Medcurity Get Compliant Now

HIPAA for Acupuncturists: Alternative Medicine Compliance Guide

Last updated: March 2026 | 10 min read

Quick Answer

Acupuncturists are covered by HIPAA if they bill insurance (medical or acupuncture insurance), Medicare, Medicaid, maintain electronic health records, or transmit patient information electronically. Even in states where acupuncture is not licensed as a medical profession, insurance billing triggers HIPAA coverage. Key requirements include privacy policies, secure records systems, patient consent, confidentiality agreements with staff, Business Associate Agreements with vendors, and breach notification procedures. Many states also have acupuncture-specific confidentiality requirements.

When HIPAA Applies to Acupuncturists

HIPAA Coverage Triggers

Acupuncturists must comply with HIPAA if ANY of these apply:

• Insurance billing (medical, acupuncture-specific, or wellness plans)
• Medicare or Medicaid billing
• Electronic health records (EHRs) or practice management software
• Any electronic transmission of patient information
• Licensed acupuncturist in a state recognizing acupuncture as healthcare

Licensed vs. Non-Licensed Acupuncturists

Licensed Acupuncturists (LAc): In states with acupuncture licensure (most states), acupuncturists are regulated as healthcare providers. Licensed acupuncturists billing any insurance almost certainly trigger HIPAA coverage.

Non-Licensed Practitioners: In states without specific acupuncture licensure, acupuncturists still must comply with HIPAA if they bill insurance or use electronic records, as they are providing healthcare services.

Insurance Billing Triggers HIPAA

Any insurance billing for acupuncture services triggers HIPAA, including:

• Medical insurance (billing for pain management, musculoskeletal conditions)
• Acupuncture-specific insurance plans
• Wellness plan coverage
• Workers' compensation
• Even if some patients pay cash

Cash-Only Practices

A purely cash-only acupuncture practice with only paper records might not be HIPAA-covered. However:

• Using any electronic records triggers HIPAA
• Many states require HIPAA compliance for licensed acupuncturists
• Professional ethics support implementing HIPAA protections

When in doubt, assume HIPAA applies.

Protected Information in Acupuncture Practices

What Must Be Protected

Under HIPAA (if applicable), the following information must be protected:

• Patient name and contact information
• Chief complaint and reason for treatment
• Medical history and past illnesses
• Current medications and supplements
• Allergies and sensitivities
• Acupuncture assessment (pulse, tongue, palpation findings)
• TCM diagnosis and pattern differentiation
• Acupuncture points used and treatment details
• Frequency of treatment and treatment plan
• Treatment outcomes and progress notes
• Herbal medicine recommendations
• Insurance information and billing records
• Payment information

TCM-Specific Documentation

Acupuncture records often include traditional Chinese medicine assessments that are distinct from conventional medical documentation:

• Yin/Yang assessment and imbalances
• Qi and Blood stagnation patterns
• Meridian assessment and blockages
• Tongue and pulse findings
• Element theory associations

These assessments are legitimate medical documentation and are protected under HIPAA just like conventional diagnoses.

Sensitive Information Considerations

Acupuncture treatment may relate to sensitive conditions:

• Fertility and reproductive health
• Mental health and emotional states
• Sexual dysfunction
• Addiction and substance abuse treatment

These sensitive conditions require extra confidentiality protections and careful handling of information.

HIPAA Compliance Requirements for Acupuncturists

Privacy Policy and Notice

If HIPAA applies, develop a Notice of Privacy Practices explaining:

• How treatment information is used and disclosed
• Patient rights under HIPAA
• Confidentiality practices
• How to request records or file complaints

Secure Records Systems

Electronic records must be:

• Stored on encrypted systems
• Accessible only to authorized staff
• Backed up securely with encryption
• Subject to regular security assessments
• Properly deleted using secure erasure methods

Physical Record Security

Paper records must be:

• Stored in locked file cabinets
• Accessible only to authorized staff
• Shredded or securely destroyed when no longer needed
• Not left visible to waiting patients

Patient Access Rights

Acupuncturists must provide patient access to records within 30 days of request. This includes:

• Treatment notes and progress reports
• TCM assessments and treatment plans
• Herbal recommendations
• Any provider communications about the patient

Referral and Consultation Coordination

When coordinating with other providers (MDs, physical therapists, etc.):

• Get written patient authorization before sharing records
• Share only information relevant to coordinated care
• Use secure methods for transmission
• Document what was shared and to whom

Staff Training and Confidentiality

All staff must:

• Sign confidentiality agreements
• Receive training on HIPAA requirements
• Understand restrictions on discussing patients
• Know procedures for handling patient information

Business Associates and Vendors

Business Associate Agreements Required

Acupuncture practices must have Business Associate Agreements with:

• EHR/practice management software vendors
• Insurance billing companies
• Cloud storage providers (if storing PHI)
• IT support and managed service providers
• Answering services or appointment schedulers

Herbal Medicine and Supplement Vendors

If acupuncturists sell herbal medicines or supplements:

• Supplier information about products is not PHI
• Patient herbalism records are protected
• If suppliers access patient information (for custom formulations), BAA may be needed

State-Specific Acupuncture Regulations

Additional State Protections

Many states with acupuncture licensure have their own privacy protections beyond HIPAA. Check your state's acupuncture board regulations for:

• Specific confidentiality requirements
• Record retention periods
• Patient access rights
• Specific disclosure restrictions

Workers' Compensation Considerations

If treating workers' compensation cases:

• Obtain authorization to report to workers' comp carrier
• Understand workers' comp disclosure requirements
• Maintain separate privacy protections even with required reporting

Frequently Asked Questions

Can I discuss acupuncture treatment with family members?

Not without written patient authorization. Even if a family member brings the patient, you cannot discuss treatment details, diagnoses, or recommendations without consent. Get authorization forms signed by patients at their first visit if they want family members to be informed.

How long should I keep acupuncture patient records?

Check your state's acupuncture board requirements - many specify 3-5 years from last treatment. Some require longer retention for minors. Keep records longer if litigation is possible. When records are no longer needed, shred paper records and securely delete electronic records.

Can I email treatment recommendations to patients?

Only via encrypted email or secure patient portals. Never send treatment information, diagnoses, or medical recommendations via unencrypted email. If patients request email communication, establish secure methods or ask them to visit to discuss recommendations.

What if my acupuncture practice has a data breach?

If patient identifying information and treatment information were exposed, notify patients within 60 days (or per your state's requirements), notify HHS, and notify media (if 500+ residents affected). Document everything. Work with IT to understand what was breached, implement corrections, and prevent future breaches.

Protect Your Acupuncture Practice with Proper Privacy Compliance

Acupuncturists treating patients for sensitive health conditions need robust privacy protections. Whether subject to HIPAA or state acupuncture regulations, Medcurity helps acupuncture practices develop secure systems, implement confidentiality procedures, and comply with both federal and state requirements.

Get Your Practice Compliant Now