
A HIPAA risk assessment for physical therapy clinics is the written analysis required under 45 CFR § 164.308(a)(1) that identifies every system handling electronic protected health information (ePHI), the threats facing those systems, and the safeguards needed to bring risk to a reasonable level. Physical therapy practices handle unusually detailed clinical information, injury histories, functional assessments, imaging orders, and insurance authorizations, while typically running with administrative staff and IT budgets sized for a small business rather than a hospital system. According to HHS Office for Civil Rights enforcement data, a missing or incomplete risk analysis is cited in 68% of OCR investigations into small and mid-size healthcare providers. This guide walks through the inventory, threat identification, documentation, and reassessment steps a physical therapy clinic's risk assessment needs to cover.
Quick Answer
A HIPAA risk assessment for a physical therapy clinic covers five core steps: inventory every system and device that creates, stores, or transmits ePHI; identify realistic threats to that data such as phishing, lost devices, vendor access, and insider misuse; evaluate the safeguards already in place; rate each gap's likelihood and impact to assign a risk level; and document the findings in a written Risk Management Plan retained for at least six years under 45 CFR § 164.316(b)(2). Clinics should repeat or update the assessment at least annually and whenever they add a new vendor, system, or location.
Key Takeaway
- 45 CFR § 164.308(a)(1) requires every physical therapy clinic, regardless of size, to complete a written risk analysis covering all ePHI systems and vendors.
- A missing or incomplete risk analysis is cited in 68% of OCR investigations into small healthcare providers, according to HHS Office for Civil Rights enforcement data.
- An EHR vendor's compliance attestation does not satisfy a clinic's own risk analysis obligation.
- Risk assessments and the resulting Risk Management Plan must be retained for at least six years under 45 CFR § 164.316(b)(2).
- Adding a telehealth platform, a new vendor, or a clinic location is a trigger event that requires an updated assessment.
Physical therapy clinics are covered entities under HIPAA whenever they create, receive, maintain, or transmit ePHI. The HIPAA Security Rule, part of 45 CFR Part 164, Subpart C, requires every covered entity to complete an accurate and thorough risk analysis under 45 CFR § 164.308(a)(1). The HHS Office for Civil Rights (OCR), the federal agency that enforces HIPAA, has repeatedly cited incomplete or missing risk analyses as a primary driver of enforcement action against small and mid-size providers.
What makes PT clinics distinct is the combination of lean administrative staff, heavy third-party referral traffic, and clinical detail, injury histories, functional assessments, home exercise videos, that goes beyond a typical primary care note. Practices that refer to or receive referrals from urgent care clinics or chiropractic offices face comparable obligations under the same rule and should confirm those relationships are handled properly.
HIPAA Enforcement in Numbers
What Your Risk Analysis Must Cover Under 45 CFR § 164.308(a)(1)(ii)(A)
- Identify the scope of all ePHI the clinic creates, receives, maintains, or transmits
- Identify all reasonably anticipated threats to that ePHI
- Assess the security measures already in place
- Determine the likelihood and potential impact of each threat
- Assign a risk level to each identified vulnerability
- Document the process and retain that documentation
MythOur EHR vendor's HIPAA compliance certification covers our practice.
Our EHR vendor's HIPAA compliance certification covers our practice.
A vendor's attestation covers its own platform and infrastructure. Under 45 CFR § 164.308(a)(1), the clinic is separately required to assess risk across its full operating environment, including staff devices, email, and other vendors.
MythA free risk assessment template is enough for any physical therapy clinic.
A free risk assessment template is enough for any physical therapy clinic.
HHS's free Security Risk Assessment Tool at HealthIT.gov is a reasonable starting point for a single-location practice with simple systems, but clinics with multiple vendors, a telehealth platform, or several locations typically need a more detailed review to catch gaps a generic template misses.
How to Conduct the Assessment: Six Phases
Inventory Every ePHI System and Vendor
Document every system, device, and third party that creates, receives, stores, or transmits ePHI, including the EHR, billing platform, telehealth tool, portable devices, and vendors.
Identify Threats and Vulnerabilities
Catalog reasonably anticipated threats such as phishing, ransomware, lost or stolen devices, improper disposal, and insider misuse, and map each one to the specific systems in the inventory.
Assess Existing Safeguards
Document the technical, physical, and administrative controls already in place. Gaps where a control is absent, partial, or undocumented become the risk findings.
Assign Likelihood and Impact Ratings
Rate each threat-vulnerability pair on likelihood and potential impact to ePHI confidentiality, integrity, and availability, then combine the two to derive an overall risk level.
Document the Risk Management Plan
For every high and medium finding, record the remediation action, the responsible person, and a target completion date. Retain this documentation for at least six years.
Reassess Annually or After a Trigger Event
Repeat or update the assessment at least once a year, and immediately after adding a system, vendor, or location, or after a security incident.
Clinics often undercount their ePHI inventory because patient data moves through more systems than the EHR alone. Build the inventory first, since it sets the scope boundary for every later step in the assessment.
Systems and Locations to Include in Your ePHI Inventory
- EHR or practice management system
- Scheduling and appointment reminder tools that send SMS or email with visit details
- Billing software and insurance clearinghouse portals
- Telehealth platforms used for remote sessions
- Portable tablets and laptops carried between treatment rooms or off-site visits
- Shared front-desk workstations where intake forms and referral faxes are scanned
- Personal email accounts staff may use when the clinic system is unavailable
- Fax-to-email gateways receiving physician referrals and imaging results
- Third-party billing vendors or virtual front-desk services with remote system access
Healthcare threat analysis tends to focus on large hospital systems, but a PT clinic's size and operating model create a distinct threat profile. The 2024 Verizon Data Breach Investigations Report found that healthcare remains one of the most targeted sectors for ransomware, with system intrusion accounting for the largest share of incidents. For PT clinics, the most common entry point is a phishing email aimed at front-desk or billing staff, roles that routinely handle outside email from insurers, attorneys, and referring physicians, and a single compromised login can expose the entire EHR if multi-factor authentication (MFA), a login method requiring a second form of verification beyond a password, isn't enforced.
Lost and stolen devices are a separate risk. Therapists doing home health visits or working across locations often carry tablets, laptops, or phones with patient data, and physical theft of an unencrypted device is a reportable breach under HIPAA regardless of whether the data was ever opened.
Vendor risk and insider access round out the profile. Most PT clinics rely on three to five third parties that touch ePHI, an EHR vendor, billing service, clearinghouse, and often a telehealth platform or managed IT provider, and each one needs a signed Business Associate Agreement (BAA), a written contract required whenever a third party accesses or processes ePHI on a covered entity's behalf. Reviewing staff access against the minimum-necessary standard at 45 CFR § 164.514(d) and removing credentials promptly when someone leaves reduces the risk of an outdated account turning into an entry point.
Does Your Clinic Have These Physical Safeguard Gaps?
Tap the ones that sound like you.
Tap every statement that applies to you.
A risk assessment without documentation carries the same weight as no risk assessment at all; OCR investigators will ask for the written analysis, and an oral explanation of what was reviewed doesn't satisfy the requirement. Rate each identified gap on likelihood and potential impact to the ePHI confidentiality, integrity, and availability triad, then combine the two ratings to assign an overall risk level.
For every high and medium finding, record the specific vulnerability, the control selected to address it, the responsible person, and a target completion date. This record is the Risk Management Plan, and it demonstrates that the clinic treated its risk analysis as an ongoing process rather than a one-time document.
Six-Year Retention Requirement
Retain the completed risk assessment, the Risk Management Plan, and any related policies for at least six years from the date created or last in effect, whichever is later, under 45 CFR § 164.316(b)(2). This is the documentation OCR will request first in an audit or breach investigation.
Telehealth expanded quickly in physical therapy after 2020, and many clinics never formally assessed the platforms they adopted during that period. HHS's COVID-era telehealth enforcement discretion ended in 2023, so any platform used since then must meet the same technical safeguards as any other system that handles ePHI; the guide to HIPAA-compliant video conferencing for telehealth providers covers what that requires in practice.
The risk assessment should also cover remote work generally: whether therapists access the EHR from personal home networks or devices, and what controls, such as a VPN or mobile device management, reduce that exposure. Clinics should also confirm the telehealth platform is covered by a signed BAA before treating it as compliant.
Trigger Events That Require a New Risk Assessment
- Adding a new EHR, billing platform, or telehealth tool
- Onboarding a new IT vendor or managed service provider
- Opening a new location or adding home health services
- A workforce reduction or high-turnover period
- Any suspected or confirmed security incident
- A change in ownership or acquisition by a larger practice group
The Security Rule doesn't set a fixed reassessment interval; it requires the risk analysis to stay current. HHS guidance and OCR enforcement history point to an annual review as the practical minimum for most covered entities, with updates triggered by the events above.
Many cyber insurance policies now require evidence of a completed HIPAA risk assessment as a condition of coverage or renewal, which gives clinics an additional reason to keep the documentation current. Specific compliance determinations for a clinic's situation should be reviewed with legal counsel.
Schedule Your HIPAA Endpoint Review
Get a focused review of your clinic's endpoint security and ePHI safeguards against HIPAA Security Rule requirements.
Frequently Asked Questions
Yes. Physical therapy clinics that create, receive, maintain, or transmit ePHI are covered entities under HIPAA and must conduct a risk analysis under 45 CFR § 164.308(a)(1), regardless of clinic size or patient volume.
A missing risk analysis is one of the most commonly cited findings in OCR enforcement actions against small healthcare providers. Outcomes have ranged from corrective action plans to civil monetary penalties, including against solo practitioners and small group practices.
No. A vendor's compliance attestation covers its own platform. The clinic is separately responsible under the Security Rule for assessing risk across its full operating environment, including staff devices, email, and other vendors.
Any vendor that accesses or processes ePHI on the clinic's behalf needs a signed BAA. That typically includes the EHR vendor, billing service, clearinghouse, telehealth platform, managed IT provider, and any cloud storage service holding patient data.
A single-location clinic with a straightforward technology environment typically takes two to four weeks to complete a thorough assessment, including inventory, threat analysis, control review, risk rating, and documentation. Multiple locations or vendors extend that timeline.
HHS offers a free Security Risk Assessment Tool at HealthIT.gov designed for small and mid-size practices, and it's a reasonable starting point for a simple, single-location clinic. Clinics with multiple vendors, telehealth programs, or several locations typically need a more detailed review to catch gaps a generic template misses.
From requirement to defensible practice
Turn HIPAA requirements into safeguards that fit patient care
A useful compliance path makes the obligation clear, identifies the evidence to retain, and connects written policy to the safeguards used every day.
People also look for
Keep exploring HIPAA security
Connect HIPAA requirements to the safeguards, assessments, and everyday decisions a healthcare practice can actually implement.
- Common question: HIPAA cybersecurity requirementsUse the plain-language HIPAA guideUnderstand administrative, physical, and technical safeguards without sorting through legal language.
- Common question: HIPAA security risk assessmentPrepare for a HIPAA risk assessmentIdentify vulnerabilities, document risk, and prioritize the gaps that matter most.
- Common question: HIPAA Security Rule explainedReview the HIPAA Security RuleSee how the standards and implementation specifications fit together.
- Common question: healthcare ransomware protectionReduce healthcare ransomware riskProtect patient data and keep clinical operations recoverable after an attack.
- Common question: HIPAA endpoint securityProtect practice workstations and devicesApply managed endpoint detection to the devices that access protected health information.



