Friday afternoon at a med spa: a nurse injector finishes a neurotoxin appointment, the nurse practitioner runs a weight-loss consult and writes a GLP-1 prescription, and the front desk books next week's laser hair removal in an app built for hair salons. On the way out, the injector posts a before-and-after to Instagram. Ask the owner about HIPAA and the answer is confident: "We are not medical. We do not take insurance."
Half of that sentence is wrong and the other half may or may not matter. The HHS Office for Civil Rights (OCR) enforcement listing includes a $1,500,000 civil money penalty against Warby Parker in a HIPAA cybersecurity hacking investigation (February 2025): a consumer brand most people think of as a retailer, penalized as a HIPAA entity. It also shows a $10,000 settlement with a dental practice over social media disclosures of patients' protected health information (October 2019). The definitions decided both.
This guide walks through the covered-entity test for a med spa, what protected health information looks like in aesthetic medicine, the violations specific to this setting, how to build the program if the test comes out "yes," what applies if it comes out "no," and which vendors need a Business Associate Agreement.
HIPAA Compliance for Med Spas: The Covered Entity Test
Step One: Is a Med Spa a Health Care Provider?
45 CFR 160.103 defines health care provider to include "any other person or organization who furnishes, bills, or is paid for health care in the normal course of business." It defines health care to include any "procedure with respect to the physical or mental condition, or functional status, of an individual or that affects the structure or function of the body," and the "sale or dispensing of a drug, device, equipment, or other item in accordance with a prescription."
Botulinum toxin is a prescription drug. Dermal fillers are prescription devices. A GLP-1 injection is a prescription drug. Laser resurfacing, microneedling, and chemical peels are procedures that affect the structure of the body. A med spa that offers any of them is a health care provider under HIPAA. "We are not medical" does not survive the definition.
Step Two: Does It Transmit Health Information Electronically for a Covered Transaction?
Being a health care provider is not enough. The covered entity definition at 160.103 reaches "a health care provider who transmits any health information in electronic form in connection with a transaction covered by this subchapter." The covered transactions are listed in the same section: health care claims, payment and remittance advice, coordination of benefits, claim status, eligibility for a health plan, referral authorizations, and the rest of the standard insurance transaction set.
A med spa that is truly cash-pay, never submits a claim, never checks a patient's insurance eligibility electronically, and never requests a prior authorization is not a covered entity. HIPAA does not apply to it directly. Card processing and patient financing plans are not covered transactions; they are payments, not health plan transactions.
The answer flips the moment any covered transaction goes out electronically. A med spa that bills a health plan for medically indicated services, checks eligibility through a portal, or shares a tax ID with a physician practice that bills electronically becomes a covered entity. And HIPAA covers the entity, not the procedure: once the practice is covered, every patient record it holds is protected, cosmetic services included. A practice that has genuinely separate covered and non-covered functions may designate itself a hybrid entity under 45 CFR 164.105, but that is a deliberate legal structure with its own documentation, not a default.
The honest position for most med spas is: run the test, write down the answer and the reasons, and rerun it whenever billing or ownership changes. That memo is the first compliance document the practice should own. The definition is explained further in what is a covered entity under HIPAA.
What P.H.I. Looks Like in a Med Spa
For a covered med spa, P.H.I. (Protected Health Information) is every piece of identifiable health information the practice holds, in any form.
- Intake and good-faith exam records. Medical history, current medications, allergies, pregnancy status, and the medical director's or nurse practitioner's exam notes.
- Treatment records. Units of neurotoxin per site, filler product and syringe counts, lot numbers, laser settings, and skin-type classifications.
- Before-and-after photographs. The face is the identifier. 45 CFR 164.514(b)(2)(i) lists "full face photographic images and any comparable images" among the identifiers that must be removed for information to be de-identified. A photo library on an injector's phone is a P.H.I. repository. The full list is in the 18 HIPAA identifiers.
- Weight-loss program data. GLP-1 prescriptions, weight logs, lab results, and body composition scans.
- Consent forms and membership records. Any record that ties a name to a treatment, including the membership plan that lists "monthly neurotoxin" next to a client name.
- Appointment reminders. A text that reads "See you Tuesday for your lip filler" is a disclosure of treatment information over whatever channel carries it.
Common Violations in Med Spa Settings
Before-and-after photos without a valid authorization. A photo used to promote the practice is marketing, and 164.508(a)(3) requires an authorization for "any use or disclosure of protected health information for marketing." A checkbox buried in the intake packet usually fails 164.508(c): a valid authorization needs a specific description of the information, the recipient, the purpose, an expiration date or event, a signature, the right-to-revoke statement, and plain language, with a copy to the patient. 164.508(b)(4) adds that a covered entity "may not condition the provision to an individual of treatment ... on the provision of an authorization." No photo release, no treatment, is itself a violation. The elements are in HIPAA authorization requirements.
Answering online reviews with treatment details. The enforcement listing shows an agreement with a New Jersey health care provider that disclosed patient information in response to negative online reviews (June 2023). Confirming that someone was a patient, or what they had done, in a public reply is a disclosure. The only safe reply is generic and takes the conversation offline.
Salon software holding medical notes. Booking and point-of-sale platforms built for salons store the service name next to the client name, and many will not sign a Business Associate Agreement. If the platform holds "neurotoxin, 40 units" or "GLP-1 follow-up," it holds P.H.I. on the practice's behalf, and 164.502(e) requires a written agreement before that happens.
Personal phones as the clinical camera. Photos taken on an injector's own phone sync to personal cloud accounts and family-shared albums. 164.310(d) requires policies for devices holding ePHI (electronic P.H.I.), and 164.312(a)(2)(iv) makes encryption an addressable specification the practice must implement or justify skipping.
Waiting room announcements. "Here for your Botox?" across the lobby is a disclosure to everyone in it. The rules are in HIPAA front desk rules.
Building the Program When the Answer Is Yes
Document the determination. One page: the services offered, the transactions sent electronically, the conclusion, the date, and who signed it.
Designate the officials. 164.530(a)(1) requires a privacy official, and 164.308(a)(2) requires a security official. In a single-location practice they are usually the same person, named in writing.
Run the risk analysis. 164.308(a)(1)(ii)(A) requires "an accurate and thorough assessment of the potential risks and vulnerabilities to the confidentiality, integrity, and availability of electronic protected health information." For a med spa that means the EMR, the photo library, the booking platform, the marketing list, and every phone that has ever taken a treatment photo.
Post the Notice of Privacy Practices. 164.520(c)(2) requires a provider with a direct treatment relationship to give the notice "no later than the date of the first service delivery," make a good-faith effort to get a written acknowledgment, and post it at the site. 164.520(c)(3)(i) adds that a covered entity with a website describing its services "must prominently post its notice on the web site." Most med spa websites do not.
Train everyone. 164.530(b)(1) requires training for "all members of its workforce": injectors, estheticians, front desk, and the medical director. Document it and keep the record for six years under 164.530(j)(2).
If the Answer Is No, HIPAA Is Not the End of the Story
A non-covered med spa still holds medical records. State medical privacy and breach notification laws apply, state medical boards set record-keeping rules for the supervising physician, and the promises in the practice's own website privacy policy can be enforced as consumer protection by state attorneys general. The practical move is to adopt the same safeguards voluntarily, and to avoid describing the practice as "HIPAA compliant" in marketing if it is not a covered entity, because that claim invites the question. The state-law layer is covered in state privacy laws vs federal HIPAA requirements.
Vendor B.A.A. Checklist for Med Spas
A business associate under 160.103 is a person who, on the practice's behalf, "creates, receives, maintains, or transmits protected health information" for a regulated function. For a covered med spa, the vendor list is short but almost entirely consumer-grade, which is where the gaps come from.
| Vendor category | Typical examples | B.A.A. required? |
|---|---|---|
| Aesthetic EMR and charting | Nextech, PatientNow, AestheticsPro, Aesthetic Record | Yes |
| Salon-style booking and point of sale | Vagaro, Boulevard, Mindbody | Yes, if service names or notes are stored with client names. If the vendor will not sign, that is the answer about using it for clinical data. |
| Clinical photo apps and cloud photo storage | Any app or account holding treatment photos | Yes |
| Text and email marketing platforms | Mailchimp, Klaviyo, Podium | Yes, if treatment or appointment details go into them. Otherwise keep the list to names and contact details only. |
| Telehealth or prescribing platform used for weight-loss consults | Any platform the practice contracts to run consults | Yes, if it acts on the practice's behalf. A separately licensed prescriber running an independent practice is a provider, not a business associate. |
| Compounding or dispensing pharmacy | The pharmacy filling GLP-1 or other prescriptions | No. A pharmacy dispensing on a prescription is a health care provider receiving information for treatment. |
| Card processor and financing | Payment terminals, patient financing plans | No for card processing alone. Do not send procedure names with the charge. |
| IT support, website host with form data, shredding | The MSP, the web developer with access to submissions, the document destruction company | Yes |
| Medical director | The supervising physician | Depends on the arrangement: workforce if under the practice's direct control, a separate provider if running an independent practice. Get it in writing and consult counsel. |
The Proposed Security Rule Update (Proposed, Not Final)
HHS published a Notice of Proposed Rulemaking on January 6, 2025 that would make encryption and multifactor authentication required rather than addressable, require a written asset inventory and network map, and require vulnerability scans "at least once every six months." It is proposed, not final, and OCR is not enforcing it. The status is tracked in HIPAA Security Rule delayed to 2027. For a covered med spa, encrypting the photo library and turning on multifactor authentication for the EMR are worth doing under the current rule anyway, because they are the two controls that would have stopped most of the breaches in the enforcement listing.
---
FAQ
Are med spas covered by HIPAA?
Only if the med spa is a health care provider that transmits health information electronically in connection with a covered transaction such as a claim or eligibility check (45 CFR 160.103). Med spas are health care providers because they furnish prescription drugs and procedures affecting the body; whether they are covered entities depends on their electronic transactions.
Does a cash-only med spa have to follow HIPAA?
If it never sends a claim, eligibility inquiry, or prior authorization electronically, it is not a covered entity and HIPAA does not apply directly. State medical privacy laws, breach notification laws, and medical board record rules still apply, and adopting HIPAA-level safeguards voluntarily is the sensible baseline.
Can a med spa post before-and-after photos on Instagram?
A covered med spa needs a valid HIPAA authorization under 164.508 for each patient, since a promotional photo is marketing and a full-face image is an identifier. The authorization cannot be a condition of treatment. A non-covered med spa should still obtain written consent under state law and its own privacy policy.
Is a salon booking app HIPAA compliant for a med spa?
Not on its own. If the app stores treatment names or notes with client names for a covered med spa, the vendor is a business associate and must sign a Business Associate Agreement. Many salon platforms will not, which means clinical details should not be entered into them.
If the medical director bills insurance, is the med spa a covered entity?
It depends on the legal structure. If the med spa and the billing practice are the same legal entity, the entity is covered and all of its records are protected. If they are separate entities, each is tested on its own transactions. The arrangement should be documented and reviewed with counsel.
Conclusion
Whether a med spa is a covered entity is a yes-or-no question with a documented answer, and everything else follows from it. One Guy Consulting's Full-Scope plan starts with that determination, then supplies the risk analysis, the photo authorization form, the policy set, staff training, and B.A.A. tracking sized for a single-location practice. Start with a free 30-minute compliance review. No obligation, no pressure.
Sources
- 45 CFR 160.103 (definitions: health care, health care provider, covered entity, transaction)
- 45 CFR 164.105 (hybrid entities)
- 45 CFR 164.508 (authorizations, including marketing)
- 45 CFR 164.514 (de-identification and the identifier list)
- 45 CFR 164.520 (Notice of Privacy Practices)
- 45 CFR 164.530 (administrative requirements)
- HHS OCR: Resolution Agreements and Civil Money Penalties
- Federal Register: HIPAA Security Rule NPRM (January 6, 2025)
Related Reading