This site provides independent HIPAA compliance cost estimates for informational purposes only. We are not affiliated with HHS, OCR, or any compliance vendor. This is not legal or regulatory advice. Consult a qualified HIPAA compliance professional for guidance specific to your organization.

Home Health Agency HIPAA Compliance Cost in 2026

The structural cost driver in home health is mobile PHI: every visit moves ePHI off the agency network, which makes mobile-device management, remote-wipe capability and field-staff training the incremental lines above a typical ambulatory practice. MDM is also the rare part of this budget with published rates, so this page prices it from the vendors' own cards and works it at fleet scale. The rest of a home-health programme, the risk assessment across uncontrolled visit environments and the policy work behind it, is quoted per engagement and published by nobody. This page separates the two rather than blending them into a single number.

Priced from a published card

  • MDM subscription, per device or per user
  • Identity and MFA, per user
  • Compliance platform subscription
  • Device disk encryption (enforced by the MDM you already bought)

Quoted per engagement, published by nobody

  • The risk assessment with field-mobility scope
  • Device-by-device enrollment labour
  • Field-mobility policy and procedure development
  • Mobile-app penetration testing
  • Home-health-specific training content

The right-hand column is where a home-health programme actually spends, and it is the column nobody publishes a rate for. What follows prices the left-hand column honestly and hands you the drivers for the right.

The mobile-PHI structural cost driver

Home health is the archetype HIPAA scenario where ePHI predictably leaves the controlled-network perimeter. Every visit, every field staffer carries a device into the patient's home, accesses the EHR, charts the visit, and returns. The device may be stolen, lost, dropped, or accessed by an unauthorized family member of the patient. The Security Rule's technical safeguards under 45 CFR 164.312 assume an asset inventory of bounded scope; home-health asset inventory by definition spans uncontrolled environments.

The compensating controls every home-health agency needs:

Mobile-device management (MDM). The published rates and the units are in the table below. Capabilities required: enforced disk encryption, lost-device tracking, remote wipe, conditional access tied to identity, app management (forcing the home-health EHR app and blocking app-store browsing on field devices), and tamper-detection that alerts on jailbreak or root.

Identity governance for field-staff lifecycle. Home-health staff turnover is structurally higher than office-based healthcare, and no primary source publishes a single clean rate for it, so this page states the direction and not a number. Identity-governance automation that enrolls, deprovisions, and audits access across the EHR, MDM, and ancillary systems is more critical here than at most healthcare verticals. The cost is the identity tooling subscription plus the engineering time to wire EHR and MDM into the identity workflow.

Field-staff training depth. The standard annual HIPAA training is insufficient for field staff who carry PHI into uncontrolled environments. Home-health-specific training adds modules on car-storage of devices (the device should not be visible in a parked car; the trunk is the minimum acceptable storage), patient-home conversational discipline (other household members may overhear), and incident-reporting cadence (lost or stolen device must be reported within hours, not days).

This is an informational cost reference, not legal or compliance advice. Consult a healthcare attorney or HIPAA-qualified compliance professional before making program decisions specific to your home-health agency.

The home-health EHR landscape

The dominant home-health EHRs are Homecare Homebase (now part of Hearst Health), MatrixCare (now part of ResMed), Axxess, WellSky, MEDsys, and Kinnser (now part of WellSky). Each handles OASIS submission natively, supports mobile field-charting, and signs a BAA for the SaaS infrastructure. The HIPAA-relevant evaluation criteria across these vendors:

The home-health EHR subscription cost is not strictly a HIPAA line item, but it influences the technical-safeguard cost: agencies on EHRs with mature MDM integration and strong audit-log support spend less on bolt-on tooling than agencies on EHRs with weaker native HIPAA capabilities.

The MDM layer, as published

Read the unit column before the price column. Three of these vendors publish a rate and one does not, and they do not meter the same thing: Intune bills per user, Jamf bills per device, and Omnissa publishes both. For a home-health agency, where the device count and the workforce count are genuinely different numbers, that distinction decides which product is cheapest for you.

Product and plan, as named by the vendorPublished rateUnit, as the vendor states it
Microsoft Intune Plan 1$8.00Per user/month standalone. Microsoft states it is included in Microsoft 365 E3, E5 and EMS E3/E5
Microsoft Intune Plan 2$4.00User/month, paid yearly. An add-on: requires a Plan 1 subscription
Jamf for Mobile$5.75Per mobile device, per month, billed annually, 25-device minimum
Jamf for Mac$12.50Per macOS device, per month, billed annually, 25-device minimum
Omnissa Workspace ONE Mobile Essentials$3.00 per device / $5.40 per userMonthly, based on 12 months prepaid with production-level support
Omnissa Workspace ONE UEM Essentials$5.25 per device / $9.45 per userMonthly, based on 12 months prepaid with production-level support
Citrix Endpoint ManagementNo published priceSold only inside the Universal Hybrid Multi-Cloud and Citrix Platform bundles

Sources, each read off the vendor's own pricing page and checked July 2026: Microsoft Intune pricing, jamf.com/pricing, Omnissa Workspace ONE UEM, Citrix Endpoint Management. Three naming points that matter when you go shopping. Jamf Pro is no longer a separately priced product: it is a component of Jamf for Mac and Jamf for Mobile, both of which state “Powered by: Jamf Pro, Jamf Connect and Jamf Protect”. Workspace ONE is an Omnissa product rather than a VMware one, following the 2024 divestiture of VMware's end-user computing business. And Microsoft prices Intune Plan 1 only in prose on its pricing page rather than on a card, alongside a device-only subscription for shared and kiosk devices that it documents but does not price, which is a gap worth raising in a quote if your field fleet is pooled rather than assigned.

What those rates work out to across a field fleet

Our arithmetic, not a vendor price

Every input below is a published figure from the table above. The multiplication is ours: no MDM vendor publishes an annual total for a home-health agency. The device and workforce counts are our stated assumptions and yours will differ, which is the point of showing the arithmetic rather than a total. This covers the MDM subscription only. Enrollment labour, the risk assessment and the mobile-app pen test are not in it, because nobody publishes a rate for them.

An agency assuming 150 field devices and 180 workforce members

On the device-metered products our arithmetic is: Omnissa Mobile Essentials $3.00 × 150 devices × 12 = $5,400 per year; Jamf for Mobile $5.75 × 150 × 12 = $10,350 per year, and 150 devices clears its 25-device minimum comfortably. On the user-metered product the multiplier is not 150: Intune Plan 1 at $8.00 per user per month across 180 workforce members is $8.00 × 180 × 12 = $17,280 per year. That gap is not a discount, it is a different meter. An agency that runs pooled tablets shared across shifts buys 150 units of a device-metered product and 180 of a user-metered one.

The Microsoft 365 question that usually settles it

Microsoft states that Intune Plan 1 is included in Microsoft 365 E3 and E5. An agency already licensed for E3 across its workforce has therefore already bought its MDM, and the $17,280 above is not incremental spend for it at all: the incremental question becomes whether it needs anything Plan 1 does not do. That single licensing fact moves a home-health MDM budget more than any comparison between the three vendors, and it is the first thing to check before running any of this arithmetic.

What none of this covers is the enrollment labour, which is real work at 150 devices spread across a field workforce and is quoted per engagement rather than published. Treat the subscription arithmetic as the floor of the MDM line, not the line.

Common home-health-specific incidents and their cost

Three field-staff incident patterns recur in OCR investigations of home-health agencies. Each is preventable; the cost of prevention is far below the cost of the breach response.

Pattern 1: Stolen device from parked clinician's car. A field nurse parks at a coffee shop between visits. The tablet is visible on the passenger seat. The car is broken into. The tablet is unencrypted or weakly encrypted, has no MDM enrollment, and contains the day's patient roster plus cached chart data. Breach-notification trigger under 45 CFR 164.404. What that costs is driven by the affected-individual count, which is driven by what was cached on the device: the notification itself, any credit monitoring you offer, call-centre capacity, and the regulatory response all scale with that number, and then the OCR investigation and any penalty sit on top. No per-individual rate is published for any of it, so the lever worth pulling is the one that sets the count: how much roster and chart data a field device caches offline, and whether the fleet is encrypted and remotely wipeable before it goes missing rather than after.

Pattern 2: Family-member observation of EHR screen during home visit. A clinician visits a patient, leaves the EHR open on the tablet while attending to the patient, and a family member observes another patient's data on a recently-accessed screen. Incidental-disclosure is sometimes permissible under 45 CFR 164.502(a)(1)(iii) when reasonable safeguards are in place; the relevant safeguard is auto-lock and the workflow discipline of closing screens between visits. Cost of fix: zero, just training.

Pattern 3: PHI in personal email or messaging. A clinician needs to coordinate with the office from the patient's home, uses personal Gmail or personal SMS to send a patient detail because the EHR's built-in messaging is slow. The personal email service has no BAA; the disclosure is unauthorized. Cost of fix: agency provides BAA-eligible messaging integrated with the EHR and trains staff to never use personal channels for PHI.

Home health HIPAA cost FAQ

Why is HIPAA cost different for a home-health agency than a clinic?
Three structural reasons. First, mobile PHI: home-health nurses and aides carry tablets, phones, or laptops into patient homes, which means ePHI leaves the agency's controlled-network perimeter on every visit. Mobile-device management (MDM) and remote-wipe capability become required controls rather than nice-to-have controls. Second, the field-staff distribution: a 50-clinician agency typically has 80 to 150 field staff, each of whom needs identity governance, training, and incident-reporting capability. Third, the CMS Conditions of Participation for home health (42 CFR Part 484) and the OASIS transmission requirement add federal program-integrity controls that overlap with HIPAA Security Rule audit requirements.
What did Filefax settle with OCR for, and why does it matter for home health?
Filefax Inc., a medical-records storage company, settled with OCR in 2018 for $100,000 (operating receiver settlement) after leaving boxes of paper medical records of more than 2,000 patients accessible to the public outside the company premises. While Filefax was a business associate rather than a home-health agency directly, the fact pattern (PHI leaving the controlled premises and ending up in an uncontrolled environment) is the home-health-agency archetype risk. Home-health agencies that carry paper records or unencrypted devices into patient homes and back are operating the same risk profile. The Filefax-style enforcement risk to a home-health agency is meaningful: a stolen unencrypted tablet from a clinician's car, dropped paper records, or a discarded device with PHI still on it can each trigger investigation.
What does HIPAA cost a 50-clinician home-health agency?
This page prints no all-in figure, because a home-health HIPAA budget is half published rates and half quotes, and the quoted half is the larger one. The MDM layer, which is the line that genuinely distinguishes home health from clinic-based care, does have published rates: Microsoft publishes Intune Plan 1 at $8.00 per user per month standalone and states it is included in Microsoft 365 E3 and E5; Jamf publishes Jamf for Mobile at $5.75 per mobile device per month billed annually with a 25-device minimum; Omnissa publishes Workspace ONE Mobile Essentials at $3.00 per device per month on a 12-month prepaid term. All checked July 2026 on the vendors' own pricing pages. What has no published rate is the risk assessment with field-mobility scope, the policy work, the mobile-app penetration test and the device-by-device enrollment labour, all of which are quoted per engagement. Anyone quoting you a single home-health program number is estimating, not reading it off anything.
What MDM platform should a home-health agency use?
Three publish a rate and the fourth does not, and the units are not the same, which is the thing to understand before comparing them. Microsoft Intune Plan 1 is $8.00 per USER per month standalone and is included in Microsoft 365 E3 and E5, so an agency already on E3 may be paying for it already. Jamf for Mobile is $5.75 per mobile DEVICE per month billed annually with a 25-device minimum, and Jamf for Mac is $12.50 per macOS device; note that Jamf Pro is no longer a separately priced SKU, it is a component of those bundles. Omnissa Workspace ONE, which is where VMware's end-user computing business went after the 2024 divestiture, publishes both units side by side: Mobile Essentials at $3.00 per device or $5.40 per user per month, prices stated as monthly on 12 months prepaid. Citrix Endpoint Management publishes no standalone price at all and is sold only inside its Universal Hybrid Multi-Cloud and Citrix Platform bundles. All figures checked July 2026 on the vendors' own pricing pages. The unit decides which is cheapest for you: an agency whose field staff share pooled tablets pays per device and wants a device-metered product, while an agency where every clinician has a named login pays per user either way. The HIPAA-relevant capabilities are the same across all of them: remote wipe, lost-device tracking, app management, enforced disk encryption, and conditional access tied to identity.
How does OASIS data transmission affect HIPAA cost?
The Outcome and Assessment Information Set (OASIS) is the CMS-required assessment that home-health agencies submit for Medicare and Medicaid patients. OASIS submission is via the CMS iQIES system and contains substantial PHI. The OASIS transmission process is covered by HIPAA Security Rule transmission-security requirements under 45 CFR 164.312(e)(1). Most home-health EHRs (Homecare Homebase, MatrixCare, Axxess, WellSky, MEDsys) handle OASIS submission natively with transmission-security controls. The HIPAA-relevant added cost for agencies that handle OASIS outside the EHR (manual data entry into iQIES, third-party OASIS-QA services) is in vendor BAA verification and in audit-log review for the transmission process.
What other vendors does a home-health agency need BAAs with?
Beyond the EHR vendor BAA and the standard medical-vendor BAAs, home-health agencies need BAAs with: MDM vendor, telephony / scheduling vendor (TigerConnect, similar), patient-monitoring device vendors if the agency provides remote patient monitoring, durable medical equipment (DME) suppliers that receive patient identification, hospice and palliative-care care-coordination services, social services and community-resource referral systems, payer authorization-management services, OASIS QA outsourcing vendors, billing service vendors, fax service vendors for physician orders, and patient-engagement platforms. A typical 50-clinician home-health agency maintains 40 to 80 active BAAs.
How does the 2026 Security Rule NPRM affect home-health agencies?
Three NPRM provisions hit home health harder than typical ambulatory care. First, the MFA requirement adds friction to field-staff workflow because tablets in patient homes need to authenticate without disrupting the clinical visit; the workaround is conditional access policies tied to MDM-enrolled devices, which most modern MDM platforms support but requires configuration. Second, the asset inventory + network map requirement is unusually complex because the field-device fleet is mobile and frequently changing. Third, the encryption-without-exceptions mandate eliminates the addressable carve-out that some home-health agencies relied on for the older tablet fleet. On what this costs, HHS priced its own proposal and did not price it by segment. The NPRM's regulatory impact analysis estimates roughly $9 billion in first-year costs across 1,822,600 regulated entities, and the only per-entity figure it publishes is approximately $1,235 in annualized cost per regulated entity, flat across every segment and size band. HHS counts 38,040 home health establishments in its analysis but attaches no cost to that count, and it gives no dollar figure at all for the asset inventory or encryption provisions. There is no HHS figure for a home health agency, so we print none.

Related cost guides

Updated 2026-07-17