Am I a HIPAA Covered Entity? Wrong Question for Most Medspas

Most medspa owners ask "am I a Covered Entity" like it's a yes/no quiz, then relax when the answer seems to be no. The answer is real and worth knowing, but it changes less than people think: it can shift the day you add a biller, your state's law has its own say, and the BAA question shouldn't wait on it.

The Lumè team7 min read

"I don't bill insurance, so HIPAA doesn't apply to me" is the sentence we hear most often from injectable-heavy practices sizing up new software. It's half a story. Billing is the right place to look, but the question is narrower than most people think, it can change without you noticing, and your state may ask its own version of it. If you hold client health history, photos and consent forms electronically, which is to say if you run a modern medspa at all, the quiz-style yes/no answer isn't going to serve you on its own.

Covered Entity and Business Associate, in plain terms

Two terms get thrown around like synonyms. They aren't.

A Covered Entity is a health plan, a health care clearinghouse, or a health care provider that transmits health information electronically for certain transactions. A Business Associate is a vendor that creates, receives or transmits PHI on a covered entity's behalf: a CRM, a billing service, a cloud host. Covered entities need BAAs from their business associates. That's the whole relationship, structurally.

Here's where most medspas get tangled: injectable treatments are health care by function. Neurotoxin, filler, any service a provider delivers clinically counts as providing health care in the ordinary sense of the term. But "I provide health care" doesn't by itself make you a Covered Entity. It's a necessary condition, not a sufficient one.

What makes a provider a Covered Entity?

The federal definition is specific. A provider is a Covered Entity when it transmits health information in electronic form in connection with a HIPAA transaction: the standard electronic exchanges with health plans, such as claims, eligibility checks, claim status and remittances. As CMS puts it, providers who submit HIPAA transactions, like claims, electronically are covered.

It doesn't matter whether you press the button yourself. A billing service or clearinghouse that files an electronic claim on your behalf is conducting that transaction for you.

What doesn't make you one

A few things feel like they should count, and don't:

  • Holding records. A client's chart, photos and signed consent are health information the moment they're stored. Storing them doesn't, by itself, make you a Covered Entity.
  • Taking card payments. Running a card for a filler appointment is a payment, not a HIPAA transaction. That includes HSA and FSA cards.
  • Handing a client a superbill. If the client submits it to their plan, the client is the one dealing with the plan, not you.
  • Having a medical director. Clinical oversight is about how you practice, not how you bill.

Where cash-pay practices cross the line without noticing

The exposure for a practice that thinks of itself as pure cash-pay is usually one relationship, not a policy. An outside biller who files claims for a medically indicated treatment. A clearinghouse account someone set up to check a client's coverage. A single service that started being billed to a plan.

Any of these is the practice conducting standard transactions electronically, through someone acting for it. One electronic claim is enough. And because it often happens in one corner of the business, the owner may be the last to know.

States don't wait on Washington

Even a practice that genuinely clears the federal test isn't necessarily done. Some states have their own health-privacy laws, enforced by their own attorneys general, and some reach businesses that federal HIPAA doesn't. State law doesn't ask whether you'd pass the federal Covered Entity test; it asks its own questions. A practice that scopes itself only against the federal definition has done half the homework.

Stop looking for a permanent yes/no answer

Federal scope turns on what you, or someone acting for you, sends to health plans electronically. That's a real line, and plenty of cash-pay practices are on the outside of it. But it can move the day you add a biller or start billing one service to a plan, and your state's law sits on top of it either way.

So treat scope as something to recheck when your billing or your vendors change, not a box you tick once at intake.

The BAA question comes first, not last

Here's the operational point that actually changes what you do Monday morning: if a CRM, a scheduling tool or a marketing platform touches client health data, ask the BAA question before you've settled the Covered Entity question, not after.

A vendor's willingness to sign a BAA doesn't decide your own status one way or the other. And if your practice is in scope, a vendor's BAA doesn't replace your own obligations: it covers the vendor's handling of the data, not your Privacy Rule and Security Rule responsibilities as the business that holds the client relationship. The two questions run in parallel. Treating them as sequential is how practices end up unprotected during exactly the gap where scope is unclear.

If compliance is a paid upgrade, the base product doesn't have it

Our view, stated flat: HIPAA safeguards and a BAA should be the floor at every tier, not an upgrade you chase down after you've outgrown a cheaper plan. If a vendor gates the BAA to their top-tier contract, the base product was built without it in mind.

Lumè signs a BAA with every customer, on every plan. The architecture under it: each spa's records walled off from every other spa's, an append-only audit log of every read of protected health information, and encryption in transit and at rest. The specifics are on our security page, and every plan is on pricing. This is a defensible posture, not a guarantee of compliance, and Lumè is not a certified EHR. If you bill insurance or prescribe electronically, you may need one alongside a CRM like this, not instead of it.

Confirm your own scope before you decide anything

Everything above is the scoping exercise, not a verdict. The honest answer for your practice depends on your billing, your vendor relationships and your state, not on a blog post, ours or anyone else's. Confirm your actual scope with counsel or a compliance advisor who can look at your specific contracts. What you do next, requiring BAAs and picking software that treats them as standard rather than a paid add-on, doesn't have to wait on that answer.

Frequently asked questions

If my medspa is cash-pay only, am I automatically exempt from HIPAA?
Not automatically. A provider becomes a Covered Entity by conducting HIPAA standard transactions electronically, such as claims or eligibility checks, either directly or through a billing service. A practice that does none of that, itself or through anyone acting for it, generally isn't one. Taking card payments, HSA and FSA cards included, isn't a standard transaction. One electronic claim filed for you is.
What's the actual legal difference between a Covered Entity and a Business Associate?
A Covered Entity is a health plan, a clearinghouse, or a provider that transmits health information electronically for certain standard transactions like claims or eligibility checks. A Business Associate is a vendor, such as a CRM, biller or cloud host, that creates, receives or transmits PHI on a Covered Entity's behalf. Covered Entities need BAAs from their Business Associates.
Does storing client photos and consent forms electronically make me a Covered Entity?
Not by itself. The legal trigger is conducting standard transactions electronically, not storing sensitive records. A chart or photo is still health information the moment it's stored, and state privacy laws can apply to it whether or not federal HIPAA does.
Do state laws matter if I pass the federal HIPAA Covered Entity test?
Yes. Some states have their own health-privacy laws, enforced by their own attorneys general, and some reach businesses that federal HIPAA doesn't. Clearing the federal test doesn't settle your state's requirements, so check both.
Should I wait until I know my Covered Entity status before requiring a BAA from my software vendor?
No. The two questions run in parallel. A vendor's BAA doesn't decide your status, and waiting to resolve scope before requiring one leaves the practice unprotected during exactly the period when its status is unclear.
A 30-minute demo

See Lumè in action.

Get a personalized walkthrough using your real services, staff, and workflows. Plans start at $149 a month.

One business day to a calendar invite.