HIPAA Basics Every Solo Physio Should Understand
Trebexa teamSep 18, 20262 MIN
What counts as PHI in a solo practice
- Treatment notes that reference a diagnosis, injury, or condition — the kind captured during ROM and pain score tracking
- Pain scores or ROM measurements tied to an identifiable client
- Photos that could identify a client alongside health-related context
- Any note connecting a client's identity to a health condition, even briefly
Common mistakes independent practitioners make
The most frequent gap isn't malicious — it's storing client notes in a general-purpose notes app or spreadsheet that was never designed for health data, with no encryption, no access controls, and no audit trail if something goes wrong. It often starts at intake, the first place health details get written down.What actually needs to be in place
- Encryption of stored data, both at rest and in transit
- A signed Business Associate Agreement (BAA) with any software vendor that touches PHI
- An audit log showing who accessed or changed a record, and when
- A clear policy for how long records are retained and how they're deleted
This is exactly why Trebexa offers a HIPAA-compliant storage add-on — encrypted data, a signed BAA, and a full audit log — available on paid plans for practitioners who need it, without forcing it on everyone. See Pricing for details, or contact us with compliance questions."It's probably fine" is not a HIPAA compliance strategy.
Trebexa team