Not billing insurance does not automatically place a medspa outside HIPAA's reach. We hear this one constantly, usually from an owner who's already decided the answer and is looking for confirmation: "I don't file claims, so HIPAA isn't my problem." That is half a story. The insurance-billing test is the wrong test to run, and running it gives you false confidence in exactly the scenario where you can least afford it.
The real triggers have nothing to do with whether a payer reimburses you. They have to do with what you transmit, who touches it, and what your state layers on top.
HSA and FSA Rails Are a Real Trigger — Narrower Than People Think
The common claim is that swiping an HSA or FSA card automatically makes a practice a covered entity. That skips a step. But the underlying direction is right: those payment rails are one of the ways a cash-and-carry aesthetics practice gets pulled into HIPAA-adjacent scope — not by billing insurance, but by touching a health-payment system that carries its own reporting and eligibility rules. The mistake isn't flagging HSA/FSA as relevant. The mistake is treating "we don't bill insurance" as the end of the analysis when a different rail can do the same work.
The Trigger Most Practices Miss: Your Vendor Stack
For a medspa, PHI shows up in ordinary places — a name attached to a treatment, before-and-after photos tied to an identity, dosages and lot numbers on a chart, intake and consultation notes. None of that requires a diagnosis code or an insurance claim to count as protected health information.
And once PHI exists, it usually leaves your hands. A CRM, card processing, an e-signed consent tool — any vendor handling PHI on your behalf is a Business Associate, and that relationship calls for a signed BAA regardless of whether your own practice bills insurance. This is a separate question from whether the practice itself is a covered entity. You can be a covered entity and hire business associates. You can also, in theory, sit outside HIPAA's federal reach yourself while still handing PHI to a vendor that should be treating the relationship as if you were.
This trigger is quieter than a card swipe, and it catches almost everyone. A public booking page. A card on file. A consent form that captures a name, a timestamp, and an IP address at the moment of signature. Each one is standard now. Each one is also a wire that health information crosses the instant you adopt it — which makes "we're cash-only, so we're exempt" a much harder claim to hold.
Your State Might Not Wait for HIPAA to Apply
Even where the federal picture is murky, state law doesn't necessarily wait for it. Several state attorneys general now enforce HIPAA-aligned obligations under their own statutes — in some cases with broader scope than federal HIPAA itself. A practice can be cash-only, paper-light, and still find itself answering to a state law that never asked whether it filed a claim.
Most owners run the insurance test, pass it, and stop looking. The state overlay doesn't check whether you passed the federal test first.
Why the Safer Bet Is the Floor, Not the Exemption
Put the pieces together and the exemption stops looking like a plan. Between HSA/FSA rails, a vendor stack that almost every modern front desk now runs, and state law that doesn't require the federal trigger at all, most independent medspas can't cleanly prove they sit outside every path into scope. Chasing the exemption means betting the practice on a status you'd have to defend after the fact — to a regulator or a client's attorney — using a paper trail you probably don't have.
We think the safer posture is to treat HIPAA-grade safeguards as the floor regardless of which side of the line you fall on, not something you reach for once you've decided you're covered.
What to Actually Ask a CRM Vendor
Ask whether tenant data is isolated at the database level. Ask whether there's an append-only audit log on every PHI read — not just a login log, a record of who touched the chart itself. Ask whether data is encrypted in transit and at rest. And ask whether a Business Associate Agreement is included in the standard contract at every tier, not sold as an upgrade once you've outgrown the starter plan.
We built Lumè's HIPAA architecture around those things, including versioned, e-signed consent tied to the chart. We want to be plain about what that is and isn't: it's architecture that supports a defensible posture — not a certification, and not a guarantee that your practice is HIPAA compliant. Compliance is a program a practice runs. The BAA is on every plan listed on our pricing page for that reason — the floor shouldn't move depending on what you pay.
A Plain Note Before You Act on Any of This
This is an explainer, not legal advice. State law varies enough that a practice's specific exposure depends heavily on where it operates and how it runs its front desk. If you have a specific exposure question, confirm it with your own counsel rather than relying on a general explainer — ours included.