Pabau Engage inbox

Pabau Engage is here: every patient conversation in one inbox.

Learn more
Book a demo Book a demo
Compliance and security

Physical therapy compliance: What US and UK physiotherapy practices must do

Avatar photo Katy Piper
Last Updated: September 22, 2026
Reviewed by: Avatar photo Lucy Galloway

Physical therapy compliance is the set of legal, professional and data duties a practice must meet to treat patients and get paid. Meeting them is only half the job, because every duty also has to be evidenced.

In the US those duties come from HIPAA, CMS, your state practice act, the HHS Office of Inspector General and OSHA. A UK physiotherapy practice answers instead to the HCPC, the Chartered Society of Physiotherapy and the Information Commissioner’s Office.

This guide maps every duty to the record that proves it, in both countries. We call that map the compliance evidence trail. It names the rule, the authority behind it, and the document an inspector asks to see.

Key takeaways
Found our content helpful?

Key takeaways

Physical therapy compliance covers patient consent, clinical records, data protection, staff licensure, billing accuracy and workplace safety.

US practices answer to HIPAA, CMS, their state licensing board, the HHS Office of Inspector General and OSHA.

UK physiotherapy practices answer to the HCPC, the Chartered Society of Physiotherapy and the Information Commissioner’s Office.

Every duty has one record that proves it, and a cadence at which someone has to review that record.

The CY 2026 KX modifier threshold is $2,480 for physical therapy and speech-language pathology combined, and $2,480 for occupational therapy.

What physical therapy compliance means

Physical therapy compliance means meeting the legal, professional, billing and data rules that govern a practice, and holding the records that prove you met them. The phrase also has a clinical sense, describing a patient’s adherence to a home exercise program. This article covers the regulatory sense.

Therapy compliance sits across five domains, and each one has a different owner. Clinical standards and licensure come from your state board or the HCPC. Privacy comes from HIPAA in the US and UK GDPR in Britain. Billing accuracy comes from CMS, with the Office of Inspector General (OIG) behind it. Workplace safety comes from OSHA.

Day to day, those five domains land on the same desk. The person who books the appointment also takes the consent, files the note and submits the claim. That is why compliance in a physical therapy practice usually fails at the record rather than at the rule.

Fraud, waste and abuse sit inside the billing domain rather than beside it. A claim for time that was not delivered is a billing error and a fraud exposure at once. So is a unit count the treatment note cannot support. Compliance training is what keeps the two apart.

The seven elements of an effective compliance program

The HHS Office of Inspector General names seven elements of an effective compliance program, running from written policies through to corrective action. OIG set them out in its General Compliance Program Guidance, published in November 2023.

  1. Written policies and procedures. A code of conduct, plus the procedures staff follow for intake, documentation, billing and disclosure.
  2. Compliance leadership and oversight. A named compliance officer, and an owner or board that reviews what the officer reports.
  3. Training and education. Role-specific, repeated, and recorded with dates and names.
  4. Effective lines of communication. A route to the compliance officer that staff will use, including one that lets them raise a concern anonymously.
  5. Enforcing standards through consequences and incentives. Published in advance, and applied the same way to a therapist and to an owner.
  6. Risk assessment, auditing and monitoring. An annual risk assessment first, then audits aimed at what it found.
  7. Responding to detected offenses and corrective action. Investigate, fix the process, repay any overpayment, and disclose where the law requires it.

A risk assessment sounds like a project, so element six tends to be the last one written. It is an afternoon’s work. List your ten riskiest tasks, rank them, and you have decided what your audits look at for the next year.

The compliance evidence trail

Every compliance duty has one record that proves you met it, and a cadence at which someone has to look at that record. Rule lists stop at the duty. The evidence trail carries on to the document an inspector will ask for, and to the date it was last reviewed.

Compliance dutyWho sets it (US)Who sets it (UK)The record that proves itHow often you check it
Patient consent to treatmentState practice actHCPC standards of conductSigned consent filed against the patient recordEach new episode of care
Clinical records and retentionState record-retention lawNHS Records Management Code of PracticeDated, signed treatment note and the retention scheduleAt discharge, then per schedule
Data protectionHIPAA, enforced by HHS OCRUK GDPR, enforced by the ICOSecurity risk analysis or record of processing activitiesAnnually
Staff registration and licensureState physical therapy boardHCPC registerCurrent license or registration number on the staff fileAt each renewal
Continuing educationState board CEU rulesHCPC CPD standardsCEU certificates or the CPD profile and its evidenceEach renewal cycle
Indemnity insuranceState law and payer contractsHCPC condition of registrationCertificate of cover naming the practice and the work doneAnnually
Exclusion and background screeningHHS OIG exclusion listDisclosure and Barring Service, via the employerDated screening result for every employee and contractorMonthly
Infection controlOSHA bloodborne pathogens standardHealth and Safety Executive, and CQC where registeredWritten exposure control plan carrying its review dateAt least annually
Billing accuracyCMS, with HHS OIG behind itPrivate medical insurer contractsThe claim, its modifiers and the note that supports themMonthly claim sample
Incident and breach reportingOSHA and HHS OCRICO, plus HCPC self-referralIncident log entry and the regulator’s report referencePer incident

Where a regulator sets the cadence, the table uses the regulator’s. Where none is set, the cadence is our recommendation, and you should record the one you choose. The deadlines below are the fixed ones.

Ladder of compliance review deadlines: severe-injury and data-breach reports within 8 to 72 hours, Medicare progress reports every 10 treatment days, OIG exclusion screening monthly, OSHA exposure control plan review and bloodborne pathogens training annually, HCPC registration renewal every 2 years
Five of the evidence trail’s cadences are set by a regulator rather than by the practice. Sources are OSHA, the ICO, CMS, HHS OIG and the HCPC.

In practices we onboard, the row that fails first is almost always exclusion screening. The duty is understood, and nobody owns the monthly check, so the last dated result is from whenever the therapist was hired.

Physical therapy compliance requirements in the US

Five authorities reach into a US physical therapy practice, and each one owns a different part of the trail. Your state board decides who may treat. CMS decides what it will pay for. HHS OCR, HHS OIG and OSHA police privacy, fraud and workplace safety.

HIPAA and patient data

HIPAA treats a physical therapy practice as a covered entity, so protected health information must be secured and shared only as far as needed. Protected health information, known as PHI, is any record that can identify the patient it describes.

Four records carry the weight here. A notice of privacy practices you can show a patient received. A written security risk analysis, dated within the last year. A training log with names and dates. A breach log with the date each notification went out.

Breach notification is the deadline people miss. Affected patients must be told without unreasonable delay and no later than 60 days after discovery. That clock starts when anyone at the practice knew, not when the owner was told.

Everyday controls do the rest. Unique logins per user rather than a shared front-desk account. Encryption on laptops and on every device that leaves the building. Access rights that drop the day a therapist leaves.

CMS therapy documentation requirements 2026

CMS pays for outpatient therapy only when a certified plan of care, correctly counted timed units and current progress reports stand behind the claim. Miss any one of them and the claim is payable on paper but indefensible on review.

Certification comes first. The Medicare Benefit Policy Manual treats an initial certification as timely when it is dated within 30 calendar days of the initial treatment. A certification interval runs no more than 90 calendar days from the initial treatment.

Progress reports come next. The minimum reporting period is at least once every 10 treatment days, or at least once every 30 calendar days, whichever is less. A clinician has to write it, and an assistant’s notes do not replace it.

CMS also names what a defensible progress report contains. Alongside the reporting dates and a signature, the clinician’s report must carry three further elements.

  • An assessment of improvement, and the extent of progress or lack of it toward each goal.
  • Plans for continuing treatment, with any further evaluation results or revisions to the plan.
  • Changes to long or short term goals, discharge, or an updated plan sent for the next certification.

Units are the second place claims come apart. For timed codes billed in 15-minute units, the Medicare Claims Processing Manual sets the intervals below. A single service under 8 minutes is not billable at all.

Units billedTotal timed minutes
1 unit8 through 22 minutes
2 units23 through 37 minutes
3 units38 through 52 minutes
4 units53 through 67 minutes
5 units68 through 82 minutes
6 units83 through 97 minutes
7 units98 through 112 minutes
8 units113 through 127 minutes

Source: CMS Medicare Claims Processing Manual, chapter 5, section 20.2. The pattern continues at the same spacing beyond two hours of treatment.

Modifiers are the third. GP marks services under an outpatient physical therapy plan of care, GO occupational therapy and GN speech-language pathology. Modifier 97 marks a service as rehabilitative rather than habilitative, and modifier 59 marks a distinct procedural service.

Two more modifiers turn on money. CQ flags a service furnished in whole or in part by a physical therapist assistant, which Medicare pays at 85% of the fee schedule rate. KX confirms medical necessity above the annual threshold.

For CY 2026, CMS set the KX modifier threshold at $2,480 for physical therapy and speech-language pathology combined, and $2,480 for occupational therapy. The targeted medical review threshold stays at $3,000. Our guide to physical therapy billing works through the codes behind those claims.

State practice acts and scope of practice

Your state practice act decides who may evaluate, who may treat without a referral, and how long that may go on. It changes more often than the federal rules do, which is why a policy written three years ago is usually out of date somewhere.

Take the PT practice act Texas works under. House Bill 4099, passed in 2025, extended how long a physical therapist may treat a patient without a referral. The old limit was 10 consecutive business days. From November 1, 2025 it is 30 consecutive calendar days.

That extension is not open to everyone. It applies to a physical therapist holding a doctoral degree in physical therapy. It also applies to one who has completed at least 30 continuing competence units in differential diagnosis. Arizona, meanwhile, sets its own route, which we cover in physical therapy clinic requirements in Arizona.

PT vs PTA scope of practice is the other line that moves by state. A physical therapist assistant works under a physical therapist’s plan of care and cannot perform the initial evaluation or set that plan. Supervision requirements and permitted tasks then vary.

Two records prove this part of the trail. A current license number on every staff file, checked at renewal. A written scope statement per role, showing which tasks that role may perform in your state.

OIG exclusion screening and fraud prevention

Anyone excluded by the HHS Office of Inspector General cannot be paid by a federal health care program, directly or indirectly. The OIG publishes them in the List of Excluded Individuals and Entities, known as the LEIE. Employing one exposes the practice to overpayment and civil money penalty liability.

The cadence is set for you. OIG updates the LEIE monthly, and its guidance states that screening each month best limits that liability. Screening covers contractors and vendors as well as employees, plus the exclusion list of any state Medicaid program you participate in.

Risk assessment is the other half of this element. A practice that bills Medicare carries a different risk profile from a cash-based one, and the audits should follow the profile. Upcoding, billing untimed minutes as timed units and claims for supervised time all sit high on that list for therapy.

OSHA obligations

OSHA’s injury and illness recordkeeping rule partially exempts offices of other health practitioners, NAICS 6213, which is where most outpatient physical therapy practices sit. So a routine OSHA 300 log is generally not required of you.

Severe events are still reportable by every employer. A work-related fatality goes to OSHA within 8 hours. An in-patient hospitalization, an amputation or the loss of an eye goes within 24 hours.

The bloodborne pathogens standard is where a therapy practice carries the most work, because dry needling, wound care and sharps handling all bring exposure. Three requirements carry dates you can be asked for.

  • A written exposure control plan, reviewed and updated at least annually and whenever tasks change.
  • Hepatitis B vaccination made available within 10 working days of an employee’s initial assignment to work with exposure.
  • Training at the time of assignment and at least annually after that, with records kept.

Employee medical records under that standard are kept for the duration of employment plus 30 years. Hazard communication covers the rest of the building. Every disinfectant, cleaning chemical and topical agent needs a current safety data sheet and a labelled container.

Physiotherapy compliance requirements in the UK

A UK physiotherapy practice answers to a smaller set of bodies than a US one, but the duties bite harder at the individual. Registration, indemnity and continuing development attach to the clinician, and the practice has to be able to evidence all three.

HCPC registration and CSP standards

Anyone practising as a physiotherapist in the UK must be on the HCPC register, because physiotherapist and physical therapist are protected titles. Using either title without registration is a criminal offence, and the HCPC prosecutes it.

Registration runs in two-year cycles. Physiotherapy registrants are invited to renew between 1 February and 30 April in their renewal year. At renewal they confirm that they meet the standards and hold indemnity cover.

The Chartered Society of Physiotherapy (CSP) is the profession’s body and trade union, founded in 1894. CSP membership is not a legal requirement the way HCPC registration is. It brings the professional liability insurance scheme, clinical guidance and the CPD resources most independent practitioners rely on.

Clinical guidelines come from the National Institute for Health and Care Excellence (NICE). NICE guidance is not law, but a departure from it needs a documented clinical reason in the patient’s notes.

Physiotherapy clinic GDPR compliance

UK GDPR makes a physiotherapy practice a data controller, so each patient record needs a lawful basis, a retention period and an access route. Physiotherapy clinic GDPR compliance is a records job before it is a consent job.

Start with the lawful basis, because it is easy to pick the wrong one. Clinical records are special category data, and consent is rarely the basis you rely on. Most practices process them under Article 9(2)(h), which covers the provision of health care and treatment.

That matters practically. If consent were the basis, a patient withdrawing it would oblige you to stop processing. That includes records you have a legal duty to keep. Consent to treatment and a lawful basis for data are separate documents doing separate jobs.

A privacy notice then carries the transparency duty. It names every purpose you use patient data for, written plainly enough to be understood at reception.

  • Treatment planning, clinical notes and the patient’s own record.
  • Appointment scheduling, reminders and the messages you send around them.
  • Invoicing, insurer claims and payment processing.
  • Audit, service improvement and any research, named separately.

A data protection officer is a narrower requirement than it first appears. A DPO is mandatory where core activities involve large-scale processing of special category data. Recital 91 of the UK GDPR says processing by an individual health care professional is not large scale, so many private practices fall outside it.

Falling outside it does not remove the duty. Someone still has to own data protection by name, keep the record of processing activities and answer the ICO if it calls. Write that name into the role description rather than leaving it with whoever is free.

Data subject rights need a procedure, not goodwill. A subject access request must be answered within one month, and that month includes the time you spend finding the notes. Patients can also ask you to correct records that are inaccurate or incomplete.

The right to erasure is the one to be careful with. It does not override a retention duty, so a physiotherapy record you are obliged to keep stays. The NHS Records Management Code of Practice sets 8 years after the last entry for adult health records, and private practices generally follow it.

Breaches have their own clock. A personal data breach that risks people’s rights is reported to the ICO within 72 hours of the practice becoming aware of it. Keep an internal log of every breach, including those you decide not to report, with the reason.

CPD, indemnity insurance and clinical guidelines

Continuing professional development is audited, not just declared. At the start of each renewal the HCPC randomly selects 2.5% of each profession. Those registrants must then submit a CPD profile with evidence behind it.

Keep the profile as you go rather than assembling it when the letter arrives. A dated entry per activity, what changed in your practice because of it, and the artifact that shows it happened.

Indemnity is a condition of registration. Every HCPC registrant must hold an indemnity arrangement appropriate to the work they do. That can come through an employer, a professional body scheme or an insurer. Appropriate means sized to the risk you actually carry.

Check the certificate against what the practice does now, not what it did when the policy started. Adding acupuncture, shockwave or home visits can take a service outside the cover you renewed without reading.

Consent to treatment is the last of the individual duties. The patient needs to understand the proposed treatment, the material risks and the alternatives before it starts. The notes then have to show that conversation took place.

How to write compliance plans your staff will actually follow

Compliance plans get followed when every duty names an owner, a record and a review date, on a page staff can find in ten seconds. Plans fail when they describe the law instead of the routine.

A healthcare compliance plan template gives you the structure, not the content. Take the headings from a compliance plan sample if you want a starting shape. Then replace every line with your own state’s rules, your own payers and your own staff names.

Watch the scale of what you copy. A compliance plan template for healthcare written for a hospital system carries departments, committees and reporting lines that a four-therapist practice does not have. Carrying them over produces a document nobody reads.

Scale the program to the practice instead. OIG expects the seven elements everywhere, but says smaller entities can implement them with limited resources.

  • Solo practice. One page. You are the compliance officer. Four recurring reviews in your calendar, and one folder holding the dated records.
  • Two to ten staff. A named compliance officer who is not the owner, a written reporting route, and an annual risk assessment the owner signs.
  • Multi-site group. A corporate compliance plan with a site owner per location, a shared audit schedule, and one register of corrective actions across all sites.

Having a medical practice compliance plan in place counts only if the reviews inside it happen. Put each review in the calendar as a recurring appointment with a named owner. Record the date it was done next to the record it covered.

Physiotherapy clinic standard operating procedures

Standard operating procedures should cover the tasks where a mistake leaves a record wrong, missing or unavailable. The rest is training. These are the physiotherapy clinic standard operating procedures worth writing down, and what each one has to say.

  • Patient intake and consent. Which forms are taken before first treatment, who checks they are signed, and where they are filed.
  • Clinical documentation. The deadline for writing the note, who may write which parts, and who signs it off.
  • Records access and disclosure. Who may release a record, what proof of identity is needed, and the response deadline.
  • Breach and incident response. Who is told first, the reporting clock that applies, and where the log lives.
  • Billing and claim review. How units are counted, which modifiers apply, and the sample size someone checks each month.
  • Staff onboarding and screening. License verification, exclusion or DBS screening, and the training a new starter completes before treating.
  • Equipment cleaning and infection control. What is cleaned between patients, with which product, and who records it.
  • Complaints handling. Acknowledgement timescale, who investigates, and how the outcome reaches the patient.
  • Retention and destruction. How long each record class is kept, and how it is destroyed when the period ends.

Keep each one to a single page with a version number and a review date. An SOP without a review date is a historical document, and an inspector will read it as one.

How to run a physiotherapy clinical audit in private practice

Pick five duties from the evidence trail, then try to produce the named record for each within ten minutes. A physiotherapy clinical audit in private practice needs no more apparatus than that to find where the trail breaks.

Run it as five steps, and write the result down as you go.

  1. Choose five rows. Take a mix, so one clinical, one data, one staffing, one billing and one safety.
  2. Pick a case that happened. A patient treated last month, a therapist hired last year, a claim submitted last week. Not a hypothetical one.
  3. Time yourself. Produce the record. Ten minutes is generous, and an inspector will not wait longer.
  4. Score each row. Produced, produced late, or cannot produce. A record you found but could not date scores as cannot produce.
  5. Write the corrective action. One fix per failed row, with an owner and a date, then retest the same five rows in 30 days.

A worked example makes the scoring clearer. Say the five rows are consent, the treatment note, exclusion screening, the last claim and the exposure control plan.

Consent and the note usually come back inside two minutes, because both live in the patient record. The claim takes longer, since somebody has to open the note beside it and check the units. Screening and the exposure control plan are the two that come back undated.

An undated record is a failed row, and the corrective action is the same in both cases. Give the check an owner and put it in the calendar at the cadence the regulator sets. Then file the dated result somewhere the next audit can reach it.

Corrective action is element seven of the OIG’s list, and it is the step the audit exists for. Keep a register of every action, its owner, its due date and the retest result. That register is itself a record an inspector can ask for.

Common compliance issues in therapy practices

The compliance issues in therapy practices that cost the most are missing documentation, unscreened staff, late breach reports and claims the treatment note cannot support. None of them starts as misconduct.

Each one carries a published consequence. The figures below come from the regulators themselves rather than from industry estimates.

What goes wrongWhat it breachesThe published consequence
PHI disclosed or left unsecuredHIPAACivil money penalties from $145 to $73,011 per violation, with a calendar-year cap of $2,190,294 (Federal Register, January 28, 2026)
Patient data mishandled in the UKUK GDPRUp to £17.5 million or 4% of total annual worldwide turnover, whichever is higher (ICO)
An excluded individual employed or contractedFederal health care program exclusionOverpayment liability for the items and services, plus civil money penalty exposure (HHS OIG)
KX modifier missing above the thresholdCMS therapy billing rulesThe claim is denied once the beneficiary passes $2,480 in allowed charges for the year
Practising under a protected title unregisteredUK protected title lawCriminal prosecution brought by the HCPC
No annual bloodborne pathogens trainingOSHA 29 CFR 1910.1030Citation and penalty on inspection

Two consequences sit outside any table. A state board can suspend or revoke a license, which closes the practice for as long as it lasts. And a patient who believes they were harmed can sue whatever the regulator decides.

Reputation is the slow one. Enforcement action against a health professional is published, indexed and easy to find. A single breach then follows the practice through every search a prospective patient runs.

How Pabau keeps your compliance records in one place

The evidence trail breaks because its records live in different places. Consent forms sit in a filing cabinet, treatment notes in the EMR, staff licenses in a drive folder and screening results in somebody’s inbox. Producing five of them in ten minutes is then a scavenger hunt.

Practice management software like Pabau puts them on one patient timeline instead. Pabau stores the signed consent, the treatment note, uploaded documents and the invoice against the same record. The whole trail for one patient then opens in a single screen.

Pabau EMR sidebar showing forms, photos, documents, prescriptions and lab tests, with a treatment note share panel listing who has access
Pabau’s EMR keeps forms, documents and treatment notes on one patient record, and logs who each note was shared with. That log is the record behind a data access request.

Pabau’s digital forms take consent before the appointment rather than in the waiting room, and file the signed copy automatically. Staff records, license numbers and training sit alongside, so the staffing rows of the trail are dated rather than assumed.

Audit trails are the part practices notice during their first audit. Pabau logs who opened a record and when, which is what turns a claim that access was controlled into a record that proves it.

Keep every compliance record on one patient timeline

Pabau stores consent forms, treatment notes, documents and audit trails against the same patient record. A practice can then produce the document behind any compliance duty in minutes. Staff licenses and training records sit alongside them.

Pabau practice management dashboard

Conclusion

Compliance is judged on what you can produce, not on what you know. Two practices can follow identical rules, and only the one that can date its records will survive an inspection.

So start at the evidence trail rather than at the regulations. Pick the five rows you would least like to be asked for. Give each an owner and a review date, then retest them in a month. The rows you cannot fill are the scope of your compliance program.

The trade-off worth remembering is time. Every cadence in this guide costs a few hours a year, and the penalties attached to missing them run into six figures. Book a demo to see how Pabau keeps consent, notes, staff records and audit trails in one place for a physical therapy practice.

Continue your research

Continue your research

Wondering where compliance records should live? Best physical therapy EMR software in 2026 compares seven platforms on documentation and records handling.

Setting up a practice from scratch? Physical therapy business plan: what to include and why covers the operational decisions compliance later depends on.

Billing patients directly instead of insurers? Cash-based physical therapy explains how the model changes your documentation and payer obligations.

Opening a practice in the UK? How to open a physiotherapy clinic walks through registration, insurance and setup step by step.

Losing patients partway through a course of treatment? Patient retention in physical therapy sets out what keeps people coming back to their plan of care.

Frequently asked questions

What does PT compliance mean?

PT compliance is a physical therapy practice meeting the rules that govern treatment, records, privacy, staffing and billing. It also means keeping the documents that show each rule was met. In clinical conversation the same phrase sometimes describes a patient sticking to a home exercise program.

What are the 7 elements of compliance?

The HHS Office of Inspector General lists seven. Written policies and procedures, compliance leadership and oversight, training and education, and effective lines of communication make up the first four. The rest are enforcing standards, risk assessment with auditing and monitoring, and responding to detected offenses with corrective action. The section above shows what each looks like in a therapy practice.

What are the 5 key areas of compliance?

Therapy practices can group their duties into five areas. Those are clinical care and consent, patient records and data protection, staffing and licensure, billing accuracy, and workplace safety. Each area maps onto rows of the compliance evidence trail table above. That table names the record proving each duty and how often it is reviewed.

What is statutory vs mandatory training?

Statutory training is training the law requires, such as OSHA bloodborne pathogens training in the US. Mandatory training is what an employer, regulator or insurer requires on top of that. For a therapy practice, mandatory compliance training usually covers HIPAA or UK GDPR, consent and documentation standards.

Which regulatory bodies enforce compliance standards for physiotherapists?

In the UK, the Health and Care Professions Council regulates physiotherapists and the Information Commissioner’s Office enforces data protection. In the US, a state physical therapy board licenses practitioners. CMS, the HHS Office for Civil Rights, the HHS Office of Inspector General and OSHA then enforce billing, privacy, fraud and safety rules.

Found our content helpful?
×