The short answer
Only if the practice is a HIPAA covered entity or a business associate. A health care provider is covered when it sends a standard electronic transaction, such as an insurance claim, itself or through a billing service; using email or software alone does not make it covered. A cash-pay med spa outside HIPAA still has privacy duties under the FTC Act and state laws such as Texas Chapter 181 and California's CMIA.
What makes a practice a covered entity
HHS and CMS describe a health care provider as covered only if it transmits health information electronically in connection with a transaction HHS has adopted a standard for, such as a claim. Using a billing service or clearinghouse counts as the practice conducting the transaction. Once a practice is covered, the Privacy Rule protects its patients' identifiable health information in any form, including paper and conversations.
When a med spa that never bills insurance is still covered
A med spa can be a business associate of a covered physician practice if it handles protected health information on that practice's behalf, and people working under a covered practice's direct control are part of its workforce. In either case HIPAA duties apply even though the spa itself never files a claim. Map how the spa relates to any affiliated or supervising practice before deciding.
Privacy duties that apply without HIPAA
The FTC says its Act applies to companies handling health information that aren't required to comply with HIPAA, so misleading patients about their data or causing them substantial privacy harm is still prohibited. Texas Chapter 181 defines a covered entity far more broadly than HIPAA, and California's CMIA restricts disclosure of medical information by California-licensed providers whether or not they bill insurance.
Are before-and-after photos protected health information?
For a covered entity or business associate, yes when the patient can be identified: HIPAA's de-identification standard lists full face photographic images and any comparable images among the identifiers that must be removed. Marketing use needs the patient's written authorization, not only a treatment consent. A practice outside HIPAA should apply the same care under its state law.
Your practical checklist
- Ask whether the practice, or any billing service acting for it, sends insurance claims or other standard transactions electronically.
- Check whether the med spa works on behalf of, or as part of, a covered physician practice.
- Identify the medical privacy law in your state, for example Texas Chapter 181 or California's CMIA.
- Treat identifiable patient photos as protected and get written authorization before any marketing use.
- Record the conclusion and the facts it rests on, and have healthcare counsel review it.
A worked example
Illustrative scenario: a cash-pay med spa never bills insurance, but its medical director's dermatology practice submits claims electronically, and the spa's charts are kept in that practice's EMR under its direction. The spa's team may be acting as that covered practice's workforce or business associate, so HIPAA duties can apply even though the spa never files a claim.
Illustrative workflow example; not a patient case or individualized recommendation.
Mistakes to avoid
- Assuming that no insurance billing means no patient privacy obligations at all.
- Believing that using email or cloud software is what makes a practice a covered entity.
- Posting before-and-after photos because the patient signed a treatment consent.