Bindinglaw

US · guidance

CMS SOM App. B, Tag G1028

§484.110(d) Standard: Protection of records

activein force · 2026-07-22 – presentas-observed

The clinical record, its contents, and the information contained therein must be

safeguarded against loss or unauthorized use. The HHA must be in compliance

with the rules regarding personal health information set out at 45 CFR parts 160

and 164.

Interpretive Guidelines §484.110(d)

HHA staff (whether employed directly or under arrangement) who carry documents

and/or electronic devices containing Protected Health Information from patient’s homes

to the HHA office, or to and from the HHA staff member’s home, create additional

confidentiality/protection concerns with patient records.

Section 45 CFR Parts 160 and 164, generally known as the Health Insurance Portability

and Accountability Act (HIPAA) Privacy and Security rules, establish standards for

health care providers and suppliers that conduct covered electronic transactions, such as

HHAs, among others, for the privacy of protected health information (PHI), as well as

for the security of electronic phi (ePHI).

In accordance with 45 CFR 164.530, all HHA staff must receive comprehensive and

periodic training on the protection of patient clinical records. HHAs must also establish

policies and procedures to ensure the security of clinical records and the privacy of

information contained within such records to prevent loss or unauthorized use in the

patient’s home, in transit, in the office setting, or any other location.

Survey Procedures §484.110(d)

During the home visit, observe how agency staff maintain the confidentiality of protected

health information that they transport and use for patient care encounters as well as

safeguard it against loss or unauthorized use.

CMS does not interpret or enforce the HIPAA Privacy and Security Rules, which fall

under the jurisdiction of the Office for Civil Rights (OCR). Because there are a number of

scenarios that allow for using or disclosing PHI in full compliance with the HIPAA

Privacy and Security Rules, surveyors must defer to OCR on whether the manner in

which the HHA uses, discloses, maintains or destroys PHI is consistent with these

requirements. Information on how to file a HIPAA Privacy or Security complaint with

OCR may be found at http://www.hhs.gov/ocr/privacy/hipaa/complaints/index.html.

History

Rev. 219; Issued: 04-12-24; Effective: 04-12-24; Implementation: 04-12-24

Provenance

Source
cms.gov
Retrieved
2026-07-22
Edition
som-2026-07-22
Content hash
5ef0332ce257cc77aaf39aef6fafacc2fd4b7c28c7a2afe6300013a912e8a4a3
View the official source →

The link goes to the issuing authority’s own document — the one we read to produce this record. Where a source publishes whole titles rather than sections, your browser may need a moment to jump to the provision.

Unofficial copy of government-published law, reproduced from official sources with full provenance. Not an official publication; verify against official sources before relying on it in a filing. Records in the 'guidance' corpus, and only that corpus, are sub-regulatory (interpretive guidelines, survey procedures) and are not binding law. Validity bounds follow each jurisdiction's declared temporalBasis.

Coverage · API docs

Bindinglaw

Point-in-time US law with the receipt attached. Source URL, retrieval time, content hash, and validity dates on every answer.

curl api.binding.law/v1/law/coverage

© 2026 binding.law · a Jubal, Inc. productAttorneys and firms never pay. Ever.