Most cash-pay med spas are probably not HIPAA covered entities, and almost none of them know it. The definition is short. Under 45 CFR § 160.103, “covered entity means: (1) A health plan. (2) A health care clearinghouse. (3) A health care provider who transmits any health information in electronic form in connection with a transaction covered by this subchapter.”
Read clause (3) twice. Being a health care provider is not enough. The trigger is transmitting health information electronically in connection with a covered transaction, which is the standardized electronic exchanges built around billing: claims, eligibility checks, claim status, remittance. A clinic that takes a card, bills no insurer and runs none of those transactions does not meet clause (3).
That is not the relief it sounds like. It does not make you unregulated. It changes which agency regulates you, and in one specific place it takes a protection away.
What you are, and what follows
| Your situation | Regulator | What governs the data |
|---|---|---|
| You run covered transactions | HHS Office for Civil Rights | HIPAA Privacy and Security Rules, breach notification, BAAs |
| You never do | Federal Trade Commission | FTC Act § 5, and the Health Breach Notification Rule |
| Either way | Your state | State health-privacy law and comprehensive privacy statutes |
The rule that fills the gap
The Federal Trade Commission’s Health Breach Notification Rule, 16 CFR Part 318, requires vendors of personal health records and related entities that are not covered by HIPAA to notify individuals, the FTC, and in some cases the media after a breach of unsecured identifiable health data. The rule states plainly that it “does not apply to HIPAA-covered entities.”
The FTC finalized amendments to it that took effect July 29, 2024, which make explicit that makers of health apps, connected devices and similar products fall inside it. If your clinic runs an app, a connected device program or a portal that holds health information and you are not a covered entity, this is your breach rule.
So the honest summary is that falling outside HIPAA moves you from one breach regime to another. It does not remove the obligation to have one.
The place it actually costs you
There is one consequence operators never anticipate, and it shows up in marketing rather than compliance.
The Telephone Consumer Protection Act rules exempt certain health care messages from the consent requirements that otherwise apply. The exemption in 47 CFR § 64.1200(a)(2) is written for “a call that delivers a ‘health care’ message made by, or on behalf of, a ‘covered entity’ or its ‘business associate,’ as those terms are defined in the HIPAA Privacy Rule, 45 CFR 160.103.”
The exemption is keyed to HIPAA status. If you are not a covered entity, you do not get it, and your appointment reminders sit in ordinary TCPA territory where consent is the whole question. We work through that in texting patients.
This is the part worth internalizing: HIPAA status is not only a burden. It carries a benefit you lose along with it.
Deciding which one you are
- Do you submit claims to any insurer, ever? Including a single out-of-network claim, or a superbill you transmit electronically on a patient’s behalf.
- Do you check eligibility or benefits electronically? This is a covered transaction in its own right, and clinics do it without recognizing it.
- Does any vendor do either on your behalf? Their conduct can pull you in.
- Do you take HSA or FSA cards? By itself this is a payment method rather than a covered transaction, but the surrounding workflow is worth checking.
If every answer is a firm no, you are probably outside HIPAA. Document the analysis rather than the conclusion, because the answer changes the day someone decides to bill an insurer.
What to actually do
The safeguards do not change much between the two regimes. What changes is who audits you and what a failure is called.
- Write down which regime applies and why, with the date and who decided. This is the single most useful page in the binder.
- Keep the security controls either way. Access control, encryption at rest and in transit, audit logging, a real off-boarding process. Both regulators expect them.
- Have a breach plan naming the right recipient. HHS for a covered entity, the FTC under Part 318 if not, plus your state attorney general in most cases.
- Check your vendor paper. Covered entities need business associate agreements. See who in your stack needs one.
- Look at your website separately. Tracking technologies are their own question and the guidance moved in court. See clinic website tracking technologies.
What this means for you
Stop buying a HIPAA compliance package before you have answered whether HIPAA applies to you, because a large share of this market is paying for the wrong framework and still carrying the risk that actually attaches. Do the clause (3) analysis, write it down, and re-run it whenever the billing model changes. Then build the safeguards regardless, because every regime expects them and because the patients do not care which agency would take the complaint. The clinics that get this wrong are not the ones with weak security. They are the ones who assumed a regulator and never checked.
Related reading
Frequently asked questions
Is a cash-pay med spa a HIPAA covered entity?
Often not. Under 45 CFR § 160.103 a health care provider is a covered entity only if it transmits health information electronically in connection with a covered transaction, which are the standardized exchanges built around billing. A clinic that bills no insurer and runs none of those transactions does not meet that test.
If HIPAA does not apply, is patient data unregulated?
No. The FTC’s Health Breach Notification Rule, 16 CFR Part 318, applies to entities holding identifiable health data that are not covered by HIPAA, and its 2024 amendments effective July 29, 2024 make clear it reaches health apps and connected devices. Section 5 of the FTC Act and state privacy law also apply.
Does taking a single insurance claim make me a covered entity?
It can. The test turns on transmitting health information electronically in connection with a covered transaction. Clinics that consider themselves cash-pay sometimes run eligibility checks or submit occasional claims, which is why the analysis should be re-run whenever the billing model changes.
Do I still need business associate agreements if I am not covered?
Business associate agreements are a HIPAA construct. If you are not a covered entity you have no BAAs to sign, though you still want contractual security and breach-notification terms with any vendor holding your patients’ data.
Which is better, being covered or not?
Neither is simply better. Falling outside HIPAA moves you to the FTC’s breach rule rather than removing the obligation, and it costs you the TCPA health care message exemption in 47 CFR § 64.1200(a)(2), which is written by reference to covered entity status.
This is general information, not legal advice. Rules vary by state and change. Confirm your own facts with counsel.