Skip to main content
Patient Protect circular logo mark in purple and white used for site navigationPatient Protect

HIPAA Compliance for Physical Therapists

The HIPAA compliance and security operating system for physical therapy practices. Treatment leaves the clinic — home visits, mobile documentation, progress photography, exercise platforms, and a rotating bench of PRN and contract clinicians. Patient Protect runs the risk analysis across every device and workflow, manages access, training, and vendor agreements, and preserves the record.

What HIPAA actually looks like for physical therapy practices.

The regulatory framework, the enforcement patterns OCR has historically cited, the non-HIPAA standards that apply, the gaps audits routinely surface, and the record-retention overlay — HIPAA’s six-year rule for compliance documentation, and the separate state law that governs how long clinical records must be kept.

Regulatory framework

Physical therapy practices operate under HIPAA as covered entities through standard electronic transactions — claims submission to Medicare Part B, private payers, workers' compensation systems, and eligibility verification. Medicare therapy services impose specific documentation requirements: plan of care signed by referring physician within 30 days, periodic reassessment, KX modifier and therapy-cap exception documentation, progress-note specificity. State physical therapy practice acts govern record-keeping. The ABPTS specialty board rules apply where the practice employs specialty-certified clinicians.

OCR enforcement patterns

OCR's PT enforcement record includes unauthorized record access by former employees, missing or expired BAAs with therapy-specific platforms (home exercise prescription, electronic claims), and disclosure errors involving workers' compensation and personal-injury attorneys. Progress photos synced to a personal cloud account are a recurring exposure — not because a brand name is inherently unlawful, but because a consumer account is unconfigured, uncovered by a BAA, and outside the practice's control. Medicare audits surface HIPAA-adjacent documentation gaps — missing referring-physician signatures, inadequate progress-note specificity — that compound into HIPAA exposure.

Standards beyond HIPAA

Medicare therapy cap exceptions and KX modifier documentation under §1833(g). Section 164.512(l) workers' compensation disclosure exception (state-specific implementation varies). Plan-of-care signature requirements under Medicare. State licensure board rules on direct-access vs referral-required care. State workers' compensation systems impose their own record-disclosure frameworks. Home exercise program (HEP) platforms are business associates when they receive PHI.

Common compliance gaps

Progress photos stored on consumer platforms or staff personal devices is the single highest-frequency compliance gap in PT practice. Other recurring gaps: missing referring-physician signatures on plans of care creating both Medicare and HIPAA documentation issues, undocumented disclosures to personal-injury attorneys (which require §164.508 authorization, not the §164.512(l) workers' comp exception), missing BAAs with HEP platforms and electronic claims clearinghouses, and inadequate audit logging on staff access to celebrity-patient or executive-patient records.

Compliance documentation, then state record law.

HIPAA's six-year rule governs compliance documentation, not clinical records (§164.530(j)). State PT board rules govern patient record retention — typically seven to ten years post-last-encounter. Medicare requires retention of plan-of-care and treatment documentation for the period of care plus a tail. Workers' compensation cases impose their own retention requirements under state law — typically the duration of the claim plus a multi-year period. Progress photos as part of the medical record are subject to the same retention as the rest of the record.

Reference summary, not legal advice. This page summarizes how HIPAA and adjacent regulatory frameworks apply to physical therapy practices based on Patient Protect’s reading of the relevant CFR provisions, OCR enforcement record, and state statutes. Operators with specific compliance questions should consult a qualified HIPAA attorney. Patient Protect is a HIPAA compliance platform; we are not a law firm and do not provide legal advice.

Where physical therapy practices are most exposed.

Referring physician data exchanges lack BAA coverage

PT practices receive referrals and send progress reports to physicians constantly. If these exchanges happen via unencrypted email, fax-to-email services, or patient portals without BAAs, every transmission is a potential HIPAA violation.

Workers' compensation records add disclosure complexity

Workers' comp cases involve employers, insurers, attorneys, and case managers — all requesting patient information. Knowing what you can disclose, to whom, and under what authorization is complex. One wrong disclosure is a violation.

Exercise and treatment documentation tools may not be compliant

Home exercise program apps, outcome tracking tools, and patient engagement platforms all handle ePHI. Many PT-specific tools lack BAAs, encryption, or proper access controls — and practices adopt them without compliance review.

High patient volumes mean high breach exposure

PT practices often see 30–50 patients per day across multiple therapists. Each patient interaction generates ePHI. The sheer volume of data handling amplifies every compliance gap — a single unsecured workflow affects thousands of records annually.

Built for physical therapy practices, not hospital systems.

Referral workflow compliance

Track BAAs with every referring physician and specialist. Secure messaging ensures clinical data stays encrypted end-to-end, replacing unsecured fax and email.

BAA management for PT vendors

Track agreements with EHR vendors, exercise platforms, billing services, and outcome tracking tools. Expiration alerts and e-sign keep everything current.

Workforce training for clinical staff

HIPAA training modules designed for PT practice workflows — high-volume patient handling, shared workstations, and multi-provider documentation. Completion tracked automatically.

Real-time compliance scoring

See your practice's compliance standing update as you close gaps. Prioritize the highest-risk items first. Know where you stand before an audit — not during one.

Plan-of-care documentation aligned with Medicare therapy requirements

Physical therapy plans of care under Medicare require physician signature within 30 days, periodic reassessment, and specific documentation of progression. Patient Protect's policy generation produces the documentation framework Medicare auditors expect — without which Part B reimbursement is vulnerable to clawback for documentation deficiency.

KX modifier and therapy cap exception tracking

Therapy services exceeding the annual cap require the KX modifier with documentation justifying medical necessity. The platform tracks cap thresholds per patient and surfaces the documentation requirements before claims are submitted — the alternative is appeals after denial.

State-specific HIPAA rules for physical therapy practices.

HIPAA is federal — but your state layers additional breach notification deadlines, AG reporting requirements, and privacy laws on top. Select your state to see what applies to your practice.

District of Columbia compliance requirements for physical therapy practices

In addition to federal HIPAA requirements, physical therapy practices operating in District of Columbia must comply with the following state-specific obligations.

Breach notification deadline

In the most expedient time possible and without unreasonable delay, subject to the needs of law enforcement and any measures necessary to determine the scope of the breach and restore the reasonable integrity of the data system.

The statute does not fix a numeric outer bound. Unreasonable delay is itself a violation and may result in state enforcement action, so treat the operative timeframe as the shortest window your incident circumstances reasonably support.

Attorney General notification

Required for all breaches

Your practice must notify the state AG in addition to affected patients and HHS.

District of Columbia-specific laws & requirements

DC uses the New-York pattern: HIPAA covers individual notice, but AG notice is independent

For HIPAA-regulated entities operating in DC, satisfying HIPAA breach-notification obligations to individuals is deemed to satisfy the § 28-3852 individual-notice requirement under subsection (g). But the separate DC Attorney General notification obligation under § 28-3852(b-1) is triggered independently once a breach affects 50 or more DC residents, and HIPAA compliance does not substitute for that AG notice. Practices notifying HHS under HIPAA still owe a separate written AG notice to DC.

Source: D.C. Code § 28-3852(a)

Verified against primary state authority as of August 2026. General reference — consult legal counsel for your specific obligations.

Primary sources: code.dccouncil.gov · oag.dc.gov

What happens after the paperwork is done.

Every major compliance platform covers risk assessments and policy templates. This is the part that differs.

What to ask

Patient Protect

01

Risk assessment that satisfies §164.308(a)(1)

A readiness quiz is not a risk analysis.

Full SRA wizard mapped to NIST CSF with live scoring

02

Auto-generated policies with workforce acknowledgment

HIPAA requires documented proof your staff reviewed them.

48 policies from your risk profile, versioned acknowledgment

03

Staff training with delivery tracking

§164.308(a)(5) — sending a PDF is not sufficient.

HIPAA Foundations — 19 modules, 95 assessment questions, verifiable certificates

04

Full BAA lifecycle management

Expired BAAs are a top enforcement target.

E-signature, renewal alerts, Vendor Risk Scanner

Yes on all 10. Now run the checklist on the rest.

From $39/mo · No long-term contracts.

Enterprise-grade compliance. Independent-practice pricing.

No contracts · No setup fees · Cancel anytime

Basic

$39/mo

Risk assessments, policies, BAA management, training, and compliance scoring.

Recommended

Pro

$99/mo

Everything in Basic plus secure messaging, breach intelligence, live diagnostics, and AI compliance assistant.

See full feature comparison →

Common questions about HIPAA compliance for physical therapy practices.

Do physical therapy practices need HIPAA compliance?

Yes. Physical therapy practices are covered entities under HIPAA. Every practice that transmits health information electronically — including insurance claims and referral communications — must comply with the full HIPAA Security, Privacy, and Breach Notification Rules.

How does HIPAA apply to workers' compensation in PT?

Workers' comp records are subject to HIPAA protections. While certain disclosures to employers and insurers are permitted, they must follow specific authorization requirements. Unauthorized disclosure of treatment details beyond what's permitted is a HIPAA violation.

Are home exercise program apps HIPAA compliant?

Many are not. If an exercise prescription app stores patient names, treatment data, or any identifying information, it must comply with HIPAA requirements and your practice needs a signed BAA with the vendor. Always verify before adopting any patient-facing tool.

What does HIPAA compliance cost for a PT practice?

Compliance consultants charge $3,000–$8,000 per year for physical therapy practices. Patient Protect starts at $39/month ($468/year) with no contracts — covering risk assessments, policy management, BAA tracking, staff training, and continuous monitoring.

Are progress photos taken for insurance documentation considered PHI?

Yes. Photos documenting patient progress, range-of-motion, swelling, or other clinical findings linked to patient identity are PHI. What decides compliance is not the brand of the storage but whether the service is covered by a BAA, configured for the practice, and under the practice's control. A personal iCloud, Google Photos, or Dropbox account — or a staff member's camera roll — fails all three: no agreement, no configuration, no ability to remove access when someone leaves. Clinical photos need storage carrying the same access, audit, and retention controls as the EHR.

Do PT practices need a BAA with the referring physician's practice?

Generally no — provider-to-provider PHI exchange for treatment purposes is permitted under §164.506 without a BAA. However, electronic transmission infrastructure (clearinghouses, secure messaging platforms, fax services that handle PHI) typically requires BAAs. The provider relationship is treatment-purpose; the technical intermediaries handling the data are business associates.

Can PT practices share patient progress with employers or attorneys for workers' comp cases?

Workers' compensation is one of HIPAA's permitted disclosure categories under §164.512(l) — practices may disclose PHI as authorized by state workers' comp law without specific patient authorization. The disclosure must be limited to what state law requires. Disclosures for personal-injury attorneys typically require specific patient authorization under §164.508 because they fall outside the workers' comp exception.

Does a physical therapy practice have to complete a HIPAA Security Risk Analysis?

Yes, and it has to follow treatment out of the clinic. Every covered practice must conduct and document an accurate, thorough assessment of the risks affecting all its ePHI. For a PT practice that means the EHR and scheduling systems, home-exercise and patient-engagement platforms, progress photos and videos including how they are captured and removed from devices, laptops and tablets used during home visits, telehealth and messaging, workers' compensation and attorney disclosure workflows, and access held by PRN, per-diem, contract, and student personnel. High visit volume and rotating staff are the two conditions that most often make a PT analysis go stale between reviews.

Which of our physical therapy vendors need Business Associate Agreements?

Any organization handling PHI on the practice's behalf: the EHR, scheduling and billing vendors, claims clearinghouse, home-exercise program platform, secure messaging, telehealth platform, cloud storage and backup, and any photo or video storage used for progress documentation. The home-exercise platform is the one most often missed, because it feels like a patient tool rather than a vendor holding treatment data. Referring physicians are not business associates — a treatment referral between providers does not require a BAA simply because PHI is exchanged. Employers, insurers, and attorneys are not business associates either; those are authorization-governed disclosures.

What changes when our therapists document during home visits?

The obligation does not change; the controls do. Once treatment leaves the clinic, the practice is still responsible for ePHI on a device it may not physically control, on a network it does not own, in an environment where family members are present. That means device encryption and screen lock, a documented rule about what may be stored locally versus synced, remote wipe capability, a policy on photographing patients in the home, and a procedure for a device that goes missing. Mobility is a workflow decision the risk analysis has to account for explicitly — the common failure is a clinic whose SRA describes only the building.

Is the government's Security Risk Assessment Tool mandatory?

No. The government's SRA Tool is one method designed to help small and medium-sized organizations perform the required analysis. HIPAA requires the underlying risk analysis — not the use of one particular tool. Patient Protect provides its own guided SRA and connects the findings directly to remediation, policies, tasks, and documentation.

Does our EHR make the practice HIPAA compliant?

No. An EHR may provide important safeguards for the records it maintains, but it does not conduct the practice's complete SRA, remediate every identified risk, train the workforce, manage all policies, identify every Business Associate, prepare the practice for incidents, or preserve the full body of compliance evidence.

How much does Patient Protect cost for a physical therapy practice?

Patient Protect Basic costs $39 per office per month and includes up to 25 personnel. It includes the guided Security Risk Analysis, risk management, policies, workforce training, workforce and vendor management, BAA tracking, compliance scoring, and centralized documentation needed to operate the practice's core HIPAA compliance program.

Patient Protect is intuitive, proactive, and affordable — exactly what small clinics like ours need to keep patient data safe and stay on the right side of HIPAA.
Dr. Thomas E Murray, D.D.S.Patient Protect Member Since 2017

Your PT practice moves too fast for annual compliance reviews.

Get continuous monitoring that keeps up with your patient volume. Free risk assessment — no login required.

Or explore the full HIPAA compliance software comparison or all HIPAA compliance solutions