DrinCloud

HomeBlog

Legal

The legal checklist for cash-pay clinics

HIPAA and BAAs, TCPA consent, the Good Faith Estimate, e-prescribing mandates by state, registration and insurance. What a cash-pay clinic must have in order.

July 28, 2026 · 7 min read

A common misunderstanding almost cost a colleague her practice: "I don't bill insurance, so most of the healthcare rules don't apply to me." Half true, and the wrong half is expensive. Dropping insurance removes an enormous amount of machinery, claims, clearinghouses, payer audits, MIPS reporting. It does not remove HIPAA, it does not remove the No Surprises Act, and it adds one federal law most clinic owners have never read: the TCPA.

Here is the checklist we walk new cash-pay owners through, with the numbers attached. One caveat that applies to every single line: details vary by state, verify with your state board and a local attorney before you rely on any of this.

1. HIPAA and the Business Associate Agreement

Strictly speaking, HIPAA covered-entity status is triggered by transmitting certain electronic transactions to payers. A pure cash practice that never touches an insurer may sit in a gray zone. In practice that gray zone is worthless as a defense, for three reasons:

  • Most states have their own medical privacy laws that apply regardless of HIPAA status, and some (California, Texas, New York) are stricter.
  • The FTC has been fining health businesses for privacy failures under its own authority, no HIPAA required.
  • The moment one patient submits your superbill to their PPO, you have entered the payer ecosystem.

So run the practice as if HIPAA fully applies. The penalty structure gives you the incentive: civil fines are tiered by culpability, from a bit over $100 per violation at the lowest tier to more than $50,000 per violation at the "willful neglect, not corrected" tier, with annual caps that run into the millions. A single lost laptop with an unencrypted patient list can be counted as one violation per record.

The practical to-do list is short:

  1. A written risk assessment. HHS publishes a free Security Risk Assessment tool; a solo practice can complete it in an afternoon.
  2. A signed Business Associate Agreement (BAA) with every vendor that touches patient data: your EHR, your email provider, your text-messaging service, your cloud storage, your billing processor if it sees clinical data. No BAA, no vendor. If a software company charges extra for the BAA or reserves it for the enterprise tier, that is a tell.
  3. Encryption in transit and at rest, unique logins per employee, and automatic logoff.
  4. Annual staff training with a signed attendance sheet, and a written breach response plan.

None of this requires a consultant for a small practice. It requires an afternoon and discipline.

2. TCPA: the law that fines you per text message

The Telephone Consumer Protection Act governs automated calls and SMS. Appointment reminders sent by software are squarely inside it. Statutory damages run $500 per message, up to $1,500 per message for willful violations, and TCPA class actions against medical and dental offices are a real cottage industry, because every patient in your database received the same texts.

What keeps you safe:

  • Written consent at intake. A checkbox with clear language: "I agree to receive appointment reminders and practice communications by SMS. Message and data rates may apply. Reply STOP to opt out." Store the date and the wording.
  • Honor opt-outs immediately. STOP must actually stop everything automated.
  • A2P 10DLC registration. Since carriers rolled out 10DLC, any business texting from a regular number must register its brand and campaign through its messaging provider. Unregistered traffic gets filtered or blocked, and the registration itself is your evidence of legitimate use. Your reminder software should handle the registration; ask them to show you.

Marketing texts (recall campaigns, birthday offers) need consent language that covers marketing specifically, not just reminders. Two checkboxes cost you nothing at intake and save you a class action later.

3. The Good Faith Estimate: mandatory since 2022

This is the one that surprises new cash-pay owners most. Under the No Surprises Act, since January 1, 2022, every provider must give uninsured and self-pay patients a written Good Faith Estimate (GFE) of expected charges, before or at the time of scheduling. Not on request. By default.

The mechanics:

  • Scheduled at least 3 business days out: GFE within 1 business day of scheduling. At least 10 business days out: within 3 business days.
  • The GFE lists expected services, their codes where applicable, and expected charges, plus your name, NPI and TIN.
  • If the final bill exceeds the GFE by $400 or more, the patient can take you to the federal patient-provider dispute resolution process for a $25 filing fee, and the burden is on you to justify the difference.
  • Keep copies. The estimate is part of the record.

For a clinic with published flat prices this is close to free to comply with: the GFE is your price list on a template with your identifiers. It is also, honestly, a sales asset. A patient who receives a clear written estimate before the visit trusts you more than one who hears "it depends." If you sell packages or treatment plans, the estimate doubles as the quote. We wrote more about turning transparency into a closing tool in the pieces on superbills and reimbursement and pricing.

4. E-prescribing: check your state before you pick your tools

There is no federal requirement that a cash-pay clinic prescribe electronically for non-controlled substances. States, however, have moved on their own. As of the last few years, California, New York, Florida, Michigan, Minnesota and Delaware are among the states mandating electronic prescribing for most or all prescriptions, with exceptions that vary (low-volume prescribers, technical failures, certain drug classes). Texas, by contrast, still permits paper for non-controlled substances; controlled substances are electronic-only almost everywhere under state EPCS rules.

The operational consequence: if you prescribe in a mandate state, you need an e-prescribing platform, and if your practice-management software does not include one (ours does not, and we say so on the features page), you budget a standalone e-Rx tool, typically in the range of $30-80 per prescriber per month. If you rarely prescribe, check whether your state's exception thresholds cover you. And verify the current rule with your board: this list changes almost every legislative session.

5. Registration, entity and the corporate practice of medicine

Three structural items people discover late:

  • Professional entity. Most states require licensed professionals to practice through a professional entity (PLLC or professional corporation), not a standard LLC. California goes further: no PLLCs at all, physicians use a Professional Corporation. Formation costs run roughly $100-800 in state fees depending on the state, plus publication requirements in a few (New York's can add several hundred dollars).
  • Corporate practice of medicine. In many states a non-physician cannot own a medical practice. If a spouse, investor or MSO structure is involved, get legal advice before signing anything.
  • Clinic registration or facility licensing. A private office usually does not need a facility license, but some states require registering the practice location, a fictitious-name permit for a trade name (California requires one), or special registration if you dispense drugs, operate lasers, or run an ambulatory surgery setting. Ask your board directly; the answer is state-specific and free.

6. Insurance: malpractice, cyber, general liability

Dropping insurers does not drop your exposure to patients.

PolicyWhat it coversRealistic annual cost (small practice)
Malpractice / professional liabilityClaims of negligent careTherapists and counselors often $400-1,500 · physicians commonly $4,000-12,000+, specialty and state dependent
Cyber liabilityBreach response, notification, ransomwareRoughly $500-2,000
General liabilitySlip-and-fall, propertyRoughly $400-1,000

Two details worth the premium conversation: whether the malpractice policy is claims-made (cheaper now, needs tail coverage when you leave) or occurrence, and whether the cyber policy covers regulatory fines and patient notification costs, which are the actual expenses after a breach. Notification alone can run several dollars per patient, and a 3,000-patient database makes that real money.

The one-page checklist

ItemCostFrequency
Risk assessment + written HIPAA policies$0 (HHS tool) + your timeAnnual review
BAAs with every data vendor$0, refuse vendors who chargeOnce per vendor
Staff HIPAA training$0-30 per personAnnual
TCPA consent language at intake$0Every new patient
A2P 10DLC registrationUsually $0-50 via providerOnce
Good Faith Estimate workflow$0 with templatesEvery self-pay patient
e-Rx platform (mandate states, if prescribing)$30-80/prescriber/monthMonthly
Professional entity + registrations$100-800 + extrasOnce + annual reports
Malpractice, cyber, general liabilitySee table aboveAnnual

Nothing on this list is exotic and almost nothing is expensive. The pattern among practices that get burned is not ignorance of medicine, it is treating the administrative layer as something to "get to later." Later is when the class action arrives.

If you are still at the planning stage, the step-by-step guide to opening a cash-pay practice puts these items in order alongside the NPI, EIN and entity paperwork. And when you evaluate software, make the legal layer part of the evaluation: BAA included at every price, consent captured at intake, documented security practices, and clean superbills for the patients who will chase reimbursement on their own.

DrinCloud is practice software built only for cash-pay clinics, with the BAA, SMS consent capture and superbills included on every plan. Fifteen days free, no card: start here.

← All articles

See it in your own practice

Fifteen days free, sample data already loaded, no credit card.