Spence Consultants Spence Consultants LLC

Home / Insights / AI and compliance risk

Applied AI · Home care

Can home care agencies use AI tools without compliance risk?

Short answer

Yes, but not the way most agencies are currently doing it. The deciding factor is never the tool. It is what data enters the tool, and under what contract.

If protected health information goes into an AI system, you need a signed Business Associate Agreement with that vendor before the data moves, and consumer tiers of the major assistants are not eligible for one. Separately, and this is the part most agencies miss entirely, your caregiver files are covered by the New York SHIELD Act even when no patient information is involved. Get those two questions right and most practical AI use is available to you.

The question I get from home care administrators is almost always framed as a yes or no. Can we use this. What I have found is that the yes or no framing is what creates the risk, because it pushes agencies toward one of two bad outcomes: a blanket ban that staff quietly ignore, or a blanket permission that nobody scoped.

Both produce the same result. People use the tools anyway, off the record, with whatever data is in front of them. The difference is whether you know about it.

Here is the framework I would use instead.

There is no LHCSA-specific AI rule, and that is the problem

Administrators keep waiting for the Department to publish something that tells them what is allowed. As of this writing there is no LHCSA-specific artificial intelligence regulation to wait for.

That absence gets misread as permission. It is not. It means your exposure comes from rules that already exist and already apply: HIPAA, the New York SHIELD Act, patient confidentiality obligations under 10 NYCRR Part 766, and the plain expectation that a written policy is both maintained and actually followed.

None of those rules mention AI. All of them apply to it.

Question one: does protected health information touch the tool?

Under HIPAA, a business associate is any person or organization that creates, receives, maintains, or transmits protected health information while performing a function or service for a covered entity. That definition is about what the vendor does with the data, not what category of software it is. An AI vendor processing your patient information is a business associate by function.

The Privacy Rule requires that before a covered entity discloses protected health information to a business associate, it first obtain satisfactory assurances, documented through a signed Business Associate Agreement. The sequencing is not negotiable. Without an executed BAA, disclosing protected health information to a vendor is itself an impermissible disclosure, regardless of whether the vendor's infrastructure happens to be secure.

The specific thing to stop doing: pasting a clinical note, a plan of care, an aide activity sheet, or a patient's name and condition into a consumer chatbot to get help rewriting it. That is a disclosure. The helpfulness of the output does not change the analysis.

Consumer tiers are the trap here. Reporting on vendor BAA availability as of 2026 indicates that ChatGPT Free, Plus, Pro, Team, and self-serve Business are not eligible for a BAA, while BAAs are available through the API and sales-managed enterprise paths. Vendor terms differ, change, and depend on the specific product tier and configuration. Verify against the vendor's current compliance documentation rather than against an article, including this one.

Question two: the one nobody asks

Here is where home care agencies get caught, and it has nothing to do with patients.

The New York SHIELD Act applies to any person or business that owns or licenses computerized data including the private information of a New York resident. Private information covers Social Security numbers, driver's license numbers, financial account and card numbers, biometric information, and email addresses or usernames paired with passwords or security answers. Every employer with employees in New York is covered, because a name combined with a Social Security number meets the definition. There is no small business exemption, though size is taken into account in judging whether safeguards are reasonable.

Now think about what is in a caregiver personnel file. Social Security number. Driver's license. Direct deposit details. Possibly biometric time clock data.

An agency can create real exposure using AI for recruiting, scheduling, or human resources without a single patient record ever entering the system.

This is the gap I see most often. An administrator correctly locks down patient data, then lets the scheduling coordinator paste a roster with employee identifiers into a general assistant to reformat it, because that feels like an operations task rather than a compliance one.

The SHIELD Act requires reasonable safeguards, and a business is deemed compliant if it maintains a data security program with defined elements. Several of them speak directly to AI adoption:

  • Designating one or more employees to coordinate the security program.
  • Identifying reasonably foreseeable internal and external risks.
  • Training and managing employees in the program's practices and procedures.
  • Selecting service providers capable of maintaining appropriate safeguards, and requiring those safeguards by contract.
  • Securely disposing of private information within a reasonable time after it is no longer needed.

Read the fourth one again. Selecting capable service providers and binding them contractually is exactly the vendor diligence question an AI tool raises. And breach notification runs on a 30-day clock from discovery.

One useful piece of relief: a business that complies with the HIPAA Security Rule is deemed compliant with the SHIELD Act's data security requirements. If you build one program well, it covers both.

"HIPAA compliant" is not a product badge

Treat any vendor claim of blanket HIPAA compliance as marketing until proven otherwise. Eligibility depends on the exact service, the tier licensed, whether a BAA is executed, and how the deployment is configured. Large vendors typically cover some products and not others under the same corporate BAA, which means an agency needs a current inventory of which specific services are covered rather than a general belief that it has an agreement with the company.

Two further points that matter more than they sound:

A covered entity cannot delegate its HIPAA obligations to a vendor. Using an AI system does not relieve you of the obligation to ensure protected health information is protected, and a signed BAA alone does not establish compliance. If the vendor experiences a breach, you are responsible for breach notification to affected individuals and to HHS.

Second, in 2024 OCR issued guidance clarifying that the Privacy Rule's nondiscrimination provisions apply to AI-driven decision-making, with obligations that overlap Section 1557 of the Affordable Care Act. For a home care agency, the live version of that is any AI-assisted screening, matching, or scheduling logic that could produce disparate outcomes by protected characteristic. If you are piloting AI in hiring, that is the exposure to think through before the pilot, not after.

A workable rule your staff can actually follow

Policies fail when they require judgment at the moment of use. The version that works sorts data into tiers, so a coordinator at 4pm on a Friday does not have to reason from first principles.

The four-tier data rule
TierWhat it isGeneral AI tool
1. Public Job descriptions, training outlines, marketing copy, general policy language, meeting agendas with no names. Permitted
2. Internal Process documents, de-identified aggregate metrics, draft procedures, anonymized scenarios for training. Permitted with review
3. Personnel Anything containing caregiver identifiers: SSN, license number, direct deposit, biometrics, home address. Covered vendor only
4. Patient Any protected health information: names, conditions, plans of care, activity sheets, progress notes, addresses. BAA required, no exceptions

Most of the genuine productivity gain in a home care office sits in tiers one and two, which is the part administrators tend not to believe until they try it. Drafting an in-service module. Rewriting a policy in plain language for a bilingual workforce. Turning a messy set of exit reasons into a themed summary once the names are stripped. Building the supervisor coaching script. None of that requires a single identifier.

What a surveyor will actually ask

This is the part I want administrators to internalize, because it is where the compliance conversation usually stops too early.

New York surveyors already apply a specific two-part test in another domain. In the criminal history record check review, they check whether the agency has a written policy addressing every required element, and then whether the agency has implemented and follows that policy. A policy that exists and a policy that is operated are two different findings.

Assume the same test arrives for AI. That means the defensible position is not a ban and not a memo. It is:

What to have written down

  • A named owner for AI decisions, consistent with the SHIELD Act requirement to designate a security program coordinator.
  • An inventory of approved tools, listing the specific service and tier, not just the company name.
  • Which executed BAAs are in place, with dates, and what products each one covers.
  • The data tier rule, stated in language a scheduler can apply without calling anyone.
  • A human review requirement for any output touching care, employment, or compliance decisions.
  • Inclusion of each AI tool in your security risk analysis.
  • An incident path for suspected improper disclosure, mapped to the 30-day SHIELD notification clock.
  • Dated training records showing staff were actually trained on all of the above.

That last item is the one agencies skip, and it is the one that converts a good policy into evidence. This is the same failure I described in the survey readiness piece: the policy exists, the proof that anyone followed it does not.

The competitive read

I will be direct about why I think this matters beyond avoiding a citation.

The agencies that answer the monitoring question first get to use these tools first. Right now most of the sector is frozen, waiting for guidance that is not coming, while their staff use consumer tools unsupervised because the work still has to get done. The gap between official policy and actual practice is the risk. Closing it is not primarily a technology project. It is a policy, training, and documentation project, which is to say it is a workforce project.

An agency that can hand a surveyor a tool inventory, a signed BAA, a data tier rule, and dated training records is not just compliant. It is free to move.

Common questions

Can we use ChatGPT at all?
For tier one and tier two work, yes. For anything containing patient or caregiver identifiers, not on a consumer tier, because those tiers are not BAA-eligible. Confirm current tier eligibility with the vendor before relying on it.
Our vendor says their product is HIPAA compliant. Is that enough?
No. Ask which specific services the BAA covers, get the agreement executed and dated, and confirm the configuration. You remain responsible for compliance and for breach notification even with a signed BAA in place.
Does this apply if we only use AI for scheduling and recruiting?
Yes, in New York. The SHIELD Act covers caregiver private information independently of HIPAA. Recruiting and scheduling are where most agencies have their unexamined exposure.
Do we have to tell patients we use AI?
That depends on the use and on your notice of privacy practices. It is a question for your privacy officer and counsel, and the answer differs for back-office drafting versus anything touching care decisions.
Is there a New York regulation on AI in home care we should be tracking?
There is no LHCSA-specific AI rule at present. HHS has signaled that further guidance on AI and HIPAA is expected, and states continue to legislate, so this is worth a standing review rather than a one-time policy.

Sources

  1. HHS guidance on business associates and the HIPAA Privacy Rule, 45 CFR 164.504(e). Definition of a business associate by function, and the requirement for satisfactory assurances documented through a Business Associate Agreement before disclosure.
  2. HHS Office for Civil Rights, 2024 guidance on the application of Privacy Rule nondiscrimination provisions to AI-driven decision-making, and its overlap with Section 1557 of the Affordable Care Act.
  3. New York State Stop Hacks and Improve Electronic Data Security (SHIELD) Act, signed July 26, 2019, data security provisions effective March 2020, subsequently amended. Definition of private information, the enumerated data security program elements, the deemed-compliance provision for HIPAA Security Rule compliance, and the 30-day breach notification period.
  4. New York State Department of Health, Division of Home and Community Based Services, The Survey Process Toolkit, July 2, 2024, for the written-policy-and-implementation review standard applied in criminal history record check review under 10 NYCRR Part 402.
  5. Vendor BAA eligibility by product tier as reported in industry compliance analyses current to mid-2026. Vendor terms change; verify against current vendor documentation.

This article is general information, not legal advice, and it is not a compliance opinion. Regulations and vendor terms change. Confirm current requirements with your privacy officer, your counsel, and your DOH regional office before acting.

Want the policy, the tool inventory, and the training records built?

That is a scoped engagement with a fixed fee and a deliverable you own and operate after we leave. Start with a conversation about where your staff are already using these tools.

Book a free consultation See the Applied AI practice