"I don't bill insurance, so HIPAA doesn't apply to me" is the sentence we hear most often from injectable-heavy practices sizing up new software. It's half a story. Billing is the right place to look, but the question is narrower than most people think, it can change without you noticing, and your state may ask its own version of it. If you hold client health history, photos and consent forms electronically, which is to say if you run a modern medspa at all, the quiz-style yes/no answer isn't going to serve you on its own.
Covered Entity and Business Associate, in plain terms
Two terms get thrown around like synonyms. They aren't.
A Covered Entity is a health plan, a health care clearinghouse, or a health care provider that transmits health information electronically for certain transactions. A Business Associate is a vendor that creates, receives or transmits PHI on a covered entity's behalf: a CRM, a billing service, a cloud host. Covered entities need BAAs from their business associates. That's the whole relationship, structurally.
Here's where most medspas get tangled: injectable treatments are health care by function. Neurotoxin, filler, any service a provider delivers clinically counts as providing health care in the ordinary sense of the term. But "I provide health care" doesn't by itself make you a Covered Entity. It's a necessary condition, not a sufficient one.
What makes a provider a Covered Entity?
The federal definition is specific. A provider is a Covered Entity when it transmits health information in electronic form in connection with a HIPAA transaction: the standard electronic exchanges with health plans, such as claims, eligibility checks, claim status and remittances. As CMS puts it, providers who submit HIPAA transactions, like claims, electronically are covered.
It doesn't matter whether you press the button yourself. A billing service or clearinghouse that files an electronic claim on your behalf is conducting that transaction for you.
What doesn't make you one
A few things feel like they should count, and don't:
- Holding records. A client's chart, photos and signed consent are health information the moment they're stored. Storing them doesn't, by itself, make you a Covered Entity.
- Taking card payments. Running a card for a filler appointment is a payment, not a HIPAA transaction. That includes HSA and FSA cards.
- Handing a client a superbill. If the client submits it to their plan, the client is the one dealing with the plan, not you.
- Having a medical director. Clinical oversight is about how you practice, not how you bill.
Where cash-pay practices cross the line without noticing
The exposure for a practice that thinks of itself as pure cash-pay is usually one relationship, not a policy. An outside biller who files claims for a medically indicated treatment. A clearinghouse account someone set up to check a client's coverage. A single service that started being billed to a plan.
Any of these is the practice conducting standard transactions electronically, through someone acting for it. One electronic claim is enough. And because it often happens in one corner of the business, the owner may be the last to know.
States don't wait on Washington
Even a practice that genuinely clears the federal test isn't necessarily done. Some states have their own health-privacy laws, enforced by their own attorneys general, and some reach businesses that federal HIPAA doesn't. State law doesn't ask whether you'd pass the federal Covered Entity test; it asks its own questions. A practice that scopes itself only against the federal definition has done half the homework.
Stop looking for a permanent yes/no answer
Federal scope turns on what you, or someone acting for you, sends to health plans electronically. That's a real line, and plenty of cash-pay practices are on the outside of it. But it can move the day you add a biller or start billing one service to a plan, and your state's law sits on top of it either way.
So treat scope as something to recheck when your billing or your vendors change, not a box you tick once at intake.
The BAA question comes first, not last
Here's the operational point that actually changes what you do Monday morning: if a CRM, a scheduling tool or a marketing platform touches client health data, ask the BAA question before you've settled the Covered Entity question, not after.
A vendor's willingness to sign a BAA doesn't decide your own status one way or the other. And if your practice is in scope, a vendor's BAA doesn't replace your own obligations: it covers the vendor's handling of the data, not your Privacy Rule and Security Rule responsibilities as the business that holds the client relationship. The two questions run in parallel. Treating them as sequential is how practices end up unprotected during exactly the gap where scope is unclear.
If compliance is a paid upgrade, the base product doesn't have it
Our view, stated flat: HIPAA safeguards and a BAA should be the floor at every tier, not an upgrade you chase down after you've outgrown a cheaper plan. If a vendor gates the BAA to their top-tier contract, the base product was built without it in mind.
Lumè signs a BAA with every customer, on every plan. The architecture under it: each spa's records walled off from every other spa's, an append-only audit log of every read of protected health information, and encryption in transit and at rest. The specifics are on our security page, and every plan is on pricing. This is a defensible posture, not a guarantee of compliance, and Lumè is not a certified EHR. If you bill insurance or prescribe electronically, you may need one alongside a CRM like this, not instead of it.
Confirm your own scope before you decide anything
Everything above is the scoping exercise, not a verdict. The honest answer for your practice depends on your billing, your vendor relationships and your state, not on a blog post, ours or anyone else's. Confirm your actual scope with counsel or a compliance advisor who can look at your specific contracts. What you do next, requiring BAAs and picking software that treats them as standard rather than a paid add-on, doesn't have to wait on that answer.