Guaranteed Expert Consultation Within 1 Hour. Click Here!

Guaranteed Expert Consultation Within 1 Hour. Click Here!

21st Century Cures Act EVV Mandate, CMS Conditions of Participation, HIPAA and the FLSA Home Care Rule: Compliance Requirements for US Home Health Software

Introduction: Which Rules Apply Depends on What Kind of Agency You Are

Most home care compliance content lists every rule as though every agency were subject to all of them. That’s not how home care software compliance requirements actually work. CMS Conditions of Participation apply to Medicare-certified home health agencies, not to non-medical personal care. EVV under the Cures Act attaches to Medicaid-funded services, not to private pay. HIPAA covered-entity status is clear-cut for certified agencies, but genuinely fact-specific for a purely private-pay non-medical operation. Only wage and hour rules apply to essentially everyone with employees.

This article covers all four and marks which agency types each one affects. It also covers the state licensure and workforce requirements layered on top. These are the starting points for both custom software development and custom mobile app development.

This is educational and strategic content, not legal, regulatory, or employment advice. Obligations should be confirmed with healthcare regulatory counsel, employment counsel for wage questions specifically, and the relevant state Medicaid agency and licensing authority.

The 21st Century Cures Act EVV Mandate

What the Mandate Actually Requires

Section 12006 requires state Medicaid programs to implement electronic visit verification for personal care services and home health care services. The deadlines were January 1, 2020 and January 1, 2023. States that didn’t comply faced reductions in federal matching funds, subject to good-faith extensions. Six elements must be captured for each visit. These are the type of service performed, the individual receiving the service, the date of service, the location of service delivery, the individual providing the service, and the time the service begins and ends.

What It Does Not Require

The mandate applies to services paid for by Medicaid. It does not apply to private pay, Medicare-only, or long-term care insurance visits, though agencies commonly apply the same capture across payers for consistency. It’s also not a mandate to track caregivers. CMS guidance has addressed that continuous location monitoring is not required, and that alternatives to smartphone GPS must be available. Current guidance should always be verified directly. EVV is best described as verification at defined points, not ongoing surveillance.

The State Model Determines Everything Practical

Closed or state-mandated vendor models, open provider-choice models, open models with a free state option, and MCO-choice models each imply something different about whether an agency’s own system can serve as the EVV solution. This should be confirmed per state with the state Medicaid agency. In many states, a visit that fails EVV validation cannot be billed, which makes this a revenue question as much as a compliance one.

CMS Conditions of Participation: Medicare-Certified Agencies Only

The Conditions of Participation at 42 CFR Part 484 apply to Medicare-certified home health agencies. If an agency provides only non-medical personal care, this section doesn’t describe its obligations. That’s worth stating plainly, since a great deal of vendor content implies otherwise.

For certified agencies, the software-relevant areas break down into several parts. Patient rights, including how notice is given and how transfer and discharge are handled. The comprehensive assessment, including OASIS. An individualized plan of care built from physician or allowed-practitioner orders, with verbal order capture and authentication. Coordination of care across disciplines and with the ordering practitioner. Quality assessment and performance improvement. Infection prevention and control. Skilled professional services. Home health aide services, covering training, competency evaluation, written assignments, and periodic on-site supervisory visits. And clinical records, covering required content, retention, and patient access.

Two things are worth verifying rather than assuming, because they’re specific and they change. The required frequency of on-site aide supervisory visits differs depending on whether the patient is also receiving skilled services. The required record retention period interacts with state law. Both should be confirmed directly against current CMS guidance and applicable state statute before they get built into any workflow.

Nearly everything in this list is documentation the platform either produces as a by-product of daily work, or requires someone to duplicate by hand.

HIPAA and the Question of Whether You Are a Covered Entity

Medicare-certified agencies, and agencies that conduct covered electronic transactions, are generally covered entities under HIPAA. A purely private-pay non-medical agency may not be. That determination is fact-specific enough that it’s worth establishing explicitly with counsel rather than assuming in either direction. Assuming an agency is not covered and being wrong is the more expensive error.

Where HIPAA applies, a hosted platform vendor is generally a business associate requiring a BAA, and the Privacy, Security, and Breach Notification Rules attach in full.

Regardless of covered-entity status, the practical security position looks the same either way. Caregiver devices carry client information into homes and back out, which makes device enrollment, encryption at rest, session timeouts, remote wipe, and a lost-device procedure part of the architecture. Role-based access matters too, so a caregiver sees their assigned clients rather than the agency’s full roster. Family portal access adds its own layer, since entitlement depends on authorization and, sometimes, on legal capacity.

One item worth flagging for currency. A proposed update to the HIPAA Security Rule was published in January 2025, and as of mid-2026 it remains a proposed rule rather than final law. Its status should be reverified before relying on it and periodically after.

The FLSA Home Care Rule and Wage-Hour Obligations

This is the compliance surface that applies to essentially every agency with employees. It’s also the one most often treated as a payroll matter rather than a software requirement.

The Department of Labor’s home care rule prohibits third-party employers, such as agencies, from claiming the companionship services or live-in domestic service exemptions. As a result, agency-employed caregivers are generally entitled to minimum wage and overtime.

The most software-relevant element is travel time. Time spent traveling between clients during the workday is generally compensable hours worked. That makes the schedule itself a wage document. A coordinator building a route is creating payable time, and a system that can’t show that will under-record it. Overtime accrues across the full workweek regardless of how many clients or payers the hours span, which is why projected weekly hours belong on the scheduling screen rather than a payroll report after the fact. Putting that figure in front of the coordinator at the moment of assignment is web application development work on the office side. 

Live-in and sleep-time arrangements have their own treatment, and many states impose more protective requirements than federal law. Worker classification adds another layer. The Department of Labor proposed a new rule in February 2026 to rescind and replace the 2024 independent-contractor standard, and this remains an active enforcement area with rulemaking still unsettled. Treating caregivers as independent contractors carries real risk regardless of how that rulemaking lands.

All of this should be reviewed with employment counsel specifically. The platform implements the agency’s wage and hour determinations. It does not make them.

State Licensure, Background Checks, and Training Requirements

Many states license non-medical home care agencies separately from Medicare-certified agencies, with their own application, supervision, and reporting requirements. Others regulate more lightly. This should be verified for each state of operation rather than assumed.

Caregiver requirements vary just as much. Criminal background checks and their permitted lookback period. Abuse and nurse aide registry checks. Health screening. Initial training hours required before a caregiver may work unsupervised. Annual in-service hours after that.

The software consequence is straightforward, and frequently under-built. Credential and training expiry should block a scheduling assignment rather than simply appear in a report after the fact. A visit delivered by someone whose credential has lapsed can be unbillable, recoupable, and a licensure problem at survey. Supervisory visit tracking belongs here too, for agencies where it applies, with the requirement visible as a running position rather than something reconstructed later during an audit.

For multi-state agencies, all of this multiplies, and the platform needs the rules to be configuration rather than code.

Service agreements, notices of rights, and consent, including consent for the family portal access described earlier, should be captured with versions and dates. That way the agency can show what a client agreed to and when.

Client and family complaint handling needs a documented path, an owner, and a resolution record, rather than an informal note to a coordinator.

Incident reporting should cover falls, injuries, medication errors, missed visits, and allegations of mistreatment, with prompt routing to the right people and the records the agency’s policy and its state regulator require. Missed visits deserve specific attention. For a client who depends on that visit for a meal or medication, a caregiver who doesn’t arrive is a safety event, not a scheduling gap.

Mandated reporting obligations for suspected abuse or neglect are state-specific. The pathway for meeting them should be visible and documented rather than left dependent on individual recall.

Establishing which of these obligations actually apply to a given agency is the first job of pre-build discovery, a process covered in Why US Home Care Agency Owners Need a Technology Consultant in 2026.

Final Thoughts

Agencies that establish which rules actually apply to them end up ahead. Conditions of Participation only if Medicare-certified. EVV only for Medicaid-funded services, and only as their state’s model requires. HIPAA status determined rather than assumed. Wage and hour obligations that apply to nearly everyone. Agencies that work through these questions build platforms that produce compliance evidence as a by-product of daily work, rather than something reconstructed under pressure later.

None of this replaces professional advice. Obligations should be confirmed with healthcare regulatory counsel, employment counsel for wage and hour questions specifically, and the relevant state agencies.

If you’re scoping a platform that will hold visit verification, care documentation, and wage data, establishing which obligations apply to your agency type and your states before architecture is fixed is the step that keeps compliance from becoming a rebuild. That’s the kind of groundwork NewAgeSysIT works through with agencies from the start. Learn more about digital transformation solutions from one of the leading AI software companies in the United States.

Explore more categories