Quick Answer
Usually, yes. A card processor that only authorizes, clears and settles payments falls under HIPAA's §1179 financial-institution exemption, so it needs no BAA while clinical details stay out of the charge.
Secureframe noted in 2023 that HIPAA "does not generally apply to banking and financial institutions," even though the federal business associate definition mentions financial services. The payment record is where compliance is won or lost. Tokenize the card and leave diagnoses, notes and treatment names out of every payment field.
Key Points
- HHS's 2013 Omnibus Rule preamble said HIPAA's business associate provisions do not apply to financial institutions doing Section 1179 payment processing, so payment-only card processors need no BAA.
- Processors that go "above and beyond" payment processing, such as receivables work, can become business associates, and Vorys warned in 2024 this applies without a signed agreement.
- Keep checkout to card data and a patient or account ID, since a 2025 r/PrivatePracticeDocs commenter said payment processors "should handle cards and nothing clinical."
Card data on one side, clinical records on the other: the separation that keeps a processor inside the HIPAA bank exemption.
Ask whether your card processor needs a BAA and you will often hear yes, by reflex. That reflex can hide the card security standard that binds you either way: PCI DSS, which a 2025 compliance explainer said applies to "any business processing credit card payments." The HIPAA Journal's Steve Alder drew the split cleanly in 2023: a payment-only service is HIPAA compliant by default under Section 1179, while whether you should offer it to patients is "a different matter."
A quick aside. I'd like to tell you what share of telehealth merchants already run card flows with nothing clinical in them. That figure isn't on record anywhere I can point to. So what follows reasons from the rules, and from the practitioners still arguing over them.
The conventional wisdom for telehealth operators is simple: get a BAA from every vendor, your card processor included. For card-only payment flows, I think that advice gets the law backwards. Under federal guidance, a processor running consumer card transactions is providing its normal financial services to its own customers, not performing a function on behalf of the covered entity.
The caution is understandable. The 2013 Omnibus Rule, published in the Federal Register, made business associates directly liable and set a compliance date of September 23, 2013, so nobody wants to guess wrong. Still, dropping a patient's name from a charge does not de-identify it: on a 2023 Holland & Knight podcast, Shannon Hartsfield explained that HIPAA's de-identification safe harbor requires removing 18 specific identifiers.
What Does the HIPAA Bank Exemption Actually Cover?
Section 1179 exempts the work of moving money for care: authorizing, processing, clearing, settling, billing, transferring, reconciling and collecting payments made by card, account or electronic funds transfer.
Before you ask a processor for a BAA, answer three questions about your own payment flow:
- Does the processor only authorize, settle and collect the payment?
- Does clinical detail ride along with the transaction?
- Does the processor do work for you beyond moving money?
Yes, no and no puts most card flows inside the exemption. HIPAA applies only when the data is protected health information and the holder is a covered entity or business associate. A processor that just runs the charge fails that second test. Getting paid is also a purpose the Privacy Rule already permits without patient authorization, alongside treatment and healthcare operations.
Federal regulators said so in 2013. The Omnibus Rule, which took effect March 26, 2013, carried HHS's statement (78 Fed. Reg. 5566, 5575) that the "HIPAA Rules, including the business associate provisions, do not apply to banking and financial institutions with respect to the payment processing activities defined in §1179 of the HIPAA statute." Physicians Practice put the takeaway plainly that year: "the activity determines the relationship and the requirements that need to be met."
The common assumption is that every processor touching a patient payment needs a BAA. An analysis of 5 sources shows the opposite: the exemption follows the activity, not the vendor. Our underwriting team made a parallel point in September 2026, noting that a processor prices the shape of a transaction rather than the label on the business, which is also what high-risk underwriters actually need documented before approval.
In practice, a plain card charge for a telehealth visit sits inside the exemption. I'd treat that as the baseline. The harder question is what happens once a processor starts doing more than moving money.
When Does a Card Processor Become a Business Associate?
A processor crosses the line when it works your receivables, runs lockbox services or sends patient-facing invoices and receipts on your behalf.
The HIPAA Journal points to the limit HHS set in the same Omnibus preamble: an institution may become a business associate when it performs "functions above and beyond the payment processing activities," with accounts receivable work as the example. Here is how common services sort out:
| Activity | Inside §1179? | BAA needed? |
|---|---|---|
| Authorizing, settling and collecting a card payment | Yes | No |
| Sending invoices or receipts to patients | No | Yes |
| Emailing or texting patients on your behalf | No | Yes |
| Receivables work: payment schedules, late-balance letters, address tracing | No | Yes |
| Lockbox services | No | Very likely |
Person Centered Tech drew the same line for clinicians in 2014, summed up as "you can collect credit card payments with Square, but do not use it to send receipts." When you sort a new feature, ask who the patient hears from: a line on a card statement comes from the card network, while a message sent in your practice's name is work done for you. As of 2024, legal analysis held that business associate status exists as a matter of law, even without a signed agreement, with civil penalties reaching up to $2 million per violation. A BAA is a contract, not a cure.
Think of a courier. Carrying a sealed envelope is delivery; opening it, sorting the contents and replying on your letterhead is another job entirely.
Even the strictest reading leaves the card charge alone. Privacy advocates told federal advisors in 2004 that Congress meant the exemption for consumer card and debit transactions, and their quarrel was with banks doing more than that. My advice is to price any bundled billing add-on separately against what a high-risk merchant account should cost, because the add-on, not the card rail, is what pulls you into BAA territory. Which leaves the practical question of building a checkout that keeps the processor in its lane.
If your card processor won't sign a BAA, are you breaking HIPAA?
Search clinicians' forums for whether a card processor needs a business associate agreement and you find two confident, opposite answers. Federal guidance backs one of them, with a catch that matters.
In October 2023, someone setting up a private practice asked a Reddit forum for therapists which card processor to pair with an online intake form. The replies split. "Yes, you need something HIPAA compliant," one commenter wrote. Another wrote: "HIPAA rules do not apply to financial transactions with respect to payment processing."
Part of the confusion comes from treating two rulebooks as one. A 2026 security certification prep course put the difference plainly: "The pressure is real but it flows from a contract not from a law." A processor's PCI status tells you how it protects card numbers, and nothing about HIPAA.
| HIPAA | PCI DSS | |
|---|---|---|
| Where its authority comes from | Federal statute, enacted August 21, 1996 | Contract standard created by the major card brands |
| Who enforces it | The HHS Office for Civil Rights | Banks and card brands, through contracts that can bring fines or cut off card processing |
| What it protects | Health information held by covered entities and their business associates | Card numbers and related payment data |
| What decides whether it reaches your processor | The work the processor does for you | The terms in your card-acceptance agreement |
HIPAA's own answer starts in Section 1179, which exempts payment work done "by any means, including a credit, debit, or other payment card." In the preamble to its 2013 Omnibus Rule, HHS confirmed that HIPAA's rules, "including the business associate provisions, do not apply to banking and financial institutions" doing that work. It added that no BAA is needed with an institution "solely conducting payment activities" of that kind. A 2013 analysis in Physicians Practice summed it up: "the activity determines the relationship and the requirements that need to be met."
So the second commenter was closer to right, but the reason is less comfortable than many people assume. Roy Huggins, who runs HIPAA risk analyses for clinicians, wrote that identifying details combined with a payment for health care count as protected health information. Health care attorney Marcia Augsburger noted that experts have estimated 40% of the information in most bank lockbox accounts meets that definition. Your processor does see protected data. Augsburger reported OCR's view that an institution's HIPAA duties turn on what it does with information rather than on what it receives, and that is why the processor stays exempt.
A plain card charge also sits on the firmest ground in the exemption. In 2004 testimony to a federal advisory committee, Anna Slomovic of the privacy group EPIC cited a conference report saying Congress intended to apply Section 1179 "only to consumer-oriented payment transactions, such as credit or debit card transactions." The banking industry's HIPAA task force wanted HHS to treat all "activities of a financial institution" as exempt. Both readings include an ordinary card charge. The argument was about the edges, and a decade later Huggins still described the "billing" part of the exemption as "somewhat mysterious."
Once a processor goes "above and beyond" payment processing, in HHS's words, the paperwork stops deciding anything. Vorys, a law firm that advises financial institutions, warned in 2024 that "many financial institutions wrongly believe that all banking activities are excluded from HIPAA."
"Business associates are subject to HIPAA as a matter of law, meaning that business associate status exists even in the absence of the financial institution or covered entity even recognizing it and in the absence of a required business associate agreement."
Vorys, client alert on financial institutions and HIPAA, 2024
Huggins spelled out what that means for the provider: "If you don't acquire a Business Associate contract from the banking institution before they perform a non-exempt service, you will be in violation of HIPAA." He put processor invoicing tools in that category. He also wrote that having a service email or text your clients for you creates the relationship, even when the clients consent.
So the forum question has two answers. For the charge itself, a processor that declines to sign a BAA is doing what the law expects. For the receipt it emails afterward, the payment plan it runs or the overdue reminder it texts, that same refusal can leave you out of compliance on a service you barely notice. The answer to the BAA question is in the list of services you have switched on. We process card payments ourselves, so we have a stake in this reading.
Five reviews to run on your processor
- List every service the processor performs beyond authorizing and settling the charge: emailed or texted receipts, invoices, payment plans, past-due notices, lockbox or receivables work.
- For each item, ask whether the processor will sign a BAA covering it. If not, move that task to a platform that will, such as a practice management system that signs BAAs.
- Treat a PCI DSS attestation and a BAA as answers to two different questions.
- Repeat the review whenever you switch on a new feature or the processor changes its services.
- If the processor does anything resembling billing-office work, ask your counsel where Section 1179's "billing" ends, since HIPAA specialists still describe that boundary as unclear.
How we checked this
We read the primary HHS rule text and the statute, then compared them with a law firm alert, a trade journal analysis, an article by a clinician compliance consultant, 2004 testimony from a privacy group, a certification prep course and a peer forum thread. None of the figures here come from Seamless Chex. Forum comments are anonymous opinions and show only that confusion exists. The Person Centered Tech article dates from 2014 and was last updated in 2016. The 40% lockbox estimate is secondhand and credited to unnamed experts. We are a card processor, and Vorys advises financial institutions, so both of us have a stake in how the exemption is read. Still unknown: our sources include no enforcement case showing exactly where "billing" ends or how OCR treats a specific processor add-on. None of this is legal advice for your situation.
- U.S. Department of Health and Human Services, 2013 Omnibus Rule in the Federal Register, January 25, 2013.
- Legal Information Institute, text of 42 U.S.C. 1320d-8 (Section 1179), retrieved October 5, 2026.
- Physicians Practice, analysis of financial institutions as business associates, October 31, 2013.
- Roy Huggins, Person Centered Tech, article on banks, receipts and invoices under HIPAA, January 2014, updated August 2016.
- Vorys, alert on financial institutions as unknowing business associates, June 20, 2024.
- Anna Slomovic, EPIC, testimony to the NCVHS privacy subcommittee, February 18, 2004.
- r/therapists, forum thread on card payments for private practice, October 22, 2023.
- Rich & Resourceful, certification prep video on privacy law and PCI DSS, June 6, 2026.
How Should You Set Up Checkout So the Processor Stays Exempt?
A processor that only runs the charge is providing ordinary financial services, not working on your behalf, so the job is keeping clinical detail out of everything it touches.
Five settings do most of the work:
- Take payment on a hosted page or embedded iframe, so card numbers go straight to the processor and come back to you as a token.
- Collect only name, email and card details at checkout.
- Turn off free-text fields, and keep diagnosis or treatment detail out of payment descriptions.
- Use a patient or account ID as the payment reference, with nothing linking it to clinical records.
- Restrict exports, and stop payment data from syncing with your charting system.
None of this is exotic. One small healthcare nonprofit that added online payments collected nothing beyond card data and a patient ID, the minimum needed to credit the right account, and built no system connecting payments to health records. The processor saw a charge, not a chart.
Practitioners have landed in the same place. In a 2025 r/PrivatePracticeDocs thread, one commenter wrote that "PHI belongs only in BAA-covered platforms; payment processors should handle cards and nothing clinical," and another called a card processor's missing BAA "not a red flag in this context." I agree with both, with one caveat. Tokenized checkout only protects you if your own staff stop typing visit details into the payment description field.
The same discipline applies when you add ACH payments as a second rail: send an amount and a reference, never the reason for the visit.
The alternative is letting your record system handle payments. Clinicians in a 2022 r/therapists thread said "most, if not all" electronic record systems include integrated payment processing, and the fees they reported varied widely: one paid over 6% through a Squarespace integration with Stripe, about double typical record-system rates, while another cited 2.9% plus $0.30 per transaction. Bundling buys convenience. It does not change what the exemption covers, and it can quietly decide your processing costs for you.
Will Card Processors Stay Outside HIPAA's Business Associate Rules?
Most likely yes, for processors that only authorize, clear and settle card payments, while anything resembling receivables or billing-office work keeps pulling vendors into BAA territory.
The exemption traces back to the statute Congress enacted on August 21, 1996, and Physicians Practice argued in 2013 that it is "prudent for providers to make sure they meet an exception so that they are compliant." I read that as a design brief. Meeting the exception is something you build into checkout.
My bet is that tokenized card flows carrying nothing clinical will keep processors on the exempt side. New HHS guidance narrowing §1179, or an enforcement action against a payment-only processor, would change that. The sources behind this piece show neither. Separate FTC rules on personally identifiable information can still apply, so keep the payment record lean even where HIPAA steps aside.
Summarize This Article With AI
Open this article in your preferred AI engine for an instant summary.
Frequently Asked Questions
What Else Do Telehealth Operators Ask About HIPAA Compliant Payment Processing?
Most questions come back to whether a specific payment tool needs a BAA, what data can safely ride with a charge, and how a telehealth business gets set up.
What is a business associate, and is my card processor one?
A business associate is an outside party that performs a function or activity for, or on behalf of, a covered entity and handles protected health information (PHI) along the way. A processor running ordinary consumer card transactions is serving its own customers, not acting for you. Payment-only work falls outside that definition.
Can a processor that also takes on billing work stay exempt?
Not for the extra work. Once a provider moves past running payments into services like data analysis, benefits management or healthcare lending that expose it to PHI, HIPAA standards apply. I'd split those services from card acceptance so a BAA covers only the work that actually needs one.
Is Zelle HIPAA compliant for patient payments?
As of November 2023, Zelle offered no services beyond payment processing, so it did not qualify as a business associate and needed no BAA. The bigger gap was practical. Zelle offered no buyer purchase protection, so a patient scammed by an impersonator had no way to recover the loss.
What did the 2013 Omnibus Rule change?
The Federal Register notice combined four final rules into one, including the HITECH Act's tiered civil money penalty structure. HHS estimated in 2013 that compliance would cost $114 million to $225.4 million in the first year of implementation. The same rulemaking's preamble confirmed the §1179 payment exemption.
If my practice doesn't take insurance, do I still need to follow HIPAA?
Some clinicians argue you don't. A commenter in a clinician forum claimed that "If you're opted out of Medicare and don't take any insurance for your business, you don't need to follow HIPAA." The sources behind this article don't settle that, so confirm your covered-entity status with compliance counsel. A lean payment record is worth keeping either way.
How quickly can a telemedicine business get set up with SeamlessChex?
We offer same-day onboarding and no contracts, with credit card processing first and ACH as a supporting rail, online or in person. SeamlessChex works with established businesses that meet our monthly volume minimum, including subscription and high-risk merchants other processors turn away. Start through the SeamlessChex contact page and our team picks it up from there.
Written by
Lily Flanigan
Operations Manager, SeamlessChex
Lily Flanigan is Operations Manager at SeamlessChex, a credit card processing and fintech payments platform recognized on the Inc. 5000, where she focuses on operations and process optimization.
Connect on LinkedInSeamlessChex works with established businesses processing a minimum of $25,000 per month.