1 | HIPAA Compliance
Covered Entity
Ohio at Home Healthcare is a HIPAA covered entity because it bills Ohio Medicaid and managed care organizations electronically for covered healthcare services. All Protected Health Information (PHI) is handled in accordance with the Health Insurance Portability and Accountability Act of 1996 (HIPAA) and its implementing regulations at 45 CFR Parts 160 and 164.
Minimum Necessary Rule
Staff access only the PHI required to perform their job duties.
Business Associates
Vendors with potential PHI exposure sign HIPAA-compliant Business Associate Agreements (BAAs).
Breach Notification
Any unauthorized access, use, or disclosure of unsecured PHI is reported to affected individuals without unreasonable delay, no later than 60 calendar days after discovery. For a breach affecting 500 or more individuals, we notify the Secretary of HHS within that same timeframe. For fewer than 500 individuals, we notify HHS within 60 days after the end of the calendar year in which the breach was discovered.
A breach affecting more than 500 residents of a state or jurisdiction also requires notification to prominent media outlets serving that area, without unreasonable delay and within 60 calendar days after discovery. See the HHS breach notification guidance. This summary was clarified September 22, 2026; it retains OAH's commitment to report any unauthorized access, use, or disclosure to affected individuals.
2 | How We Use and Disclose Your Information
Under HIPAA, we may use or disclose your Protected Health Information for the following purposes without your written authorization:
Treatment
Using and sharing PHI among your authorized care team—including our internal staff and, where applicable, external providers involved in your care—to deliver, coordinate, and manage your services.
Payment
Submitting claims and documentation to Medicaid, managed-care organizations, and County Boards to obtain payment for services rendered.
Healthcare Operations
Quality improvement, auditing, staff training, compliance reviews, and business management activities necessary to run our organization.
Other Permitted Disclosures (Without Authorization)
Federal and state law also permits or requires us to disclose PHI without your authorization in specific circumstances, including:
- Public health and safety activities, including mandatory reporting of abuse, neglect, or exploitation under Ohio law (including ORC 5123.61) and disease reporting
- Law enforcement requests and judicial/administrative proceedings
- Oversight agencies, including the Department of Developmental Disabilities (DODD), the Ohio Department of Medicaid (ODM), County Boards of DD, the Centers for Medicare & Medicaid Services (CMS), and the Ohio Attorney General
- Averting a serious and imminent threat to health or safety
- Workers’ compensation and occupational safety
- Coroners, medical examiners, and funeral directors
- Organ and tissue donation organizations
- Health oversight activities and compliance audits
All other uses and disclosures require your written authorization. You may revoke any authorization in writing at any time.
3 | Information We Collect and Why
| Data Type | Source | Purpose |
|---|---|---|
| Client demographics, care plans, medical histories | Enrollment forms, Individual Service Plan (ISP), Behavioral Plans, guardians | Service delivery and billing |
| Individualized Education Programs (IEPs) | Families or schools (when voluntarily shared; IEPs are education records that may be subject to FERPA—we receive them only with appropriate consent) | Aligning support with educational goals—reinforcing skills, mentorship, and consistent language during engagements |
| Live audio and/or video streams, where authorized | Remote Support sessions that include these features in the person’s ISP (during approved service windows) | Real-time safety monitoring and coaching |
| Ambient sensor data (e.g., motion, environmental conditions, and presence/movement indicators) | In-home safety sensing technology | Risk detection, safety alerts, and safety pattern analysis |
| Shift logs and Electronic Visit Verification (EVV) | Direct Support Professional (DSP) / Remote Support Associate (RSA) entries | Medicaid compliance, quality audits |
| Incident reports and notes | Staff documentation | Continuous quality improvement |
| Information submitted through contact or application forms | Ohio At Home’s separate intake service | Handling your inquiry or application; see the intake privacy information linked below |
We do not sell or rent any personal data.
4 | Our Privacy-First Approach to Remote Support
Choosing monitoring technology for your home is a significant decision. Ohio at Home selects the least intrusive technology that meets each person’s safety needs. Ambient sensing, live audio or video, and recording are different features. A sensor-only configuration does not include audio or video; those features depend on the person’s authorized plan. The camera and recording provisions below apply when those features are included.
Least-Intrusive-First Principle
We begin with ambient, non-visual sensing technology—such as motion, environmental conditions, and presence/movement indicators—before considering more detailed monitoring. Visual monitoring is used only when clinically necessary and authorized by the individual and/or their guardian (if applicable).
Privacy Gating
Our system supports granular privacy controls. Audio monitoring, video monitoring, and ambient sensing can be enabled or disabled independently based on each person’s ISP and personal preferences. This means a person may have audio support without video, or ambient sensing without either.
Emergency Escalation Protocol
During ISP development, each individual and/or their guardian (if applicable) reviews and consents to an emergency escalation protocol. This protocol defines the narrow circumstances under which monitoring may temporarily exceed the individual’s standard privacy settings. Emergency escalation is authorized only when there is an imminent risk of death or serious physical harm to the individual.
When emergency escalation occurs:
- The on-duty Remote Support Associate immediately escalates monitoring to protect the individual’s health and safety.
- The individual’s guardian or legal representative (if applicable) is notified immediately.
- A supervisor reviews the escalation within the same shift.
- The escalation is logged with the date, time, duration, reason, and staff involved.
- An incident report is filed in accordance with the procedures described in Section 11.
- An ISP review is scheduled within 30 days to evaluate whether privacy settings should be adjusted.
- Return to standard monitoring levels is determined by the individual’s ISP and support team on a case-by-case basis.
Camera Placement Safeguards
Cameras are never placed in bathrooms under any circumstances.
In rare situations where health and safety needs require it—and only after the individual’s Human Rights Committee (HRC), a team that includes the individual, family members, and independent advocates who review decisions affecting the person’s rights, has reviewed and approved the arrangement—cameras may be placed in bedrooms. HRC approval for bedroom cameras must be renewed annually.
When bedroom cameras are in place, recording can be paused at any time through any of the following:
- Guardian app (a free mobile app provided with your Remote Support service, available to individuals and guardians) — pause streaming and recording directly
- Contact Remote Support — request a pause by phone or in-home device
- Contact Administration — request a pause through your Care Coordinator or any OAH administrator
Supervisor Video Review
For prospective and current employees: Where an authorized service configuration includes video recording, the protections in this section define the boundaries of workplace monitoring during your shifts. Your supervisor can only review recorded video for the three purposes listed below—no exceptions.
Supervisors may review recorded video only for the following purposes:
- Incident follow-up — reviewing events related to a fall, behavioral incident, or missed check-in
- Quality assurance — evaluating staff performance and service delivery
- Investigating a complaint or grievance — only with permission from both the support team and the individual (or their guardian)
No other use of recorded video is permitted.
No Always-On Surveillance
Where live audio or video is included in the authorized plan, feeds activate only during approved service windows defined in the ISP. Outside of those windows, audio and video systems are inactive. Ambient sensing may continue to operate outside service windows, but only to the extent authorized in the person’s ISP. Ambient sensors can be adjusted in detection level (for example, simple presence detection versus more detailed monitoring) or turned off entirely based on the individual’s preferences and ISP.
Ambient sensor alerts are handled according to the person’s monitoring plan. During authorized hours of actively monitored Remote Support, staff review alerts and follow the plan’s response and escalation procedures. A sensor remaining active outside those hours does not, by itself, mean that staff are providing continuous monitoring.
Encryption and Access Controls
All data streams are protected by industry-standard encryption (see Section 8 for details). Only credentialed, authorized staff may access live feeds or recorded data.
5 | Your Privacy Controls
Every individual receiving Remote Support services has personalized privacy controls documented in their Individual Service Plan (ISP). These controls are developed with the individual, their guardian (if applicable), and the County Board.
Adjusting Your Monitoring
You have several ways to make a change to your monitoring at any time. Temporary changes (such as pausing monitoring) take effect immediately. Permanent changes to your ISP privacy settings are coordinated with your Care Coordinator:
- Contact Remote Support directly from your dedicated in-home device or your personal phone
- Call our 24/7 support line at (614) 800-0672
- Speak with your Care Coordinator to make a permanent change to your ISP privacy settings
What You Can Control
Depending on your ISP, you may:
- Pause all monitoring temporarily
- Disable video while keeping audio active (or vice versa)
- Reduce monitoring to ambient sensing only
- Adjust the detection level of ambient sensors (e.g., presence detection only)
- Request that specific sensors be removed or powered down (as promptly as practicable, typically within 2 business days; urgent requests are prioritized)
- Pause bedroom camera recording at any time via the Guardian app, Remote Support, or Administration (see Section 4)
- Adjust your data recording and retention preferences (see Section 7)
Ending Services
You may end services entirely by providing 30-day notice per your service agreement. This notice period exists for administrative coordination—including records transfer, County Board notification, and continuity-of-care planning—and does not restrict your right to refuse any individual service or support at any time without reprisal (see Section 6).
6 | Your Rights
You have the right to see your records, correct mistakes, control how your information is shared, and raise concerns without consequences. Specifically, under HIPAA and state law you may:
- Access your health information (see your records).
- Request amendments to incorrect or incomplete records (ask us to fix mistakes).
- Receive an accounting of disclosures (a list of who we have shared your information with, beyond your care team and billing).
- Restrict certain uses or disclosures (within regulatory limits).
- Request confidential communication (e.g., send mail to a different address).
- Receive a copy of this privacy notice.
- File a complaint without fear of retaliation.
Rights Under Ohio Law (ORC 5123.62)
As an individual receiving developmental disability services in Ohio, you also have the right to:
- Participate in the development of your Individual Service Plan (ISP).
- Refuse any service or support without reprisal.
- Be free from abuse, neglect, exploitation, and unnecessary restraint or seclusion.
- Privacy in personal affairs, communications, and visits.
- Access advocacy services through your County Board of Developmental Disabilities (the local government agency that coordinates DD services in your county).
- Be treated with dignity and respect in all interactions.
Right to Be Informed of Incidents
Under Ohio’s incident reporting rules (Ohio Administrative Code [OAC] 5123-17-02) and your service agreement with OAH, you also have the right to be informed of incidents involving your care, access incident documentation, and participate in follow-up reviews.
To exercise these rights, contact our Privacy Officer (see Section 12).
7 | Data Retention
Every individual has a personalized data retention plan established in coordination with their guardian (if applicable) and County Board. The following table describes the default retention periods:
| Record | Default Retention | Notes |
|---|---|---|
| PHI and service notes | 7 years after service termination | Per the OAH Medicaid provider agreement and applicable Ohio Medicaid regulations |
| Recorded audio/video from Remote Support sessions | 7 days (default) | Adjustable per your ISP, from as low as 24 hours to no recording at all. Recordings associated with reported incidents are retained for 7 years, regardless of the individual’s default preference. |
| Ambient sensor alert logs | 2 years | |
| Shift logs and Electronic Visit Verification (EVV) records | 7 years | Per the OAH Medicaid provider agreement and applicable Ohio Medicaid regulations |
| Incident reports and notes | 7 years | Per OAC 5123-17-02 and applicable Ohio Medicaid regulations |
| SMS/messaging consent and logs | Duration of participation plus 2 years | For TCPA compliance |
| Website form submissions | 12 months |
8 | Security Safeguards
- Role-based access with multi-factor authentication (MFA)
- Industry-standard encryption in transit (TLS 1.2 or higher) and at rest (AES-256 or equivalent)
- 24/7 intrusion monitoring and encrypted backups
- Annual penetration testing and HIPAA workforce training
- Cloud infrastructure audited to industry security standards
9 | Website and Cookie Notice
The website’s information pages do not use visitor analytics or advertising trackers, or set application cookies. The website uses this tab’s session storage for accessibility display choices and reading speed. “Remember on this browser” optionally keeps those choices across visits in local storage. A small record of reset or withdrawal of Remember may remain so other tabs honor that action; it contains no personal information or visitor identifier. See the website notice below for technical request information and other details.
Contact and application forms are handled by a separate intake service. Read the intake privacy information for its form data and cookie practices before submitting.
10 | SMS / Text Messaging Privacy
Ohio at Home Healthcare may send SMS/text messages to your mobile phone number for the following purposes:
- Identity verification codes (one-time passwords)
- Health and safety monitoring alerts and notifications
- Responses to messages you send to us
- Appointment and schedule reminders
- Urgent notifications requiring immediate attention
Consent
By providing your phone number and consenting to receive text messages, you agree to receive the communications described above. You may receive messages from automated systems. Consent is not a condition of service.
Message Frequency and Rates
Message frequency varies based on your interactions, monitoring activity, and system events. Message and data rates may apply. Check with your wireless carrier for details about your text messaging plan.
Data We Collect
In connection with our messaging program, we collect your phone number, message content (sent and received), consent and opt-in/opt-out records with timestamps, and message delivery status.
How We Use Your Data
Your phone number and messaging data are used solely to provide the messaging services described above—delivering text messages you have consented to receive, processing your opt-in and opt-out requests, maintaining records of consent as required by law, and improving our messaging services.
Data Sharing
We do not sell, rent, loan, trade, lease, or otherwise transfer for profit any phone numbers or personal information collected through our SMS program to any third party for their marketing purposes.
Your messaging data may be processed by our cloud communications provider solely for the purpose of delivering messages. This provider is bound by applicable data protection agreements.
Opt-Out and Help
You may opt out of text messages at any time by replying STOP to any message or contacting us at support@ohioathome.com or (614) 800-0672. Upon opting out, you will receive one final confirmation message. For help, reply HELP to any message. See our full Messaging Terms of Service for details, or get help with text alerts.
11 | Incident Reporting
Ohio at Home Healthcare maintains a comprehensive incident reporting process in accordance with Ohio Administrative Code 5123-17-02. Incidents detected through remote monitoring, ambient sensors, or direct observation are documented and reported as follows:
| Incident Type | Reporting Process |
|---|---|
| Major Unusual Incidents (MUI) | Initial report filed with the County Board of DD via the DODD Incident Tracking System by 4:00 PM the next business day. Guardian/legal representative notified promptly. Full investigation completed within required regulatory timelines. |
| Unusual Incidents (UI) | Documented internally and reported to the County Board per OAC 5123-17-02 requirements. Guardian/legal representative notified promptly. |
| Sensor-detected events | Logged automatically; reviewed by staff according to the individual’s monitoring plan; escalated to MUI/UI process if criteria are met. |
Individuals and their guardians have the right to be informed of all incidents, access incident documentation, and participate in follow-up investigations. Contact your Care Coordinator or our Privacy Officer for incident records.
12 | Contact Us
Privacy Officer
Ohio at Home Healthcare
875 N High St, Suite 300, Columbus, OH 43215
Contact Us about a privacy question or call (614) 800-0672
If you believe your privacy rights have been violated, you may also file a complaint with the U.S. Department of Health and Human Services, Office for Civil Rights, at ocrportal.hhs.gov or (800) 368-1019.
13 | Policy Updates
We review this policy annually or whenever regulations change. New versions will be posted on www.ohioathome.com with the “Last updated” date amended. We will make reasonable efforts to provide written notice of material changes to active clients and guardians before the changes take effect, or as soon as practicable thereafter.
Thank you for trusting Ohio at Home Healthcare. Our mission is to pair effective safety tools with compassionate human care—while respecting your right to privacy every step of the way.
About this statement
This notice covers browsing Ohio At Home’s public information pages. The organization and service policy above addresses care and service records. Separate intake forms have their own privacy information; this website notice does not describe their submission, sign-in, or retention practices.
Information you provide
These pages provide information about Ohio At Home. They do not receive form answers, documents, or payment details.
The contact form and application form open on Ohio At Home’s separately hosted intake service. Information you submit goes directly to that service. Read its privacy information before submitting.
You can read these information pages without creating an account or signing in.
If you contact Ohio At Home by phone or email, that communication takes place outside these pages. Before sending personal records or documents, ask which channel is appropriate.
Cookies and tracking
The information pages do not use visitor analytics or advertising trackers, load tracking pixels, or create visitor profiles.
The information pages do not set application cookies. Session storage keeps your text size, spacing, theme, high contrast, reduced motion, animation Play/Pause choice, link emphasis, and reading speed while you navigate or reload pages in this browser tab. “Remember on this browser” optionally keeps those choices in local storage for future visits. Browsers may restore a tab’s session after restarting. Uncheck Remember to remove choices kept across visits while retaining each open tab’s current session choices. Select Reset preferences to remove saved choices and restore device-following defaults.
A small reset or Remember-status record may remain in local storage so other open or restored tabs honor your action. It contains no personal information or visitor identifier and is not used to create a profile. Preference storage does not contain form answers, page content, browsing history, or playback history. These choices and status records are not sent to our servers. When you follow a website or form link between ohioathome.com and forms.ohioathome.com in the same tab, a small, hidden page from the other site carries only display choices, animation Play/Pause choice, and reading speed within your browser. Some previews also support this handoff; other versions keep choices separate. The handoff never includes form answers, authentication information, Remember consent, or playback history. It does not put preferences in URLs or shared cookies. Remember remains a separate choice on each site. Direct visits and new tabs use that site’s own saved choices. When this website moves from ohioathome.com to www.ohioathome.com, a new tab at the new address may restore your previously remembered website display and reading choices through a separate, fixed Ohio At Home preference page. This browser-only transfer does not overwrite choices already made at the new address, copy Remember consent, change saved data at the old address, or send preferences to our servers. Choose Remember at the new address to save restored choices for future visits. If the handoff is unavailable, navigation continues using the destination’s settings. If browser storage is unavailable, settings still apply to the current page and the panel explains any saving or clearing failure.
Where a recorded page guide is available, the Listen control plays prepared MP3 files served by this website. Playing a guide does not send page text or form answers to OpenAI. Otherwise, read-aloud uses only voices the browser identifies as local to your device. Neither mode uses a microphone. Reading speed follows your preference settings, but restoring it never starts audio. Reading text, playback position, and playback history are not saved by the website.
The separate forms’ data handling and cookie practices are described in the intake privacy information.
Browser settings such as zoom and reading preferences remain under your control.
Technical requests
When you open a webpage, technical systems receive the request needed to deliver it. That information can include a network address, the requested page, the time, and browser details.
The website application does not log request data. Hosting infrastructure may process or retain technical request information separately; the absence of analytics does not mean that no technical information is processed.
Content and contact links
The photographs, illustrations, logo, and silent animations are hosted with this website. They do not load from a third-party media service. On some pages, a decorative animation can begin after the page and its opening image have loaded. Use the animation button to pause or play it. Reduced-motion preferences, data-saving settings, and slow connections keep the image still by default when your browser reports them.
A small script hosted with this website controls the animations. It does not track you. Your animation Play/Pause choice follows the accessibility preference storage and handoff described above; animation playback position and history are not saved. The pages do not load third-party scripts, fonts, maps, chat, or social feeds. Only the preference transfers described above use embedded pages hosted by Ohio At Home. No form or staff page is embedded.
Phone and email links, when available, open the calling or email application configured on your device. Those applications and their providers handle the resulting communication under their own settings and practices.
Website changes
This statement describes the features currently available on these information pages. New features or separate services may involve different information practices. Read the information provided with a service before submitting personal information.
Privacy questions
Visit the Contact page for ways to ask Ohio At Home a privacy question. Keep an initial question general and ask how to share any supporting records.
Using the website
Read, explore, and ask questions.
The FAQ brings together answers about services, contact, careers, privacy, and accessibility.