Guide

HIPAA and Solo Massage Therapists: What Actually Applies

The honest answer to “does HIPAA apply to me” is that it depends on how you bill, and that a lot of massage therapists have been told otherwise by people selling something.

What HIPAA actually reaches

HIPAA applies to covered entities: health plans, health care clearinghouses, and health care providers who transmit health information electronically in connection with a standard transaction. That last clause is the one that decides most massage practices.

A standard transaction is an administrative exchange with a payer: a claim, an eligibility check, a remittance. The trigger is doing one of those electronically. It is not about how sensitive your notes are, how many clients you see, or whether you use software.

So the question is not “do I keep health information” (you do). It is “do I, or does someone acting for me, send claims or similar transactions to insurers electronically”.

The common case: cash-pay solo practice

A therapist who takes cash and cards, bills nobody electronically, and hands a client a receipt to submit themselves is typically not a covered entity. The records are still confidential and still sensitive. HIPAA is simply not the law creating that duty.

Where it gets less clear:

  • You bill insurance directly, or a billing service does it for you. Assume you may be covered and get advice on your specific arrangement.
  • You work as a contractor inside a clinic that bills insurance. Your obligations may run through the clinic’s status rather than your own, which is worth clarifying with the clinic rather than guessing.
  • You issue superbills but the client submits them. Common in massage, and it is the client making the submission, not you. Whether that leaves you outside coverage still depends on what else you do electronically.

None of these are answered by a checklist on a website, including this one. They are answered by someone who can look at your actual billing setup.

What binds you when HIPAA does not

This is the part that gets left out when compliance is being sold, and it is the part that matters more for most solo therapists.

Your state board. Massage boards set confidentiality and recordkeeping rules directly, and they are the body that will actually look at your practice if a complaint is made. Their rules apply whether or not HIPAA does.

State health-information law. Many states regulate health records independently of HIPAA, sometimes more strictly, and often without a covered-entity threshold.

State breach-notification law. Essentially every state requires notification if personal information is exposed. These laws generally apply to businesses, not just to covered entities.

Your duty to the client. A client who tells you about a surgery expects that to stay between you. That expectation does not depend on which federal statute is in play.

A practice that keeps records carefully, limits who can see them and can say what happened if a device goes missing is in reasonable shape under all of the above. A practice relying on a badge in an app store listing is not.

Why no app can be “HIPAA compliant”

Compliance is a property of a practice, not of software. It covers policies, workforce training, risk analysis, breach procedures, agreements with vendors, and physical and technical safeguards. Nothing installed on a phone can supply most of that.

What software can do is make the safeguards easier: keeping records encrypted, keeping them off third-party servers, requiring authentication to open them, and making it possible to produce a client’s file when it is legitimately requested. Where a vendor does handle protected health information for a covered entity, the meaningful thing it can offer is a business associate agreement, not an adjective.

Our own app is deliberate about this: SOAP Notes: Massage Client Log does not claim HIPAA compliance. Records stay encrypted on your own device with no account and no cloud, which means client information never passes through our servers and we could not read it if we wanted to. That is a description of how it works, and it is a different kind of statement from a compliance claim.

A practical shape for a solo practice

Regardless of which laws reach you:

  • Know how you bill, and revisit the question if that changes.
  • Read your own state board’s confidentiality and records rules, and keep to whichever standard is stricter.
  • Keep records somewhere only you can open, whether that is a locked cabinet or an encrypted device.
  • Keep them for as long as your state requires, which is often measured from the end of the therapeutic relationship rather than the last session. The rules we have checked against each board’s own published source are on our massage record retention by state page.
  • Write contemporaneously and correct by dated addendum, which our SOAP note guide covers in detail.
  • Ask a professional adviser about your specific setup before deciding you are outside a law.

This is general information about how HIPAA is structured, not legal advice, and it does not tell you whether you personally are a covered entity. That question is worth asking someone who can look at your billing.

RiverMap Learning apps are independent study tools. They are not affiliated with, endorsed by, or connected to any government body or examination authority. Question content is original and based on publicly available official study materials.