Policy development · Clinical care providers
Privacy & Security Policy Development for Home & Community Care Agencies
Privacy policy development for a home and community care agency has to cover situations no office-based policy template anticipates: what a personal support worker's own phone is allowed to hold, whether a wound photo can live on that phone at all, and how a lockbox code gets handled once it leaves the office. Agencies usually commission this work when a contract renewal asks for documented policies, an app rollout forces a BYOD decision, or an incident reveals nobody had written down the rule everyone assumed existed.
Reviewed by the Privacy Horizon team · Last reviewed
What you're protecting
The policy gaps unique to an in-home, mobile workforce
A conventional privacy policy set assumes data stays inside a building; this sector's policies have to assume the opposite from the first draft.
Mobile-device and BYOD rules for PSWs
What a personal or agency phone must have configured, encryption, a passcode, remote-wipe capability, before it can hold a care plan, and what happens if a worker refuses to comply.
Wound and skin-photo handling
Whether photos may be taken on a personal device at all, where they get transferred and when the original copy on the phone must be deleted, a workflow question a generic photo policy never addresses.
Paper records and lockbox codes in the field
How paper visit notes get secured in transit and at the end of a shift, and who is authorized to hold, share or change a client's lockbox code.
Family and substitute decision-maker communication
What a worker may tell a family member who meets them at the door, distinct from what the client themselves has consented to share.
Worker screening and confidentiality undertakings
The onboarding documentation that stands in for a licensing college's code of conduct, since PSWs answer to no external regulator.
Retention and disposal for field-generated records
How long visit notes, missed-visit reports and photos are kept, and how they get securely disposed of once retention periods close.
Regulatory map
Why these policies carry statutory weight, not just good practice
Written policy is the visible evidence a custodian relies on when its practices, and its agents' conduct, get questioned.
Policy as the record of how custodianship is discharged
PHIPA s.3(1) para 3 ties custodian status to funding under Connecting Care Act, 2019 s.21, and a custodian's policies are the primary record of how it discharges that status day to day.
Why policy has to be specific, not aspirational
The custodian answers for a personal support worker's conduct as its agent under s.17, which is exactly why the mobile-device and photo-handling policies have to be written as enforceable rules rather than general statements of intent.
Alberta HIA's custodian obligations
Continuing-care operators in Alberta are custodians under HIA s.1(1)(f)(ii), with the same reliance on documented policy to demonstrate reasonable safeguards.
BC PIPA's safeguards and policy expectations
A private or non-profit agency operating in BC needs documented safeguards under PIPA, with a privacy officer responsible for the policies that describe them.
Quebec's health-information Act for network-agreement providers
Agencies delivering services under an agreement with Quebec's health and social services network, including intermediate or family-type resources, need policies reflecting the province's health-information rules.
What goes wrong
What clear policy prevents in this environment
Most incidents in this sector trace back to a rule nobody wrote down clearly enough for a worker to follow under pressure.
An unclear rule leaving a photo on a personal phone
Without a specific deletion step written into policy, a wound photo taken for documentation purposes can sit indefinitely on a worker's personal device, well past when it served its purpose.
A worker sharing a lockbox code without authorization
A family member's casual request for a code, answered without a clear policy on who may share it, can leave a client's home accessible to someone never approved for that access.
Inconsistent answers to family questions at the door
Without written guidance, workers improvise what they tell a family member, sometimes disclosing more than the client consented to, sometimes creating friction by disclosing too little.
Paper notes left in a vehicle or at a prior client's home
A visit note without a clear in-transit handling rule is easy to leave behind during a busy multi-visit shift, the kind of lapse a specific procedure is written to prevent.
Our policy development for home & community care agencies
What our policy development covers for a home-care agency
Policies are drafted around your actual visit workflow and device reality, not adapted from an office-based template after the fact.

Custom BYOD and mobile-device policy
Specific, enforceable requirements for any device, agency-issued or personal, that will hold client data during a visit.
Photo and documentation handling procedure
Step-by-step guidance covering when a photo may be taken, how it is transferred to the client record, and when the device copy must be removed.
Paper-in-the-field and lockbox-code policy
Rules for securing paper records between visits and for who may hold, share or change a lockbox code, matched to your actual field operations.
Compliance-ready framing
Policies drafted with PHIPA, the applicable provincial statute and relevant SPO contract language in mind, so they hold up against both a regulator and a funder review.
Employee and vendor guidance
Clear expectations for personal support workers, nurses, schedulers and any subcontracted staffing partner, distinguishing what each role is responsible for.
Revision cycle tied to real change
Revisions as contracts renew, new devices or apps roll out, or provincial requirements change, so the policy set does not go stale between reviews.
How the engagement runs
How the policy set gets built for an agency
The process starts in the field, not at a desk, since the rules have to work for someone standing in a client's doorway.
Step 1
Review current practice against the gap
We look at how devices, photos, paper and lockbox codes are actually handled today, not just what any existing policy claims.
Step 2
Draft field-tested policy language
Policies are written in plain, specific language a worker can follow in the moment, not legal phrasing that reads well but does not translate into action.
Step 3
Align with contracts and provincial requirements
Language is checked against your SPO contract's security schedule and the statutes that apply in each province you operate in.
Step 4
Roll out and train
Policies are introduced alongside the agency's training program so workers understand not just the rule but the reason behind it.
Step 5
Review on a set schedule
Policies are revisited as contracts, devices or provincial rules change, keeping the set current rather than static.
What it costs
What shapes policy development cost for a home-care agency
Cost tracks how many distinct policies are needed, how many provinces and statutes the agency operates under, and how much current practice needs to be documented before drafting starts. An agency already running a BYOD program needs less foundational work than one adopting devices for the first time.
Whether policies need translation for a multilingual workforce, or alignment with a specific SPO contract's language, also affects scope. Tell us your current device and paper practices and we will scope a tailored quote.
Home & Community Care Agencies: Policy development questions, answered
It needs to specify the minimum device configuration required before any client data can be accessed, a passcode, encryption, remote-wipe capability, and it needs a clear answer for what happens if a worker's personal phone cannot meet that bar. Vague language telling workers to keep devices secure without defining what that means in practice is not enforceable.
The policy should state whether photos may be taken on a personal device at all, require immediate transfer to the official client record, and set a deadline for deleting the device copy, ideally the same day. Leaving this undefined is how wound photos end up sitting on personal phones indefinitely, well past their clinical purpose.
Paper policy should address how notes are secured during transport between visits and at shift end, while lockbox-code policy should name who is authorized to hold, share or change a code and under what circumstances. Both need to be specific enough that a worker facing a family member's request in the doorway knows exactly what they can and cannot do.
Largely yes for device, photo and paper handling, since the physical realities of a home visit are the same regardless of credential. Where it needs to diverge is confidentiality enforcement, a nurse answers to a professional college in addition to the agency, while a PSW's only accountability is the employer policy itself, which needs correspondingly more detail and enforcement structure.
The agency's policy needs to specify what it requires of a staffing partner's workers when they perform visits under its contract, and the staffing agreement itself should reference those requirements directly. Without that link, a subcontracted worker may never actually see the policy meant to govern their conduct.
At least annually, and immediately after any new device rollout, app change or contract renewal that introduces new requirements. A policy written before a caregiver app existed will not address the specific risks that app introduces, no matter how well it was written at the time.
More for home & community care agencies
Other services for this niche
About this service
What's Protecting Your Business from the Next Threat?
Don't wait for a breach to expose your vulnerabilities. Let Privacy Horizon secure your data, ensure compliance, and build lasting trust.