Concierge Medicine Billing: A Practical Guide to HIPAA Compliance
Concierge medicine billing can deliver a premium patient experience while staying fully compliant with HIPAA. This guide explains how HIPAA applies to concierge practices, how to manage Protected Health Information across membership and billing workflows, and what to know about Medicare, Medicaid, and key federal fraud and abuse laws. You will learn where Business Associate Agreements fit, how the HIPAA Privacy Rule and HIPAA Security Rule shape day-to-day operations, and how the Breach Notification Rule affects incident response.
HIPAA Applicability to Concierge Medicine
When HIPAA applies
HIPAA applies to a concierge practice when you are a covered entity—that is, when you electronically transmit standard transactions (for example, claims, remittance, eligibility, claim status, or referrals/authorizations) with a health plan or via a clearinghouse. If you bill insurers for any services, check benefits, or exchange claim data electronically, your concierge practice must follow HIPAA across privacy, security, and breach notification requirements.
If you are truly cash-only
Some concierge practices operate entirely on self-pay membership and do not conduct any HIPAA standard electronic transactions. In that narrow case, you may fall outside HIPAA’s “covered entity” definition. Even then, you will likely interact with vendors that handle patient information, and patients expect HIPAA-grade safeguards. Adopting HIPAA-aligned policies and security controls remains a best practice and reduces risk if your billing model evolves.
Action steps
- Inventory your electronic transactions to confirm covered-entity status and document the determination.
- If any part of your organization conducts standard transactions while other parts do not, consider a documented hybrid-entity designation and apply HIPAA to the designated health care components.
- Issue a Notice of Privacy Practices, maintain required policies, and train staff if you are covered.
Business Associates in Concierge Medicine
Who counts as a business associate
A business associate is any non-workforce vendor that creates, receives, maintains, or transmits PHI on your behalf for functions like claims, billing, data storage, or patient communications. In concierge medicine, common business associates include EHR and practice management platforms, revenue cycle and clearinghouse partners, telehealth and secure messaging vendors, cloud hosting and backup providers, analytics/reporting tools, mail houses handling statements, and marketing vendors that use PHI for targeted outreach.
Pure payment processors that only move funds without accessing PHI are generally not business associates. If a vendor uses patient data beyond simple payment processing—such as storing diagnosis-linked invoices or sending appointment reminders with clinical context—it becomes a business associate.
Business Associate Agreements
Execute Business Associate Agreements with each qualifying vendor. Strong agreements define permitted uses and disclosures, require reasonable safeguards under the HIPAA Security Rule, mandate prompt breach reporting, flow down obligations to subcontractors, and specify termination, data return, and destruction rights at contract end.
Due diligence and oversight
- Vet security practices (encryption, access controls, logging, incident response) before onboarding.
- Limit vendors to the minimum PHI necessary and disable nonessential data sharing.
- Review BAAs and vendor risk at least annually or upon major service changes.
Protected Health Information in Concierge Medicine
What qualifies as PHI/ePHI
Protected Health Information includes any individually identifiable information about a patient’s health, care, or payment for care. In concierge settings, PHI often appears in membership agreements that describe covered services, care plans, referrals, lab and imaging results, secure messages, visit summaries, and invoices that reveal diagnoses or procedures. Electronic PHI (ePHI) spans EHR data, portals, email, texting platforms, and cloud storage tied to patient care or payment.
Minimum Necessary and patient rights
- Apply the Minimum Necessary standard to billing, membership administration, and outreach—share only what’s needed for the task.
- Honor access, amendment, and accounting-of-disclosures rights and keep clear request logs.
- When a patient pays out of pocket in full, be prepared to honor appropriate requests to restrict disclosure of that specific service to a health plan.
Common risky workflows
- Unsecured texting or personal email for clinical or billing questions—move to secure, documented channels.
- Shared staff logins for scheduling or billing—replace with unique user IDs and role-based access.
- Spreadsheets tracking membership status with clinical details—consolidate into your EHR or another secured system with auditing and backups.
Core HIPAA Rules Overview
HIPAA Privacy Rule
The HIPAA Privacy Rule governs how you may use and disclose PHI for treatment, payment, and health care operations, and when patient authorization is required. It also requires a Notice of Privacy Practices, applies the Minimum Necessary standard to most non-treatment uses, and sets patient rights for access and restrictions—highly relevant in concierge billing where self-pay and membership models are common.
HIPAA Security Rule
The HIPAA Security Rule requires administrative, physical, and technical safeguards for ePHI. For concierge billing this means a written risk analysis, role-based access, unique logins, multi-factor authentication where feasible, encryption in transit and at rest, device and patch management, workforce training, vendor oversight, and ongoing monitoring with audit logs and alerts.
Breach Notification Rule
The Breach Notification Rule requires you to assess any impermissible use or disclosure of unsecured PHI, document a risk assessment, and notify affected individuals without unreasonable delay and no later than 60 days after discovery when notification is required. You must also notify regulators and, when thresholds are met, the media. Business associates must notify you of breaches they discover so you can fulfill your obligations.
Ready to simplify HIPAA compliance?
Join thousands of organizations that trust Accountable to manage their compliance needs.
Governance and documentation
- Maintain current policies, BAAs, risk analyses, training records, and incident logs.
- Reassess risks at least annually and after major changes (new vendors, new services, or expanded data sharing).
- Test your breach response playbook with tabletop exercises that include billing and membership scenarios.
Medicare Rules for Concierge Physicians
Two pathways: remain enrolled or opt out
Concierge physicians can either remain enrolled in Medicare or formally opt out. Your billing and membership design depends on that choice. Staying enrolled allows you to continue billing Medicare for covered services while offering a separate membership for non-covered amenities. Opting out requires compliant private contracts with beneficiaries and prohibits submitting claims to Medicare for your services during the opt-out period.
If you remain enrolled in Medicare
- Membership fees must cover only non-covered services and amenities (for example, extended non-covered wellness services, enhanced communication options, or convenience features).
- For any covered service, you must bill Medicare (and collect applicable cost-sharing) and you may not charge patients extra or “balance bill” beyond allowed amounts.
- Do not use membership fees to routinely waive copays or deductibles; that can implicate beneficiary inducement rules.
- Avoid bundling covered services into the membership (for example, annual wellness visits or other covered preventive services). If you offer a non-covered “executive physical,” define it carefully to avoid overlap with covered benefits.
If you opt out of Medicare
- Enter into compliant private contracts with Medicare beneficiaries before providing non-emergency services.
- Do not submit claims to Medicare for your services during the opt-out period; beneficiaries generally cannot seek Medicare reimbursement for those services.
- Structure membership benefits and pricing transparently so patients understand they are paying privately for your services.
Operational tips
- Map every membership deliverable to its coverage status and keep a crosswalk that is reviewed regularly.
- Train staff on when an Advance Beneficiary Notice is appropriate for a truly non-covered service and when it is not.
- Audit claims and membership invoices to ensure you never charge twice—once via Medicare and again via membership—for the same covered service.
Medicaid Considerations
Medicaid programs and contracts typically prohibit charging enrollees more than permitted cost-sharing for covered services. If you are enrolled with Medicaid or contracted with a Medicaid managed care plan, you generally may not require membership fees that function as payment for covered access or services. Routine waiver of Medicaid cost-sharing can also create compliance risk.
Patients may choose to self-pay for non-covered concierge amenities that are truly outside their Medicaid benefit, but state rules and managed care contracts vary. If you do not enroll with Medicaid and do not hold yourself out as a Medicaid provider, some states still restrict what you may charge enrollees for services within the Medicaid benefit. Verify requirements before launching or marketing a membership product to Medicaid beneficiaries.
Federal Fraud and Abuse Laws
Anti-Kickback Statute
The Anti-Kickback Statute prohibits offering or receiving anything of value to induce or reward referrals for items or services payable by federal health care programs. In concierge models, watch for risky features like free or discounted memberships tied to referrals, routine waiver of cost-sharing for federal program beneficiaries, or revenue-sharing with referral sources. Structure any compensation or discounts to fit an applicable safe harbor or otherwise meet risk-reduction principles.
Stark Law
Stark Law prohibits physician self-referrals for designated health services under Medicare unless an exception applies. If your concierge practice owns or refers to in-house diagnostics or therapy, ensure arrangements meet an exception such as in-office ancillary services, and that any compensation is fair market value, commercially reasonable, and not based on the volume or value of referrals.
Beneficiary inducements
Civil Monetary Penalties rules restrict giving Medicare or Medicaid beneficiaries items or services that could influence selection of a provider. Be cautious with “perks” in memberships (for example, transportation, devices, or gift cards). Some exceptions exist for items of nominal value or certain patient engagement and care coordination tools, but document the basis for any such program.
Practical guardrails
- Set membership pricing using a fair-market-value analysis unrelated to federal program volume.
- Separate non-covered amenities (membership) from covered services (claims) and keep clean documentation.
- Prohibit routine waivers of copays/deductibles; use need-based, policy-driven exceptions with documentation if allowed.
- Obtain legal review of any arrangement involving referrals, discounts, or shared revenues.
Bottom line: keep membership benefits non-covered and clearly defined, maintain rigorous HIPAA controls over PHI, and design financial relationships to avoid inducement or self-referral risk. With those guardrails, concierge medicine billing can remain compliant while delivering the access and personalization patients expect.
FAQs
What defines a business associate under HIPAA in concierge medicine?
A business associate is a non-workforce vendor that creates, receives, maintains, or transmits PHI for your practice’s functions—such as billing, claims processing, data hosting, analytics, patient messaging, or mailing statements. EHR vendors, clearinghouses, RCM companies, telehealth platforms, and cloud providers are typical examples. You must have Business Associate Agreements with these vendors that define permitted uses, safeguards, breach reporting, and subcontractor obligations.
How does HIPAA apply to electronic medical billing?
If you electronically submit standard transactions like claims, remittance, or eligibility checks, you are a HIPAA covered entity and must comply with the HIPAA Privacy Rule, the HIPAA Security Rule, and the Breach Notification Rule. That means issuing a Notice of Privacy Practices, applying Minimum Necessary to billing data, implementing administrative/physical/technical safeguards for ePHI, executing BAAs with vendors, training your workforce, and maintaining documentation and audit trails.
Can concierge physicians charge Medicare patients a membership fee?
Yes, but only for non-covered services and amenities if you remain enrolled in Medicare. Covered services must still be billed to Medicare with applicable cost-sharing and without extra “access” fees. Alternatively, you can opt out of Medicare and use private contracts; in that case you do not submit claims to Medicare and beneficiaries generally cannot seek Medicare reimbursement for your services.
What are the penalties for HIPAA violations in medical billing?
HIPAA penalties are tiered based on the level of culpability—from unknowing to willful neglect—and can include substantial civil monetary penalties per violation category per year, corrective action plans, and ongoing oversight. Serious or intentional misconduct can also trigger criminal liability. Beyond fines, breaches and violations can damage patient trust and lead to contractual and reputational consequences.
Ready to simplify HIPAA compliance?
Join thousands of organizations that trust Accountable to manage their compliance needs.