Every physical therapy clinic has the same architectural feature and the same HIPAA question. The feature is the open gym: six tables, four patients, two therapists, one big room. The question is whether treating people in that room, where everyone can hear everyone, is a federal privacy problem.
It is not. HIPAA was written for the real world, and the real world includes open treatment areas. But the rule that makes the open gym legal comes with conditions, and the conditions are where PT clinics actually fail. This article covers the open-gym rules, the PHI a PT clinic holds that nobody thinks of as PHI, the vendor list that needs B.A.A.s (Business Associate Agreements), and the violations that actually show up in this specialty.
HIPAA Compliance for Physical Therapy: What the Rules Actually Ask
Why the Open Gym Is Legal
Two provisions do the work. 45 CFR 164.502(a)(1)(iii) permits disclosures "incident to" an otherwise permitted use: the unavoidable overhearing that comes with running a clinic in a shared space. And 45 CFR 164.530(c) requires "reasonable safeguards" to keep those incidental disclosures small.
Reasonable is the operative word. Nobody expects soundproof pods between treatment tables. What OCR expects is that you thought about it and wrote the thinking down: initial evaluations and sensitive conversations happen in a private room, therapists lower their voices for diagnosis talk on the floor, progress discussions stick to the exercise in front of you, and the whiteboard by the door does not list full names next to conditions. Those four habits, written into a policy, are the difference between an incidental disclosure and a complaint.
The PHI Nobody Counts
Ask a PT clinic where its P.H.I. (Protected Health Information) lives and you will hear "the EMR." The real inventory is longer: outcome questionnaires on clipboards, the schedule grid visible at the front desk, home exercise program printouts left on tables, photos and videos of patients demonstrating movement (those are PHI the moment they are identifiable), text threads with patients about scheduling, and the referral faxes from physicians stacked by the printer. Every one of those needs a home in your risk assessment, because every one of them walks out the door in a different way.
The Vendor List That Needs BAAs
PT clinics run on a specific software stack, and most of it touches PHI: the EMR and scheduling platform, the home exercise program app that emails patients their routines, the outcomes-tracking service, the billing clearinghouse, and any texting or reminder platform. Each one is a business associate, and each one needs a signed BAA before PHI flows, not after. The test is simple: if the vendor creates, receives, maintains, or transmits PHI for you, it is on the list. The BAA guide covers what the agreement must say, and BAA management is the ongoing part practices skip.
The Violations That Actually Happen in PT
The enforcement pattern for small outpatient clinics is boring and repeatable: no documented risk assessment, no mobile device policy while therapists text patients from personal phones, home-program apps adopted by one enthusiastic therapist with no BAA, and front-desk conversations in a lobby three feet from the waiting chairs. The front desk rules cover that last set. None of these are exotic. All of them are findable in an afternoon of honest self-review.
Staff and Students
PT clinics host students, aides, and techs, and the workforce rules apply to all of them: training before PHI access, unique logins (a shared tablet login on the gym floor fails this), and access scaled to role per the minimum necessary rule. A student on rotation is your workforce for HIPAA purposes; their training is your responsibility, and it belongs in your training program records.
What a Compliant PT Clinic Actually Looks Like
Not quieter. Not slower. It has five documents: a risk assessment that mentions the open gym by name, a front-office and floor policy with the four habits above, a BAA file with every software vendor in it, a device policy covering the personal phones that already exist, and training logs for everyone including students. That is the whole visible difference, and it is exactly what OCR asks to see when a complaint arrives.
---
FAQ
Are open treatment gyms a HIPAA violation?
No. Incidental overhearing in shared treatment spaces is permitted under 45 CFR 164.502(a)(1)(iii), provided the clinic applies reasonable safeguards: private space for sensitive conversations, lowered voices, and no identifying displays.
Do physical therapists need HIPAA training?
Yes. Every workforce member with PHI access needs training, including aides, techs, front desk staff, and students on rotation, before access and with periodic refreshers.
Is a home exercise program app a business associate?
If it stores or transmits identifiable patient information for your clinic, yes. It needs a signed BAA before patient data goes in, and it belongs in your vendor inventory.
Can PT clinics text patients?
Yes, within limits: appointment logistics with minimal content are workable, clinical details need a secured channel and patient agreement. A written texting policy is the requirement most clinics are missing.
Are videos of patients exercising PHI?
If the patient is identifiable, yes. Recording for documentation, education, or marketing each has different rules, and marketing use requires written authorization.
Conclusion
One Guy Consulting works with outpatient clinics exactly like this: small teams, open floor plans, no compliance officer on payroll. The Full-Scope plan is a flat $1,300 a year regardless of headcount and includes the policies, training, and four hours of monthly consulting to fit them to an open-gym floor. Start with a free 30-minute compliance review. No obligation, no pressure.
Sources
- 45 CFR 164.502 (incidental disclosures)
- 45 CFR 164.530(c) (reasonable safeguards)
- HHS guidance: Incidental Uses and Disclosures
Related Reading