All resources
Audit Readiness9 min readAugust 4, 2026

HIPAA Compliance for Chiropractic Offices: What OCR Actually Checks

The Office for Civil Rights audits look nothing like the compliance seminars you've attended. Here's exactly what investigators examine when they open a chiropractic practice — and the gaps they find most often.

Most chiropractic offices prepare for HIPAA audits the wrong way. They spend a Saturday updating their Notice of Privacy Practices, print a new copy for the front desk, and consider themselves covered.

Then OCR shows up — or, more commonly, a patient complaint triggers a compliance review — and investigators ask for documents that don't exist: training logs, risk assessment records, Business Associate Agreements for vendors you've been using for years. The NPP sitting on the counter turns out to be the least of your problems.

This guide walks through what OCR's audit protocol actually covers, where chiropractic offices consistently fall short, and what documentation you need to survive a review without a corrective action plan (CAP) or a civil monetary penalty.

What triggers an OCR investigation in a chiropractic office?

OCR receives complaints, conducts random desk audits under its ongoing audit program, and opens investigations after breach notifications. In chiropractic, the most common triggers are:

  • A former patient files a complaint about a perceived disclosure — often a scheduling conversation overheard in an open bay
  • A breach notification after a lost laptop, stolen phone, or misdirected fax containing patient records
  • A personal injury attorney requests records and the release process is mishandled
  • A disgruntled ex-employee files a complaint about internal access controls
  • Your practice is selected for OCR's random desk audit program

Random audits and complaint-driven investigations follow the same protocol. OCR will request a defined set of documentation — typically within 10 days — and your ability to produce it quickly is itself evidence of your compliance posture.

The OCR Audit Protocol: 8 areas that apply directly to chiropractic

OCR's audit protocol is publicly available and covers 180 audit elements across the Privacy Rule, Security Rule, and Breach Notification Rule. For a typical chiropractic office, these eight areas carry the most weight.

1. Workforce training — the most commonly cited gap

HIPAA requires that all workforce members receive training on your policies and procedures. "Workforce" is broader than you might expect: it includes full-time staff, part-time staff, volunteers, and students on clinical rotation.

What OCR asks for:

  • Training logs with specific dates, staff names, and topics covered
  • Evidence that training happened when policies changed
  • Training records for new hires (must occur within a reasonable timeframe of hire)
  • Proof that training content was relevant to each employee's role

The 'we covered it at the staff meeting' problem

Meeting notes that say "reviewed HIPAA" don't satisfy OCR. Investigators look for documented training that covers specific required elements — minimum necessary standard, how to handle PHI access requests, breach notification procedures. A sign-in sheet from a staff meeting rarely qualifies.

2. Notice of Privacy Practices — content and distribution

Most chiro offices have an NPP. What they often miss:

  • The NPP must include your practice's contact information for complaints
  • You must make a good-faith effort to obtain a written acknowledgement of receipt from each patient
  • Those acknowledgements must be retained for six years
  • The NPP must be posted in a clear and prominent location and on your website (if you have one)
  • Your actual practices must match what the NPP says

3. Open treatment areas — the chiropractic-specific exposure

Open adjusting bays are where most chiropractic practices differ from general medical offices — and where OCR applies specific analysis.

HIPAA's "incidental use and disclosure" standard acknowledges that some PHI exposure is unavoidable in healthcare settings. But the standard requires that you implement reasonable safeguards. For open-bay chiropractic offices, this means:

  • Training staff on keeping voices lowered when discussing diagnoses or treatment plans
  • Using patient numbers or first names only in open areas when possible
  • Positioning treatment tables so that a patient's paperwork isn't visible to others
  • Documenting that you've assessed this risk and implemented controls

Document the risk assessment, not just the fix

OCR doesn't expect you to have private rooms. They expect you to have assessed the risk of your physical layout and implemented proportionate controls. A written risk assessment that says "our open bays create incidental exposure; we mitigate through voice training and positioning" is far more valuable than a physical partition with no documentation.

4. Personal injury records — high-risk disclosures

Chiropractic offices treating motor vehicle accident and workers' compensation patients handle one of HIPAA's most legally complex disclosure types: records released to attorneys, insurance adjusters, and third-party payers.

OCR commonly finds deficiencies in:

  • Releasing records to PI attorneys without a valid patient authorization
  • Failing to apply the minimum necessary standard to attorney record requests
  • Releasing records that include information from other providers without authorization
  • Not tracking which records were released, to whom, and under what authority

Every PI record release should be documented in a disclosure log that includes the date, recipient, description of PHI disclosed, and the legal basis for disclosure (authorization, court order, or legal requirement). OCR will ask for this log.

5. Business Associate Agreements

Any vendor who handles your patient data on your behalf is a Business Associate and must have a signed BAA before they touch PHI. Common chiropractic vendors that require BAAs:

  • Your practice management / EHR software vendor
  • Your billing service or billing software
  • Your transcription service
  • Your document shredding company
  • Your IT support company (if they ever access systems with patient data)
  • Any cloud storage service used for patient records (including Google Drive, Dropbox)
  • Your patient portal provider

Verbal agreements don't count

OCR requires a written BAA. Contracts that include data protection language but don't specifically address HIPAA often don't satisfy the requirement. Your billing software's standard Terms of Service is not a BAA.

6. Risk analysis — the most missed requirement

The Security Rule requires a comprehensive risk analysis that identifies potential threats to the confidentiality, integrity, and availability of electronic PHI (ePHI). OCR's own audits found this is the single most commonly missing element across all covered entities.

A risk analysis for a chiropractic office should cover:

  • Every system and device that stores or transmits patient data
  • Potential threats to each system (theft, malware, unauthorized access, hardware failure)
  • Current controls for each threat and whether they are adequate
  • Residual risk and a remediation plan for unacceptable risks

This doesn't require an IT firm or a lengthy technical document. A thorough spreadsheet that walks through your systems, threats, and controls satisfies the requirement if it's updated annually and after significant changes.

7. Access controls and minimum necessary standard

Every staff member should only have access to the PHI they need to do their job. Front desk staff generally don't need access to clinical notes. Billers don't need access to psychotherapy records. OCR will ask:

  • How is access to your EHR or practice management system controlled?
  • How do you revoke access when an employee is terminated?
  • Do you have unique login credentials for each user, or do you share passwords?
  • What is your policy on workforce members accessing PHI from personal devices?

8. Breach notification procedures

Your staff need to know what to do when they suspect a breach — and they need to know to report it internally immediately. The 60-day notification clock starts when the breach is discovered, not when it's reported to you. Delayed internal reporting that causes you to miss the 60-day window is a separate HIPAA violation on top of the breach itself.

Your breach notification procedure should cover:

  • Who staff should notify immediately upon suspecting a breach
  • How you assess whether a breach is reportable (the four-factor test)
  • The 60-day notification timeline for OCR and affected patients
  • How you document breach investigations and your risk assessment

What investigators actually find in chiropractic offices

Based on OCR resolution agreements and published audit findings, these are the deficiencies that appear most often in small-to-mid-size chiropractic practices:

Common findings

No formal risk analysis

Required by the Security Rule; often missing entirely

Incomplete training records

Staff trained verbally or informally, no documentation

Missing or unsigned BAAs

Billing vendors, IT companies, cloud services

No disclosure log for PI records

Required when releasing records to attorneys/insurers

Shared login credentials

Multiple staff using the same EHR password

PHI on personal devices

No written policy; no mobile device management

Terminated employee access

EHR access not revoked within 24–48 hours

What "corrective action" looks like — and why you want to avoid it

When OCR finds violations, they issue a Corrective Action Plan. CAPs typically require the practice to:

  • Complete a full risk analysis within 60 days
  • Submit updated policies and procedures for OCR review and approval
  • Train all staff and submit training documentation
  • Submit compliance reports to OCR for one to three years
  • Maintain OCR oversight for the duration of the agreement

The oversight burden alone — preparing quarterly reports for OCR, maintaining meticulous documentation, managing the relationship — is significant for a small practice. And CAPs don't prevent civil monetary penalties for willful neglect: those can reach $50,000 per violation category, per year.

The documentation stack you need before OCR knocks

If you received an OCR records request tomorrow, you should be able to produce these within 10 days:

  • Training logs: name, date, topics covered, for every current and recent staff member
  • Your current Notice of Privacy Practices and patient acknowledgements (6-year retention)
  • Signed Business Associate Agreements for every qualifying vendor
  • A current risk analysis document covering all systems that store or transmit ePHI
  • Your written HIPAA policies and procedures
  • An accounting of disclosures log for PI and non-routine record releases
  • Documented incident/breach investigation records
  • Access control logs or procedures (who has access to what, and how it's managed)

Audit readiness is an ongoing process, not a filing project

The practices that survive OCR reviews without corrective action plans aren't the ones with the most elaborate documentation — they're the ones whose documentation is current and whose staff can actually describe what they're supposed to do. A training record from three years ago helps less than you think. Annual re-training with current logs is what investigators want to see.

A note on chiropractic-specific risk

General HIPAA training programs are built for hospitals and large medical groups. They cover topics your front desk staff will never encounter (psychotherapy notes, psychiatric disclosures, organ donation consent) while skipping the scenarios your team faces every day: a PI attorney showing up unannounced for records, a patient asking their spouse to pick up an adjustment schedule, an insurance adjuster calling to verify treatment dates.

Effective compliance training for a chiropractic office covers the actual situations your staff encounters — and it documents that it did so. That documentation is what you produce when OCR comes calling.

Get your practice audit-ready

SkillWave delivers chiropractic-specific HIPAA training with the documentation — training logs, completion records, certificates — that OCR asks for. Unlimited staff, one flat rate.

Get your practice started
Back to all resources