The intake form at a massage studio asks about surgeries, medications, pregnancy, and pain. The acupuncturist's chart records a diagnosis in two medical vocabularies. Both practices hold information that would be protected health information in a doctor's office. Whether it is protected health information here depends on a question neither form asks: how does the practice get paid?
This article walks through the HIPAA covered-entity test as it applies to massage therapists and acupuncturists, gives the answer for the cash-only practice most of them run, explains the situations that pull a bodywork practice under HIPAA, and covers the state confidentiality and licensing duties that apply regardless. None of the settlement titles on the OCR (HHS Office for Civil Rights) enforcement list name a massage or acupuncture practice, which is consistent with most of them sitting outside the test. It is not a reason to skip the analysis.
Does HIPAA Apply to Massage Therapists: The Three-Part Test
Part one: is it health care? 45 CFR 160.103 defines health care as "care, services, or supplies related to the health of an individual," including "preventive, diagnostic, therapeutic, rehabilitative, maintenance, or palliative care, and counseling, service, assessment, or procedure with respect to the physical or mental condition, or functional status, of an individual or that affects the structure or function of the body." Therapeutic massage and acupuncture fit that language without strain. A purely cosmetic or relaxation service is a closer call, but the definition is broad and most practices offer at least some therapeutic work.
Part two: is the practitioner a health care provider? The same section defines a health care provider to include "any other person or organization who furnishes, bills, or is paid for health care in the normal course of business." A licensed massage therapist or acupuncturist who is paid for the services above is a health care provider under HIPAA's definition. That surprises people, and it is only the second step.
Part three: does the practice transmit a standard transaction electronically? A health care provider is a covered entity only if it "transmits any health information in electronic form in connection with a transaction covered by this subchapter." The transaction definition lists "health care claims or equivalent encounter information," "eligibility for a health plan," "health care claim status," and similar exchanges with health plans. This is the step that decides it. A practice that never sends a claim or an eligibility inquiry to a health plan electronically is not a covered entity, no matter how much health information sits in its filing cabinet.
The Cash-Only Practice: Not a Covered Entity
Most massage practices, and many acupuncture practices, are paid directly by the client. Medicare does not cover massage therapy at all; the federal Medicare coverage page says so in one sentence. For those practices, HIPAA's Privacy Rule, Security Rule, and Breach Notification Rule do not apply. A client's intake form is confidential under state law and professional ethics, but it is not P.H.I. (Protected Health Information) in the federal sense, and the practice does not need a Notice of Privacy Practices, a HIPAA risk analysis, or business associate agreements.
Handing a client a receipt or a superbill to submit to their own insurer does not change the answer. The client is transmitting, not the practice. Accepting a health savings account card or a flexible spending card is a payment, not a claim.
What Pulls a Bodywork Practice Under HIPAA
| Situation | Covered entity? | Why |
|---|---|---|
| Cash, card, HSA, or FSA payment; client files own claims | No | No electronic transaction by the practice |
| Acupuncturist bills private health plans electronically, directly or through a billing service | Yes | Electronic claims are the core standard transaction |
| Practice runs online eligibility checks before booking | Yes | An eligibility inquiry is a standard transaction on its own |
| Acupuncture furnished inside a physician practice that bills Medicare | The physician practice is; the acupuncturist is its workforce | Medicare pays for acupuncture only through physicians and certain other practitioners, and cannot pay licensed acupuncturists directly |
| Massage therapist employed by a chiropractic or physical therapy clinic that bills electronically | The clinic is; the therapist is its workforce | Workforce members follow the clinic's HIPAA policies |
| Practice bills auto insurers or workers' compensation carriers only | A different question | Those payers are generally not health plans under 160.103; ask counsel |
| Practice contracts with a hospital or health plan wellness program and receives member information | Not a covered entity, but possibly a business associate | A B.A.A. (Business Associate Agreement) may be required, and the Security Rule then applies to that work |
The Medicare row deserves a note, because acupuncture is where this question gets real. Medicare Part B covers acupuncture, including dry needling, for chronic low back pain, up to 12 treatments in 90 days and a maximum of 20 in a 12-month period, but only when furnished by a physician or another qualifying provider such as a nurse practitioner or physician assistant who holds the required acupuncture degree and license. Medicare cannot pay a licensed acupuncturist directly. An acupuncturist working under that arrangement is inside a covered entity's workforce and follows its program. An acupuncturist billing commercial plans electronically from an independent practice is a covered entity in the acupuncturist's own name. The covered entity guide covers the same test for other provider types.
Once HIPAA Applies
A covered acupuncture or massage practice owes the same program as any other small covered provider, scaled under 164.306(b)(2) to "the size, complexity, and capabilities of the covered entity." The list is not long:
- A named privacy official and security official under 164.530(a)(1) and 164.308(a)(2), usually the owner.
- A risk analysis under 164.308(a)(1)(ii)(A) covering the scheduling and charting software, the tablet at the front desk, the phone, and the billing path. The risk assessment guide covers the method.
- Short written policies, training documented for everyone who works there, and a sanction policy.
- A Notice of Privacy Practices under 164.520, handed out at the first visit and posted on the website.
- Business associate agreements with the practice management software, the billing service, the cloud email, and any online intake form vendor. The BAA guide lists the required terms.
- Encrypted devices, unique logins, and a tested backup.
- Six years of documentation retention under 164.316(b)(2)(i) and 164.530(j)(2).
One trap is specific to this setting: online intake forms. A massage practice that collects health history through a web form is holding health information in a vendor's cloud. If the practice is a covered entity, that vendor is a business associate and needs a BAA, and many consumer form builders will not sign one. The website compliance guide explains what to check.
One more note for covered practices: HHS published a proposed Security Rule overhaul in January 2025 that would make encryption and multifactor authentication required rather than Addressable. It has not been finalized and is not in force. Turning both on now is the reasonable answer under the current rule anyway.
Duties That Apply Whether or Not HIPAA Does
Not being a covered entity means HIPAA does not apply. It does not mean confidentiality is optional. A massage or acupuncture practice should expect all of the following, and confirm the specifics with counsel or the state licensing board:
- Licensing law and board rules. Massage therapy and acupuncture are licensed professions in most states, and licensing statutes and board rules typically include client confidentiality and record-keeping duties enforced through the license.
- State consumer privacy and data breach laws. These apply to any business that holds personal information. A stolen tablet full of intake forms and card numbers triggers state notification duties, covered entity or not.
- Professional ethics codes. The codes adopted by the professional associations and, in many states, written into board rules cover confidentiality and informed consent.
- Contract duties. A B.A.A. signed with a covered client, or a confidentiality clause in a wellness program contract, is enforceable on its own terms.
- Ordinary negligence. Careless handling of a client's health history can support a claim regardless of any statute.
The state privacy laws guide covers how those overlays relate to the federal rule. 160.203(b) keeps any state law that is "more stringent" about privacy in force even where HIPAA applies.
A Practical Way to Decide
- List every way money comes in. For each payer that is a health plan, ask whether any claim, eligibility check, or claim-status inquiry goes out electronically, by the practice or by anyone acting for it.
- If the answer is yes for any payer, the practice is a covered entity for all clients. Build the short program above.
- If the answer is no, write down that conclusion and the date, keep client records confidential under state law and the ethics code, and revisit the question the day the practice signs up with a billing service or a network that bills electronically.
- If a hospital, clinic, or health plan asks the practice to sign a business associate agreement, read it before signing, because it brings the Security Rule with it.
---
FAQ
Is a massage therapist a covered entity under HIPAA?
Usually not. A massage therapist is a health care provider under the 45 CFR 160.103 definitions, but becomes a covered entity only by transmitting a standard transaction, such as a claim or an eligibility check, to a health plan electronically. A cash-pay practice does not.
Does accepting HSA or FSA cards make a practice a covered entity?
No. Taking a health savings account or flexible spending account card is a payment, not a health care claim or eligibility inquiry sent to a health plan. The client, not the practice, deals with the plan.
Does HIPAA apply to acupuncturists who bill insurance?
Yes, if the claims or eligibility checks go to the health plan electronically, whether the acupuncturist sends them or a billing service does. Once covered, the practice owes the full Privacy, Security, and Breach Notification Rule program for every client, cash-pay clients included.
Does a cash-only practice need a HIPAA privacy notice or business associate agreements?
No. Those are HIPAA requirements, and HIPAA does not apply to a practice that is not a covered entity. State licensing rules, state privacy and breach laws, and the profession's ethics code still require confidentiality.
What if a clinic or hospital asks a massage therapist to sign a business associate agreement?
Read it before signing. A business associate agreement makes the HIPAA Security Rule apply directly to the work performed under it, including a risk analysis and safeguards for any protected health information received. It may be appropriate; it should not be signed as a formality.
Conclusion
A massage or acupuncture practice that has crossed into covered-entity territory needs a program sized to a small practice, not a hospital: a short risk analysis, a few policies, and B.A.A.s with the software that holds the intake forms. One Guy Consulting's Full-Scope plan covers all of it. Start with a free 30-minute compliance review. No obligation, no pressure.
Sources
- 45 CFR 160.103 (definitions: health care, health care provider, covered entity, transaction, health plan)
- 45 CFR 160.203 (preemption: more stringent state law)
- 45 CFR 164.306 (security standards: general rules)
- 45 CFR 164.308 (administrative safeguards)
- Medicare.gov: Acupuncture coverage
- Medicare.gov: Massage therapy coverage
- CMS: Are You a Covered Entity?
- HHS OCR resolution agreements and civil money penalties
Related Reading