Your med spa is a health care provider under HIPAA. That is not the same thing as being a HIPAA covered entity, and the gap between the two is decided by one clause about electronic transactions with payers.

Owners usually hear that as good news. It is not, for two reasons. The test turns on conduct, including conduct by vendors you hired, so a clinic can be covered without ever having filled in a claim form. And the rules that actually constrain a cash-pay clinic's marketing stack sit outside HIPAA entirely: the FTC Act, and the contracts you accepted when you installed Google's and Meta's tags. Those contracts restrict health data whether or not HIPAA reaches you.

This post walks the covered-entity test at 45 CFR 160.103, names the two documented ways a cash-pay clinic gets pulled back in, states what the FTC's Health Breach Notification Rule does and does not reach, prints the status of the HHS online tracking bulletin after the June 2024 vacatur, and quotes what Google and Meta publish on their own pages about health data in their ad tools.

Every source on this page was read on 19 August 2026. We make med spa software, so we have an obvious interest in how clinics store and route client data. The regulations and vendor terms below hold regardless of whose software you run them in. Nothing here is legal advice, and covered-entity status is a per-clinic factual question.

The covered entity test has two parts, and a cash-pay clinic often passes only the first

45 CFR 160.103 defines a covered entity as "(1) A health plan. (2) A health care clearinghouse. (3) A health care provider who transmits any health information in electronic form in connection with a transaction covered by this subchapter." A med spa is not a plan and not a clearinghouse, so everything turns on the third prong.

The first half of that prong is easy to satisfy. The same section defines a health care provider to include "any other person or organization who furnishes, bills, or is paid for health care in the normal course of business", and defines health care to include any "procedure with respect to the physical or mental condition, or functional status, of an individual or that affects the structure or function of the body". Neuromodulators, fillers, lasers and body contouring are health care under that definition. Your clinic is a health care provider.

The second half is where clinics separate. The provider also has to transmit health information in electronic form in connection with a transaction covered by the subchapter, and 45 CFR 160.103 lists twelve transaction types that are all payer-facing: health care claims or equivalent encounter information, payment and remittance advice, coordination of benefits, claim status, enrollment and disenrollment in a health plan, eligibility for a health plan, health plan premium payments, referral certification and authorization, first report of injury, claims attachments, health care electronic funds transfer and remittance advice, and others the Secretary may prescribe.

CMS states the trigger in one sentence on its "Are You a Covered Entity?" page, read on 19 August 2026: "Providers who submit HIPAA transactions, like claims, electronically are covered." Nothing on that list is set off by taking a credit card, running a booking page, storing before-and-after photos, or texting a client a reminder. So the accurate statement for many cash-pay clinics is conditional. You may not be a covered entity. Being a health care provider does not settle it. Prong three does.

Two documented ways a cash-pay clinic ends up covered anyway

The test is about conduct, and someone else's conduct can decide it for you.

45 CFR 162.923(c) provides that "A covered entity may use a business associate, including a health care clearinghouse, to conduct a transaction covered by this part." An outside billing service that submits a single electronic claim on your behalf is conducting that transaction for you. This is the sharpest practical hook in the area, because most cash-pay operators have never thought of their billing vendor as the thing that sets their regulatory status.

The second trap is the definition of electronic media in 45 CFR 160.103. Faxes and voice telephone calls sit outside that definition only "if the information being exchanged did not exist in electronic form immediately before the transmission." A claim assembled inside your chart system and then faxed is not a paper record that happened to move. It existed in electronic form immediately before it went out.

Status is per-clinic and dated. A clinic that has never billed a payer becomes a covered entity the first time it does, and one location in a group can conduct a covered transaction while another does not. CMS publishes a Covered Entity Decision Tool as a PDF linked from the same page. Run it with your billing arrangements in front of you and keep the output with the date on it.

Whichever answer you get, the record-keeping consequence is the same. Client records, treatment notes and clinical photos should sit somewhere that could satisfy HIPAA tomorrow, because status can flip on a single new insurance line. We covered where those records belong in the three ways clinics split a client platform and an EMR.

Falling outside HIPAA does not mean falling outside everything

The usual next move is to assume a clinic outside HIPAA lands automatically under the FTC's Health Breach Notification Rule. That is not what the rule says. 16 CFR 318.1(a) reads: "This part applies to foreign and domestic vendors of personal health records, PHR related entities, and third party service providers." It is not a catch-all for every provider HIPAA misses, and it carves the other direction too, stating that the part "does not apply to HIPAA-covered entities, or to any other entity to the extent that it engages in activities as a business associate of a HIPAA-covered entity."

The rule reaches a clinic only if what the clinic offers is a personal health record. 16 CFR 318.2 defines that as an electronic record that "has the technical capacity to draw information from multiple sources and that is managed, shared, and controlled by or primarily for the individual." The FTC calls the question "a fact-intensive inquiry whose outcome depends not only on the nature of the information contained in that record, but also on numerous other factors, such as its technical capacity, its source(s) of information, and its relationship to the individual." In the preamble to the 2024 final rule, the Commission's worked website examples turn on that same hinge: the same site is or is not a personal health record depending on whether it can draw from a second source, such as an API or a data broker.

The 2024 rulemaking narrowed the key definition rather than widening it. The Commission wrote that it "has substituted the word means for includes to avoid implying greater breadth than the Commission intends." The rule was published on 30 May 2024 at 89 FR 47028, Federal Register document 2024-10855, effective 29 July 2024, with the codified amendatory text beginning at 89 FR 47054. We searched the full text of that rule and its preamble on 19 August 2026 for the words booking, appointment and schedul. They appear zero times there, and zero times in the codified rule at 16 CFR part 318.

What the GoodRx case proves, and what it does not

The first company the Health Breach Notification Rule publicly reached is worth reading precisely. The FTC's press release of 1 February 2023 announced the first enforcement action under the Health Breach Notification Rule, against GoodRx, with a $1.5 million civil penalty. The stipulated order in United States v. GoodRx Holdings, Inc., No. 3:23-cv-00460-DMR (N.D. Cal.), entered 17 February 2023, states at section XII that "Judgment in the amount of $1,500,000 is entered in favor of Plaintiff against Defendant as a civil penalty", payable within seven days of entry from funds already held in escrow. Two limits matter for a med spa. The FTC pleaded GoodRx as a vendor of personal health records, a consumer product that lets users "save, track, and receive alerts about their prescriptions, refills, pricing, and medication purchase history". And the conduct ran from at least 2017 to 2020, with the order entered more than a year before the 2024 amendment took effect, so the case is not evidence of what that amendment reaches. The action was also brought under the FTC Act, including sections 5(a)(1) and 5(m)(1)(A), and the deception and unfairness authority in Section 5 is not limited to personal health records.

The two regimes side by side

The table below sets HIPAA and the Health Breach Notification Rule against each other on scope, definitions, notification and penalty ceilings.

Question

HIPAA

FTC Health Breach Notification Rule

What puts you in scope

Transmitting health information in electronic form in connection with a covered transaction, 45 CFR 160.103

Being a vendor of personal health records, a PHR related entity, or a third party service provider, 16 CFR 318.1(a)

The definition that decides it

"Transaction", twelve payer-facing types at 45 CFR 160.103

"Personal health record", 16 CFR 318.2: capacity to draw from multiple sources, and controlled by or primarily for the individual

Who is expressly out

Providers conducting none of the listed transactions electronically

HIPAA covered entities, and any entity acting as a business associate, 16 CFR 318.1(a)

Outer limit on individual notice

Outside the sources we read for this post

"Without unreasonable delay and in no case later than 60 calendar days after the discovery of a breach", 16 CFR 318.4(a)

Media and regulator notice

Outside the sources we read for this post

Media notice at 500 or more residents of one state or jurisdiction, 318.3(a)(3); FTC notice contemporaneous with individual notice at 500 or more individuals overall, 318.4(b); below that, annually within 60 calendar days of year end

Civil penalties

Tier minimums $145, $1,461, $14,602 and $73,011; maximum $73,011 per violation for the first three tiers; $2,190,294 calendar-year cap. 45 CFR 102.3, as amended 28 January 2026 by 91 FR 3666

Up to $53,088 per violation, 16 CFR 1.98(d), applying only to penalties assessed after 17 January 2025. Source note 90 FR 5581

Read the first three rows together and the point appears. The regimes are mutually exclusive by design, but the exclusivity runs one way only. Being outside HIPAA does not put you inside the Health Breach Notification Rule. There is a third territory, occupied by the FTC Act's general deception and unfairness authority and by state privacy law, and neither one turns on the covered-entity test above.

The penalty row carries a date trap. The HIPAA figures are the inflation-adjusted amounts codified at 45 CFR 102.3, amended 28 January 2026, printed there under a column heading that still reads 2025. The unadjusted statutory numbers in 45 CFR 160.404 are not current, and 160.404(a) itself points readers to part 102. The most recent codified FTC adjustment we found is 90 FR 5581 from 17 January 2025; we searched Federal Register issues from December 2025 through 19 August 2026 and found no newer FTC adjustment. Date each figure to its own source instead of calling either one the 2026 number.

The two 500s are different counts. 16 CFR 318.3(a)(3) counts 500 or more residents of a single state and triggers media notice there. 16 CFR 318.4(b) counts 500 or more individuals overall and controls when the FTC is told at the same time as the individuals. There is no ten-business-day FTC deadline in this rule; that framing comes from the HIPAA breach regime.

The HHS tracking bulletin: what a federal court vacated in June 2024

The HHS Office for Civil Rights bulletin "Use of Online Tracking Technologies by HIPAA Covered Entities and Business Associates" is quoted constantly in med spa marketing advice, and its status is routinely misstated. Everything in it is OCR's position in a sub-regulatory guidance document, not a regulation, and a federal court held part of that same document unlawful.

The banner at the top of the page, still live on 19 August 2026, says: "On June 20, 2024, the U.S. District Court for the Northern District of Texas issued an order declaring unlawful and vacating a portion of this guidance document. See Am. Hosp. Ass'n v. Becerra, No. 4:23-cv-1110, 2024 WL 3075865 (N.D. Tex. June 20, 2024). Specifically, the Court vacated the guidance to the extent it provides that HIPAA obligations are triggered in 'circumstances where an online technology connects (1) an individual's IP address with (2) a visit to a[n] [unauthenticated public webpage] addressing specific health conditions or healthcare providers.' HHS is evaluating its next steps in light of that order." The docket confirms the case as N.D. Tex. 4:23-cv-01110 before Judge Mark T. Pittman, filed 2 November 2023 and terminated 20 June 2024.

The bulletin has not been revised since. Its footer reads "Content last reviewed June 26, 2024", six days after the order, and the vacated language still sits in the body text flagged only by the banner. HHS says on that page that it is evaluating next steps, and says nothing else about the rest of the document.

The table below takes the bulletin passage by passage and records what the June 2024 order did and did not reach.

Passage in the OCR bulletin

What it says

Status after the 20 June 2024 order

User-authenticated pages

Tracking technologies there "generally have access to PHI", and the entity must configure such pages to use and disclose PHI only in compliance with the Privacy Rule

Not within the terms of the vacatur. Still in the document

IP address plus a visit to an unauthenticated page about specific conditions or providers

Treated as triggering HIPAA obligations

Vacated, in the court's words as quoted by HHS. Text remains in the body under the banner

Unauthenticated pages that let people schedule appointments

Such pages "may have access to PHI in certain circumstances", for example where the technology collects an email address or a "reason for seeking health care typed or selected by an individual"

Not within the terms of the vacatur, and the court did not rule on it either way

Appointments booked through a clinic website

Where a third party tracking technology is present, "the tracking technology vendor is a business associate, and a BAA is required"

Not within the terms of the vacatur. Still in the document

Cookie banners

Banners asking users to accept or reject tracking "do not constitute a valid HIPAA authorization"

Not within the terms of the vacatur. Still in the document

Privacy policies and terms of use

The Privacy Rule "does not permit disclosures of PHI to a tracking technology vendor based solely on a regulated entity informing individuals in its privacy policy, notice, or terms and conditions of use"

Not within the terms of the vacatur. Still in the document

Scrubbing by the tracking vendor

"It is insufficient for a tracking technology vendor to agree to remove PHI from the information it receives or de-identify the PHI before the vendor saves the information"

Not within the terms of the vacatur. Still in the document

De-identification upstream by a BAA-bound intermediary

The entity "can choose to establish a BAA with another vendor, for example a Customer Data Platform vendor", which de-identifies data containing PHI and discloses only de-identified data to vendors "unwilling to enter into a BAA"

Expressly permitted by the bulletin. Not within the terms of the vacatur

The document itself

Sub-regulatory guidance from OCR

"Content last reviewed June 26, 2024". HHS "is evaluating its next steps"

The third row is the one most often reported wrongly. The scheduling passage was not upheld by any court. It was outside the terms of what the court vacated, and it remains OCR's stated position. It also rests on a different theory from the one the court struck: what a person types into a booking form, rather than an IP address paired with the fact of a page visit.

Compare the seventh and eighth rows, because that pair is the practical answer. OCR's position is that scrubbing performed by the ad vendor after it receives the data is insufficient, while de-identification performed upstream by an intermediary that has signed a BAA with the clinic is expressly permitted. That is the difference between an architecture OCR describes as non-compliant and one it describes, in its own words, as an option.

Weigh the document accordingly. Guidance that a federal court has partly declared unlawful, and that its author has left unrevised, is thin ground for a compliance program on its own. It is also not the only thing enforcing these limits, which is the next section.

What your software has to do about tracking, whatever your HIPAA status

This is a requirements list, not a vendor verdict. Put it in your next software evaluation and make whoever is pitching answer it in writing.

  • Your booking flow has to let you keep third-party tags off any page where a client types an email address, a phone number or a reason for the visit, without stripping analytics from your marketing pages.

  • You need a documented tag inventory, page by page, rather than a developer's memory of what fires where.

  • If you want conversion data in an ad platform, you need a path that de-identifies before disclosure, run by a party that will sign a BAA with you. That is the architecture the OCR bulletin describes.

  • You need consent and disclosure records that are dated and exportable, since two of the three fixes clinics reach for first are ones OCR says do not work.

  • You need to answer, on one screen, which vendors hold client data and under what contract. The shape of that record is covered in our note on client management for med spas.

What Google and Meta publish about health data in their own tools

This is the leg of the subject that gets almost no coverage, and it binds a cash-pay clinic regardless of covered-entity status. The ad platforms restrict health data by contract, and their terms do not ask whether HIPAA applies to you. The table below quotes what each vendor publishes on its own pages, all read on 19 August 2026.

Vendor page

What the page says

What it means operationally

Google, Analytics Help, "HIPAA and Google Analytics". No revision date published; footer shows 2026 Google

"Google makes no representations that Google Analytics satisfies HIPAA requirements and does not offer Business Associate Agreements in connection with this service." Also: "Authenticated pages are likely to be HIPAA-covered and customers should not set Google Analytics tags on those pages"

An affirmative published statement, not an inferred absence. Google also flags unauthenticated pages related to the provision of health care services as more likely to be covered

Google Cloud, "HIPAA Compliance". No revision date published

Customers subject to HIPAA "must review and accept Google's Business Associate Agreement", which covers the infrastructure "and the services listed below": Google Cloud, Google Workspace, Cloud Identity, Google Workspace Migrate, Chronicle and Looker (original). "The BAA is not subject to modification"

Google Analytics, Google Ads and Tag Manager do not appear anywhere on that page. Its deeper product-list link returned a 404 when we followed it on 19 August 2026

Meta, Business Tools Terms, section 1.h. Effective 3 November 2025

Prohibits sharing data that "includes or is based on, directly or otherwise, health information, financial information, consumer report information, or other categories of sensitive information", for data the business "knows or reasonably should know" falls in those categories

The contract forbids the input. A clinic sending health-related event data through Meta business tools may be in breach of these terms independently of HIPAA

Meta for Developers, "Data Processing Options" (Limited Data Use). No revision date published; accessed 19 August 2026

"To utilize this feature, you must proactively enable Limited Data Use." The page describes LDU as supporting compliance with US state privacy regulations and lists availability by state, varying by product

LDU is off until you switch it on, and the page publishes no mention of HIPAA, protected health information or business associate agreements

The Google rows are unusual because the company makes an affirmative statement rather than leaving readers to infer one from a list. Note also that Google's Analytics page still points customers at the HHS bulletin as the reference for which pages are risky. A vendor voluntarily following partly-vacated guidance is a stronger practical constraint than the guidance's legal status suggests, because the vendor enforces it through its own terms.

The Meta rows matter more for a cash-pay clinic. The Business Tools Terms, effective 3 November 2025, prohibit sending health information through the tools at all. The business associate question never arises, because the contract forbids the input first. That prohibition applies to any business using the tools, including a clinic that is not a covered entity.

Limited Data Use is scoped by Meta to US state privacy regulations. A business associate agreement under 45 CFR 164.504(e) requires specific written assurances that a state-privacy processing flag does not purport to give, so switching LDU on is not the same act as putting a BAA in place. The read for a cash-pay med spa is that your HIPAA analysis and your ad-platform analysis are separate exercises with separate answers, and you can lose the second while winning the first. If you are choosing tools this quarter, the vendor breakdown in our comparison of med spa platforms is a reasonable place to start those questions.

When HIPAA does apply, what its marketing rule actually requires

If your clinic does conduct a covered transaction, the marketing rules go live, and they are narrower than the summaries suggest.

45 CFR 164.508(a)(3)(i) requires a covered entity to "obtain an authorization for any use or disclosure of protected health information for marketing, except if the communication is in the form of: (A) A face-to-face communication made by a covered entity to an individual; or (B) A promotional gift of nominal value provided by the covered entity." The first exception does a lot of work in aesthetics. The in-person conversation at the treatment chair, the most common med spa marketing motion there is, sits outside the authorization requirement by the express terms of the rule. Where an authorization is required and the marketing involves financial remuneration, 164.508(a)(3)(ii) requires the authorization to say so.

45 CFR 164.501 defines marketing as "a communication about a product or service that encourages recipients of the communication to purchase or use the product or service", then excludes two categories. Refill reminders and communications about a drug "currently being prescribed for the individual" are excluded, but only where any financial remuneration received is "reasonably related to the covered entity's cost of making the communication". Treatment and health care operations communications are excluded too, including describing "a health-related product or service... that is provided by, or included in a plan of benefits of, the covered entity making the communication", and that exclusion is voided by any financial remuneration.

The term financial remuneration is where most write-ups go wrong. 164.501(3) defines it as "direct or indirect payment from or on behalf of a third party whose product or service is being described", and adds that such payment "does not include any payment for treatment of an individual". A clinic promoting its own services and being paid by its own clients is not receiving financial remuneration under that definition. The term is aimed at payments from an outside manufacturer, not at your own revenue.

One trade-off is worth naming and then leaving: 47 CFR 64.1200(a)(2) conditions the TCPA health care message exemption on the caller being a "covered entity" or its "business associate" as defined in the HIPAA Privacy Rule, and 64.1200(a)(3)(v) caps exempt residential prerecorded calls at one per day per patient and three per week with opt-out honoring, so a clinic outside HIPAA cannot claim it and a clinic inside it gets a metered version. Everything else about text and call consent belongs in a post of its own.

How to check your own clinic in an afternoon

Do this in order, date each answer, and keep the file.

  1. List every party that sends anything on your behalf: billing service, EMR vendor with a billing module, superbill generator, anyone who touches a payer. Ask each in writing whether it transmits any of the twelve transactions at 45 CFR 160.103 electronically for you. One yes settles it under 45 CFR 162.923(c).

  2. Check whether any claim you fax is generated from an electronic record. If it is, the electronic media carve-out at 45 CFR 160.103 does not reach it.

  3. Run the CMS Covered Entity Decision Tool from the CMS "Are You a Covered Entity?" page and save the output with today's date.

  4. Open your booking flow in a private window and inspect which third-party tags fire on the page where a client types an email address or a reason for the visit. Compare that list against the OCR bulletin's scheduling passage and Google's Analytics Help page.

  5. Read Meta Business Tools Terms section 1.h, effective 3 November 2025, against the event data you currently send. That check is independent of your HIPAA answer.

  6. Confirm whether Limited Data Use is enabled. Meta's documentation states you must proactively enable it, so assume it is off until you have seen otherwise.

  7. Write down which vendors hold client data and under what contract. If any of them would need a BAA given your answer to step 3, get one or move the data.

  8. Redo steps 1 and 3 the first time you add an insurance line, a billing vendor or a location. Status changes on conduct, not on the calendar.

If step 7 leaves you with more vendors than you expected, that is the usual outcome, and it is a consolidation question as much as a compliance one. You can walk your own stack through with us on a Velarya demo.

Frequently asked questions

Is a cash-pay med spa covered by HIPAA?

It may not be. 45 CFR 160.103 makes a health care provider a covered entity only if it transmits health information in electronic form in connection with a transaction covered by the subchapter, and all twelve listed transactions are payer-facing. CMS states that providers who submit HIPAA transactions like claims electronically are covered. Taking card payments and running a booking page are not on that list. Status is a per-clinic factual question, it can flip the first time you bill insurance, and CMS publishes a Covered Entity Decision Tool for exactly this determination.

Can my billing company make my med spa a covered entity?

Yes, and that is the trap most operators miss. 45 CFR 162.923(c) provides that a covered entity may use a business associate, including a health care clearinghouse, to conduct a transaction covered by the part. An outside billing service that submits one electronic claim on your behalf is conducting that transaction for you. The same logic reaches a faxed claim generated from an electronic chart, because the electronic media definition at 45 CFR 160.103 excludes faxes only where the information did not exist in electronic form immediately before transmission.

Can I run the Meta pixel on my med spa booking page?

Two separate questions apply. Meta's Business Tools Terms, section 1.h, effective 3 November 2025, prohibit sharing data that includes or is based on health information or other sensitive categories, where the business knows or reasonably should know the data falls in those categories. That applies whether or not HIPAA reaches you. Separately, OCR's online tracking bulletin states that unauthenticated pages allowing appointment scheduling may have access to protected health information in certain circumstances, for example where a person types an email address or a reason for seeking care.

Does Google sign a business associate agreement for Google Analytics?

Google's Analytics Help page "HIPAA and Google Analytics", read on 19 August 2026, states that "Google makes no representations that Google Analytics satisfies HIPAA requirements and does not offer Business Associate Agreements in connection with this service." The Google Cloud HIPAA compliance page, read the same day, lists the services its BAA covers as Google Cloud, Google Workspace, Cloud Identity, Google Workspace Migrate, Chronicle and Looker (original), and states that the BAA is not subject to modification. Google Analytics, Google Ads and Tag Manager do not appear on that page.

Is the HHS tracking guidance still in effect after the 2024 court ruling?

Partly. A banner on the bulletin, live on 19 August 2026, records that on 20 June 2024 the Northern District of Texas declared unlawful and vacated the guidance to the extent it treats HIPAA obligations as triggered by connecting an IP address with a visit to an unauthenticated public webpage addressing specific health conditions or providers, in Am. Hosp. Ass'n v. Becerra, No. 4:23-cv-1110. The rest of the document remains posted, including the appointment-scheduling passages, on which the court did not rule. The page is stamped "Content last reviewed June 26, 2024".

Does a cookie banner or a privacy policy solve the tracking problem?

Not in OCR's view. The bulletin states that website banners asking users to accept or reject tracking technologies "do not constitute a valid HIPAA authorization", and that the Privacy Rule "does not permit disclosures of PHI to a tracking technology vendor based solely on a regulated entity informing individuals in its privacy policy, notice, or terms and conditions of use that it plans to make such disclosures." Both are sub-regulatory guidance rather than regulation, and they sit in a document a federal court held partly unlawful, so weigh them as the regulator's stated position.

What is the FTC Health Breach Notification Rule and does it apply to my clinic?

16 CFR 318.1(a) applies the rule to vendors of personal health records, PHR related entities and third party service providers, and expressly not to HIPAA covered entities or business associates acting as such. It is not a catch-all for providers outside HIPAA. A clinic is in scope only if it offers a personal health record, defined at 16 CFR 318.2 as a record with the technical capacity to draw information from multiple sources that is managed, shared and controlled by or primarily for the individual. The FTC calls that a fact-intensive inquiry.

Do I need a signed authorization to send a treatment recall text?

Only if you are a covered entity, and even then the rule is narrower than most summaries. 45 CFR 164.508(a)(3)(i) excepts face-to-face communications and promotional gifts of nominal value from the marketing authorization requirement. 45 CFR 164.501 excludes from marketing certain treatment and health care operations communications, including describing a health-related product or service provided by the covered entity making the communication, unless financial remuneration is involved. 164.501(3) limits financial remuneration to payment from a third party whose product is described.

Malik Masmas

CEO

Share