HIPAA and AI Governance for Small Chiropractic Practices
A practical compliance stack — BAAs, PHI minimization, audit logging — for a 1–3 DC clinic running AI across the patient journey.
- PUBLISHED
- May 13, 2026
- READ TIME
- 7 MIN
- AUTHOR
- ONE FREQUENCY
- Topic
- HIPAA AI chiropractic, chiropractic compliance AI, chiropractor BAA
- Industry
- chiropractors
- Published
- May 13, 2026
- Read time
- 7 min
- Word count
- 1,250
HIPAA and AI governance for a 1–3 DC chiropractic practice is not a 200-page binder. It is a one-page checklist the owner signs, keeps with the malpractice paperwork, and reviews every six months. Most clinics that fail HIPAA audits do not fail because they lacked a 200-page binder. They fail because nobody signed a Business Associate Agreement with the SMS vendor, or because the front desk pasted PHI into a free ChatGPT tab to draft a letter. The work is to close the obvious gaps, document the closures, and move on.
The compliance stack for a small chiropractic practice
Six components every clinic needs in writing:
- Business Associate Agreements with every vendor that touches PHI. EHR (ChiroTouch, Jane, ChiroFusion, Genesis), voice agent (Numa, Hyro, Modento), ambient SOAP (Suki, Heidi, DeepScribe), Claude or ChatGPT under BAA-covered tier, eligibility (Availity, Change Healthcare), review platform (Birdeye, Podium), email and SMS (the messaging side of Modento, Dialog Health, Klara). No BAA, no PHI. Hard rule.
- PHI minimization on AI prompts. The staff prompt library never includes full patient identifiers. First name, last initial, condition. Nothing more on consumer-facing prompts. The clinical-facing prompts (ambient SOAP, billing AI) operate inside the BAA boundary.
- Audit logging. Every AI-touched record has a log: who accessed it, when, what action was taken, what AI vendor was involved. Most EHRs ship this natively; the AI overlays must integrate.
- Patient consent for recording. Every recorded call (inbound and outbound) needs a consent disclosure on opening. Two-party-consent states (CA, FL, IL, MD, MA, MI, MT, NV, NH, PA, WA) require explicit consent.
- State chiropractic board record retention. 7–10 years for adults; longer for minors. The AI-drafted SOAP note is the official record and must meet retention rules.
- Breach notification readiness. A one-page incident-response plan: who gets called, who notifies patients, who files with HHS. Most clinics never need it; the ones that do are glad they wrote it.
The one-page governance checklist
The checklist the owner signs has 12 items:
- BAA on file for every PHI-touching vendor (with vendor names and dates).
- Staff trained on PHI minimization (with training date).
- Audit logs enabled on the EHR and on every AI overlay.
- Consent disclosure live on every recorded call.
- AI-drafted SOAP notes reviewed and signed by the licensed DC within 24 hours.
- Active-care vs maintenance language defended in every plan visit.
- Card-on-file processor is PCI-compliant.
- Free consumer AI tools (ChatGPT, Gemini, Copilot consumer tier) blocked from clinic networks.
- Patient portal uses MFA for staff access.
- Backup and disaster recovery on the EHR (with last test date).
- Incident response plan reviewed in the last 6 months.
- Owner signature and date.
This page lives next to the malpractice insurance binder. The owner reviews and re-signs every six months.
Vendor-specific guidance
ChiroTouch's BAA is included with the platform; the AI Assistant runs inside the same boundary. ChiroFusion ships a BAA and the AI overlay (recall, billing) inherits it; the ChiroFusion blog publishes the latest compliance updates. Genesis Chiropractic Software ships a BAA and a strong audit log; the Genesis blog covers HIPAA-relevant practice operations. Jane App ships a BAA. Suki, Heidi, and DeepScribe all sign BAAs by default. Anthropic Claude requires the BAA-covered enterprise tier; same for OpenAI and Microsoft Copilot. The American Chiropractic Association publishes a standing guide on HIPAA basics; Chiropractic Economics and Dynamic Chiropractic both run regular updates on compliance for small practices.
Pitfalls to avoid
Do not let any vendor see PHI without a BAA. The fastest way to a fine is the SMS vendor or the answering service operating on a verbal agreement.
Do not use free consumer AI tools in the office. Block the URLs on the clinic network. The 12 seconds the CA "saves" pasting a patient name into free ChatGPT is the 12 seconds that turns into a $50,000 fine.
Do not skip the active-vs-maintenance defense. The AI must draft SOAP notes that defend active care with outcome-assessment movement (pain scales, Oswestry, NDI) at intake, mid-plan, and discharge. Maintenance language without ABN coverage is the Medicare audit trigger.
Do not rely on the vendor for record retention. The clinic owns the record. Confirm the EHR export and retention strategy in writing.
Do not store recordings indefinitely. Define a retention window (most clinics run 12–24 months) and stick to it.
Do publish the incident response plan. Print it. Pin it. Train the staff on it. The 30 minutes it takes to write is the cheapest insurance the clinic buys.
Internal links and next steps
The chiropractic AI playbook covers the workflow context; the ROI breakdown sizes the cost of the compliance stack against the upside. The AI enablement engagement includes the governance checklist as a deliverable; AI for chiropractors is the chiropractic-specific landing page.
FAQ
Q: Do I need a HIPAA security officer in a 2-DC practice? A: Yes, but it is usually the office manager. The role is real even if part-time.
Q: How often do I update the BAA list? A: Quarterly. Every new vendor that touches PHI gets a BAA before going live.
Q: What does a HIPAA audit actually look like? A: For a small practice, usually a complaint-driven OCR letter asking for documentation. The clinic has 30 days to respond with policies, BAAs, training records, and audit logs.
Q: Does my malpractice carrier care about AI? A: Increasingly yes. Most carriers ask about vendor BAAs and PHI handling on the renewal form. Have the answers ready.
Q: What about state-specific chiropractic board rules? A: Every state board has its own record retention, advertising, and informed consent rules. The AI overlays must comply with the state-board rules where the clinic operates.
Q: How does this fit with the rest of the AI stack? A: Governance is the spine. Every workflow — receptionist, SOAP, billing, marketing — runs inside the compliance boundary. The boundary is the deliverable that makes the rest defensible.
Q: What is the most common BAA gap? A: The SMS vendor. Clinics that have switched messaging platforms three times often have stale BAAs. Pull every vendor in the stack and confirm.
Q: Do I need a HIPAA risk analysis? A: Yes. HHS requires periodic risk analysis. Most small practices satisfy this with an annual one-day workshop and a written report. The AI vendors plug into the risk analysis as enumerated PHI flows.
Q: How does this handle state-specific health privacy laws? A: Some states (CA, IL, WA) have stricter rules than HIPAA — California's CCPA and the new state privacy regimes can apply to clinic data. The governance checklist references state law where it adds requirements.
Q: What about telehealth-style virtual consults? A: If the clinic runs virtual consults, the video platform needs a BAA and the visit notes follow the same rules as in-person SOAP. Most platforms (Doxy, Zoom Healthcare) are BAA-ready out of the box.
Closing thoughts
Compliance for chiropractic AI is not a wall to scale — it is a checklist to maintain. The clinics that treat it as a recurring 30-minute task every quarter stay defensible. The clinics that treat it as a one-time project go stale within 12 months and end up scrambling when a vendor changes or an audit letter arrives. Build the discipline; the rest of the AI stack rests on it.
If you want a one-page checklist scoped against your stack, contact us or see AI for chiropractors.
Cited and consulted.
- 01American Chiropractic Association — Compliance Guidanceacatoday.org · accessed May 8, 2026
- 02Chiropractic Economics — Compliance and Riskchiroeco.com · accessed May 8, 2026
- 03Dynamic Chiropractic — HIPAA and Documentationdynamicchiropractic.com · accessed May 8, 2026
- 04ChiroTouch Blog — Security and Compliancechirotouch.com · accessed May 8, 2026
Ready to ship the next outcome?
One Frequency Consulting brings 25+ years of technology leadership and military discipline to every engagement. First call is operator-grade scoping — sixty minutes, no charge.