It is 11 pm. An adult daughter in another state is searching for help for her aging mother. She finds your website, reads about your services, and starts filling out your contact form. She types her mother''s name, a diagnosis, her own phone number, and a few sentences about what is happening at home. Then she stops. Where does this information go? Who sees it? Is it safe with your agency?
If your website cannot answer that question in a document she can find in seconds, she may close the tab and try a competitor instead. A privacy policy answers that question. It is one of the simplest pages on your website to create, and one of the easiest to overlook.
This guide covers what a privacy policy is, why the law requires one, the best ways to get one written correctly, what happens if you do not have one, and why it matters even more in the home care industry.
What Is a Privacy Policy?
A privacy policy is a page on your website that explains, in plain language, what personal information you collect from visitors, how you use it, who you share it with, and how a visitor can exercise their rights over that information.
A complete privacy policy typically covers:
- What information you collect, such as a name, phone number, email address, or health related details submitted through a contact form
- How that information reaches you, whether through a contact form, a phone call, live chat, or website analytics
- Why you collect it, such as to respond to an inquiry or schedule a consultation
- Who else sees it, such as a scheduling platform, a CRM, an email provider, or an analytics tool
- How long you keep it and how you protect it
- What rights a visitor has to access, correct, or delete their information, and how to reach a real person with questions
A privacy policy is different from terms of service, which govern how someone may use your website. It is also different from a HIPAA Notice of Privacy Practices, a separate and more detailed document required only of certain health care providers. Every home care website needs the first. Some agencies need the second as well, which is covered further below.
Why Privacy Policies Are Legally Required
No single federal law spells out every requirement for a website privacy policy. Instead, the obligation comes from two directions.
Federal Trade Commission Act, Section 5
Section 5 of the FTC Act prohibits unfair or deceptive business practices. If your website collects a visitor''s name, phone number, or health information and never discloses what happens to it, or discloses it inaccurately, the FTC can treat that silence or inaccuracy as deceptive. This applies to any business collecting personal information online, home care agencies included.
State Privacy Laws
State privacy laws close the rest of the gap, and the list keeps growing. As of the middle of 2026, twenty states have comprehensive consumer privacy laws in effect, with several more scheduled to take effect in the coming years. California''s law, one of the strictest, requires covered businesses to describe the categories of personal information they collect, where it comes from, why they collect it, whether they sell or share it, and what rights consumers have, and to review and update that policy at least once every twelve months.
Most home care agencies are small businesses and may fall below the size thresholds that trigger the strictest state laws. That said, thresholds vary by state and change over time, and Section 5 of the FTC Act applies regardless of company size. Confirming which specific state laws apply to your agency is worth a conversation with an attorney who handles data privacy.
Where HIPAA Fits In, and Where It Does Not
HIPAA is the law most people think of first when they hear health privacy, but it does not automatically cover every home care agency. HIPAA applies to covered entities, generally health care providers who transmit health information electronically in connection with specific transactions, such as billing Medicare or Medicaid electronically.
Agencies that provide skilled nursing or home health services and bill insurance directly are typically covered entities under HIPAA. Agencies that provide personal care or companion services on a private pay basis, with no insurance billing, are often not covered entities, though this depends on each agency''s specific operations.
A note on this section: Whether HIPAA applies to a specific agency depends on its billing practices, its relationships with insurers, and its state''s own health privacy laws layered on top of HIPAA. This is a determination worth confirming directly with an attorney for your specific agency rather than assuming either way.
Whether or not HIPAA technically applies, the information home care agencies collect through a website, a diagnosis, medication needs, cognitive status, or details about a family''s situation, is just as sensitive as anything HIPAA protects. Treating it with that level of care, regardless of the legal requirement, is both an ethical standard and a meaningful trust signal to the families evaluating your agency.
What Happens If You Do Not Have One
Operating without a privacy policy carries real risk, not just a technical gap.
- Regulatory exposure: state attorneys general can pursue civil penalties for privacy law violations. Under California''s law, penalties can reach several thousand dollars per violation, and every affected visitor can count as a separate violation.
- Private lawsuits: several state privacy laws, including California''s, allow consumers to bring their own legal claims in certain circumstances, separate from any government enforcement action.
- Lost trust and lost leads: a family member deciding between your agency and a competitor is unlikely to notice a well written privacy policy, but many will notice its absence, especially after typing sensitive information into your contact form.
California''s Attorney General once pursued Delta Air Lines for failing to post a clear privacy policy on a mobile app, arguing the omission violated the state''s online privacy law. The case was ultimately dismissed for unrelated procedural reasons, but it remains a widely cited example of how seriously regulators can treat a missing or inadequate policy, even against a company with far more legal resources than a typical home care agency.
The Best Ways to Get a Privacy Policy
There is no single right way to obtain one, but the options generally fall into three categories.
1. An attorney who handles data privacy
This is the most thorough option, especially useful if your agency operates in multiple states, bills insurance, or uses tools like AI chat that raise their own disclosure questions. An attorney can confirm exactly which state laws apply to your agency and draft language that matches your actual practices.
2. A reputable privacy policy generator, reviewed afterward
Generator tools can produce a reasonable starting draft based on a questionnaire about your website and business. They are not a substitute for legal review, but they are a faster and lower cost starting point than a blank page, provided someone reviews the output against what your site actually collects.
3. A policy built around what your website actually does
Whichever route you choose, the policy has to match reality. If your website uses a contact form, a scheduling tool, analytics, and an AI chat assistant like Carey, all four need to be named. A generic template that does not reflect your actual tools is its own kind of deceptive practice under Section 5.
What to include, at minimum
- Every category of information your site collects, including anything typed into a chat assistant
- Every tool or vendor that receives that information
- A clear statement of whether information is sold or shared, and to whom
- How a visitor can ask questions or request their information be corrected or removed
- A last updated date, revisited at least once a year and any time you add a new tool
Why This Matters Even More for Home Care
Families searching for home care are rarely casual browsers. They are often managing a parent''s diagnosis, a recent hospital discharge, or a sudden change in a loved one''s ability to live independently, and they are doing it under real stress. Adult children making these decisions are also frequently the target of scams aimed at older adults and their families, which makes them more cautious, not less, about who they hand personal information to online.
The information submitted through a home care contact form is rarely just a name and an email address. It often includes a diagnosis, mobility needs, or a description of a difficult family situation. A visible, honest privacy policy tells that visitor your agency takes their trust seriously before anyone on your team ever picks up the phone. In an industry built entirely on trust, that is not a compliance checkbox. It is a first impression.
Getting Started
- List every tool on your website that touches visitor information: contact forms, live chat, analytics, and any AI assistant
- Choose an attorney, a reviewed generator, or your web provider to draft language that matches that list
- Publish the policy and link it clearly in your website footer
- Revisit it at least once a year, and immediately after adding any new tool that collects information
This post is educational content, not legal advice. Have your privacy policy reviewed by an attorney licensed in your state before publishing it.