Skip to main content
Patient Protect circular logo mark in purple and white used for site navigationPatient Protect

HIPAA Compliance for Physical Therapists

The HIPAA compliance and security operating system for physical therapy practices. Treatment leaves the clinic — home visits, mobile documentation, progress photography, exercise platforms, and a rotating bench of PRN and contract clinicians. Patient Protect runs the risk analysis across every device and workflow, manages access, training, and vendor agreements, and preserves the record.

Physical therapy practices that electronically submit claims, check benefits, request authorization, or have those transactions conducted on their behalf are HIPAA covered entities. Once covered, the duties below are required across every location and workflow handling PHI.

HIPAA compliance is not optional for a covered physical therapy practice.

If your practice is a HIPAA covered entity, it is required to maintain an active, documented compliance program — and if it performs covered functions as a Business Associate, it must implement the Security Rule and every other duty attaching to that role. The responsibility does not transfer to your EHR, IT company, consultant, insurance carrier, or software provider. Those partners can support the work; your practice remains responsible for completing it.

Watching one training video is not a compliance program. Downloading a policy template is not a compliance program. Signing one BAA is not a compliance program. HIPAA requires your practice to implement, maintain, and document the complete operating system behind each of those activities.

Your practice is required to do all of the following

  1. 01Conduct and document a Security Risk Analysis

    Identify every place electronic protected health information enters, moves through, or leaves the practice. Assess the systems, devices, people, vendors, locations, workflows, threats, and vulnerabilities that could compromise that information.

    45 CFR §164.308(a)(1)(ii)(A)

  2. 02Manage the risks the analysis uncovers

    Turn identified risks into a documented remediation plan. Assign responsibility, prioritize the work, implement safeguards, and preserve evidence showing how the practice responded.

    45 CFR §164.308(a)(1)(ii)(B)

  3. 03Designate Privacy and Security Officials

    Assign and document who is responsible for developing, maintaining, and enforcing the practice's privacy and security program. In a small practice, one person may perform both roles — but the responsibilities must still be assigned and documented.

    45 CFR §164.530(a) · §164.308(a)(2)

  4. 04Maintain written policies and procedures

    Document how the practice protects patient information, controls access, handles permitted disclosures, responds to incidents, enforces workforce accountability, and maintains required privacy and security safeguards.

    45 CFR §164.316(a) · §164.530(i)

  5. 05Train the entire workforce

    Train workforce members on the privacy policies relevant to their roles and maintain an ongoing security-awareness program. Preserve records showing who was trained, what the training covered, and when it was completed.

    45 CFR §164.530(b) · §164.308(a)(5)

  6. 06Identify and govern every Business Associate

    Determine which vendors and service providers create, receive, maintain, or transmit protected health information on the practice's behalf. Execute the required Business Associate Agreement before protected information flows and maintain the agreement as part of the practice's compliance record.

    45 CFR §164.502(e) · §164.308(b) · §164.504(e)

  7. 07Implement administrative, physical, and technical safeguards

    Control who can access patient information, secure the systems and locations where it is maintained, review activity, authenticate users, protect data integrity, and safeguard electronic transmission.

    45 CFR §164.308 · §164.310 · §164.312

  8. 08Protect patient privacy rights

    Maintain the required notices, authorization processes, complaint procedures, and workflows for responding to patient requests involving access, amendments, confidential communications, restrictions, and applicable disclosure accounting.

    45 CFR §164.520 · §164.524 · §164.526 · §164.522 · §164.528

  9. 09Prepare for incidents, outages, and breaches

    Maintain security-incident procedures, data backup, disaster recovery, emergency operations, mitigation, and breach-notification processes before an event occurs.

    45 CFR §164.308(a)(6) · §164.308(a)(7) · Subpart D

  10. 10Preserve proof that the work was completed

    Retain the assessments, risk decisions, policies, training records, official designations, BAAs, acknowledgments, incident records, and other documentation needed to demonstrate what the practice actually did.

    45 CFR §164.316(b) · §164.530(j)

The Security Risk Analysis is where the work begins.

The Security Rule requires an accurate, thorough assessment of the risks and vulnerabilities affecting every form of electronic protected health information your practice creates, receives, maintains, or transmits. This is commonly called a Security Risk Analysis, or SRA.

The federal government publishes its own Security Risk Assessment Tool for small and medium-sized practices. You are not required to use that particular tool. You are required to perform and document the underlying analysis.

Patient Protect provides its own guided SRA. It walks the practice through the assessment in plain language, identifies what is missing, and carries those findings into risk management, remediation, policies, tasks, and documentation — so the assessment ends with the problem assigned and resolved, not merely named.

A five-minute readiness quiz is not an SRA. Reviewing only your EHR is not an SRA. Reusing an old checklist that no longer reflects your systems, vendors, workforce, or workflows is not an SRA.

That includes our own free tool. The Patient Protect Score is a free exposure scan and a starting point. It is not your completed Security Risk Analysis, and we will not tell you it is.

What a physical therapy practice’s Security Risk Analysis must cover

Physical therapy moves treatment beyond the exam room. Home visits, mobile documentation, progress photography, exercise platforms, temporary staffing, workers' compensation, and frequent communication all expand the practice's ePHI surface.

  • The EHR, scheduling, billing, claims, and patient-portal systems
  • Home-exercise and patient-engagement platforms that receive identifiable treatment information
  • Progress photos and videos — including how they are captured, uploaded, stored, accessed, retained, and removed from devices
  • Laptops, tablets, and phones used in the clinic, during home visits, or while staff work remotely
  • Telehealth, secure messaging, email, text, e-fax, referral, and care-coordination workflows
  • Workers' compensation, employer, insurer, case-manager, and attorney disclosure processes
  • Access granted to PRN, per-diem, temporary, contract, student, and former personnel

What the physical therapy compliance program must also address

  • Approved devices and storage for treatment photos and videos
  • Immediate access changes as rotating and temporary personnel enter or leave the practice
  • Business Associate governance for EHR, HEP, messaging, cloud, billing, and other service vendors
  • Written procedures distinguishing workers' compensation disclosures from attorney or employer requests requiring different authority
  • Training on mobile care, home visits, progress documentation, photography, and high-frequency disclosure requests

The practice remains responsible for ePHI when treatment leaves the clinic. Mobility changes the controls required; it does not change the obligation.

What HIPAA actually looks like for physical therapy practices.

The regulatory framework, the enforcement patterns OCR has historically cited, the non-HIPAA standards that apply, the gaps audits routinely surface, and the record-retention overlay — HIPAA’s six-year rule for compliance documentation, and the separate state law that governs how long clinical records must be kept.

Regulatory framework

Physical therapy practices operate under HIPAA as covered entities through standard electronic transactions — claims submission to Medicare Part B, private payers, workers' compensation systems, and eligibility verification. Medicare therapy services impose specific documentation requirements: plan of care signed by referring physician within 30 days, periodic reassessment, KX modifier and therapy-cap exception documentation, progress-note specificity. State physical therapy practice acts govern record-keeping. The ABPTS specialty board rules apply where the practice employs specialty-certified clinicians.

OCR enforcement patterns

OCR's PT enforcement record includes unauthorized record access by former employees, missing or expired BAAs with therapy-specific platforms (home exercise prescription, electronic claims), and disclosure errors involving workers' compensation and personal-injury attorneys. Progress photos synced to a personal cloud account are a recurring exposure — not because a brand name is inherently unlawful, but because a consumer account is unconfigured, uncovered by a BAA, and outside the practice's control. Medicare audits surface HIPAA-adjacent documentation gaps — missing referring-physician signatures, inadequate progress-note specificity — that compound into HIPAA exposure.

Standards beyond HIPAA

Medicare therapy cap exceptions and KX modifier documentation under §1833(g). Section 164.512(l) workers' compensation disclosure exception (state-specific implementation varies). Plan-of-care signature requirements under Medicare. State licensure board rules on direct-access vs referral-required care. State workers' compensation systems impose their own record-disclosure frameworks. Home exercise program (HEP) platforms are business associates when they receive PHI.

Common compliance gaps

Progress photos stored on consumer platforms or staff personal devices is the single highest-frequency compliance gap in PT practice. Other recurring gaps: missing referring-physician signatures on plans of care creating both Medicare and HIPAA documentation issues, undocumented disclosures to personal-injury attorneys (which require §164.508 authorization, not the §164.512(l) workers' comp exception), missing BAAs with HEP platforms and electronic claims clearinghouses, and inadequate audit logging on staff access to celebrity-patient or executive-patient records.

Compliance documentation, then state record law.

HIPAA's six-year rule governs compliance documentation, not clinical records (§164.530(j)). State PT board rules govern patient record retention — typically seven to ten years post-last-encounter. Medicare requires retention of plan-of-care and treatment documentation for the period of care plus a tail. Workers' compensation cases impose their own retention requirements under state law — typically the duration of the claim plus a multi-year period. Progress photos as part of the medical record are subject to the same retention as the rest of the record.

Reference summary, not legal advice. This page summarizes how HIPAA and adjacent regulatory frameworks apply to physical therapy practices based on Patient Protect’s reading of the relevant CFR provisions, OCR enforcement record, and state statutes. Operators with specific compliance questions should consult a qualified HIPAA attorney. Patient Protect is a HIPAA compliance platform; we are not a law firm and do not provide legal advice.

Where physical therapy practices are most exposed.

Referring physician data exchanges lack BAA coverage

PT practices receive referrals and send progress reports to physicians constantly. If these exchanges happen via unencrypted email, fax-to-email services, or patient portals without BAAs, every transmission is a potential HIPAA violation.

Workers' compensation records add disclosure complexity

Workers' comp cases involve employers, insurers, attorneys, and case managers — all requesting patient information. Knowing what you can disclose, to whom, and under what authorization is complex. One wrong disclosure is a violation.

Exercise and treatment documentation tools may not be compliant

Home exercise program apps, outcome tracking tools, and patient engagement platforms all handle ePHI. Many PT-specific tools lack BAAs, encryption, or proper access controls — and practices adopt them without compliance review.

High patient volumes mean high breach exposure

PT practices often see 30–50 patients per day across multiple therapists. Each patient interaction generates ePHI. The sheer volume of data handling amplifies every compliance gap — a single unsecured workflow affects thousands of records annually.

Built for physical therapy practices, not hospital systems.

Referral workflow compliance

Track BAAs with every referring physician and specialist. Secure messaging ensures clinical data stays encrypted end-to-end, replacing unsecured fax and email.

BAA management for PT vendors

Track agreements with EHR vendors, exercise platforms, billing services, and outcome tracking tools. Expiration alerts and e-sign keep everything current.

Workforce training for clinical staff

HIPAA training modules designed for PT practice workflows — high-volume patient handling, shared workstations, and multi-provider documentation. Completion tracked automatically.

Real-time compliance scoring

See your practice's compliance standing update as you close gaps. Prioritize the highest-risk items first. Know where you stand before an audit — not during one.

Plan-of-care documentation aligned with Medicare therapy requirements

Physical therapy plans of care under Medicare require physician signature within 30 days, periodic reassessment, and specific documentation of progression. Patient Protect's policy generation produces the documentation framework Medicare auditors expect — without which Part B reimbursement is vulnerable to clawback for documentation deficiency.

KX modifier and therapy cap exception tracking

Therapy services exceeding the annual cap require the KX modifier with documentation justifying medical necessity. The platform tracks cap thresholds per patient and surfaces the documentation requirements before claims are submitted — the alternative is appeals after denial.

HIPAA already requires the work. Patient Protect starts at $39 a month.

For a covered practice, HIPAA does not ask whether the organization has the budget, internal expertise, or spare time to build a compliance program. The obligation already exists. The only real question is whether you run it through spreadsheets, generic templates, disconnected training and scattered agreements — or keep the whole program in one place.

  • Guided Security Risk Analysis
  • Risk-management and remediation workflows
  • 48 customizable policies and procedures
  • HIPAA Foundations workforce training
  • Completion tracking and verifiable training certificates
  • Workforce and vendor management
  • Business Associate Agreement tracking and documentation
  • Compliance scoring and centralized audit evidence
Start your 14-day free trial

$39 per office per month · Up to 25 personnel · No long-term contract

State-specific HIPAA rules for physical therapy practices.

HIPAA is federal — but your state layers additional breach notification deadlines, AG reporting requirements, and privacy laws on top. Select your state to see what applies to your practice.

What happens after the paperwork is done.

Every major compliance platform covers risk assessments and policy templates. This is the part that differs.

What to ask

Patient Protect

01

Risk assessment that satisfies §164.308(a)(1)

A readiness quiz is not a risk analysis.

Full SRA wizard mapped to NIST CSF with live scoring

02

Auto-generated policies with workforce acknowledgment

HIPAA requires documented proof your staff reviewed them.

48 policies from your risk profile, versioned acknowledgment

03

Staff training with delivery tracking

§164.308(a)(5) — sending a PDF is not sufficient.

HIPAA Foundations — 19 modules, 95 assessment questions, verifiable certificates

04

Full BAA lifecycle management

Expired BAAs are a top enforcement target.

E-signature, renewal alerts, Vendor Risk Scanner

Yes on all 10. Now run the checklist on the rest.

From $39/mo · No long-term contracts.

Enterprise-grade compliance. Independent-practice pricing.

No contracts · No setup fees · Cancel anytime

Basic

$39/mo

Risk assessments, policies, BAA management, training, and compliance scoring.

Recommended

Pro

$99/mo

Everything in Basic plus secure messaging, breach intelligence, live diagnostics, and AI compliance assistant.

See full feature comparison →

Common questions about HIPAA compliance for physical therapy practices.

Do physical therapy practices need HIPAA compliance?

Yes. Physical therapy practices are covered entities under HIPAA. Every practice that transmits health information electronically — including insurance claims and referral communications — must comply with the full HIPAA Security, Privacy, and Breach Notification Rules.

How does HIPAA apply to workers' compensation in PT?

Workers' comp records are subject to HIPAA protections. While certain disclosures to employers and insurers are permitted, they must follow specific authorization requirements. Unauthorized disclosure of treatment details beyond what's permitted is a HIPAA violation.

Are home exercise program apps HIPAA compliant?

Many are not. If an exercise prescription app stores patient names, treatment data, or any identifying information, it must comply with HIPAA requirements and your practice needs a signed BAA with the vendor. Always verify before adopting any patient-facing tool.

What does HIPAA compliance cost for a PT practice?

Compliance consultants charge $3,000–$8,000 per year for physical therapy practices. Patient Protect starts at $39/month ($468/year) with no contracts — covering risk assessments, policy management, BAA tracking, staff training, and continuous monitoring.

Are progress photos taken for insurance documentation considered PHI?

Yes. Photos documenting patient progress, range-of-motion, swelling, or other clinical findings linked to patient identity are PHI. What decides compliance is not the brand of the storage but whether the service is covered by a BAA, configured for the practice, and under the practice's control. A personal iCloud, Google Photos, or Dropbox account — or a staff member's camera roll — fails all three: no agreement, no configuration, no ability to remove access when someone leaves. Clinical photos need storage carrying the same access, audit, and retention controls as the EHR.

Do PT practices need a BAA with the referring physician's practice?

Generally no — provider-to-provider PHI exchange for treatment purposes is permitted under §164.506 without a BAA. However, electronic transmission infrastructure (clearinghouses, secure messaging platforms, fax services that handle PHI) typically requires BAAs. The provider relationship is treatment-purpose; the technical intermediaries handling the data are business associates.

Can PT practices share patient progress with employers or attorneys for workers' comp cases?

Workers' compensation is one of HIPAA's permitted disclosure categories under §164.512(l) — practices may disclose PHI as authorized by state workers' comp law without specific patient authorization. The disclosure must be limited to what state law requires. Disclosures for personal-injury attorneys typically require specific patient authorization under §164.508 because they fall outside the workers' comp exception.

Does a physical therapy practice have to complete a HIPAA Security Risk Analysis?

Yes, and it has to follow treatment out of the clinic. Every covered practice must conduct and document an accurate, thorough assessment of the risks affecting all its ePHI. For a PT practice that means the EHR and scheduling systems, home-exercise and patient-engagement platforms, progress photos and videos including how they are captured and removed from devices, laptops and tablets used during home visits, telehealth and messaging, workers' compensation and attorney disclosure workflows, and access held by PRN, per-diem, contract, and student personnel. High visit volume and rotating staff are the two conditions that most often make a PT analysis go stale between reviews.

Which of our physical therapy vendors need Business Associate Agreements?

Any organization handling PHI on the practice's behalf: the EHR, scheduling and billing vendors, claims clearinghouse, home-exercise program platform, secure messaging, telehealth platform, cloud storage and backup, and any photo or video storage used for progress documentation. The home-exercise platform is the one most often missed, because it feels like a patient tool rather than a vendor holding treatment data. Referring physicians are not business associates — a treatment referral between providers does not require a BAA simply because PHI is exchanged. Employers, insurers, and attorneys are not business associates either; those are authorization-governed disclosures.

What changes when our therapists document during home visits?

The obligation does not change; the controls do. Once treatment leaves the clinic, the practice is still responsible for ePHI on a device it may not physically control, on a network it does not own, in an environment where family members are present. That means device encryption and screen lock, a documented rule about what may be stored locally versus synced, remote wipe capability, a policy on photographing patients in the home, and a procedure for a device that goes missing. Mobility is a workflow decision the risk analysis has to account for explicitly — the common failure is a clinic whose SRA describes only the building.

Is the government's Security Risk Assessment Tool mandatory?

No. The government's SRA Tool is one method designed to help small and medium-sized organizations perform the required analysis. HIPAA requires the underlying risk analysis — not the use of one particular tool. Patient Protect provides its own guided SRA and connects the findings directly to remediation, policies, tasks, and documentation.

Does our EHR make the practice HIPAA compliant?

No. An EHR may provide important safeguards for the records it maintains, but it does not conduct the practice's complete SRA, remediate every identified risk, train the workforce, manage all policies, identify every Business Associate, prepare the practice for incidents, or preserve the full body of compliance evidence.

How much does Patient Protect cost for a physical therapy practice?

Patient Protect Basic costs $39 per office per month and includes up to 25 personnel. It includes the guided Security Risk Analysis, risk management, policies, workforce training, workforce and vendor management, BAA tracking, compliance scoring, and centralized documentation needed to operate the practice's core HIPAA compliance program.

Corrections & Updates

Healthcare security data changes as investigations progress, vendors update systems, and laws and guidance evolve. If you see something outdated, incomplete, or incorrect — or have newer source material — we’d appreciate hearing from you.

Submit a correction →

Patient Protect is intuitive, proactive, and affordable — exactly what small clinics like ours need to keep patient data safe and stay on the right side of HIPAA.
Dr. Thomas E Murray, D.D.S.Patient Protect Member Since 2017

Your PT practice moves too fast for annual compliance reviews.

Get continuous monitoring that keeps up with your patient volume. Free risk assessment — no login required.

Or explore the full HIPAA compliance software comparison or all HIPAA compliance solutions