← Journal
Compliance

You Don't Bill Insurance. That's Only Half the HIPAA Story.

Cash-pay medspa owners love to say HIPAA doesn't apply to them because they don't bill insurance. That's a half-truth built on a narrow reading of federal law — and HSA/FSA rails, electronic record transmission, and state-level overlays can pull you right back into scope.

The Lumè team4 min read

We hear the same sentence from owners in almost the same words: "I don't bill insurance, so HIPAA doesn't apply to me." It's a reasonable thing to believe. Insurance billing is the version of HIPAA most people run into first. If you built a cash-pay injectables practice and never touch a claims system, it's fair to assume you sidestepped the whole thing.

We're not attorneys, and this isn't legal advice. It's the explanation we wish someone had given us plainly instead of in a sales deck. And the honest answer to "I don't bill insurance" is: that's half a story.

The Half That's True

Federal HIPAA is narrower than most people think. Providing a healthcare service doesn't make you a Covered Entity by itself. A genuinely cash-pay practice with no insurance claims can, on that narrow reading, sit outside the federal definition. If a medspa injects neurotoxin, that's an FDA-regulated drug — but the drug alone doesn't pull you into HIPAA's scope. If that were the whole analysis, this would be a short article.

It isn't the whole analysis.

The Half That Gets Left Out

Three things routinely pull a "cash-pay" practice back into scope, and none of them show up on a billing statement.

HSA and FSA rails. A lot of medspas take these cards at checkout, and it feels identical to a debit swipe. It isn't quite. The account behind the card runs through a different set of rules than your merchant terminal does. We're not going to tell you this resolves cleanly to yes or no — it doesn't. If HSA/FSA volume is meaningful for your practice, that's a question worth putting to someone who can look at how you actually process it, not a blanket answer from a blog post.

Electronic record transmission. Chart notes, before/after photos, signed consent — the moment any of it moves electronically between systems, you've introduced a transmission question, whether or not an insurance claim is anywhere in the chain. A booking platform pushing data to a charting tool, a chart syncing to backup, a photo emailed to another provider — all of it counts as movement, not storage.

State overlays. Several state attorneys general now enforce HIPAA-aligned obligations under their own state law, sometimes with broader scope than federal HIPAA itself. That enforcement runs independent of whether you clear the federal Covered Entity test. "I checked, I'm not federally covered" can be true and still leave you exposed under your own state's law. Confirming one doesn't confirm the other.

The Right Question Isn't "Am I Covered"

Spending months determining whether you clear the federal threshold is the wrong use of your attention. The better question: if a client's photos, consent form, or payment record leaked or got subpoenaed tomorrow, would your systems hold up? Could you show who accessed that record, when, and under which version of the consent they signed?

That question doesn't wait on a legal determination. And the systems that answer it well are the same systems whether or not you turn out to be technically covered.

The Floor, Not a Paid Upgrade

Here's our actual opinion: if compliance is a feature you pay up to a higher tier to reach, the base product doesn't have it. That's a marketing tier with a BAA taped on, not compliance architecture.

We built to a different standard: a Business Associate Agreement in the standard contract at every tier, tenant data isolated at the database level, an append-only audit log on every PHI read, encryption in transit and at rest. HIPAA-aligned architecture should be the floor of any medical software product — not an enterprise add-on you go chasing once you've outgrown the cheap plan.

When you're evaluating a vendor's BAA, the question isn't whether they offer one. It's whether it's sitting in your actual contract, at the tier you're paying for, or waiting on a page marked "Enterprise."

What to Do With This

Covered Entity status can turn on billing and transmission specifics unique to your practice — how you process payments, what you integrate with, what moves electronically and where. Confirm your actual status with an attorney who can look at your setup. That part, we can't do for you.

The software decision doesn't have to wait on that answer, though. Ask any vendor to show you their BAA and their audit trail — not describe them, show them. "Defensible" and "addressable" are the honest words here, not "guaranteed compliant." Nobody selling medical software should promise you the second. What they can build, and what you can insist on seeing, is the first.

Frequently asked questions

If my medspa doesn't bill insurance, am I exempt from HIPAA?
Not necessarily. Federal HIPAA's Covered Entity definition is narrower than most people think, and a genuinely cash-pay practice with no insurance claims can sit outside it on that narrow reading. But HSA/FSA payment processing, electronic transmission of records between systems, and state-level privacy laws can independently pull you back into scope regardless of billing method.
Do HSA and FSA card payments count as insurance billing under HIPAA?
Not exactly, but they're not identical to a plain debit swipe either. HSA/FSA accounts run through a different set of rules than a standard merchant terminal, and whether that exposes you to HIPAA obligations depends on how your practice actually processes those transactions. This needs a case-by-case look from someone who can review your specific payment setup.
Does emailing a client's photos or chart notes to another provider trigger HIPAA?
Any electronic movement of chart notes, photos, or signed consent forms between systems raises a transmission question, whether or not an insurance claim is involved. This includes a booking platform pushing data to a charting tool, a chart syncing to backup, or a photo emailed to a colleague. The insurance status of the practice doesn't change whether that movement counts.
Can I be exempt from federal HIPAA but still be legally required to comply with something similar?
Yes. Several state attorneys general enforce HIPAA-aligned obligations under their own state law, and that enforcement operates independently of federal Covered Entity status. Confirming you're not federally covered does not confirm you're clear under your state's law — the two determinations are separate and both need checking.
What should I actually look for in a medspa software vendor's BAA?
Confirm the Business Associate Agreement is included in your actual contract at the tier you're paying for, not held back for an 'Enterprise' plan. Also ask the vendor to show you their audit trail — who accessed a record, when, and under which consent version — rather than just describing it in a sales conversation.
Get a demo

See exactly how Lumè fits your medspa.

A focused 30-minute walkthrough of the platform, tailored to how your spa runs. The first call is the demo.