Skip to content
Bellator Cyber Guard
Healthcare19 min readDeep Dive

HIPAA Compliance for Chiropractors: What's Required

HIPAA compliance for chiropractors explained: covered entity status, required safeguards, BAAs, and 2026 breach notification deadlines you need to know.

By Bellator Cyber Guard Security Team

Chiropractors Are HIPAA Covered Entities

HIPAA compliance for chiropractors means following the same Privacy Rule and Security Rule requirements that apply to any medical office: protecting patient health information, limiting who can access it, and reporting breaches within set deadlines. If your practice submits claims electronically, checks insurance eligibility online, or uses an electronic health record (EHR) system, you are a "covered entity" under the Health Insurance Portability and Accountability Act (HIPAA), the 1996 federal law that governs how patient health information is protected. That status applies whether you run a solo practice with one front-desk employee or a multi-location clinic.

Being a covered entity carries specific obligations: a written risk assessment, administrative and technical safeguards, staff training, signed agreements with vendors who touch patient data, and a plan for notifying patients if that data is exposed. Skipping these steps does not just create legal exposure; it also leaves the practice more vulnerable to the ransomware and phishing attacks that regularly target small medical offices.

Quick Answer

Yes, chiropractors who transmit any health information electronically, such as billing claims or insurance eligibility checks, are HIPAA covered entities and must follow the Privacy Rule and Security Rule. That means completing a written risk assessment, implementing administrative and technical safeguards, training staff annually, signing Business Associate Agreements with vendors like billing companies and EHR providers, and maintaining a breach notification plan. There is no chiropractic-specific exemption, and practice size does not remove the obligation.

What Counts as Protected Health Information in a Chiro Office

Protected health information (PHI) is any information that identifies a patient and relates to their health condition, treatment, or payment for care, in any form: paper, verbal, or electronic. In a chiropractic setting, that includes intake forms, SOAP notes, X-ray and imaging files, insurance and billing records, appointment schedules, and even text messages confirming a visit. Electronic PHI, or ePHI, is subject to the additional technical requirements in the HIPAA Security Rule.

Most chiropractic offices rely on outside vendors for at least part of their operations: a cloud-based EHR, a billing service, an imaging system, or a texting platform for appointment reminders. Under HIPAA, any vendor that creates, receives, maintains, or transmits PHI on your behalf is a "business associate," and federal law requires a signed Business Associate Agreement (BAA) before you share data with them. If you outsource billing, review our guide on medical billing company hipaa compliance requirements to confirm your billing partner is covered. A few deadlines and thresholds matter most once a breach occurs, detailed below.

Key HIPAA Deadlines and Thresholds

6 years
Retention period for HIPAA policies, risk assessments, and training records under 45 CFR 164.316(b)(2)(i)
60 days
Maximum time to notify affected patients after discovering a breach, per the HHS Breach Notification Rule
500+
Number of affected patients that triggers mandatory notice to HHS and local media, per 45 CFR 164.408

Where Chiropractic Practices Typically Fall Short

Chiropractic offices tend to run lean, with a small administrative staff handling scheduling, billing, and patient communication at the same time. That efficiency is also where compliance gaps show up.

  • Appointment reminders sent by unsecured text. Standard SMS is not encrypted and was not built to carry PHI. See our overview of hipaa compliant text messaging for medical staff for compliant alternatives.
  • Cloud storage without a BAA or encryption. Storing X-rays or notes in a general-purpose file-sharing app that has not signed a BAA can create a documentation gap during an audit. Our guide to hipaa compliant cloud storage for medical records covers what to look for.
  • Shared logins on front-desk computers. One login for the whole front desk makes it impossible to track who accessed which patient record, which the Security Rule's access-control standard is designed to prevent.
  • No documented risk assessment. Many offices assume buying an EHR system automatically makes them compliant. The EHR vendor secures its own platform; the practice is still responsible for its own written risk assessment and policies.

HIPAA Safeguards Action Checklist

  • Complete and document a written HIPAA risk assessment covering every system that touches PHI
  • Assign a HIPAA Privacy Officer and Security Officer (can be the same person in a small practice)
  • Sign Business Associate Agreements with every vendor that touches patient data
  • Require unique logins and multi-factor authentication for EHR and billing system access
  • Encrypt PHI stored on laptops, servers, and cloud platforms
  • Train every staff member on HIPAA policies at hire and at least annually
  • Maintain a written incident response and breach notification plan
  • Retain HIPAA policies, risk assessments, and training records for six years

What Happens If Your Practice Is Not Compliant

The U.S. Department of Health and Human Services (HHS) Office for Civil Rights (OCR) enforces HIPAA and can investigate after a patient complaint, a reported breach, or a routine compliance review. OCR's civil penalty structure is tiered by the level of culpability, from unknowing violations to willful neglect, and the dollar amounts are adjusted annually for inflation; current figures are published on HHS's HIPAA enforcement page. Beyond fines, a breach that exposes 500 or more patient records is posted publicly on HHS's breach portal, which patients and local media can see.

For most small chiropractic practices, the more immediate risk is not a federal fine but a ransomware attack or stolen laptop that forces the office to notify every affected patient, pay for credit monitoring, and operate without patient records while systems are rebuilt. A documented risk assessment and working backups can reduce how much damage that kind of incident causes, though no set of controls removes the risk entirely.

Breach Notification Deadline

Under the HIPAA Breach Notification Rule (45 CFR 164.404), you must notify affected patients within 60 days of discovering a breach involving unsecured PHI, regardless of how many patients are affected. According to HHS, breaches involving 500 or more individuals also require notifying HHS and local media within that same 60-day window. Confirm your specific obligations with legal counsel, since state breach notification laws can add requirements beyond HIPAA.

Building a HIPAA Compliance Program

1

Run a risk assessment

Identify every system, vendor, and workflow that touches PHI, and document the gaps you find.

2

Write your policies

Put privacy and security policies in writing, covering access control, device use, and incident response.

3

Sign BAAs with vendors

Get a signed Business Associate Agreement from your EHR, billing, imaging, and texting vendors before sharing PHI.

4

Lock down access

Require unique logins, multi-factor authentication, and encryption on every device that touches patient data.

5

Train your team

Deliver HIPAA training at hire and refresh it at least once a year, covering phishing and password hygiene.

6

Test and update

Review the risk assessment and policies at least annually or after any major system change.

Training, Vendors, and Technical Safeguards Work Together

Written policies only reduce risk if staff actually follow them. Annual refreshers should cover phishing recognition, password hygiene, and what to do if a device is lost or stolen. Our breakdown of hipaa employee training requirements covers what a defensible program looks like, and hipaa security awareness training walks through how to structure ongoing refreshers rather than a one-time session.

On the technical side, a periodic what is a vulnerability assessment and why it matters on your network and EHR access helps confirm the safeguards you documented in your risk assessment are actually working, not just written down. Many chiropractic offices pair that with managed endpoint detection and response (EDR) to catch ransomware and unauthorized access attempts on office computers, since a single infected laptop can expose every patient record it can reach.

Key Takeaway

HIPAA compliance is not a one-time purchase or a single software feature. It is an ongoing program of a risk assessment, written policies, signed vendor agreements, trained staff, and tested technical safeguards, reviewed at least once a year.

Where Bellator Cyber Guard Fits

Bellator Cyber Guard's Bellator Core plan combines managed EDR, remote monitoring, and Ransomware Rollback® for $33 per computer per month, built for practices that need both day-to-day protection and a way to recover quickly if ransomware reaches an office computer. For practices that want endpoint protection without the added monitoring and rollback featuresBellator Shield covers managed EDR alone at $19 per computer per month. Neither plan replaces your written HIPAA policies or risk assessment, but both address the technical safeguards the Security Rule requires and reduce how much a ransomware or malware incident can affect patient data. Compare the two on the protection plans page, and see our broader overview of medical practice cybersecurity for how these pieces fit into a full compliance program.

Get a Free HIPAA Endpoint Security Review

Talk through your chiropractic practice's risk assessment gaps and technical safeguards with no pressure to buy.

Frequently Asked Questions

Yes. The HIPAA Security Rule requires every covered entity, including chiropractic practices, to conduct and document a risk assessment identifying where PHI is created, stored, and transmitted, and what could go wrong. There is no size exemption.

Yes. A single-provider office that bills insurance electronically or uses an EHR system is a covered entity under HIPAA regardless of staff count. The compliance obligations are the same; the workload of meeting them is usually lighter with fewer systems to document.

A Business Associate Agreement (BAA) is a written contract required whenever a vendor creates, receives, maintains, or transmits PHI on your behalf. Billing companies, EHR vendors, imaging services, and texting platforms that touch patient data all need a signed BAA before you share information with them.

HHS does not set a specific interval, but most compliance programs train new hires before they access PHI and refresh all staff at least once a year, or sooner after a policy change, a new system rollout, or a security incident.

Share

Share on X
Share on LinkedIn
Share on Facebook
Send via Email
Copy URL
(800) 492-6076

From requirement to defensible practice

Turn HIPAA requirements into safeguards that fit patient care

A useful compliance path makes the obligation clear, identifies the evidence to retain, and connects written policy to the safeguards used every day.

People also look for

Keep exploring HIPAA security

Connect HIPAA requirements to the safeguards, assessments, and everyday decisions a healthcare practice can actually implement.