Do physical therapy practices need HIPAA compliance?
Yes. Physical therapy practices are covered entities under HIPAA. Every practice that transmits health information electronically — including insurance claims and referral communications — must comply with the full HIPAA Security, Privacy, and Breach Notification Rules.
How does HIPAA apply to workers' compensation in PT?
Workers' comp records are subject to HIPAA protections. While certain disclosures to employers and insurers are permitted, they must follow specific authorization requirements. Unauthorized disclosure of treatment details beyond what's permitted is a HIPAA violation.
Are home exercise program apps HIPAA compliant?
Many are not. If an exercise prescription app stores patient names, treatment data, or any identifying information, it must comply with HIPAA requirements and your practice needs a signed BAA with the vendor. Always verify before adopting any patient-facing tool.
What does HIPAA compliance cost for a PT practice?
Compliance consultants charge $3,000–$8,000 per year for physical therapy practices. Patient Protect starts at $39/month ($468/year) with no contracts — covering risk assessments, policy management, BAA tracking, staff training, and continuous monitoring.
Are progress photos taken for insurance documentation considered PHI?
Yes. Photos documenting patient progress, range-of-motion, swelling, or other clinical findings linked to patient identity are PHI. What decides compliance is not the brand of the storage but whether the service is covered by a BAA, configured for the practice, and under the practice's control. A personal iCloud, Google Photos, or Dropbox account — or a staff member's camera roll — fails all three: no agreement, no configuration, no ability to remove access when someone leaves. Clinical photos need storage carrying the same access, audit, and retention controls as the EHR.
Do PT practices need a BAA with the referring physician's practice?
Generally no — provider-to-provider PHI exchange for treatment purposes is permitted under §164.506 without a BAA. However, electronic transmission infrastructure (clearinghouses, secure messaging platforms, fax services that handle PHI) typically requires BAAs. The provider relationship is treatment-purpose; the technical intermediaries handling the data are business associates.
Can PT practices share patient progress with employers or attorneys for workers' comp cases?
Workers' compensation is one of HIPAA's permitted disclosure categories under §164.512(l) — practices may disclose PHI as authorized by state workers' comp law without specific patient authorization. The disclosure must be limited to what state law requires. Disclosures for personal-injury attorneys typically require specific patient authorization under §164.508 because they fall outside the workers' comp exception.
Does a physical therapy practice have to complete a HIPAA Security Risk Analysis?
Yes, and it has to follow treatment out of the clinic. Every covered practice must conduct and document an accurate, thorough assessment of the risks affecting all its ePHI. For a PT practice that means the EHR and scheduling systems, home-exercise and patient-engagement platforms, progress photos and videos including how they are captured and removed from devices, laptops and tablets used during home visits, telehealth and messaging, workers' compensation and attorney disclosure workflows, and access held by PRN, per-diem, contract, and student personnel. High visit volume and rotating staff are the two conditions that most often make a PT analysis go stale between reviews.
Which of our physical therapy vendors need Business Associate Agreements?
Any organization handling PHI on the practice's behalf: the EHR, scheduling and billing vendors, claims clearinghouse, home-exercise program platform, secure messaging, telehealth platform, cloud storage and backup, and any photo or video storage used for progress documentation. The home-exercise platform is the one most often missed, because it feels like a patient tool rather than a vendor holding treatment data. Referring physicians are not business associates — a treatment referral between providers does not require a BAA simply because PHI is exchanged. Employers, insurers, and attorneys are not business associates either; those are authorization-governed disclosures.
What changes when our therapists document during home visits?
The obligation does not change; the controls do. Once treatment leaves the clinic, the practice is still responsible for ePHI on a device it may not physically control, on a network it does not own, in an environment where family members are present. That means device encryption and screen lock, a documented rule about what may be stored locally versus synced, remote wipe capability, a policy on photographing patients in the home, and a procedure for a device that goes missing. Mobility is a workflow decision the risk analysis has to account for explicitly — the common failure is a clinic whose SRA describes only the building.
Is the government's Security Risk Assessment Tool mandatory?
No. The government's SRA Tool is one method designed to help small and medium-sized organizations perform the required analysis. HIPAA requires the underlying risk analysis — not the use of one particular tool. Patient Protect provides its own guided SRA and connects the findings directly to remediation, policies, tasks, and documentation.
Does our EHR make the practice HIPAA compliant?
No. An EHR may provide important safeguards for the records it maintains, but it does not conduct the practice's complete SRA, remediate every identified risk, train the workforce, manage all policies, identify every Business Associate, prepare the practice for incidents, or preserve the full body of compliance evidence.
How much does Patient Protect cost for a physical therapy practice?
Patient Protect Basic costs $39 per office per month and includes up to 25 personnel. It includes the guided Security Risk Analysis, risk management, policies, workforce training, workforce and vendor management, BAA tracking, compliance scoring, and centralized documentation needed to operate the practice's core HIPAA compliance program.