A patient's attorney faxes a records request on a Tuesday. Your chiropractic assistant pulls the chart, emails a PDF from a personal Gmail account, and nobody logs the date. That one sequence touches four separate obligations, and it is the single most common way chiropractor HIPAA compliance falls apart in a small clinic.

This is a working guide for the person who signs the vendor contracts and answers the complaint letter — the owner-doctor, the office manager wearing the privacy officer hat, the compliance lead covering six locations. It covers what your practice must do, who inside the practice does it, on what deadline, and what the documented evidence looks like when someone asks to see it. No clinical advice, no theory.

First: Confirm You're a Covered Entity (Most Chiropractic Offices Are)

HIPAA does not apply to you because you are a healthcare provider. It applies because you are a healthcare provider who transmits health information electronically in connection with a HIPAA standard transaction — claims, eligibility checks, claim status, remittance advice, referral authorization.

If your office runs an electronic eligibility verification on a new patient, you are in. If a clearinghouse submits claims on your behalf, you are in. If a billing service does it for you, you are still in — the transaction is made on your behalf.

A genuinely cash-only practice that never touches a standard electronic transaction may fall outside HIPAA. That is rarer than owners think. Before you rely on it, check whether anyone in your office has ever run an insurance verification portal, submitted a superbill electronically, or billed a personal injury carrier through a payer portal. Also check your state's health information privacy statute and your chiropractic board's recordkeeping rules, which apply regardless of HIPAA status.

Documented evidence: a one-page memo in your compliance binder stating your covered entity determination, the transactions you conduct, and the date you last reviewed it. Sign it. Re-review annually.

What Does HIPAA Require of a Chiropractic Office?

A chiropractic practice that qualifies as a covered entity must, at minimum:

  • Name a Privacy Official and a Security Official in writing. Can be the same person. Can be the owner.
  • Conduct and document a security risk analysis covering every system that creates, receives, maintains, or transmits electronic PHI.
  • Maintain written policies and procedures for privacy, security, and breach notification — and retain them for six years.
  • Train every workforce member, including part-time CAs, massage therapists, and student interns, and keep signed training records.
  • Execute a Business Associate Agreement with every vendor that touches PHI before they touch it.
  • Post and distribute a Notice of Privacy Practices, and obtain a good-faith acknowledgment of receipt from each patient.
  • Respond to records requests within 30 days, with one 30-day extension available if you notify the patient in writing.
  • Notify affected individuals of a breach within 60 days of discovery, and report to HHS on the applicable timeline.
  • Apply sanctions to workforce members who violate your policies, and document that you did.

Everything below is the operational detail behind those nine lines.

The 30-Day Clock That Starts the Moment a Patient Asks for Their Chart

OCR's Right of Access Initiative has generated dozens of enforcement actions since 2019, and a striking share involved solo and small practices — the kind with one front-desk person and no formal intake log. Settlement amounts for small offices have frequently landed in the five figures, plus a corrective action plan and a monitoring period.

The rule: you have 30 calendar days from the request to provide access, in the form and format requested if you can readily produce it. One 30-day extension is allowed, but only if you tell the patient in writing within the original 30 days why you need it and when you will deliver. Read the HHS guidance on the individual right of access and keep a printed copy at the front desk.

Fees, and Where Chiropractic Offices Get It Wrong

You may charge a reasonable, cost-based fee for copies. HHS guidance also permits a flat fee of up to $6.50 for electronic copies of ePHI provided to the individual. You may not charge for search or retrieval time. You may not condition access on payment of an outstanding balance.

The attorney request is a different animal. A 2020 federal court decision narrowed the third-party directive rules, so records you send to an attorney at the patient's direction are not automatically capped at the patient rate. Train your staff to distinguish three request types: the patient asking for their own chart (right of access), the patient directing records to a third party, and a third party requesting records under a signed authorization. Different forms, different fees, different verification steps.

The Log That Ends the Argument

Keep a records request log with six columns: date received, requester, patient, what was requested, date fulfilled, and who fulfilled it. When OCR sends a data request letter, this log is your defense. Without it, you are arguing from memory against a patient with a screenshot of an unanswered email.

The Open Adjusting Bay: Incidental Disclosure Isn't a Free Pass

Chiropractic layout creates exposure that a primary care office doesn't have. Three tables in one room. A doctor discussing a lumbar film with one patient while another is six feet away. A front desk that faces the waiting area.

HIPAA permits incidental disclosures — but only if you have applied reasonable safeguards and limited disclosures to the minimum necessary. "That's just how our building is" is not a safeguard. Documented mitigation is.

Practical, defensible steps for an open-bay practice:

  • Lower your voice and move clinically detailed conversations — diagnoses, imaging findings, sensitive history — to a private room or a designated consultation corner.
  • Kill the sign-in sheet that lists reason for visit. A name-and-time sheet is generally acceptable; a symptom column is not.
  • Angle front-desk monitors away from the counter and set screensaver lock at two minutes.
  • Stop calling out balances, insurance denials, and treatment plans across the room. Hand a printed card instead.
  • Add background masking (music, white noise) near the adjusting area and note it in your safeguards policy.

Write these into a one-page "Physical and Verbal Safeguards" policy, have every staff member sign it, and revisit it whenever you change your floor plan.

Your Vendor List Is the Fastest Chiropractor HIPAA Compliance Audit You Can Run

Sit down with your bank statement and your credit card statement for the last twelve months. Circle every recurring charge. For each one, answer: does this vendor create, receive, maintain, or transmit PHI on our behalf?

In a typical chiropractic office, the yes list includes the practice management and EHR platform, the billing service or clearinghouse, the appointment reminder and two-way texting service, the online intake form provider, cloud backup and file storage, the IT support company with remote access, the shredding vendor, the answering service, the transcription service, the imaging archive, and often the review-request tool that pulls patient names and phone numbers.

Every one of those needs a signed Business Associate Agreement before PHI moves. A vendor's marketing page saying "HIPAA compliant" is not an agreement. Neither is a checkbox in a terms of service you clicked in 2021 and never saved. If you cannot produce a signed, dated PDF, you do not have a BAA.

If the gap is real — and after this exercise it usually is for two or three vendors — you can generate a signature-ready Business Associate Agreement through a six-step wizard and export it as PDF or DOCX for countersignature. One-time purchase, no subscription, which is the right shape for a practice that needs four agreements and not a platform.

Who Does Not Need a BAA

Your janitorial crew, provided they aren't handling records. The postal service and comparable conduits. Another treating provider you refer to — that's a provider-to-provider treatment disclosure, not a business associate relationship. Your malpractice carrier in most circumstances. Don't paper the world; paper the vendors who actually hold data.

The Security Risk Analysis Is Not Optional, and "We Use a Secure EHR" Isn't One

The Security Rule requires an accurate and thorough assessment of the risks and vulnerabilities to the confidentiality, integrity, and availability of your ePHI. It is the most frequently cited deficiency in OCR investigations of small providers, and it is the item most often missing entirely in a chiropractic office.

Your analysis must cover systems your vendors host, not just the desktop at the front counter: laptops, the tablet patients fill intake on, staff phones with the scheduling app installed, the imaging workstation, the backup drive in the supply closet, and anything a remote biller can reach.

Two references worth using: the free Security Risk Assessment Tool from ONC and OCR, and NIST SP 800-66r2, which maps Security Rule requirements to concrete controls. If you'd rather not assemble the risk analysis, policy set, and supporting documents by hand, tools that automate the HIPAA risk analysis and full compliance document set will get you to a defensible baseline faster than a blank Word file will.

Note the regulatory weather: HHS published a proposed rule in January 2025 to significantly strengthen the Security Rule, including tightening or removing the "addressable" flexibility that many small practices have leaned on. It is not final as of this writing. Build toward encryption, multi-factor authentication, and documented asset inventories now rather than waiting.

Documented evidence: a dated risk analysis report, a risk management plan listing each identified risk with an owner and a target date, and evidence you closed at least some of them. A risk analysis with no remediation log reads as a checkbox exercise.

Reviews, Testimonials, and Before-and-After Posts

OCR has settled cases against providers who disclosed patient information while responding to online reviews. The pattern is consistent: a patient leaves a negative review, the practice replies with treatment details to defend itself, and the reply is a disclosure without authorization.

Set the rule in writing and put one person in charge of it. You may respond generically — "Thank you for the feedback, please call the office so we can discuss" — and nothing more. You may not confirm that the reviewer is a patient. You may not reference visits, findings, or balances.

Patient testimonials and progress photos require a signed HIPAA authorization that names the specific use, the media, and an expiration. A generic intake consent does not cover marketing.

Breach Notification: Two Deadlines to Put on the Calendar Right Now

Discovery starts the clock. For a breach of unsecured PHI affecting 500 or more individuals, you notify affected individuals, HHS, and prominent media within 60 days of discovery. For breaches affecting fewer than 500, you still notify individuals within 60 days, but you report to HHS no later than 60 days after the end of the calendar year.

That means every small breach your practice discovered during 2025 must be submitted to HHS by March 1, 2026. If you have a running incident log — a lost laptop, a fax to the wrong number, an email to the wrong patient — schedule that submission now. You can see how reported breaches are published on the HHS breach portal.

Not every incident is a breach. Run the four-factor risk assessment — nature and extent of the PHI, who received it, whether it was actually acquired or viewed, and the extent of mitigation — and document your conclusion either way. A written determination that an incident posed a low probability of compromise is a legitimate outcome. An undocumented shrug is not.

A 60-Day Assignment Sheet for Your Practice

  1. Week 1 — Owner: Sign the written designation of Privacy Official and Security Official. Confirm covered entity status in a dated memo.
  2. Week 2 — Office manager: Build the vendor inventory from twelve months of statements. Mark every vendor with PHI access and whether a signed BAA exists.
  3. Weeks 3–4 — Privacy Official: Execute missing BAAs. Start the records request log. Replace any sign-in sheet that captures reason for visit.
  4. Weeks 4–6 — Security Official: Complete the security risk analysis. Produce a remediation plan with owners and dates. Enable MFA on email and the practice management system.
  5. Week 7 — Privacy Official: Run workforce training. Collect signatures. File them with the date and the material covered.
  6. Week 8 — Owner: Review the incident log. Submit any 2025 small-breach reports ahead of the March 1 deadline. Calendar the next annual review.

Strong chiropractor HIPAA compliance is not a binder you buy once. It is six or seven recurring habits with a named owner and a date attached to each. The practices that survive an investigation are rarely the ones with the most elaborate program — they are the ones that can produce a signed BAA, a dated risk analysis, a training roster, and a records log within 48 hours of the request letter.

If the vendor inventory turned up agreements you can't find, close that gap first — it's the fastest fix on the list. Build and export a signature-ready BAA for each vendor, get it countersigned, and file it where your Privacy Official can find it under pressure.