HostMedical Book a Call
Compliance

HIPAA for Med Spas: The Compliance Layer Most Owners Forget Exists

BB Brittany Bati  ·  May 5, 2026  ·  4 min read

Owners spend a lot of energy on CPOM and entity structure, and comparatively little on HIPAA — often because a med spa doesn’t feel like a “medical practice” in the way a hospital or primary care office does. But if your practice collects medical history, performs treatments that require a good-faith exam, or stores any patient health information electronically, HIPAA almost certainly applies, and the penalties for getting it wrong aren’t theoretical.

What Actually Counts as Protected Health Information Here

Intake forms with medical history, treatment notes, before-and-after photos tied to a patient’s identity, consultation records, even appointment scheduling data that links a name to a specific treatment — all of this can qualify as protected health information under HIPAA. Booking software, CRM systems, and marketing platforms that touch this data all need to be evaluated for whether they’re HIPAA-compliant, not assumed to be because they’re popular or widely used.

The Core Pieces of a Compliance Program

  • A written Notice of Privacy Practices, actually provided to patients — not just posted somewhere on the website
  • Business Associate Agreements (BAAs) with every vendor that touches patient data — booking platforms, payment processors, EMR systems, even some marketing tools
  • Staff training on privacy and security practices, documented and repeated periodically, not a one-time onboarding mention
  • A designated privacy officer, even if that’s a role held alongside other responsibilities in a small practice
  • A breach response plan, so that if something does go wrong, the practice isn’t improvising the notification process under pressure
A vendor being popular in the med spa industry isn’t the same as that vendor being HIPAA-compliant by default. That has to be confirmed, not assumed.

Where This Intersects With Marketing

Before-and-after photos are a particular risk area — using them for marketing requires a specific, documented patient authorization, separate from general treatment consent. A signature on an intake form doesn’t automatically cover permission to post a patient’s photo on Instagram.

If you’re not sure whether your current systems and vendor relationships actually satisfy HIPAA, that’s exactly where we start every engagement.

Ready to Build This the Right Way?

Tell me where your practice stands today and we’ll talk through the structure, the compliance path, and the right level of support.

Book a Consultation
Keep Reading
Risk Management
Malpractice, General Liability, and Cyber: The Insurance Stack a Med Spa Actually Needs
Compliance
Standing Orders and Protocols: The Difference Between “We Have a Binder” and Real Oversight