HIPAA Compliance for Small PT Clinics: A Practical Checklist

HIPAA compliance isn't optional for physical therapy practices — and it's not just about avoiding fines. Done properly, a HIPAA compliance programme protects your patients, your staff, and your practice from the growing threat of healthcare data breaches. Yet for many independent and small-group PT clinics, HIPAA compliance remains a confusing patchwork of policies and procedures that haven't been reviewed since the practice opened.

This checklist covers the core requirements the Office for Civil Rights (OCR) looks for during audits, written specifically for outpatient PT practices.

OCR resolution agreements and civil monetary penalties for HIPAA violations have increased significantly since 2023. The average settlement for a small provider breach now exceeds ,000 — often for failures that are entirely preventable.

Privacy Rule Requirements

The Privacy Rule governs how Protected Health Information (PHI) is used and disclosed. For a PT clinic, the core requirements are:

Security Rule Requirements

The Security Rule applies to Electronic PHI (ePHI) — essentially anything stored or transmitted digitally. For a modern PT clinic using an EHR, this covers almost everything.

Administrative Safeguards

Physical Safeguards

Technical Safeguards

Business Associate Agreements (BAAs)

Any vendor that creates, receives, maintains, or transmits ePHI on your behalf is a Business Associate and must sign a BAA before you share any PHI with them. This includes:

Many small practices assume their EHR vendor handles HIPAA compliance for them. They don't — they handle their part. You are responsible for your practice's compliance, including having a signed BAA with every applicable vendor.

Breach Notification

If a breach of unsecured PHI occurs, you must notify affected individuals within 60 days, notify HHS, and — if the breach affects 500 or more individuals in a state — notify prominent media outlets in that state. Document all breach incidents, even those that turn out not to be reportable, as OCR may request this documentation during an audit.

Documentation

HIPAA requires that you retain all policies, procedures, and documentation of compliance activities for a minimum of 6 years. In an audit, OCR will ask for written evidence — not just verbal assurance — that your safeguards are in place and operating. A folder of Word documents updated two weeks before an audit is not adequate. Ongoing, dated documentation is.

Working With a HIPAA-Compliant EHR

Choosing an EHR that handles the technical and physical safeguards — encryption, audit logs, automatic logoff, role-based access control — dramatically reduces your compliance burden. Cowboy Systems is designed to satisfy the technical requirements of the HIPAA Security Rule out of the box, and includes a standard Business Associate Agreement for all plans. Your responsibility remains the administrative safeguards: policies, training, and risk assessments.

See Cowboy Systems in action

Book a personalised demo and see how Cowboy Systems fits your practice.

Book a Demo
© 2026 Cowboy Systems  ·  Blog  ·  Home