Buyer's guide · 2026

HIPAA-Compliant Med Spa Software

Almost every med spa platform says it is “HIPAA compliant.” Very few will hand you a signed BAA, show you the audit trail, or explain how one clinic's records are isolated from another's. This guide gives you the twelve things to verify before you move patient data into any system.

The 12-point vendor checklist

  1. 1. Signed Business Associate Agreement (BAA)

    Any vendor touching PHI must execute a BAA before go-live. Ask for the countersigned document, not a marketing claim.

  2. 2. Row-level tenant isolation

    Every record should be scoped to your clinic at the database layer, so one clinic can never read another's charts even if application code is wrong.

  3. 3. Role-based access control

    Front desk, injector, medical director and owner should each see a different slice. Blanket admin logins are an audit finding waiting to happen.

  4. 4. Immutable audit trail

    Who viewed, edited or exported a chart, with timestamps that cannot be edited or deleted by staff.

  5. 5. Encryption in transit and at rest

    TLS everywhere plus encrypted storage. Necessary but nowhere near sufficient on its own.

  6. 6. Consent forms signed inside the chart

    Treatment-specific consents must attach to the visit and be cryptographically sealed — not emailed PDFs sitting in an inbox.

  7. 7. Photo handling with metadata stripping

    Before/after photos carry GPS and device EXIF. Sanitize on upload and store them under the same access rules as the chart.

  8. 8. Secure patient messaging

    SMS and email reminders must avoid PHI in the body, with the clinical detail behind an authenticated portal.

  9. 9. Access reviews and offboarding

    Instant revocation when staff leave, plus a report of who currently has access to what.

  10. 10. Breach notification workflow

    A documented path for detecting, logging and reporting an incident within the HIPAA timeline.

  11. 11. Data export and portability

    You should be able to export your full patient dataset yourself, without a support ticket or an exit fee.

  12. 12. Backups and disaster recovery

    Point-in-time recovery, tested restores, and a stated recovery objective.

How MedAestheticsOS is built

Every clinic runs in its own isolated tenant enforced at the database layer, staff permissions are role-scoped, and every chart view, edit and export is written to an audit trail your medical director can review. Treatment consents are signed in the chart and cryptographically sealed, photos are stripped of EXIF metadata on upload, and you can export your full dataset yourself at any time. A BAA is executed during onboarding.

Frequently asked questions

Is med spa software automatically HIPAA compliant?

No. HIPAA compliance is a property of how a clinic and its vendors operate together. Software can be HIPAA-capable — offering a BAA, access controls, audit logging and encryption — but the clinic still owns policies, training and access reviews.

Does a med spa need a BAA with its software vendor?

Yes. If a vendor creates, receives, maintains or transmits protected health information on your behalf, HIPAA requires a Business Associate Agreement before that data is shared.

Are before-and-after photos protected health information?

Yes, when they are identifiable and tied to treatment. Store them inside the chart under the same access controls, strip EXIF metadata on upload, and get separate written consent before using any image in marketing.

Is texting appointment reminders to patients HIPAA compliant?

Reminders are permitted, but keep clinical detail out of the message. Send the time and location, and put the treatment detail behind an authenticated patient portal.

What HIPAA safeguards does MedAestheticsOS provide?

MedAestheticsOS offers a signed BAA, row-level tenant isolation, role-based access, an immutable audit trail, encrypted storage, e-signed treatment consents sealed into the chart, EXIF-stripped photo storage, and self-service full data export.

This guide is general information for software buyers and is not legal advice. Work with your compliance counsel and medical director on your clinic's HIPAA program.