← Back to blog

Is AI allowed in home health documentation?

By Tiantian Zha · Published September 9, 2026

Three questions come up in almost every conversation with home health agencies considering AI documentation. Does Medicare allow AI? Is it HIPAA compliant? Is patient data secure?

These are key questions, and they have clear answers. The short version: yes, AI is allowed in home health documentation. Now let's unpack the long version, because the details are important.

What CMS says about AI and the OASIS

The clearest guidance on AI and the OASIS from the Centers for Medicare & Medicaid Services (CMS) came with the April 2026 release of OASIS-E2.

In the section on General OASIS Item Conventions (1.5.8.1) CMS wrote that an agency's software may not "answer" or "generate" the OASIS response for the assessing clinician. Nearly every EMR and documentation vendor now advertises AI. Did that one sentence rule all of it out?

The final guidance is more specific:

An agency's software may not "answer" or "generate" a final code for the OASIS items. Following agency policies, the assessing clinician is responsible for considering available information and ensuring the appropriate OASIS item response(s) were selected, within the appropriate timeframe and consistent with data collection guidance.

Two details matter here.

First, the restriction is on the final code. Software cannot be the thing that picks the answer and enters it.

Second, consider what the clinician has to do. They consider the available information, then make sure the right response was selected. That's a review step. It does not prohibit software helping before that step.

Our read: this is not a change in policy. CMS used very similar language in a quarterly Q&A several years ago. What changed is where the language sits. AI now plays a much bigger role in documentation, so CMS moved the point to the front of the manual. The message is that clinicians must review and approve AI documentation.

So the line is not about whether AI touched the assessment. It is about who makes and enters the final response. A tool that drafts for a clinician to review and finalize is allowed. A tool that generates and submits OASIS responses automatically is not.

Is it HIPAA compliant?

HIPAA does not regulate AI as a tool in healthcare. HIPAA regulates the protected health information (PHI) of patients.

Here is what that means for home health agencies. An AI software vendor that receives, stores, or sends PHI on your behalf is a business associate. Just like your billing company. Just like your EMR. To maintain HIPAA compliance, every business associate needs a signed Business Associate Agreement, or BAA.

That makes the BAA the most important document in your evaluation. Four things it should say:

How to keep patient data secure

The Security Rule applies to business associates the same way it applies to everyone else holding ePHI. Check these five boxes when you are evaluating security with vendors.

The bottom line

When it comes to AI documentation in home health, compliance with Medicare and HIPAA comes down to three principles:

  1. AI is allowed to help with documentation work.
  2. AI is not allowed to replace a clinician who is accountable.
  3. Patient data is protected by a BAA, just like other business partners.

When you speak with AI vendors, be sure their BAA is fully compliant and confirm that there is a clinician-in-the-loop for all documentation.

See how Andy AI drafts compliant OASIS for clinician finalization – accurate, compliant, and finished in about 15 minutes – on the OASIS & VBP page, or book a 15-minute demo.

Sources