Is Square HIPAA Compliant? Only Part of Square Sits Inside the BAA

Practical guidance for healthcare teams and business associates

A business associate does not have to be a hospital-sized company to earn a hospital-sized penalty. In June 2016, OCR announced a $650,000 settlement with a business associate over its failure to safeguard nursing home residents' P.H.I. (Protected Health Information). The vendor was not the covered entity. It held the data, and that was enough.

That is the frame for the question. Is Square HIPAA compliant? Partly, and by design. Square (legally Block, Inc.) publishes a HIPAA Business Associate Agreement, last updated March 16, 2026, that is "incorporated into the terms governing your use of Square's services." The BAA applies "only to the Services and configurations where Square is acting as your Business Associate, including when you use Square Appointments, Invoices, or other features that have been explicitly identified as HIPAA-enabled by Square." It also says, in the same paragraph, that "Not all Services are HIPAA-enabled." So the answer is yes for the covered features, no for the rest, and the practice is responsible for knowing which is which. This guide walks the BAA's scope, its exclusions, and a setup list.

Is Square HIPAA Compliant? What the BAA Covers and Excludes

Does Square Sign a BAA?

Yes, in an unusual form. Square's B.A.A. (Business Associate Agreement) is a published legal page rather than a document you request, and it is incorporated into the general terms for sellers. The page does not describe a signature or acceptance step, and it does not tie coverage to a paid subscription tier. What it does is define "Services" narrowly as "only those Square products, features, or configurations used by you in connection with your provision of health care services," and then narrow again to the HIPAA-enabled ones.

That structure matches what HIPAA requires of the contract itself. 45 CFR 164.504(e)(2)(i) says a business associate contract must "establish the permitted and required uses and disclosures of protected health information by the business associate." Square's version does that by listing what Square may do (perform the Services, use PHI for its own "proper management and administration," create de-identified data under 164.514(b), provide data aggregation) and by committing to the safeguards, breach reporting under 164.410, subcontractor flow-down, and return-or-destroy terms that 164.504(e)(2)(ii) requires. On paper, it is a proper BAA. The full checklist for judging one is in the business associate agreement guide.

Which Square Features Are Inside the BAA?

Square names two features by name and leaves the door open for more.

Square featureInside the BAA?What the BAA says
Square AppointmentsYes, when configured for health care useNamed explicitly as a Service where Square acts as your business associate
Square InvoicesYes, when configured for health care useNamed explicitly
Other "HIPAA-enabled" featuresOnly if Square has identified them as such"Square may, but is not obligated to, identify particular products or configurations as HIPAA-enabled"
Square Buyer Services (Square Go, Square Profile, Square Pay, Square Local Offers)No"Designed for consumers and are not operated by Square on behalf of Covered Entity Sellers"; data is processed "as an independent controller, not as a Business Associate"
Everything elseNo, unless identified"You are responsible for evaluating whether a particular Service or configuration is appropriate for your use with PHI"

The Buyer Services exclusion deserves a second read. When a patient books through Square Go or pays through Square Pay, Square says the booking data, payment information, transaction history, and preferences it collects from that patient are outside the BAA entirely, and "use of Square Buyer Services by your customers does not create a Business Associate relationship." The patient-facing side of Square is a consumer product that happens to be attached to your account.

What the Square BAA Puts on You

Section 4 of the BAA is the part practices do not read. Two lines matter most.

On encryption: "To the extent that you choose to use the Services to transmit PHI without encryption, you are responsible for documenting under the Security Rule that encryption is not reasonable and appropriate for such communications and implementing any equivalent alternative measures if reasonable and appropriate." That is Square restating 45 CFR 164.306(d)(3) back at you. Encryption in transit is an Addressable specification at 164.312(e)(2)(ii), and Addressable means implement or document why not, as the HIPAA encryption guide explains. If you text an invoice with a clinical line item to a patient, the documentation burden is yours.

On scope: "You are solely responsible for determining whether and how you use Square Services in connection with PHI, including features that collect Square Buyer Data and any services enabling communication with your customers." Square Messages, marketing tools, receipts, and the customer directory are "services enabling communication." The BAA does not bless them; it hands them to you.

Payments, Receipts, and the Section 1179 Carve-Out

Square's BAA defines PHI to exclude "any information exempt from HIPAA under Section 1179 of the Social Security Act." That statutory section addresses certain payment-processing activities by financial institutions. Whether a given card transaction falls inside it is a legal question for counsel, not a setting in a dashboard, and the safe operating assumption for a small practice is simpler: the card swipe is one thing, and what you type around it is another. A receipt that reads "Consultation" carries a name and a date of service. A receipt that reads "Suboxone induction, week 2" carries a diagnosis. The minimum necessary rule applies to every free-text field Square offers.

How to Set Up Square for HIPAA

  1. Save the BAA. Print the Square HIPAA BAA page to PDF with the date and the "last updated" line visible, and file it in your vendor register. Because it is incorporated into the terms rather than signed, your evidence that it applies is your account plus that dated copy.
  2. Inventory which Square features touch PHI. Appointments, Invoices, Customer Directory notes, Messages, Marketing, receipts, and any third-party app from the Square App Marketplace. Mark each one as inside the BAA, outside the BAA, or unknown.
  3. Neutralize service names and line items. Public booking pages and receipts should describe a service category, not a condition. "60-minute session" instead of a diagnosis. This is the single highest-value change.
  4. Keep clinical notes out of Square. The customer directory note field is not a chart. Clinical detail belongs in the EHR, which has its own BAA and its own audit trail.
  5. Decide about patient messaging. Square's own BAA says communication features are your call. Appointment reminders are generally fine; treatment content by text is not. The texting rules apply here unchanged.
  6. Check marketing against 164.508. 45 CFR 164.508(a)(3)(i) says "a covered entity must obtain an authorization for any use or disclosure of protected health information for marketing," with narrow exceptions. Segmenting a Square Marketing campaign by the services a patient bought is a marketing use of PHI.
  7. One login per person. 45 CFR 164.312(a)(2)(i) requires a "unique name and/or number for identifying and tracking user identity." Use Square's team permissions so the front desk cannot see everything the owner can.
  8. Add Square to the risk analysis. 45 CFR 164.308(a)(1)(ii)(A) requires an "accurate and thorough assessment" of risks to ePHI the practice holds. A scheduling and invoicing system holds ePHI.
  9. Train the front desk. The person who types the reason for the visit into the appointment note is the control that matters. The front desk rules cover the rest of that job.

Common Square HIPAA Mistakes

Assuming "Square has a BAA" means all of Square is covered. The BAA says the opposite twice.

Diagnosis in the line item. Itemized invoices that read like a superbill go to patients by email and text, and to anyone who sees the patient's phone.

Marketplace apps. A third-party app connected to Square that reads appointment data is a separate business associate with its own BAA, or a separate problem.

Alternatives to Square for Practice Payments

OptionBAAFitWatch out for
Square (Appointments, Invoices, HIPAA-enabled features)Published, incorporated into termsCash-pay and small practices that want scheduling and payments in one placeBuyer Services and communication features are outside the BAA
StripeNot offered on any public Stripe page found; Stripe's Services Agreement tells users not to provide PHI as third-party dataDeveloper-built payment flowsKeep every field free of PHI
EHR or practice-management paymentsUsually inside the EHR vendor's BAAPractices whose EHR offers integrated card processingConfirm the payment module is within the existing BAA's scope
QuickBooks PaymentsNo, per the QuickBooks HIPAA analysisBookkeeping, not patient recordsInvoice detail

Square is a reasonable choice for a practice that reads its BAA and builds around it. The features Square names are covered. The features it does not name are yours to justify, and the fastest way to keep that justification short is to keep clinical detail out of every Square field that a patient, a marketer, or a marketplace app can see.

---

FAQ

Does Square have a HIPAA Business Associate Agreement?

Yes. Square publishes a HIPAA BAA (last updated March 16, 2026) that is incorporated into its seller terms. It applies only to Services where Square acts as your business associate, which Square says includes Square Appointments, Invoices, and features Square has identified as HIPAA-enabled.

Which parts of Square are not covered by the BAA?

Square Buyer Services (Square Go, Square Profile, Square Pay, Square Local Offers) are excluded; Square processes that data as an independent controller. Any feature Square has not identified as HIPAA-enabled is also outside the BAA, and Square says you are responsible for evaluating it.

Do I need a paid Square plan to be covered by the BAA?

The Square BAA page does not condition coverage on a subscription tier. It conditions coverage on using the named or HIPAA-enabled Services for health care. Confirm with Square whether your specific configuration is HIPAA-enabled.

Can I put the reason for the visit in a Square appointment or invoice?

Every free-text field in Square is PHI once it names a patient and a condition. The safer practice is a neutral service description on anything a patient sees, with clinical detail kept in the EHR.

Is Square Messages or Square Marketing HIPAA compliant?

Square's BAA says you are solely responsible for services enabling communication with your customers. Marketing that uses PHI requires a patient authorization under 45 CFR 164.508(a)(3), and treatment content by text carries its own risks.

Conclusion

Payments, scheduling, and invoicing are where PHI quietly leaks in a small practice, because nobody thinks of the card terminal as a medical system. One Guy Consulting's Full-Scope plan includes vendor and BAA management, the policy templates, and consulting time to map every Square feature your office uses against the BAA's scope. Start with a free 30-minute compliance review. No obligation, no pressure.

Sources


Related Reading