
Toolkit overview
Image 1 of 6: Toolkit overviewHIPAA Compliance Toolkit — Home Health & Home Care Agencies
Last updated:
18 editable HIPAA policies plus the Security Risk Assessment workbook and audit evidence checklist, written for home health and home care agencies whose workforce serves clients in their homes.
The HIPAA Compliance Toolkit — Home Health & Home Care Agencies is a set of 18 editable HIPAA Security & Privacy Rules document templates in Microsoft Word (.docx), plus 2 pre-filled Excel workbooks (.xlsx), written for Home health & home care agencies. It is a one-time purchase with instant download and a single-organization license; you replace the amber [placeholders] with your organization's details. The toolkit provides a structure to adapt to your applicable requirements. It does not establish HIPAA compliance or provide certification; HHS does not recognize private Security Rule certifications as proof of compliance.
- What it is
- 18 editable HIPAA Security & Privacy Rules document templates, plus 2 Excel workbooks
- Formats
- Microsoft Word (.docx) + Excel (.xlsx)
- Best for
- Home health & home care agencies
- Price
- $149 — one-time purchase, single-organization license
- Delivery
- Instant download after checkout
New to HIPAA Security & Privacy Rules? Read our HIPAA guide →
Overview
The HIPAA Compliance Toolkit for Home Health & Home Care Agencies is a complete set of editable HIPAA policies built for agencies whose workforce serves clients in their homes. It is designed for home-based care workflows. HIPAA applies when an agency is a covered entity or business associate; handling health information or providing non-medical care alone does not establish that status. Confirm which requirements apply to your agency before adopting the policies. You get 18 Microsoft Word policies plus two Excel workbooks. The documents speak the language of a real agency. They reference the EVV and scheduling platform, field caregivers documenting on smartphones and tablets, route sheets and visit notes carried in vehicles, and a small agency office — sometimes a home office — anchoring a workforce that is rarely in it. You download the files instantly and tailor them to your agency. This toolkit is for the administrator, the owner, or the director of nursing. It is for anyone who needs a defensible written HIPAA program without hiring a consultant or starting from a blank page.
Most agencies come here under real pressure. A referral partner or payer asks for your written HIPAA policies before signing a contract. A caregiver's phone goes missing between visits with the EVV app signed in, and you need to show a documented security program. Your cyber or professional liability insurer wants proof that written safeguards exist. An accreditation survey is on the calendar, or a new EVV or scheduling platform rollout exposes how thin the current documentation is. The Security Rule requires covered entities to document a risk analysis under 45 CFR 164.308(a)(1), and payers and partners ask agencies that handle client health information for the same documentation. This toolkit answers those demands in one package.
Inside are 18 policies that map directly to the HIPAA Security and Privacy Rules. The HIPAA Security Management Policy anchors the set. It implements the security management process at 45 CFR 164.308(a)(1), including risk analysis, risk management, a sanction policy, and activity review — and it reaches the field, from the caregiver's smartphone in a parked vehicle to the visit note in a client's kitchen. You also get the Security Official Designation and Responsibilities, the Workforce Security and Access Authorization Policy, the ePHI Access Control Policy, and the Authentication and Password Policy.
The Workstation Use and Security Policy, Encryption and Transmission Security Policy, Audit Controls and Activity Review Policy, Device and Media Control Policy, Facility Security Plan, and Contingency and Disaster Recovery Plan cover the technical and physical safeguards, written for an operation whose care setting is usually someone else's home. The Security Incident Response Procedure, Breach Notification Procedure, Business Associate Management Policy, Sanction Policy, and Workforce Termination and Offboarding Procedure handle enforcement and response, down to collecting devices, keys, and credentials from a departing field caregiver. The HIPAA Privacy Rule Compliance Policy and a Security Awareness and Training Program complete the set.
Two Excel workbooks come with it: the HIPAA Security Risk Assessment, which structures the risk analysis around where ePHI actually lives in a field operation, and the Audit Evidence Checklist, which helps you organize proof of your program in one place.
The toolkit also speaks your daily reality. It addresses caregiver smartphones, tablets, and laptops used in the field and in vehicles, including personal devices. It helps you assess EVV and scheduling vendors under the Business Associate Management Policy and document agreements where the relationship requires them. It covers verbal PHI inside client homes where family members share the space, disclosure limits for family caregivers and household members, client-home Wi-Fi and public networks, and the paper trail of route sheets, visit notes, and care plans. It accounts for a distributed workforce of employees and contract (1099) caregivers who onboard, train, and offboard without ever sitting in your office. Because the documents name these realities directly, you can review and adapt the policies against your actual operation.
Be clear about what these documents do and do not do. HHS does not endorse or recognize private Security Rule certifications, and no template makes an agency compliant on its own. Documentation is the readiness layer. It records your decisions, assigns accountability, and gives you something concrete to show a partner, an insurer, or an investigator. Real compliance comes from operating the controls every day: training every caregiver, employee and contractor alike, reviewing access, collecting what departing staff carry, and reviewing and updating the risk analysis as needed to keep it current as your environment changes.
This toolkit gives your agency's program a professional foundation and a genuine head start. You and your team still run the program itself. The files are editable Word and Excel, delivered as an instant download under a single-organization license.
The set includes a Business Associate Management Policy, not a BAA contract template. HHS publishes free sample agreement provisions. The annual review and 30/60-day internal deadlines in the policy preview are template choices for your review, not universal HIPAA deadlines. The toolkit does not include legal review, a completed risk analysis, delivered staff training or certification.
Which HIPAA Security & Privacy Rules edition do I need?
4 editions share this framework. They differ by who they are written for — the documents themselves are the same professional standard throughout.
| Edition | Written for | Documents | Price |
|---|---|---|---|
| HIPAA Compliance Toolkit — Dental Practices | Dental practices | 18 + 2 workbooks | $149 |
| HIPAA Compliance Toolkit — Home Health & Home Care Agencies You’re viewing this | Home health & home care agencies | 18 + 2 workbooks | $149 |
| HIPAA Compliance Toolkit — Medical Practices | Medical practices & clinics | 18 + 2 workbooks | $149 |
| HIPAA Compliance Toolkit — Mental Health Practices | Mental & behavioral health practices | 18 + 2 workbooks | $149 |
What's inside — 18 documents + 2 workbooks
- HIPAA Security Management Policy (.docx)
- Security Official Designation and Responsibilities (.docx)
- Workforce Security and Access Authorization Policy (.docx)
- Security Awareness and Training Program (.docx)
- Workstation Use and Security Policy (.docx)
- ePHI Access Control Policy (.docx)
- Authentication and Password Policy (.docx)
- Encryption and Transmission Security Policy (.docx)
- Audit Controls and Activity Review Policy (.docx)
- Device and Media Control Policy (.docx)
- Facility Security Plan (.docx)
- Contingency and Disaster Recovery Plan (.docx)
- Security Incident Response Procedure (.docx)
- Breach Notification Procedure (.docx)
- Business Associate Management Policy (.docx)
- Sanction Policy (.docx)
- HIPAA Privacy Rule Compliance Policy (.docx)
- Workforce Termination and Offboarding Procedure (.docx)
That works out to $8.28 per document. Individual templates are $9.99 each.
Excel workbooks
- HIPAA Security Risk Assessment (Excel)
- Audit Evidence Checklist (Excel)
See the real content before you buy
We publish genuine excerpts — not marketing mockups. Read the opening sections of the HIPAA Security Management Policy exactly as you'll receive it:
Read the free previewFrequently asked questions
- Does this HIPAA toolkit include a Security Risk Assessment?
- It includes an editable HIPAA Security Risk Assessment workbook to complete for your organization, 18 Word policies and procedures, and an Audit Evidence Checklist workbook. The purchase does not include a completed assessment or legal review.
- Does this satisfy the HIPAA Security Rule risk analysis requirement?
- The Security Rule requires an accurate and thorough risk analysis under 45 CFR 164.308(a)(1)(ii)(A); it does not require this workbook or one particular methodology. The toolkit provides a structure. Your organization must perform the analysis, address its risks, operate the applicable safeguards and keep the assessment current.
- Is it written for my care setting?
- We publish editions by care setting — medical, dental and mental/behavioral health practices, and home health & home care agencies — with systems, risk examples and workflows to review against how your organization creates, stores and transmits ePHI.
- Does the toolkit include a Business Associate Agreement contract?
- No. It contains a Business Associate Management Policy, not a BAA contract template. HHS publishes free sample agreement provisions. Determine which relationships require an agreement and obtain appropriate review for the actual arrangement.
- Does a non-medical home-care agency automatically fall under HIPAA?
- No. HIPAA applies when the agency meets the definition of a covered entity or business associate. Handling health information or providing non-medical care alone does not settle that status. Confirm applicability before adopting the policies; other privacy or contractual obligations may still apply.
- What format are the files and how are they delivered?
- Editable Microsoft Word (.docx) and Excel (.xlsx) files, delivered as an instant download immediately after checkout. Organization-specific values are amber [bracketed placeholders] you replace with find-and-replace.
- What license do I get?
- A single-organization license. If you are a consultant or MSP intending to reuse the documents across multiple clients, contact us first for a fair multi-client arrangement.
- What if a file is defective or is not what the page described?
- Because delivery is instant, sales are final — but if a file is defective or materially does not do what this site describes, email support@compliancedocshq.com within 14 days of purchase and we will repair, replace or refund it. The choice of remedy is ours, but we will make a genuine defect right. Purchases made through a marketplace such as Etsy follow that marketplace's policies.
- What happens after I pay, and what if I lose the download link?
- You are taken to a receipt page with your download, and a delivery email is sent to the address you enter at checkout. No account is required. Download links expire for security — if yours has lapsed, reload your receipt page or email support@compliancedocshq.com for a fresh link.
