MED SPA · COMPLIANCE
Is a med spa a HIPAA covered entity?
The honest answer is “it depends on one specific thing, and your counsel decides.” Here is what that thing is, why the answer changes less than most owners expect, and what a careful intake build does either way.
This is the most important disclaimer on the site: nothing here determines your practice’s regulatory status. That determination is legal advice, it depends on facts we do not have, and it belongs to your counsel. What follows describes the question and how we build so that the answer does not require a rebuild.
THE SHORT ANSWER
The one thing it depends on
HIPAA’s definition of a covered health care provider turns on electronic standard transactions: claims, eligibility checks, payment and remittance, and the rest of the transactions the rule names. A practice that submits an electronic claim to a health plan has done one. A practice that only ever takes a card at the front desk for a cosmetic service may never have done one. That is the whole test, and it is why two med spas on the same street can have different answers.
Why the answer is less freeing than it sounds
- Florida’s patient-records statute (s. 456.057) governs the confidentiality of records held by licensed practitioners regardless of HIPAA status. A physician-supervised med spa holds records under a licensed practitioner.
- Florida’s Information Protection Act (s. 501.171) requires reasonable measures to protect personal information and notice within 30 days of a breach. It does not ask whether you are a HIPAA covered entity.
- The telemarketing statutes, federal and Florida, apply to every automated text and call the practice sends, and apply more sharply to elective services because the follow-up looks more like a sale.
- The FTC’s advertising and endorsement rules govern every result claim, before-and-after, and testimonial, and the FTC has been most active precisely in cosmetic and wellness.
- Patients assume it. A person handing over a medical history at a med spa expects it to be handled like medical information, whatever the statute says.
What the build does regardless
Because the answer can change (a practice adds a medically necessary service, joins a group, starts accepting a plan for one line), we configure every med spa the same way, and the way is the careful one. Intake forms live inside the HIPAA-enabled platform. Aday Interactive signs a BAA with the practice on every plan, whether or not the practice turns out to need one. First-touch messages carry logistics, not clinical detail. Consent to messaging is captured on its own checkbox, in the language of the form. Social messaging channels are not in the inbox. Retention on recordings and transcripts is a setting rather than a default of forever.
A practice that later learns it is a covered entity has nothing to rebuild. A practice that learns it is not has lost nothing by being careful, and has a build its patients and its counsel are comfortable with.
What the build does not do
It does not tell you what you are. The consultation call does not either. If a prospective client asks us directly whether their practice is a covered entity, the answer is that we are a technology firm, the question is a legal one, and we will build to the careful standard while their counsel answers it. That is not evasion. A CRM vendor that answers a regulatory-status question is a vendor whose answer you should not rely on.
The questions to bring to counsel
- Do we, or any entity we are part of, submit electronic claims or eligibility checks to any health plan for any service?
- Are our records held under a licensed practitioner, and what does s. 456.057 require of us?
- Which of our automated messages could be read as telephonic sales calls, and is our consent language sufficient for them?
- Do any of our marketing materials make result claims that need substantiation?
- If our status changed, what would change in our operations, and is our current setup ready for it?
The last question is the one this post is about. The answer, for a practice built the careful way, is “nothing in the intake system.”
Questions we get asked about this
What decides whether a med spa is a covered entity?
Whether it transmits health information electronically in connection with a standard transaction, which in practice means billing a health plan electronically. A cash-pay cosmetic practice that never does may not be. Your counsel decides.
If we are not a covered entity, are we free of confidentiality rules?
No. Florida's patient-records statute applies to records held by licensed practitioners, Florida's Information Protection Act requires reasonable measures and 30-day breach notice, and the telemarketing and FTC advertising rules apply to every practice.
Will TheraCRM.pro tell us our status?
No. We are a technology firm and the question is legal. We build to the careful standard while your counsel answers it.
What changes in the build if our status changes?
Nothing in the intake system. Forms inside the HIPAA-enabled platform, a BAA on every plan, logistics-only messages, and separate consent are configured for every med spa from the start.
Related
Building the careful way, before counsel has answered?
A 30-minute consultation shows the med spa configuration and the BAA. Bring your counsel’s questions; we will answer the technical half and leave the legal half to them.