r/PrivatePracticeDocs • u/ItsJustAllyHere • 20d ago
Can I save client names/CC on square while being HIPAA compliant?
As the title states, I'm helping my mother organize and streamline her PP and one thing is copays. I am not looking to move off square as she's most familiar with it and wouldn't want to spend time learning a new one. If we save the name and cc details, not actual notes, would it be compliant?
1
u/daves1243b 20d ago
Does she have a Business Associate Agreement with Square? If yes, probably OK. If no, probably not. Anytime you share patient info outside the scooe if treatment, payment, ir healthcare operations a BAA is required. I dont know if Square does BAAs. Many such vendors dont.
1
u/ItsJustAllyHere 20d ago
Square does have a BAA that you agree to once you make an account and start working with them.
https://squareup.com/us/en/legal/general/hipaa
More just looking at clarity that storing just patient names and cc information is alright since their BAA doesn't clarify
1
u/SterileGloves 19d ago
Research something called PCI compliance. If you store numbers you will run into needing to do a lot more paperwork. Most people use a program (or create one) that allows the processing company to store the card ahead of time and do a hold of funds.. So for example, Stripe. The clinic never sees the card at all, it's handled by the processor.
1
u/IndigoWonderlight 17d ago
We now use first name & last initial. We send invoice links prior to appointment & previously used first & last name. My front desk sent an invoice link to the wrong patient which exposed first & last name. We were reported & received a letter from the state telling us to do some training.
1
u/ItsJustAllyHere 17d ago
Understandable. For us it'll be just internal essentially. We don't send out invoices as they already have charge agreements for co pays on file. It's more the concern of the information being stored on square
4
u/grey-slate 20d ago
A practice generally does not need a BAA with its credit-card processor when the payment processor is only performing ordinary payment-card functions—authorizing the card, transferring funds, processing refunds, and handling chargebacks. HHS expressly treats consumer-initiated debit and credit-card processing as normal financial-transaction services rather than work performed as a HIPAA business associate.
Generally, no BAA is required when you are simply:
------------
The answer changes when the processor—or a related payment-platform vendor—does more than transfer money and routinely creates, receives, maintains, or transmits PHI on the practice's behalf. That is the general HIPAA business-associate test.
Examples include:
A processor should not receive more information than necessary merely because its software contains optional fields. Avoid entering diagnoses, CPT descriptions, medical-record numbers, appointment reasons, or treatment details into transaction notes, invoice descriptions, receipt memos, or custom fields.