant channels with encryption in transit; paper PHI must be stored securely when not in use and disposed of in HIPAA-compliant shredding bins rather than general waste; devices must be locked when unattended; and ePHI must never be left visible to unauthorized individuals in public settings, patient homes, or shared spaces.
Section 7: Incident Reporting Requirements
Every workforce member must know what to do — and specifically what not to do — when they suspect a security incident has occurred. The policy must specify a reporting timeline (recommended: "immediately upon discovery or suspicion, not to exceed four hours"), name the reporting channel (HIPAA Security Officer, IT helpdesk number, or managed security provider direct line), and explicitly instruct staff not to attempt to investigate, resolve, or conceal a suspected incident before reporting it. The instinct to "fix it quietly" costs agencies hundreds of thousands of dollars in forensic complications every year.
Section 8: Acknowledgement and Enforcement
The AUP must be signed by every workforce member before they access any ePHI — and this acknowledgement must be re-executed at least annually. The policy must reference the sanctions policy and make clear that violations will result in disciplinary action up to and including termination and referral for criminal prosecution where applicable. An AUP without teeth is a suggestion.
Making the AUP Work for Field Staff
The most common AUP failure in home health is writing a document for an administrative office audience and handing it to nurses and aides who encounter patient data in completely different operational contexts. Review each provision through the lens of a field nurse completing a visit at 7am in a patient's living room. Does the language make sense in that context? If not, add context-specific examples. An AUP that field staff understand and can apply is compliance infrastructure. One they can't interpret is paper.
If you're ready to protect your home health agency with a cybersecurity partner that actually understands healthcare — not one that learned it from a brochure — start with a free HIPAA Risk Assessment. No obligation, no sales pressure. Thirty minutes with a healthcare cybersecurity expert.
→ Schedule Your Free HIPAA Risk Assessment — https://shieldforce.io/hipaa-assessment
→ Explore Home Healthcare Cybersecurity — https://shieldforce.io/home-healthcare
→ View Transparent Pricing from $35/user/month — https://shieldforce.io/home-healthcare/checkout

