top of page

What You Need to Know About AI Compliance in PT, OT, and SLP Private Practice

  • Writer: Rockstar Staff
    Rockstar Staff
  • Apr 16
  • 6 min read

Updated: Jul 24

Clinic owner reviewing an AI compliance checklist covering HIPAA and Medicare documentation requirements

This isn't about being overly cautious or anti-technology. It's about protecting your patients, your practice, and your license. Here's what every PT, OT, and SLP private practice owner needs to understand before adopting AI tools.


Is HIPAA Actually the Starting Line, Not the Finish Line?

Yes. The first question to ask about any AI tool is simple: does it handle patient data, and if so, is it HIPAA-compliant? Any vendor processing PHI on your behalf must sign a Business Associate Agreement with your practice. Not optional. A BAA outlines how the vendor is permitted to use patient data, what safeguards are in place, and what happens in the event of a breach.


Here's where many practice owners get caught off guard: popular general-purpose AI tools, including ChatGPT in its standard consumer form, don't offer BAAs. OpenAI doesn't enter into Business Associate Agreements with covered entities for the standard consumer product, which means using ChatGPT to process, summarize, or document anything involving identifiable patient information is a HIPAA violation, regardless of how useful the tool is.


The practical rule: use general AI tools like ChatGPT and Claude for operational and marketing tasks, drafting emails, writing blog posts, building SOPs, but never for anything involving patient data. If you want AI in your clinical documentation workflow, use a platform purpose-built for healthcare, explicitly HIPAA-compliant, and willing to execute a BAA. Tools like SPRY Scribe, ScribePT, WebPT, and TheraPlatform are designed with this in mind.


Beyond the BAA itself, HIPAA's minimum necessary standard requires AI tools to only access the patient information strictly needed for their function. This matters because AI models are often designed to learn from as much data as possible, which can conflict directly with HIPAA's data minimization requirements. Ask vendors directly how they handle this.


Do Medicare and CMS Documentation Requirements Still Apply to AI-Generated Notes?

Yes, fully. AI-generated notes don't get a pass on documentation standards. If your practice bills Medicare or works with insurance, every note, regardless of how it was drafted, must meet clinical documentation requirements, demonstrate medical necessity, and use the correct CPT and ICD-10 codes.


This means you're still responsible for reviewing every AI-generated note before it goes into the record or gets submitted for billing. An AI scribe producing a plausible-sounding but clinically inaccurate note is a liability, not a time saver. Always build review into your workflow.


Rockstar Insight: For PT and SLP practices billing Medicare, the KX modifier threshold for combined PT and SLP services for 2026 is $2,480, up from $2,410 in 2025. Your documentation needs to reflect the medical necessity that justifies services beyond that threshold. AI tools can help you draft those notes faster, but the clinical reasoning still needs to come from you.


What Does ASHA Say About AI Use in SLP Practice Specifically?

ASHA has been clear: AI tools must support clinical judgment, not replace it. ASHA's Code of Ethics places a direct responsibility on certified professionals to evaluate any technology they use in their work, and that includes AI. Just because a tool performs well in a controlled setting or a vendor demo doesn't mean it will perform the same way in your clinic, with your patient population, or across the full range of communication disorders you treat.


ASHA also flags a specific concern about validation: even if an AI system meets or exceeds expert-level performance in a lab environment, that doesn't mean it can be readily adopted into clinical practice, that it will perform similarly when deployed in real-world settings, or that the evaluation metrics used actually reflect meaningful clinical outcomes.


There's also currently limited legislative or regulatory oversight of AI tools in healthcare specifically, which means the burden of due diligence falls largely on you as the clinician. If something goes wrong with an AI-generated note or recommendation, your license is on the line, not the software vendor's.


Do State Licensure and Scope of Practice Rules Affect AI Use Too?

Yes. Compliance doesn't stop at the federal level. Your state licensure board has its own requirements around scope of practice, telehealth delivery, and supervision, and these vary significantly from state to state.


If you're using AI tools to support remote or telehealth services, you need to know your state's specific rules about how those services can be delivered and documented. Clinical fellows also have special billing and documentation requirements that AI tools need to be configured to accommodate. Before committing to any AI platform, ask the vendor directly whether their tool is designed to support multi-state compliance and whether they can provide guidance on your specific state's requirements.


What AI-Specific Risks Are Easy to Overlook?

  • De-identification is not a workaround. Some practice owners assume removing a patient's name from data before feeding it into an AI tool makes it safe. HIPAA's de-identification standard is more rigorous than that. There are 18 specific identifiers that must be removed, and even de-identified datasets can carry re-identification risk when combined with other data sources.

  • AI can introduce bias. Federal healthcare rules have required covered entities to identify patient care decision support tools that use variables related to protected characteristics, race, ethnicity, language, disability status, and take reasonable steps to mitigate discrimination risk. If the AI tool you're using was trained on data that doesn't reflect your patient population, its outputs may be less accurate or appropriate for certain groups.

  • Audit trails matter. HIPAA requires comprehensive logging of who accessed PHI and when. Your AI vendor should maintain automatic audit logs, and you should confirm this specifically before signing any agreement.


What's a Practical Compliance Checklist Before Adopting Any AI Tool?

Does this tool involve patient data in any way? If yes, does the vendor offer a BAA? Is the platform explicitly HIPAA-compliant, with documented security standards including encryption at rest and in transit? Has the tool been validated for use in clinical settings with a population similar to yours? Does it align with your state's scope of practice and telehealth regulations? And do you have a review process in place so that no AI-generated content goes into a patient record without clinician oversight?


Building an AI Adoption Process That Actually Protects Your License

AI tools can genuinely make your practice more efficient, but they don't operate outside the rules that govern healthcare. HIPAA, CMS documentation standards, ASHA ethics guidance, and state licensure requirements all still apply, and in some cases, AI introduces new compliance considerations that didn't exist before.


The good news is that compliance and efficiency aren't opposites. Purpose-built healthcare AI tools are designed to work within these frameworks. The key is knowing what questions to ask before you adopt anything, and making sure your whole team understands the rules too.


FAQ

Is it a HIPAA violation to use ChatGPT for patient documentation?

Yes, in its standard consumer form. OpenAI doesn't sign Business Associate Agreements for that version, so processing or summarizing anything involving identifiable patient information through it constitutes a HIPAA violation regardless of how useful the output is.

$2,480, up from $2,410 in 2025. Once a patient's therapy charges cross that threshold, claims require the KX modifier along with documentation clearly supporting continued medical necessity, objective measures and updated goals, not just a checkbox.

No. HIPAA's de-identification standard requires removing 18 specific identifiers, and even properly de-identified data can carry re-identification risk when combined with other data sources. Simply omitting a name doesn't meet the standard.

No. Every note, regardless of how it was drafted, must meet clinical documentation requirements, demonstrate medical necessity, and use correct CPT and ICD-10 codes. The clinician remains fully responsible for reviewing every AI-generated note before it's submitted or filed.

Whether they'll sign a Business Associate Agreement, whether their platform is explicitly HIPAA-compliant with documented encryption standards, whether the tool has been validated for clinical settings with a population similar to yours, and whether they support your specific state's scope of practice and telehealth regulations.



If navigating all of this feels like one more thing on an already full plate, that's a sign your practice may benefit from more operational support. Rockstar Global works with PT, OT, and SLP private practice owners to build the systems and team structures that let you grow without getting buried.


Book a free discovery call, and let's talk about what that could look like for you.

 
 
Untitled design.png

Written by the Rockstar Global Team

The Rockstar Global team has placed hundreds of HIPAA-trained healthcare virtual assistants with private practices across the US. In 2025, Rockstar Global was honored with a Silver Stevie® Award in the American Business Awards®. Our leadership brings 15+ years in the private practice industry, and we built Rockstar around one idea: practice owners shouldn't have to choose between clinical excellence and a functioning business. We handle payroll, benefits, and replacements, so owners get the support without the management overhead.

Related Articles

Book your discovery call

Tell us about your practice and we'll show you how Rockstar can take the operational weight off your plate.

bottom of page