skip to main content

Does HIPAA Apply to MedSpas?

MedSpa owners frequently assume that because they provide medical or aesthetic services and collect health information, HIPAA automatically applies to their businesses. That assumption is understandable — but not always correct. Whether HIPAA applies depends less on the services you provide and more on how your business operates from an administrative and billing perspective.

A Primer on HIPAA

The Health Insurance Portability and Accountability Act of 1996, better known as HIPAA, establishes national standards for protecting individually identifiable health information. Its Privacy Rule governs how protected health information (PHI) may be used and disclosed, while its Security Rule requires safeguards for electronic PHI. HIPAA imposes obligations such as providing a Notice of Privacy Practices, limiting disclosures of patient information, implementing administrative and technical safeguards, and entering into business associate agreements with certain vendors.

Importantly, however, HIPAA does not apply to every business that touches health information. It applies only to “covered entities” and their “business associates.” Health care providers are covered entities only if they transmit health information electronically in connection with certain standardized administrative transactions.

Why Many MedSpas May Not Be Covered Entities

The key definition appears in 45 C.F.R. § 160.103. Under that regulation, a health care provider becomes a covered entity only if it conducts specific, covered “transactions” electronically. Those transactions generally involve standardized insurance-related exchanges, such as submitting claims, verifying eligibility, or receiving remittance advice from health plans.

Many MedSpas operate on a primarily cash-pay model and do not bill insurance. If a MedSpa does not submit electronic claims to insurers, does not conduct electronic eligibility or authorization inquiries in HIPAA-standard formats, and does not otherwise engage in those defined transactions, it may not meet the definition of a HIPAA covered entity. In that sense, a MedSpa can be similar to other cash-only medical practices that fall outside HIPAA because standardized electronic transactions are avoided altogether.

The important point is this: providing clinical services or maintaining patient charts does not, by itself, trigger HIPAA. The trigger is participation in the regulated electronic transactions defined by federal regulation.

The Practical Difficulty of Staying Outside HIPAA

While it is possible for a MedSpa to operate outside HIPAA, it is often more difficult in practice than owners expect. Some MedSpas submit insurance claims for certain services, even occasionally. Others use third-party billing companies, clearinghouses, or electronic health record systems that facilitate standardized electronic transactions. Even limited participation in those transactions can bring the entire practice within HIPAA’s scope.

Moreover, even if HIPAA technically does not apply, its privacy and security framework provides a sensible and widely recognized standard for safeguarding patient information. Implementing written privacy policies, limiting internal access to sensitive information, training staff, and securing electronic systems are prudent risk-management practices regardless of federal status. From a business perspective, patients expect confidentiality whether or not a federal rule mandates it.

Professional Rules and Other Laws Still Matter

Even if a MedSpa falls outside HIPAA’s definition of a covered entity, it is not operating in a privacy vacuum. Licensed professionals involved in MedSpa services, such as physicians, nurse practitioners, and physician assistants, are typically subject to confidentiality obligations tied to their licensure. Breaches of patient confidentiality can result in professional discipline independent of HIPAA enforcement.

In addition, state consumer protection and data privacy laws may impose obligations regarding the collection, storage, and disclosure of personal information. Many states have consumer privacy or data breach notification laws, and some states impose heightened requirements for sensitive personal data, including health-related information. These laws can apply regardless of whether a business is a HIPAA covered entity.

Finally, the FTC has adopted rules that govern certain vendors of personal health records not subject to HIPAA.  Even if a MedSpa is not subject to HIPAA or any other state privacy law, its vendors are likely subject to the FTC’s rules on notifying consumers of breaches of personal health information. 

The Bottom Line

For MedSpa owners, HIPAA is not automatic. It applies only if the business meets the regulatory definition of a covered entity, typically by engaging in standardized electronic insurance transactions. However, structuring a practice to remain outside HIPAA requires careful attention, and even then, other professional and state-law privacy obligations remain in place.

The safest approach is not to focus solely on whether HIPAA technically applies, but to ensure that patient information is handled with the level of care and security that today’s regulatory and consumer landscape demands.

If you have questions about implementing the appropriate patient privacy measures in your MedSpa, please contact Evan Sampson, Counsel in the firm’s Health Care Practice Group, at 856.301.2561 or esampson@postschell.com.

Disclaimer: This post does not offer specific legal advice, nor does it create an attorney-client relationship. You should not reach any legal conclusions based on the information contained in this post without first seeking the advice of counsel.

About the Author

Evan M. Sampson is Counsel in the firm’s Health Care Practice Group, where he advises health care providers and organizations on a broad range of regulatory, transactional, and litigation matters.

Read more >