HIPAA Compliance Checklist for Solo and Small Physical Therapy Practices

September 8, 2026

Resumo

  • A small physical therapy practice can manage HIPAA compliance without dedicated compliance staff or a large budget. Build routine checks around administrative, physical, and technical safeguards.
  • Designate a privacy and security officer. The owner can fill both roles in a solo practice.
  • Complete and document a HIPAA risk assessment. Review it regularly and whenever your technology or operations change.
  • Train staff on privacy and security procedures, and keep records of completed training.
  • Obtain a signed Business Associate Agreement from every vendor that handles patient data.
  • Encrypt patient data, restrict access through unique accounts, and review access logs.
  • Maintain a written breach response plan that assigns responsibilities and explains notification steps.

Why small PT practices are common OCR targets

Small physical therapy practices receive no exemption from HIPAA enforcement. The Office for Civil Rights, or OCR, may investigate a practice after a complaint, reported breach, or compliance review. Practice size can affect what safeguards are reasonable, but it does not remove the requirement to protect electronic protected health information.

OCR inquiries often expose documentation gaps before technical failures. Investigators may request a current security risk assessment, written policies, staff training records, and signed Business Associate Agreements for vendors that handle patient data. A small practice may use appropriate safeguards every day but struggle to prove compliance if the owner never documented them.

The HIPAA Security Rule organizes required safeguards into three categories. Administrative safeguards cover assigned responsibility, risk management, policies, and training. Physical safeguards address clinic access, workstations, devices, and record disposal. Technical safeguards cover encryption, access controls, audit logs, and secure communication. Maintaining evidence across all three categories gives OCR a clear record of how your practice identifies and manages privacy and security risks.

Administrative safeguards: policies, roles, and training

Assign responsibility before writing policies. HIPAA requires a privacy officer and a security official, but one person may fill both roles. In a solo practice, the owner can take these roles. A designated officer is the named person who maintains policies, coordinates training, reviews risks, handles complaints, and documents compliance work. Record the appointment in writing, even when you appoint yourself.

A HIPAA risk assessment identifies where electronic protected health information sits, who can access it, what could expose it, and which safeguards reduce that exposure. HIPAA commonly refers to this review as a risk analysis. Your assessment should cover computers, mobile devices, email, cloud software, patient portals, backups, and remote work. For each risk, record its likelihood, potential effect, current controls, planned corrective action, responsible person, and target date.

Treat the risk assessment as a living document. Review it at least annually as a practical baseline, and update it when you add software, replace devices, move locations, or change how clinicians communicate with patients. Keep completed assessments and remediation records because an undocumented review gives an investigator little evidence that the practice addressed known risks.

Train each workforce member when they join and whenever policies or job duties change. Annual refresher training gives a small practice a manageable cadence for covering secure communication, appropriate access, incident reporting, and device handling. Keep the training date, topics, materials, attendee names, and signed acknowledgments. Contractors who handle patient information may need role-specific instruction as well as a Business Associate Agreement.

A one-to-three-person practice can maintain a short policy manual, one risk register, a vendor list, and a training log. Review those records during a scheduled annual compliance meeting and after significant operational changes. A larger practice should assign policy owners, tailor training by job access, track corrective actions centrally, and schedule periodic access reviews. Either model should produce written evidence showing who made decisions, what the practice found, and how the practice responded.

Physical safeguards: your clinic space and devices

Physical safeguards limit who can see, handle, or remove patient information in your clinic. Walk through the space during a normal workday and check each place where patients, visitors, and clinicians could view or access records.

  • Position front-desk monitors away from waiting areas and use privacy filters where repositioning cannot prevent accidental viewing.
  • Set computers and treatment-room screens to lock automatically after a short period. Clinicians should also lock screens before leaving a room.
  • Keep a device inventory that records each computer, phone, tablet, external drive, and other device that may store patient information. Record its location and the person responsible for it.
  • Control practice-owned tablets used for home visits or patient HEP access. Use a sign-out record, avoid leaving tablets in vehicles, and store them in a locked location when nobody is using them.
  • Store paper charts, printed schedules, and intake forms where patients and visitors cannot access them. Avoid leaving names or clinical details visible at the front desk or in shared treatment areas.
  • Use cross-cut shredding or a qualified destruction service for paper containing protected health information.
  • Remove patient data before recycling, donating, returning, or selling old hardware. Physical destruction may be appropriate when secure data removal cannot be verified.
  • Document who may enter areas containing records or devices, including cleaners, contractors, and building staff.

These physical controls address visibility, possession, storage, and disposal. Technical safeguards cover how software protects patient data through encryption, account permissions, and activity records.

Technical safeguards: encryption, access, and audit trails

Technical safeguards control who can view electronic protected health information, how software protects it, and how you can trace activity. Apply these controls to every system that stores or transmits patient data, including documentation, scheduling, billing, telehealth, patient engagement, and home exercise program tools.

Encryption protects readable patient information by converting it into coded data. Your software should encrypt data while stored on servers, computers, tablets, and backups. Software should also encrypt data while moving between a patient’s device, your browser, and the vendor’s servers. If you choose an alternative control, your HIPAA risk assessment should document why the alternative provides reasonable protection.

Access controls should give each person a unique account and only the permissions required for their work. Shared logins prevent you from knowing who viewed or changed a record. Role-based permissions can give a front-desk employee access to scheduling without exposing clinical notes unnecessarily. Multi-factor authentication, automatic screen locks, and prompt account removal after an employee leaves add further protection.

Audit logs create a record of account activity. A suitable platform should record logins, failed access attempts, record views, edits, downloads, and permission changes. Someone in your practice should review those logs after a suspected incident and periodically check for unusual activity. Logs provide little value if the vendor records them but cannot make them available when you need to investigate.

Unsecured patient texting and email deserve your first review because ordinary messaging accounts may expose patient details or retain them outside approved software. Use a secure patient portal or encrypted messaging function for clinical information. If patients request another communication method, document the request, explain the privacy risk, and follow your written policy. Keep appointment reminders limited to the minimum necessary information, and never place diagnoses, treatment details, or exercise instructions in an unsecured message.

Business Associate Agreements and evaluating HIPAA-compliant software

Any vendor that creates, receives, maintains, or transmits protected health information on your behalf may qualify as a business associate. Review scheduling, documentation, billing, patient engagement, telehealth, and home exercise program software. Cloud storage, email, IT support, and data backup services may also require review when they can access patient information.

A Business Associate Agreement, or BAA, defines how a vendor may use and protect patient information. The agreement should require appropriate safeguards, restrict permitted uses and disclosures, require the vendor to report security incidents, and address subcontractors that handle the same data. It should also explain what happens to patient information when the contract ends. Your practice should sign the BAA before sharing protected health information with the vendor and retain a copy with your compliance records.

A vendor’s claim that its software is “HIPAA compliant” does not replace a BAA or your own review. The federal government does not issue a general HIPAA certification for software products. HIPAA compliance also depends on how your practice configures and uses the software. For example, secure messaging cannot protect a patient conversation when a clinician copies the same information into an ordinary text message.

Use the following checklist when evaluating software that touches patient data.

  • Signed BAA. Confirm that the vendor will sign a BAA covering the specific service you plan to use. Review any exclusions in the agreement.
  • Encryption. Ask whether the vendor encrypts patient information while stored and while transmitted. Confirm that backups and mobile access receive equivalent protection.
  • Access controls. Require unique user accounts, strong authentication options, and permissions based on each person’s job duties. Avoid shared clinic logins.
  • Access logging. Confirm that the software records who viewed, changed, downloaded, or shared patient information. Ask how long the vendor retains those logs.
  • Secure communication. Check whether patients and clinicians can exchange messages through a protected portal or app instead of standard texting or unencrypted email.
  • Incident response. Ask how quickly the vendor will notify your practice after a suspected breach and what information the notice will include.
  • Data handling. Confirm how you can export patient records and how the vendor deletes or returns data after cancellation.

Document each review, including the vendor’s answers and the signed BAA. A current vendor inventory makes future risk assessments and contract renewals easier to manage.

Breach notification: what triggers it and what to do

HIPAA generally treats an impermissible use or disclosure of unsecured protected health information as a breach. An incident may avoid notification if a documented assessment finds a low probability that the information was compromised. The assessment should consider what information was involved, who received it, whether anyone accessed it, and how effectively you reduced the potential harm. Properly encrypted information may fall outside the breach definition when the encryption key remains secure.

Your practice must notify affected patients without unreasonable delay and no later than 60 calendar days after discovering a reportable breach. Breaches affecting 500 or more people also require prompt notice to the Department of Health and Human Services. Smaller breaches go into an annual HHS submission. A breach affecting more than 500 residents of a state or jurisdiction may require notice to prominent local media. State law may impose additional or shorter deadlines.

A written response plan should tell you who investigates an incident and who handles notifications. The plan should also provide templates for recording what happened, what information was involved, and how your practice responded. When a vendor discovers a breach, its Business Associate Agreement should require timely notice to your practice.

Access controls reduce the chance of unauthorized access, while signed BAAs clarify each vendor’s response duties. If an incident occurs, preserve relevant records, limit further exposure, document your assessment, and obtain legal or compliance guidance when the reporting decision remains unclear. Most incidents can be managed through a calm, documented response.

Where small PT practices most often fall short

Small physical therapy practices often fall short in three areas that leave a thin compliance record. Use the following questions to check whether your earlier safeguards work in daily operations.

  • Do clinicians communicate through personal text messages or ordinary email? Return to the technical safeguards and require secure patient communication through approved accounts or software. Document the rule and train everyone who handles patient information.

  • Can you produce a signed Business Associate Agreement for every vendor that receives or stores patient data? Review scheduling, documentation, billing, cloud storage, patient engagement, telehealth, and home exercise program software. A vendor’s claim of HIPAA compliance does not replace a signed agreement.

  • Can you produce your latest documented risk assessment? An informal understanding of your risks gives an OCR reviewer little evidence that you identified vulnerabilities and addressed them. Return to the administrative safeguards and record each risk, the corrective action, the responsible person, and the completion date.

Your self-check should also confirm that training records, access lists, device inventories, and breach procedures remain current. Review the risk assessment at least annually and whenever you add software, move locations, or change how staff access patient information. Refresh training when policies or tools change, and keep proof that each person completed it.

HIPAA compliance works best as a recurring operating task. A calendar reminder for reassessment, training, vendor review, and access review helps a small practice maintain the documentation that an investigation would request.

Getting started this week

Start by naming a privacy and security officer in writing. A solo owner can fill both roles. Record who handles policies, training, access reviews, patient complaints, and incident response.

Next, begin a documented risk assessment. List where patient information enters, moves through, and leaves your practice. Record the safeguards already in place, identify gaps, assign each fix to a person, and set a due date.

Before the week ends, inventory every vendor that handles patient information. Include scheduling, documentation, billing, messaging, cloud storage, telehealth, and home exercise program tools. Confirm that each vendor has signed a Business Associate Agreement, and request one immediately if your records lack it.

Schedule quarterly access reviews and an annual risk reassessment before closing the checklist. Regular reviews turn HIPAA compliance into a manageable operating habit that protects patient information and gives your practice a clear record of its safeguards.

Perguntas frequentes

How often should a small practice complete a HIPAA risk assessment?

A HIPAA risk assessment documents threats to electronic patient information and the safeguards addressing them. Your practice should review it at least annually and after major changes, such as adopting new software or moving locations. Regular reviews keep the document current for audits and guide your next security improvements.

Does a solo physical therapist need a privacy officer?

A privacy officer oversees HIPAA policies, complaints, training, and required documentation. A solo physical therapist can designate themselves and should record that designation in writing. Naming the role creates clear responsibility without requiring another employee or outside consultant.

What does “HIPAA compliant software” actually guarantee?

“HIPAA compliant software” describes vendor safeguards, but no government certification guarantees that software will make your practice compliant. You still need a signed Business Associate Agreement and must confirm encryption, access controls, activity logs, and secure communication. Reviewing those items before purchase reduces vendor-related privacy risks.

What are the penalties for using a vendor without a BAA?

A missing required Business Associate Agreement can constitute a HIPAA violation when a vendor creates, receives, maintains, or transmits protected health information. OCR may require corrective action and can impose civil monetary penalties based on factors such as culpability, duration, and efforts to correct the issue. Inventory your vendors now, request missing agreements, and stop sharing patient information with any vendor that will not sign one.

Kevin Kaminyar
Diretor Global de Crescimento