Guides

How to pick HIPAA-compliant scheduling software for US physical therapy clinics

HIPAA physical therapy scheduling software must cover online booking, reminders and messaging with business associate agreements and Security Rule safeguards.

What to take away

  • HIPAA physical therapy scheduling software must sign a business associate agreement before any patient data flows.
  • Online booking, appointment reminders and patient messaging tools all create HIPAA obligations under the Privacy Rule and Security Rule.
  • Vendors must encrypt data in transit and at rest, log access, and support breach notification.
  • Patients can request restrictions, access and amendments to scheduling data, and you must honor those rights.
  • Costs vary, but the contract must state who pays for a breach and how data is returned or destroyed.

What HIPAA requires of online booking and patient messaging

The HIPAA Privacy Rule sets national standards for protecting individually identifiable health information. It applies to covered entities, which includes most physical therapy clinics that bill insurance electronically. A scheduling system that collects names, dates of birth, diagnoses or treatment notes is handling protected health information (PHI).

Online booking requirements start with identity verification. If a patient books a physical therapy appointment through a public web form, the form must not expose PHI to unauthorized parties. That means secure sockets layer encryption, no PHI in URLs, and no confirmation emails that list a diagnosis or treatment type.

The HIPAA Security Rule adds technical safeguards. The rule requires access controls, audit controls, integrity controls and transmission security. For scheduling software, that means role-based logins, an audit trail of who viewed or changed an appointment, and encryption of data in transit and at rest.

Patient messaging tools are where many clinics slip. A vendor that sends unencrypted text messages containing appointment details may be transmitting PHI without safeguards. The Department of Health and Human Services has not endorsed standard SMS for PHI.

If you use text reminders, the message should contain the minimum necessary information, such as a time and clinic name, not a diagnosis.

A business associate agreement (BAA) is mandatory before you share PHI with a scheduling vendor. The BAA must describe permitted uses, require safeguards, and mandate reporting of breaches. Without a signed BAA, using the software for patient data is a violation.

For a broader look at how scheduling fits into clinic operations, see physical therapy operations.

Online booking requirements

  • Verify patient identity before showing appointment slots.
  • Use HTTPS for every page that collects or displays PHI.
  • Avoid pre-filled fields that reveal prior treatment.
  • Offer a privacy notice before the patient submits data.
  • Log every booking, change and cancellation with a user ID and timestamp.

Appointment reminders

Reminders are treatment communications under the Privacy Rule. A reminder can include the appointment time, provider name and location. It should not include the reason for the visit unless the patient has agreed in writing. Automated voice, email and text reminders all count.

Patient messaging tools

Secure messaging portals are preferable to standard email or SMS. The tool must encrypt messages, authenticate both parties, and allow patients to download or transmit their data. If the vendor cannot produce a BAA and a security overview, do not use it for PHI.

Privacy Rule duties for appointment reminders and confirmations

The HIPAA Privacy Rule gives patients rights over their scheduling data. You must provide a notice of privacy practices that explains how you use appointment information. You must also honor requests for confidential communications.

A patient can ask you to contact them only at a specific phone number or address. You must accommodate reasonable requests. If the patient says do not leave a voicemail, the reminder system must respect that flag.

The minimum necessary standard applies. For a confirmation, the minimum necessary is the date, time and clinic location. Adding the treating therapist's name is usually fine. Adding the diagnosis is not.

Patients also have a right to access their scheduling records. If a patient asks for a copy of appointment history, you must provide it in the form and format requested, if readily producible. The software should export that history.

When a patient requests an amendment to correct a wrong date of birth or contact number, you must act on it. Scheduling systems that lock patient demographics create compliance problems.

State laws can be stricter than HIPAA. California's Confidentiality of Medical Information Act, Texas laws on medical records, and New York's rules on HIV-related information all add layers. A national vendor must support state-specific consent flags.

For a state-by-state view of rules that affect opening and running a clinic, see the physical therapy compliance checklist.

Confirmation calls and voicemails

A confirmation call to a home number can be heard by family members. The Privacy Rule allows you to leave a brief message with the appointment time and clinic name unless the patient has requested otherwise. Avoid mentioning the reason for the visit.

Email and portal confirmations

Email is not inherently secure. If you send confirmations by email, use encryption or a patient portal. The patient must consent to email communication after being told of the risks. Keep that consent in the chart.

Security Rule safeguards for scheduling software vendors

The HIPAA Security Rule has three safeguard categories: administrative, physical and technical. For scheduling software, the technical safeguards matter most, but you still need a vendor that documents all three.

Administrative safeguards include a risk analysis, a sanction policy for workforce members who violate rules, and a contingency plan. Ask the vendor for its most recent risk analysis summary and its breach response plan.

Physical safeguards cover the data centers where your scheduling data lives. The vendor should provide evidence of locked facilities, visitor logs and workstation security. Cloud vendors often use third-party audits such as SOC 2 Type II to show this.

Technical safeguards include unique user identification, emergency access procedures, automatic logoff, and encryption. The vendor must encrypt PHI in transit using TLS 1.2 or higher and at rest using AES-256 or equivalent. It must also log access and retain logs for at least six years.

Audit controls are a common gap. The software should record who accessed which appointment record and when. If a staff member looks up a celebrity patient's schedule out of curiosity, the audit log should catch it.

Integrity controls ensure data is not altered improperly. The system should use checksums or versioning. Transmission security covers email, text and API connections. Every integration, including billing and telehealth, must be encrypted.

Vendors must also support breach notification. Under the HIPAA Breach Notification Rule, you must notify affected patients within 60 days of discovering a breach. The vendor must alert you without unreasonable delay, ideally within 24 to 72 hours.

The Federal Trade Commission also enforces data security for health apps and some vendors. Its Business Guidance | Federal Trade Commission explains how unfair or deceptive data practices can lead to enforcement, even for companies that are not covered entities.

Questions to ask about technical safeguards

  • Do you encrypt data at rest and in transit?
  • Do you support multi-factor authentication for all users?
  • How long do you retain audit logs, and can we export them?
  • What is your uptime and disaster recovery record?
  • Will you notify us of a breach within 24 hours?

Vendor security documentation

Ask for a completed security questionnaire, a copy of the BAA, and evidence of independent audits. A vendor that hesitates on any of these is a risk. For a comparison framework that includes security criteria, see physical therapy software.

Business associate agreements and vendor due diligence

A business associate agreement is a contract required by the HIPAA Privacy Rule. It must be in place before the vendor creates, receives, maintains or transmits PHI on your behalf. The BAA cannot be a generic click-through. It must name the permitted uses and disclosures.

The BAA should require the vendor to implement safeguards, report breaches, and ensure subcontractors sign their own BAAs. It should also address what happens at termination: return or destruction of PHI, and a certificate of destruction.

Due diligence goes beyond the BAA. Check the vendor's HIPAA compliance history. Search the HHS Office for Civil Rights breach portal for the vendor's name. Check the FTC's Business Guidance Resources | Federal Trade Commission for enforcement actions involving health data.

Ask for the name of the vendor's privacy officer and security officer. A serious vendor will have both. Ask whether the vendor has cyber insurance and how much. Ask whether it will indemnify your clinic for its own breaches.

Review subcontractors. If the vendor uses a cloud host, a text messaging gateway or an analytics provider, those subcontractors also need BAAs. The vendor should list them and confirm they are covered.

Keep a copy of every BAA and every security document. During an OCR investigation, you will need to show that you performed due diligence. A simple vendor file with dates and documents is enough.

For more on how vendor choices affect the business, see choosing physical therapy software.

BAA clauses to negotiate

  • Breach notification timeline, ideally 24 to 72 hours.
  • Right to audit the vendor's security controls.
  • Data ownership and export in a usable format.
  • Indemnification for vendor-caused breaches.
  • Destruction or return of data at contract end.

Red flags in vendor contracts

A vendor that refuses to sign a BAA is not usable for PHI. A vendor that claims it is not a business associate because it only stores data is wrong. A vendor that will not disclose subcontractors is hiding risk. A vendor that limits breach notification to 30 days or more is too slow.

Checklist for evaluating HIPAA-compliant scheduling software

Use this checklist before you sign. It covers online booking, reminders, messaging and vendor safeguards. Each item should have a documented answer.

  • Signed business associate agreement in place before any PHI is shared.
  • Online booking uses HTTPS and does not expose PHI in URLs or confirmation emails.
  • Appointment reminders follow the minimum necessary standard and honor patient communication preferences.
  • Patient messaging tools encrypt messages and support secure patient portals.
  • Role-based access controls and unique user IDs for every staff member.
  • Audit logs record who viewed or changed each appointment and are retained for at least six years.
  • Data encrypted in transit and at rest, with documented encryption standards.
  • Breach notification process with a defined timeline and named contact.
  • Data export and destruction process documented in the contract.
  • Vendor provides evidence of independent security audits, such as SOC 2 Type II.
  • Subcontractors are listed and covered by their own BAAs.
  • Patient rights to access, amend and restrict communications are supported.

Table: compliance feature comparison

Feature Required by HIPAA? What to verify
Business associate agreement Yes Signed before go-live, covers subcontractors
Encryption in transit Yes TLS 1.2 or higher
Encryption at rest Yes AES-256 or equivalent
Audit logs Yes User ID, timestamp, record accessed, 6-year retention
Role-based access Yes Unique logins, no shared accounts
Patient messaging encryption Yes Portal or encrypted email, not standard SMS
Breach notification Yes 24 to 72 hour vendor notice
Data export Yes Usable format on request
Multi-factor authentication Recommended Available for all users
SOC 2 Type II report Recommended Current, no exceptions

Worked example: evaluating a reminder vendor

Suppose a vendor offers automated text reminders for $49 per month. It says it is HIPAA compliant but will not sign a BAA. It sends messages through a standard SMS gateway. The messages include the patient's name and appointment time.

Under the Privacy Rule, the appointment time and clinic name are usually acceptable with patient consent. The patient's name in an unencrypted text is riskier. Without a BAA, the vendor is not permitted to handle PHI. The clinic should reject the vendor or require a BAA and encrypted messaging. If the vendor refuses, use a secure portal instead.

Patient rights around scheduling data and communications

The HIPAA Privacy Rule gives patients the right to inspect and copy their records, including appointment history. You must respond within 30 days, with one 30-day extension if needed. You may charge a reasonable cost-based fee.

Patients can request an amendment to scheduling data. If you deny the request, you must provide a written denial and allow the patient to submit a statement of disagreement. The scheduling system should support these workflows or integrate with the EHR that does.

Patients can request restrictions on disclosures. For scheduling, a common request is to not leave voicemails or to use a specific phone number. You must accommodate reasonable requests. You are not required to agree to restrict disclosures to a health plan for treatment purposes, but you must honor requests for confidential communications.

Patients also have a right to an accounting of disclosures. Most scheduling communications are for treatment, payment or operations, which are exempt from accounting. But if you disclose scheduling data to an employer or school, that may need to be tracked.

When a patient uses an online booking portal, they may be creating data in a system you do not control. The vendor must give patients a way to access and correct that data. The BAA should require the vendor to support patient rights.

State laws can add rights. California allows patients to request restrictions on disclosures to health plans. Texas has specific rules on mental health records. New York requires special handling for HIV-related information. A national scheduling system should allow configurable consent flags.

For licensing and regulatory context that affects how you handle patient data, see physical therapy licensing requirements.

Access and amendment requests

  • Log every request with date and response.
  • Provide records in the format requested if readily producible.
  • Charge only reasonable cost-based fees.
  • Document any denial and the patient's right to review.

Confidential communications

  • Ask patients at intake how they want to be contacted.
  • Record the preference in the scheduling system.
  • Train staff to check the flag before sending reminders.
  • Update the preference whenever the patient asks.

Cost and contract questions before purchase

Pricing for HIPAA-compliant scheduling software varies. Small clinics may pay $50 to $150 per provider per month. Larger clinics may pay more for modules, messaging and analytics. The BAA and security features are usually included, but some vendors charge extra for secure messaging.

Ask about implementation fees, training, and data migration. Moving from a non-compliant spreadsheet to a compliant system takes time. Ask who configures the reminder templates and who validates the BAA.

Contract terms matter. Look for a termination clause that lets you export data. Avoid auto-renewal clauses that lock you in for years without a compliance review. Ask whether the vendor can change the BAA without your consent.

Ask about liability. If the vendor causes a breach, who pays for notification, credit monitoring and OCR fines? A strong contract includes indemnification. Ask for the vendor's cyber insurance certificate.

Check the total cost of ownership. Add the subscription, implementation, messaging fees, and staff training. Compare that to the cost of a breach, which can include fines, legal fees and lost patients.

The Federal Register publishes health rules that can affect scheduling systems, including changes to HIPAA and CMS programs. Monitor Federal Register :: Health & Public Welfare for updates that may require contract changes.

For legal research on healthcare business rules, the FTC's Legal Library: Browse | Federal Trade Commission is a useful starting point. It collects enforcement actions and guidance that can inform your vendor review.

Cost components to compare

Cost item Typical range Notes
Per-provider subscription $50 to $150 per month Includes scheduling and reminders
Implementation $500 to $2,000 one time Data migration and training
Secure messaging add-on $10 to $30 per provider per month Some vendors bundle it
BAA review $0 to $500 Legal review of vendor BAA
Breach insurance Varies Vendor should carry its own

Contract questions

  • Can we export all data in a usable format at any time?
  • What is the breach notification timeline?
  • Will you sign our BAA or use yours?
  • Who are your subcontractors, and are they covered by BAAs?
  • What happens to our data if we cancel?
  • Do you indemnify us for your breaches?
  • How often do you test your security controls?

Common questions

Do I need a BAA if the scheduling vendor only stores appointment times? Yes. Appointment times linked to a patient are PHI. Any vendor that creates, receives, maintains or transmits PHI on your behalf needs a BAA.

Can I use standard text messages for appointment reminders? Standard SMS is not encrypted. If the message contains only the time and clinic name, and the patient consents, it may be acceptable. Avoid names, diagnoses or treatment details.

What encryption standard should I require? Require TLS 1.2 or higher for data in transit and AES-256 or equivalent for data at rest. Ask the vendor to document this in writing.

How long should audit logs be kept? The HIPAA Security Rule requires retention of documentation for six years. Audit logs should be kept at least that long.

What if a vendor refuses to sign a BAA? Do not use that vendor for any PHI. You can use it for de-identified data only, which is rarely useful for scheduling.

Do state laws change what I need? Yes. California, Texas, New York and other states have stricter rules for certain data. Choose software that supports state-specific consent and communication flags.

More in Guides

Guides

How Denver physical therapy practices use direct access for self-scheduling

Denver physical therapy self-scheduling works because Colorado direct access lets patients book PT first, and clinics can add cash-pay packages for outdoor athletes.

Guides

3 cash-pay physical therapy packages that work in high-deductible US insurance markets

Cash-pay physical therapy packages can stabilize revenue when high-deductible plans leave patients paying out of pocket. Here are three models.

Latest from Method Desk