PILLAR: Compliance Operations

Best HIPAA Compliant Payment Processing

Here is the part most vendor pages skip: a processor that only moves money generally does not need to be “HIPAA compliant” at all. HIPAA's payment-processing exception keeps pure card transactions outside the business-associate rules. The picture changes the moment your invoices, payment portal, or card-on-file records carry treatment details — and that is where healthcare-native platforms earn their fees.

For most small and mid-size practices, our pick is Rectangle Health (healthcare-native, from $40/month). Hospitals and health systems should look at InstaMed, and budget-minded practices can now use Square — which began offering a HIPAA BAA in 2026. All claims below verified 2026-08-24; see who HIPAA actually applies to for the wider rules.

Best for Most Practices

Rectangle Health

Healthcare-native from $40/mo, posts payments to your PM system, compliance tools built in

Best for Health Systems

InstaMed

J.P. Morgan's healthcare payments network — enterprise scale, BAA, deep EHR integration

Best on a Budget

Square

$0/mo, transparent card rates, and — new in 2026 — a HIPAA BAA on covered products

Cyanotype of a card terminal with a receipt curling from its slot beside a spare rollFIG · 01
A card terminal on a reception counter beside a receipt roll.

Does a payment processor need to be HIPAA compliant?

Usually not — and that surprises most practice managers. HIPAA's statute (section 1179) carves out financial institutions when they authorize, process, clear, settle, bill, transfer, reconcile, or collect payments for health care, whether by card, check, or electronic funds transfer. HHS confirmed in the 2013 Omnibus Rule preamble that the business-associate provisions do not apply to banking and financial institutions for those payment activities. In other words: swiping a patient's card is treated like any other retail charge, not a PHI disclosure that needs a Business Associate Agreement.

The Privacy Rule reinforces this from the other side: 45 CFR §164.501 defines “payment” to include billing, claims management, and collection activities, so a practice may disclose the minimum necessary information to get paid without patient authorization. The exception is narrow, though. It protects the transaction, not everything you happen to send alongside it. Where your setup falls determines whether you need any of the platforms below to sign a BAA:

Exempt — no BAA needed

Pure payment activity

  • Authorizing, processing, clearing, and settling a card charge
  • Transferring or reconciling funds to your bank account
  • A receipt showing amount, date, and practice name only

Covered by the payment-processing exception. The processor is not a business associate.

Gray zone — audit what you send

Payment plus incidental detail

  • Invoice line items naming the service (“Counseling session 5/12”)
  • Card-on-file records tied to appointment types
  • Payment reminder texts or emails that mention treatment

The transaction itself is exempt, but the descriptive data you attach may be PHI. Strip it, or use a vendor that signs a BAA.

Business associate — BAA required

Functions beyond payment

  • Vendor runs your accounts receivable or billing follow-up
  • Patient payment portal that displays statements or balances by visit
  • Vendor stores or analyzes claims, CPT codes, or diagnosis data

HHS is explicit: functions above and beyond payment processing make the vendor a business associate. Sign a BAA before PHI flows.

A practical test: could a stranger reading the processor's records learn anything about a patient's care beyond “they paid this clinic $180 on June 3”? If yes, you have left the exception. This matters most for self-pay workflows — the amounts on a good faith estimate or an Advance Beneficiary Notice are fine to charge, but the service descriptions on them do not belong in your processor's invoice fields.

Is Square HIPAA compliant?

Yes — with conditions, and the answer changed in 2026. For years the standard advice was that Square was fine for card-present payments under the payment exception but could not be trusted with anything touching PHI because it would not sign a BAA. That advice is now out of date: Square (Block, Inc.) publishes a HIPAA Business Associate Agreement, last updated March 16, 2026, incorporated into its service terms for healthcare sellers.

What changed: Square's 2026 BAA

Square's BAA covers its HIPAA-enabled offerings — the agreement names Square Appointments and Square Invoices among them — not every Square product. Consumer-side Buyer Services (Square Go, Square Pay, Square Profile, Local Offers) are explicitly excluded: data patients hand those apps is processed by Square for itself, outside the BAA.

Practical read for a practice: Square is now a legitimate option even when appointment types and invoice descriptions carry PHI — provided you stay inside the HIPAA-enabled products and confirm the BAA applies to your account configuration before the first charge. Security-wise, Square tokenizes card data, encrypts in transit, and maintains PCI DSS certification. If you use Square Appointments as your scheduler, note that dedicated healthcare schedulers still handle intake and reminders better — see our HIPAA-compliant scheduling comparison.

Fees are Square's standard retail rates (as of Aug 2026): 2.6% + 15¢ in person, 2.9% + 30¢ online, and 3.3% + 30¢ for card-not-present invoice payments on the free plan. No monthly fee is required, which keeps it the cheapest entry point on this page.

Is Stripe HIPAA compliant?

No. Stripe does not sign Business Associate Agreements, and as of August 2026 its publicly documented position is unchanged: it does not consider itself a business associate under HIPAA. Unlike Square, there is no healthcare carve-out to opt into.

No BAA — but not automatically off-limits

Because pure payment processing sits outside the business-associate rules, a practice can still lawfully run patient card payments through Stripe. The burden shifts entirely to you: nothing that qualifies as PHI may reach Stripe's systems, ever, because no contract protects it there.

If you keep Stripe — common for practices whose website builder or membership platform is welded to it — enforce these rules on every field your integration can write:

  • Charge descriptions: practice name and amount only — never “Therapy session” or a CPT code
  • Metadata and custom fields: no patient names tied to visit types, no diagnosis or treatment notes
  • Invoice line items: “Professional services” beats an itemized clinical description
  • Receipts and statement descriptors: your business name, not your specialty, where the specialty itself reveals care (e.g., an addiction clinic)
  • Integrations: check what your EHR or booking tool pushes into Stripe automatically — that pipe is the usual leak

Document this in your risk assessment as a deliberate control, the same way you would scope any vendor that touches your revenue cycle. If your invoices genuinely need clinical detail — itemized superbills, statement history, balances by visit — Stripe is the wrong tool; use a healthcare-native platform below that signs a BAA. Sending PHI to a vendor with no BAA is one of the most common HIPAA violations OCR sees.

Which payment platforms are worth comparing in 2026?

Two of these are general-purpose processors that healthcare borrowed (Square, Stripe); four are healthcare-native platforms built around the revenue cycle. The native platforms cost more but do the thing general processors cannot: touch PHI under a signed BAA and post payments back into your practice-management ledger.

Square

General-purpose processor that added a HIPAA BAA in 2026

Strengths

  • No monthly fee; hardware from a free magstripe reader
  • HIPAA BAA on covered products (Appointments, Invoices)
  • Transparent flat-rate pricing, next-day deposits
  • Appointments, invoicing, and card-on-file built in

Limitations

  • BAA covers only HIPAA-enabled products — Buyer Services excluded
  • No posting of payments into an EHR/PM ledger
  • 3.3% + 30¢ on free-plan invoice payments adds up
Best for: Cash-pay and small practices that want cheap, simple, and now BAA-covered

Stripe

Developer-first processor with no BAA — strict PHI hygiene required

Strengths

  • Best-in-class API, checkout, and subscription billing
  • 2.9% + 30¢ standard online rate, no monthly fee
  • Huge integration ecosystem (websites, booking, memberships)

Limitations

  • No BAA, and none planned — PHI must never reach it
  • No healthcare features: no EHR posting, no patient statements
  • Integrations can silently push appointment data into metadata
Best for: Online-first practices with a developer and a PHI-free payment flow

Rectangle Health

Practice Management Bridge — payments plus compliance for practices

Strengths

  • Healthcare-native: posts payments to your PM/EHR ledger
  • HIPAA, PCI, and OSHA compliance tooling in one platform
  • Text-to-pay, card-on-file, recurring payment plans
  • Packages from $40/mo; processing from 1.99% (as of Aug 2026)

Limitations

  • Processing rates are quote-based on volume and mix
  • More platform than a tiny cash-pay practice needs
  • Contract terms vary — review before signing
Best for: Small-to-mid practices that want payments and compliance in one vendor

InstaMed

J.P. Morgan's healthcare payments network for providers and payers

Strengths

  • Built for healthcare end to end; signs a BAA
  • Network processed $656B in healthcare payments 2022–2025
  • Integrates with major EHR/PM systems
  • Handles patient, payer, and payout flows in one rail

Limitations

  • Enterprise sales process; quote-based pricing
  • Overkill for solo and small practices
  • Implementation is a project, not a signup
Best for: Hospitals, health systems, and large groups consolidating payment rails

PayGround

Patient-facing digital wallet for medical bills across providers

Strengths

  • Patients manage and pay bills from multiple providers in one app
  • Free for patients; scheduling and payment tracking built in
  • Healthcare-only focus — designed around HIPAA from the start

Limitations

  • Provider-side pricing is quote-based (not published)
  • Younger platform with a smaller integration list
  • Wallet model needs patient adoption to pay off
Best for: Practices betting on a consumer-style patient payment experience

Clearent by Xplor

Xplor Pay — processing with EMR ledger automation for practices

Strengths

  • Pushes payments from terminal and web through to EMR ledgers
  • Text-to-pay, payment plans, and card-on-file
  • P2PE-validated, PCI DSS compliant infrastructure

Limitations

  • Quote-based pricing; no published rates
  • BAA availability not stated publicly — confirm in contract
  • Brand transition (Clearent → Xplor Pay) can confuse support paths
Best for: Practices whose EMR already partners with Xplor Pay for A/R automation

How do the payment platforms compare side by side?

The BAA row is the one that decides whether a platform may see PHI at all. “Partial” there means a BAA exists but is scoped (Square: HIPAA-enabled products only) or is not stated publicly and must be confirmed in the contract (PayGround, Clearent).

FeatureSquareStripeRectangleInstaMedPayGroundClearent
Signs a HIPAA BAA
Partial
No
Yes
Yes
Partial
Partial
Built for healthcare
No
No
Yes
Yes
Yes
Yes
Posts payments to EHR/PM ledger
No
No
Yes
Yes
Partial
Yes
Text-to-pay
Partial
Partial
Yes
Yes
Yes
Yes
Card-on-file / recurring plans
Yes
Yes
Yes
Yes
Yes
Yes
Patient statements or portal
No
No
Yes
Yes
Yes
Partial
In-person terminal
Yes
Yes
Yes
Yes
Partial
Yes
Published pricing
Yes
Yes
Partial
No
No
No
No monthly fee option
Yes
Yes
No
No
No
No
Compliance tooling (risk assessment, training)
No
No
Yes
No
No
No

Legend: = Yes · = Partial / scoped / confirm in contract · = No. Verified Aug 2026 against vendor sites.

PCI DSS vs HIPAA: where do they overlap?

Every processor on this page is PCI DSS compliant — that is the floor for accepting cards at all. Vendors love to blur the two, but PCI compliance says nothing about HIPAA, and vice versa. The controls overlap; the obligations, regulators, and penalties do not.

Rule of thumb: PCI governs the card number. HIPAA governs everything that reveals the card was used for health care. A terminal can be fully PCI validated while your receipt printer leaks PHI.

TopicPCI DSSHIPAAOverlap
What it protectsCardholder data (PAN, expiry, CVV, track data)Protected health information (any identifiable health or payment-for-care data)Partial
Who enforces itCard brands via your acquirer — contractual, not lawHHS Office for Civil Rights and state attorneys general — federal lawSeparate
Current version / rulePCI DSS v4.0.1; all v4 requirements mandatory since Mar 31, 2025Security Rule (45 CFR 164.302–318); Jan 2025 update still proposedSeparate
EncryptionRequired for stored PAN and transmission over open networks“Addressable” — required in practice once your risk analysis says soHigh
Multi-factor authenticationMandatory for all access into the cardholder data environmentNot yet mandatory; proposed in the pending Security Rule updatePartial
Risk assessmentTargeted risk analysis for specific requirementsEnterprise-wide risk analysis (164.308(a)(1)) — OCR's #1 enforcement findingPartial
Audit logsRetain 12 months, 3 months immediately availableRequired; retention set by your policy, documentation kept 6 yearsHigh
Vendor contractsService-provider responsibility matrixBusiness Associate Agreement — unless the payment exception appliesPartial
Penalty exposureBrand fines passed through by acquirer; loss of card acceptanceUp to $2.19M per violation category per year (2026 adjusted)Separate

The practical win: a PCI-scoped payment terminal on its own network segment, with tokenization so no card numbers touch your EHR, also shrinks your HIPAA attack surface. Fold both into one risk assessment rather than running two, and align your encryption standards to the stricter of the two (usually PCI).

What does HIPAA compliant payment processing cost?

Published rates as of August 2026. Healthcare-native platforms price on volume and card mix, so treat “custom quote” as a negotiation: a practice running $50k/month in cards should be quoting interchange-plus, not a flat rate.

PlatformMonthlyCard rateBAANote
Square$0 (Plus $49)2.6% + 15¢ in person; 2.9% + 30¢ onlineScopedInvoice card payments 3.3% + 30¢ on free plan
Stripe$02.9% + 30¢ onlineNoCustom rates at volume; no healthcare tier
Rectangle HealthFrom $40From 1.99% (quote)YesPackages tiered; higher tiers add compliance tools
InstaMedCustomCustom quoteYesEnterprise contract via J.P. Morgan
PayGroundCustomCustom quoteConfirmFree for patients; provider pricing not published
Clearent by XplorCustomCustom quoteConfirmOften bundled through EMR partner agreements

Rates change; confirm on the vendor's pricing page before signing. Hardware, chargeback fees, and PCI non-compliance fees are extra on every platform.

Which payment processor should your practice choose?

Start from your billing workflow, not the processor's marketing. The right answer depends on whether payments need to land in a clinical ledger and how much PHI your invoices carry.

Primary care or specialty group, 2–15 providers

Pick: Rectangle Health

You post co-pays and balances into a PM system all day. A processor that writes to the ledger and sends text-to-pay reminders pays for its $40+/mo in staff time alone.

Solo therapist or cash-pay clinician

Pick: Square (BAA-enabled products)

No monthly fee, card-on-file for no-shows, and since 2026 a BAA covering Appointments and Invoices. Keep session descriptions generic and you are inside both the exception and the BAA.

Hospital, health system, or large MSO

Pick: InstaMed

One network for patient payments, payer remittance, and payouts, integrated with the enterprise EHR. Nothing else on this list is built for that scale.

Online-first practice already on Stripe

Pick: Stripe, with a PHI-free flow

Lawful under the payment exception if the integration never writes clinical detail. Audit every metadata field your booking or EHR tool pushes, and document it.

Whichever you choose, the processor is only one link in the revenue cycle. Verify coverage up front with an insurance verification form, and run the billing compliance checklist annually so the data feeding the terminal is clean before it ever reaches a card network. Text-to-pay features also pull you into SMS rules — see our HIPAA compliant texting comparison for the consent side.

Quick Reference Card

If You NeedOur PickStarting At
Most small–mid practicesRectangle HealthFrom $40/mo
Cheapest with a BAASquare$0/mo
Hospital / health systemInstaMedCustom
Patient digital walletPayGroundCustom
EMR ledger automationClearent by XplorCustom
Online, PHI-free flowStripe$0/mo

Five-question payment-vendor check

  1. 1Does the vendor do anything beyond processing (A/R, statements, portal)? If yes, get a BAA.
  2. 2Strip service descriptions, CPT codes, and appointment types from invoice and metadata fields.
  3. 3Confirm the BAA's product scope in writing — Square's covers HIPAA-enabled products only.
  4. 4Keep the terminal PCI-scoped and tokenized so card numbers never enter the EHR.
  5. 5Log the decision and controls in your annual risk analysis.

The payment exception protects the transaction, not your habits around it. Document the scope in your risk assessment, keep a signed BAA for any vendor that sees more than a card number, and revisit the decision when your billing workflow changes.

Related Tools & Guides