We hear the same sentence from owners in almost the same words: "I don't bill insurance, so HIPAA doesn't apply to me." It's a reasonable thing to believe. Insurance billing is the version of HIPAA most people run into first. If you built a cash-pay injectables practice and never touch a claims system, it's fair to assume you sidestepped the whole thing.
We're not attorneys, and this isn't legal advice. It's the explanation we wish someone had given us plainly instead of in a sales deck. And the honest answer to "I don't bill insurance" is: that's half a story.
The Half That's True
Federal HIPAA is narrower than most people think. Providing a healthcare service doesn't make you a Covered Entity by itself. A genuinely cash-pay practice with no insurance claims can, on that narrow reading, sit outside the federal definition. If a medspa injects neurotoxin, that's an FDA-regulated drug — but the drug alone doesn't pull you into HIPAA's scope. If that were the whole analysis, this would be a short article.
It isn't the whole analysis.
The Half That Gets Left Out
Three things routinely pull a "cash-pay" practice back into scope, and none of them show up on a billing statement.
HSA and FSA rails. A lot of medspas take these cards at checkout, and it feels identical to a debit swipe. It isn't quite. The account behind the card runs through a different set of rules than your merchant terminal does. We're not going to tell you this resolves cleanly to yes or no — it doesn't. If HSA/FSA volume is meaningful for your practice, that's a question worth putting to someone who can look at how you actually process it, not a blanket answer from a blog post.
Electronic record transmission. Chart notes, before/after photos, signed consent — the moment any of it moves electronically between systems, you've introduced a transmission question, whether or not an insurance claim is anywhere in the chain. A booking platform pushing data to a charting tool, a chart syncing to backup, a photo emailed to another provider — all of it counts as movement, not storage.
State overlays. Several state attorneys general now enforce HIPAA-aligned obligations under their own state law, sometimes with broader scope than federal HIPAA itself. That enforcement runs independent of whether you clear the federal Covered Entity test. "I checked, I'm not federally covered" can be true and still leave you exposed under your own state's law. Confirming one doesn't confirm the other.
The Right Question Isn't "Am I Covered"
Spending months determining whether you clear the federal threshold is the wrong use of your attention. The better question: if a client's photos, consent form, or payment record leaked or got subpoenaed tomorrow, would your systems hold up? Could you show who accessed that record, when, and under which version of the consent they signed?
That question doesn't wait on a legal determination. And the systems that answer it well are the same systems whether or not you turn out to be technically covered.
The Floor, Not a Paid Upgrade
Here's our actual opinion: if compliance is a feature you pay up to a higher tier to reach, the base product doesn't have it. That's a marketing tier with a BAA taped on, not compliance architecture.
We built to a different standard: a Business Associate Agreement in the standard contract at every tier, tenant data isolated at the database level, an append-only audit log on every PHI read, encryption in transit and at rest. HIPAA-aligned architecture should be the floor of any medical software product — not an enterprise add-on you go chasing once you've outgrown the cheap plan.
When you're evaluating a vendor's BAA, the question isn't whether they offer one. It's whether it's sitting in your actual contract, at the tier you're paying for, or waiting on a page marked "Enterprise."
What to Do With This
Covered Entity status can turn on billing and transmission specifics unique to your practice — how you process payments, what you integrate with, what moves electronically and where. Confirm your actual status with an attorney who can look at your setup. That part, we can't do for you.
The software decision doesn't have to wait on that answer, though. Ask any vendor to show you their BAA and their audit trail — not describe them, show them. "Defensible" and "addressable" are the honest words here, not "guaranteed compliant." Nobody selling medical software should promise you the second. What they can build, and what you can insist on seeing, is the first.