← All posts

Sep 3, 2026

Does HIPAA actually apply to your massage practice?

Somewhere between massage school and your first solo client, most people pick up a vague dread about HIPAA — the sense that jotting "shoulder impingement, avoid deep pressure" in a notebook might be breaking a federal law. For the majority of solo, cash- and card-pay massage practices, that dread is aimed at the wrong target. The law is real, but it almost certainly doesn't apply to you the way you've been told. What does apply — and what actually protects your clients — is something you already understand: the plain duty to keep what a client tells you between the two of you.

Who HIPAA actually covers

HIPAA doesn't cover "anyone who handles health information." It covers a specific list of covered entities — health plans, health care clearinghouses, and health care providers who electronically transmit health information for a defined set of standard transactions, like billing an insurance claim. Two things have to be true at once: you're providing a health care service, and you're submitting that kind of electronic transaction, directly or through a clearinghouse. If you take cash, a payment app, or a card swipe and you never bill an insurer for a session, the second half of that test isn't met — and you're not a HIPAA-covered entity.

The exception that actually catches people

Two situations flip the answer. The first is insurance billing: if you submit claims or eligibility checks electronically, even occasionally, that transaction brings you into HIPAA's scope. The second is contract work: if you provide massage under a chiropractor's, physical therapist's, or clinic's roof and they're a covered entity, you may be their business associate — someone who handles protected health information on a covered entity's behalf — and they're required to have you sign a BAA before you touch that information. Neither situation is rare, and both are worth a five-minute gut check: do you bill insurance electronically, or do you work inside someone else's covered practice?

The honest catch

Here's the honest catch, the part the "you're exempt, relax" version of this article skips: not being a covered entity doesn't mean privacy stops mattering. It means the specific federal law doesn't apply — not that you're released from the duty. Your licensing board's rules and your professional association's code of ethics still require confidentiality, regardless of how you're paid. And your clients aren't parsing the legal technicality anyway: they tell you about surgeries, pregnancies, chronic pain, and family stress on the assumption it goes nowhere. That's the actual bar you're meeting. It's a professional standard, not a federal one — but it isn't a lower one.

What to actually do about it

You don't need a compliance program you don't legally need. You do need the ordinary habits, kept consistently:

  • Keep client details out of your personal text thread. A message about a client's injury shouldn't live in the same history as your own group chats, on a phone you might lose or hand to a kid to play a game.
  • Skip the shared notes app for intake information. What belongs on an intake form is sensitive by nature — it deserves a record built for it, not a note anyone with your passcode can open.
  • Pick tools that don't sell client data or run trackers on the pages your clients touch. That's a promise you can only make if the tool itself makes it.
  • Get the BAA whether or not you're required to have one. If there's any chance you'll ever bill insurance, take on clinic work, or just want the paperwork in your back pocket, it costs nothing to use a tool that offers a self-serve BAA — the agreement a scheduling tool has to sign before it can hold client health information — instead of one that doesn't offer it at all.

This is really the same ground client data privacy for massage therapists covers from the other direction: whether or not HIPAA applies to you, you owe your clients confidentiality, and the habits that satisfy one satisfy the other.

Built in, not something you unlock

Stillbook is HIPAA-ready, with a self-serve BAA on every plan, whether or not your practice is ever legally required to have one. It's not there to scare you into upgrading, and it's not a tier you have to earn — it's just there, in-app, in case you need it. The privacy your clients actually care about, the ordinary everyday kind, is built in regardless of which side of the covered-entity line you land on.

A calmer way to run your practice.

Free during early access. No credit card, cancel anytime, export your data whenever you like.

Are you a client looking to book?

Your therapist will have texted or emailed you a personal link — check there to book or change your appointment.