- VanRein Compliance
- Posts
- The HIPAA Course We Built After Talking to 100+ Chiropractors
The HIPAA Course We Built After Talking to 100+ Chiropractors
ChiroFest takeaways and a new industry-specific course

Today we are officially launching HIPAA for Chiropractors, a training course built specifically for chiropractic practices, not a generic HIPAA course with your industry's name stapled on.
Chiropractic care has a compliance challenge most other practices do not: the open treatment bay. Multiple patients, multiple tables, one shared room, and a doctor moving between them asking about symptoms out loud. It is efficient, but it is also one of the highest-risk environments for verbal PHI exposure in all of healthcare. A question as ordinary as "how's the shoulder since the accident" carries down the room, and the patient two tables over just learned something they were never supposed to hear.
This course was built around moments like that. It covers what counts as PHI in a chiropractic record, from SOAP notes to adjustment logs to the whiteboard behind the front desk. It walks through the personal injury and workers' compensation cases that make up a real share of chiropractic patients, where health information intersects with legal and financial stakes. And it gives your team practical, immediate changes, how to phrase a question in an open bay, where to move a sensitive conversation, what your front desk should never say out loud. Enroll now!
We just got back from ChiroFest, the largest chiropractic conference in the Pacific Northwest, and this is our third year attending. Every year, the conversations tell us the same thing: Chiropractors know HIPAA applies to them. Most just don't have anyone helping them apply it.
A lot of what we heard was familiar. Practices building their own training from scratch. Manuals sitting on a shelf, treated as the finish line instead of the starting point. A few offices still running entirely on paper.
One moment stood out: walking the vendor floor, we asked a few EHR and practice management vendors where their trust center was and what their security posture looked like. More than one didn't have an answer. If your vendor can't tell you how they protect data, you can't tell your patients either.
The takeaway we kept repeating all week: You don't have to build this alone. Training, policies, risk assessments, that's the work we do, so you can focus on running your practice. Catch the full conversation in this week's episode.
If you want help figuring out where your practice actually stands, book a free 30-minute call with us.







Reply