HIPAA depends on roles and data flow, not the word care

KOKO Care is in development and in-home testing. Homebot One describes consent and personal control as design goals and says features will be introduced progressively through testing. Its page also states that KOKO Care is not a medical device and does not replace professional care, emergency services, or human judgment. Those statements do not determine HIPAA applicability for a proposed deployment.

HIPAA applies to covered entities and business associates. The relationship depends on the work performed and protected health information involved. HHS distinguishes a software sale without access to a covered entity's PHI from services such as hosting or troubleshooting that involve that information. Its cloud guidance also explains that maintaining encrypted electronic PHI on behalf of a covered entity or another business associate can create business associate status even without a decryption key.

Build a KOKO Care program budget

Review KOKO privacy questions for the home

Draw the proposed data flow before asking for a conclusion

Start with one bounded routine and list every party. A direct household arrangement may involve the resident, family members, Homebot One, and technology providers. A care-organization deployment may also involve a health plan, provider, facility, caregiver, researcher, contractor, or integration vendor. Do not assume all are covered entities, business associates, or subcontractors. Record who is acting for whom and why each party receives information.

Then identify the information rather than labeling everything health data. Ask whether the routine involves a schedule, reminder, call request, support ticket, sensor observation, location, account identifier, medication-related detail, symptom, clinical record, or another category. These examples are questions, not statements about KOKO's current collection. Mark where information originates, whether it becomes linked to an identifiable person, where it is stored, and which system is the record of authority.

  • Exact KOKO build, program, organization, and intended routine
  • Data elements created, received, maintained, or transmitted
  • Purpose and legal role of every party in the flow
  • Storage, remote access, support, integration, and subprocessors
  • Exit path for export, return, deletion, and account closure

If a business associate relationship exists, inspect the agreement

A business associate agreement is not a general privacy badge. HHS says a covered entity that engages a business associate must have a written contract or other arrangement defining the work and requiring protection of protected health information. The covered entity's privacy, security, legal, and procurement teams should determine whether the relationship applies and which entity signs the agreement. A generic web statement should not replace that review.

For a KOKO Care proposal, reconcile the agreement with the data flow. Ask which services create, receive, maintain, or transmit electronic PHI; which workforce members and subcontractors can access systems; and how audit records, incidents, and termination are handled. Review cloud storage as well as remote troubleshooting. Encryption and a vendor's inability to read stored PHI do not, by themselves, remove business associate obligations.

  • Permitted and required uses and disclosures
  • Safeguards, access controls, audit information, and training
  • Security-incident and breach cooperation duties
  • Required subcontractor safeguards and any agreed geographic processing limits
  • Return, destruction, retention exceptions, and termination assistance

Map KOKO data retention and deletion

Check privacy and breach duties beyond HIPAA

A statement that HIPAA does not apply is not the end of the analysis. The FTC's Health Breach Notification Rule addresses certain vendors of personal health records, PHR-related entities, and service providers that are not covered by HIPAA. The FTC explains that its 2024 amendments clarify application to health apps, connected devices, and similar technologies when the rule's definitions are met. State privacy, consumer-protection, biometric, health-data, and breach laws may also apply.

Do not describe KOKO or Homebot One as covered by a particular rule without facts about the product, data, relationships, location, and use. Ask qualified counsel or the responsible compliance team to document the analysis. Regardless of the legal label, request data minimization, clear permission, purpose limits, secure access, retention limits, incident contacts, and a way for the person at home to understand and control sharing.

Set consent and control rules around children and guests

Plan a response to a suspected cybersecurity incident

Make the pilot prove both care value and data governance

Before a pilot, create two linked plans. The routine plan states what KOKO is expected to do, what it will not do, when a human intervenes, and how the resident controls participation. The data plan states which information is allowed, which is prohibited, who can see it, how long it is retained, and which agreements and notices apply. Do not expand one plan without reviewing the other.

Test the controls with low-risk sample information before real care data is introduced. Verify account roles, consent withdrawal, support access, export, deletion, incident escalation, and the manual alternative when the system is unavailable. Record the exact build and service configuration. At the decision point, evaluate whether the observed benefit justifies the complete operational and compliance burden rather than assuming a care label settles either question.

  • Named resident, care, privacy, security, clinical, and vendor owners
  • Approved routine and explicit prohibited uses
  • Applicable agreements, notices, and evidence
  • Human fallback and emergency-service boundary
  • Stop conditions and end-of-pilot data actions

Set account responsibilities before a Care trial

Review the KOKO price and value buyer hub

Frequently asked questions

Is KOKO Care automatically covered by HIPAA?

No conclusion follows from the word care alone. HIPAA applicability depends on the entities, relationships, information, and actions in a specific deployment. The responsible organization should document that analysis.

Does a care organization always need a business associate agreement with a robot vendor?

Not always. Review whether the vendor performs services involving PHI on behalf of a covered entity or business associate. HHS also says a cloud provider maintaining encrypted electronic PHI can be a business associate even when it lacks the decryption key.

Can other health-data rules matter when HIPAA does not apply?

Yes. Depending on the facts, the FTC Health Breach Notification Rule and state privacy, health-data, biometric, consumer-protection, or breach laws may require review.

Is KOKO Care a replacement for professional care or emergency services?

No. Homebot One's official KOKO Care page states that KOKO Care is not a medical device and does not replace professional care, emergency services, or human judgment.

Sources & further reading

  1. KOKO Care: Official development, consent, and care-boundary information (opens in a new tab)
  2. HHS: Covered Entities and Business Associates (opens in a new tab)
  3. HHS: Is a Software Vendor a Business Associate? (opens in a new tab)
  4. HHS: Guidance on HIPAA and Cloud Computing (opens in a new tab)
  5. FTC: Complying with the Health Breach Notification Rule (opens in a new tab)

From Homebot One, the team building KOKO in Fremont, California.