Skip to main content
Patient Protect circular logo mark in purple and white used for site navigationPatient Protect

HIPAA Compliance for Chiropractors

The HIPAA compliance and security operating system for chiropractic practices. High patient volume, digital X-ray, open adjusting bays, workers' compensation, and multiple locations each open a different path to exposure. Patient Protect runs the risk analysis across every site and system, manages policies, training, and vendor agreements, and keeps the proof in one place.

What HIPAA actually looks like for chiropractic practices.

The regulatory framework, the enforcement patterns OCR has historically cited, the non-HIPAA standards that apply, the gaps audits routinely surface, and the record-retention overlay — HIPAA’s six-year rule for compliance documentation, and the separate state law that governs how long clinical records must be kept.

Regulatory framework

Chiropractic practices operate under HIPAA as covered entities through standard electronic transactions — claims submission to Medicare Part B (for spinal manipulation services), private payers, and electronic eligibility verification. Medicare imposes additional documentation requirements for reimbursement of chiropractic adjustments, including subluxation diagnosis specificity, treatment plan progression, and periodic reassessment. State chiropractic practice acts and state chiropractic boards govern record-keeping standards. Some states permit chiropractors to dispense supplements or perform manipulation under anesthesia, each adding compliance overlay specific to those services.

OCR enforcement patterns

OCR's chiropractic enforcement record is smaller than for medical or dental practices, but published cases have included unencrypted device theft, unauthorized access by former employees, and breach response failures. Medicare audits of chiropractic practices frequently surface HIPAA-adjacent documentation gaps — incomplete treatment plans, missing diagnosis specificity, inadequate audit logging on patient record access — that compound into HIPAA exposure when patient records cannot be produced as required.

Standards beyond HIPAA

Medicare Local Coverage Determinations for chiropractic services impose specific documentation requirements that interact with HIPAA's record-retention and access rules. ACA HCPCS coding for chiropractic services. State-specific rules on manipulation under anesthesia (where permitted). DEA registration where the chiropractor holds dual licensure permitting prescribing. State pharmacy board rules where supplement dispensary or other adjunctive therapies involve regulated substances.

Common compliance gaps

Routinely surfaced in chiropractic practice reviews: missing BAAs with imaging system vendors (chiropractic X-ray equipment commonly stores images on practice servers and transmits to specialists without explicit BAA infrastructure), supplement-tracking and wellness-product systems that link patients to purchases and aren't accounted for in the risk analysis, missing or stale BAAs with electronic claims clearinghouses, dual-role practitioner credential separation issues for chiropractors who also hold acupuncture or nutrition counseling licensure, and inadequate documentation of Medicare Part B compliance procedures.

Compliance documentation, then state record law.

HIPAA's six-year rule governs compliance documentation, not clinical records (§164.530(j)). State chiropractic acts govern patient record retention — typically seven to ten years post-last-encounter. Medicare requires retention of treatment plans and supporting documentation for ongoing-care evidence — typically the duration of the patient relationship plus a multi-year tail. State malpractice tail coverage may require longer retention as a condition of coverage. X-ray imaging is often subject to separate retention requirements under state radiation-safety regulations.

Reference summary, not legal advice. This page summarizes how HIPAA and adjacent regulatory frameworks apply to chiropractic practices based on Patient Protect’s reading of the relevant CFR provisions, OCR enforcement record, and state statutes. Operators with specific compliance questions should consult a qualified HIPAA attorney. Patient Protect is a HIPAA compliance platform; we are not a law firm and do not provide legal advice.

Where chiropractic practices are most exposed.

X-ray and imaging systems create untracked ePHI exposure

Chiropractic X-rays move between operatories, external imaging centers, and referring physicians. Each transfer point is a potential breach if the data isn't encrypted and the vendor doesn't have a signed BAA. Most practices don't audit these data flows.

Multi-location practices multiply compliance gaps

Each office location needs its own access controls, workforce training documentation, and risk assessment. Sharing a single compliance checklist across locations doesn't satisfy HIPAA — and OCR audits each site independently.

No dedicated IT staff to monitor for threats

Most chiropractic offices rely on a local IT contractor or the front desk for technology decisions. Ransomware, phishing, and credential theft target exactly these under-resourced practices. Without monitoring, breaches take months to detect and contain.

OIG scrutiny adds compliance pressure beyond HIPAA

Chiropractic practices face heightened OIG attention for documentation and billing patterns. While distinct from HIPAA, audit exposure compounds — an OIG investigation can trigger HIPAA scrutiny of records handling, access controls, and patient data security.

Built for chiropractic practices, not hospital systems.

Multi-location compliance management

Manage risk assessments, policies, and training across all practice locations from a single dashboard. Each site maintains compliant documentation independently.

Vendor BAA tracking

Track agreements with imaging labs, EHR vendors, billing services, and IT contractors. Expiration alerts ensure no agreement lapses without notice.

Staff training with completion tracking

Deliver HIPAA training to staff across all locations. Track completion per employee with audit-ready documentation — no spreadsheets or paper sign-off sheets.

Real-time compliance scoring

See your practice's compliance standing across all locations. Identify which site has the most exposure and prioritize remediation before an audit, not during one.

X-ray imaging and DICOM compliance for chiropractic operations

Chiropractic X-rays follow the same DICOM standard as medical imaging and carry the same PHI exposure. The risk analysis covers chiropractic imaging systems, imaging-software BAAs, and the access controls that keep diagnostic images compliant under §164.312.

Medicare Part B documentation for chiropractic adjustments

Manual manipulation of the spine for subluxation correction is reimbursable under Medicare Part B with specific documentation requirements. Patient Protect's policy generation produces the documentation framework Medicare auditors expect — diagnosis specificity, treatment-plan progression, periodic reassessment notes — without which Part B claims are vulnerable to clawback.

State-specific HIPAA rules for chiropractic practices.

HIPAA is federal — but your state layers additional breach notification deadlines, AG reporting requirements, and privacy laws on top. Select your state to see what applies to your practice.

District of Columbia compliance requirements for chiropractic practices

In addition to federal HIPAA requirements, chiropractic practices operating in District of Columbia must comply with the following state-specific obligations.

Breach notification deadline

In the most expedient time possible and without unreasonable delay, subject to the needs of law enforcement and any measures necessary to determine the scope of the breach and restore the reasonable integrity of the data system.

The statute does not fix a numeric outer bound. Unreasonable delay is itself a violation and may result in state enforcement action, so treat the operative timeframe as the shortest window your incident circumstances reasonably support.

Attorney General notification

Required for all breaches

Your practice must notify the state AG in addition to affected patients and HHS.

District of Columbia-specific laws & requirements

DC uses the New-York pattern: HIPAA covers individual notice, but AG notice is independent

For HIPAA-regulated entities operating in DC, satisfying HIPAA breach-notification obligations to individuals is deemed to satisfy the § 28-3852 individual-notice requirement under subsection (g). But the separate DC Attorney General notification obligation under § 28-3852(b-1) is triggered independently once a breach affects 50 or more DC residents, and HIPAA compliance does not substitute for that AG notice. Practices notifying HHS under HIPAA still owe a separate written AG notice to DC.

Source: D.C. Code § 28-3852(a)

Verified against primary state authority as of August 2026. General reference — consult legal counsel for your specific obligations.

Primary sources: code.dccouncil.gov · oag.dc.gov

What happens after the paperwork is done.

Every major compliance platform covers risk assessments and policy templates. This is the part that differs.

What to ask

Patient Protect

01

Risk assessment that satisfies §164.308(a)(1)

A readiness quiz is not a risk analysis.

Full SRA wizard mapped to NIST CSF with live scoring

02

Auto-generated policies with workforce acknowledgment

HIPAA requires documented proof your staff reviewed them.

48 policies from your risk profile, versioned acknowledgment

03

Staff training with delivery tracking

§164.308(a)(5) — sending a PDF is not sufficient.

HIPAA Foundations — 19 modules, 95 assessment questions, verifiable certificates

04

Full BAA lifecycle management

Expired BAAs are a top enforcement target.

E-signature, renewal alerts, Vendor Risk Scanner

Yes on all 10. Now run the checklist on the rest.

From $39/mo · No long-term contracts.

Enterprise-grade compliance. Independent-practice pricing.

No contracts · No setup fees · Cancel anytime

Basic

$39/mo

Risk assessments, policies, BAA management, training, and compliance scoring.

Recommended

Pro

$99/mo

Everything in Basic plus secure messaging, breach intelligence, live diagnostics, and AI compliance assistant.

See full feature comparison →

Common questions about HIPAA compliance for chiropractic practices.

Are chiropractic offices required to comply with HIPAA?

Yes. Chiropractic practices that transmit health information electronically — including insurance claims, appointment scheduling, and patient records — are covered entities under HIPAA. This includes virtually every modern chiropractic practice.

How does HIPAA apply to chiropractic X-rays?

X-ray images are ePHI under HIPAA. They must be encrypted during transmission, stored with access controls, and shared only with vendors who have signed BAAs. This applies to digital imaging systems, external radiology services, and any cloud storage used for imaging data.

Do multi-location chiropractic practices need separate compliance programs?

Each location needs its own risk assessment and documented controls, but policies can be centrally managed. Patient Protect supports multi-location practices with unified policy management and per-site compliance tracking from a single account.

What does HIPAA compliance cost for a chiropractic practice?

Compliance consultants charge $3,000–$7,000 per year for chiropractic practices, with additional fees for multi-location setups. Patient Protect starts at $39/month ($468/year) per practice with no contracts, covering risk assessments, policy management, BAA tracking, and staff training.

Are chiropractic practices subject to Medicare HIPAA enforcement?

Yes. Chiropractors enrolled in Medicare Part B for spinal manipulation are subject to HIPAA enforcement at the standard tier. Medicare also conducts its own provider audits that often surface HIPAA-adjacent documentation gaps — incomplete treatment plans, missing diagnosis specificity, inadequate audit logging on PHI access. The two enforcement frameworks compound rather than substitute.

Do chiropractic practices that don't bill insurance still need HIPAA compliance?

It depends on the transactions, not on whether anything moves electronically. A chiropractic practice is a covered entity under §160.103 when it conducts an adopted standard transaction — an electronic claim, eligibility check, prior authorization, claim status inquiry, or remittance — or has a billing service conduct one for it. Electronic referrals and records-sharing with another treating provider are not themselves adopted transactions. A genuinely cash-only practice that never bills electronically may fall outside HIPAA, though state medical-privacy and consumer-health laws can still govern the same records, and most practices discover a payer-facing transaction somewhere once they look.

How are supplement and wellness product sales treated under HIPAA?

If the practice maintains records linking patients to supplement purchases — for clinical follow-up, insurance reimbursement, or patient-history purposes — those records are PHI. Pure retail-style sales without patient-record linkage are not. The practical line for most chiropractic practices: any product sold in connection with a treatment recommendation is part of the medical record, and the records system handling those sales is subject to HIPAA.

Does a chiropractic practice have to complete a HIPAA Security Risk Analysis?

Yes, and it must represent every location. Every covered practice must conduct and document an accurate, thorough assessment of the risks affecting all its ePHI. For a chiropractic practice that means the EHR, digital X-ray and imaging systems, every workstation in every adjusting bay and at every front desk, claims and clearinghouse workflows, workers' compensation and personal-injury documentation, patient portals and intake forms, any supplement or ancillary-service system that ties activity to identifiable patients, and remote IT support. One organization-wide analysis can cover multiple offices, but every location has to appear in the scope and in the findings.

Which of our chiropractic vendors need Business Associate Agreements?

Any organization performing a function involving PHI on the practice's behalf — the EHR or practice-management vendor, imaging software and storage, billing company, claims clearinghouse, cloud backup, remote IT support, appointment-reminder service, and patient-communication platform. Referring physicians, imaging centers, and other treating providers generally are not business associates; HHS treats provider-to-provider treatment disclosures as a different relationship. Attorneys, employers, and workers' compensation carriers are not business associates either — those are disclosures governed by authorization and state law, not by BAA. Classify before you paper.

How do we protect privacy in an open adjusting area?

HIPAA does not require private treatment rooms. It requires reasonable safeguards, and it explicitly tolerates incidental disclosures that occur despite them. What that means operationally in an open bay: position screens so they are not readable from adjacent tables, lower your voice for clinical discussion, avoid discussing one patient's condition where the next is waiting, keep sign-in sheets limited to name only, and move any conversation involving diagnosis, payment disputes, or sensitive history to a private space. Document the safeguards you chose and why in the risk analysis. An open floor plan is a design decision the practice can defend; an undocumented one is not.

Is the government's Security Risk Assessment Tool mandatory?

No. The government's SRA Tool is one method designed to help small and medium-sized organizations perform the required analysis. HIPAA requires the underlying risk analysis — not the use of one particular tool. Patient Protect provides its own guided SRA and connects the findings directly to remediation, policies, tasks, and documentation.

Does our EHR make the practice HIPAA compliant?

No. An EHR may provide important safeguards for the records it maintains, but it does not conduct the practice's complete SRA, remediate every identified risk, train the workforce, manage all policies, identify every Business Associate, prepare the practice for incidents, or preserve the full body of compliance evidence.

How much does Patient Protect cost for a chiropractic practice?

Patient Protect Basic costs $39 per office per month and includes up to 25 personnel. It includes the guided Security Risk Analysis, risk management, policies, workforce training, workforce and vendor management, BAA tracking, compliance scoring, and centralized documentation needed to operate the practice's core HIPAA compliance program.

Patient Protect is intuitive, proactive, and affordable — exactly what small clinics like ours need to keep patient data safe and stay on the right side of HIPAA.
Dr. Thomas E Murray, D.D.S.Patient Protect Member Since 2017

Your chiropractic practice carries the same HIPAA burden as a hospital.

See where your compliance stands today. Free risk assessment — no login required.

Or explore the full HIPAA compliance software comparison or all HIPAA compliance solutions