It is a different purchase from rostering and call monitoring, from care management software with eMAR, and from a family portal, and most agencies need it most where they have bought it least. This guide sets out what to require of any tool, whoever makes it.
What a home care communication app is, and what it is not
A home care communication app is a messaging tool for the people who deliver and organise care in other people's homes: care workers between visits, coordinators planning the next run, and the manager on call at night. The rule that makes the choice matter is Regulation 17(2) of the Health and Social Care Act 2008 (Regulated Activities) Regulations 2014, which requires a registered provider to “maintain securely an accurate, complete and contemporaneous record in respect of each service user” and “such other records as are necessary to be kept in relation to” the “persons employed in the carrying on of the regulated activity” and “the management of the regulated activity”. CQC's guidance on what good digital social care records look like says Regulation 17 “applies to paper and digital records”, and that CQC does “not endorse or recommend a specific digital social care record system” – the provider must “assure yourself” that any system it uses “enables you to meet the regulations”.
Search results for this phrase mix four different products, and an agency comparing them against each other wastes everyone's time:
- Rostering and electronic call monitoring: the visit schedule, travel, and the check-in and check-out data a commissioner may require.
- Care management software: assessments, care plans, visit notes and, in most products, an eMAR for medicines. This is the care record.
- Family portals: a view for relatives of visits and notes, with the person's consent.
- Staff messaging: the conversation between care workers, the office and on-call managers – the subject of this guide.
Several care management products include messaging features in their mobile app, and for some care teams that is enough. The test in the rest of this guide applies whichever kind of product carries the messages, including the consumer app most teams use today.
What home care messages carry
Home care runs on messages because nobody is in the same place. A care home's staff talk at the nurses' station; a home care team's equivalent is a phone. In a typical week the messages include:
- Visit changes: a hospital discharge moved to today, a cancelled call, a double-up visit that needs a second worker in twenty minutes.
- Escalations: no answer at the door, a person found on the floor, a refused medicine, a missed visit reported by a daughter.
- Health information: a photograph of a pressure area, a change in someone's breathing, a query about a dose.
- Safeguarding concerns: a bruise, a new “friend” collecting the pension, a relative asking a worker to withdraw cash.
- Welfare: a worker running late on a dark lane, a car that will not start, an aggressive visitor at an address.
- Shift cover and handover between the day and evening runs, and between the office and the on-call manager.
- Families: a son sending updates about his mother to the regular care worker's personal number, or asking her to pass a message to the office – the agency's conversation too, held on a phone it does not control.
Almost every item on that list is a record of something the provider must be able to account for later – to a family, to a local authority safeguarding enquiry, to CQC or to a court. Several are personal data about the person receiving care that the provider, as controller, is responsible for wherever it is held. The question is not whether these messages exist; it is whether the provider holds them.
Requirement one: the messages are records the provider keeps
The care record still belongs in the care management system: what was done on a visit, the medicines given, the decision taken. A message is not a substitute for writing it up. But the message is evidence of when something was known and what was said, and a provider that cannot produce it is relying on recollection. Ask any supplier, in writing:
- Where is the record made? A record captured on the provider's side as each message is sent survives a lost, broken or wiped phone; a record that depends on collecting handsets afterwards fails exactly when it is needed.
- Who controls membership? When a care worker leaves, the provider should be able to remove them on the same day, and the history should stay with the provider rather than leave on the worker's phone.
- Who sets retention? The provider's retention schedule, not the app's default, should decide how long messages are kept, and the provider should be able to export or disclose them for a subject access request, a complaint or an enquiry.
- Can a message be changed or deleted without trace? An edit history and a deletion record matter for anything that may become evidence.
- What happens if we stop paying? Ask before signing how the record is returned, in what format, and how long the supplier keeps it.
- Is everyone told? Staff accept a work channel that is on the record when they are told plainly at the start; a channel that is quietly kept is a different thing and damages trust.
Then decide the rule that links the two systems: anything that belongs in the care record – a refused medicine, a fall, a safeguarding concern – is entered there by the worker or the office, and the message stays as the contemporaneous evidence of how it was first reported.
Requirement two: UK GDPR, the DSPT and personal phones
Health information about the people receiving care is special category data under Article 9 of the UK GDPR, and the provider is the controller for it in any work messaging tool. A supplier that hosts the messages is a processor, and Article 28 of the UK GDPR requires a written contract that sets out what it may do with the data, its security, its sub-processors, and deletion or return at the end. Read the sub-processor list and where each one processes data, not just the headline about where messages are stored.
Do a data protection impact assessment before rolling a tool out. The ICO's guidance on when to do a DPIA lists indicators of high risk that include “sensitive data or data of a highly personal nature” and “data concerning vulnerable data subjects”, and says “in most cases, a combination of two of these factors indicates the need for a DPIA”. A home care messaging tool has both. The DPIA is also where the provider records its decisions about photographs, retention and personal devices.
If the agency has access to NHS patient data or systems, it is also within the NHS Data Security and Protection Toolkit, whose site says “all organisations that have access to NHS patient data and systems must use this toolkit”. The toolkit is a self-assessment against the National Data Guardian's 10 data security standards, so a new messaging tool needs to fit the answers the agency has already given in it.
Personal phones are the practical reality: most care workers will not carry a second device, and the agency's policy should say so honestly rather than pretend. Require a tool that keeps work messages separate from the worker's own apps, can be signed out and its data removed from a phone when the worker leaves, uses a passcode or biometric lock, and does not leave photographs of the people receiving care in the phone's own camera roll or open to sharing into other apps.

Requirement three: reaching a lone worker, and being reached
The HSE's guidance on protecting lone workers says “as an employer, you must manage any health and safety risks before people can work alone”, and that “there will always be greater risks for lone workers without direct supervision or anyone to help them if things go wrong”. Messaging is part of how a home care agency meets that duty, so test a tool against the lone-working arrangements in the agency's own policy, not against a demonstration in the office.
- Does it work where your workers work? Rural lanes, blocks of flats and basements with poor signal. Try it on a real run.
- Can the on-call manager see who needs help, and act at 11pm? Escalation that depends on one coordinator's personal phone fails when she is asleep or on leave.
- Can bank and agency workers, and where the person agrees, family carers, be included on day one without a work email account? If the tool's identity is a corporate account, the people most likely to need help on an unfamiliar run are the ones left out.
- Is it simple enough to use in gloves, in a hurry, in a stranger's hallway? Pilot it with the least confident user on the team, not the manager.
- Is it a lone-worker alarm? Usually not. A messaging app does not replace a dedicated check-in or personal alarm system where the risk assessment calls for one, or calling 999 in an emergency.
Finally, ask what happens to the existing group. The tool that replaces a consumer chat has to be at least as easy, or the old group comes back within a month and the agency ends up with two.
Where ComplyChat is, and is not, the answer
Start with where it is not. ComplyChat does no rostering, call monitoring, care planning or eMAR, and it is not a family portal. It does not replace the care management system, the visit notes or a lone-worker alarm, and a message in it is not a safeguarding referral. If your care management software already includes messaging that every worker uses, and nothing in those conversations needs to be kept beyond what that system keeps, you may not need anything else.
The gap it is built for is the conversation that currently happens on personal phones because there is nowhere better: the coordinator's group chat, the text to the on-call manager, the message from a bank worker who has no account on any of your systems. In ComplyChat a mobile number verified by SMS is the identity, so bank and agency staff can be added without a work account; everyone added to a channel is told it is on the record and can object or leave; and messages are recorded on the server as they are sent, not gathered from handsets afterwards. Messages are stored and processed in the UK, and the supporting services that may process data elsewhere, such as the SMS verification code and push notifications, are named on the published sub-processor list. On paid plans, once the agency's Microsoft 365 tenant is connected, the lasting record files there under the agency's own retention rules. The Free plan has one private group, direct messages, up to 25 staff and three calendar months of recent history, with no Microsoft 365 archive, so it suits trying the tool, not keeping the record.
Whatever you choose, the question for the next management meeting is the same: when a care worker messages tonight that nobody is answering the door, where does that message land, and could the agency produce it next year?
Questions people ask
What is a home care communication app?
A home care communication app is a messaging tool that connects care workers on visits with the office, the on-call manager and each other. It is separate from rostering and call monitoring, from care management software that holds the care plan and visit notes, and from a family portal, although some products combine more than one of these.
Can home care workers use WhatsApp for work?
No law names a messaging app, but the provider remains responsible for what is said in it: Regulation 17 requires records to be maintained securely, and the provider is the UK GDPR controller for health information about the people it supports, wherever it is held. A group on personal phones that the provider cannot control, search, retain or remove leavers from makes both duties hard to meet, which is why many agencies move work messaging to a tool they control.
Do home care providers need the Data Security and Protection Toolkit?
A home care provider must complete the Data Security and Protection Toolkit if it has access to NHS patient data or systems: the toolkit's website says “all organisations that have access to NHS patient data and systems must use this toolkit to provide assurance that they are practising good data security and that personal information is handled correctly”.
Do we need a DPIA for a staff messaging app?
A home care provider should expect to need one: the ICO says “in most cases, a combination of two of these factors indicates the need for a DPIA”, and its factors include sensitive data and data about vulnerable people, both of which home care messages carry. Where a provider decides a DPIA is not needed, the ICO says “you should document your reasons”.
Official guidance and your next step
Read CQC's guidance on Regulation 17 and its guidance on good digital social care records; the ICO's guidance on DPIAs and special category data; the Data Security and Protection Toolkit if the agency handles NHS data; and the HSE's lone working guidance. CQC also points providers to the Digitising Social Care programme for resources on choosing a digital social care record system.
This is a buying guide for providers in England, not legal advice, and not an assessment of any particular product.
Then do one thing: ask three care workers to show you, on their own phones, where they sent the last message about a person they support. That is your current communication system, and the starting point for whatever replaces it.
We build ComplyChat for the work conversations organisations need to keep, and in home care those are the messages between lone workers and the office. We wrote this guide so an agency can judge any tool, including ours, against what its duties actually require – and so the parts of home care that ComplyChat does not do are clear before anyone asks.
Sources
Every document this guide quotes or links to, in the order it first cites them.
- Health and Social Care Act 2008 (Regulated Activities) Regulations 2014 legislation.gov.uk
- What good digital social care records look like cqc.org.uk
- Article 9 of the UK GDPR legislation.gov.uk
- Article 28 of the UK GDPR legislation.gov.uk
- When to do a DPIA ico.org.uk
- Data Security and Protection Toolkit dsptoolkit.nhs.uk
- Protecting lone workers hse.gov.uk
- CQC's guidance on Regulation 17 cqc.org.uk




