HIPAA BinderGet my forms

Do I need HIPAA forms for my massage practice?

Often no. You need HIPAA forms only if your practice is a covered entity, and a massage practice becomes one only when a claim, eligibility check, or remittance moves electronically between you and a health plan(45 CFR 160.103). A cash- or card-only practice that never files electronically usually is not covered, and neither auto nor workers’ comp claims change that.

That is a different answer than most compliance vendors give, so the table below shows exactly which facts flip the test and which do not. If you land on the covered side, the document checklist follows.

Researched and written by Larry Osakwe · Last verified August 1, 2026

Checked against the current 45 CFR text and 42 U.S.C. 300gg-91. Not a lawyer, not a certified compliance professional, and not affiliated with HHS.

How we research thisReport an error

What actually makes a massage practice a covered entity

The test is narrow and mechanical. It is not about whether you keep health information, how sensitive it is, or how professional you are. It is about whether a covered transaction moves electronically between you and a health plan.

If this is true of your practiceCovered entity?Why
You take cash, cards, or HSA/FSA cards and never bill insuranceNoPayment is not a HIPAA standard transaction. How a client pays you is irrelevant to the test.
You hand the client a paper receipt or superbill to submit themselvesNoThe client transmits the claim, not you. The test in 45 CFR 160.103 asks whether YOU transmit health information electronically in connection with a covered transaction.
You e-file a claim to an auto insurer after a car accidentNoAutomobile liability and automobile medical payment insurance are excepted benefits, so those carriers are not health plans under 45 CFR 160.103. A claim to a non-health-plan is not a covered transaction.
You e-file a claim to a workers' compensation carrierNoWorkers' compensation or similar insurance is also an excepted benefit, and is excluded from the health plan definition on the same footing as auto liability.
You submit an electronic claim to a health insurer, Medicare, or MedicaidYesThis is the classic covered transaction. One claim is enough, and it covers all your client information from then on, not just that client's.
Your software or billing service files claims or checks eligibility for youYesTransmission by someone acting on your behalf counts as transmission by you. This is the most common way a practice becomes covered without deciding to.
You work inside a chiropractic, PT, or medical clinic that bills electronicallyUsuallyYou are generally accessing PHI under that clinic's covered-entity status. Your separate cash practice may still be outside HIPAA; the two answers can differ.

One caution on the two “No” rows for auto and workers’ comp: they mean those claims do not make you covered. If you are already a covered entity for some other reason, the records in those cases are PHI like everything else.

Do massage therapists have to comply with HIPAA?

Often not. A massage practice is a HIPAA covered entity only if it transmits health information electronically in connection with a covered transaction, which in practice means electronic claims, eligibility checks, or remittance with a health plan (45 CFR 160.103). A large share of massage practices are cash- or card-only and never do any of that, so they fall outside HIPAA entirely. This is the honest answer, and it differs from what most compliance vendors will tell you. What it does not mean is that you have no obligations: state confidentiality law, your licensing board's ethics rules, and consumer-protection law all still apply to the health information you hold.

The covered-entity test, profession by profession

Does billing an auto insurer or workers' comp make me a covered entity?

Generally no, and this is the single most misunderstood point for massage therapists who do injury work. The covered-entity test turns on transmitting a covered transaction with a health plan. 45 CFR 160.103 defines health plan to exclude any policy, plan, or program to the extent it provides or pays for excepted benefits listed at 42 U.S.C. 300gg-91(c)(1), and that list expressly includes liability insurance including automobile liability insurance (C), workers' compensation or similar insurance (D), and automobile medical payment insurance (E). So an electronic claim to an auto carrier or a comp carrier is not a transaction with a health plan, and does not by itself make you a covered entity. Personal-injury and workers'-comp records are still sensitive and still governed by state law and by whatever the carrier and attorney agreements require.

If I'm not a covered entity, do I still need a privacy notice?

HIPAA does not require one, but you probably still want the substance of it. You hold injury histories, pregnancy status, trauma disclosures, and medication lists. State confidentiality statutes, licensing-board ethics rules, and consumer-protection law reach that information whether or not HIPAA does, and clients assume it is protected. A short written privacy practice, sensible records storage, and agreements with the software vendors who hold your SOAP notes are good practice on their own terms. Just do not let a vendor sell you a HIPAA compliance program on the false premise that HIPAA applies to you when it does not.

Does ClinicSense, Jane, or Noterro make my practice HIPAA compliant?

No, and if you are not a covered entity the question does not arise in the first place. If you are covered, these platforms are business associates: they sign a BAA and secure the data inside their systems, which is real value. But no booking or notes platform supplies your Notice of Privacy Practices, your acknowledgment forms, your written policies, a Security Risk Analysis covering your whole practice, your training log, or your breach procedure. The software handles the data; the documentation layer is yours.

How would I accidentally become a covered entity?

Almost always through someone else's electronic transmission rather than a decision you made. The three common routes: switching on electronic eligibility verification inside your booking software, joining a clinic or panel that bills health insurers on your behalf, or hiring a billing service that files a claim for one client. Any of these makes you a covered entity, and once you are, the rules apply to all of your client information in any format, not just the insured clients. Revisit the question whenever your billing arrangement changes, and write down the answer you reached and when.

If you are covered: the eight documents

If the table above put you on the covered side, this is the document set you must be able to produce. It is the same set every covered practice needs, flavored with the vendors and records a massage practice actually has. Each item cites the rule that requires it, so you can verify any of it against the regulation.

  • Notice of Privacy Practices

    The notice you give every client, post in a clear and prominent place in the practice, and publish on your website, describing how you use and disclose client information.

    45 CFR § 164.520

  • NPP acknowledgment of receipt

    The form documenting your good-faith effort to obtain each client's written acknowledgment that they received the notice; it belongs in the intake packet at the first appointment.

    45 CFR § 164.520(c)(2)

  • Client authorization + rights request forms

    The written-permission form for disclosures HIPAA does not already permit, plus request forms for access, amendment, restrictions, and an accounting of disclosures. In massage this is mostly attorneys and insurers in injury cases.

    45 CFR § 164.508; §§ 164.522–164.528

  • Business Associate Agreements + vendor register

    A signed BAA with every vendor that touches client data, tracked in a register. For a massage practice that usually means your booking and notes platform (ClinicSense, MassageBook, Jane, Noterro, Vagaro), any outside billing service, cloud backup, and email.

    45 CFR § 164.502(e); § 164.504(e)

  • Security Risk Analysis

    The documented, accurate and thorough assessment of risks to electronic client data across every system that holds it, intake forms and SOAP notes included, not just the booking software: the most-cited deficiency in OCR enforcement.

    45 CFR § 164.308(a)(1)(ii)(A)

  • Privacy & security policies with a training log

    Your written rulebook for access, minimum-necessary use, and safeguards, plus documented training and a sanctions policy. In a solo practice this is short, but it still has to exist in writing.

    45 CFR § 164.530(b); § 164.308(a)(5); § 164.316

  • Breach notification procedure + breach log

    What to do when something goes wrong: notification without unreasonable delay and no later than 60 calendar days after discovery, plus your state's breach statute answered specifically.

    45 CFR §§ 164.400–414

  • Privacy Official & Security Official designation

    Names, in writing, the person responsible for your privacy policies and the person responsible for security. In a solo massage practice both are you, and the designation still has to be written down.

    45 CFR § 164.530(a); § 164.308(a)(2)

The full annotated table of contents, with what each document does and an honest binder-vs-software comparison, is on the HIPAA binder template page.

If you are not covered: what you still owe

Falling outside HIPAA does not put you outside privacy law. Every state regulates the confidentiality of health information held by licensed practitioners, most massage licensing boards impose their own ethics rules on client records, and consumer-protection statutes reach a practice that promises confidentiality and then fails to deliver it. None of that runs through HIPAA, and none of it goes away because HIPAA does not apply.

What that means practically is unglamorous. Write down how you handle client information and follow it. Keep SOAP notes and intake forms somewhere access-controlled rather than in a shared drive or a personal inbox. Check what your booking platform does with the data it holds and whether it will sign an agreement about it. If you ever share records with an attorney, insurer, or another provider, get the client’s written permission first.

The reason to be precise about this rather than buying a compliance program you do not need: a practice that thinks HIPAA applies when it does not tends to spend money on the wrong documents and still miss the state rules that actually govern it.

Sources

Last verified August 1, 2026. Educational self-help information, not legal advice and not a covered-entity determination for any specific practice. Whether HIPAA applies to your practice turns on its actual billing arrangements; confirm with the sources above and, where appropriate, a qualified attorney. State law may add stronger requirements, and frequently does for massage therapists.

Covered after all? Get every document your massage practice needs

The complete binder, built to order for your practice and state, with every policy citing the rule that requires it.

See the massage binder and pricing