Covered entity status
A med spa is a covered entity under 45 CFR §160.103 when it transmits PHI electronically in connection with a covered transaction — most commonly e-prescribing under NCPDP SCRIPT (which is required the moment the medical director prescribes any medication), electronic insurance claims (rare in med spas but possible for medical-necessity cases), or electronic referrals to or from other providers. Many med spas trigger CE status without realizing it: a medical director who prescribes one medication electronically, a referral to a dermatologist that goes through the EHR, or an electronic lab order for pre-procedure bloodwork are each independent CE-establishing events.

