Is Square HIPAA Compliant? Yes, in Scope
Square publishes a HIPAA BAA that attaches by use, naming Appointments and Invoices in scope. Square Buyer Services are expressly outside it.
Written and reviewed by the Patient Protect team — Joseph A. Perrin, CTO (federal infrastructure background, platform security architect), Angie Perrin, CSO (CHPC, 10+ years clinical practice), and Alexander Perrin, CEO (20 years enterprise SaaS, primary author of the Secure Care Research Institute research program). See editorial standards.

Yes, within a scope Square defines — and the scope is both wider and narrower than most guidance claims, including an earlier version of this page.
Square (now Block, Inc.) publishes a HIPAA Business Associate Agreement, and it works differently from most: there is nothing to sign. Square's support documentation puts it plainly — if you are a covered entity or business associate and use Square in a way that causes Square to create, receive, maintain or transmit PHI on your behalf, then you agree to the HIPAA BAA.
The scope clause is where the real answer lives. The BAA "applies only to the Services and configurations where Square is acting as your Business Associate, including when you use Square Appointments, Invoices, or other features that have been explicitly identified as HIPAA-enabled by Square." Appointments and Invoices are named. We previously listed both as outside the BAA, which was wrong.
Square attaches two important qualifications to that. Whether a service supports HIPAA compliance "depends on how it is configured and used." And Square "may, but is not obligated to, identify particular products or configurations as HIPAA-enabled" — not all services are, and evaluating whether a given one is appropriate for PHI is explicitly your responsibility. So the question is never "does Square sign a BAA." It is "is this specific product, in this configuration, one Square has identified as HIPAA-enabled."
The exclusion most practices will never think to check
Square carves out an entire category by name. Square Buyer Services — Square Go, Square Profile, Square Pay and Square Local Offers — are consumer-facing products, and Square states it processes data from them as an independent controller, not as a business associate. That holds even when the data concerns appointment bookings, payment information or transaction history, and Square is explicit that a customer's use of Buyer Services does not create a business associate relationship with you.
The practical shape of that: a patient who books through your Square Appointments setup is on one side of the line, and a patient who finds you through a consumer Square surface is on the other, and the difference is not visible from your dashboard.
What Square's BAA Covers
Square's BAA scope is narrow by design. It covers the payment transaction — card present, card not present, and online payments processed through Square's payment infrastructure.
Payment processing through Square Terminal and Square Register. When a patient swipes, taps, or inserts a card at the point of sale, that transaction is covered. The BAA applies to the payment data in transit and at rest within Square's payment processing systems.
Square Online checkout. Payments collected through Square's online checkout flow are covered under the BAA. This applies to the transaction itself — the card number, amount, and authorization — not to any additional information collected on the page.
The transaction, not the context. This is the critical distinction. The BAA covers the fact that a payment occurred, the amount, and the card data. It does not cover what the payment was for, who the patient is in a clinical sense, or any health information associated with that transaction.
Square's BAA is available by request. It is not automatic. You must contact Square, request the BAA, and execute it before processing any payments that could be associated with healthcare services.
Working Out Which Square Products You Can Use
Square names two products in its scope clause and leaves the rest to be established. Here is how that lands on the products healthcare practices actually use, and what still needs asking.
Square Appointments. Appointments is named in Square's BAA scope clause, so the product itself is on the right side of the line. What still matters is the content: service types that name procedures — "root canal," "adjustment," "intake session" — make the scheduling record PHI, and PHI inside a covered product still has to be handled like PHI. Coverage is not a reason to be careless with what you write in the field.
Square Messages. Messages is not among the features Square names in the scope clause, and Square is explicit that not all services are HIPAA-enabled. Unless Square has identified your messaging configuration as HIPAA-enabled, treat it as outside — any exchange referencing treatment, symptoms or a specific procedure is PHI on a platform you have not confirmed is covered.
Square Invoices. Named in the scope clause, so invoicing is covered. That is worth knowing because invoices are where PHI most reliably appears: a line item reading "D2740 Porcelain Crown" or "90837 Psychotherapy 60 min" ties an identifiable patient to a treatment. Coverage means Square is contractually your business associate for it — not that the data stops being PHI.
Square Marketing. Not named in the scope clause. Campaign content that references health conditions, treatment history or appointment types is PHI, and marketing to a patient list needs its own analysis regardless of platform. Confirm with Square before any of it touches patient data.
Customer notes and records in the Square Dashboard. Not named either. The directory lets you store notes, visit history and preferences, which is exactly the shape clinical detail drifts into. Keep it out unless Square confirms the configuration is HIPAA-enabled.
Square Buyer Services. The one unambiguous exclusion. Square Go, Square Profile, Square Pay and Square Local Offers sit outside the BAA by name, with Square acting as an independent controller rather than your business associate — including for appointment bookings and transaction history made through them.
The Healthcare Payment Processing Question
Payment processing occupies a specific position under HIPAA. The payment transaction itself — card authorization, settlement, and processing — has a partial exemption when the data involved is limited to financial information. But that exemption has limits.
A charge for "$250 — dental services" contains minimal clinical information. A charge for "$250 — root canal, tooth #14" associates an identifiable individual with a specific diagnosis and treatment. The second example is unambiguously PHI.
The distinction comes down to what information travels with the transaction. When you keep transaction descriptions generic — "professional services," "office visit," "dental services" — the payment data stays in the financial realm. When you attach procedure names, diagnostic codes, or treatment details to the charge, you have crossed the line into protected health information.
This is why Square's narrow BAA scope can work for healthcare practices — but only if you are disciplined about what information you attach to each transaction.
Common Mistakes Healthcare Practices Make with Square
These are the patterns that turn a compliant payment workflow into a HIPAA violation.
Adding treatment details to Square invoices. Line items that include procedure names, CDT codes, CPT codes, or treatment descriptions create PHI in a system without BAA coverage. Every invoice with clinical detail is a separate compliance gap.
Using Square Appointments with procedure types as service names. When your appointment types are named "Root Canal," "TMJ Evaluation," or "Psychiatric Assessment" instead of generic labels, the scheduling system associates patients with specific healthcare services.
Storing clinical notes in Square's customer directory. The notes field is not something Square names as HIPAA-enabled, and Square puts the burden of evaluating a configuration on you. Treatment observations, medication lists, allergies or clinical reminders belong in the chart, not in a CRM field whose coverage you have not confirmed.
Using Square Messages for patient communication about treatment. Confirming appointments is one thing. Discussing symptoms, treatment plans, medication changes, or lab results through Square Messages is transmitting PHI through an uncovered channel.
Assuming the BAA covers all Square products. This is the most dangerous mistake. Square's ecosystem is designed to be an all-in-one business platform — payments, scheduling, invoicing, marketing, messaging. The BAA covers only one of those functions. Practices that adopt the full Square suite without understanding the BAA scope create compliance exposure across every uncovered product.
How to Use Square Safely in Healthcare
Square can work in a healthcare practice — if you keep its role narrow.
Use Square exclusively for payment processing. Accept payments through Square Terminal, Square Register, or Square Online. Do not expand Square's role into scheduling, messaging, invoicing, or customer relationship management.
Strip treatment details from transaction descriptions. Use "Professional Services," "Office Visit," or "Dental Services" as line items. Never include procedure names, diagnostic codes, or treatment specifics in any Square transaction record.
Use your practice management system for everything else. Scheduling, clinical notes, patient communication, treatment-specific billing, and insurance claims belong in a HIPAA-compliant practice management platform with its own BAA. Square handles the card swipe. Your PMS handles the clinical context.
Execute the BAA before processing any payments. Contact Square and request the BAA. Do not process healthcare-related payments until the agreement is signed and in place.
Train your staff on the boundary. Every team member who touches Square needs to understand what goes into Square (payment amount and generic description) and what stays in the practice management system (everything clinical). One staff member entering "crown prep" in a Square invoice description creates a violation.
Where Payments Fit in Your Compliance Program
The next move is establishing which of your Square products Square has identified as HIPAA-enabled — that is a question for Square rather than for us, and the answer decides where patient data can sit. While you are asking, read the agreement against what a BAA has to contain. Stripe is the instructive comparison: it takes the opposite position and restricts PHI in its terms outright. And if billing detail is what carries the clinical information, QuickBooks is the other half of that flow.
Frequently Asked Questions
Does Square sign a BAA?
Yes. Square (Block, Inc.) will sign a Business Associate Agreement, but it covers payment processing only — transactions through Square Terminal, Square Register, and Square Online checkout. The BAA must be requested directly from Square. It does not cover Square Appointments, Messages, Invoices, Marketing, or customer records.
Is Square Appointments HIPAA compliant?
No. Square Appointments is not covered under Square's BAA. If your appointment types or customer records contain information that associates a patient with a healthcare service, that data constitutes PHI on an uncovered platform. Use a HIPAA-compliant practice management system for scheduling.
Can I use Square for dental or medical billing?
You can use Square to process the payment itself — the card transaction. You should not use Square for detailed billing that includes procedure codes, treatment descriptions, or clinical line items. Clinical billing belongs in your practice management system. Square should see only the payment amount and a generic service description.
Is Square Terminal HIPAA compliant?
Square Terminal is covered under Square's BAA for payment processing. The device itself processes card transactions, and those transactions are within the BAA's scope. The compliance risk is not the terminal hardware — it is what information you associate with the transaction in Square's software.
What about Square for telehealth payments?
Square Online checkout can process telehealth payments under the BAA, provided the transaction description does not include treatment details. A charge labeled "Telehealth Visit — $150" is lower risk than "Telehealth — CBT Session, Anxiety Disorder." Keep descriptions generic and process the clinical billing through your practice management system.
Can I use Square and still be HIPAA compliant?
Yes — if you limit Square to payment processing, execute the BAA, and ensure no PHI enters any other Square product. The key is discipline: Square handles the payment, your practice management system handles everything clinical. Most compliance violations with Square happen not because the payment processing fails, but because practices expand Square's role beyond what the BAA covers. The boundary between what each vendor may hold is the subject of HIPAA-compliant tools.
Patient Protect tracks your full compliance state, including vendor BAAs and payment processing configurations, starting at $39/month.
Corrections & Updates
Healthcare security data changes as investigations progress, vendors update systems, and laws and guidance evolve. If you see something outdated, incomplete, or incorrect — or have newer source material — we’d appreciate hearing from you.
