Do I need HIPAA forms for my chiropractic practice?
Usually yes. Your clinic needs HIPAA forms if it is a covered entity, and it becomes one when any claim, eligibility check, or remittance moves electronically, by you or by a billing service acting for you (45 CFR 160.103). Most chiropractors bill Medicare Part B and private insurers electronically, so most clinics meet the test.
Not sure which side you fall on? Walk the covered-entity test, profession by profession, then come back for the checklist below.
Researched and written by Larry Osakwe · Last verified July 15, 2026
Checked against the current 45 CFR text. Not a lawyer, not a certified compliance professional, and not affiliated with HHS.
The eight documents your chiropractic clinic needs
This is the HIPAA compliance checklist for a chiropractic practice: the same document set every covered practice must be able to produce, flavored with the vendors and records a chiropractic clinic actually has. Each item cites the rule that requires it, so you can verify any of it against the regulation.
Notice of Privacy Practices
The notice you give every patient, post in a clear and prominent place in your clinic, and publish on your website, describing how the practice uses and discloses patient information.
45 CFR § 164.520
NPP acknowledgment of receipt
The form documenting your good-faith effort to obtain each patient's written acknowledgment that they received the notice; it belongs in the intake packet at the first visit.
45 CFR § 164.520(c)(2)
Patient authorization + rights request forms
The written-permission form for disclosures HIPAA does not already permit (attorneys, auto insurers, case managers in personal-injury cases), plus request forms for access, amendment, restrictions, and an accounting of disclosures.
45 CFR § 164.508; §§ 164.522–164.528
Business Associate Agreements + vendor register
A signed BAA with every vendor that touches patient data, tracked in a register. For a chiropractic clinic that typically means your practice-management/EHR platform (ChiroTouch, Jane, ChiroFusion), any outside billing service or clearinghouse, imaging storage, cloud backup, and email.
45 CFR § 164.502(e); § 164.504(e)
Security Risk Analysis
The documented, accurate and thorough assessment of risks to your electronic patient data across every system that holds it, spinal X-rays and imaging included, not just the EHR: the most-cited deficiency in OCR enforcement.
45 CFR § 164.308(a)(1)(ii)(A)
Privacy & security policies with a training log
Your written rulebook for access, minimum-necessary use, and safeguards, plus documented workforce training and a sanctions policy, covering the DCs, chiropractic assistants, billing staff, and the front desk.
45 CFR § 164.530(b); § 164.308(a)(5); § 164.316
Breach notification procedure + breach log
What to do when something goes wrong: notification without unreasonable delay and no later than 60 calendar days after discovery, plus your state's breach statute answered specifically.
45 CFR §§ 164.400–414
Privacy Official & Security Official designation
Names, in writing, the person responsible for your privacy policies and the person responsible for security; in a small clinic both are usually the owner.
45 CFR § 164.530(a); § 164.308(a)(2)
The full annotated table of contents, with what each document does and an honest binder-vs-software comparison, is on the HIPAA binder template page.
What your EHR covers, and what stays yours
“Our EHR is HIPAA compliant” is true and insufficient. The platform secures the data it holds; the documents HIPAA requires your practice to maintain are a separate layer, and no software subscription produces them for you.
| Your EHR (ChiroTouch, Jane, ChiroFusion) handles | Still yours to produce and maintain |
|---|---|
| Secures the ePHI inside its own system: encryption, access controls, audit logs | A Security Risk Analysis across every system that touches patient data: EHR, imaging, email, backups, devices |
| Signs a BAA with you as one of your business associates | BAAs with every other vendor (billing service, clearinghouse, cloud, email), tracked in a vendor register |
| Handles claims, scheduling, SOAP notes, and documentation workflows electronically | Your Notice of Privacy Practices, posted, published, and handed to patients, with acknowledgments on file |
| Carries its own breach obligations for incidents inside its platform | Your written policies, training log, sanctions policy, and a breach procedure covering the whole practice |
Do chiropractors have to comply with HIPAA?
Generally yes. Chiropractic billing is heavily insurance-driven, and Medicare covers manual spinal manipulation, so most chiropractors transmit electronic claims to insurers or Medicare and are covered entities under 45 CFR 160.103. A genuine cash-only or membership practice that never files electronically, and gives patients only paper superbills, may fall outside HIPAA. The trap: a cash or membership practice can still be covered if its EHR or billing service transmits even one covered transaction. Confirm before assuming.
The covered-entity test, profession by professionDoes a cash-only chiropractic practice need HIPAA forms?
Possibly not, but confirm before assuming. A cash or membership practice that never electronically transmits a covered transaction, and only hands patients paper superbills to self-submit, may fall outside HIPAA. The catch is how easily the test gets tripped without an obvious decision point: an EHR that runs electronic eligibility checks, a billing service that files the occasional claim, or a single electronically billed Medicare patient each makes you a covered entity, and the rules then cover all your patient information in any form. Document exactly whether and how you ever bill electronically, revisit the answer when your billing model changes, and remember state privacy and records laws apply either way.
Does ChiroTouch or Jane make my practice HIPAA compliant?
No. ChiroTouch, Jane, ChiroFusion, and similar platforms are business associates: they sign a BAA and secure the data inside their systems, and that is real value. But no EHR supplies your Notice of Privacy Practices, your acknowledgment forms, your written policies, a Security Risk Analysis that covers your whole practice, your training log, or your breach procedure. The software handles the clinical data; the compliance documentation layer is yours. The table above shows exactly where the line sits.
How do I handle records for personal-injury and auto-accident cases?
Releases to attorneys, auto insurers, and case managers generally require a signed patient authorization and the minimum-necessary standard; disclosures to other treating providers are generally permitted without one. Because personal-injury and motor-vehicle-accident caseloads generate these third-party requests constantly, your policies and Notice of Privacy Practices should spell out how they are handled, which is exactly what the authorization and rights forms in the checklist above exist for. The spinal X-rays and imaging that anchor those cases are PHI too, so they belong inside your Security Risk Analysis wherever they are stored.
Don’t skip the training log
Two rules make training a documentation requirement, not a nice-to-have. The Privacy Rule (45 CFR 164.530(b)) requires you to train all members of your workforce on your privacy policies: new hires within a reasonable period after they join, and everyone affected within a reasonable period after a material policy change, with the training documented. The Security Rule (45 CFR 164.308(a)(5)) separately requires a security awareness and training program for the entire workforce, management included, with periodic security updates.
Neither rule names a fixed interval, so an annual all-hands pass, logged with names and dates, is how small practices evidence both: it catches new hires, refreshes everyone else, and pairs naturally with the annual review of your Security Risk Analysis. In a chiropractic clinic the log must cover everyone who touches patient information, which means the DCs, chiropractic assistants, billing staff, and the front desk, not just the owner. If your clinic shares one record system with massage therapists or other providers, they belong in the log too.
Get the documents done
The chiropractic binder
Every document above, built to order for your clinic, state, and software stack.
See the full template
The annotated binder table of contents, document by document.
Generate your NPP
Build your Notice of Privacy Practices now and see it before you pay.
See a sample first
Real excerpts from a delivered binder, citations included.
Sources
- www.ecfr.gov/current/title-45/subtitle-A/subchapter-C/part-160/subpart-A/section-160.103
- www.ecfr.gov/current/title-45/subtitle-A/subchapter-C/part-164/subpart-E/section-164.520
- www.ecfr.gov/current/title-45/subtitle-A/subchapter-C/part-164/subpart-C/section-164.308
- www.ecfr.gov/current/title-45/subtitle-A/subchapter-C/part-164/subpart-E/section-164.530
- www.ecfr.gov/current/title-42/chapter-IV/subchapter-B/part-410/subpart-B/section-410.21
- www.cms.gov/priorities/key-initiatives/burden-reduction/administrative-simplification/hipaa/covered-entities
Last verified July 15, 2026. Educational self-help information, not legal advice and not a covered-entity determination for any specific practice. Whether HIPAA applies to your clinic turns on its actual billing arrangements; confirm with the sources above and, where appropriate, a qualified attorney. State law may add stronger requirements.
Every HIPAA document your chiropractic clinic needs, done for you
The complete binder, built to order for your clinic and state, with every policy citing the rule that requires it.
See the chiropractic binder and pricing