PILLAR: Compliance Operations
Best HIPAA Compliant Payment Processing
Here is the part most vendor pages skip: a processor that only moves money generally does not need to be “HIPAA compliant” at all. HIPAA's payment-processing exception keeps pure card transactions outside the business-associate rules. The picture changes the moment your invoices, payment portal, or card-on-file records carry treatment details — and that is where healthcare-native platforms earn their fees.
For most small and mid-size practices, our pick is Rectangle Health (healthcare-native, from $40/month). Hospitals and health systems should look at InstaMed, and budget-minded practices can now use Square — which began offering a HIPAA BAA in 2026. All claims below verified 2026-08-24; see who HIPAA actually applies to for the wider rules.
Best for Most Practices
Rectangle Health
Healthcare-native from $40/mo, posts payments to your PM system, compliance tools built in
Best for Health Systems
InstaMed
J.P. Morgan's healthcare payments network — enterprise scale, BAA, deep EHR integration
Best on a Budget
Square
$0/mo, transparent card rates, and — new in 2026 — a HIPAA BAA on covered products
FIG · 01Does a payment processor need to be HIPAA compliant?
Usually not — and that surprises most practice managers. HIPAA's statute (section 1179) carves out financial institutions when they authorize, process, clear, settle, bill, transfer, reconcile, or collect payments for health care, whether by card, check, or electronic funds transfer. HHS confirmed in the 2013 Omnibus Rule preamble that the business-associate provisions do not apply to banking and financial institutions for those payment activities. In other words: swiping a patient's card is treated like any other retail charge, not a PHI disclosure that needs a Business Associate Agreement.
The Privacy Rule reinforces this from the other side: 45 CFR §164.501 defines “payment” to include billing, claims management, and collection activities, so a practice may disclose the minimum necessary information to get paid without patient authorization. The exception is narrow, though. It protects the transaction, not everything you happen to send alongside it. Where your setup falls determines whether you need any of the platforms below to sign a BAA:
Exempt — no BAA needed
Pure payment activity
- Authorizing, processing, clearing, and settling a card charge
- Transferring or reconciling funds to your bank account
- A receipt showing amount, date, and practice name only
Covered by the payment-processing exception. The processor is not a business associate.
Gray zone — audit what you send
Payment plus incidental detail
- Invoice line items naming the service (“Counseling session 5/12”)
- Card-on-file records tied to appointment types
- Payment reminder texts or emails that mention treatment
The transaction itself is exempt, but the descriptive data you attach may be PHI. Strip it, or use a vendor that signs a BAA.
Business associate — BAA required
Functions beyond payment
- Vendor runs your accounts receivable or billing follow-up
- Patient payment portal that displays statements or balances by visit
- Vendor stores or analyzes claims, CPT codes, or diagnosis data
HHS is explicit: functions above and beyond payment processing make the vendor a business associate. Sign a BAA before PHI flows.
A practical test: could a stranger reading the processor's records learn anything about a patient's care beyond “they paid this clinic $180 on June 3”? If yes, you have left the exception. This matters most for self-pay workflows — the amounts on a good faith estimate or an Advance Beneficiary Notice are fine to charge, but the service descriptions on them do not belong in your processor's invoice fields.
Is Square HIPAA compliant?
Yes — with conditions, and the answer changed in 2026. For years the standard advice was that Square was fine for card-present payments under the payment exception but could not be trusted with anything touching PHI because it would not sign a BAA. That advice is now out of date: Square (Block, Inc.) publishes a HIPAA Business Associate Agreement, last updated March 16, 2026, incorporated into its service terms for healthcare sellers.
What changed: Square's 2026 BAA
Square's BAA covers its HIPAA-enabled offerings — the agreement names Square Appointments and Square Invoices among them — not every Square product. Consumer-side Buyer Services (Square Go, Square Pay, Square Profile, Local Offers) are explicitly excluded: data patients hand those apps is processed by Square for itself, outside the BAA.
Practical read for a practice: Square is now a legitimate option even when appointment types and invoice descriptions carry PHI — provided you stay inside the HIPAA-enabled products and confirm the BAA applies to your account configuration before the first charge. Security-wise, Square tokenizes card data, encrypts in transit, and maintains PCI DSS certification. If you use Square Appointments as your scheduler, note that dedicated healthcare schedulers still handle intake and reminders better — see our HIPAA-compliant scheduling comparison.
Fees are Square's standard retail rates (as of Aug 2026): 2.6% + 15¢ in person, 2.9% + 30¢ online, and 3.3% + 30¢ for card-not-present invoice payments on the free plan. No monthly fee is required, which keeps it the cheapest entry point on this page.
Is Stripe HIPAA compliant?
No. Stripe does not sign Business Associate Agreements, and as of August 2026 its publicly documented position is unchanged: it does not consider itself a business associate under HIPAA. Unlike Square, there is no healthcare carve-out to opt into.
No BAA — but not automatically off-limits
Because pure payment processing sits outside the business-associate rules, a practice can still lawfully run patient card payments through Stripe. The burden shifts entirely to you: nothing that qualifies as PHI may reach Stripe's systems, ever, because no contract protects it there.
If you keep Stripe — common for practices whose website builder or membership platform is welded to it — enforce these rules on every field your integration can write:
- Charge descriptions: practice name and amount only — never “Therapy session” or a CPT code
- Metadata and custom fields: no patient names tied to visit types, no diagnosis or treatment notes
- Invoice line items: “Professional services” beats an itemized clinical description
- Receipts and statement descriptors: your business name, not your specialty, where the specialty itself reveals care (e.g., an addiction clinic)
- Integrations: check what your EHR or booking tool pushes into Stripe automatically — that pipe is the usual leak
Document this in your risk assessment as a deliberate control, the same way you would scope any vendor that touches your revenue cycle. If your invoices genuinely need clinical detail — itemized superbills, statement history, balances by visit — Stripe is the wrong tool; use a healthcare-native platform below that signs a BAA. Sending PHI to a vendor with no BAA is one of the most common HIPAA violations OCR sees.
Which payment platforms are worth comparing in 2026?
Two of these are general-purpose processors that healthcare borrowed (Square, Stripe); four are healthcare-native platforms built around the revenue cycle. The native platforms cost more but do the thing general processors cannot: touch PHI under a signed BAA and post payments back into your practice-management ledger.
Square
General-purpose processor that added a HIPAA BAA in 2026
Strengths
- No monthly fee; hardware from a free magstripe reader
- HIPAA BAA on covered products (Appointments, Invoices)
- Transparent flat-rate pricing, next-day deposits
- Appointments, invoicing, and card-on-file built in
Limitations
- BAA covers only HIPAA-enabled products — Buyer Services excluded
- No posting of payments into an EHR/PM ledger
- 3.3% + 30¢ on free-plan invoice payments adds up
Stripe
Developer-first processor with no BAA — strict PHI hygiene required
Strengths
- Best-in-class API, checkout, and subscription billing
- 2.9% + 30¢ standard online rate, no monthly fee
- Huge integration ecosystem (websites, booking, memberships)
Limitations
- No BAA, and none planned — PHI must never reach it
- No healthcare features: no EHR posting, no patient statements
- Integrations can silently push appointment data into metadata
Rectangle Health
Practice Management Bridge — payments plus compliance for practices
Strengths
- Healthcare-native: posts payments to your PM/EHR ledger
- HIPAA, PCI, and OSHA compliance tooling in one platform
- Text-to-pay, card-on-file, recurring payment plans
- Packages from $40/mo; processing from 1.99% (as of Aug 2026)
Limitations
- Processing rates are quote-based on volume and mix
- More platform than a tiny cash-pay practice needs
- Contract terms vary — review before signing
InstaMed
J.P. Morgan's healthcare payments network for providers and payers
Strengths
- Built for healthcare end to end; signs a BAA
- Network processed $656B in healthcare payments 2022–2025
- Integrates with major EHR/PM systems
- Handles patient, payer, and payout flows in one rail
Limitations
- Enterprise sales process; quote-based pricing
- Overkill for solo and small practices
- Implementation is a project, not a signup
PayGround
Patient-facing digital wallet for medical bills across providers
Strengths
- Patients manage and pay bills from multiple providers in one app
- Free for patients; scheduling and payment tracking built in
- Healthcare-only focus — designed around HIPAA from the start
Limitations
- Provider-side pricing is quote-based (not published)
- Younger platform with a smaller integration list
- Wallet model needs patient adoption to pay off
Clearent by Xplor
Xplor Pay — processing with EMR ledger automation for practices
Strengths
- Pushes payments from terminal and web through to EMR ledgers
- Text-to-pay, payment plans, and card-on-file
- P2PE-validated, PCI DSS compliant infrastructure
Limitations
- Quote-based pricing; no published rates
- BAA availability not stated publicly — confirm in contract
- Brand transition (Clearent → Xplor Pay) can confuse support paths
How do the payment platforms compare side by side?
The BAA row is the one that decides whether a platform may see PHI at all. “Partial” there means a BAA exists but is scoped (Square: HIPAA-enabled products only) or is not stated publicly and must be confirmed in the contract (PayGround, Clearent).
| Feature | Square | Stripe | Rectangle | InstaMed | PayGround | Clearent |
|---|---|---|---|---|---|---|
| Signs a HIPAA BAA | Partial | No | Yes | Yes | Partial | Partial |
| Built for healthcare | No | No | Yes | Yes | Yes | Yes |
| Posts payments to EHR/PM ledger | No | No | Yes | Yes | Partial | Yes |
| Text-to-pay | Partial | Partial | Yes | Yes | Yes | Yes |
| Card-on-file / recurring plans | Yes | Yes | Yes | Yes | Yes | Yes |
| Patient statements or portal | No | No | Yes | Yes | Yes | Partial |
| In-person terminal | Yes | Yes | Yes | Yes | Partial | Yes |
| Published pricing | Yes | Yes | Partial | No | No | No |
| No monthly fee option | Yes | Yes | No | No | No | No |
| Compliance tooling (risk assessment, training) | No | No | Yes | No | No | No |
Legend: ✓ = Yes · – = Partial / scoped / confirm in contract · ✗ = No. Verified Aug 2026 against vendor sites.
PCI DSS vs HIPAA: where do they overlap?
Every processor on this page is PCI DSS compliant — that is the floor for accepting cards at all. Vendors love to blur the two, but PCI compliance says nothing about HIPAA, and vice versa. The controls overlap; the obligations, regulators, and penalties do not.
Rule of thumb: PCI governs the card number. HIPAA governs everything that reveals the card was used for health care. A terminal can be fully PCI validated while your receipt printer leaks PHI.
| Topic | PCI DSS | HIPAA | Overlap |
|---|---|---|---|
| What it protects | Cardholder data (PAN, expiry, CVV, track data) | Protected health information (any identifiable health or payment-for-care data) | Partial |
| Who enforces it | Card brands via your acquirer — contractual, not law | HHS Office for Civil Rights and state attorneys general — federal law | Separate |
| Current version / rule | PCI DSS v4.0.1; all v4 requirements mandatory since Mar 31, 2025 | Security Rule (45 CFR 164.302–318); Jan 2025 update still proposed | Separate |
| Encryption | Required for stored PAN and transmission over open networks | “Addressable” — required in practice once your risk analysis says so | High |
| Multi-factor authentication | Mandatory for all access into the cardholder data environment | Not yet mandatory; proposed in the pending Security Rule update | Partial |
| Risk assessment | Targeted risk analysis for specific requirements | Enterprise-wide risk analysis (164.308(a)(1)) — OCR's #1 enforcement finding | Partial |
| Audit logs | Retain 12 months, 3 months immediately available | Required; retention set by your policy, documentation kept 6 years | High |
| Vendor contracts | Service-provider responsibility matrix | Business Associate Agreement — unless the payment exception applies | Partial |
| Penalty exposure | Brand fines passed through by acquirer; loss of card acceptance | Up to $2.19M per violation category per year (2026 adjusted) | Separate |
The practical win: a PCI-scoped payment terminal on its own network segment, with tokenization so no card numbers touch your EHR, also shrinks your HIPAA attack surface. Fold both into one risk assessment rather than running two, and align your encryption standards to the stricter of the two (usually PCI).
What does HIPAA compliant payment processing cost?
Published rates as of August 2026. Healthcare-native platforms price on volume and card mix, so treat “custom quote” as a negotiation: a practice running $50k/month in cards should be quoting interchange-plus, not a flat rate.
| Platform | Monthly | Card rate | BAA | Note |
|---|---|---|---|---|
| Square | $0 (Plus $49) | 2.6% + 15¢ in person; 2.9% + 30¢ online | Scoped | Invoice card payments 3.3% + 30¢ on free plan |
| Stripe | $0 | 2.9% + 30¢ online | No | Custom rates at volume; no healthcare tier |
| Rectangle Health | From $40 | From 1.99% (quote) | Yes | Packages tiered; higher tiers add compliance tools |
| InstaMed | Custom | Custom quote | Yes | Enterprise contract via J.P. Morgan |
| PayGround | Custom | Custom quote | Confirm | Free for patients; provider pricing not published |
| Clearent by Xplor | Custom | Custom quote | Confirm | Often bundled through EMR partner agreements |
Rates change; confirm on the vendor's pricing page before signing. Hardware, chargeback fees, and PCI non-compliance fees are extra on every platform.
Which payment processor should your practice choose?
Start from your billing workflow, not the processor's marketing. The right answer depends on whether payments need to land in a clinical ledger and how much PHI your invoices carry.
Primary care or specialty group, 2–15 providers
Pick: Rectangle Health
You post co-pays and balances into a PM system all day. A processor that writes to the ledger and sends text-to-pay reminders pays for its $40+/mo in staff time alone.
Solo therapist or cash-pay clinician
Pick: Square (BAA-enabled products)
No monthly fee, card-on-file for no-shows, and since 2026 a BAA covering Appointments and Invoices. Keep session descriptions generic and you are inside both the exception and the BAA.
Hospital, health system, or large MSO
Pick: InstaMed
One network for patient payments, payer remittance, and payouts, integrated with the enterprise EHR. Nothing else on this list is built for that scale.
Online-first practice already on Stripe
Pick: Stripe, with a PHI-free flow
Lawful under the payment exception if the integration never writes clinical detail. Audit every metadata field your booking or EHR tool pushes, and document it.
Whichever you choose, the processor is only one link in the revenue cycle. Verify coverage up front with an insurance verification form, and run the billing compliance checklist annually so the data feeding the terminal is clean before it ever reaches a card network. Text-to-pay features also pull you into SMS rules — see our HIPAA compliant texting comparison for the consent side.
Quick Reference Card
| If You Need | Our Pick | Starting At |
|---|---|---|
| Most small–mid practices | Rectangle Health | From $40/mo |
| Cheapest with a BAA | Square | $0/mo |
| Hospital / health system | InstaMed | Custom |
| Patient digital wallet | PayGround | Custom |
| EMR ledger automation | Clearent by Xplor | Custom |
| Online, PHI-free flow | Stripe | $0/mo |
Five-question payment-vendor check
- 1Does the vendor do anything beyond processing (A/R, statements, portal)? If yes, get a BAA.
- 2Strip service descriptions, CPT codes, and appointment types from invoice and metadata fields.
- 3Confirm the BAA's product scope in writing — Square's covers HIPAA-enabled products only.
- 4Keep the terminal PCI-scoped and tokenized so card numbers never enter the EHR.
- 5Log the decision and controls in your annual risk analysis.
The payment exception protects the transaction, not your habits around it. Document the scope in your risk assessment, keep a signed BAA for any vendor that sees more than a card number, and revisit the decision when your billing workflow changes.
Related Tools & Guides
Good Faith Estimate Generator
The estimate you hand a self-pay patient before any payment is collected.
Advance Beneficiary Notice (ABN) Guide
When Medicare may not pay and the patient becomes the payer.
Who Does HIPAA Apply To?
Covered entities, business associates, and the entities HIPAA skips.
BAA Template Generator
Generate a Business Associate Agreement for vendors that do handle PHI.
Medical Billing Compliance Checklist
Audit the billing workflow that feeds your payment processor.