Physical Therapy Practice Security Risk Assessment: Step-by-Step HIPAA Compliance Checklist

Product Pricing
Ready to get started? Book a demo with our team
Talk to an expert

Physical Therapy Practice Security Risk Assessment: Step-by-Step HIPAA Compliance Checklist

Kevin Henry

HIPAA

May 14, 2026

7 minutes read
Share this article
Physical Therapy Practice Security Risk Assessment: Step-by-Step HIPAA Compliance Checklist

This guide gives you a practical, step-by-step HIPAA compliance checklist tailored to physical therapy operations. It shows how to run a Physical Therapy Practice Security Risk Assessment and turn findings into prioritized action.

You will learn what HIPAA expects from PT practices, how to assess risk around electronic protected health information (ePHI), and how to implement administrative, physical, and technical safeguards that stand up to audits.

HIPAA Compliance Requirements for PT Practices

HIPAA’s Privacy, Security, and Breach Notification Rules apply to physical therapy clinics that create, receive, maintain, or transmit ePHI. Your first objective is to understand the requirements that shape your compliance program.

Core expectations

  • Designate leadership: appoint HIPAA Privacy and Security Officers with authority and resources to oversee governance, training, and oversight.
  • Adopt written policies: document how you access, use, disclose, retain, and dispose of ePHI, aligned to the Minimum Necessary standard.
  • Implement safeguards: deploy administrative, physical, and technical controls proportional to your size, complexity, and risk profile.
  • Train your workforce: provide role-based training on privacy, security, and Security Incident Reporting, with tracked completion and refresher cycles.
  • Manage vendors: execute a Business Associate Agreement with any vendor handling ePHI, and verify their security posture.
  • Document everything: keep evidence of decisions, assessments, remediation, and monitoring to demonstrate due diligence.

Conducting Comprehensive Security Risk Assessments

A risk assessment is the foundation of your program. It identifies where ePHI lives, what could go wrong, how likely it is, and what impact it could have on patients and your practice.

Step-by-step approach

  • Define scope: include all locations, people, and processes that create, receive, maintain, or transmit ePHI, on-premises and in the cloud.
  • Inventory assets and data flows: map systems, devices, applications, and integrations that touch ePHI, including backups and media.
  • Identify threats and vulnerabilities: consider human error, theft, ransomware, misconfiguration, insecure disposal, and third-party risks.
  • Estimate likelihood and impact: rate each risk scenario to prioritize what requires immediate attention.
  • Document findings: summarize exposure, affected controls, and business impact in a clear report.
  • Launch risk analysis remediation: define corrective actions, owners, budgets, and timelines; track status to closure.
  • Verify and monitor: test implemented controls, measure effectiveness, and update the register as your environment changes.

Evidence to collect

  • Asset and application inventories, network diagrams, and data-flow maps.
  • Policies, procedures, training logs, and audit logs showing enforcement.
  • Vendor BAA list, due diligence results, and service scope descriptions.
  • Remediation plans, completion records, and periodic reassessment results.

Implementing Administrative Safeguards

Administrative safeguards guide how you govern risk, people, and processes. They make technical and physical controls sustainable.

Governance and roles

  • Assign HIPAA Privacy and Security Officers and define their responsibilities, decision rights, and reporting cadence.
  • Set a compliance calendar for assessments, policy reviews, training, and tabletop exercises.

Policies, procedures, and training

  • Adopt policies covering access control, device use, data retention, disposal, sanctions, and Security Incident Reporting.
  • Train by role: onboarding, annual refreshers, and just-in-time micro-training tied to observed risks.
  • Enforce the Minimum Necessary standard with role-based access and approval workflows for exceptions.

Risk management and continuity

  • Translate assessment results into risk analysis remediation tasks with due dates and metrics.
  • Establish contingency plans: data backup, disaster recovery, and emergency operations with documented RTO/RPO targets.
  • Include change management: security review for new software, devices, or processes before go-live.

Applying Physical Safeguards in Clinical Settings

Physical safeguards limit who can access facilities, workstations, and media that store or display ePHI. They protect busy front desks, open gyms, and treatment rooms.

Ready to assess your HIPAA security risks?

Join thousands of organizations that use Accountable to identify and fix their security gaps.

Take the Free Risk Assessment

Facility and workstation controls

  • Control entry: keys or badges for staff; visitor sign-in, escorts, and visible badges for guests and vendors.
  • Protect screens: privacy filters, screen positioning away from public view, and auto-locks on short inactivity.
  • Secure storage: lock rooms, carts, and cabinets holding devices, drives, or paper containing ePHI.

Device and media protection

  • Maintain an inventory of devices and media that store ePHI; assign owners and track custody.
  • Use secure disposal: shred paper, wipe and destroy drives, and document the chain of custody.
  • Reduce exposure: limit ePHI on portable media and disable unneeded USB ports where feasible.

Enforcing Technical Safeguards and Access Controls

Technical safeguards protect ePHI in systems and networks. Focus on identity, device health, encryption, and continuous monitoring.

Identity and access management

  • Issue unique user IDs and role-based permissions aligned to the Minimum Necessary standard.
  • Require multi-factor authentication for EHRs, patient portals, remote access, and administrative consoles.
  • Apply strong passwords, session timeouts, and automatic logoff on shared workstations.

Data protection and system security

  • Encrypt ePHI in transit and at rest; prefer managed, monitored encryption with centralized key management.
  • Keep systems current: automated patching, vulnerability management, and timely removal of unsupported software.
  • Secure endpoints: enable disk encryption, anti-malware, EDR, and mobile device management for BYOD and clinic-owned devices.
  • Segment networks: separate guest Wi‑Fi from clinical systems; restrict admin tools to secured subnets or jump hosts.

Logging and monitoring

  • Enable audit logs for access, changes, and exports of ePHI; review them regularly for anomalies.
  • Alert on suspicious activity, excessive failed logins, or large data transfers; integrate alerts into response playbooks.
  • Back up data securely, encrypt backups, and test restores on a defined cadence.

Managing Business Associate Agreements

A Business Associate Agreement formalizes how vendors protect ePHI on your behalf. You are responsible for ensuring BAAs exist and are enforced.

Lifecycle management

  • Identify business associates: EHR, billing, telehealth, texting, cloud storage, shredding, and IT support providers.
  • Execute and file a Business Associate Agreement before sharing ePHI; include subcontractor flow-down requirements.
  • Define Security Incident Reporting obligations, breach notification timeframes, and cooperation duties.
  • Perform due diligence: review security attestations, controls, and incident history proportional to risk.
  • Monitor performance: track service changes, audit rights, and termination procedures to ensure data return or destruction.

Establishing Incident Response and Documentation Procedures

Incidents happen. A prepared, documented process limits harm, speeds recovery, and demonstrates compliance discipline.

Security Incident Reporting

  • Define what constitutes a security incident and how staff report it quickly (who, how, when, with what details).
  • Maintain a triage workflow: detect, contain, eradicate, recover, and communicate with leadership and affected parties as required.
  • Run tabletop exercises: rehearse scenarios such as lost laptops, misdirected faxes, ransomware, and vendor breaches.

Investigation, breach risk assessment, and notification

  • Analyze scope: systems, accounts, and ePHI elements involved; determine the likelihood of compromise.
  • Perform a documented breach risk assessment and proceed with notifications consistent with HIPAA requirements.
  • Capture lessons learned and update policies, controls, and training to prevent recurrence.

Documentation and audit readiness

  • Centralize artifacts: policies, training logs, risk assessments, risk analysis remediation status, BAAs, audits, and incident files.
  • Maintain retention schedules; ensure records are accessible, accurate, and version-controlled.
  • Report program health to leadership with clear metrics and improvement plans.

Conclusion

Start with a thorough risk assessment, close gaps through targeted remediation, and sustain progress with strong governance, vendor oversight, and practiced response. This approach creates a defensible, efficient HIPAA compliance posture for your physical therapy practice.

FAQs.

What systems must be included in a physical therapy security risk assessment?

Include every system, device, and service that creates, receives, maintains, or transmits ePHI: EHR, scheduling and billing, patient portals, telehealth and messaging tools, email, imaging, backups, on-site and cloud file storage, mobile devices, office workstations, network gear, Wi‑Fi, remote access, and any vendor platforms connected to your workflows.

How often should physical therapy practices perform a HIPAA security risk assessment?

Perform a comprehensive assessment at least annually and whenever you introduce material changes—new EHR modules, telehealth platforms, office moves, or significant staffing shifts. Revisit risk analysis remediation monthly or quarterly to track progress and adjust priorities as your environment evolves.

What are the key administrative safeguards for HIPAA compliance in PT clinics?

Assign HIPAA Privacy and Security Officers, maintain written policies, enforce the Minimum Necessary standard with role-based access, deliver role-specific training and sanctions, manage vendors with BAAs and due diligence, and operate a documented risk management process that translates findings into tracked remediation.

How do Business Associate Agreements affect physical therapy practices?

BAAs define how vendors protect your ePHI and what happens if there is an incident. They require Security Incident Reporting, breach cooperation, and subcontractor accountability. Without a valid Business Associate Agreement, you assume greater risk and may be out of compliance even if the vendor suffers the breach.

Share this article

Ready to assess your HIPAA security risks?

Join thousands of organizations that use Accountable to identify and fix their security gaps.

Take the Free Risk Assessment

Related Articles