Alex Bendersky
Healthcare Technology Innovator

HIPAA Compliant EMR for PT, OT and SLP Clinics: Security, Messaging and Telehealth (2026)

Last Updated on -  
October 5, 2026
Time
min Read
‍The Top 20 Voices in Physical Therapy You Should Be Following for Innovation, Education, and Impact
SPRY
October 5, 2026
•
5 min read
Minal Patel
PT, DPT, OCS
Expertise in rehabilitation, outpatient care, and the intricacies of medical coding and billing.
Summary
HIPAA Compliant EMR for PT, OT and SLP Clinics: Security, Messaging and Telehealth (2026)

Webinar

From Claims Delays to Clean Approvals: How AI Helps Clinics Win

September 17, 2025
1 p.m. - 2 p.m. EST
Tired of Forms? Automate Prior Auths
Used by PT, OT & rehab clinics to reduce prior auth delays.

AI-Native Prior Authorization for Rehab Therapy Clinics

Automate 80% of workflows, reduce denials by 75%, and secure approvals one week before appointments—all while preparing for CMS’s 2026 mandate.
Book a Demo
Summary for this page

A quick AI-generated overview extracted directly from the content of this page.

Summary: What a HIPAA compliant EMR for physical, occupational and speech therapy needs in 2026: the Security Rule's administrative, physical and technical safeguards, a signed business associate agreement, breach notification deadlines, secure messaging and telehealth, the proposed Security Rule update (not yet final), how SPRY handles HIPAA, and an interactive HIPAA EMR vendor checklist.

A HIPAA compliant EMR for physical, occupational and speech therapy is one that supports the HIPAA Security Rule's administrative, physical and technical safeguards and whose vendor signs a business associate agreement (BAA) with your clinic. There is no official HIPAA certification for software, so compliance is shared: the vendor protects the system, and your clinic controls who has access, trains staff and runs its own risk analysis. SPRY offers a BAA, HIPAA-compliant telehealth video and an ONC-certified EHR, with messaging, intake and the patient portal in the same platform.

Below: what HIPAA requires of a therapy EMR, what the vendor and clinic each own, breach deadlines, the proposed Security Rule update, secure messaging and telehealth, how SPRY handles HIPAA, a vendor checklist and FAQs.

What HIPAA requires from a PT, OT or SLP EMR

HIPAA Security Rule safeguards and what to check in an EMR
SafeguardKey standardsWhat to check in your EMR
AdministrativeRisk analysis, security official, workforce training, incident procedures, contingency plan, business associate agreementsA signed BAA, backup and recovery plans, and reports that support your risk analysis
PhysicalFacility access, workstation use and security, device and media controlsHosting in secured data centers; guidance for clinic tablets, kiosks and shared workstations
TechnicalAccess control, audit controls, integrity, authentication, transmission securityRole-based access, audit logs, automatic logoff, strong sign-in and encryption

Source: HHS HIPAA Security Rule. HHS does not require or recognize a HIPAA certification, so ask vendors for evidence rather than a badge.

Who is responsible for what: vendor vs clinic

Shared HIPAA responsibilities
AreaEMR vendor (business associate)Your clinic (covered entity)
ContractSigns and follows the BAAKeeps a signed BAA with every vendor that handles PHI
System securityHosting, encryption, backups, patching and audit loggingUses the features: user roles, logoff settings and strong passwords
AccessProvides role-based permissionsAssigns roles, removes former staff promptly and reviews access
TrainingDocuments how features workTrains staff on HIPAA and on safe use of the EMR
Risk analysisShares security informationRuns and documents its own risk analysis
BreachesReports breaches to the clinicNotifies patients, HHS and, if required, the media

HIPAA breach notification deadlines

Breach notification rules
NoticeDeadline
Business associate to covered entityWithout unreasonable delay and no later than 60 days after discovery
Affected individualsWithout unreasonable delay and no later than 60 days after discovery
HHS, 500 or more individualsWithin 60 days of discovery
HHS, fewer than 500 individualsWithin 60 days after the end of the calendar year
MediaWhen more than 500 residents of a state or jurisdiction are affected, within 60 days

Source: HHS Breach Notification Rule.

The proposed HIPAA Security Rule update

HHS proposed the first major update to the Security Rule in December 2024, and it was published in January 2025. As of October 2026 it is still a proposal, not a final rule. It would make encryption and multi-factor authentication required, remove the difference between required and addressable specifications, and add regular vulnerability scanning, penetration testing and compliance audits. Asking EMR vendors about these items now prepares you for the final rule. See the HHS fact sheet on the proposed rule.

Proposed Security Rule changes and what to ask your EMR vendor
Proposed changeQuestion for your vendor
Encryption of ePHI at rest and in transitIs all patient data encrypted in storage and in transit?
Multi-factor authenticationCan we require MFA for every user?
Vulnerability scans every 6 months and penetration tests every 12 monthsHow often do you scan and test, and can we see a summary?
Annual compliance auditDo you have an independent security report, such as SOC 2 or HITRUST?
All specifications requiredWhich safeguards are switched on by default?

Secure messaging, intake and patient communication

In outpatient therapy, PHI often leaks outside the EMR: staff text patients from personal phones, email home exercise programs or leave intake forms on paper. Moving these tasks into the EMR keeps them under the same safeguards and the same BAA.

Common PHI risk points in therapy clinics
Risk pointSafer workflow
Texting patients from personal phonesTwo-way messaging inside the EMR
Emailing exercise programs and documentsShare through the patient portal
Paper intake and consent formsDigital intake linked to the chart
Shared clinic tablets and kiosksPatient kiosk mode with automatic logoff
Faxed referrals left on the machineReferrals read and filed into the chart
Consumer video apps for telehealthTelehealth inside the EMR

SPRY includes digital intake, a patient portal, an iPad kiosk and Fax AI, which reads and files referrals and plans of care. Two-way messaging is available as an add-on. Learn more about SPRY patient engagement.

HIPAA compliant telehealth for therapy

HHS's temporary telehealth enforcement discretion expired on May 11, 2023, and the transition period ended on August 9, 2023, so therapy telehealth must now meet HIPAA in full. See HHS guidance on HIPAA and telehealth. A HIPAA compliant telehealth EMR runs the video visit inside the same system as scheduling, documentation and billing, under the same BAA.

SPRY telehealth offers HIPAA-compliant, high-definition video consultations with built-in screen sharing for exercise demonstration, and visits are booked in the same scheduler as in-person appointments.

How SPRY handles HIPAA

SPRY security and compliance at a glance
AreaWhat SPRY provides
Business associate agreementSPRY signs a BAA committing to HIPAA safeguards, breach and unauthorized-use reporting, matching terms for subcontractors and return or protection of PHI at termination
CertificationONC-certified EHR (late 2025)
TelehealthHIPAA-compliant video consultations with screen sharing
Patient communicationDigital intake, patient portal and kiosk; two-way messaging add-on
Reliability and support99.9% uptime, 24/7 support and a dedicated account manager
MigrationData migrated for you in as few as 30 days

Read SPRY's business associate agreement. Ask SPRY, like any vendor, for its current security documentation during evaluation.

Customer results

  • The Therapy Network (5 clinics) reported 98% clean claims on first submission, roughly one-third fewer denials and more than 1,300 staff hours saved, worth about $79,000, after moving to SPRY (Healthcare IT News).
  • Excel Therapy migrated its data in under 48 hours with no workflow interruptions and reported a 95%+ clean claim rate and $50,000 more revenue in year one (case study).

SPRY is rated 4.8 on G2 and Capterra and was ranked #1 for physical and occupational therapy by Black Book Research in 2026.

HIPAA EMR vendor checklist

HIPAA EMR vendor checklist

Tick each item you have confirmed in writing for the EMR you use or are evaluating. The checklist shows your gaps and the rule each one relates to.

    This checklist is a planning aid, not legal advice or a HIPAA audit. HHS does not certify software as HIPAA compliant. This tool does not store any data.

    Compare full feature sets in the PT EMR buyer's guide. Mental health and substance use providers have extra rules; see mental health EMR software.

    Frequently asked questions

    What makes an EMR HIPAA compliant?

    An EMR supports HIPAA compliance when it provides the Security Rule's safeguards, such as access control, audit logs, encryption and backups, and the vendor signs a BAA. Your clinic must still assign access, train staff and run its own risk analysis.

    Is there a HIPAA certification for EMR software?

    No. HHS does not certify or recognize HIPAA certifications for software. Ask vendors for a signed BAA and evidence of their safeguards, such as an independent security report.

    Is SPRY HIPAA compliant?

    SPRY signs a business associate agreement, offers HIPAA-compliant telehealth video and is an ONC-certified EHR. Intake, the patient portal, kiosk and messaging run inside the same platform.

    Does SPRY sign a business associate agreement?

    Yes. SPRY's BAA commits it to HIPAA safeguards, reporting unauthorized use or disclosure of PHI, holding subcontractors to the same terms, and returning or protecting PHI when the agreement ends.

    Is it HIPAA compliant to text patients?

    Texting PHI from personal phones is a common risk. Use secure two-way messaging inside your EMR, covered by your vendor's BAA, and follow your clinic's policy on patient consent.

    Is telehealth for physical therapy HIPAA compliant?

    It can be, if the video platform meets HIPAA and the vendor signs a BAA. HHS's temporary telehealth enforcement discretion ended in 2023, so consumer video apps without a BAA are no longer covered.

    What is the difference between ONC certification and HIPAA compliance?

    ONC certification shows an EHR meets federal health IT criteria, which supports MIPS Promoting Interoperability. HIPAA compliance is about how PHI is protected and is shared between the vendor and your clinic.

    How fast must a HIPAA breach be reported?

    Individuals must be notified without unreasonable delay and no later than 60 days after discovery. Breaches affecting 500 or more people must also be reported to HHS within 60 days.

    What is changing in the HIPAA Security Rule?

    HHS has proposed requiring encryption, multi-factor authentication, regular vulnerability scans and penetration tests, and annual compliance audits. As of October 2026 the update is still a proposal, not a final rule.

    Share on Socials:

    Reduce costs and improve your reimbursement rate with a modern, all-in-one clinic management software.

    Get a Demo
    Table of Content
    Have a question? Ask someone who actually knows

    Case Study

    90% Engagement Lift & 70% Reduction in Check-In Time at Excel Therapy

    Read Case Study

    Ready to Maximize Your Savings?

    See how other clinics are saving with SPRY.

    Transform Your

    HIPAA Compliant

    Practice Today

    See How SPRY Addresses Unique

    HIPAA Compliant

    Challenges