Does HIPAA apply to a med spa that doesn't bill insurance?
The HIPAA covered-entity test at 45 CFR §160.103 turns on whether the practice (or a service acting on its behalf) conducts a HIPAA standard transaction adopted under 45 CFR Part 162 — most commonly an 837 health care claim, 270/271 eligibility, or 835 remittance. Having a medical director, offering injectables, prescribing electronically, ordering labs, or storing treatment photos does not, individually, establish covered-entity status. Cash-pay status does not settle the question in either direction. What most often pulls a med spa in is one insurance-billed service line, a billing/membership vendor transacting on the practice's behalf, or performing covered work as a Business Associate for another entity. Even where HIPAA does not apply, state consumer-health privacy laws (WA MHMDA, NV CHPA, CT DPA, CA CMIA/CPRA), state medical board rules, FTC Health Breach Notification Rule enforcement, and vendor recordkeeping obligations still impose substantial exposure. Run the transaction test for the legal entity and document the conclusion.
Are before/after photos PHI?
When stored as part of a treatment record documenting patient response to a medical procedure (injectables, laser treatment, fillers, weight-loss progress with hormone or GLP-1 therapy), yes. Photos linked to patient identity and treatment are ePHI and require storage covered by a BAA, encrypted, access-controlled, and audit-logged. A personal Dropbox, Google Drive, or iCloud account, or a staff member's device, fails that test — not because of the brand, but because there is no agreement, no configuration, and no control. The same vendor's business offering under a BAA, configured correctly, is a different matter.
Can our med spa be a hybrid entity — covered for some operations, not for others?
Possibly — but not by simply declaring it. Section 164.105 permits a single legal entity that performs both covered and non-covered functions to designate itself a hybrid entity. The designation is formal: the entity must document which of its components are health care components, and those components then carry the full HIPAA obligation, including safeguards against the rest of the business. It is not a matter of asserting that the medical services are covered and the aesthetic services are not. And if the clinical operation sits in a separate legal entity, hybrid designation is not the right analysis at all — that entity's own transaction status decides its coverage. Without a documented designation, there is no boundary to defend.
Do we need a BAA with our photo storage platform?
Yes, if photos are linked to patient identity and treatment. Photo storage providers receiving ePHI on the practice's behalf are business associates under §160.103 and require a written BAA. This is one of the most commonly missed BAAs in the med-spa segment because consumer cloud storage is the default pattern. Compliant photo storage requires either a HIPAA-tier subscription on a major cloud platform with a BAA or a purpose-built clinical photo platform.
Our med spa offers GLP-1 weight loss and IV therapy — does that change our HIPAA status?
Yes — meaningfully. Adding GLP-1 weight loss adds e-prescribing, compounding pharmacy partnerships, and lab orders to the operation; each is a covered transaction or PHI flow that establishes CE status. Adding IV therapy adds prescribing, administration records, and supplier relationships. Either addition pushes a previously-ambiguous med spa firmly into CE territory and adds significant BAA, risk-analysis, and training requirements.
How should we evaluate HIPAA compliance vendors for a med spa?
Start from your own threat model rather than from a brand or an endorsement. A med spa's highest-frequency exposures are clinical photography stored outside the practice's control, social engineering aimed at patient financial information, and vendor relationships that were never classified. Ask any vendor you evaluate the same four questions: does it produce a documented Security Risk Analysis and the remediation record behind it, does it govern the photography workflow specifically, does it track which vendors are Business Associates and hold the agreements, and does it preserve the evidence you would need to show what you actually did? A documentation package is a necessary foundation. The question worth asking is whether it is the whole program for your operation.
What state laws apply to med spas beyond HIPAA?
State medical board rules govern medical-component supervision (which procedures require a medical director, what supervision RNs/PAs/NPs/aestheticians require) and procedure-specific consent and record-keeping requirements. State consumer-health privacy laws (Washington MHMDA, Nevada CHPA, Connecticut DPA, California CMIA/CPRA) apply to before/after photos and treatment records regardless of HIPAA status. Multi-state med spa operators face a state-by-state matrix.
Does a medical spa have to complete a HIPAA Security Risk Analysis?
Where the entity is covered, yes — and that determination has to be made and documented first, because providing a medical service does not by itself complete the classification. Where HIPAA applies, the med spa must conduct and document an accurate, thorough assessment of the risks affecting all its ePHI: the EHR or practice-management system, scheduling, intake and consent, clinical consultation and prescribing records, before-and-after photographs from capture through deletion, personal phones and shared devices with automatic cloud sync, telehealth and laboratory workflows, and the marketing, advertising, and lead-generation systems receiving health-related information. Where HIPAA does not apply, state medical-privacy and consumer-health law still governs the same records.
Which of our med spa vendors need Business Associate Agreements?
Any organization performing a function involving PHI on the covered entity's behalf: the EHR or practice-management system, scheduling and intake tools, photo storage and photo-management platforms, telehealth platform, secure messaging, payment processors where PHI flows, cloud backup, IT support, and any marketing agency, web form, analytics, or lead-generation vendor receiving identifiable health information. That last group is the one most often missed, because marketing vendors are not thought of as handling patient data until someone traces where the intake form posts. Laboratories running pre-procedure bloodwork and pharmacies dispensing to patients are generally treating providers rather than business associates.
Our medical director is an independent contractor. Does that change who holds the compliance obligation?
It changes who the workforce is, not whether the obligation exists. HIPAA's definition of workforce reaches people whose conduct is under the direct control of the entity whether or not they are paid by it, so a contracted medical director performing supervised clinical work is generally inside the workforce for training, sanction, and access purposes rather than being a business associate. What the arrangement does not do is move the obligation off the entity. If the med spa's legal entity is covered, it owns the risk analysis, the policies, the training records, and the breach response regardless of how the physician is engaged. Practices sometimes assume the medical director's own credentials or malpractice coverage carry the compliance program with them. They do not.
Is the government's Security Risk Assessment Tool mandatory?
No. The government's SRA Tool is one method designed to help small and medium-sized organizations perform the required analysis. HIPAA requires the underlying risk analysis — not the use of one particular tool. Patient Protect provides its own guided SRA and connects the findings directly to remediation, policies, tasks, and documentation.
Does our EHR make the practice HIPAA compliant?
No. An EHR may provide important safeguards for the records it maintains, but it does not conduct the practice's complete SRA, remediate every identified risk, train the workforce, manage all policies, identify every Business Associate, prepare the practice for incidents, or preserve the full body of compliance evidence.
How much does Patient Protect cost for a medical spa?
Patient Protect Basic costs $39 per office per month and includes up to 25 personnel. It includes the guided Security Risk Analysis, risk management, policies, workforce training, workforce and vendor management, BAA tracking, compliance scoring, and centralized documentation needed to operate the practice's core HIPAA compliance program.