Empower Your Practice

Journal for Practice Managers

Chiropractic EHR Compliance Requirements: Full US Guide

Kate Pope
Written by
Kate Pope
Vlad Kovalskiy
Reviewed by
Vlad Kovalskiy
Last updated:
Expert Verified

Chiropractic EHR compliance requirements are more complex than most practitioners realize, and the cost of getting them wrong can be severe. From HIPAA violations carrying fines of up to $50,000 per incident to OIG audit scrutiny over billing irregularities, chiropractors operate in one of the most compliance-intensive corners of healthcare.

This article answers which system actually protects your license, your revenue, and your patients. That means walking through HIPAA, federal billing law, certified EHR requirements, MIPS/MACRA obligations, and compliant discounting rules in plain language backed by real enforcement data.

Use this guide to audit your current setup, evaluate new software, and ensure your practice is protected heading into 2026 and beyond.

Why Chiropractic EHR Compliance Requirements Matter More Than You Think

Chiropractors are among the most audited healthcare providers in the United States. The Office of Inspector General (OIG) has repeatedly identified chiropractic billing as a high-risk area, with improper Medicare payments for chiropractic services totaling hundreds of millions of dollars annually. In fiscal year 2023 alone, OIG Work Plan activities flagged chiropractic subluxation documentation as a persistent compliance gap.

Under the False Claims Act, providers who knowingly submit incorrect claims to Medicare or Medicaid face civil penalties of $13,946 to $27,894 per false claim. Criminal charges are possible in egregious cases. The Anti-Kickback Statute adds another layer: any financial arrangement that even appears to reward patient referrals, including certain discounting practices, can trigger federal prosecution.

And that's before HIPAA enters the picture. The Health Insurance Portability and Accountability Act imposes mandatory safeguards on all electronic health records. A single preventable data breach can cost a small chiropractic practice tens of thousands of dollars in fines and remediation costs, plus the reputational damage that follows.

The right chiropractic EHR system acts as a structural compliance safeguard, building correct behavior into every workflow so that documentation, coding, billing, and data security happen the right way by default.

HIPAA Compliance Requirements for Chiropractic Electronic Health Records

HIPAA compliance is the baseline requirement for any practice that stores, transmits, or accesses electronic health records. For chiropractic practices, this means implementing both the Privacy Rule and the Security Rule across every system that touches patient data.

The Privacy Rule

The Privacy Rule governs how protected health information (PHI) can be used and disclosed. For chiropractic practices, this means:

  • Patients must receive a Notice of Privacy Practices at their first visit
  • PHI can only be shared for treatment, payment, or healthcare operations without explicit patient authorization
  • Patients have the right to access and amend their records
  • Minimum necessary standards apply: staff should only access the data they need for their specific role

A compliant chiropractic EHR enforces these rules automatically through role-based access controls, ensuring front-desk staff cannot view clinical notes they have no reason to access, and that providers cannot inadvertently expose billing data to unauthorized parties.

The Security Rule

The Security Rule applies specifically to electronic PHI (ePHI) and requires administrative, physical, and technical safeguards. For chiropractic EHR systems, the critical technical requirements include:

  • Data encryption: All ePHI must be encrypted both at rest and in transit. This is non-negotiable for any cloud-based EHR or system transmitting data over the internet.
  • Audit controls: The system must record and examine activity in systems containing ePHI
  • Automatic logoff: Workstations must time out after periods of inactivity
  • Unique user IDs: Every staff member must have individual login credentials; shared passwords are a HIPAA violation
  • Emergency access procedures: The practice must be able to access ePHI during system outages

HIPAA Violation Penalties: What's Actually at Stake

Many chiropractors underestimate HIPAA's financial consequences. Penalties are tiered based on culpability:

Violation CategoryMinimum PenaltyMaximum Penalty
Lack of knowledge, despite reasonable diligence$145 per violation$73,011 per violation
Reasonable cause, not willful neglect$1,461 per violation$73,011 per violation
Willful neglect, corrected within 30 days$14,602 per violation$73,011 per violation
Willful neglect, not corrected within 30 days$73,011 per violation$2,190,294 per violation

These are the inflation-adjusted amounts applicable in 2026. The annual penalty cap for identical violations is $2,190,294.

The actual penalty depends on the nature and number of HIPAA violations, the circumstances surrounding them, the harm involved, and other factors considered by the Office for Civil Rights. A data breach affecting hundreds of patients can therefore create significant financial exposure, but HIPAA does not simply impose a separate maximum penalty for every patient record exposed.

For chiropractors, this makes patient-data security more than a technical feature. It is an essential part of protecting the practice from regulatory, financial, and reputational risk.

Certified vs. Non-Certified EHR: A Distinction That Costs Money

One of the most consequential and least-discussed distinctions in chiropractic EHR software is whether the system is a certified EHR under CMS standards. This matters for two reasons: Medicare reimbursement and MIPS participation.

CMS requires that providers participating in certain quality programs use certified EHR technology (CEHRT). A non-certified system may offer all the same clinical features as a certified one but it cannot be used for Meaningful Use attestation or MIPS reporting, which can trigger financial penalties.

For chiropractors who bill Medicare, failing to use certified EHR technology under MACRA legislation (the Medicare Access and CHIP Reauthorization Act) can result in a negative payment adjustment on all Medicare Part B claims. As of recent program years, that penalty can reach -9% of your Medicare reimbursement.

How to verify certification: Search the ONC Certified Health IT Product List (CHPL) at healthit.gov. Vendors should be able to provide their ONC certification number on request. When evaluating software like ChiroTouch, DrChrono, PrognoCIS, or any other platform, confirm certification status before purchase.

MIPS Reporting and MACRA Compliance for Chiropractors

MIPS (Merit-based Incentive Payment System) is the primary quality reporting framework under MACRA legislation for most eligible clinicians, including chiropractors. Participation is not always mandatory, but the consequences of non-participation or poor performance are real.

Who Must Participate in MIPS?

Chiropractors who bill Medicare and meet minimum thresholds (currently: more than $90,000 in Medicare Part B allowed charges AND more than 200 Medicare patients per year) are required to participate in MIPS. Those who fall below these thresholds are exempt but can participate voluntarily.

MIPS Performance Categories

MIPS reporting scores are calculated across four performance categories:

  1. Quality (30%) — Submit quality measures relevant to chiropractic care, such as functional outcomes assessments and patient-reported outcomes for musculoskeletal conditions
  2. Promoting Interoperability (25%) — Demonstrate use of certified EHR technology, including patient portal engagement, electronic prescribing, and health information exchange
  3. Improvement Activities (15%) — Document care coordination, patient engagement, and population management activities
  4. Cost (30%) — CMS calculates this automatically from claims data

A compliant chiropractic EHR automates much of the MIPS data collection, generating the reports needed for submission without requiring manual chart review. Systems that do not support MIPS reporting force providers to handle this manually or miss the deadlines entirely.

Meaningful Use: The Foundation of Promoting Interoperability

Meaningful Use (now called Promoting Interoperability) established the framework for how providers must use certified EHR technology. For chiropractors still evaluating systems, Meaningful Use attestation historically required demonstrating that the EHR was being actively used for core clinical functions.

The current Promoting Interoperability category continues this logic, rewarding practices that use their EHR to engage patients through a patient portal, exchange records electronically, and submit immunization data where applicable.

Billing Compliance: ICD-10 Coding, CPT Codes, and the Documentation Trap

Chiropractic billing compliance is where most enforcement actions originate. The gap between what chiropractors document and what they bill is the single largest OIG audit trigger, and it's an area where the right EHR system provides direct, measurable protection.

ICD-10 Coding for Chiropractic Care

ICD-10 coding accuracy is mandatory for all claims. Chiropractic diagnoses must be specific, current, and supported by clinical documentation. Common ICD-10 codes used in chiropractic practice include subluxation codes (M99.01–M99.09), spinal pain codes, and codes for musculoskeletal conditions treated through spinal adjustments and manipulation.

For 2026, CMS has introduced updates to the ICD-10-CM code set that affect chiropractic documentation. New specificity requirements mean that older, non-specific codes are increasingly being rejected by payers. A chiropractic EHR with built-in, updated ICD-10 coding libraries and automated claims scrubbing catches these errors before submission, preventing denials and protecting against audit exposure.

CPT Codes and Chiropractic Modifiers

Chiropractic manipulation CPT codes (98940, 98941, 98942) correspond to the number of spinal regions treated. Upcoding is one of the most common HIPAA violations and OIG audit findings. Downcoding, while less scrutinized, represents lost revenue.

Chiropractic modifiers add critical context to claims. The AT modifier (active/acute treatment) is required on Medicare claims to indicate that care is medically necessary and not maintenance in nature. Omitting the AT modifier on appropriate claims results in automatic claim denial; including it on maintenance care is a compliance violation.

A compliant EHR system prompts providers to apply correct chiropractic modifiers based on documentation, reducing the likelihood of both underbilling and fraudulent billing.

2026 also sees expanding use of remote monitoring CPT codes in chiropractic contexts, particularly for practices treating chronic musculoskeletal conditions. Staying current on these additions is part of ongoing billing compliance.

Medical Necessity: The Documentation Foundation

Every chiropractic claim submitted to Medicare or Medicaid must be supported by documentation establishing medical necessity. CMS defines medically necessary chiropractic services as those involving manual manipulation of the spine to correct a subluxation.

This means SOAP notes must do more than describe what happened during the visit. They must establish:

  • The patient's presenting complaint and history
  • Objective findings (range of motion, orthopedic tests, neurological status)
  • A specific diagnosis linked to an appropriate ICD-10 code
  • A treatment plan with defined goals and a reasonable prognosis for improvement
  • The specific spinal adjustments performed, with regions identified

soap note template

SOAP notes that are copied forward without modification (a practice known as "cloning") are a major OIG audit red flag. A compliant chiropractic EHR flags cloned documentation and requires providers to input patient-specific findings at each visit.

Learn more about how cloud-based EHR systems support compliant documentation workflows.

Automated Claims Scrubbing and Revenue Cycle Management

Automated claims scrubbing is one of the highest-value features in chiropractic practice management software. Before a claim is submitted to a payer, the scrubber checks for:

  • Mismatched CPT codes and diagnoses
  • Missing or incorrect modifiers
  • Duplicate claims
  • Invalid or outdated ICD-10 coding
  • Insurance eligibility verification failures

Effective denial management is the backbone of healthy revenue cycle management. Practices without automated claims scrubbing typically see denial rates of 5–10%; those with it routinely achieve denial rates below 3%.

Insurance eligibility verification is equally important. Checking patient coverage before each visit prevents the common scenario of rendering care, billing the payer, and discovering weeks later that the patient's insurance had lapsed.

Explore how Medesk's chiropractic EHR platform supports end-to-end revenue cycle management.

Chiropractic Documentation Standards: What an Audit Actually Looks For

OIG audits of chiropractic practices follow a predictable pattern. Auditors request a sample of patient records and evaluate them against specific documentation criteria. Understanding what they look for is the first step in building audit-ready documentation systems.

The Seven Elements of Compliant Chiropractic Documentation

  1. Initial examination: A comprehensive history and physical examination establishing the baseline condition and subluxation diagnosis
  2. Diagnosis: Specific ICD-10 diagnosis codes supported by objective clinical findings
  3. Treatment plans: Written treatment plans with specific goals, proposed frequency and duration of care, and expected functional outcomes
  4. Progress notes (SOAP notes): Patient-specific notes at every visit documenting subjective complaints, objective findings, assessment, and plan
  5. Functional outcomes assessments: Validated outcome tools (Oswestry, PROMIS, etc.) used to measure patient progress toward treatment goals
  6. Re-evaluations: Periodic re-examinations when care extends beyond typical treatment timelines
  7. Discharge planning: Documentation of when maximum therapeutic benefit has been achieved

Practices that use a chiropractic EHR with structured templates for each of these elements rather than free-text notes consistently produce more audit-ready documentation. The structure of the template itself enforces completeness.

State-Level Chiropractic Board Compliance

Federal compliance requirements are just the floor. Every state chiropractic board has its own recordkeeping requirements, which can be more stringent than federal standards. Common state-level requirements include:

  • Minimum record retention periods (typically 5–10 years; longer for minors)
  • Specific content requirements for initial examinations
  • Informed consent documentation standards
  • Requirements for maintaining records when a practice closes or a provider retires

A chiropractic EHR that allows configuration of state-specific documentation templates helps practices meet both federal and state-level compliance obligations simultaneously.

Read our guide to top policies for healthcare practices to understand how documentation policies support compliance.

Compliant Discounting: The Compliance Risk Nobody Talks About

One of the most overlooked chiropractic EHR compliance requirements involves discounting. Many chiropractors offer cash pay discounts, hardship adjustments, or participate in discount programs, and most have no idea how close to a compliance violation they are.

The Anti-Kickback Statute and Discounting

The Anti-Kickback Statute prohibits offering anything of value to induce patient referrals or to reward utilization of a healthcare service. Discounts that appear to reward patients for choosing or continuing chiropractic care can implicate this statute.

Compliant Discount Structures

There are legitimate discounting models that survive federal scrutiny:

  • Prompt pay discount: A discount offered to all patients who pay at the time of service is generally permissible, provided it is offered uniformly and not conditioned on referral behavior. The discount must be reasonable and consistently applied.
  • Hardship waiver: Routine waiver of copays or coinsurance (without individual financial need assessment) is a False Claims Act risk. Legitimate hardship waivers require documented financial need on a case-by-case basis.
  • Contractual discounts: Discounts negotiated through payer contracts are always permissible — these are the contracted rates.
  • Discount Medical Plan Organization (DMPO): Participating in a certified DMPO such as ChiroHealthUSA provides a legally structured framework for offering discounts to cash-pay patients while remaining compliant with federal law.

DMPO arrangements are recognized as a safe harbor under applicable regulations, making them one of the safest ways for chiropractors to offer discounted services.

Improper discounting is specifically cited by the OIG as a compliance risk and is explicitly prohibited under the False Claims Act. Your chiropractic practice management software should allow you to configure discount rules that are applied consistently and documented for audit purposes.

screen analytics 3

Cloud-Based EHR vs. Client-Server EHR: Compliance Risk Differences

The architecture of your EHR system has direct implications for HIPAA compliance and patient data security. This distinction is almost entirely absent from most chiropractic EHR comparisons, yet it's one of the most consequential decisions a practice will make.

Client-Server EHR Systems

In a client-server EHR, patient data is stored on a local server at your practice location. This approach puts the full burden of HIPAA's physical and technical safeguard requirements on the practice. You are responsible for:

  • Physical security of the server hardware
  • Backup and disaster recovery
  • Software updates and security patches
  • Data encryption configurations
  • Breach monitoring and detection

For a small chiropractic practice without dedicated IT staff, these responsibilities are difficult to manage consistently. A missed security patch or an unencrypted backup drive can constitute a HIPAA violation.

Cloud-Based EHR Systems

A cloud-based EHR shifts most of the technical safeguard burden to the vendor, who operates as a Business Associate under HIPAA and must sign a Business Associate Agreement (BAA) with your practice. Reputable vendors maintain:

  • Enterprise-grade data encryption (AES-256 or equivalent)
  • Redundant backup systems with geographic distribution
  • SOC 2 Type II certification, demonstrating ongoing security controls
  • 24/7 intrusion monitoring
  • Automatic security updates

SOC 2 Type II certification is a particularly important credential to verify. Unlike SOC 2 Type I (which is a point-in-time assessment), Type II certification requires a vendor to demonstrate consistent security controls over a minimum six-month audit period. When evaluating platforms, ask specifically for their SOC 2 Type II certification documentation.

For most chiropractic practices, a cloud-based EHR with a signed BAA and SOC 2 Type II certification represents significantly lower HIPAA compliance risk than a self-managed client-server system. See why cloud-based EHR is now the default choice for compliance-conscious practices.

Key Compliance Features to Require in Any Chiropractic EHR

Not all EHR systems are equal. When evaluating chiropractic practice management software, the following compliance-specific features should be non-negotiable:

Documentation and Clinical Compliance

  • Structured SOAP note templates specific to chiropractic care, with mandatory fields that enforce documentation completeness
  • Clone detection or modification prompting to prevent copy-forward documentation practices
  • Functional outcomes assessment tools integrated into the workflow (Oswestry Disability Index, Neck Disability Index, PROMIS)
  • Treatment plan management with goal tracking and re-evaluation prompts
  • Chiropractic-specific ICD-10 coding libraries updated annually

Billing and Coding Compliance

  • CPT code validation against documentation to prevent upcoding
  • Automated claims scrubbing with payer-specific rules
  • Chiropractic modifier management (AT modifier, 59 modifier, etc.)
  • Insurance eligibility verification in real time before each appointment
  • Denial management workflows with root cause tracking

Security and Privacy Compliance

  • Role-based access controls with audit trails
  • Data encryption at rest and in transit
  • BAA availability from the vendor
  • SOC 2 Type II certification
  • Automatic session timeout and unique user authentication
  • EPCS compliance for practices with prescribing providers (Electronic Prescribing for Controlled Substances)

Interoperability and Reporting

  • MIPS reporting support with automated data collection
  • Patient portal with secure messaging and record access
  • Telehealth capabilities integrated into the appointment scheduling workflow
  • CMS-compatible reporting formats for quality measure submission

Building a Compliance Program Around Your EHR

Even the best chiropractic EHR is only as effective as the compliance program surrounding it. Technology enforces processes, but the processes must exist first.

Step 1: Conduct a HIPAA Risk Assessment

HIPAA requires covered entities to conduct a thorough assessment of potential risks to ePHI. It is a required administrative safeguard. The risk assessment should identify where PHI lives, who can access it, and what controls exist to prevent unauthorized access or disclosure. Most cloud-based EHR vendors provide templates or assistance for this process.

Step 2: Establish Policies and Procedures

Document your practice's policies for privacy, security, breach response, and workforce training. These policies must be reviewed and updated regularly, at minimum annually, or whenever there is a significant change in operations or technology.

Step 3: Train Your Staff

HIPAA requires workforce training on privacy and security policies. All staff who handle patient data must be trained at hire and periodically thereafter. Document all training sessions.

Step 4: Implement a Billing Compliance Audit Process

Conduct periodic internal audits of a random sample of claims, comparing what was billed to what was documented. This mirrors what an OIG auditor would do. Many chiropractic practice management software platforms support this through reporting tools that flag statistical outliers in billing patterns.

Step 5: Designate a Compliance Officer

Even in a small practice, someone must be responsible for compliance oversight. This person monitors regulatory changes, coordinates training, and responds to potential violations. In solo practices, this is often the chiropractor themselves: the more your EHR enforces compliance automatically, the less manual oversight burden you carry.

Explore additional healthcare practice policy frameworks in our guide to top policies for healthcare practices.

How to Evaluate EHR Compliance Claims from Vendors

Every EHR vendor claims to be "HIPAA-compliant." Very few can back that claim up with evidence. Here is how to separate credible compliance claims from marketing language:

Ask for documentation, not descriptions:

  • Request the vendor's most recent SOC 2 Type II audit report (not just a certificate)
  • Request a copy of their standard Business Associate Agreement
  • Ask for their ONC certification number and verify it on the CHPL

Test the system against your workflows:

  • Does the system require specific fields to be completed before a SOAP note can be saved?
  • Can you configure role-based access controls to limit what different staff members can see?
  • Does the system flag potential upcoding or documentation gaps?

Evaluate their breach response history:

  • Has the vendor experienced a data breach? (Search HHS's Breach Notification Portal)
  • How did they respond, and what changes did they make afterward?

Review the BAA carefully:

  • Does the vendor accept full HIPAA Business Associate liability?
  • What are their obligations in the event of a data breach affecting your patients?

A vendor that hesitates on any of these questions warrants serious scrutiny. Chiropractic EHR compliance requirements demand a software partner who treats security and documentation accuracy as core product commitments, not add-on features.

Frequently Asked Questions

1. Do chiropractors use EHR?

Yes. Chiropractors use electronic health records to document patient visits, manage SOAP notes, submit insurance claims, and meet HIPAA compliance requirements. Adoption has grown significantly as Medicare billing requirements and MIPS reporting obligations make paper-based systems impractical.

2. What are the HIPAA compliance requirements for electronic health records?

HIPAA requires that electronic health records include data encryption, role-based access controls, audit logs, automatic session timeouts, and unique user authentication. Chiropractic practices must also sign a Business Associate Agreement with their EHR vendor, conduct regular risk assessments, and train staff on privacy and security policies.

3. What are the chiropractic modifiers in 2026?

The most critical chiropractic modifier is AT (active treatment), required on Medicare claims to establish that care is medically necessary rather than maintenance. Other commonly used modifiers include 59 (distinct procedural service) and GA (waiver of liability on file). Incorrect modifier use is a leading cause of claim denials and OIG audit findings.

4. What is the best software for a chiropractic clinic?

The best chiropractic EHR software is one that meets your specific compliance needs: certified EHR status for MIPS reporting, automated claims scrubbing, structured SOAP note templates, and SOC 2 Type II security certification. Leading platforms include ChiroTouch, DrChrono, PrognoCIS, SPRY, Kareo, and Medesk.

5. What is the False Claims Act risk for chiropractors?

The False Claims Act imposes civil penalties of $13,946–$27,894 per false claim submitted to Medicare or Medicaid, plus up to three times actual damages. For chiropractors, common False Claims Act risks include billing for services not rendered, upcoding CPT codes, billing maintenance care with the AT modifier, and routinely waiving Medicare copays.


EHR vs EMR: Key Differences & Advantages

EHR vs EMR: Key Differences & Advantages

EHR vs EMR: how are they different? How are they similar? Most importantly, which one does your practice need? Read our article to find out!
How to Start a Physical Therapy Clinic in 2025

How to Start a Physical Therapy Clinic in 2025

Discover how to start a successful physical therapy clinic with our comprehensive 10-step guide. Learn about business plans, financing, and more.
Top 5 Medical Dictation Software for Your Private Practice in 2025

Top 5 Medical Dictation Software for Your Private Practice in 2025

Confused by medical speech recognition software? We break down 5 top options to help you pick the perfect tool for faster, more accurate documentation.