Are chiropractic offices required to comply with HIPAA?
Yes. Chiropractic practices that transmit health information electronically — including insurance claims, appointment scheduling, and patient records — are covered entities under HIPAA. This includes virtually every modern chiropractic practice.
How does HIPAA apply to chiropractic X-rays?
X-ray images are ePHI under HIPAA. They must be encrypted during transmission, stored with access controls, and shared only with vendors who have signed BAAs. This applies to digital imaging systems, external radiology services, and any cloud storage used for imaging data.
Do multi-location chiropractic practices need separate compliance programs?
Each location needs its own risk assessment and documented controls, but policies can be centrally managed. Patient Protect supports multi-location practices with unified policy management and per-site compliance tracking from a single account.
What does HIPAA compliance cost for a chiropractic practice?
Compliance consultants charge $3,000–$7,000 per year for chiropractic practices, with additional fees for multi-location setups. Patient Protect starts at $39/month ($468/year) per practice with no contracts, covering risk assessments, policy management, BAA tracking, and staff training.
Are chiropractic practices subject to Medicare HIPAA enforcement?
Yes. Chiropractors enrolled in Medicare Part B for spinal manipulation are subject to HIPAA enforcement at the standard tier. Medicare also conducts its own provider audits that often surface HIPAA-adjacent documentation gaps — incomplete treatment plans, missing diagnosis specificity, inadequate audit logging on PHI access. The two enforcement frameworks compound rather than substitute.
Do chiropractic practices that don't bill insurance still need HIPAA compliance?
It depends on the transactions, not on whether anything moves electronically. A chiropractic practice is a covered entity under §160.103 when it conducts an adopted standard transaction — an electronic claim, eligibility check, prior authorization, claim status inquiry, or remittance — or has a billing service conduct one for it. Electronic referrals and records-sharing with another treating provider are not themselves adopted transactions. A genuinely cash-only practice that never bills electronically may fall outside HIPAA, though state medical-privacy and consumer-health laws can still govern the same records, and most practices discover a payer-facing transaction somewhere once they look.
How are supplement and wellness product sales treated under HIPAA?
If the practice maintains records linking patients to supplement purchases — for clinical follow-up, insurance reimbursement, or patient-history purposes — those records are PHI. Pure retail-style sales without patient-record linkage are not. The practical line for most chiropractic practices: any product sold in connection with a treatment recommendation is part of the medical record, and the records system handling those sales is subject to HIPAA.
Does a chiropractic practice have to complete a HIPAA Security Risk Analysis?
Yes, and it must represent every location. Every covered practice must conduct and document an accurate, thorough assessment of the risks affecting all its ePHI. For a chiropractic practice that means the EHR, digital X-ray and imaging systems, every workstation in every adjusting bay and at every front desk, claims and clearinghouse workflows, workers' compensation and personal-injury documentation, patient portals and intake forms, any supplement or ancillary-service system that ties activity to identifiable patients, and remote IT support. One organization-wide analysis can cover multiple offices, but every location has to appear in the scope and in the findings.
Which of our chiropractic vendors need Business Associate Agreements?
Any organization performing a function involving PHI on the practice's behalf — the EHR or practice-management vendor, imaging software and storage, billing company, claims clearinghouse, cloud backup, remote IT support, appointment-reminder service, and patient-communication platform. Referring physicians, imaging centers, and other treating providers generally are not business associates; HHS treats provider-to-provider treatment disclosures as a different relationship. Attorneys, employers, and workers' compensation carriers are not business associates either — those are disclosures governed by authorization and state law, not by BAA. Classify before you paper.
How do we protect privacy in an open adjusting area?
HIPAA does not require private treatment rooms. It requires reasonable safeguards, and it explicitly tolerates incidental disclosures that occur despite them. What that means operationally in an open bay: position screens so they are not readable from adjacent tables, lower your voice for clinical discussion, avoid discussing one patient's condition where the next is waiting, keep sign-in sheets limited to name only, and move any conversation involving diagnosis, payment disputes, or sensitive history to a private space. Document the safeguards you chose and why in the risk analysis. An open floor plan is a design decision the practice can defend; an undocumented one is not.
Is the government's Security Risk Assessment Tool mandatory?
No. The government's SRA Tool is one method designed to help small and medium-sized organizations perform the required analysis. HIPAA requires the underlying risk analysis — not the use of one particular tool. Patient Protect provides its own guided SRA and connects the findings directly to remediation, policies, tasks, and documentation.
Does our EHR make the practice HIPAA compliant?
No. An EHR may provide important safeguards for the records it maintains, but it does not conduct the practice's complete SRA, remediate every identified risk, train the workforce, manage all policies, identify every Business Associate, prepare the practice for incidents, or preserve the full body of compliance evidence.
How much does Patient Protect cost for a chiropractic practice?
Patient Protect Basic costs $39 per office per month and includes up to 25 personnel. It includes the guided Security Risk Analysis, risk management, policies, workforce training, workforce and vendor management, BAA tracking, compliance scoring, and centralized documentation needed to operate the practice's core HIPAA compliance program.