CUNNINGHAM LAW · WEBSITE PREVIEW FOR REVIEW
Healthcare resources

Cunningham Law · Healthcare

Does HIPAA Apply to Your DPC or Cash-Pay Practice?

Does HIPAA apply to a DPC or cash-pay practice? Understand the key questions about transactions and vendors before discussing your practice with Kim Cunningham.

Empty examination room with a treatment chair and diagnostic equipment; generated editorial image

A practical starting point

The label “cash-pay,” “concierge” or “DPC” does not decide HIPAA status. Examine electronic standard transactions and business associate roles, then consider other confidentiality duties separately.

A practice owner asks a reasonable question: “If patients pay us directly, do we still have to follow HIPAA?” The answer needs facts about the practice, not just its payment model. Direct primary care and concierge medicine describe arrangements that can operate in different ways. Neither phrase is a complete legal classification.

This guide explains how to prepare the question for review. It does not decide whether your particular business is a covered entity or business associate. Start by separating the practice's marketing description from the transactions and relationships behind the service.

What makes a provider a HIPAA covered entity?

HHS describes a HIPAA-covered healthcare provider by reference to the electronic transmission of health information in connection with transactions for which HIPAA standards have been adopted. In plain English, that generally means, if the entity interacts with insurance companies or the federal government through electronic transactions, it may be a HIPAA covered entity. The relevant inquiry is not simply whether the office uses a computer or accepts a card payment. See HHS's explanation of who must comply.

Make a list of how the practice handles claims, eligibility inquiries and other administrative transactions. Ask what outside billing services do on the practice's behalf. A provider cannot answer the question accurately by looking only at what its own receptionist submits.

Review the workflow behind “we do not take insurance”

A hypothetical practice may collect a monthly membership fee while using a separate service for occasional transactions involving a health plan. Another practice may have changed models and retained older processes. Yet another practice may have opted out of Medicare but still send prescriptions or referrals. These examples are reasons to investigate, not conclusions that either practice is automatically covered or exempt.

Bring the billing workflow, vendor descriptions and an explanation of who submits what. Identify the entity operating each part of the business. If there are multiple legal entities, do not assume one answer applies to all of them. Counsel may need to distinguish the relationships before analyzing the rules.

Useful questions include whether staff ever check benefits electronically, whether a third party transmits standard transactions for the practice, and whether the organization performs services involving protected information for another regulated organization. Record uncertain answers as uncertain; filling a gap with an assumption defeats the purpose of the review.

Covered entity and business associate are different questions

An organization may need to consider more than provider status. HHS explains that HIPAA applies to covered entities and business associates; organizations outside those definitions do not have HIPAA obligations merely because they hold health-related information. The facts of a service relationship matter. See the covered entity and business associate guidance.

Do not use a vendor's request for a signed agreement as the only evidence of your own status. Ask why the agreement is requested, which party is undertaking which work and whose information is involved. Likewise, buying a product advertised for healthcare does not itself resolve whether your practice meets a legal definition.

Keep confidentiality work moving while status is reviewed

“HIPAA does not apply” is not the same as “there are no privacy obligations.” State laws, professional duties, and contractual commitments require separate attention. This article does not compare state confidentiality laws or determine which law governs a particular encounter.

While the legal analysis is underway, use deliberate operational practices: know where records are stored, limit unnecessary access, and keep a clear route for patient questions. These are practical starting points, not a claim that adopting them satisfies every applicable rule. Avoid telling patients that their information has a particular legal protection unless the statement has been reviewed for accuracy.

A fact sheet is more useful than a yes-or-no quiz

Prepare a short description of the entity, services, payment model and administrative transactions. Add a vendor list and flag recent changes. You can use the checklist below to decide which documents to gather. It deliberately does not calculate a HIPAA status result.

Consider a new remote service before it launches. One change to the practice can change the analysis dramatically. Adding messaging, transcription or outsourced administration may introduce information flows the original review never considered. Give your advisor the actual proposed workflow rather than a product name alone. Return to the fact sheet when the business changes so an old conclusion is not silently carried into a different operation.

Where to go next

If HIPAA applies, our small practice checklist helps organize the next discussion. If a vendor will handle information for the practice, read the business associate agreement guide. Kim's existing HIPAA decision-tree resource is another starting point for questions.

Kim Cunningham is a solo practitioner at Cunningham Law, LLC, based in Beaufort and licensed in South Carolina, Georgia, and Ohio. Request a free 30-minute consultation to discuss the legal questions behind your healthcare practice. Do not put patient records or confidential details into the initial inquiry.

Your review checklist

Select the items you want to discuss. This creates a planning agenda, not a compliance score or legal determination. Your selections stay on this page and are not submitted.

0 items selected

Common questions

Does accepting a credit card make a practice HIPAA covered?

A payment method alone does not answer the HIPAA covered entity question. Identify the actual transactions and applicable definitions.

Can a DPC practice simply opt out of HIPAA?

A practice label or preference does not replace the legal definitions. Whether the rules apply depends on the organization’s activities and relationships.

Sources and further reading

General educational information, not legal advice. Application depends on the facts and governing law.

Talk through your practice’s questions.

Kim Cunningham of Cunningham Law offers a free 30-minute consultation. Share a general description of your question so Kim can arrange the next step.

Request a free consultation