A practice owner asks a reasonable question: “If patients pay us directly, do we still have to follow HIPAA?” The answer needs facts about the practice, not just its payment model. Direct primary care and concierge medicine describe arrangements that can operate in different ways. Neither phrase is a complete legal classification.
This guide explains how to prepare the question for review. It does not decide whether your particular business is a covered entity or business associate. Start by separating the practice's marketing description from the transactions and relationships behind the service.
What makes a provider a HIPAA covered entity?
HHS describes a HIPAA-covered healthcare provider by reference to the electronic transmission of health information in connection with transactions for which HIPAA standards have been adopted. In plain English, that generally means, if the entity interacts with insurance companies or the federal government through electronic transactions, it may be a HIPAA covered entity. The relevant inquiry is not simply whether the office uses a computer or accepts a card payment. See HHS's explanation of who must comply.
Make a list of how the practice handles claims, eligibility inquiries and other administrative transactions. Ask what outside billing services do on the practice's behalf. A provider cannot answer the question accurately by looking only at what its own receptionist submits.
Review the workflow behind “we do not take insurance”
A hypothetical practice may collect a monthly membership fee while using a separate service for occasional transactions involving a health plan. Another practice may have changed models and retained older processes. Yet another practice may have opted out of Medicare but still send prescriptions or referrals. These examples are reasons to investigate, not conclusions that either practice is automatically covered or exempt.
Bring the billing workflow, vendor descriptions and an explanation of who submits what. Identify the entity operating each part of the business. If there are multiple legal entities, do not assume one answer applies to all of them. Counsel may need to distinguish the relationships before analyzing the rules.
Useful questions include whether staff ever check benefits electronically, whether a third party transmits standard transactions for the practice, and whether the organization performs services involving protected information for another regulated organization. Record uncertain answers as uncertain; filling a gap with an assumption defeats the purpose of the review.
Covered entity and business associate are different questions
An organization may need to consider more than provider status. HHS explains that HIPAA applies to covered entities and business associates; organizations outside those definitions do not have HIPAA obligations merely because they hold health-related information. The facts of a service relationship matter. See the covered entity and business associate guidance.
Do not use a vendor's request for a signed agreement as the only evidence of your own status. Ask why the agreement is requested, which party is undertaking which work and whose information is involved. Likewise, buying a product advertised for healthcare does not itself resolve whether your practice meets a legal definition.
Keep confidentiality work moving while status is reviewed
“HIPAA does not apply” is not the same as “there are no privacy obligations.” State laws, professional duties, and contractual commitments require separate attention. This article does not compare state confidentiality laws or determine which law governs a particular encounter.
While the legal analysis is underway, use deliberate operational practices: know where records are stored, limit unnecessary access, and keep a clear route for patient questions. These are practical starting points, not a claim that adopting them satisfies every applicable rule. Avoid telling patients that their information has a particular legal protection unless the statement has been reviewed for accuracy.
A fact sheet is more useful than a yes-or-no quiz
Prepare a short description of the entity, services, payment model and administrative transactions. Add a vendor list and flag recent changes. You can use the checklist below to decide which documents to gather. It deliberately does not calculate a HIPAA status result.
Consider a new remote service before it launches. One change to the practice can change the analysis dramatically. Adding messaging, transcription or outsourced administration may introduce information flows the original review never considered. Give your advisor the actual proposed workflow rather than a product name alone. Return to the fact sheet when the business changes so an old conclusion is not silently carried into a different operation.
Where to go next
If HIPAA applies, our small practice checklist helps organize the next discussion. If a vendor will handle information for the practice, read the business associate agreement guide. Kim's existing HIPAA decision-tree resource is another starting point for questions.
Kim Cunningham is a solo practitioner at Cunningham Law, LLC, based in Beaufort and licensed in South Carolina, Georgia, and Ohio. Request a free 30-minute consultation to discuss the legal questions behind your healthcare practice. Do not put patient records or confidential details into the initial inquiry.

