Medcurity Get Compliant Now

HIPAA for Chiropractors: Complete Compliance Guide

Last updated: March 2026 | 11 min read

Quick Answer

Chiropractors are covered entities under HIPAA if they bill insurance, Medicare, Medicaid, or maintain electronic health records. They must protect all patient information including treatment records, medical histories, X-rays, and payment information. Key requirements include written privacy policies, secure EHR systems, patient authorization for disclosures, secure storage of X-rays and imaging, Business Associate Agreements with vendors, and breach notification procedures.

HIPAA Applicability for Chiropractic Practices

When HIPAA Applies to Chiropractors

HIPAA requirements apply if your chiropractic practice meets any of these criteria:

• You bill insurance (commercial, PPO, HMO)
• You bill Medicare or Medicaid
• You maintain electronic health records (EHR software)
• You transmit patient information electronically (email, fax, electronic billing)
• You use practice management software to store patient data
• You have staff who handle patient information

Private Cash-Only Practices

A purely cash-only chiropractic practice with only paper records might not be covered by HIPAA. However:

• If you use any electronic storage (computers, phones, email), HIPAA likely applies
• Many state chiropractic boards require HIPAA compliance regardless
• Your malpractice insurance likely requires HIPAA compliance

Even cash practices should assume HIPAA applies and implement protections.

Group Practices and Multi-Location Practices

All sizes of chiropractic practices are covered entities. Group practices must:

• Appoint a Privacy Officer
• Train all staff on HIPAA
• Implement access controls for each location
• Maintain separate breach response procedures for each location (if needed)

Chiropractic-Specific HIPAA Requirements

Protected Health Information in Chiropractic Care

In chiropractic practices, protected information includes:

• Patient name, address, phone, email
• Diagnosis and treatment information (subluxations, adjustments)
• Medical history and prior injuries
• Diagnostic imaging (X-rays, MRI, CT scans)
• Treatment plans and progress notes
• Insurance information and billing records
• Reason for visit and symptoms reported

X-Ray and Imaging Storage

Digital X-Rays: Must be stored on encrypted servers with:

• Access restricted to authorized chiropractors/staff
• Audit logs tracking who accessed each image
• Encrypted backup systems
• Regular security updates and patches
• Secure deletion after appropriate retention periods

Physical X-Ray Films: Must be stored in:

• Locked, secure areas
• Access limited to authorized staff
• Documented chain of custody if transferred
• Proper disposal through medical waste services (if destroying)

X-Ray Transfer and Release

When transferring X-rays to other providers:

• Obtain written authorization from the patient
• Use secure transfer methods (encrypted email, secure portal, hand delivery)
• Do not use unencrypted email or unsecured file sharing
• Document the transfer (who received, when, what was sent)
• Include release restrictions if requested by patient

Patient Request for Records

Patients have the right to request copies of their records. Chiropractors must:

• Provide access within 30 calendar days
• Provide in patient's requested format (digital, paper, etc.)
• Include all treatment notes, X-rays, and diagnostic reports
• Charge only reasonable copying/administrative costs
• Provide at no cost if required by state law

Privacy Requirements for Chiropractic Practices

Notice of Privacy Practices

Chiropractors must provide written Notice of Privacy Practices (NPP) explaining:

• How treatment information is used and disclosed
• Patient rights (access, amendment, accounting of disclosures)
• Practice contact information for privacy questions
• How complaints can be filed
• State-specific privacy rights (if applicable)

Patients must sign acknowledgment of NPP before treatment.

Permitted Disclosures Without Authorization

Patient information can be disclosed without explicit consent for:

• Treatment (referrals to physical therapists, MDs, etc.)
• Payment (billing insurance, follow-up on claims)
• Healthcare operations (scheduling, staff training, quality improvement)

Disclosures Requiring Written Authorization

Must have written authorization before disclosing to:

• Employers (for workers' compensation)
• Attorneys (for legal proceedings)
• Insurers beyond treatment/payment (marketing, etc.)
• Family members (even with implied permission)
• Third-party mediators or consultants

Court Orders and Subpoenas

Chiropractors can disclose records when legally required by:

• Court order issued by a judge
• Valid subpoena (with notice to patient when possible)
• Workers' compensation board request
• Law enforcement warrant or legal process

Do not automatically comply with administrative subpoenas - verify legitimacy first.

Security Safeguards for Chiropractic Practices

Administrative Safeguards

Designate a Privacy Officer responsible for:

• HIPAA compliance and policy enforcement
• Staff training and confidentiality agreements
• Business Associate management
• Breach response and notification
• Security risk assessments

Physical Safeguards

Secure physical access to patient records:

• Locked file cabinets for paper records
• Limited staff access to record storage
• Secure disposal (shredding) of old records
• Reception area positioned to prevent unauthorized viewing
• Treatment area privacy (curtains, doors)
• Computers positioned away from public view

Technical Safeguards

Secure all electronic systems:

• EHR software with automatic logoff after inactivity
• Strong passwords (12+ characters, updated regularly)
• Encryption for stored data and email containing PHI
• Firewall and antivirus on all computers
• Regular software updates and security patches
• Regular backups of data with encryption
• Audit logs tracking user access and changes
• Two-factor authentication for sensitive systems

Business Associates for Chiropractors

Common Business Associates in Chiropractic

You must have BAAs with vendors handling patient information:

• EHR/practice management software vendors
• Medical billing and insurance claims processors
• Cloud backup and storage providers
• IT support and managed service providers
• Answering services and appointment schedulers
• Medical record retrieval services
• Shredding and document destruction services

BAA Requirements

Each BAA must specify:

• Permitted uses and disclosures of PHI
• Data safeguard requirements
• Breach notification obligations
• Subcontractor management
• Audit and access rights
• Record destruction obligations

Frequently Asked Questions

Can I text appointment reminders to patients?

Yes, if you only include the patient's name and appointment time/date. Do not include diagnosis, treatment details, or other health information in text messages. If a patient requests appointments via unsecured text, still send only minimal information. Consider using HIPAA-compliant appointment reminder services instead.

What if my EHR vendor has a data breach?

You are responsible for notifying patients even if your vendor had the breach. The vendor should notify you immediately. You must assess risk, notify affected patients within 60 days, notify HHS, and notify media (if 500+ affected). Document everything. Work with your vendor to determine root cause and prevent future breaches.

How long should I keep patient chiropractic records?

Recommended minimum is 5-6 years from last treatment. Many states require longer. Check your state's chiropractic board regulations and your malpractice insurance policy. Minors' records should be kept longer (until age of majority plus 5-7 years). X-rays may have different retention requirements due to radiation exposure documentation.

Can I share X-rays on unsecured email?

No. Never send X-rays, diagnostic images, or any PHI via unencrypted email. Use encrypted email services, secure patient portals, or secure file transfer services. If you must email images, use end-to-end encryption and ensure the recipient has proper authorization from the patient.

Secure Your Chiropractic Practice with HIPAA Compliance

Chiropractic practices handle sensitive patient information and diagnostic imaging that requires careful protection. Medcurity helps chiropractors implement secure systems, protect X-rays and patient records, and develop compliance strategies for multi-location practices.

Get Your Practice Compliant Today