Chiropractors Are HIPAA Covered Entities
HIPAA compliance for chiropractors means following the same Privacy Rule and Security Rule requirements that apply to any medical office: protecting patient health information, limiting who can access it, and reporting breaches within set deadlines. If your practice submits claims electronically, checks insurance eligibility online, or uses an electronic health record (EHR) system, you are a "covered entity" under the Health Insurance Portability and Accountability Act (HIPAA), the 1996 federal law that governs how patient health information is protected. That status applies whether you run a solo practice with one front-desk employee or a multi-location clinic.
Being a covered entity carries specific obligations: a written risk assessment, administrative and technical safeguards, staff training, signed agreements with vendors who touch patient data, and a plan for notifying patients if that data is exposed. Skipping these steps does not just create legal exposure; it also leaves the practice more vulnerable to the ransomware and phishing attacks that regularly target small medical offices.
Quick Answer
Yes, chiropractors who transmit any health information electronically, such as billing claims or insurance eligibility checks, are HIPAA covered entities and must follow the Privacy Rule and Security Rule. That means completing a written risk assessment, implementing administrative and technical safeguards, training staff annually, signing Business Associate Agreements with vendors like billing companies and EHR providers, and maintaining a breach notification plan. There is no chiropractic-specific exemption, and practice size does not remove the obligation.
What Counts as Protected Health Information in a Chiro Office
Protected health information (PHI) is any information that identifies a patient and relates to their health condition, treatment, or payment for care, in any form: paper, verbal, or electronic. In a chiropractic setting, that includes intake forms, SOAP notes, X-ray and imaging files, insurance and billing records, appointment schedules, and even text messages confirming a visit. Electronic PHI, or ePHI, is subject to the additional technical requirements in the HIPAA Security Rule.
Most chiropractic offices rely on outside vendors for at least part of their operations: a cloud-based EHR, a billing service, an imaging system, or a texting platform for appointment reminders. Under HIPAA, any vendor that creates, receives, maintains, or transmits PHI on your behalf is a "business associate," and federal law requires a signed Business Associate Agreement (BAA) before you share data with them. If you outsource billing, review our guide on medical billing company hipaa compliance requirements to confirm your billing partner is covered. A few deadlines and thresholds matter most once a breach occurs, detailed below.
Key HIPAA Deadlines and Thresholds
Where Chiropractic Practices Typically Fall Short
Chiropractic offices tend to run lean, with a small administrative staff handling scheduling, billing, and patient communication at the same time. That efficiency is also where compliance gaps show up.
- Appointment reminders sent by unsecured text. Standard SMS is not encrypted and was not built to carry PHI. See our overview of hipaa compliant text messaging for medical staff for compliant alternatives.
- Cloud storage without a BAA or encryption. Storing X-rays or notes in a general-purpose file-sharing app that has not signed a BAA can create a documentation gap during an audit. Our guide to hipaa compliant cloud storage for medical records covers what to look for.
- Shared logins on front-desk computers. One login for the whole front desk makes it impossible to track who accessed which patient record, which the Security Rule's access-control standard is designed to prevent.
- No documented risk assessment. Many offices assume buying an EHR system automatically makes them compliant. The EHR vendor secures its own platform; the practice is still responsible for its own written risk assessment and policies.
HIPAA Safeguards Action Checklist
- Complete and document a written HIPAA risk assessment covering every system that touches PHI
- Assign a HIPAA Privacy Officer and Security Officer (can be the same person in a small practice)
- Sign Business Associate Agreements with every vendor that touches patient data
- Require unique logins and multi-factor authentication for EHR and billing system access
- Encrypt PHI stored on laptops, servers, and cloud platforms
- Train every staff member on HIPAA policies at hire and at least annually
- Maintain a written incident response and breach notification plan
- Retain HIPAA policies, risk assessments, and training records for six years
What Happens If Your Practice Is Not Compliant
The U.S. Department of Health and Human Services (HHS) Office for Civil Rights (OCR) enforces HIPAA and can investigate after a patient complaint, a reported breach, or a routine compliance review. OCR's civil penalty structure is tiered by the level of culpability, from unknowing violations to willful neglect, and the dollar amounts are adjusted annually for inflation; current figures are published on HHS's HIPAA enforcement page. Beyond fines, a breach that exposes 500 or more patient records is posted publicly on HHS's breach portal, which patients and local media can see.
For most small chiropractic practices, the more immediate risk is not a federal fine but a ransomware attack or stolen laptop that forces the office to notify every affected patient, pay for credit monitoring, and operate without patient records while systems are rebuilt. A documented risk assessment and working backups can reduce how much damage that kind of incident causes, though no set of controls removes the risk entirely.
Breach Notification Deadline
Under the HIPAA Breach Notification Rule (45 CFR 164.404), you must notify affected patients within 60 days of discovering a breach involving unsecured PHI, regardless of how many patients are affected. According to HHS, breaches involving 500 or more individuals also require notifying HHS and local media within that same 60-day window. Confirm your specific obligations with legal counsel, since state breach notification laws can add requirements beyond HIPAA.
Building a HIPAA Compliance Program
Run a risk assessment
Identify every system, vendor, and workflow that touches PHI, and document the gaps you find.
Write your policies
Put privacy and security policies in writing, covering access control, device use, and incident response.
Sign BAAs with vendors
Get a signed Business Associate Agreement from your EHR, billing, imaging, and texting vendors before sharing PHI.
Lock down access
Require unique logins, multi-factor authentication, and encryption on every device that touches patient data.
Train your team
Deliver HIPAA training at hire and refresh it at least once a year, covering phishing and password hygiene.
Test and update
Review the risk assessment and policies at least annually or after any major system change.
Training, Vendors, and Technical Safeguards Work Together
Written policies only reduce risk if staff actually follow them. Annual refreshers should cover phishing recognition, password hygiene, and what to do if a device is lost or stolen. Our breakdown of hipaa employee training requirements covers what a defensible program looks like, and hipaa security awareness training walks through how to structure ongoing refreshers rather than a one-time session.
On the technical side, a periodic what is a vulnerability assessment and why it matters on your network and EHR access helps confirm the safeguards you documented in your risk assessment are actually working, not just written down. Many chiropractic offices pair that with managed endpoint detection and response (EDR) to catch ransomware and unauthorized access attempts on office computers, since a single infected laptop can expose every patient record it can reach.
Key Takeaway
HIPAA compliance is not a one-time purchase or a single software feature. It is an ongoing program of a risk assessment, written policies, signed vendor agreements, trained staff, and tested technical safeguards, reviewed at least once a year.
Where Bellator Cyber Guard Fits
Bellator Cyber Guard's Bellator Core plan combines managed EDR, remote monitoring, and Ransomware Rollback® for $33 per computer per month, built for practices that need both day-to-day protection and a way to recover quickly if ransomware reaches an office computer. For practices that want endpoint protection without the added monitoring and rollback featuresBellator Shield covers managed EDR alone at $19 per computer per month. Neither plan replaces your written HIPAA policies or risk assessment, but both address the technical safeguards the Security Rule requires and reduce how much a ransomware or malware incident can affect patient data. Compare the two on the protection plans page, and see our broader overview of medical practice cybersecurity for how these pieces fit into a full compliance program.
Get a Free HIPAA Endpoint Security Review
Talk through your chiropractic practice's risk assessment gaps and technical safeguards with no pressure to buy.
Frequently Asked Questions
Yes. The HIPAA Security Rule requires every covered entity, including chiropractic practices, to conduct and document a risk assessment identifying where PHI is created, stored, and transmitted, and what could go wrong. There is no size exemption.
Yes. A single-provider office that bills insurance electronically or uses an EHR system is a covered entity under HIPAA regardless of staff count. The compliance obligations are the same; the workload of meeting them is usually lighter with fewer systems to document.
A Business Associate Agreement (BAA) is a written contract required whenever a vendor creates, receives, maintains, or transmits PHI on your behalf. Billing companies, EHR vendors, imaging services, and texting platforms that touch patient data all need a signed BAA before you share information with them.
HHS does not set a specific interval, but most compliance programs train new hires before they access PHI and refresh all staff at least once a year, or sooner after a policy change, a new system rollout, or a security incident.
From requirement to defensible practice
Turn HIPAA requirements into safeguards that fit patient care
A useful compliance path makes the obligation clear, identifies the evidence to retain, and connects written policy to the safeguards used every day.
People also look for
Keep exploring HIPAA security
Connect HIPAA requirements to the safeguards, assessments, and everyday decisions a healthcare practice can actually implement.
- Common question: HIPAA cybersecurity requirementsUse the plain-language HIPAA guideUnderstand administrative, physical, and technical safeguards without sorting through legal language.
- Common question: HIPAA security risk assessmentPrepare for a HIPAA risk assessmentIdentify vulnerabilities, document risk, and prioritize the gaps that matter most.
- Common question: HIPAA Security Rule explainedReview the HIPAA Security RuleSee how the standards and implementation specifications fit together.
- Common question: healthcare ransomware protectionReduce healthcare ransomware riskProtect patient data and keep clinical operations recoverable after an attack.
- Common question: HIPAA endpoint securityProtect practice workstations and devicesApply managed endpoint detection to the devices that access protected health information.


