← Journal
Compliance

Your Medspa Doesn't Bill Insurance. HIPAA May Still Apply.

Every medspa owner runs the same mental test: no insurance claims, so no HIPAA. That test is incomplete, and the gaps — payment rails, vendor contracts, state law — are exactly where practices get exposed after a breach, not before one.

The Lumè team4 min read

Not billing insurance does not automatically place a medspa outside HIPAA's reach. We hear this one constantly, usually from an owner who's already decided the answer and is looking for confirmation: "I don't file claims, so HIPAA isn't my problem." That is half a story. The insurance-billing test is the wrong test to run, and running it gives you false confidence in exactly the scenario where you can least afford it.

The real triggers have nothing to do with whether a payer reimburses you. They have to do with what you transmit, who touches it, and what your state layers on top.

HSA and FSA Rails Are a Real Trigger — Narrower Than People Think

The common claim is that swiping an HSA or FSA card automatically makes a practice a covered entity. That skips a step. But the underlying direction is right: those payment rails are one of the ways a cash-and-carry aesthetics practice gets pulled into HIPAA-adjacent scope — not by billing insurance, but by touching a health-payment system that carries its own reporting and eligibility rules. The mistake isn't flagging HSA/FSA as relevant. The mistake is treating "we don't bill insurance" as the end of the analysis when a different rail can do the same work.

The Trigger Most Practices Miss: Your Vendor Stack

For a medspa, PHI shows up in ordinary places — a name attached to a treatment, before-and-after photos tied to an identity, dosages and lot numbers on a chart, intake and consultation notes. None of that requires a diagnosis code or an insurance claim to count as protected health information.

And once PHI exists, it usually leaves your hands. A CRM, card processing, an e-signed consent tool — any vendor handling PHI on your behalf is a Business Associate, and that relationship calls for a signed BAA regardless of whether your own practice bills insurance. This is a separate question from whether the practice itself is a covered entity. You can be a covered entity and hire business associates. You can also, in theory, sit outside HIPAA's federal reach yourself while still handing PHI to a vendor that should be treating the relationship as if you were.

This trigger is quieter than a card swipe, and it catches almost everyone. A public booking page. A card on file. A consent form that captures a name, a timestamp, and an IP address at the moment of signature. Each one is standard now. Each one is also a wire that health information crosses the instant you adopt it — which makes "we're cash-only, so we're exempt" a much harder claim to hold.

Your State Might Not Wait for HIPAA to Apply

Even where the federal picture is murky, state law doesn't necessarily wait for it. Several state attorneys general now enforce HIPAA-aligned obligations under their own statutes — in some cases with broader scope than federal HIPAA itself. A practice can be cash-only, paper-light, and still find itself answering to a state law that never asked whether it filed a claim.

Most owners run the insurance test, pass it, and stop looking. The state overlay doesn't check whether you passed the federal test first.

Why the Safer Bet Is the Floor, Not the Exemption

Put the pieces together and the exemption stops looking like a plan. Between HSA/FSA rails, a vendor stack that almost every modern front desk now runs, and state law that doesn't require the federal trigger at all, most independent medspas can't cleanly prove they sit outside every path into scope. Chasing the exemption means betting the practice on a status you'd have to defend after the fact — to a regulator or a client's attorney — using a paper trail you probably don't have.

We think the safer posture is to treat HIPAA-grade safeguards as the floor regardless of which side of the line you fall on, not something you reach for once you've decided you're covered.

What to Actually Ask a CRM Vendor

Ask whether tenant data is isolated at the database level. Ask whether there's an append-only audit log on every PHI read — not just a login log, a record of who touched the chart itself. Ask whether data is encrypted in transit and at rest. And ask whether a Business Associate Agreement is included in the standard contract at every tier, not sold as an upgrade once you've outgrown the starter plan.

We built Lumè's HIPAA architecture around those things, including versioned, e-signed consent tied to the chart. We want to be plain about what that is and isn't: it's architecture that supports a defensible posture — not a certification, and not a guarantee that your practice is HIPAA compliant. Compliance is a program a practice runs. The BAA is on every plan listed on our pricing page for that reason — the floor shouldn't move depending on what you pay.

A Plain Note Before You Act on Any of This

This is an explainer, not legal advice. State law varies enough that a practice's specific exposure depends heavily on where it operates and how it runs its front desk. If you have a specific exposure question, confirm it with your own counsel rather than relying on a general explainer — ours included.

Frequently asked questions

Does HIPAA apply to a medspa that only takes cash payments?
Not billing insurance doesn't automatically exempt a practice from HIPAA or HIPAA-adjacent obligations. HSA/FSA transactions, vendor relationships involving PHI, and state laws modeled on HIPAA can all create obligations independent of whether you file insurance claims. A cash-only practice should still evaluate these other triggers rather than stopping at the insurance test.
Does accepting HSA or FSA cards make my medspa a covered entity?
Not automatically, but it's a relevant factor. HSA and FSA payment rails carry their own eligibility and reporting rules, and using them can pull a cash-and-carry practice into HIPAA-adjacent scope even without insurance billing. It's one of several triggers to check, not a standalone test.
What counts as protected health information (PHI) in a medspa?
PHI in a medspa context includes a client's name attached to a treatment, before-and-after photos tied to an identity, dosages and lot numbers on a chart, and intake or consultation notes. None of this requires a diagnosis code or insurance claim to qualify as PHI. Once this information exists and is shared with a vendor, that vendor is likely a Business Associate under HIPAA.
Do I need a Business Associate Agreement (BAA) with my CRM or booking software?
Yes, if that vendor handles PHI on your behalf — including CRMs, card processors, or e-signature consent tools — a signed BAA is required regardless of whether your own practice bills insurance. This is a separate question from whether your practice itself is a covered entity; you can be exempt yourself and still owe this obligation through your vendor relationships.
Can state law require HIPAA-like compliance even if federal HIPAA doesn't apply?
Yes. Several state attorneys general enforce HIPAA-aligned obligations under their own statutes, and some of these have broader scope than federal HIPAA. A practice can be cash-only and still fall under a state law that never checks whether it filed an insurance claim.
Get a demo

See exactly how Lumè fits your medspa.

A focused 30-minute walkthrough of the platform, tailored to how your spa runs. The first call is the demo.