Also on CyberFence: CyberFence's industry directory for other professions · CyberFence for Teams for business VPN with BAA and SSO .

Home health aide in navy scrubs showing tablet to elderly male client seated in armchair in home living room with walker and family photos visible

Home health aides log more patient-facing hours than almost any other healthcare worker — and they do it entirely in the field, at the homes of the people they serve. Every visit involves electronic health records, care plan documentation, medication logs, and agency portal check-ins, all completed on tablets and phones over the client's home Wi-Fi network.

That connectivity pattern creates a specific HIPAA exposure that most home care agencies haven't addressed systematically, and that most individual aides don't have the technical background to recognize. This guide explains what's at risk, why client home Wi-Fi creates a compliance problem, and what a VPN does to solve it.

What Home Health Aides Handle on Every Visit

A home health aide's device workload during a typical shift includes more sensitive data than many office workers see in a week:

  • Electronic visit verification (EVV) — federally required documentation of visit start/end times, location, and services rendered. EVV data links the aide's identity to the patient's care record on every visit.
  • Care plan documentation — detailed records of activities of daily living (ADLs), patient condition, and any changes in health status. Filed through agency apps that connect to the patient's EHR.
  • Medication administration records (MAR) — if aides assist with medications, each administration is documented and transmitted through the agency's clinical system.
  • Patient vitals — blood pressure, weight, temperature, and other measurements entered into connected health apps at the point of care.
  • Incident reports — any fall, injury, behavioral change, or concern documented in real time and transmitted to supervisors and clinical staff.
  • Agency portal login — scheduling, payroll, HR, and training systems, all accessed through credentials that tie the aide's professional account to their patient caseload.

Every piece of this data is Protected Health Information (PHI) under HIPAA. Every transmission of PHI over an unsecured network is a potential compliance violation.

Why Client Home Wi-Fi Is a HIPAA Problem

HIPAA's Security Rule requires covered entities and their business associates to implement encryption for PHI transmitted over open networks. Client home Wi-Fi qualifies as an open network for HIPAA purposes — it's a network the agency doesn't control, hasn't configured, and can't verify.

When an aide connects their tablet or phone to a client's home Wi-Fi and opens the EVV app or care documentation portal, they're transmitting PHI over an uncontrolled network. The security of that network depends entirely on the client — who may be running a default router configuration from 2018, sharing a password with family members and visitors, or connecting devices that have never been updated.

Home care agencies that qualify as covered entities (those billing Medicare or Medicaid) and their aides who handle PHI are subject to these requirements. An aide using an agency-issued device to document care over a client's unsecured Wi-Fi creates an exposure that the agency is responsible for under the Security Rule.

A VPN eliminates this exposure. When the aide connects to CyberFence before opening any care documentation app, every transmission is encrypted before it leaves the device — the client's Wi-Fi carries only encrypted packets, with no access to the PHI being transmitted.

HIPAA-Ready Encryption for Every Home Visit

CyberFence encrypts all connections from your tablet and phone with AES-256-GCM encryption — client homes, agency portals, care apps, anywhere you document care. US-operated, zero logs, HIPAA-aligned.

See Plans →

The EVV Compliance Layer

Electronic visit verification became federally required for Medicaid personal care and home health services under the 21st Century Cures Act, with full implementation across most states by 2024. EVV data — visit location, duration, and service type tied to patient records — is transmitted from the aide's device to the state Medicaid system through the agency's EVV platform.

This means aides are now transmitting patient data to state government systems from client home networks on every Medicaid visit. The agencies providing these services have HIPAA Business Associate Agreements with the underlying EVV technology providers, and those agreements include security requirements for how data is transmitted.

Encrypting EVV transmissions via VPN is a straightforward way to satisfy the transmission security requirements in those BAAs and the underlying HIPAA Security Rule provisions.

Personal Device Risk

Many home health aides use personal smartphones rather than agency-issued devices, particularly at smaller agencies or in independent contractor arrangements. Personal devices present additional risks beyond network security:

  • Shared device access — family members who use the aide's phone have potential access to care documentation apps if session management is weak
  • Public Wi-Fi exposure — aides who check patient documentation from coffee shops, public transit, or other locations between visits are transmitting PHI over clearly unsecured networks
  • App-level phishing — fake apps impersonating EVV or care documentation platforms have appeared in app stores; a VPN with DNS filtering blocks connections to known malicious domains
  • Unencrypted data in transit on cellular — while 4G/5G cellular data has encryption at the carrier level, VPN adds an additional application-layer encryption that protects against interception at the destination server level

CyberFence's auto-connect feature protects personal devices the same way it protects agency-issued ones — the VPN connects automatically when the aide joins any network, so care documentation is encrypted regardless of whether the aide is using home Wi-Fi, a client's Wi-Fi, or a public hotspot.

What the Agency Is Responsible For

Home care agencies that provide aides to Medicare or Medicaid beneficiaries are covered entities under HIPAA. They're responsible for the security of PHI handled by their workforce — which includes aides using personal or agency devices to document care.

Agency HIPAA compliance programs should include:

  • A written policy requiring encrypted connections for any PHI access outside the agency office
  • Documented training on using VPN before accessing care documentation apps
  • A VPN solution provided to aides or included as a required tool for employment
  • Annual HIPAA Security Rule risk assessments that account for remote care documentation

Agencies that have experienced HIPAA enforcement actions understand that the cost of a breach — OCR investigation, potential civil monetary penalties, required corrective action plans — far exceeds the cost of implementing reasonable technical controls. VPN for field staff is one of the most cost-effective controls available, at under $10 per aide per month.

A Day in the Field With CyberFence

In practice, using CyberFence as a home health aide requires almost no behavior change:

  1. Arrive at client's home
  2. Connect to client's Wi-Fi (CyberFence auto-connects in the background)
  3. Open EVV app or care documentation portal — all transmissions are encrypted
  4. Document visit, medication administration, and vitals
  5. Complete check-out — all transmitted data was encrypted throughout the visit

The aide doesn't need to think about VPN activation. CyberFence detects the new network and establishes the encrypted connection automatically. The care documentation apps work exactly as before — the only difference is that PHI transmissions are now encrypted regardless of the underlying network's security level.

What CyberFence Provides for Home Health Professionals

  • AES-256-GCM encryption on every connection — client homes, public networks, cellular data
  • Auto-connect on untrusted networks — protection activates before any data leaves your device
  • Web Shield DNS filtering — blocks phishing sites impersonating care documentation and EVV platforms
  • Zero-log policy — no activity records; supports HIPAA minimum necessary principle
  • US-operated infrastructure — data stays under US law; relevant for HIPAA compliance documentation
  • iOS and Android apps — works on both iPhone and Android tablets and phones used for field care documentation
  • HIPAA Security Rule alignment — satisfies transmission security requirements for PHI over open networks

Home health aides serve some of the most vulnerable patients in the healthcare system, in the most intimate setting possible. Protecting the data that follows those visits — and the HIPAA compliance status of the agencies that employ them — is a responsibility that starts with encrypted connections on every home visit.

Start Protecting Patient Data on Every Visit

Download CyberFence from the App Store or Google Play and start your free trial. AES-256-GCM encryption, Web Shield, zero logs — everything home care professionals need for HIPAA-aligned documentation in the field.

View Plans →

Want to go deeper? Read how CyberFence protects other regulated industries , the CyberFence Teams product page , or CyberFence plans and pricing .