Card-not-present payments may be available to a medical spa, but no universal approval category or federal license guarantees acceptance. A payment provider may evaluate the services, sales channels, marketing, refunds, data flows, medication-related activity, transaction history, and states served. Legal, privacy, clinical, and underwriting reviews are separate questions.
Card-present and card-not-present payments are different
A card-present transaction generally occurs when a customer uses a card at the business through an in-person terminal. A card-not-present transaction occurs when the card is not physically presented—for example, through a hosted checkout page, invoice, payment link, recurring billing arrangement, or telephone payment interface.
The distinction describes how a transaction is processed; it does not determine whether the model is lawful. A med spa might use card-present payments for an in-office service and card-not-present payments for a deposit, consultation, prepaid package, membership, or balance due after an appointment.
For underwriting, the central question is whether the remote workflow accurately reflects the business the provider approved. Do not misdescribe services, route unrelated transactions through an account, or change the model without reviewing the provider’s terms. Approval is not guaranteed and may depend on risk policies, documentation, refund exposure, transaction history, disputes, and contractual restrictions.
The payments hub guide provides broader context for evaluating processing infrastructure.
Map the payment use cases first
Before selecting a workflow, separate each type of charge:
This inventory distinguishes ordinary service payments from arrangements that may receive additional review.
Privacy and HIPAA questions are separate from card acceptance
A card transaction is not automatically the same as a HIPAA-standard electronic healthcare transaction. HHS describes covered healthcare providers in relation to electronic transmission of health information for transactions for which HHS has adopted standards. A financial institution processing payment-card transactions in its ordinary banking role generally does not become a business associate merely because it facilitates payment. See HHS guidance on business associates and HHS’s explanation of who must comply with HIPAA.
That distinction does not remove the med spa’s own privacy and security responsibilities. A payment workflow may still touch names, appointment details, treatment references, diagnoses, clinical notes, or other protected health information. The business should assess whether it is a HIPAA covered entity and identify vendors that create, receive, maintain, or transmit protected health information on its behalf.
Before connecting a hosted checkout, scheduling platform, CRM, text-payment tool, patient portal, or cloud service, document what information the vendor receives, whether it stores or transmits electronic protected health information, whether a business-associate agreement may be required, and what security controls and breach procedures apply. HHS’s HIPAA cloud-computing guidance and Security Rule summary provide relevant background.
Payment descriptions should be reviewed for unnecessary clinical detail while still meeting accounting, refund, disclosure, and recordkeeping needs. Operators comparing subscription models can also review recurring billing for hormone clinics, while disclosing the actual services and business model accurately.
Advertising and checkout language should align
FTC health-claims materials primarily address advertising and consumer-protection representations. They emphasize that health-related claims must not be deceptive or unsupported. Review the med spa’s website, social media, promotions, affiliates, and sales communications against the FTC’s health-claims guidance.
Separately, the payment flow should clearly explain:
- What the customer is purchasing.
- Whether the charge is one-time or recurring.
- Cancellation, refund, expiration, and rescheduling terms.
- Conditions for redeeming a prepaid service.
- Whether clinical eligibility or provider review is required.
- Whether a promotion describes a possible benefit rather than a guaranteed result.
These checkout and billing practices may raise operational, contractual, or state-law questions beyond the scope of the FTC health-claims material. Payment should not imply a guaranteed medical outcome, prescription, treatment eligibility, or provider approval.
Medication-related activity changes the review
A med spa accepting payment for its own lawful services is not necessarily operating an online pharmacy. The review becomes more involved when the business sells or ships prescription medication, describes itself as a pharmacy, collects payment before required clinical and legal steps are completed, or presents medication as available without appropriate review.
FDA consumer guidance identifies prescription requirements where applicable, clear business and contact information, and appropriate state pharmacy licensure as considerations for safer online pharmacy operations. See How to Buy Medicines Safely From an Online Pharmacy and BeSafeRx resources.
FDA materials do not provide blanket approval for a med spa’s payment model. If medication-related activity is proposed, clearly identify the roles of the med spa, clinical organization, prescriber, pharmacy, medical director, and fulfillment entity. Qualified legal and clinical professionals should review the arrangement in every state served. This article does not address medication sourcing, prescribing, dosing, administration, or patient-use instructions.
A four-gate eligibility workflow
1. Define the transaction
List every charge—consultation, deposit, treatment, membership, product, or medication-related service. Record when payment occurs, expected refund situations, and whether recurring authorization is involved.
2. Test the data flow
Trace information from booking or intake through the payment interface, receipt, accounting system, CRM, patient portal, and storage environment. Minimize clinical details in payment fields and identify vendors that may handle protected health information.
3. Review customer representations
Compare the website, advertisements, checkout language, consent screens, refund policy, subscription terms, and receipts. Remove unsupported health or outcome claims and clarify that payment does not guarantee clinical eligibility or a medical result.
4. Submit the real model for underwriting
Provide accurate information about services, website content, sales channels, transaction patterns, refunds, disputes, recurring billing, medication-related activity, and states served. Confirm that approval covers the actual model rather than an abbreviated description.
This is a screening workflow, not a promise of approval.
State and local review still matters
This article is a national overview, not a state-law determination. No target state was supplied, and the approved research does not verify any state-specific rule. Owners should obtain a separate review for every state where patients are located or services are offered.
That review may need to address practitioner licensing, medical-practice and facility requirements, telehealth rules, pharmacy and prescription requirements, deposits, prepaid packages, memberships, gift cards, cancellation fees, automatic renewals, privacy, breach notification, consumer protection, surcharges, convenience fees, and payment-method rules. A provider’s underwriting approval does not replace this review, and compliance with one state requirement does not guarantee payment approval.
Prepare for provider review
An underwriting file may include the legal business name, ownership information, service descriptions, website and advertising materials, refund and cancellation policies, sample receipts, expected transaction volumes, fulfillment timelines, dispute procedures, and recurring-billing details. If a clinician, pharmacy, or fulfillment company is involved, identify each entity and explain its role.
Owners comparing account options can also review common reasons telehealth merchant-account applications are declined. A decline does not prove that every provider will reach the same decision, but it may indicate that the submitted model, documentation, or risk profile needs closer examination.
What to do next
Start with the transaction map, data-flow review, state footprint, and customer-facing terms. Then ask prospective providers what documentation and restrictions apply to the specific model. Do not search for guaranteed approval claims or omit material business activity.
MDLaunchr is the brand behind WhiteLabelClinic.com, a white-label telehealth infrastructure platform designed to help qualified businesses evaluate and coordinate technology, operational, compliance, clinical-network, and fulfillment relationships. Explore how MDLaunchr and WhiteLabelClinic.com can support a compliance-first telehealth launch.
Frequently asked questions
Are card-not-present payments illegal for med spas?
The federal sources reviewed do not establish a blanket prohibition or a single federal licensing regime for card-not-present payments at med spas. Eligibility depends on the actual services, sales practices, data handling, state requirements, medication-related activity, and provider underwriting.
Does an online card payment automatically make a processor a HIPAA business associate?
Not necessarily. HHS explains that a financial institution processing payment-card transactions in its ordinary banking role generally is not a business associate merely because it facilitates payment. Other vendors may qualify based on how they handle protected health information.
Can a med spa evaluate recurring billing?
Yes, it may evaluate recurring billing subject to applicable law, clear authorization, understandable renewal terms, cancellation procedures, refund controls, and provider requirements. Recurring billing should reflect the actual service relationship.
Is a med spa an online pharmacy if it accepts payment remotely?
Not automatically. The classification depends on the business’s activities and representations. Selling or shipping prescription medication or coordinating medication fulfillment can create additional pharmacy, clinical, and state-law questions.
Does payment-provider approval prove compliance?
No. Underwriting approval is a private provider decision and does not establish compliance with HIPAA, advertising rules, medical-practice requirements, pharmacy rules, consumer-protection laws, or other state obligations.
Written and reviewed by MDLaunchr's clinical and compliance team. We build white-label telehealth infrastructure for founders, creators, and healthcare operators—covering providers, pharmacy, technology, and compliance.
This article is for general informational and educational purposes only and is not medical, legal, or regulatory advice. It does not create a provider-patient relationship and should not be used to diagnose or treat any condition. Telehealth and compounding regulations vary by state and change over time—consult qualified legal, clinical, and compliance professionals before launching or operating a telehealth program.
Frequently asked questions
Are card-not-present payments illegal for med spas?
The federal sources reviewed do not establish a blanket prohibition or a single federal licensing regime for card-not-present payments at med spas. Eligibility depends on the actual services, sales practices, data handling, state requirements, medication-related activity, and provider underwriting.
Does an online card payment automatically make a processor a HIPAA business associate?
Not necessarily. HHS explains that a financial institution processing payment-card transactions in its ordinary banking role generally is not a business associate merely because it facilitates payment. Other vendors may qualify based on how they handle protected health information.
Can a med spa evaluate recurring billing?
Yes, it may evaluate recurring billing subject to applicable law, clear authorization, understandable renewal terms, cancellation procedures, refund controls, and provider requirements. Recurring billing should reflect the actual service relationship.
Is a med spa an online pharmacy if it accepts payment remotely?
Not automatically. The classification depends on the business’s activities and representations. Selling or shipping prescription medication or coordinating medication fulfillment can create additional pharmacy, clinical, and state-law questions.
Does payment-provider approval prove compliance?
No. Underwriting approval is a private provider decision and does not establish compliance with HIPAA, advertising rules, medical-practice requirements, pharmacy rules, consumer-protection laws, or other state obligations.
- U.S. Department of Health & Human Services — Business AssociatesWho Must Comply with HIPAA Privacy StandardsCloud ComputingLaws Regulations
- U.S. Food & Drug Administration — How Buy Medicines Safely Online PharmacyBesaferx Resources Consumers
- Federal Trade Commission — Health Claims