HIPAA compliance isn't optional for physical therapy practices — and it's not just about avoiding fines. Done properly, a HIPAA compliance programme protects your patients, your staff, and your practice from the growing threat of healthcare data breaches. Yet for many independent and small-group PT clinics, HIPAA compliance remains a confusing patchwork of policies and procedures that haven't been reviewed since the practice opened.
This checklist covers the core requirements the Office for Civil Rights (OCR) looks for during audits, written specifically for outpatient PT practices.
OCR resolution agreements and civil monetary penalties for HIPAA violations have increased significantly since 2023. The average settlement for a small provider breach now exceeds ,000 — often for failures that are entirely preventable.
Privacy Rule Requirements
The Privacy Rule governs how Protected Health Information (PHI) is used and disclosed. For a PT clinic, the core requirements are:
- Notice of Privacy Practices (NPP) — You must provide patients with a written NPP at first visit and have them acknowledge receipt. Your NPP must describe how you use PHI, patient rights, and your complaint process. Update it whenever your practices change materially.
- Minimum Necessary Standard — Only access and share the minimum PHI required for the specific purpose. A front desk coordinator scheduling appointments does not need access to full clinical notes.
- Patient Access Rights — Patients have the right to access their own PHI within 30 days of request (15 days if the records are electronic). You must have a documented process for handling these requests.
- Authorisation for non-TPO disclosures — Disclosures outside treatment, payment, and healthcare operations (TPO) require written patient authorisation. This includes sharing records with personal trainers, employers, or attorneys without a court order.
Security Rule Requirements
The Security Rule applies to Electronic PHI (ePHI) — essentially anything stored or transmitted digitally. For a modern PT clinic using an EHR, this covers almost everything.
Administrative Safeguards
- Designate a HIPAA Security Officer (can be the practice owner in a small clinic)
- Conduct and document a Risk Analysis — identify where ePHI lives and what threats exist
- Implement a Risk Management plan based on the analysis
- Train all workforce members with access to ePHI on security policies — document the training
- Establish workforce sanction policies for HIPAA violations
Physical Safeguards
- Workstation use policies — screens should not be visible to patients in waiting areas
- Workstation security — lock screens when unattended, use cable locks for portable devices
- Device and media controls — documented process for disposing of hardware that stored ePHI
Technical Safeguards
- Unique user credentials — no shared logins for EHR or billing systems
- Automatic logoff after periods of inactivity
- Audit controls — your EHR should log who accessed what records and when
- Encryption — ePHI must be encrypted in transit (TLS) and at rest (AES-256)
- Emergency access procedures — a documented process for accessing ePHI in the event of system failure
Business Associate Agreements (BAAs)
Any vendor that creates, receives, maintains, or transmits ePHI on your behalf is a Business Associate and must sign a BAA before you share any PHI with them. This includes:
- Your EHR / practice management system provider
- Billing services and clearinghouses
- Cloud storage providers (Google Drive, Dropbox — only if PHI is stored there)
- Transcription or AI documentation services
- IT support companies with remote access to systems containing ePHI
- Answering services that receive patient messages
Many small practices assume their EHR vendor handles HIPAA compliance for them. They don't — they handle their part. You are responsible for your practice's compliance, including having a signed BAA with every applicable vendor.
Breach Notification
If a breach of unsecured PHI occurs, you must notify affected individuals within 60 days, notify HHS, and — if the breach affects 500 or more individuals in a state — notify prominent media outlets in that state. Document all breach incidents, even those that turn out not to be reportable, as OCR may request this documentation during an audit.
Documentation
HIPAA requires that you retain all policies, procedures, and documentation of compliance activities for a minimum of 6 years. In an audit, OCR will ask for written evidence — not just verbal assurance — that your safeguards are in place and operating. A folder of Word documents updated two weeks before an audit is not adequate. Ongoing, dated documentation is.
Working With a HIPAA-Compliant EHR
Choosing an EHR that handles the technical and physical safeguards — encryption, audit logs, automatic logoff, role-based access control — dramatically reduces your compliance burden. Cowboy Systems is designed to satisfy the technical requirements of the HIPAA Security Rule out of the box, and includes a standard Business Associate Agreement for all plans. Your responsibility remains the administrative safeguards: policies, training, and risk assessments.
See Cowboy Systems in action
Book a personalised demo and see how Cowboy Systems fits your practice.
Book a Demo