HIPAA Compliance for Chiropractic Offices: What OCR Actually Checks
The Office for Civil Rights audits look nothing like the compliance seminars you've attended. Here's exactly what investigators examine when they open a chiropractic practice — and the gaps they find most often.
Most chiropractic offices prepare for HIPAA audits the wrong way. They spend a Saturday updating their Notice of Privacy Practices, print a new copy for the front desk, and consider themselves covered.
Then OCR shows up — or, more commonly, a patient complaint triggers a compliance review — and investigators ask for documents that don't exist: training logs, risk assessment records, Business Associate Agreements for vendors you've been using for years. The NPP sitting on the counter turns out to be the least of your problems.
This guide walks through what OCR's audit protocol actually covers, where chiropractic offices consistently fall short, and what documentation you need to survive a review without a corrective action plan (CAP) or a civil monetary penalty.
What triggers an OCR investigation in a chiropractic office?
OCR receives complaints, conducts random desk audits under its ongoing audit program, and opens investigations after breach notifications. In chiropractic, the most common triggers are:
- A former patient files a complaint about a perceived disclosure — often a scheduling conversation overheard in an open bay
- A breach notification after a lost laptop, stolen phone, or misdirected fax containing patient records
- A personal injury attorney requests records and the release process is mishandled
- A disgruntled ex-employee files a complaint about internal access controls
- Your practice is selected for OCR's random desk audit program
Random audits and complaint-driven investigations follow the same protocol. OCR will request a defined set of documentation — typically within 10 days — and your ability to produce it quickly is itself evidence of your compliance posture.
The OCR Audit Protocol: 8 areas that apply directly to chiropractic
OCR's audit protocol is publicly available and covers 180 audit elements across the Privacy Rule, Security Rule, and Breach Notification Rule. For a typical chiropractic office, these eight areas carry the most weight.
1. Workforce training — the most commonly cited gap
HIPAA requires that all workforce members receive training on your policies and procedures. "Workforce" is broader than you might expect: it includes full-time staff, part-time staff, volunteers, and students on clinical rotation.
What OCR asks for:
- Training logs with specific dates, staff names, and topics covered
- Evidence that training happened when policies changed
- Training records for new hires (must occur within a reasonable timeframe of hire)
- Proof that training content was relevant to each employee's role
The 'we covered it at the staff meeting' problem
2. Notice of Privacy Practices — content and distribution
Most chiro offices have an NPP. What they often miss:
- The NPP must include your practice's contact information for complaints
- You must make a good-faith effort to obtain a written acknowledgement of receipt from each patient
- Those acknowledgements must be retained for six years
- The NPP must be posted in a clear and prominent location and on your website (if you have one)
- Your actual practices must match what the NPP says
3. Open treatment areas — the chiropractic-specific exposure
Open adjusting bays are where most chiropractic practices differ from general medical offices — and where OCR applies specific analysis.
HIPAA's "incidental use and disclosure" standard acknowledges that some PHI exposure is unavoidable in healthcare settings. But the standard requires that you implement reasonable safeguards. For open-bay chiropractic offices, this means:
- Training staff on keeping voices lowered when discussing diagnoses or treatment plans
- Using patient numbers or first names only in open areas when possible
- Positioning treatment tables so that a patient's paperwork isn't visible to others
- Documenting that you've assessed this risk and implemented controls
Document the risk assessment, not just the fix
4. Personal injury records — high-risk disclosures
Chiropractic offices treating motor vehicle accident and workers' compensation patients handle one of HIPAA's most legally complex disclosure types: records released to attorneys, insurance adjusters, and third-party payers.
OCR commonly finds deficiencies in:
- Releasing records to PI attorneys without a valid patient authorization
- Failing to apply the minimum necessary standard to attorney record requests
- Releasing records that include information from other providers without authorization
- Not tracking which records were released, to whom, and under what authority
Every PI record release should be documented in a disclosure log that includes the date, recipient, description of PHI disclosed, and the legal basis for disclosure (authorization, court order, or legal requirement). OCR will ask for this log.
5. Business Associate Agreements
Any vendor who handles your patient data on your behalf is a Business Associate and must have a signed BAA before they touch PHI. Common chiropractic vendors that require BAAs:
- Your practice management / EHR software vendor
- Your billing service or billing software
- Your transcription service
- Your document shredding company
- Your IT support company (if they ever access systems with patient data)
- Any cloud storage service used for patient records (including Google Drive, Dropbox)
- Your patient portal provider
Verbal agreements don't count
6. Risk analysis — the most missed requirement
The Security Rule requires a comprehensive risk analysis that identifies potential threats to the confidentiality, integrity, and availability of electronic PHI (ePHI). OCR's own audits found this is the single most commonly missing element across all covered entities.
A risk analysis for a chiropractic office should cover:
- Every system and device that stores or transmits patient data
- Potential threats to each system (theft, malware, unauthorized access, hardware failure)
- Current controls for each threat and whether they are adequate
- Residual risk and a remediation plan for unacceptable risks
This doesn't require an IT firm or a lengthy technical document. A thorough spreadsheet that walks through your systems, threats, and controls satisfies the requirement if it's updated annually and after significant changes.
7. Access controls and minimum necessary standard
Every staff member should only have access to the PHI they need to do their job. Front desk staff generally don't need access to clinical notes. Billers don't need access to psychotherapy records. OCR will ask:
- How is access to your EHR or practice management system controlled?
- How do you revoke access when an employee is terminated?
- Do you have unique login credentials for each user, or do you share passwords?
- What is your policy on workforce members accessing PHI from personal devices?
8. Breach notification procedures
Your staff need to know what to do when they suspect a breach — and they need to know to report it internally immediately. The 60-day notification clock starts when the breach is discovered, not when it's reported to you. Delayed internal reporting that causes you to miss the 60-day window is a separate HIPAA violation on top of the breach itself.
Your breach notification procedure should cover:
- Who staff should notify immediately upon suspecting a breach
- How you assess whether a breach is reportable (the four-factor test)
- The 60-day notification timeline for OCR and affected patients
- How you document breach investigations and your risk assessment
What investigators actually find in chiropractic offices
Based on OCR resolution agreements and published audit findings, these are the deficiencies that appear most often in small-to-mid-size chiropractic practices:
Common findings
No formal risk analysis
Required by the Security Rule; often missing entirely
Incomplete training records
Staff trained verbally or informally, no documentation
Missing or unsigned BAAs
Billing vendors, IT companies, cloud services
No disclosure log for PI records
Required when releasing records to attorneys/insurers
Shared login credentials
Multiple staff using the same EHR password
PHI on personal devices
No written policy; no mobile device management
Terminated employee access
EHR access not revoked within 24–48 hours
What "corrective action" looks like — and why you want to avoid it
When OCR finds violations, they issue a Corrective Action Plan. CAPs typically require the practice to:
- Complete a full risk analysis within 60 days
- Submit updated policies and procedures for OCR review and approval
- Train all staff and submit training documentation
- Submit compliance reports to OCR for one to three years
- Maintain OCR oversight for the duration of the agreement
The oversight burden alone — preparing quarterly reports for OCR, maintaining meticulous documentation, managing the relationship — is significant for a small practice. And CAPs don't prevent civil monetary penalties for willful neglect: those can reach $50,000 per violation category, per year.
The documentation stack you need before OCR knocks
If you received an OCR records request tomorrow, you should be able to produce these within 10 days:
- Training logs: name, date, topics covered, for every current and recent staff member
- Your current Notice of Privacy Practices and patient acknowledgements (6-year retention)
- Signed Business Associate Agreements for every qualifying vendor
- A current risk analysis document covering all systems that store or transmit ePHI
- Your written HIPAA policies and procedures
- An accounting of disclosures log for PI and non-routine record releases
- Documented incident/breach investigation records
- Access control logs or procedures (who has access to what, and how it's managed)
Audit readiness is an ongoing process, not a filing project
A note on chiropractic-specific risk
General HIPAA training programs are built for hospitals and large medical groups. They cover topics your front desk staff will never encounter (psychotherapy notes, psychiatric disclosures, organ donation consent) while skipping the scenarios your team faces every day: a PI attorney showing up unannounced for records, a patient asking their spouse to pick up an adjustment schedule, an insurance adjuster calling to verify treatment dates.
Effective compliance training for a chiropractic office covers the actual situations your staff encounters — and it documents that it did so. That documentation is what you produce when OCR comes calling.
Get your practice audit-ready
SkillWave delivers chiropractic-specific HIPAA training with the documentation — training logs, completion records, certificates — that OCR asks for. Unlimited staff, one flat rate.
Get your practice started