Compliance

    HIPAA Compliance: What Human Services Agencies Need to Know

    A comprehensive guide to maintaining HIPAA compliance while using modern software tools.

    Jennifer Torres, JD
    Compliance Director
    Sep 8, 2025
    10 min read

    Understanding HIPAA in Human Services Context

    The Health Insurance Portability and Accountability Act (HIPAA) isn't just for hospitals. Many human services agencies handle Protected Health Information (PHI) and must comply with HIPAA requirements. Understanding these obligations is essential for protecting clients and your organization.

    Who Must Comply?

    Covered Entities

    You're a covered entity if you:

    • Provide health care services and bill electronically
    • Operate as a health plan
    • Act as a health care clearinghouse

    Business Associates

    Even if you're not a covered entity, you may be a "business associate" if you:

    • Handle PHI on behalf of covered entities
    • Provide services involving PHI access
    • Create, receive, maintain, or transmit PHI

    Many human services agencies fall into one of these categories, particularly those providing:

    • Mental health services
    • Substance abuse treatment
    • Developmental disability services
    • Health-related case management

    The Three HIPAA Rules

    1. Privacy Rule

    The Privacy Rule governs how PHI can be used and disclosed:

    Key Requirements:

    • Minimum necessary standard: Only access/share what's needed
    • Client authorization required for most disclosures
    • Individuals have rights to access and amend their records
    • Privacy notices must be provided

    Common Exceptions:

    • Treatment, payment, and operations
    • Required by law
    • Public health activities
    • Abuse/neglect reporting

    2. Security Rule

    The Security Rule mandates safeguards for electronic PHI (ePHI):

    Administrative Safeguards:

    • Risk assessments
    • Workforce training
    • Access management policies
    • Incident response procedures

    Physical Safeguards:

    • Facility access controls
    • Workstation security
    • Device and media controls

    Technical Safeguards:

    • Access controls (unique user IDs, automatic logoff)
    • Audit controls (activity logging)
    • Integrity controls (data hasn't been altered)
    • Transmission security (encryption)

    3. Breach Notification Rule

    When PHI is compromised, you must:

    • Notify affected individuals within 60 days
    • Notify HHS (timing depends on breach size)
    • Notify media for breaches affecting 500+ in a state
    • Document all breaches regardless of size

    Software Selection Considerations

    When choosing technology platforms, verify:

    Business Associate Agreements (BAAs)

    • Any vendor handling PHI must sign a BAA
    • The BAA must address all required elements
    • Keep BAAs organized and accessible

    Security Features

    Look for:

    • Role-based access controls
    • Encryption at rest and in transit
    • Audit logging
    • Automatic session timeouts
    • Multi-factor authentication options

    Data Location and Handling

    Understand:

    • Where data is stored (cloud location matters)
    • How backups are handled
    • Data retention and destruction policies
    • Subcontractor relationships

    Common Compliance Mistakes

    1. Assuming you're exempt: Many agencies underestimate their HIPAA obligations
    2. Inadequate risk assessments: Must be thorough and regular
    3. Training gaps: All staff need appropriate training
    4. Missing BAAs: Every vendor with PHI access needs one
    5. Weak access controls: Too many people with too much access
    6. Poor documentation: Policies exist but aren't followed or documented

    Building a Compliance Program

    Start With Assessment

    • Identify all PHI in your organization
    • Map data flows (where it goes, who accesses it)
    • Conduct thorough risk assessment
    • Document findings and create remediation plan

    Implement Policies and Procedures

    • Develop comprehensive policies
    • Create practical procedures staff can follow
    • Review and update regularly

    Train Your Workforce

    • Initial training for all new staff
    • Regular refresher training
    • Role-specific training where needed
    • Document all training

    Monitor and Improve

    • Regular audits of compliance
    • Incident tracking and response
    • Continuous improvement based on findings

    The Bottom Line

    HIPAA compliance isn't optional, and the penalties for violations can be severe—both financially and reputationally. But more importantly, these requirements exist to protect the vulnerable individuals your agency serves.

    Investing in compliance is investing in trust. When clients know their sensitive information is protected, they're more likely to engage fully in services—leading to better outcomes for everyone.

    See OutcomeGrid in action

    Documentation, EVV, billing, and outcomes in one platform built for Colorado human services agencies.

    Talk to our team

    Related Articles