# Do med spas have to follow HIPAA?

Canonical: https://prospyrmed.com/resources/practice-answers/med-spa-hipaa-applicability
Sources reviewed: 2026-09-30 · Prepared by Prospyr

Only if the practice is a HIPAA covered entity or a business associate. A health care provider is covered when it sends a standard electronic transaction, such as an insurance claim, itself or through a billing service; using email or software alone does not make it covered. A cash-pay med spa outside HIPAA still has privacy duties under the FTC Act and state laws such as Texas Chapter 181 and California's CMIA.

## What makes a practice a covered entity

HHS and CMS describe a health care provider as covered only if it transmits health information electronically in connection with a transaction HHS has adopted a standard for, such as a claim. Using a billing service or clearinghouse counts as the practice conducting the transaction. Once a practice is covered, the Privacy Rule protects its patients' identifiable health information in any form, including paper and conversations.

Source: [HHS: Covered Entities and Business Associates](https://www.hhs.gov/hipaa/for-professionals/covered-entities/index.html) — Federal HIPAA guidance; applies to covered entities and business associates
Source: [HHS: Summary of the HIPAA Privacy Rule](https://www.hhs.gov/hipaa/for-professionals/privacy/laws-regulations/index.html) — Federal HIPAA guidance summary; not a substitute for the regulation text
Source: [CMS: Are You a Covered Entity? (with Covered Entity Decision Tool)](https://www.cms.gov/regulations-and-guidance/administrative-simplification/hipaa-aca/areyouacoveredentity) — Federal administrative simplification guidance

## When a med spa that never bills insurance is still covered

A med spa can be a business associate of a covered physician practice if it handles protected health information on that practice's behalf, and people working under a covered practice's direct control are part of its workforce. In either case HIPAA duties apply even though the spa itself never files a claim. Map how the spa relates to any affiliated or supervising practice before deciding.

Source: [45 CFR 160.103: HIPAA definitions (covered entity, business associate, workforce)](https://www.ecfr.gov/current/title-45/subtitle-A/subchapter-C/part-160/subpart-A/section-160.103) — Federal regulation; check the current eCFR text
Source: [CMS: Are You a Covered Entity? (with Covered Entity Decision Tool)](https://www.cms.gov/regulations-and-guidance/administrative-simplification/hipaa-aca/areyouacoveredentity) — Federal administrative simplification guidance

## Privacy duties that apply without HIPAA

The FTC says its Act applies to companies handling health information that aren't required to comply with HIPAA, so misleading patients about their data or causing them substantial privacy harm is still prohibited. Texas Chapter 181 defines a covered entity far more broadly than HIPAA, and California's CMIA restricts disclosure of medical information by California-licensed providers whether or not they bill insurance.

Source: [FTC: Collecting, Using, or Sharing Consumer Health Information? Look to HIPAA, the FTC Act, and the Health Breach Notification Rule](https://www.ftc.gov/business-guidance/resources/collecting-using-or-sharing-consumer-health-information-look-hipaa-ftc-act-health-breach) — Federal business guidance; applies whether or not HIPAA applies
Source: [Texas Health and Safety Code Chapter 181: Medical Records Privacy](https://statutes.capitol.texas.gov/Docs/HS/htm/HS.181.htm) — Texas statute; broader covered-entity definition than HIPAA; confirm current text for recent amendments
Source: [California Civil Code §56.10: Confidentiality of Medical Information Act](https://leginfo.legislature.ca.gov/faces/codes_displaySection.xhtml?lawCode=CIV&sectionNum=56.10) — California statute; applies to California-licensed providers of health care

## Are before-and-after photos protected health information?

For a covered entity or business associate, yes when the patient can be identified: HIPAA's de-identification standard lists full face photographic images and any comparable images among the identifiers that must be removed. Marketing use needs the patient's written authorization, not only a treatment consent. A practice outside HIPAA should apply the same care under its state law.

Source: [45 CFR 164.514: De-identification standard, including full-face photographic images](https://www.ecfr.gov/current/title-45/subtitle-A/subchapter-C/part-164/subpart-E/section-164.514) — Federal regulation; applies to covered entities and business associates
Source: [HHS: Marketing under the HIPAA Privacy Rule](https://www.hhs.gov/hipaa/for-professionals/privacy/guidance/marketing/index.html) — HIPAA covered entities and business associates

## Practical checklist

1. Ask whether the practice, or any billing service acting for it, sends insurance claims or other standard transactions electronically.
2. Check whether the med spa works on behalf of, or as part of, a covered physician practice.
3. Identify the medical privacy law in your state, for example Texas Chapter 181 or California's CMIA.
4. Treat identifiable patient photos as protected and get written authorization before any marketing use.
5. Record the conclusion and the facts it rests on, and have healthcare counsel review it.

## Worked example

Illustrative scenario: a cash-pay med spa never bills insurance, but its medical director's dermatology practice submits claims electronically, and the spa's charts are kept in that practice's EMR under its direction. The spa's team may be acting as that covered practice's workforce or business associate, so HIPAA duties can apply even though the spa never files a claim.

## Mistakes to avoid

- Assuming that no insurance billing means no patient privacy obligations at all.
- Believing that using email or cloud software is what makes a practice a covered entity.
- Posting before-and-after photos because the patient signed a treatment consent.

## Related questions

- [Can a med spa post before-and-after photos with treatment consent?](https://prospyrmed.com/resources/practice-answers/patient-photo-marketing-authorization)
- [Does HIPAA require keeping every medical record for six years?](https://prospyrmed.com/resources/practice-answers/medical-record-retention)
- [Can a practice withhold patient records because a bill is unpaid?](https://prospyrmed.com/resources/practice-answers/patient-record-access)

Prepared by Prospyr from the cited primary sources. These are educational workflow resources, not individualized clinical, coding, legal or tax advice. No clinician, certified-coder or attorney review is claimed. Confirm current code instructions, payer terms and applicable law for the actual service and date. CPT is a registered trademark of the American Medical Association; this is not a substitute for a licensed current code set.