How Physical Therapy Clinics Should Handle Home Exercise Videos Under HIPAA

Product Pricing
Ready to get started? Book a demo with our team
Talk to an expert

How Physical Therapy Clinics Should Handle Home Exercise Videos Under HIPAA

Kevin Henry

HIPAA

August 30, 2026

8 minutes read
Share this article
How Physical Therapy Clinics Should Handle Home Exercise Videos Under HIPAA

HIPAA Applicability to Physical Therapy Practices

Most physical therapy clinics function as a HIPAA-covered entity because they provide healthcare services and transmit claims or other standard electronic transactions. When you record, store, or share patient-specific home exercise videos that can identify a person, those recordings become electronic Protected Health Information (ePHI) and fall under HIPAA’s Privacy and Security Rules.

HIPAA applies whether you capture the video in the clinic, during telehealth, or receive it from a patient. If the content can reasonably identify the individual—face, voice, name, date of birth, chart number, or metadata linking it to a chart—it is ePHI. Generic, de-identified exercise clips used for general education are not ePHI unless you attach them to a specific patient record.

When you are a HIPAA-covered entity

  • You submit electronic claims or eligibility inquiries.
  • You use an EHR or patient portal to manage care.
  • You exchange ePHI with payers or other providers.

What makes a home exercise video ePHI

  • It contains images, voice, or captions that identify the patient.
  • It sits in a system tied to a medical record or billing account.
  • Its filename, metadata, or link uniquely maps to the patient.

Home Exercise Programs and HIPAA Compliance

Home exercise videos support treatment, so creating and sharing them with a patient is generally permitted for treatment purposes. Your obligations focus on safeguarding ePHI, using the minimum necessary information, and documenting how the video fits into clinical care.

Integrating videos into the medical record

  • Decide when a clip becomes part of the designated record set—e.g., it demonstrates technique, function, or progress you use for clinical decisions.
  • Apply your retention schedule and state documentation rules to videos you treat as records.
  • Index videos with patient identifiers inside secure systems, not in public filenames or links.

Minimum necessary and de-identification

  • Capture only what you need for patient instruction; avoid background family members or other patients.
  • Use neutral backdrops, limit audio, and keep on-screen text generic when possible.
  • Prefer de-identified generic exercise libraries unless personalization is clinically necessary.

Patient-generated videos versus clinic recordings

  • Patient-sent videos become ePHI once received; provide a secure upload path.
  • Clinic-made videos should be created on managed devices with security controls and stored in systems under your policies.
  • Document when you review patient videos and any clinical actions taken.

Secure Communication Methods for Home Exercise Videos

Choose encrypted communication platforms that support access control, auditing, and a Business Associate Agreement. Your goal is to protect ePHI in transit and at rest while keeping the workflow simple for patients.

Preferred channels

  • Patient portal or EHR messaging with embedded video or secure streaming.
  • Dedicated telehealth or rehabilitation apps that provide encryption, user authentication, and audit logs.
  • Encrypted email or secure file transfer with password-protected attachments and expiring links.

Channels to avoid

  • Personal email, consumer cloud drives, or messaging apps without a BAA.
  • Public links that can be forwarded or indexed.
  • Social media direct messages, which are rarely appropriate for ePHI.

Technical safeguards to implement

  • Encryption in transit and at rest, multifactor authentication, and role-based access.
  • Unique user IDs, automatic logoff, and audit logging for viewing and downloads.
  • Retention controls, versioning, and secure deletion for outdated clips.
  • Watermarking or read-only streaming when you need to limit redistribution.

Patient Authorization for Video Recordings

For treatment, you generally may record and use a patient’s video without a HIPAA authorization, though informed consent is still best practice. You must obtain written patient authorization when the use or disclosure is outside treatment, payment, and healthcare operations—such as external training, marketing, or posting testimonials.

Ready to assess your HIPAA security risks?

Join thousands of organizations that use Accountable to identify and fix their security gaps.

Take the Free Risk Assessment

When a patient authorization is required

  • Using identifiable clips for advertising, social media, websites, or press.
  • Sharing with third parties not involved in care, or for non-clinical education.
  • Any disclosure not otherwise permitted by HIPAA or required by law.

Core elements of a valid authorization

  • What will be recorded or shared and for what purpose.
  • Who may receive the video and the authorization’s expiration date or event.
  • A notice of the right to revoke and how to do so in writing.
  • A statement that refusal will not affect treatment, where applicable.
  • Patient (or legal representative) signature and date.

Workflow tips

  • Use a concise script explaining why the video helps care and how it is protected.
  • Capture consent or authorization before recording; store the form with the record.
  • Label videos to reflect authorization limits and expiration.
  • Honor revocations promptly and remove or archive content as required.

Risk Analysis Requirement

The Security Rule requires a security risk analysis that covers how you create, receive, maintain, and transmit ePHI. Include video capture, storage, and sharing in your analysis and map the full lifecycle—from the camera to deletion.

What to assess

  • Assets: phones, tablets, laptops, cloud storage, portals, and backup systems.
  • Data flows: where videos originate, who can access them, and where they are stored.
  • Threats and vulnerabilities: lost devices, misaddressed emails, unsafe apps, or weak access controls.

Risk management actions

  • Implement device management, remote wipe, and enforced encryption.
  • Disable auto-uploads to personal clouds; separate work and personal photo libraries.
  • Establish naming, indexing, and retention standards for video files.
  • Test incident response and breach notification processes with video-specific scenarios.

Training on HIPAA Compliance

Your team needs role-specific training on capturing, labeling, and sharing videos appropriately. Reinforce practical steps and provide quick-reference guides that make the secure path the easy path.

Training essentials

  • How to use approved apps and portals for video instructions and patient follow-up.
  • What not to do: no personal texting, no unapproved cloud drives, no social media DMs.
  • BYOD rules: passcodes, encryption, MDM enrollment, and no auto-backups to personal accounts.
  • Recognizing phishing and social engineering aimed at video links and portals.

Reinforcement and accountability

  • Annual refreshers and just-in-time micro-training when workflows change.
  • Spot checks and audits of message threads, portals, and access logs.
  • Clear sanctions for violations and rapid coaching for near misses.

Vendor Management and Business Associate Agreements

Any vendor that creates, receives, maintains, or transmits ePHI for your clinic must sign a Business Associate Agreement before use. Strong vendor compliance management ensures third-party platforms handling home exercise videos meet your security and privacy standards.

When a BAA is required

  • Telehealth, video hosting, patient engagement, or messaging apps that store or transmit clips.
  • Cloud storage, content delivery networks, or transcription services touching ePHI.
  • IT support firms with potential access to systems containing videos.

What to look for in the BAA

  • Specific safeguards (encryption, MFA, logging) and subcontractor flow-down obligations.
  • Breach notification timelines, cooperation duties, and incident reporting detail.
  • Permitted uses/disclosures, data return or destruction at termination, and right to audit.

Ongoing vendor compliance management

  • Due diligence: security questionnaires, certifications, and penetration test summaries.
  • Access reviews, least-privilege controls, and termination procedures for staff and vendors.
  • Contract lifecycle reviews to keep BAAs and security exhibits current with product changes.

Key takeaways

  • Treat identifiable home exercise videos as ePHI and handle them within secured systems.
  • Use encrypted communication platforms and approved workflows that minimize risk.
  • Obtain patient authorization for uses outside treatment and document limits clearly.
  • Perform a security risk analysis that covers the full video lifecycle and manage vendor risks with strong BAAs.

FAQs

What are the HIPAA requirements for sharing home exercise videos?

You may share personalized videos with the patient for treatment if you protect ePHI with reasonable administrative, physical, and technical safeguards. Use secure systems with encryption, access controls, and audit logs; apply the minimum necessary standard; and incorporate the video into your documentation and retention policies when it informs care.

How should physical therapy clinics obtain patient authorization for video recordings?

Use a written patient authorization when the video will be used beyond treatment, payment, or healthcare operations—such as marketing or public posting. The authorization should describe the video, purpose, recipients, expiration, the right to revoke, and the patient’s signature and date. Capture it before recording and store it with the record.

What security measures protect ePHI in home exercise programs?

Protect ePHI with encryption in transit and at rest, multifactor authentication, role-based access, and audit logging. Manage devices with passcodes and remote wipe, disable personal cloud backups, use approved portals or secure messaging, and set retention and deletion rules for outdated videos.

How do Business Associate Agreements affect vendor compliance?

A Business Associate Agreement contractually requires vendors that handle your ePHI to implement HIPAA-aligned safeguards, restrict use and disclosure, notify you of breaches, flow down obligations to subcontractors, and return or destroy data at termination. Ongoing vendor compliance management verifies they continue to meet these obligations over time.

Share this article

Ready to assess your HIPAA security risks?

Join thousands of organizations that use Accountable to identify and fix their security gaps.

Take the Free Risk Assessment

Related Articles