Do I need HIPAA forms for my physical therapy practice?
Usually yes. Your clinic needs HIPAA forms if it is a covered entity, and it becomes one when any claim, eligibility check, or remittance moves electronically, by you or by a billing service acting for you (45 CFR 160.103). Most insurance-billing PT clinics meet that test; a strictly cash practice may not.
Not sure which side you fall on? Walk the covered-entity test, profession by profession, then come back for the checklist below.
Researched and written by Larry Osakwe · Last verified July 15, 2026
Checked against the current 45 CFR text. Not a lawyer, not a certified compliance professional, and not affiliated with HHS.
The eight documents your PT clinic needs
This is the HIPAA compliance checklist for a physical therapy practice: the same document set every covered practice must be able to produce, flavored with the vendors and records a PT clinic actually has. Each item cites the rule that requires it, so you can verify any of it against the regulation.
Notice of Privacy Practices
The notice you give every patient, post in a clear and prominent place in your clinic, and publish on your website, describing how the practice uses and discloses patient information.
45 CFR § 164.520
NPP acknowledgment of receipt
The form documenting your good-faith effort to obtain each patient's written acknowledgment that they received the notice; it belongs in the intake packet at the initial evaluation.
45 CFR § 164.520(c)(2)
Patient authorization + rights request forms
The written-permission form for disclosures HIPAA does not already permit (attorneys, employers, workers'-comp case managers), plus request forms for access, amendment, restrictions, and an accounting of disclosures.
45 CFR § 164.508; §§ 164.522–164.528
Business Associate Agreements + vendor register
A signed BAA with every vendor that touches patient data, tracked in a register. For a PT clinic that typically means your EMR and billing platform (WebPT, Prompt, Jane), any outside billing service or clearinghouse, your telehealth platform, cloud backup, and email.
45 CFR § 164.502(e); § 164.504(e)
Security Risk Analysis
The documented, accurate and thorough assessment of risks to your electronic patient data across every system that holds it, not just the EMR: the most-cited deficiency in OCR enforcement.
45 CFR § 164.308(a)(1)(ii)(A)
Privacy & security policies with a training log
Your written rulebook for access, minimum-necessary use, and safeguards, plus documented workforce training and a sanctions policy, covering PTs, PTAs, techs, and the front desk.
45 CFR § 164.530(b); § 164.308(a)(5); § 164.316
Breach notification procedure + breach log
What to do when something goes wrong: notification without unreasonable delay and no later than 60 calendar days after discovery, plus your state's breach statute answered specifically.
45 CFR §§ 164.400–414
Privacy Official & Security Official designation
Names, in writing, the person responsible for your privacy policies and the person responsible for security; in a small clinic both are usually the owner.
45 CFR § 164.530(a); § 164.308(a)(2)
The full annotated table of contents, with what each document does and an honest binder-vs-software comparison, is on the HIPAA binder template page.
What your EMR covers, and what stays yours
“Our EMR is HIPAA compliant” is true and insufficient. The platform secures the data it holds; the documents HIPAA requires your practice to maintain are a separate layer, and no software subscription produces them for you.
| Your EMR (WebPT, Prompt, Jane) handles | Still yours to produce and maintain |
|---|---|
| Secures the ePHI inside its own system: encryption, access controls, audit logs | A Security Risk Analysis across every system that touches patient data: EMR, email, telehealth, backups, devices |
| Signs a BAA with you as one of your business associates | BAAs with every other vendor (billing service, telehealth, cloud, email), tracked in a vendor register |
| Handles claims, scheduling, and documentation workflows electronically | Your Notice of Privacy Practices, posted, published, and handed to patients, with acknowledgments on file |
| Carries its own breach obligations for incidents inside its platform | Your written policies, training log, sanctions policy, and a breach procedure covering the whole practice |
Is a physical therapy clinic a HIPAA covered entity?
Generally yes. A PT clinic becomes a covered entity when it transmits any covered transaction electronically (45 CFR 160.103): claims to insurance, Medicare, or Medicaid, electronic eligibility checks, or electronic remittance, whether you send them or a billing service sends them for you. Most insurance-billing clinics meet the test the day they open. The genuine exception is a strictly cash-based practice that never transmits a covered transaction, though that is harder to sustain than it sounds.
The covered-entity test, profession by professionDoes a cash-pay PT practice need HIPAA forms?
Possibly not, but confirm before assuming. A cash-based PT that never electronically transmits a covered transaction, and only hands patients paper documentation to self-submit, may fall outside HIPAA. The catch is Medicare: PTs generally cannot privately contract out of it, so treating Medicare-eligible patients can pull a cash practice back into electronic transactions. Document exactly whether and how you ever bill electronically, revisit the answer when your billing model changes, and remember state privacy laws apply either way.
Does WebPT (or any EMR) make my clinic HIPAA compliant?
No. WebPT, Prompt, Jane, and similar platforms are business associates: they sign a BAA and secure the data inside their systems, and that is real value. But no EMR supplies your Notice of Privacy Practices, your acknowledgment forms, your written policies, a Security Risk Analysis that covers your whole practice, your training log, or your breach procedure. The software handles the clinical data; the compliance documentation layer is yours. The table above shows exactly where the line sits.
How do I handle records for workers' comp and physician referrals?
Disclosures to referring physicians for treatment are generally permitted without a separate authorization. Releases to employers, workers'-comp insurers, and case managers usually require a signed patient authorization and the minimum-necessary standard, and workers' comp adds state-specific carve-outs. Because post-op and workers'-comp caseloads generate these requests constantly, your policies and Notice of Privacy Practices should spell out how they are handled, which is exactly what the authorization and rights forms in the checklist above exist for.
Don’t skip the training log
Two rules make training a documentation requirement, not a nice-to-have. The Privacy Rule (45 CFR 164.530(b)) requires you to train all members of your workforce on your privacy policies: new hires within a reasonable period after they join, and everyone affected within a reasonable period after a material policy change, with the training documented. The Security Rule (45 CFR 164.308(a)(5)) separately requires a security awareness and training program for the entire workforce, management included, with periodic security updates.
Neither rule names a fixed interval, so an annual all-hands pass, logged with names and dates, is how small practices evidence both: it catches new hires, refreshes everyone else, and pairs naturally with the annual review of your Security Risk Analysis. In a PT clinic the log must cover everyone who touches patient information, which means PTs, PTAs, techs, and the front desk, not just the owner.
Get the documents done
The PT binder
Every document above, built to order for your clinic, state, and software stack.
See the full template
The annotated binder table of contents, document by document.
Generate your NPP
Build your Notice of Privacy Practices now and see it before you pay.
See a sample first
Real excerpts from a delivered binder, citations included.
Sources
- www.ecfr.gov/current/title-45/subtitle-A/subchapter-C/part-160/subpart-A/section-160.103
- www.ecfr.gov/current/title-45/subtitle-A/subchapter-C/part-164/subpart-E/section-164.520
- www.ecfr.gov/current/title-45/subtitle-A/subchapter-C/part-164/subpart-C/section-164.308
- www.ecfr.gov/current/title-45/subtitle-A/subchapter-C/part-164/subpart-E/section-164.530
- www.cms.gov/priorities/key-initiatives/burden-reduction/administrative-simplification/hipaa/covered-entities
Last verified July 15, 2026. Educational self-help information, not legal advice and not a covered-entity determination for any specific practice. Whether HIPAA applies to your clinic turns on its actual billing arrangements; confirm with the sources above and, where appropriate, a qualified attorney. State law may add stronger requirements.
Every HIPAA document your PT clinic needs, done for you
The complete binder, built to order for your clinic and state, with every policy citing the rule that requires it.
See the PT binder and pricing