Summary: What a HIPAA compliant EMR for physical, occupational and speech therapy needs in 2026: the Security Rule's administrative, physical and technical safeguards, a signed business associate agreement, breach notification deadlines, secure messaging and telehealth, the proposed Security Rule update (not yet final), how SPRY handles HIPAA, and an interactive HIPAA EMR vendor checklist.
A HIPAA compliant EMR for physical, occupational and speech therapy is one that supports the HIPAA Security Rule's administrative, physical and technical safeguards and whose vendor signs a business associate agreement (BAA) with your clinic. There is no official HIPAA certification for software, so compliance is shared: the vendor protects the system, and your clinic controls who has access, trains staff and runs its own risk analysis. SPRY offers a BAA, HIPAA-compliant telehealth video and an ONC-certified EHR, with messaging, intake and the patient portal in the same platform.
Below: what HIPAA requires of a therapy EMR, what the vendor and clinic each own, breach deadlines, the proposed Security Rule update, secure messaging and telehealth, how SPRY handles HIPAA, a vendor checklist and FAQs.
What HIPAA requires from a PT, OT or SLP EMR
| Safeguard | Key standards | What to check in your EMR |
|---|---|---|
| Administrative | Risk analysis, security official, workforce training, incident procedures, contingency plan, business associate agreements | A signed BAA, backup and recovery plans, and reports that support your risk analysis |
| Physical | Facility access, workstation use and security, device and media controls | Hosting in secured data centers; guidance for clinic tablets, kiosks and shared workstations |
| Technical | Access control, audit controls, integrity, authentication, transmission security | Role-based access, audit logs, automatic logoff, strong sign-in and encryption |
Source: HHS HIPAA Security Rule. HHS does not require or recognize a HIPAA certification, so ask vendors for evidence rather than a badge.
Who is responsible for what: vendor vs clinic
| Area | EMR vendor (business associate) | Your clinic (covered entity) |
|---|---|---|
| Contract | Signs and follows the BAA | Keeps a signed BAA with every vendor that handles PHI |
| System security | Hosting, encryption, backups, patching and audit logging | Uses the features: user roles, logoff settings and strong passwords |
| Access | Provides role-based permissions | Assigns roles, removes former staff promptly and reviews access |
| Training | Documents how features work | Trains staff on HIPAA and on safe use of the EMR |
| Risk analysis | Shares security information | Runs and documents its own risk analysis |
| Breaches | Reports breaches to the clinic | Notifies patients, HHS and, if required, the media |
HIPAA breach notification deadlines
| Notice | Deadline |
|---|---|
| Business associate to covered entity | Without unreasonable delay and no later than 60 days after discovery |
| Affected individuals | Without unreasonable delay and no later than 60 days after discovery |
| HHS, 500 or more individuals | Within 60 days of discovery |
| HHS, fewer than 500 individuals | Within 60 days after the end of the calendar year |
| Media | When more than 500 residents of a state or jurisdiction are affected, within 60 days |
Source: HHS Breach Notification Rule.
The proposed HIPAA Security Rule update
HHS proposed the first major update to the Security Rule in December 2024, and it was published in January 2025. As of October 2026 it is still a proposal, not a final rule. It would make encryption and multi-factor authentication required, remove the difference between required and addressable specifications, and add regular vulnerability scanning, penetration testing and compliance audits. Asking EMR vendors about these items now prepares you for the final rule. See the HHS fact sheet on the proposed rule.
| Proposed change | Question for your vendor |
|---|---|
| Encryption of ePHI at rest and in transit | Is all patient data encrypted in storage and in transit? |
| Multi-factor authentication | Can we require MFA for every user? |
| Vulnerability scans every 6 months and penetration tests every 12 months | How often do you scan and test, and can we see a summary? |
| Annual compliance audit | Do you have an independent security report, such as SOC 2 or HITRUST? |
| All specifications required | Which safeguards are switched on by default? |
Secure messaging, intake and patient communication
In outpatient therapy, PHI often leaks outside the EMR: staff text patients from personal phones, email home exercise programs or leave intake forms on paper. Moving these tasks into the EMR keeps them under the same safeguards and the same BAA.
| Risk point | Safer workflow |
|---|---|
| Texting patients from personal phones | Two-way messaging inside the EMR |
| Emailing exercise programs and documents | Share through the patient portal |
| Paper intake and consent forms | Digital intake linked to the chart |
| Shared clinic tablets and kiosks | Patient kiosk mode with automatic logoff |
| Faxed referrals left on the machine | Referrals read and filed into the chart |
| Consumer video apps for telehealth | Telehealth inside the EMR |
SPRY includes digital intake, a patient portal, an iPad kiosk and Fax AI, which reads and files referrals and plans of care. Two-way messaging is available as an add-on. Learn more about SPRY patient engagement.
HIPAA compliant telehealth for therapy
HHS's temporary telehealth enforcement discretion expired on May 11, 2023, and the transition period ended on August 9, 2023, so therapy telehealth must now meet HIPAA in full. See HHS guidance on HIPAA and telehealth. A HIPAA compliant telehealth EMR runs the video visit inside the same system as scheduling, documentation and billing, under the same BAA.
SPRY telehealth offers HIPAA-compliant, high-definition video consultations with built-in screen sharing for exercise demonstration, and visits are booked in the same scheduler as in-person appointments.
How SPRY handles HIPAA
| Area | What SPRY provides |
|---|---|
| Business associate agreement | SPRY signs a BAA committing to HIPAA safeguards, breach and unauthorized-use reporting, matching terms for subcontractors and return or protection of PHI at termination |
| Certification | ONC-certified EHR (late 2025) |
| Telehealth | HIPAA-compliant video consultations with screen sharing |
| Patient communication | Digital intake, patient portal and kiosk; two-way messaging add-on |
| Reliability and support | 99.9% uptime, 24/7 support and a dedicated account manager |
| Migration | Data migrated for you in as few as 30 days |
Read SPRY's business associate agreement. Ask SPRY, like any vendor, for its current security documentation during evaluation.
Customer results
- The Therapy Network (5 clinics) reported 98% clean claims on first submission, roughly one-third fewer denials and more than 1,300 staff hours saved, worth about $79,000, after moving to SPRY (Healthcare IT News).
- Excel Therapy migrated its data in under 48 hours with no workflow interruptions and reported a 95%+ clean claim rate and $50,000 more revenue in year one (case study).
SPRY is rated 4.8 on G2 and Capterra and was ranked #1 for physical and occupational therapy by Black Book Research in 2026.
HIPAA EMR vendor checklist
HIPAA EMR vendor checklist
Tick each item you have confirmed in writing for the EMR you use or are evaluating. The checklist shows your gaps and the rule each one relates to.
This checklist is a planning aid, not legal advice or a HIPAA audit. HHS does not certify software as HIPAA compliant. This tool does not store any data.
Compare full feature sets in the PT EMR buyer's guide. Mental health and substance use providers have extra rules; see mental health EMR software.
Frequently asked questions
What makes an EMR HIPAA compliant?
An EMR supports HIPAA compliance when it provides the Security Rule's safeguards, such as access control, audit logs, encryption and backups, and the vendor signs a BAA. Your clinic must still assign access, train staff and run its own risk analysis.
Is there a HIPAA certification for EMR software?
No. HHS does not certify or recognize HIPAA certifications for software. Ask vendors for a signed BAA and evidence of their safeguards, such as an independent security report.
Is SPRY HIPAA compliant?
SPRY signs a business associate agreement, offers HIPAA-compliant telehealth video and is an ONC-certified EHR. Intake, the patient portal, kiosk and messaging run inside the same platform.
Does SPRY sign a business associate agreement?
Yes. SPRY's BAA commits it to HIPAA safeguards, reporting unauthorized use or disclosure of PHI, holding subcontractors to the same terms, and returning or protecting PHI when the agreement ends.
Is it HIPAA compliant to text patients?
Texting PHI from personal phones is a common risk. Use secure two-way messaging inside your EMR, covered by your vendor's BAA, and follow your clinic's policy on patient consent.
Is telehealth for physical therapy HIPAA compliant?
It can be, if the video platform meets HIPAA and the vendor signs a BAA. HHS's temporary telehealth enforcement discretion ended in 2023, so consumer video apps without a BAA are no longer covered.
What is the difference between ONC certification and HIPAA compliance?
ONC certification shows an EHR meets federal health IT criteria, which supports MIPS Promoting Interoperability. HIPAA compliance is about how PHI is protected and is shared between the vendor and your clinic.
How fast must a HIPAA breach be reported?
Individuals must be notified without unreasonable delay and no later than 60 days after discovery. Breaches affecting 500 or more people must also be reported to HHS within 60 days.
What is changing in the HIPAA Security Rule?
HHS has proposed requiring encryption, multi-factor authentication, regular vulnerability scans and penetration tests, and annual compliance audits. As of October 2026 the update is still a proposal, not a final rule.
Reduce costs and improve your reimbursement rate with a modern, all-in-one clinic management software.
Get a DemoLegal Disclosure:- Comparative information presented reflects our records as of Nov 2025. Product features, pricing, and availability for both our products and competitors' offerings may change over time. Statements about competitors are based on publicly available information, market research, and customer feedback; supporting documentation and sources are available upon request. Performance metrics and customer outcomes represent reported experiences that may vary based on facility configuration, existing workflows, staff adoption, and payer mix. We recommend conducting your own due diligence and verifying current features, pricing, and capabilities directly with each vendor when making software evaluation decisions. This content is for informational purposes only and does not constitute legal, financial, or business advice.




.webp)

