HIPAA laws for caregivers
A plain-language guide for Stay Home Companions | Michigan
Prepared September 22, 2026. This educational guide explains core privacy rules and practical caregiving habits. It is not the complete law, legal advice, a certification, or a replacement for employer training.
What caregivers need to know
Protect client information. Access it only for your assigned work, share it only through an authorized process, and report privacy concerns promptly. Stay Home Companions requires staff to follow its HIPAA and confidentiality policies. Those duties do not disappear when a shift ends.
Michigan Home Help has a specific requirement
The MDHHS Home Help agency caregiver terms require caregivers to follow laws governing the use and sharing of clients' protected health information, expressly including HIPAA privacy rules. This appears in MSA-204, Section 5, item 10. Caregivers working in that program must follow its requirements as well as agency policies. [2]
How federal coverage works
HIPAA means Health Insurance Portability and Accountability Act. Its federal rules apply to covered entities and business associates. Covered entities include health plans, clearinghouses, and health care providers that conduct specified electronic transactions. Business associates perform certain work involving protected information for covered entities. The label "non-medical" alone does not settle an agency's obligations. Program agreements and contracts also matter. [1]
What is protected health information?
PHI is individually identifiable health information protected by HIPAA in a covered setting. It can be spoken, written, or electronic: for example, a client's name linked to a diagnosis, care information, or health care payment. A photograph or address can help identify someone. Other personal information also deserves protection under company policies even when it is not legally PHI. [3]
When information may be shared
Work access is not permission to browse
The minimum necessary rule generally limits access, requests, and sharing to what is needed for the purpose. Follow the access permissions assigned to your role. Do not look up a neighbor, relative, or former client out of curiosity. An entire record is not automatically needed for every task. [4]
There are exceptions to this standard, including disclosures to or requests by a health care provider for treatment, disclosures to the individual, valid authorizations, and disclosures required by law. These exceptions do not authorize unrelated browsing or gossip. [4]
Consent is not the same as every authorization
HIPAA permits certain uses and disclosures without a signed authorization, including treatment, payment, and health care operations subject to the rule's conditions. Other disclosures require a valid authorization or another legal basis. A signed acknowledgement of a privacy notice is not blanket permission to disclose information. Route unusual requests to the office. [3]
Family members do not automatically get every detail
HIPAA permits sharing information directly relevant to a family member's or friend's involvement in care or payment when the person agrees or does not object. If the person cannot agree or object, a provider may use professional judgment about the person's best interests. This is not unrestricted access to the entire record. [5]
Caregiver example: An unfamiliar caller says, "I am her daughter. What medications is she taking?" Verify the caller and follow the agency's permission process before sharing. Refer uncertainty to the office rather than guessing about the caller's authority.
Clients have rights, too
Where HIPAA applies, individuals generally have rights to access their records, request corrections, receive a privacy notice, request restrictions and confidential communications, and complain about privacy practices. These rights have conditions and exceptions. Forward requests promptly to the office; do not dismiss a request or promise a result you cannot authorize. [8]
Protect information during every shift
Practical safeguards to use with your employer's procedures
Conversations and paper records
Speak privately. Avoid discussing clients in stores, hallways, or around visitors who are not authorized to hear the information. Keep notes and schedules out of public view. Return records through the agency's process; do not leave them in a vehicle or discard them in household trash. Use approved secure disposal. [3,15]
Phones, messages, and photos
Use agency-approved devices and communication methods. Lock screens, protect passwords, check the recipient before sending, and report lost devices. Do not move client records to personal email, cloud storage, or an unapproved app. The Security Rule requires safeguards for electronic PHI; the agency must assess and manage its risks. These examples are practical safeguards, not a complete list of technical legal requirements. [6]
Recommended practice: Do not post client photos, names, home interiors, or identifying stories on personal social media. For an agency publication, use the office's authorization process. Removing a name does not necessarily make a story anonymous.
If you send information to the wrong person
Stop further sharing and report the incident to the office immediately. Record what happened, when, what information was involved, and who may have received it. Preserve relevant messages and follow instructions; do not conceal the mistake or make promises to the recipient on the agency's behalf.
Under HIPAA, an impermissible use or disclosure is generally presumed to be a breach unless a qualifying exception or documented risk assessment supports otherwise. The responsible organization evaluates the incident and any required notices. Proof of actual harm is not a prerequisite. [7]
Required individual breach notices must be sent without unreasonable delay and no later than 60 days after discovery. Other reporting duties also apply. That outer deadline is not permission for staff to wait: report concerns promptly so the agency can act. [7]
Michigan requirements and training
Is HIPAA different in Michigan?
HIPAA is federal. Applicable state laws that provide stronger privacy protections or greater individual rights generally remain in effect. Michigan program terms can impose additional duties, including Home Help's express HIPAA privacy commitment. [2,9]
Certain behavioral health and substance use treatment information has additional confidentiality requirements. Do not assume that a general release or a HIPAA permission resolves every situation. Have the office review the applicable Michigan and federal requirements before unusual disclosures. [10]
Privacy does not prevent required abuse reporting
Michigan law requires specified human-services and other professionals who suspect or have reasonable cause to believe an adult has been abused, neglected, or exploited to report immediately. A report to a supervisor does not replace a mandated reporter's own reporting duty. Contact Michigan Adult Protective Services at 855-444-3911; call 911 for immediate danger. Notify the agency as well, without delaying the required report. [11,12]
HIPAA permits disclosures required by law and certain abuse-related disclosures when the applicable conditions are met. It is not a reason to conceal suspected abuse. [3]
Do caregivers need to buy a course?
The federal training rule requires covered entities to provide workforce training appropriate to their policies and staff duties, including training for new staff and material policy changes. It requires documentation, not purchase of a particular commercial course. Security awareness training is also required where applicable. Free HHS resources are available. Reading this guide supports, but does not complete, employer-specific training. [6,13,14]
Stay Home Companions' supplied policy requires training upon hire and annually. Follow that company requirement. The Privacy Rule does not prescribe one universal annual course for every worker. Its six-year documentation rule runs from creation or when the document was last in effect, whichever is later; it is not permission to destroy all client records at six years. [13]
Questions or privacy concerns: contact Christine Steve or the office at 269-382-3355. Ask before sharing when you are unsure.
Free official references
1. HHS: Covered entities and business associates
2. MDHHS: Home Help caregiver terms, MSA-204, page 4, item 10
3. HHS: Summary of the Privacy Rule
4. HHS: Minimum necessary requirement
5. HHS: Family members and friends
6. HHS: Summary of the Security Rule
7. HHS: Breach Notification Rule
8. HHS: Your rights under HIPAA
9. HHS: More protective state privacy laws
10. MDHHS: Behavioral health information sharing and privacy
11. Michigan Legislature: Adult reporting, MCL 400.11a
12. MDHHS: Adult Protective Services mandated reporters
13. eCFR: Training and documentation, 45 CFR 164.530
14. HHS: Free training materials
15. HHS: Safe disposal of protected information
Research checked September 22, 2026. References are free official government resources. Numbers in the guide match this list. Company training and contact details come from the materials supplied by Stay Home Companions.