Med spas, wellness clinics and telehealth platforms often assume that because they don’t bill insurance, HIPAA simply doesn’t apply. That assumption is understandable, and it’s often close to right, but the actual legal test is narrower and more specific than “we’re cash-pay,” and getting it wrong can leave a business either over-investing in compliance it doesn’t need or under-protecting client information it’s still legally required to protect under other laws.

The Legal Test: Are You a “Covered Entity”?

HIPAA applies to a specific category called a “covered entity,” and a healthcare provider only qualifies if it transmits health information electronically in connection with a “covered transaction,” a specific, defined list under HIPAA’s Transactions Rule (45 C.F.R. Part 162). Covered transactions include things like submitting a claim electronically to a health plan, checking insurance eligibility electronically, or handling a referral authorization electronically.

Ordinary business activities, like emailing a client, storing records in an EHR, or accepting a card payment, are not themselves covered transactions. The trigger is specifically about electronic transactions with a health plan.

Where This Gets Tricky for Med Spas, Wellness, and Telehealth Businesses

A genuinely cash-pay business that never submits claims or checks eligibility electronically generally is not a HIPAA covered entity, and HIPAA’s Privacy, Security, and Breach Notification Rules don’t apply as a matter of federal law. But a few common scenarios in these specific verticals can flip that status without anyone realizing it:

  • Med spas offering a mix of cosmetic and covered medical services sometimes submit claims for the medical portion (say, a covered dermatology visit bundled with a cosmetic treatment), which can trigger covered-entity status for the whole practice.
  • Telehealth platforms using billing or EHR software that defaults to electronic eligibility checks or claims submission, even for patients who ultimately pay cash, can trigger this without the platform intending to bill insurance at all.
  • Wellness clinics that occasionally submit a claim as a courtesy for a patient who has out-of-network benefits, even infrequently, can trigger the same result.
  • Any Medicare or Medicaid enrollment, since enrolled providers are generally required to submit claims electronically. A formal Medicare opt-out avoids this.

The takeaway: “cash-pay” as a business model and “not a covered entity” as a legal status usually go together, but not automatically. It depends on what the business actually does electronically, not how it markets itself.

What About E-Prescribing?

This comes up constantly for businesses. Basic e-prescribing, simply transmitting a prescription to a pharmacy, is not itself a HIPAA standard transaction, so it doesn’t automatically trigger covered-entity status on its own. Where it gets more complicated: many e-prescribing platforms also handle formulary checks, medication history lookups, or prior authorization requests tied to a Medicare Part D standard. If your software is doing that on a patient’s behalf, that activity looks a lot more like a covered transaction. And separately, DEA’s electronic prescribing rules for controlled substances (EPCS) apply regardless of HIPAA status, so a non-covered telehealth platform still has to comply with EPCS if it e-prescribes controlled substances.
Even If You’re Not a Covered Entity, You’re Not Off the Hook
Falling outside HIPAA doesn’t mean client health information has no legal protection. Several other obligations typically still apply:

  • State confidentiality law. All states independently protect the confidentiality of patient and medical records, separate from HIPAA.
  • The FTC’s Health Breach Notification Rule, which applies broadly to health apps and non-HIPAA-covered businesses handling personal health records, and has been actively enforced against consumer health platforms recently.
  • General FTC Act obligations. Privacy claims in your marketing or policies that don’t match your actual practices can be a deceptive trade practice, HIPAA status aside.
What to Do About It
  • Confirm, transaction by transaction, whether your business ever submits claims or checks eligibility electronically, including occasional courtesy submissions
  • Check your EHR, telehealth, or e-prescribing platform’s actual functionality rather than assuming based on your business model
  • Confirm EPCS compliance separately if you e-prescribe controlled substances
  • Don’t assume HIPAA’s absence means no obligation at all. State confidentiality law and the FTC’s Health Breach Notification Rule still apply
  • Review your privacy policy and marketing language to make sure any HIPAA-related claims are actually accurate
Bottom Line

Whether HIPAA applies comes down to a specific legal test, not a business model label. Many genuinely cash-pay businesses fall outside HIPAA’s covered-entity definition, but the analysis depends on the details of how the business actually handles billing, eligibility, and prescribing, and even a business that clears that bar still has other legal obligations to protect patient information.

If you’d like help analyzing your business’s HIPAA status, or want your privacy policies and vendor agreements reviewed regardless of that status, we’re happy to take a look.

This article is for general informational purposes only and does not constitute legal or tax advice. Every practice’s situation is different, and the facts of your arrangement matter. Please contact our office to discuss your specific circumstances.