Do Chargebacks Leak PHI? The HIPAA Gap in Payment Disputes

Get Started ›
Clinic billing desk with a card dispute notice set apart from a closed patient chart folder

Key Points

  • The HIPAA Privacy Rule at 45 CFR 164.501 lists billing, claims management and collection activities as payment, so a practice may contest a medical chargeback.
  • HHS's proposed Privacy Rule, published in the Federal Register on November 3, 1999, placed minimum necessary use and disclosure beside payment, so dispute files should hold only proof of the charge.
  • In April 2025, a Mochi Health patient alleged the company's dispute response to Citibank included medical history, intake forms, diagnosis and the provider's notes.
Three things health care merchants believe about chargebacks. Myth or fact?
Call each one, then see how other readers called it.
1 HIPAA stops a practice from contesting a patient's chargeback.
2 Your practice, not the card issuer, carries the HIPAA duty for what enters a dispute file.
3 Sending the full chart gives a practice its best odds of winning a dispute.
Clinic billing desk with a card dispute notice set apart from a closed patient chart folder

A chargeback response is a disclosure decision: what proves the charge goes to the issuer, and the chart stays in the practice.

Quick Answer

Yes. A chargeback response means that a merchant sends evidence to the card issuer; when it includes diagnoses, intake forms or provider notes, protected health information leaves the practice.

Contesting the charge is not the problem. HIPAA treats billing and collection as payment activity, so a provider may defend its revenue. Scope is the problem. According to HHS's proposed Privacy Rule, minimum necessary was written as a general rule for uses and disclosures, so the dispute file should hold only what proves the charge.

BAAs and PCI DSS scoping cover the charge, not the dispute. I'd recommend two controls: a neutral billing descriptor and a proof-of-service packet built from authorization, booking and delivery records. Nothing clinical.

Did this answer your question?

How can high-risk merchants handle chargebacks with their processor without exposing PHI?

By treating every dispute response as a disclosure decision: keep the card descriptor neutral, prove authorization and delivery, and leave diagnoses, intake forms and provider notes out of the issuer's file.

A chargeback is a cardholder dispute that reopens a paid transaction and asks the merchant to prove it was valid. For a telehealth, GLP-1 or peptide business, that proof often lives in the same systems that hold patient records. That overlap is the problem.

Business associate agreements, tokenization and PCI scope all describe the moment a card is charged. None of them tells a billing team what to attach when an issuer asks for evidence weeks later. In my view, that is where protected health information slips out: not through a breach, but through a well-meant upload.

According to HHS's proposed Privacy Rule, printed in Volume 64 of the Federal Register at pages 59917 through 59966, the minimum necessary standard was drafted into the same framework that permits disclosure for payment. The permission and the limit arrived together. I suspect many dispute workflows remember only the first half.

Here is what the rest of this article covers:

  • The permission question: why contesting a medical charge counts as payment activity, and where the minimum necessary limit applies.
  • Five leak points: the billing descriptor, itemized receipts, clinical attachments, patient message threads and the vendor tools that store dispute files.
  • The proof-of-service packet: what to send an issuer when you need to win without handing over a chart.
  • The next 12 to 24 months: five forecast signals, with the evidence for and against each one.

If you are comparing secure credit card processing for a high-risk health business, add one question to your shortlist. Who controls what goes into the dispute file? A processor cannot recall an over-shared packet once it reaches the issuer. The right partner can, however, help you set a neutral descriptor and a representment process your team owns.

Chargebacks on health charges are becoming a privacy question, not only a revenue one. Handle them with the same discipline you apply at intake, and you can defend revenue, protect patients and answer issuers with confidence.

Most writing on HIPAA-compliant payment processing stops at the checkout page. It covers business associate agreements, tokenization, and whether a processor ever touches protected health information. Very little of it follows the money after a patient disputes the charge.

A chargeback is a card dispute the cardholder files through their issuing bank. The merchant answers with evidence, a process called representment. That evidence, plus the billing descriptor attached to every card transaction, is where health information can slip into a bank's file.

The right to fight is not in doubt. The limit is the problem.

According to HHS's 1999 proposed Privacy Rule, slated for 45 CFR Parts 160 through 164, the standards were meant to answer "growing public concerns" that electronic technology in health care was causing, or might cause, "a substantial erosion of the privacy" surrounding identifiable health information. In my view, a dispute upload portal is a modern version of that exact risk. It is fast, it is electronic, and it is easy to leave off a compliance review.

The stakes became concrete last year, when a telehealth patient publicly alleged that a provider had sent their diagnosis and clinical notes to a card issuer to contest a chargeback. One allegation proves nothing about the industry. It does show how easily a routine rebuttal can become a privacy complaint.

In this piece, I'll show what HIPAA actually permits during a dispute, where PHI tends to leak, and how to build a packet that proves your case without a chart.

Three questions this article answers

  1. Does fighting a chargeback on a medical charge violate HIPAA? Short version: no, but permission is only half the rule.
  2. Where does PHI actually leak in a card dispute? Five places, starting with the descriptor printed on the patient's own statement.
  3. What should a HIPAA-conscious dispute packet contain? Proof of authorization and delivery, not the chart.

Forecast: 12-24 months

Where PHI exposure in card disputes heads next

Forecasts on how clinics, telehealth sellers, processors and issuers will handle patient data when a card charge for care is disputed.

9 sources analyzed4 community discussions2 web sources2 government sources1 video source
A

What changes for healthcare chargebacks

Read each forecast with its early indicator and confidence level before changing how your practice answers a disputed charge.

73/100
Medium confidence 12-24 months

Over the next 12-24 months, cash-pay clinics, telehealth sellers and wellness merchants will field more first-party disputes over services already delivered. This extends the global rise reported in Datos Insights research commissioned by Ethoca, a Mastercard company, and the friendly-fraud pattern small merchants described in early 2026.

68/100
Medium confidence 12-24 months

Responsibility for patient data in dispute files will keep landing on providers and their vendors rather than on the card side. Social Security Act §1179 (42 U.S.C. 1320d-8) covers entities authorizing, processing, clearing, settling, billing, transferring, reconciling or collecting payments for a financial institution. Meanwhile the 2013 HITECH rule widened who counts as a business associate. Practices will push dispute-management and billing vendors that handle clinical files into business associate agreements.

64/100
Medium confidence 12-24 months

Patients who find diagnoses and provider notes in a merchant's dispute response will increasingly take the matter to their card issuer and to lawyers. Those cases will test how HIPAA's Privacy, Enforcement and Breach Notification rules, as modified under the HITECH Act in 2013, apply to over-disclosure during a chargeback.

61/100
Medium confidence 12-24 months

Telehealth and cash-pay providers will move away from attaching full charts to chargeback responses. They will shift toward packets limited to proof that care was booked and delivered, after cases like Mochi's, where a patient says the records sent in a dispute included medical history, intake forms, diagnosis and provider notes.

Early Indicators A merchant who logged two chargebacks in ten years reported five in a few months before February 2026, all false claims filed without contacting the seller. Another cardholder admitted in writing that a parcel was probably stolen and pursued the chargeback anyway. The January 25, 2013 final rule (78 FR 5566) revised the §160.103 business associate definition to include health information organizations, e-prescribing gateways and other persons that facilitate data transmission. Practice groups such as the Illinois Chiropractic Society are already fielding member calls about patients disputing charges for legitimate services, with what information can be released as the main worry. Guidance to chiropractors already frames payment as the HIPAA exception that applies to a chargeback dispute and points practices to the Federal Register as the source. A patient posting in a compounded-tirzepatide community, disputing a charge with Citibank, says they are weighing a contingency law firm after Mochi submitted their medical records as dispute evidence.

B

Rules, research and dispute cases behind this

Public regulations, industry research and merchant dispute accounts behind these forecasts, with the line each source contributes.

Source What it states Forecasts it backs
chargeback with PROOF she received services [Community / Forum] Chase was the issuing bank. According to the poster, Stripe confirmed that Chase sided with the cardholder after "reviewing" for one month. “I know Stripe doesn’t make the final decision, but I’d like to know what else I could’ve done and if there’s any internal team who actually reviews this kind…” HIPAA is not what stops practices from fighting disputes
HIPAA Privacy Regulations: Definitions - Payment - § 164.501 [Web source] Listed payment activities include eligibility and coverage determinations, coordination of benefits, cost-sharing determinations, adjudication or subrogation of claims, risk adjusting, and "billing, claims management, collection… HIPAA is not what stops practices from fighting disputes
Chargeback Disputes: Protecting Your Practice Payments [Video] The speaker identifies payment as the exception that applies to a chargeback dispute. [0:02]. “the exceptions that are very clear inside of HIPPA indicate that you can release information for treatment, for payment, and for healthcare operations.”
According to the speaker, HIPAA and "what information can be released" is typically the main concern when a practice disputes a chargeback. [0:02].
HIPAA is not what stops practices from fighting disputes
Dispute packets shrink to proof of service
Chargeback fraud or "friendly fraud" is out of control. [Community / Forum] In "the last few months" before February 2026, the poster had five chargebacks. They describe all five as fraudulent. The card was not stolen; the dispute itself was false, which is the pattern known as "friendly fraud.". “I absolutely believe in consumer protection and that there needs to be a system in place for when companies legitimately do wrong to a customer.” Chargeback volume keeps climbing into care services
Chargeback case [Community / Forum] Asked whether the parcel might have been stolen, the customer replied in writing: "yes, it was probably stolen." They still pursued the chargeback. Chargeback volume keeps climbing into care services
Surging Card Disputes: A Global Perspective on the State of [Web source] Headline finding: "Global chargeback volume continues to rise.". “As digital commerce expands, consumer behavior evolves, and fraudsters become more sophisticated, FIs and merchants face mounting challenges in managing the…” Chargeback volume keeps climbing into care services
Other Modifications to the HIPAA Rules - Federal Register [Government] Under §160.103, the definition of "Business Associate" was revised to include:. “Effective date: This final rule is effective on March 26, 2013.”
It modifies four HIPAA rules (Privacy, Security, Enforcement, and Breach Notification) under two statutes: the HITECH Act and the Genetic Information Nondiscrimination Act (GINA).
Card-side intermediaries stay outside HIPAA, providers don't
Patients escalate over records in dispute files
Social Security Act §1179 [Government] Payment intermediaries: It also covers any entity engaged in "authorizing, processing, clearing, settling, billing, transferring, reconciling, or collecting payments, for a financial institution." That is eight enumerated payment functions. “this part, and any standard adopted under this part, shall not apply to the entity with respect to such activities” Card-side intermediaries stay outside HIPAA, providers don't
Banned from /joinmochihealth [Community / Forum] OP says they are considering hiring a law firm that works on contingency. “They literally just do a dump of everything: medical history, intake forms, diagnosis, communications with your provider, notes your provider took.”
According to OP, the records Mochi submitted included medical history, intake forms, diagnosis, communications with the provider, and the provider's notes.
Patients escalate over records in dispute files
Dispute packets shrink to proof of service
Where the forecasts come from: every public source, the line it contributes, and the calls it supports.
C

What would shift the outlook on dispute PHI

Regulatory, card-network and enforcement developments that would weaken or reverse these forecasts on patient data in payment disputes.

Our Margin for Error

We hold 74 with the most confidence, while 74 is the one we would flag as most likely to shift.

  • HIPAA is not what stops practices from fighting disputes. A reversal by regulators or buyers undercuts it before anything else.
  • HIPAA is not what stops practices from fighting disputes. If the balance of sources tips against the consensus, that becomes the safer call.
Methodology Each forecast is scored 0-100 from the public sources shown for it: how many there are and how authoritative they are.

What will matter most for health care chargebacks in the next 12-24 months?

Over the next 12 to 24 months, I expect card disputes to become a recognized privacy exposure for cash-pay and telehealth merchants. Volume is rising, and HIPAA exposure stays with providers.

Three signals point that way. None is decisive alone, but together they show where dispute risk is heading for clinics, telehealth brands, and supplemental health sellers.

PredictionWeak signalWhy it mattersPublic source
Disputes over care already delivered keep climbing. Cash-pay clinics, telehealth sellers, and wellness merchants will field more first-party chargebacks. Research on large financial institutions published in April 2025 reported that "Global chargeback volume continues to rise." According to a leather-goods maker posting on r/PersonalFinanceCanada in February 2026, each recent dispute was a false claim on a card that was never stolen, the pattern known as "friendly fraud." In an August 2026 retail case, the buyer replied in writing that the parcel was "probably stolen" and still pursued the chargeback. Each dispute a clinic answers is a decision about what patient information leaves the practice. More disputes mean more chances to over-share. Merchant thread, r/PersonalFinanceCanada, February 2026
Liability for dispute files stays with providers. Processors and issuing banks keep their carve-out for routine payment work, so responsibility for patient data lands on the practice and the vendors it hires. Section 1179 exempts payment work done for a financial institution, while HIPAA's business associate definition already reaches subcontractors. A dispute-management tool that stores a clinic's evidence can sit on the provider's side of that line. A clinic cannot hand responsibility for an over-shared chart to its processor or the issuing bank. Its own dispute workflow and vendor contracts are where the exposure sits. Social Security Act §1179 (42 U.S.C. 1320d-8)
Patients escalate over records in dispute files. People who find diagnoses or provider notes in a merchant's response will take it to their issuer and to lawyers, testing how HIPAA's enforcement and breach rules apply. The patient in the Mochi Health case described earlier wrote that they were considering a law firm that works on contingency. A dispute over one charge can turn into a privacy claim. That changes the math on how fully a provider should answer. HIPAA Omnibus final rule, which modified the Privacy, Security, Enforcement, and Breach Notification Rules under the HITECH Act and GINA

What could change this outlook? Formal HHS guidance treating everything in a chargeback response as permitted payment activity would weaken it. So would card issuers requiring full clinical records before they rule on a medical dispute. Either shift would push providers back toward fuller disclosure, and I would revise these calls if one arrived.

What most buyers miss: HIPAA is not the reason to stop fighting chargebacks. The Privacy Rule's payment definition covers collection work, so a practice that quietly absorbs every dispute gives up revenue it is allowed to defend. In my view, the next two years will not turn on whether providers may respond. They will turn on scope. The businesses that prove the service with a lean, timeline-based packet stand the best chance of protecting cash flow, patient trust, and their standing with their processor.

Does fighting a chargeback on a medical charge violate HIPAA?

No. HIPAA's payment definition covers billing, claims management and collection, so a practice may contest a card dispute. The open question is how much patient information the response should carry.

The HIPAA Privacy Rule at 45 CFR 164.501 lists "billing, claims management, collection activities" as payment, and HHS says claims management includes "investigating and resolving payment disputes." On the card side, Social Security Act §1179 (42 U.S.C. 1320d-8) exempts financial institutions, and entities performing eight enumerated payment functions for them, when they use information in connection with "a customer dispute." An analysis of 4 sources shows a consistent split between permission and scope. Each one allows disclosure to resolve a dispute, and none defines what a dispute response should contain.

I read that as a two-part problem, so I use a simple lens I call the permission-and-limit test:

  • Permission: Is the disclosure made to resolve this payment dispute, and is it about the patient who received the care?
  • Limit: Is each item the least information needed to show the charge was authorized and the service was delivered?

The first question is usually easy. The payment definition confines these disclosures to PHI about "the individual to whom care was rendered," and one covered entity may not disclose PHI for another covered entity's payment activities. The second question is where practices get into trouble.

Why privacy law is not what stops practices from fighting back

Contrary to popular belief, HIPAA is not the barrier. A state chiropractic association told its members that HIPAA, and "what information can be released," is typically the main concern when a practice disputes a chargeback, then pointed them to payment as the exception that applies. In my view, that guidance is right about permission and silent about scope.

According to HHS's proposed Privacy Rule, published in the Federal Register on November 3, 1999, a general rule titled "Minimum necessary use and disclosure" sat right beside use and disclosure for treatment, payment, and health care operations. Permission and restraint were drafted as a pair from the start. I would treat minimum necessary as governing any dispute response a practice sends, and I'd confirm the specifics with health care counsel.

ProvisionWhat it permitsWhat it leaves open
45 CFR 164.501, definition of paymentBilling, claims management and collection, including resolving payment disputesWhich records a dispute response actually needs
Social Security Act §1179Issuers and processors handling information for a customer dispute, outside HIPAA's standardsWhat the provider should send them in the first place
Payment disclosure scopePHI about the individual to whom care was renderedWhether a diagnosis or chart is ever required
Minimum necessary (1999 proposed rule)A general rule limiting use and disclosureA dispute-specific list of what to include

One detail in §1179 matters more than it looks. The exemption applies only "to the extent that" an entity is doing financial-institution or payment work, and only "with respect to such activities." The issuer reviewing your rebuttal sits outside HIPAA's standards for that task. Your practice does not. Once a diagnosis leaves your system inside a dispute file, the only party whose HIPAA duties governed that choice was you.

In practice, permission and scope are separate decisions. The takeaway is simple: you may defend the charge, but you still decide what leaves the building. Defending it matters, because lost disputes can shape what you pay for a high-risk merchant account, and a rising chargeback count can end in reserves held on a terminated account or a search for TMF/MATCH list merchant account approval.

HIPAA lets a practice fight a chargeback. It does not ask the practice to hand an issuer a chart, and that gap is exactly where patient data starts to leak.

Where does PHI actually leak in a card dispute?

Five places: the billing descriptor, itemized receipts, clinical attachments, patient message threads, and the vendor tools that store dispute files. Each can carry health details into an issuer's record.

According to HHS's 1999 proposed Privacy Rule, the standards were written to protect individually identifiable health information "maintained or transmitted in connection with certain administrative and financial transactions." A chargeback is exactly that kind of transaction. What this means is that the dispute file sits inside the privacy conversation, not beside it.

Look at the identifiers HHS's commentary on the payment definition names: name and address, date of birth, Social Security number, payment history, account number, and the name and address of the provider or health plan. None of them is a diagnosis, an intake form or a provider's note. Yet clinical detail still finds its way into dispute records through five doors.

The billing descriptor

The descriptor is the merchant name a cardholder sees on a statement, and it travels with the transaction into any dispute. If it names a condition, a drug or a specialty, the charge itself tells a reader something about the patient's health. I have not found HHS guidance that labels a descriptor PHI, and none of the evidence here tests the question. I would still treat a condition-revealing descriptor as avoidable exposure.

Itemized receipts and invoices

Receipts built for patients often list the service, the medication and sometimes the dose. Attached to a rebuttal, that line item becomes clinical data sitting in a bank's file. In practice, a receipt can prove the amount and date without naming the treatment.

Clinical attachments

This is the most serious leak. In April 2025, a patient of the telehealth company Mochi Health publicly alleged that the company's dispute response to Citibank included medical history, intake forms, diagnosis, communications with the provider, and the provider's notes. The patient said they had filed a complaint with HHS's Office for Civil Rights. The account is unverified and one-sided, and no response from Mochi appears alongside it. Another participant in the discussion made the sharper point: medical documents could not prove that a prescription was ever delivered.

Patient message threads

Merchants are routinely told to include every email with the customer. In one retail chargeback case posted in August 2026, the recommended evidence packet bundled all email exchanges, and those emails carried the buyer's own mention of "financial difficulties." A clinic's patient messages are likely to carry symptoms and side effects instead. Forwarding the full thread forwards all of it.

Vendor tools that store dispute evidence

The January 25, 2013 HIPAA Omnibus Rule (78 FR 5566) revised the business associate definition to include subcontractors and "Other Persons That Facilitate Data Transmission," while also setting exceptions to that definition. The §1179 exemption covers entities working for a financial institution, not vendors working for the practice. A chargeback-management platform that stores clinical attachments may therefore sit on the regulated side of the line. I'd recommend asking any dispute vendor whether it will sign a BAA before it ever receives a chart.

Leak pointWhat can surfaceWho sees itLower-risk alternative
Billing descriptorCondition, drug or specialty in the merchant nameCardholder, issuer, dispute reviewersNeutral business name plus a support phone number
Itemized receiptService, medication, doseIssuer and acquirer dispute teamsAmount, date, visit or order ID
Clinical attachmentsHistory, intake, diagnosis, notesIssuer reviewersProof of booking and delivery only
Message threadsSymptoms, side effects, personal circumstancesIssuer reviewersExcerpts showing consent, access or delivery
Dispute vendorsAnything uploadedVendor staff and subcontractorsA signed BAA first, or a PHI-free packet

How often does this happen? No public dataset counts it, and I won't estimate. The measurement that would settle it is straightforward: the share of health care dispute responses that include a diagnosis, clinical notes or a condition-revealing descriptor.

The takeaway: PHI rarely leaks through one reckless upload. It seeps through defaults, and every default on this list can be changed.

Want a card processor that lets you control the dispute file?

SeamlessChex provides dedicated credit card processing for telemedicine, GLP-1, peptide and supplemental health businesses, with ACH available as a second rail. We partner with established businesses processing $25,000 or more per month.

Nobody has published how often health care dispute files carry PHI. So I won't quote you odds. What you can control is the descriptor on the statement and the packet your team sends, starting with the next chargeback that lands on your desk.

Get approved with SeamlessChex

Hands arranging a card receipt, appointment confirmation and shipping confirmation into a lean dispute packet
A proof-of-service packet shows the charge was authorized and the service delivered, without sending the chart.

What should a HIPAA-conscious dispute packet contain?

Proof that the patient authorized the charge and received the service, organized as one timeline. Leave diagnosis, intake forms and provider notes out unless counsel says otherwise.

Our underwriting team makes a related point about a very different vertical: an application should describe the real shape of the business and how each element is controlled, not just a category label. A dispute response works the same way. The issuer is not judging your medicine. It is judging whether the cardholder agreed to pay and got what was paid for.

That is why I'd recommend building every response around the proof-of-service packet, a three-part structure that covers authorization, delivery, and communication:

  • Authorization: the signed financial and cancellation policy, the booking or order confirmation, and the transaction record.
  • Delivery: appointment or telehealth session timestamps, and carrier tracking with proof of delivery for anything shipped.
  • Communication: only the message excerpts that show consent, access, delivery, or a cancellation request.

Why more paper does not mean a better case

A common misconception is that sending everything wins. A training-studio owner lost a $1,225 dispute after submitting signed policies, receipts, a booking confirmation, text messages and photos of the student in the studio. Chase, the issuer, sided with the cardholder after reviewing for one month. A leather-goods maker who had two chargebacks in ten years reported five in a few months before February 2026, lost every one despite submitting evidence, and paid a $20 fee each time.

Compare a seller who averages 1-2 chargebacks per year and reports never losing one. Their packet is a single PDF with a clear timeline: the sales entry, the invoice, proof of delivery, and the relevant emails. The evidence here is anecdotal, but it points one way. In practice, organization beats volume. What this means for a clinic is blunt: a chart adds exposure, not odds.

Packet elementIncludeLeave out
AuthorizationSigned financial and cancellation policy, booking confirmation, transaction recordIntake questionnaire answers
Delivery of serviceAppointment or session timestamps, tracking and proof of deliveryDiagnosis, provider notes, lab results
CommunicationsExcerpts showing consent, access, delivery or a cancellation requestFull threads discussing symptoms
ReceiptAmount, date, order or visit ID, neutral service labelDrug name, dose, condition
NarrativeOne-page timeline in plain languageClinical justification for treatment

According to HHS's 1999 proposal, the privacy standards were built around individuals' rights as well as "the authorized and required uses and disclosures of this information." I don't read anything in the payment rules as suspending those rights for a patient who disputes a charge. Treat the disputing patient's privacy exactly as you would any other patient's.

Fix the setup before the next dispute arrives

Two fixes sit upstream of any rebuttal. The first is a neutral billing descriptor that identifies your business without naming a condition or drug. The second is a processing relationship where a person can actually work a dispute with you. In the studio case above, the merchant submitted evidence through a platform dashboard and could not escalate afterward.

At SeamlessChex, we lead with dedicated credit card processing, with ACH as a secondary rail, for established businesses processing $25,000 or more per month. That structure allows businesses to set their descriptor, standardize their packet, and respond with confidence.

The short version: prove authorization, prove delivery, show the conversation, and stop there.

What should health care merchants do before the next dispute?

Treat every chargeback response as a disclosure decision. Set a neutral descriptor, standardize a proof-of-service packet, and keep diagnosis and provider notes out of issuer files.

According to Datos Insights research commissioned by Ethoca, a Mastercard company, global chargeback volume continues to rise. The sponsor sells dispute tools, so I read that finding with some care. The direction still matters. More disputes mean more moments when someone at a practice decides what patient information leaves the building.

The law already gives you the right to defend a charge. HHS paired that right with a minimum necessary rule from its very first proposal. What nobody has written down is the dispute-specific version, so each practice has to write its own.

I'd start with the next three disputes that arrive. Pull each packet before it is submitted, strike anything clinical, and ask whether the case still stands. In my view, it usually will. The issuer is asking whether the patient agreed to pay and received the service, not whether the treatment was right.

And if your current processor won't let you set a clean descriptor, or won't put a person on the phone when a dispute lands, that is the moment to look at a dedicated credit card merchant account built for established health and wellness businesses.

Written by

Jonathan Albert

Co-Founder, SeamlessChex

Jonathan Albert is Co-Founder of SeamlessChex, a credit card processing and fintech payments platform recognized on the Inc. 5000.

Connect on LinkedIn

Summarize This Article With AI

Open this article in your preferred AI engine for an instant summary.

Frequently Asked Questions

What do health care merchants ask about chargebacks and HIPAA?

The questions below cover disclosure permission, business associate status, descriptors, vendor contracts, subpoenas and patient complaints, plus which businesses SeamlessChex works with.

Can I share patient information with my card processor to fight a chargeback?

Yes, within limits. According to the annotated HIPAA payment definition that Bricker Graydon publishes, covered entities may disclose PHI for payment purposes "to any other entity, regardless of whether it is a covered entity." I'd still send only what proves authorization and delivery.

Is the card issuer a business associate when it reviews my evidence?

Generally no. Social Security Act §1179 takes financial institutions, and entities processing payments for them, outside HIPAA's standards when they handle a customer dispute. That makes your practice the last point of control.

Does a billing descriptor count as PHI?

A billing descriptor is the merchant name printed on the cardholder's statement. I haven't found HHS guidance that settles whether a condition-revealing descriptor is PHI. I would treat one as avoidable exposure and use a neutral business name.

Do I need a BAA with my chargeback management vendor?

Possibly. A business associate handles PHI on a covered entity's behalf, and the 2013 Omnibus Rule extended that definition to subcontractors. If a vendor stores clinical attachments for your practice, ask counsel whether it needs a signed agreement.

What if a bank or court asks for more records?

That is a different pathway. Disclosures to comply with a civil or criminal subpoena, or other laws, fall under 45 CFR 164.512 rather than the payment definition. Route those requests to counsel, not your dispute workflow.

What happens if a patient complains about a dispute file?

Patients can file complaints with HHS's Office for Civil Rights, and one telehealth patient said they did exactly that. Minimum necessary, the rule that each disclosure carry only what its purpose needs, is the standard I'd expect any review to apply.

Which businesses does SeamlessChex work with?

SeamlessChex works with established businesses processing a minimum of $25,000 per month. We lead with credit card processing and merchant accounts, including telemedicine and supplemental health, with ACH available as a second option.

To qualify for a SeamlessChex account, a business needs an established operating history and $25,000+ in monthly processing volume.

Get Started