Home Health Agency HIPAA Compliance Cost in 2026
The structural cost driver in home health is mobile PHI: every visit moves ePHI off the agency network, which makes mobile-device management, remote-wipe capability and field-staff training the incremental lines above a typical ambulatory practice. MDM is also the rare part of this budget with published rates, so this page prices it from the vendors' own cards and works it at fleet scale. The rest of a home-health programme, the risk assessment across uncontrolled visit environments and the policy work behind it, is quoted per engagement and published by nobody. This page separates the two rather than blending them into a single number.
Priced from a published card
- MDM subscription, per device or per user
- Identity and MFA, per user
- Compliance platform subscription
- Device disk encryption (enforced by the MDM you already bought)
Quoted per engagement, published by nobody
- The risk assessment with field-mobility scope
- Device-by-device enrollment labour
- Field-mobility policy and procedure development
- Mobile-app penetration testing
- Home-health-specific training content
The right-hand column is where a home-health programme actually spends, and it is the column nobody publishes a rate for. What follows prices the left-hand column honestly and hands you the drivers for the right.
The mobile-PHI structural cost driver
Home health is the archetype HIPAA scenario where ePHI predictably leaves the controlled-network perimeter. Every visit, every field staffer carries a device into the patient's home, accesses the EHR, charts the visit, and returns. The device may be stolen, lost, dropped, or accessed by an unauthorized family member of the patient. The Security Rule's technical safeguards under 45 CFR 164.312 assume an asset inventory of bounded scope; home-health asset inventory by definition spans uncontrolled environments.
The compensating controls every home-health agency needs:
Mobile-device management (MDM). The published rates and the units are in the table below. Capabilities required: enforced disk encryption, lost-device tracking, remote wipe, conditional access tied to identity, app management (forcing the home-health EHR app and blocking app-store browsing on field devices), and tamper-detection that alerts on jailbreak or root.
Identity governance for field-staff lifecycle. Home-health staff turnover is structurally higher than office-based healthcare, and no primary source publishes a single clean rate for it, so this page states the direction and not a number. Identity-governance automation that enrolls, deprovisions, and audits access across the EHR, MDM, and ancillary systems is more critical here than at most healthcare verticals. The cost is the identity tooling subscription plus the engineering time to wire EHR and MDM into the identity workflow.
Field-staff training depth. The standard annual HIPAA training is insufficient for field staff who carry PHI into uncontrolled environments. Home-health-specific training adds modules on car-storage of devices (the device should not be visible in a parked car; the trunk is the minimum acceptable storage), patient-home conversational discipline (other household members may overhear), and incident-reporting cadence (lost or stolen device must be reported within hours, not days).
This is an informational cost reference, not legal or compliance advice. Consult a healthcare attorney or HIPAA-qualified compliance professional before making program decisions specific to your home-health agency.
The home-health EHR landscape
The dominant home-health EHRs are Homecare Homebase (now part of Hearst Health), MatrixCare (now part of ResMed), Axxess, WellSky, MEDsys, and Kinnser (now part of WellSky). Each handles OASIS submission natively, supports mobile field-charting, and signs a BAA for the SaaS infrastructure. The HIPAA-relevant evaluation criteria across these vendors:
- Native MDM integration: does the EHR mobile app integrate with Intune, Jamf, Workspace ONE for conditional access?
- Offline-mode encryption: when the device loses connectivity in a rural patient's home, what data is cached locally, and how is it encrypted?
- Audit-log completeness: what user activity is captured, at what granularity, and for how long?
- OASIS transmission security: is the OASIS submission to CMS iQIES handled natively or does it require a third-party tool?
- BAA terms: what is the vendor's breach-notification SLA, what is the data-residency commitment, and what audit rights does the agency retain?
The home-health EHR subscription cost is not strictly a HIPAA line item, but it influences the technical-safeguard cost: agencies on EHRs with mature MDM integration and strong audit-log support spend less on bolt-on tooling than agencies on EHRs with weaker native HIPAA capabilities.
The MDM layer, as published
Read the unit column before the price column. Three of these vendors publish a rate and one does not, and they do not meter the same thing: Intune bills per user, Jamf bills per device, and Omnissa publishes both. For a home-health agency, where the device count and the workforce count are genuinely different numbers, that distinction decides which product is cheapest for you.
| Product and plan, as named by the vendor | Published rate | Unit, as the vendor states it |
|---|---|---|
| Microsoft Intune Plan 1 | $8.00 | Per user/month standalone. Microsoft states it is included in Microsoft 365 E3, E5 and EMS E3/E5 |
| Microsoft Intune Plan 2 | $4.00 | User/month, paid yearly. An add-on: requires a Plan 1 subscription |
| Jamf for Mobile | $5.75 | Per mobile device, per month, billed annually, 25-device minimum |
| Jamf for Mac | $12.50 | Per macOS device, per month, billed annually, 25-device minimum |
| Omnissa Workspace ONE Mobile Essentials | $3.00 per device / $5.40 per user | Monthly, based on 12 months prepaid with production-level support |
| Omnissa Workspace ONE UEM Essentials | $5.25 per device / $9.45 per user | Monthly, based on 12 months prepaid with production-level support |
| Citrix Endpoint Management | No published price | Sold only inside the Universal Hybrid Multi-Cloud and Citrix Platform bundles |
Sources, each read off the vendor's own pricing page and checked July 2026: Microsoft Intune pricing, jamf.com/pricing, Omnissa Workspace ONE UEM, Citrix Endpoint Management. Three naming points that matter when you go shopping. Jamf Pro is no longer a separately priced product: it is a component of Jamf for Mac and Jamf for Mobile, both of which state “Powered by: Jamf Pro, Jamf Connect and Jamf Protect”. Workspace ONE is an Omnissa product rather than a VMware one, following the 2024 divestiture of VMware's end-user computing business. And Microsoft prices Intune Plan 1 only in prose on its pricing page rather than on a card, alongside a device-only subscription for shared and kiosk devices that it documents but does not price, which is a gap worth raising in a quote if your field fleet is pooled rather than assigned.
What those rates work out to across a field fleet
Our arithmetic, not a vendor price
Every input below is a published figure from the table above. The multiplication is ours: no MDM vendor publishes an annual total for a home-health agency. The device and workforce counts are our stated assumptions and yours will differ, which is the point of showing the arithmetic rather than a total. This covers the MDM subscription only. Enrollment labour, the risk assessment and the mobile-app pen test are not in it, because nobody publishes a rate for them.
An agency assuming 150 field devices and 180 workforce members
On the device-metered products our arithmetic is: Omnissa Mobile Essentials $3.00 × 150 devices × 12 = $5,400 per year; Jamf for Mobile $5.75 × 150 × 12 = $10,350 per year, and 150 devices clears its 25-device minimum comfortably. On the user-metered product the multiplier is not 150: Intune Plan 1 at $8.00 per user per month across 180 workforce members is $8.00 × 180 × 12 = $17,280 per year. That gap is not a discount, it is a different meter. An agency that runs pooled tablets shared across shifts buys 150 units of a device-metered product and 180 of a user-metered one.
The Microsoft 365 question that usually settles it
Microsoft states that Intune Plan 1 is included in Microsoft 365 E3 and E5. An agency already licensed for E3 across its workforce has therefore already bought its MDM, and the $17,280 above is not incremental spend for it at all: the incremental question becomes whether it needs anything Plan 1 does not do. That single licensing fact moves a home-health MDM budget more than any comparison between the three vendors, and it is the first thing to check before running any of this arithmetic.
What none of this covers is the enrollment labour, which is real work at 150 devices spread across a field workforce and is quoted per engagement rather than published. Treat the subscription arithmetic as the floor of the MDM line, not the line.
Common home-health-specific incidents and their cost
Three field-staff incident patterns recur in OCR investigations of home-health agencies. Each is preventable; the cost of prevention is far below the cost of the breach response.
Pattern 1: Stolen device from parked clinician's car. A field nurse parks at a coffee shop between visits. The tablet is visible on the passenger seat. The car is broken into. The tablet is unencrypted or weakly encrypted, has no MDM enrollment, and contains the day's patient roster plus cached chart data. Breach-notification trigger under 45 CFR 164.404. What that costs is driven by the affected-individual count, which is driven by what was cached on the device: the notification itself, any credit monitoring you offer, call-centre capacity, and the regulatory response all scale with that number, and then the OCR investigation and any penalty sit on top. No per-individual rate is published for any of it, so the lever worth pulling is the one that sets the count: how much roster and chart data a field device caches offline, and whether the fleet is encrypted and remotely wipeable before it goes missing rather than after.
Pattern 2: Family-member observation of EHR screen during home visit. A clinician visits a patient, leaves the EHR open on the tablet while attending to the patient, and a family member observes another patient's data on a recently-accessed screen. Incidental-disclosure is sometimes permissible under 45 CFR 164.502(a)(1)(iii) when reasonable safeguards are in place; the relevant safeguard is auto-lock and the workflow discipline of closing screens between visits. Cost of fix: zero, just training.
Pattern 3: PHI in personal email or messaging. A clinician needs to coordinate with the office from the patient's home, uses personal Gmail or personal SMS to send a patient detail because the EHR's built-in messaging is slow. The personal email service has no BAA; the disclosure is unauthorized. Cost of fix: agency provides BAA-eligible messaging integrated with the EHR and trains staff to never use personal channels for PHI.
Home health HIPAA cost FAQ
Why is HIPAA cost different for a home-health agency than a clinic?
What did Filefax settle with OCR for, and why does it matter for home health?
What does HIPAA cost a 50-clinician home-health agency?
What MDM platform should a home-health agency use?
How does OASIS data transmission affect HIPAA cost?
What other vendors does a home-health agency need BAAs with?
How does the 2026 Security Rule NPRM affect home-health agencies?
Related cost guides
Hospital HIPAA Cost
Hospital-affiliated home-health context
Physician Group Cost
Mid-size ambulatory pricing read
Telehealth HIPAA Cost
Remote patient monitoring overlay
Business Associate Guide
DME and remote-monitoring BA considerations
2026 Security Rule Changes
MFA and asset-inventory impact on field fleets
HIPAA Penalties
Filefax + mobile-device-loss enforcement