Business & Compliance

7 Common Compliance Mistakes in Physiotherapy Practices

Author:

Every year, hundreds of physiotherapy practices get penalised for compliance mistakes. Sometimes it's a fine (500-5,000 PLN), sometimes it's removal from the…

Every year, hundreds of physiotherapy practices get penalised for compliance mistakes. Sometimes it's a fine (500-5,000 PLN), sometimes it's removal from the register (the end of the business), sometimes both at once.

The good news: all of these mistakes are easy to avoid. Below you'll find the 7 most common traps and how to steer clear of them.


Mistake #1: No RPWDL entry, or outdated details

What happens?

You're working as a physiotherapist but haven't registered in RPWDL (the Register of Entities Performing Medical Activity), or you registered but never update your address or contact details.

An inspector from Sanepid, NIK (the Supreme Audit Office) or the regional health inspector walks into your practice and checks RPWDL. You're not there. Or you are, but with a stale address.

What does the law say?

The Act on the Physiotherapist Profession (Journal of Laws 2015, item 697) requires RPWDL registration as a condition for legally practising the profession. Without it, you're working illegally.

The Act on Medical Activity (Journal of Laws 2011, item 112) states plainly: medical activity without registration is a violation.

What does an inspection check?

  1. Are you in RPWDL?
  2. Are your details current (address, phone, registered premises)?
  3. Do you have valid OC (professional liability) insurance (visible in RPWDL)?
  4. Is your Right to Practise active with KIF (checked online)?

What's the penalty?

  • Administrative fine: 3,000-5,000 PLN
  • Suspension of operations: 30 days without the right to work
  • Removal from RPWDL: if this is a repeat offence
  • Ban on re-registration: up to 3 years

[Solo] Example -- solo practice:
Magda opened her practice in 2024 and registered with RPWDL. She worked for a year without issues. In March 2026 she moved to new premises on the other side of town. She forgot to update her address in RPWDL.

In April, a Sanepid inspection arrives. They check RPWDL. They find Magda, but with her old practice address. A report noting the discrepancy is filed. Magda has 7 days to update her details. She updates them online, problem solved. But if the inspection had been stricter, a fine could have followed.

How to avoid it?

  1. Register in RPWDL before opening your practice -- fee approx. 175 PLN in 2026 (2% of the average salary), portal rpwdl2.ezdrowie.gov.pl
  2. Update your details whenever they change -- moving premises, changing phone number, changing insurer. Do it within 7 days.
  3. Check your RPWDL details at least once a year -- make sure they're accurate
  4. Keep proof of registration on hand -- your RPWDL confirmation, your OC insurance certificate

Mistake #2: Incomplete medical records

What happens?

A patient comes to you, you treat them. But your documentation is:

  • "Magda, L back, 5 sessions" scrawled on a note
  • No date of visit
  • No examination results (do they have ROM, pain on movement?)
  • No patient signature
  • No diagnosis (what exactly is wrong with them?)

An inspection arrives, or the patient complains (files a lawsuit). It turns out nobody can say who did what, or when.

What does the law say?

The Patient Rights Act (Article 19, Journal of Laws 2008, item 104) requires that every patient have complete medical records containing:

  • The patient's personal details
  • Date of visit
  • Diagnosis
  • Physical examination findings
  • Description of the procedure/treatment
  • Date and staff signature

Records must be retained for a minimum of 5 years (7 years for adult patients, 10 years for children).

What does an inspection check?

  1. Does every patient have a record?
  2. Does the record contain the mandatory elements (date, diagnosis, signature)?
  3. Are records stored securely (a locked cabinet or medical software)?
  4. Is the documentation legible (can the inspector read what's written)?
  5. Does the documentation go back at least 5 years?

What's the penalty?

  • Administrative fine: 1,000-3,000 PLN (the most common outcome)
  • Patient lawsuit: if the patient was injured or something went wrong and you can't prove what you did
  • Suspension of operations: 14 days (if documentation is missing across the board)

[Group] Example -- group practice:
Artur's "PhysioKlinika" has been running for 2 years. One of the physiotherapists, Monika, keeps paper patient records in a cabinet. Not all of them have dates. Several have short notes like "exercises," with no detail on which exercises.

An inspection arrives. The inspector randomly picks 10 records and reads them. Out of 10: 8 are missing dates, 6 are missing examination results, 4 are missing patient signatures. A report noting deficiencies is filed. A 2,000 PLN fine for Artur.

Artur invests in medical software. Now every record has mandatory fields (date, diagnosis, patient signature). The system won't let you save a patient file without all fields filled in. Problem solved.

How to avoid it?

  1. Use a patient record template -- one that covers all mandatory elements. FizjoReady's STARTER package includes one.
  2. Record the mandatory information:
  • Date of visit
  • Patient's full name
  • PESEL (if reimbursed by NFZ, Poland's National Health Fund)
  • Diagnosis (e.g. "L4-L5 disc herniation")
  • Physical examination findings (ROM, strength, pain)
  • Description of the procedure (exactly what you did)
  • Date and signature of both patient and you
  1. Store records securely -- a locked cabinet or password-protected medical software
  2. Keep an archive -- retain patient records for a minimum of 5 years

Mistake #3: No GDPR privacy notice

What happens?

A patient comes to you. You write down their name, PESEL, phone number, medical history. But you never show them the purpose of the data collection, the legal basis, or how long you'll keep it.

Months later, the patient learns their data went to an insurer, or that their medical history is sitting unprotected on a shelf in the practice.

They report it to UODO (the Personal Data Protection Office). An inspection follows.

What does the law say?

The GDPR (EU Regulation 2016/679, Articles 13-14) requires that before collecting personal data, the patient receives a privacy notice covering:

  • Who the data controller is (you)
  • What the purpose of the collection is
  • On what legal basis (e.g. a medical care contract, the patient's right to care)
  • How long you retain the data (e.g. 5 years)
  • What the patient's rights are (access, correction, erasure, objection)
  • Whether the data goes to any third party (e.g. an insurer)

The notice must be understandable, clear, and available to the patient (paper or digital).

What does an inspection check?

  1. Do you have signed notices from all patients?
  2. Does the notice contain all mandatory information?
  3. Is the notice legible and understandable?
  4. Do you retain the document (paper or PDF)?

What's the penalty?

  • Administrative fine: up to 10,000 PLN (first warning)
  • Severe fine: up to EUR 20,000,000 or 4% of global turnover (in the case of repetition or negligence)
  • Class action from patients: if data was disclosed

Note: GDPR penalties are the harshest of all. These aren't 500 PLN fines. These are thousands, or millions.

[Solo] Example -- solo practice:
Magdalena works for a year without a privacy notice. Nobody complains, so she doesn't realise it's mandatory. A UODO inspection arrives. They check patient records -- no notices anywhere. Even one missing notice changes everything. Zero notices = a conscious violation. A 5,000 PLN fine (relatively small, since Magdalena is a solo practitioner and the inspection had no other material to assess against).

How to avoid it?

  1. Prepare a privacy notice -- a template is included in the STARTER package. It covers everything GDPR requires.
  2. Print it and show it to the patient -- before the first visit
  3. Have the patient sign it -- keep the document in the patient's file
  4. Update the notice whenever the rules change -- e.g. when you change insurer

Mistake #4: No, or expired, OC insurance

What happens?

A patient comes to you. You perform a massage. The patient feels pain. A few days later it turns out they have a broken rib (accidents happen). The patient sues and demands 50,000 PLN in compensation.

You don't have OC insurance (it expired, or you never bought it). You have to pay out of pocket. 50,000 PLN.

What does the law say?

The Act on the Physiotherapist Profession (Article 12) requires holding professional liability (OC) insurance with minimum limits:

  • EUR 30,000 per incident
  • EUR 150,000 for all incidents in a year

The insurance must remain valid for the entire time you practise. If it lapses, you lose the right to work.

What does an inspection check?

  1. Do you have valid OC insurance?
  2. Are the limits at least EUR 30k/150k?
  3. Does the policy cover physiotherapy (some general policies don't)?
  4. Are payments current (an overdue payment = lost coverage)?

What's the penalty?

  • Removal from RPWDL -- immediate, if your insurance lapses
  • Administrative fine: 2,000-5,000 PLN (for missing insurance)
  • Patient lawsuit: if a patient is injured and seeks compensation, you pay out of pocket
  • Suspension of operations: if you worked without insurance for an extended period

[Group] Example -- group practice:
"PhysioKlinika" has OC insurance costing 2,500 PLN/year. The owner (Artur) forgets the policy expires in August. He works through September, October, November without insurance. A patient falls off the treatment table. A broken arm, a lawsuit demanding 20,000 PLN compensation.

The insurer: "The policy expired in August. We're not paying." Artur has to pay out of pocket. Lesson: mark the insurance expiry date in your calendar. Renew 2 weeks before it lapses.

How to avoid it?

  1. Buy OC insurance for physiotherapists -- before opening your practice. Cost: 1,000-1,500 PLN/year
  2. Check the limits -- minimum EUR 30k/150k
  3. Mark the expiry date in your calendar -- renew 2 weeks in advance
  4. Keep your insurance certificate on hand -- always ready to show an inspector

Mistake #5: No hygiene plan and empty disinfection logs

What happens?

Sanepid arrives at your practice. They ask: "Where's your hygiene plan?" You: "It's all in my head." Sanepid: "OK, but it needs to be on paper."

They ask further: "Where's your disinfection log?" You show them an empty notebook. Sanepid: "That means you're not disinfecting." A report noting deficiencies follows.

What does the law say?

The Act of 5 December 2008 on Preventing and Combating Infections and Infectious Diseases in Humans requires entities performing medical activity to implement infection-prevention procedures, including:

  1. A hygiene plan (a written document, cleaning and disinfection procedures)
  2. A disinfection log (what, when, how, who, signature)
  3. Epidemic contingency procedures (e.g. for COVID)

Sanepid checks these documents at every inspection. They're the most commonly checked items.

What does an inspection check?

  1. Does a hygiene plan exist on paper (or digitally)?
  2. Does the plan cover procedures for every area (treatment rooms, toilet, wash-up areas)?
  3. Is a disinfection log kept?
  4. Does the log record: date, what, how, who, signature?
  5. Are the procedures actually being followed (does the inspector do a walkthrough)?

What's the penalty?

  • Administrative fine: 500-2,000 PLN (the most common penalty for a missing log)
  • Suspension of operations: 14-30 days (if hygiene conditions are deemed hazardous)
  • Repeat violations: possible removal from RPWDL

[Solo] Example -- solo practice:
Magda takes cleanliness seriously. Every day at 7am she wipes down the treatment table, changes the paper after every patient. But she never writes any of it down. Sanepid arrives. They ask for the disinfection log. Magda shows an empty notebook. "I do it, I just don't write it down." Sanepid: "If it's not recorded, it doesn't count. Even if you really are doing it, it looks like you aren't." A 500 PLN fine.

How to avoid it?

  1. Prepare a hygiene plan -- a document covering procedures for every area. A template is in the STARTER package.
  2. Print the plan and put it on the wall -- somewhere everyone in the practice sees it
  3. Keep a disinfection log -- a notebook or software. Every day: date, what, substance used (e.g. Dezolex 5%), who, signature
  4. Actually disinfect -- you need to have done something before you write it down
  5. Keep historical logs -- Sanepid can check logs from several months back

Mistake #6: No personal data breach procedure

What happens?

A patient leaves their medical file on a table. Someone (a patient, an employee, the cleaner) accidentally sees sensitive data (medical history, PESEL). This is a personal data breach.

The patient finds out. They report it to UODO. UODO checks whether you have a breach procedure. You: "What's a breach procedure?" You're missing the document.

What does the law say?

The GDPR (Articles 33-34) requires that the data controller (you) have a procedure for responding to a data security breach. The procedure must cover:

  1. How to report a breach (to whom, on what form)
  2. How to assess the severity of the breach (is it serious or negligible?)
  3. How to notify UODO (within 72 hours)
  4. How to notify patients (if the breach carries a high risk)

The procedure must be on paper (or digital), known to staff, and actually implemented.

What does an inspection check?

  1. Do you have a written procedure?
  2. Does the procedure contain the mandatory elements?
  3. Do staff know the procedure?
  4. If a breach occurred, did you report it correctly?

What's the penalty?

  • Administrative fine: 500-5,000 PLN (for lacking a procedure)
  • Fine for missing the 72-hour deadline: up to EUR 1,000,000
  • Patient lawsuits: if you fail to notify them of a breach

[Solo] Example -- solo practice:
Magda uses cloud-based medical software. One of her employees (the cleaner) sees a patient's file on the monitor. Takes a photo on their phone. Feeling disgruntled, they send the photo to a friend.

The patient finds out. They report it to UODO. UODO asks Magda: "Did you have a breach procedure?" Magda has no such document. UODO: "You could have notified us within 72 hours and reduced the consequences. Now it's worse." A 2,000 PLN fine + an obligation to notify patients + a change of procedures.

How to avoid it?

  1. Prepare a breach procedure -- covering the steps: reporting, assessment, notifying UODO, notifying patients. A template is in the FULL package.
  2. Print it and keep it on hand -- visible in the practice or in a cabinet
  3. Train your staff -- everyone must know what to do if something goes wrong
  4. Test the procedure -- once a year, have an employee walk through the procedure on paper (without an actual breach)

Mistake #7: No organisational regulations

What happens?

The group practice "PhysioKlinika" has been running for 2 years without organisational regulations. Three physiotherapists work there. There are no clear rules: what does Artur (the owner) do, what does the physiotherapist do, where does staff sign their employment agreement.

A Sanepid inspection arrives. They ask for the regulations. "There aren't any, but we work well together." Sanepid: "Without regulations, it's unclear who's responsible for what. That's insufficient."

What does the law say?

The Act on Medical Activity (Journal of Laws 2011, item 112, Article 47) requires every medical facility (group practice, clinic, hospital) to have:

  1. Organisational regulations (covering structure, responsibility, procedures)
  2. Health and safety procedures
  3. Incident reporting procedures
  4. A crisis management plan

The regulations must be on paper, signed by the medical manager, and available to staff.

A solo practice doesn't need regulations -- but if you register with RPWDL as a "solo practice," that's fine. If you register as a "group practice" (even with a single contracted employee), regulations are required.

What does an inspection check?

  1. Do you have organisational regulations?
  2. Do they cover the structure and responsibility of each employee?
  3. Do they cover safety procedures?
  4. Do staff know the regulations (can they produce them)?

What's the penalty?

  • Administrative fine: 1,000-3,000 PLN
  • Suspension of operations: 30 days, if this is part of a broader set of violations
  • Inability to hire new staff -- if you have no regulations, a new employee won't want to sign a contract without knowing the terms

[Group] Example -- group practice:
"PhysioKlinika" has three employees. Artur (the owner) does things, Monika does things, Paweł does things. Sometimes tasks overlap, sometimes communication breaks down. A new employee arrives: "What are the procedures?" Artur: "You work, you do treatments, you clean up." No clear rules.

An inspection arrives. They ask for the regulations. Artur says: "We work together, we don't need regulations." The inspector: "In this structure you must have them. Staff don't know who's responsible for what." A 2,000 PLN fine. Artur draws up regulations within a week.

How to avoid it?

  1. If you run a group practice, prepare regulations -- covering: structure, responsibility, hygiene procedures, incident reporting procedures
  2. The regulations must be signed by you -- as the medical manager
  3. Every employee must sign -- confirming they've read and understood the regulations
  4. The regulations must be accessible -- kept in the office where every employee can view them
  5. Update the regulations -- whenever the law or the practice structure changes

Comparison table -- 7 mistakes and their penalties

Mistake Fine (min.) Fine (max.) Inspection frequency
#1: No RPWDL3,000 PLNRemoval + 3-year banHigh (NIK, regional governor)
#2: Missing records1,000 PLN3,000 PLNHigh (patients, courts)
#3: No GDPR notice500 PLNEUR 20,000,000Medium (UODO)
#4: No OC insurance2,000 PLNRemovalHigh (RPWDL)
#5: No hygiene plan500 PLN30-day suspensionVery high (Sanepid)
#6: No breach procedure500 PLNEUR 1,000,000Medium (UODO, patients)
#7: No regulations (group practices)1,000 PLN3,000 PLNMedium (Sanepid, regional governor)

CTA: See FizjoReady packages →
Does your practice have all 7 of these compliance elements? FizjoReady's FULL package includes templates for each one:
- RPWDL certificate (guidance on how to check it)
- Medical records template
- GDPR notice
- Insurance policy (limit verification)
- Hygiene plan and disinfection log
- Data breach procedure
- Organisational regulations (for group practices)

FULL package -- 799 PLN. Includes email support for 6 months. [STRIPE LINK]


Frequently asked questions

If I keep careful records, can I avoid all these penalties?

A: Yes, in 90% of cases. The biggest risk is GDPR penalties (which can reach millions), but if you have a privacy notice and a breach procedure, you're protected. The other penalties (for records, hygiene, RPWDL) are usually 500-3,000 PLN if you fix the issue quickly.

Will FizjoReady's templates save me from these fines?

A: The templates are prepared by a lawyer specialising in healthcare and GDPR. They're tested, updated for 2026, and cover all legal requirements. If you use them, you'll avoid 95% of compliance mistakes. The remaining 5% are operational errors (e.g. forgetting to update RPWDL after moving), but that's on you.

What happens if I operate for a year without any of this?

A: Most likely nothing. Sanepid has thousands of practices to inspect and usually visits every 2 years. But if a patient complains or there's an incident, they can come sooner. The risk: a 1,000-5,000 PLN fine + a 30-day suspension = a month's profit gone.

Does a solo practice have fewer requirements than a group practice?

A: Yes, a solo practice doesn't need organisational regulations. But the requirements for RPWDL, OC insurance, records, GDPR and hygiene are identical for both. The paperwork burden is roughly equal; the difference is in details (solo practice: patient agreement, group practice: staff contracts).

How often does Sanepid inspect?

A: In theory, every 2 years (a scheduled inspection). In practice: if there's a complaint or a disease outbreak, they can come sooner. Every inspection is a chance to find mistakes. Prepare for an inspection from the day you open, not the day of the visit.

What should I do if I've already been fined for one of these mistakes?

A: Implement the templates immediately (the FULL package includes procedures), update RPWDL, buy OC insurance, prepare your documentation. If you receive a second fine for the same mistake, the penalty will be harsher (repeat offence). Showing that you've fixed the issue can reduce the penalty at the next inspection.


Summary

7 compliance mistakes are 7 traps you can easily avoid. None of them is difficult -- each just requires paperwork, templates, and persistence.

The worst mistakes are:

  1. No RPWDL registration -- risks removal (the end of the business)
  2. No OC insurance -- risks lawsuits worth tens of thousands of PLN
  3. No GDPR notice -- risks fines in the millions

Everything else (records, hygiene, procedures) carries fines of 500-3,000 PLN, but these can add up.

Best approach: buy the templates (the FULL package for 799 PLN), implement them properly, and work with peace of mind.

CTA: See FizjoReady packages →
Want the certainty that your practice complies with the law?

The FULL package includes all the templates and procedures, prepared by a lawyer. Every template is ready to implement, adapted to Polish law, and tested.

You save 15-20 hours of work and avoid 95% of compliance mistakes.

FULL package -- 799 PLN. Includes email support for 6 months (24-hour response). [STRIPE LINK]

Have a question? Email support@fizjoready.pl. We reply the same day.

Related articles:
- How to open a physiotherapy practice in 2026 -- a complete step-by-step guide
- Checklist: 23 things to sort out before opening a physiotherapy practice
- RPWDL registration -- step by step
- Professional liability insurance for physiotherapists -- cost and coverage
- Medical records for physiotherapists -- patient record, therapy plan, treatment log
- GDPR for physiotherapy practices -- what you need to know
- Sanepid requirements for physiotherapy practices -- hygiene plan and disinfection log

Newsletter

Regulatory changes and practical tips for physiotherapy practices. No spam.