HIPAA Compliance by Vertical
HIPAA Compliance for Physical Therapy Clinics
HIPAA compliance for physical therapy clinics — referral PHI flows, exercise/biomechanics platforms, and the home exercise app vendor sprawl.
By the Shieldra Compliance Team · Last updated July 2026
Key takeaways
- PHI in scope: Referrals from primary care and orthopedic providers, Initial evaluation and progress notes, Insurance authorization and claims data, Home exercise program assignments and patient compliance data.
- Start with these controls: BAA-covered referral channels (no personal email); BAA with home exercise platform vendor; BAA with insurance pre-auth TPA.
- The most common mistake: Personal email used for referral coordination
- A signed BAA is required with every vendor that touches PHI, and no tool is HIPAA compliant on its own.
PHI handled in this environment
- Referrals from primary care and orthopedic providers
- Initial evaluation and progress notes
- Insurance authorization and claims data
- Home exercise program assignments and patient compliance data
- Outcome measures and re-evaluation data
Common compliance pain points
- Referral fax and email sprawl: PT referrals come in via fax, email, EHR direct messaging, and paper. Each channel needs to be either BAA-covered or designed to not contain PHI. Many clinics still use personal email for referral coordination.
- Home exercise platform integrations: Modern PT clinics push exercise programs to patients via apps (Medbridge, PT Wired, etc.). These platforms receive PHI and need BAAs. Clinics often skip the BAA step because the integration "just works."
- Insurance pre-authorization workflows: Pre-auth involves transmitting PHI to insurance third-party administrators. Each TPA may or may not have a BAA on file. Verify before sending or assume violation.
- Patient outcome data for marketing: Outcome stories and testimonials are powerful marketing — and a HIPAA trap. Patient authorization for marketing use must be specific, written, and revocable.
Priority controls
- BAA-covered referral channels (no personal email)
- BAA with home exercise platform vendor
- BAA with insurance pre-auth TPA
- Documented patient marketing authorization policy
- Encrypted fax (or no fax)
- Annual workforce HIPAA training tailored to PT-specific scenarios
Common mistakes
- Personal email used for referral coordination
- Home exercise app vendor in production without a BAA
- Marketing testimonials posted without specific written patient authorization
- Faxing PHI to unencrypted office fax machines
- No documented Privacy Officer appointment
Enforcement context
PT clinics often operate as independent practices, which puts them in OCR's small-practice enforcement bucket. Settlements typically arise from patient complaints (records access, marketing without authorization) and from missed BAAs with vendors. The 2026 Security Rule update raises baseline technical requirements regardless of practice size.
Frequently asked questions
What PHI do physical therapy clinic organizations handle?
Referrals from primary care and orthopedic providers; Initial evaluation and progress notes; Insurance authorization and claims data; Home exercise program assignments and patient compliance data; Outcome measures and re-evaluation data. Any of these, combined with an identifier, is protected health information and brings the full Security Rule into scope.
What are the priority HIPAA controls for physical therapy clinic?
BAA-covered referral channels (no personal email); BAA with home exercise platform vendor; BAA with insurance pre-auth TPA; Documented patient marketing authorization policy; Encrypted fax (or no fax); Annual workforce HIPAA training tailored to PT-specific scenarios.
What are the most common HIPAA mistakes in physical therapy clinic?
Personal email used for referral coordination; Home exercise app vendor in production without a BAA; Marketing testimonials posted without specific written patient authorization; Faxing PHI to unencrypted office fax machines; No documented Privacy Officer appointment.
What does HIPAA enforcement look like for physical therapy clinic?
PT clinics often operate as independent practices, which puts them in OCR's small-practice enforcement bucket. Settlements typically arise from patient complaints (records access, marketing without authorization) and from missed BAAs with vendors. The 2026 Security Rule update raises baseline technical requirements regardless of practice size.