HIPAA and Data Retention Requirements for EVV and mPERS Records in Minnesota
An EVV clock-in record and an mPERS fall alert both look, on the surface, like operational data: a timestamp, a location, a device status. Both are also Protected Health Information under HIPAA, because both are tied to an identifiable individual and relate to the provision of health care to them. Agencies that treat this data as “just app logs” rather than PHI are the ones most likely to discover the gap during an audit or, worse, a breach, rather than beforehand.
What Counts as PHI in an EVV/mPERS Context
HIPAA defines PHI broadly: individually identifiable health information, held or transmitted by a covered entity or business associate, in any form. That standard doesn’t require a diagnosis or a clinical note to apply. An EVV record showing that a specific client received PCA services at a specific address, on a specific date, from a specific caregiver, meets the definition on its own, because it reveals that an identified person received a health care service. An mPERS record goes further: a fall-detection alert, a call log with a monitoring center, or GPS coordinates at the moment of an emergency dispatch are all tied to a health event for an identifiable person, which puts them squarely inside PHI as well, not in some lesser “operational data” category outside HIPAA’s reach.
This is worth stating plainly because it’s an easy assumption to get wrong: GPS coordinates alone, disconnected from any person, aren’t PHI. GPS coordinates tied to a named client’s verified visit or emergency alert are.
Federal HIPAA Retention Baseline
HIPAA itself doesn’t set a specific retention period for the underlying records (visit logs, alert histories, and the like). What it does require, under the HIPAA Privacy and Security Rules, is that HIPAA-related documentation, policies, procedures, risk assessments, business associate agreements, and records of actions taken to comply, be retained for six years from the date of creation or the date it was last in effect, whichever is later (45 CFR § 164.316(b)(2)). That six-year clock is a floor for compliance documentation specifically; it’s not automatically the retention period for every underlying clinical or operational record, which is where state law and program-specific requirements layer on top.
Minnesota’s Additional Retention Rules
Minnesota generally requires health care providers to retain patient records for longer than HIPAA’s federal floor, and Medicaid provider agreements typically carry their own recordkeeping requirements tied to audit and reimbursement periods, which can extend well past the HIPAA baseline. Retention periods and specific statutory citations shift with updates to state law and DHS provider manuals, so treat any specific number here as a starting point for a conversation with your agency’s own counsel, not a figure to hard-code into a records-destruction policy. Two things are worth confirming directly rather than assuming: the current DHS-required retention period for EVV and PCA/PERS billing records tied to your specific waiver programs, and whether that period is measured from the date of service, the date of last billing activity, or the date of a client’s discharge, since agencies sometimes get this wrong by defaulting to the shortest number they’ve heard rather than the one that actually applies to their programs.
Where GPS and Location Data Fit Under HIPAA
Location data deserves its own callout because it’s the piece of EVV and mPERS data that feels the least like “health information” and gets handled the most casually as a result. A GPS trail showing where a caregiver clocked in for a visit, or where a client was when a fall-detection alert fired, is exactly the kind of granular, re-identifiable data that HIPAA’s minimum necessary standard is meant to constrain: it should be accessible to people who need it for care coordination, billing, or compliance review, and not treated as general operational data available to anyone with system access. Agencies should be able to answer, for any EVV or mPERS vendor they use, who inside that vendor’s organization can see raw location data, and under what access controls, the same way they’d expect to answer that question about their own EHR access.
Business Associate Agreements With EVV/PERS Vendors
Any EVV or mPERS vendor handling this data on an agency’s behalf is a business associate under HIPAA, full stop, and needs a signed Business Associate Agreement (BAA) in place before any client data flows to them, not after. A BAA needs to address, at minimum: permitted uses of the data, the vendor’s obligation to implement appropriate safeguards, breach notification timelines back to the agency, and what happens to the data if the relationship ends (deletion, return, or continued retention under an independent legal obligation). An agency that’s rolled out an EVV or PERS vendor without a BAA in place, even a free state-run portal generally has this handled at the state level, but any third-party Alt-EVV or PERS app doesn’t, has a compliance gap that exists regardless of how well the underlying software performs.
Breach Notification Basics
If PHI in an EVV or mPERS system is exposed, through a vendor breach, a lost device, or unauthorized access, the HIPAA Breach Notification Rule generally requires notifying affected individuals without unreasonable delay and no later than 60 days after discovery, notifying HHS (with timing depending on the number of individuals affected), and in some cases notifying local media for larger breaches. As the business associate, an EVV or PERS vendor is contractually and legally obligated to notify the agency promptly of any breach on their end, which is exactly the kind of obligation that should be spelled out explicitly in the BAA rather than assumed to be covered by general “we take security seriously” language.
What Agencies Should Actually Have in Writing
Pulling this together, a reasonably defensible position for an agency using EVV and mPERS technology means being able to produce, on request:
- A signed BAA with every vendor that touches client visit or location data
- A documented retention schedule for EVV and PERS records, aligned to both HIPAA’s six-year documentation floor and Minnesota’s longer provider-specific requirements
- A record of who has access to raw GPS and alert data, both internally and at each vendor
- A written breach notification process, including the vendor’s contractual obligation to notify the agency promptly
None of this needs to be elaborate. It needs to exist, be current, and be something office staff can actually locate quickly if DHS, a client, or a vendor ever asks.
The Bottom Line
EVV and mPERS data reads like operational logging, but it’s PHI under HIPAA, and treating it that way from the start (BAAs signed before data flows, retention periods documented rather than assumed, access limited to who actually needs it) is meaningfully cheaper than fixing the gap after an audit or a breach makes it visible. We cover the audit side of this in our EVV audit preparation checklist; this is a related but distinct obligation from audit readiness, and it’s worth confirming with your own counsel rather than taking any vendor’s word for it, including ours.
Zayd gives your agency free, DHS-compliant EVV — and more for partner agencies.
DHS-compliant, syncs into HHAeXchange. So your team can focus on client care.
Don't miss the next one.
One email when we publish. EVV compliance updates and what's actually working for MN home care agencies.