Guide

Books without PHI: why QuickBooks does not need a BAA — if you behave

Summary

Not if you keep it that way: bookkeeping software only needs a Business Associate Agreement if patient health information actually flows into it. Record revenue in aggregate, patient payments under generic categories rather than name-linked entries with diagnosis or treatment detail, and reconcile per-patient billing inside your EHR or PM system instead—both of which already carry a BAA. The moment identifiable clinical or per-patient billing detail enters your books, the software becomes a business associate and needs one.

By Gale Editorial · Updated 2026-07-27. Every figure cited to a dated source. How we write.

The short answer: usually no, if you keep PHI out

Ordinary bookkeeping software doesn't need a HIPAA Business Associate Agreement in the typical case, because the typical case never puts protected health information into it at all. A BAA is required only when a vendor creates, receives, maintains, or transmits PHI on your behalf 1—and a bookkeeping platform tracking aggregate revenue, categorized expenses, and bank reconciliations usually never touches anything that meets that bar.

This assumes you're a covered entity doing the entering in the first place, which almost every solo clinical practice is; the covered-entity test is worth confirming once if your practice mixes clinical and non-clinical services, since the BAA question only arises after that first one is settled.

What actually makes a vendor a business associate

A business associate is a vendor that creates, receives, maintains, or transmits PHI on a covered entity's behalf—not simply a vendor a covered entity happens to pay 1. Your malpractice insurer, your landlord, and your accounting software's payment processor are all vendors you pay in the course of running a practice, and none of them automatically becomes a business associate just by invoicing you or moving money.

What flips a vendor into business-associate territory is what data actually passes through its systems, not the size of the check you write it or how central it is to running the practice. The baa map is the fuller list of which practice vendors cross that line and which don't—EHRs and clearinghouses always do, because clinical and claims data is the entire point of what they hold; a bookkeeping platform depends entirely on what you choose to put into it, which is exactly why the same product can be PHI-free for one practice and a business associate for another.

What counts as PHI in a bookkeeping context

Protected health information is individually identifiable health information: anything tied to a named or identifiable person that relates to their health condition, the care they received, or payment for that care 2. A patient's name attached to a diagnosis code, a treatment date, or even the simple fact that they received care from your practice all clear that bar.

An aggregate revenue total—gross collections for the month—clears it in the other direction: it's a business figure, not information about any identifiable person. The line moves the moment you attach that number to a name. Psychotherapy notes sit at the strictest end of this spectrum—psychotherapy notes get extra protection even within a clinical record—which is one more reason they, and anything resembling clinical detail, have no reason to ever appear in a bookkeeping entry.

The discipline that keeps your books out of BAA territory

Keeping bookkeeping software PHI-free is a habit, not a software setting: never enter a patient's name in a memo field, never note a diagnosis or service type tied to an individual, and never let a per-patient invoice history live inside books software the way it might live inside your EHR. Reconcile at the batch level—total card deposits for the day, total insurance payments received for the week—rather than patient by patient.

If you're a workforce of one, training a workforce of one is really just this discipline, repeated consistently: the habit of entering a deposit as a number, not a name, every single time, so there's never a decision to make about whether one exception is safe.

When bookkeeping software does need a BAA

The calculus changes the moment you use a bookkeeping platform's built-in customer or class fields to track individual patients by name against their payments, session dates, or balances—that's per-patient billing detail living inside the software, and it's PHI the moment it's there regardless of what the platform is designed for. Some solo practices use their bookkeeping software's customer list as an informal patient ledger because it's convenient, avoiding a second login; that convenience is exactly what turns an ordinarily PHI-free tool into one that needs a BAA.

If your workflow genuinely requires per-patient financial tracking beyond what your PM or EHR provides, that's a signal to get a BAA in place before entering the first patient record, not a reason to skip the agreement because the software "is just for bookkeeping." A vendor's marketing describing itself as general small-business software doesn't change what the law asks about the data actually stored—only what you put in the system does that.

If PHI slips in anyway

An occasional slip—a memo field that got a patient's name typed into it once—isn't automatically a reportable breach, but a pattern of it is a real exposure: unsecured PHI that's been compromised triggers notification obligations to affected individuals, and to HHS, on a clock that starts the moment you discover it 3. The fix is prevention, not cleanup—search existing entries periodically for anything that looks like a name next to a payment, and correct the habit before it produces a real incident.

Keeping the books PHI-free also simplifies what happens if the subpoena arrives for financial records in an unrelated dispute—a set of books that never held clinical detail has nothing clinical to produce, which is a meaningfully smaller problem than the alternative.

The software itself is still a deductible expense

None of this changes the ordinary tax treatment of the software: a bookkeeping subscription is a deductible business expense like any other ordinary and necessary cost of running the practice 4, entirely separate from the HIPAA question. Choosing books software with an eye toward how easily it keeps patient detail out—clean categories, no built-in patient-record features you'd be tempted to use—is worth weighing alongside price and features, and if you outsource the entering itself, a bookkeeper, CPA, or fractional CFO should follow exactly the same discipline you would: numbers, not names.

Common questions

Not without treating it as a place PHI now lives. A customer or class field with a patient's name tied to payments or session activity is exactly the kind of per-patient detail that turns ordinary bookkeeping software into a business associate. Keep patient-level billing in your EHR or PM system, which already carries a BAA, and use the books for aggregate totals only.

If your books genuinely never contain PHI, the person working in them doesn't need one either—there's nothing protected passing through their hands. The moment any patient-identifiable clinical or billing detail enters the books, though, that changes for both the software and anyone with access to it, including a bookkeeper or CPA.

Often yes, because the fact that someone is a patient of your practice at all is itself health information once it's tied to their identity. A name attached to a payment for your services implies they received care from you—treat any name-linked entry as a risk, not just entries that also mention a diagnosis or treatment detail.

Correct the entry to a generic description, and check nearby records from around the same period for the same habit, since a single instance often isn't isolated. Going forward, build the aggregation habit into how you or your bookkeeper enters deposits, so the correction is a one-time cleanup rather than an ongoing pattern.

Yes—the BAA question is about what data exists and who can access it, not which specific product holds it. A spreadsheet with patient names next to payment amounts carries the same exposure as software with the same information, and the same aggregation discipline—totals, not names—applies whether you're using a bookkeeping platform or a plain spreadsheet.

Run your practice on Gale

The software is free. Gale earns one flat 3.5% all-in per paid transaction — only on transactions that actually pay. No subscription, no setup fee, no network cut.

Start or manage a practice →

References

  1. 1.HHS Office for Civil Rights (2026). Business Associates. U.S. Department of Health and Human Services. linkThat a vendor becomes a business associate only when it creates, receives, maintains, or transmits PHI on the practice's behalf, requiring a BAA.
  2. 2.HHS Office for Civil Rights (2026). Summary of the HIPAA Privacy Rule. U.S. Department of Health and Human Services. linkThe definition of protected health information as individually identifiable health information, used to distinguish aggregate revenue figures from PHI.
  3. 3.HHS Office for Civil Rights (2026). Breach Notification Rule. U.S. Department of Health and Human Services. linkThat compromised unsecured PHI triggers notification obligations to individuals and HHS on a clock starting at discovery, as the consequence of PHI slipping into an unprotected system.
  4. 4.Internal Revenue Service (2026). Guide to business expense resources. Internal Revenue Service. linkThat a bookkeeping software subscription is deductible as an ordinary and necessary business expense, separate from the HIPAA question.

https://www.gale.care/for-providers/bk-books-software-baa · 4 sources. Competitor details are cited to dated public sources and maintained as they change; figures are estimates, not commitments. Synthetic demonstration.

Findability, by specialty

How practices like yours get found in local search and AI answers — the honest playbook, per specialty.

SEO for private practices · SEO for AI search / answer engines (all verticals)