Does HIPAA apply to a GLP-1 telehealth clinic that markets as a wellness platform?
The marketing framing is not the analysis, but neither is prescribing. Under 45 CFR §160.103 an operation becomes a covered entity by conducting a standard transaction adopted under Part 162 — claims, eligibility, prior authorization, claim status, remittance, or a retail pharmacy drug claim — or by having one conducted on its behalf. Ordinary e-prescribing under NCPDP SCRIPT is not among them, so prescribing a GLP-1 agonist electronically does not by itself make the clinic a covered entity. Calling the operation a wellness platform does not make it one either. Map the entities, find which one transacts or performs Business Associate work, and document the result — and note that state consumer-health privacy laws reach the data regardless of where HIPAA lands.
We use a telehealth platform — isn't compliance their responsibility?
The telehealth platform is a business associate to the clinic and is responsible for the platform's compliance condition, but the clinic remains responsible for its own compliance program — risk analysis, training, BAAs with all other vendors, breach notification. The platform's BAA covers the platform, not the clinic's broader operation.
Do I need a BAA with every compounding pharmacy partner?
Not automatically — classify each one. A pharmacy that dispenses to the patient is acting as a treating provider, and provider-to-provider treatment disclosures do not require a BAA. A pharmacy or fulfillment partner performing a function on the clinic's behalf — running the clinic's fulfillment workflow, handling its patient data as a service to the clinic — is a business associate under §160.103 and requires a written BAA under §164.308(b)(1) before PHI flows. A 503A or 503B designation does not decide this; the actual function does. Skipping the classification, or relying on one master BAA to cover unrelated partners, are both common gaps in this segment.
What state laws apply beyond HIPAA?
Washington's My Health My Data Act (RCW 19.373), Nevada's Consumer Health Privacy Act (SB 370), Connecticut's Personal Data Privacy Act, California's CMIA plus CPRA health-data provisions, and a growing list of states. These laws cover weight, dietary, and metabolic-health data explicitly, and each imposes consent, data-minimization, and breach-notification requirements distinct from HIPAA. Enforcement differs law by law and is worth checking per state rather than generalizing: Washington's MHMDA is enforceable by consumers through the state Consumer Protection Act and California's CMIA carries its own private right of action, while Nevada's and Connecticut's statutes are attorney-general enforced. HIPAA itself has no private right of action.
Are before/after photos for weight-loss tracking PHI?
When stored in connection with treatment, yes. Photos that document patient response to medication are part of the medical record under HIPAA and require the same protections as any other ePHI. Operators that store photos in consumer-grade cloud platforms without a BAA, or that allow staff to use personal-device camera rolls, are routinely exposed.
How do DEA telehealth controlled-substance rules affect GLP-1 compliance?
GLP-1 medications are not currently controlled substances, so the DEA telehealth-controlled-substance framework does not directly apply. However, clinics that also prescribe controlled medications (some weight-loss combinations include phentermine, Schedule IV) are subject to DEA telehealth rules in addition to HIPAA. The compliance approach for clinics with mixed prescribing should account for both.
We started as a consultation-only platform and grew into prescribing — do we have to retroactively comply?
HIPAA obligations attach prospectively from the date of becoming a CE — no retroactive penalty for the pre-prescribing period. But the records the clinic holds from that period, if they include PHI from current patients, fall under the Privacy Rule once the clinic is a CE. The practical implication: compliance must cover both prospective operations and the patient records inherited from the pre-prescribing period.
Does a GLP-1 clinic have to complete a HIPAA Security Risk Analysis?
Every covered entity and every Business Associate in the operating chain does, which is why the entity map has to come first. Where an organization is covered, it must conduct and document an accurate, thorough assessment of the risks affecting all its ePHI. For a GLP-1 operation that means the full patient journey — advertisement and eligibility screening, online intake and questionnaires, identity verification, clinical evaluation, prescribing, pharmacy fulfillment, monitoring, and discontinuation — plus the weight, photograph, biometric, and messaging data generated along the way, and the affiliate, analytics, and tracking technologies that receive health-related information. A single analysis covering only the clinical entity's EHR misses most of the operation.
Which of our GLP-1 vendors need Business Associate Agreements?
Any organization performing a function involving PHI on the covered entity's behalf: the telehealth platform, EHR, intake and questionnaire tools, identity-verification service, patient messaging and support platforms, billing and payment processors handling PHI, cloud storage, analytics and tracking vendors receiving health-related data, and the management company where one operates the clinical workflow. Pharmacies dispensing to the patient and laboratories performing tests are generally treating providers, not business associates — a 503A or 503B designation does not change that analysis, the actual function does. Affiliates and influencers collecting health information are only business associates if they act on behalf of a covered entity; otherwise they are a state consumer-health privacy problem, not a BAA problem.
Our brand, clinical entity, and prescriber network are separate companies — which one is the covered entity?
Possibly none of them, possibly several, and the answer changes what each one owes. Coverage attaches to the specific legal entity that conducts an adopted standard transaction, or has one conducted on its behalf — not to the brand the patient sees. A consumer-facing marketing company that never transacts is typically outside HIPAA while still being reached by state consumer-health privacy law. The professional entity employing the prescribers is usually where coverage lands if anyone bills. A management company operating the clinical workflow is frequently a Business Associate of that entity. The failure mode in this segment is not getting the answer wrong; it is never running the analysis, so no entity has documented what it owes and each assumes another one is handling it.
Is the government's Security Risk Assessment Tool mandatory?
No. The government's SRA Tool is one method designed to help small and medium-sized organizations perform the required analysis. HIPAA requires the underlying risk analysis — not the use of one particular tool. Patient Protect provides its own guided SRA and connects the findings directly to remediation, policies, tasks, and documentation.
Does our EHR make the practice HIPAA compliant?
No. An EHR may provide important safeguards for the records it maintains, but it does not conduct the practice's complete SRA, remediate every identified risk, train the workforce, manage all policies, identify every Business Associate, prepare the practice for incidents, or preserve the full body of compliance evidence.
How much does Patient Protect cost for a GLP-1 clinic?
Patient Protect Basic costs $39 per office per month and includes up to 25 personnel. It includes the guided Security Risk Analysis, risk management, policies, workforce training, workforce and vendor management, BAA tracking, compliance scoring, and centralized documentation needed to operate the practice's core HIPAA compliance program.