Skip to main content

New: AI Privacy Impact Assessments for teams shipping AI features. Learn about AI-PIAs

Policy development · Clinical care providers

Privacy & Security Policy Development for Home & Community Care Agencies

Privacy policy development for a home and community care agency has to cover situations no office-based policy template anticipates: what a personal support worker's own phone is allowed to hold, whether a wound photo can live on that phone at all, and how a lockbox code gets handled once it leaves the office. Agencies usually commission this work when a contract renewal asks for documented policies, an app rollout forces a BYOD decision, or an incident reveals nobody had written down the rule everyone assumed existed.

Reviewed by the Privacy Horizon team · Last reviewed

What you're protecting

The policy gaps unique to an in-home, mobile workforce

A conventional privacy policy set assumes data stays inside a building; this sector's policies have to assume the opposite from the first draft.

Mobile-device and BYOD rules for PSWs

What a personal or agency phone must have configured, encryption, a passcode, remote-wipe capability, before it can hold a care plan, and what happens if a worker refuses to comply.

Wound and skin-photo handling

Whether photos may be taken on a personal device at all, where they get transferred and when the original copy on the phone must be deleted, a workflow question a generic photo policy never addresses.

Paper records and lockbox codes in the field

How paper visit notes get secured in transit and at the end of a shift, and who is authorized to hold, share or change a client's lockbox code.

Family and substitute decision-maker communication

What a worker may tell a family member who meets them at the door, distinct from what the client themselves has consented to share.

Worker screening and confidentiality undertakings

The onboarding documentation that stands in for a licensing college's code of conduct, since PSWs answer to no external regulator.

Retention and disposal for field-generated records

How long visit notes, missed-visit reports and photos are kept, and how they get securely disposed of once retention periods close.

Regulatory map

Why these policies carry statutory weight, not just good practice

Written policy is the visible evidence a custodian relies on when its practices, and its agents' conduct, get questioned.

Policy as the record of how custodianship is discharged

PHIPA s.3(1) para 3 ties custodian status to funding under Connecting Care Act, 2019 s.21, and a custodian's policies are the primary record of how it discharges that status day to day.

Read our guide →

Why policy has to be specific, not aspirational

The custodian answers for a personal support worker's conduct as its agent under s.17, which is exactly why the mobile-device and photo-handling policies have to be written as enforceable rules rather than general statements of intent.

Read our guide →

Alberta HIA's custodian obligations

Continuing-care operators in Alberta are custodians under HIA s.1(1)(f)(ii), with the same reliance on documented policy to demonstrate reasonable safeguards.

Primary source →

BC PIPA's safeguards and policy expectations

A private or non-profit agency operating in BC needs documented safeguards under PIPA, with a privacy officer responsible for the policies that describe them.

Read our guide →

Quebec's health-information Act for network-agreement providers

Agencies delivering services under an agreement with Quebec's health and social services network, including intermediate or family-type resources, need policies reflecting the province's health-information rules.

Primary source →

What goes wrong

What clear policy prevents in this environment

Most incidents in this sector trace back to a rule nobody wrote down clearly enough for a worker to follow under pressure.

  • An unclear rule leaving a photo on a personal phone

    Without a specific deletion step written into policy, a wound photo taken for documentation purposes can sit indefinitely on a worker's personal device, well past when it served its purpose.

  • A worker sharing a lockbox code without authorization

    A family member's casual request for a code, answered without a clear policy on who may share it, can leave a client's home accessible to someone never approved for that access.

  • Inconsistent answers to family questions at the door

    Without written guidance, workers improvise what they tell a family member, sometimes disclosing more than the client consented to, sometimes creating friction by disclosing too little.

  • Paper notes left in a vehicle or at a prior client's home

    A visit note without a clear in-transit handling rule is easy to leave behind during a busy multi-visit shift, the kind of lapse a specific procedure is written to prevent.

Our policy development for home & community care agencies

What our policy development covers for a home-care agency

Policies are drafted around your actual visit workflow and device reality, not adapted from an office-based template after the fact.

Two data analysts Working on data analysis dashboard for business strategy
  1. Custom BYOD and mobile-device policy

    Specific, enforceable requirements for any device, agency-issued or personal, that will hold client data during a visit.

  2. Photo and documentation handling procedure

    Step-by-step guidance covering when a photo may be taken, how it is transferred to the client record, and when the device copy must be removed.

  3. Paper-in-the-field and lockbox-code policy

    Rules for securing paper records between visits and for who may hold, share or change a lockbox code, matched to your actual field operations.

  4. Compliance-ready framing

    Policies drafted with PHIPA, the applicable provincial statute and relevant SPO contract language in mind, so they hold up against both a regulator and a funder review.

  5. Employee and vendor guidance

    Clear expectations for personal support workers, nurses, schedulers and any subcontracted staffing partner, distinguishing what each role is responsible for.

  6. Revision cycle tied to real change

    Revisions as contracts renew, new devices or apps roll out, or provincial requirements change, so the policy set does not go stale between reviews.

How the engagement runs

How the policy set gets built for an agency

The process starts in the field, not at a desk, since the rules have to work for someone standing in a client's doorway.

  1. Step 1

    Review current practice against the gap

    We look at how devices, photos, paper and lockbox codes are actually handled today, not just what any existing policy claims.

  2. Step 2

    Draft field-tested policy language

    Policies are written in plain, specific language a worker can follow in the moment, not legal phrasing that reads well but does not translate into action.

  3. Step 3

    Align with contracts and provincial requirements

    Language is checked against your SPO contract's security schedule and the statutes that apply in each province you operate in.

  4. Step 4

    Roll out and train

    Policies are introduced alongside the agency's training program so workers understand not just the rule but the reason behind it.

  5. Step 5

    Review on a set schedule

    Policies are revisited as contracts, devices or provincial rules change, keeping the set current rather than static.

What it costs

What shapes policy development cost for a home-care agency

Cost tracks how many distinct policies are needed, how many provinces and statutes the agency operates under, and how much current practice needs to be documented before drafting starts. An agency already running a BYOD program needs less foundational work than one adopting devices for the first time.

Whether policies need translation for a multilingual workforce, or alignment with a specific SPO contract's language, also affects scope. Tell us your current device and paper practices and we will scope a tailored quote.

Home & Community Care Agencies: Policy development questions, answered

It needs to specify the minimum device configuration required before any client data can be accessed, a passcode, encryption, remote-wipe capability, and it needs a clear answer for what happens if a worker's personal phone cannot meet that bar. Vague language telling workers to keep devices secure without defining what that means in practice is not enforceable.

The policy should state whether photos may be taken on a personal device at all, require immediate transfer to the official client record, and set a deadline for deleting the device copy, ideally the same day. Leaving this undefined is how wound photos end up sitting on personal phones indefinitely, well past their clinical purpose.

Paper policy should address how notes are secured during transport between visits and at shift end, while lockbox-code policy should name who is authorized to hold, share or change a code and under what circumstances. Both need to be specific enough that a worker facing a family member's request in the doorway knows exactly what they can and cannot do.

Largely yes for device, photo and paper handling, since the physical realities of a home visit are the same regardless of credential. Where it needs to diverge is confidentiality enforcement, a nurse answers to a professional college in addition to the agency, while a PSW's only accountability is the employer policy itself, which needs correspondingly more detail and enforcement structure.

The agency's policy needs to specify what it requires of a staffing partner's workers when they perform visits under its contract, and the staffing agreement itself should reference those requirements directly. Without that link, a subcontracted worker may never actually see the policy meant to govern their conduct.

At least annually, and immediately after any new device rollout, app change or contract renewal that introduces new requirements. A policy written before a caregiver app existed will not address the specific risks that app introduces, no matter how well it was written at the time.

What's Protecting Your Business from the Next Threat?

Don't wait for a breach to expose your vulnerabilities. Let Privacy Horizon secure your data, ensure compliance, and build lasting trust.

(647) 622-2644

Free, no obligation

Get a quote

Tell us what you need and we'll come back within one business day with a tailored quote.

We only use your details to respond to this request.