Buyer's guide · 2026
HIPAA-Compliant Med Spa Software
Almost every med spa platform says it is “HIPAA compliant.” Very few will hand you a signed BAA, show you the audit trail, or explain how one clinic's records are isolated from another's. This guide gives you the twelve things to verify before you move patient data into any system.
The 12-point vendor checklist
- 1. Signed Business Associate Agreement (BAA)
Any vendor touching PHI must execute a BAA before go-live. Ask for the countersigned document, not a marketing claim.
- 2. Row-level tenant isolation
Every record should be scoped to your clinic at the database layer, so one clinic can never read another's charts even if application code is wrong.
- 3. Role-based access control
Front desk, injector, medical director and owner should each see a different slice. Blanket admin logins are an audit finding waiting to happen.
- 4. Immutable audit trail
Who viewed, edited or exported a chart, with timestamps that cannot be edited or deleted by staff.
- 5. Encryption in transit and at rest
TLS everywhere plus encrypted storage. Necessary but nowhere near sufficient on its own.
- 6. Consent forms signed inside the chart
Treatment-specific consents must attach to the visit and be cryptographically sealed — not emailed PDFs sitting in an inbox.
- 7. Photo handling with metadata stripping
Before/after photos carry GPS and device EXIF. Sanitize on upload and store them under the same access rules as the chart.
- 8. Secure patient messaging
SMS and email reminders must avoid PHI in the body, with the clinical detail behind an authenticated portal.
- 9. Access reviews and offboarding
Instant revocation when staff leave, plus a report of who currently has access to what.
- 10. Breach notification workflow
A documented path for detecting, logging and reporting an incident within the HIPAA timeline.
- 11. Data export and portability
You should be able to export your full patient dataset yourself, without a support ticket or an exit fee.
- 12. Backups and disaster recovery
Point-in-time recovery, tested restores, and a stated recovery objective.
How MedAestheticsOS is built
Every clinic runs in its own isolated tenant enforced at the database layer, staff permissions are role-scoped, and every chart view, edit and export is written to an audit trail your medical director can review. Treatment consents are signed in the chart and cryptographically sealed, photos are stripped of EXIF metadata on upload, and you can export your full dataset yourself at any time. A BAA is executed during onboarding.
Frequently asked questions
Is med spa software automatically HIPAA compliant?
No. HIPAA compliance is a property of how a clinic and its vendors operate together. Software can be HIPAA-capable — offering a BAA, access controls, audit logging and encryption — but the clinic still owns policies, training and access reviews.
Does a med spa need a BAA with its software vendor?
Yes. If a vendor creates, receives, maintains or transmits protected health information on your behalf, HIPAA requires a Business Associate Agreement before that data is shared.
Are before-and-after photos protected health information?
Yes, when they are identifiable and tied to treatment. Store them inside the chart under the same access controls, strip EXIF metadata on upload, and get separate written consent before using any image in marketing.
Is texting appointment reminders to patients HIPAA compliant?
Reminders are permitted, but keep clinical detail out of the message. Send the time and location, and put the treatment detail behind an authenticated patient portal.
What HIPAA safeguards does MedAestheticsOS provide?
MedAestheticsOS offers a signed BAA, row-level tenant isolation, role-based access, an immutable audit trail, encrypted storage, e-signed treatment consents sealed into the chart, EXIF-stripped photo storage, and self-service full data export.
This guide is general information for software buyers and is not legal advice. Work with your compliance counsel and medical director on your clinic's HIPAA program.