Doxy.me utilizes Stripe.com to process patient credit cards and deposit that money into your bank account. Here's how you can use Stripe and still maintain compliance.
Stripe and PHI
Although processing payments through a credit-card processor can generate personally identifiable information, Health and Human Services (HHS) has stated that this process is specifically excluded from certain HIPAA mandates and BAA requirements.
Limit your use of Stripe
The caveat when using Stripe is you must limit your use of the payment service to only collecting payment. Anything "above and beyond" just taking payment makes them a business associate and a BAA is required. So do not use any of Stripe's other features like invoicing and financial analysis.
For any other questions about Doxy.me, reach out to our support team, and we'll be able to help.