US · guidance
CMS SOM App. B, Tag G1028
§484.110(d) Standard: Protection of records
The clinical record, its contents, and the information contained therein must be
safeguarded against loss or unauthorized use. The HHA must be in compliance
with the rules regarding personal health information set out at 45 CFR parts 160
and 164.
Interpretive Guidelines §484.110(d)
HHA staff (whether employed directly or under arrangement) who carry documents
and/or electronic devices containing Protected Health Information from patient’s homes
to the HHA office, or to and from the HHA staff member’s home, create additional
confidentiality/protection concerns with patient records.
Section 45 CFR Parts 160 and 164, generally known as the Health Insurance Portability
and Accountability Act (HIPAA) Privacy and Security rules, establish standards for
health care providers and suppliers that conduct covered electronic transactions, such as
HHAs, among others, for the privacy of protected health information (PHI), as well as
for the security of electronic phi (ePHI).
In accordance with 45 CFR 164.530, all HHA staff must receive comprehensive and
periodic training on the protection of patient clinical records. HHAs must also establish
policies and procedures to ensure the security of clinical records and the privacy of
information contained within such records to prevent loss or unauthorized use in the
patient’s home, in transit, in the office setting, or any other location.
Survey Procedures §484.110(d)
During the home visit, observe how agency staff maintain the confidentiality of protected
health information that they transport and use for patient care encounters as well as
safeguard it against loss or unauthorized use.
CMS does not interpret or enforce the HIPAA Privacy and Security Rules, which fall
under the jurisdiction of the Office for Civil Rights (OCR). Because there are a number of
scenarios that allow for using or disclosing PHI in full compliance with the HIPAA
Privacy and Security Rules, surveyors must defer to OCR on whether the manner in
which the HHA uses, discloses, maintains or destroys PHI is consistent with these
requirements. Information on how to file a HIPAA Privacy or Security complaint with
OCR may be found at http://www.hhs.gov/ocr/privacy/hipaa/complaints/index.html.
History
Rev. 219; Issued: 04-12-24; Effective: 04-12-24; Implementation: 04-12-24
Provenance
- Source
- cms.gov
- Retrieved
- 2026-07-22
- Edition
- som-2026-07-22
- Content hash
5ef0332ce257cc77aaf39aef6fafacc2fd4b7c28c7a2afe6300013a912e8a4a3
The link goes to the issuing authority’s own document — the one we read to produce this record. Where a source publishes whole titles rather than sections, your browser may need a moment to jump to the provision.
Unofficial copy of government-published law, reproduced from official sources with full provenance. Not an official publication; verify against official sources before relying on it in a filing. Records in the 'guidance' corpus, and only that corpus, are sub-regulatory (interpretive guidelines, survey procedures) and are not binding law. Validity bounds follow each jurisdiction's declared temporalBasis.