Skip to content
iCare EVV
ProductResourcesCompanyContact
Sign inBook a demo→
Home/HIPAA and Shared Responsibility
HIPAA overview

Compliance is a working system, not a product badge.

iCare EVV LLC is intended to operate as a HIPAA Business Associate when applicable—when it provides services to a Covered Entity or another Business Associate and creates, receives, maintains, or transmits PHI on that organization’s behalf.

Draft — legal review required

Review responsibilities→Send a security or privacy question→
  • No “HIPAA certified” claim
  • BAA evaluated case by case
  • Shared operational responsibility
DOCUMENT STATUSReview required
Identity · effective date · jurisdiction · approval
!

Draft — legal and compliance approval required

Proposed effective date: July 21, 2026 · Version 1.0. Ohio formation jurisdiction and authorized-representative approval remain outstanding.

Legal role

Business Associate status depends on the actual service relationship

The status is not created merely because a customer uses iCare or enters health-related information. When HIPAA requires a Business Associate relationship, the parties must execute an appropriate BAA and any applicable service, privacy, security, or data-processing agreements.

1Services and data actually processed determine the role
2Permitted uses and disclosures must be governed by agreement
3BAA requests are reviewed during contracting
4Questions go to support@icareevv.com
Safeguard areas

Controls that support accountable use

01

Administrative

Role design, access review, incident response, workforce procedures, and vendor governance require organizational ownership.

02

Technical

Authenticated sessions, permissions, tenant scoping, audit history, and secure transport support protected workflows.

03

Operational

Configuration, device practice, data minimization, training, review queues, and escalation determine how controls work day to day.

Shared responsibility

Technology and organizational practice work together

01

iCare responsibilities

  • Operate documented platform controls
  • Protect platform access and tenant boundaries
  • Maintain relevant activity and security capabilities
  • Support agreed contractual and incident processes
02

Customer responsibilities

  • Determine legal role and permitted use
  • Assign and review appropriate access
  • Configure workflows and retention for requirements
  • Train the workforce and respond to operational risk
i

Business associate agreement

BAA availability is evaluated case by case. Send requests to support@icareevv.com.

i

No product certification claim

iCare does not claim that software itself is “HIPAA certified.” Compliance depends on platform safeguards, customer configuration, workforce practices, access controls, policies, training, and governing agreements.

Authoritative references

Review HIPAA requirements at their source

01

Covered Entities and Business Associates

U.S. Department of Health and Human Services guidance on regulated roles and Business Associate arrangements.

Learn more →
02

HIPAA Security Rule

HHS overview of standards for protecting electronic protected health information.

Learn more →
Next step

Review the exact service and responsibility model.

Security, privacy, procurement, and legal questions should be evaluated against the configured service and governing agreements.

Contact iCare→
iCare EVV

Clearer home-care operations, from schedule to completed visit.

support@icareevv.com

Platform

Product overviewCaregiver appiPhone early accessAndroid early access

Resources

What is EVV?EVV implementation checklistScheduling workflow guideImplementation guideCare operations in practiceFrequently asked questionsHelp center

Company

About iCareContactBook a demoSign in

Trust

HIPAA overviewPrivacyTerms
© 2026 iCare. All rights reserved.Do not send protected health information through public forms.