🇮🇳 India 🇺🇸 US
Healthcare SEO AI search (AIO) Local SEO & Google Business Profile Content marketing Performance marketing Google Ads Meta Ads Email & SMS marketing Reputation management Website design Branding YouTube & video Marketing consulting
Dental practices Pediatric practices Primary care Med spas Dermatology IVF & fertility Dallas (HQ) Houston New York All US cities and specialties
US healthcare marketing statistics Med spa consumer behavior report Dental patient experience report Google benchmarks: 9 specialties Free tools All US research US case studies
Software
Healthcare practices Pharma Medical devices
About Ichelon Consulting US How we work Santosh Reddy, Director Ravi Kumarraju, Partner & Director
Book a call with the US team Call +1 (724) 612-3694
We Do It Right. The right diagnosis. The right strategy. The right systems. Giving healthcare leaders the confidence to make better decisions, build stronger operations, and achieve sustainable growth. — Team Ichelon
Ichelon Consulting US · HIPAA by role

HIPAA for providers in med spas and medical practices: photos, phones, social media and the four stages

Providers stay HIPAA compliant by treating every patient photo as protected health information, keeping clinical texts and images inside approved apps rather than personal camera rolls, looking only at the charts of patients they are treating, never posting or talking publicly about a patient without written authorization, and handing back every login and device when they leave. Clinical access is broad by design; the risks sit in phones, photos and public comments.

Guide for US practice owners · Published October 4, 2026

TL;DR
  • Full-face photos are identifiers under HIPAA's de-identification rule (45 CFR 164.514(b)(2)(i)(Q)). Before-and-after images are PHI.
  • Marketing use of a patient photo or story needs a signed HIPAA authorization (164.508(a)(3)), separate from treatment consent.
  • Treatment is exempt from minimum necessary (164.502(b)(2)), but browsing charts you are not involved with is not treatment.
  • Never comment to media or online about a patient. OCR settled with a practice whose doctor spoke to a TV reporter.
  • At exit: EHR and e-prescribing access off, photos and texts deleted from personal devices, confirmed in writing.
  • Every practice welcome — retainers from $499/mo, Goals-Driven engagements, Performance-Linked Payout Models available.
Ichelon Consulting US
  • Dallas, Texas LLC
  • 10-person US client team · Central Time (CST)
  • 25+ US healthcare clients
  • BAA signed with every client
  • HIPAA compliance training across client and delivery teams
  • Contracts and invoices in USD
How we work with US practices →
Trusted by US practices · case studies → 25+ US clients · 8 shown · TX · CA · VA · nationwide telehealth
Dr. Rajan Kohli
Owner, Lakewood Primary Care & Wellness · North Dallas, TX
Client video · Practice website build
“They were able to get all my ideas and work with me over a period of three to four months and create this amazing website. It's super customized, very modern, and it incorporates all the elements that I had wanted — the patient portal, nice pictures, a very interactive website, patient reviews. I would highly recommend their company to anyone who wants to make an excellent website.”
Dr. Rajan Kohli Owner, Lakewood Primary Care & Wellness · North Dallas, TX
Who this covers

Providers: broad access, personal devices and a public profile

Short answer: providers need full clinical access to do their job, so access limits matter less than habits. The three places providers get into trouble are photos, personal phones and public comments.

This page applies our four-stage HIPAA framework to physicians (MD, DO), nurse practitioners, physician assistants, registered nurses and nurse injectors, and aestheticians or laser technicians. In a med spa, that includes the medical director, delegating physicians and contract injectors. In dental offices, apply the same rules to dentists and hygienists.

A note on scope: HIPAA covers health care providers that conduct standard transactions electronically, such as insurance claims. Some cash-pay med spas fall outside that definition. State law can still apply. Texas, for example, defines "covered entity" broadly enough to include anyone who comes into possession of protected health information, and requires employees to complete training on state and federal PHI law within 90 days of hire, with signed records kept six years (Texas Health and Safety Code 181.001 and 181.101). Treat HIPAA as the floor either way.

The four stages

The four stages for providers

Stage 1 · Onboard

Verify licenses and any required supervision or delegation agreements through your credentialing process. Training must cover your policies as necessary for the role (164.530(b)), so make the provider version different from the front desk version: photo rules, device rules, social media, media inquiries, texting colleagues, and access logging. Locum and contract providers working under your direction count as workforce (45 CFR 160.103 defines workforce by direct control, not by who pays) and go through the same training and confidentiality agreement.

Stage 2 · Access

Disclosures to a provider for treatment are exempt from the minimum necessary standard (164.502(b)(2)(i)), so providers can see what they need to treat. That exemption does not cover curiosity. Looking up a coworker, a neighbor, a celebrity patient or an ex-partner is an impermissible use, and audit logs (164.312(b)) make it easy to find. Every provider gets a unique login with MFA, including on the EHR mobile app and e-prescribing. Encrypted, passcode-locked devices only; turn off lock-screen message previews.

Stage 3 · Operate

Daily rules for photos, devices, texting and public comments are in the next section.

Stage 4 · Offboard

Remove EHR, practice management, e-prescribing, imaging, photo app and secure messaging access on the last day (termination procedures, 164.308(a)(3)(ii)(C)). Have the provider delete patient photos, texts and files from personal devices and confirm it in writing. Collect practice-owned devices. If patients will be told about the provider's departure, coordinate the message with the practice; patient lists remain practice PHI and do not leave with the provider for marketing a new practice.

Operate

Photos, phones, social media and the press

Before-and-after photos

  • They are PHI. Full-face photographs and comparable images are among the identifiers HIPAA lists for de-identification (164.514(b)(2)(i)(Q)). Body photos can identify people through tattoos, scars, jewelry and room backgrounds.
  • Where they live: the EHR or an approved clinical photo app, on a practice device or inside a managed app on a personal device. Never the personal camera roll, personal cloud backup, or a group text.
  • Marketing use: a signed HIPAA authorization specific to marketing (164.508(a)(3)), stating what will be used, where, and that the patient can revoke it. A treatment consent form is not enough. Our before-and-after photo compliance guide covers editing, disclosures and FTC points.

Personal phones and texting

  • Clinical conversations with colleagues go through a secure messaging app covered by a BAA, not standard SMS or consumer chat apps.
  • No patient photos in texts, even to the medical director for a quick opinion. Use the secure app or the chart.
  • Screen lock, encryption and remote wipe enrolled before any practice app is installed.
  • Turn off message previews on the lock screen.

Social media

  • No posts, stories or comments about patients without authorization, on practice or personal accounts. "Unnamed" is not enough if someone could recognize the patient.
  • Watch backgrounds: charts, schedules, screens and other patients in treatment rooms.
  • Do not reply to reviews or comments with clinical detail, even to correct a false claim. Route them to the practice manager.
  • Influencer and paid endorsement content has its own rules: see our FTC endorsement guide for aesthetics.

Media and public comments

If a patient goes to the press or posts a complaint, the provider's instinct is to tell their side. HIPAA does not allow disclosure of PHI to defend a reputation.

OCR case: speaking to a reporter. Allergy Associates of Hartford in Connecticut paid $125,000 after one of its doctors discussed a patient's information with a TV reporter. The practice's privacy officer had told the doctor to decline to comment, and OCR noted that the practice took no disciplinary action afterward.
OCR case: looking without a reason. Yakima Valley Memorial Hospital in Washington paid $240,000 after 23 security guards used their own logins to view 419 patients' records with no job reason. The same audit-log logic applies to clinical staff browsing charts they are not treating.
Checklist

Printable provider HIPAA checklist

Stage 1 · Onboard

  • License and any supervision or delegation agreements verified
  • Provider-specific training completed: photos, devices, social media, media, texting
  • Confidentiality agreement and policy acknowledgment signed (locums included)
  • State-law training requirement checked (for example, Texas: within 90 days of hire)

Stage 2 · Access

  • Unique EHR, e-prescribing and photo-app logins with MFA
  • Personal device enrolled: passcode, encryption, remote sign-out, previews off
  • Photo storage set to the clinical system, not the camera roll
  • Understands that chart access is logged and reviewed

Stage 3 · Operate

  • Marketing authorization on file before any patient photo or story is shared
  • Clinical messages and images sent only through the secure app
  • No patient content on personal social accounts
  • Media and review inquiries referred to the designated spokesperson
  • Incidents reported to the privacy official the same day

Stage 4 · Offboard

  • EHR, e-prescribing, imaging, photo app and messaging access removed on last day
  • Patient photos, texts and files deleted from personal devices; confirmed in writing
  • Practice devices, keys and badge returned
  • Patient communication about the departure agreed with the practice
Our research · State of Med Spa Google Presence 2026

What we found when we studied 555 US med spas on Google

Patients praise the care almost without exception. The one area where complaints outnumber praise is booking and communication, and that is where most med spas can win.

4.87★
average Google rating. Near-perfect ratings are table stakes.
5.83
median new reviews per month. Most profiles grow slowly.
~54%
of booking and communication reviews are negative, the one weak theme.

Full study · 555 US med spas across 20 metros · roughly ±4% nationally · review velocity and themes from a 115-spa subsample · verified against raw data.

Common violations

Common provider violations and the fix

What happensWhy it is a problemFix
Results posted without authorizationMarketing use of PHI without a signed authorization.Authorization form; marketing approval step.
Photos in personal camera rollPHI synced to a personal cloud, lost with the phone, kept after exit.Approved photo app; offboarding deletion confirmation.
Chart browsingUse not related to treatment; caught by audit logs.Training plus regular log review and sanctions.
Replying to a public complaintDiscloses PHI to the public or press.Spokesperson policy; generic replies only.
Curbside consults by textImages and details on consumer messaging apps.Secure messaging under a BAA.

For the marketing side of a med spa, see our med spa marketing page, med spa marketing statistics for 2026, the med spa Google presence report, and state rules such as the California medical board advertising guide or Texas guide. Practice owners should also read HIPAA for practice managers. Browse all US guides or book a call.

Sources

Sources

Keep reading

Related pages from the US team

HIPAA compliance by role

The full four-stage framework and the roles-by-stages matrix.

Before-and-after photo compliance

Consent, editing and disclosure rules for aesthetic photos.

HIPAA for med spa advertising

How med spas run ads and content without exposing PHI.

HIPAA for front desk staff

The four stages for coordinators, with a printable checklist.

HIPAA offboarding checklist

What to close and recover when a provider leaves.

How we work

Every practice welcome — Goals-Driven engagements from $499/mo

We benchmark your last 90 days, agree monthly goals with you, and track them live on Ichelon Agency OS with a report every Monday. Performance-Linked Payout Models are available. Our US leadership is based in Dallas, and strategy calls run in US business hours.

Read the full engagement model →

FAQ

Common questions

Are before-and-after photos protected health information?

Yes, when a covered entity takes them in connection with care. Full-face photographs and comparable images are listed identifiers under HIPAA's de-identification standard, and even cropped photos can identify someone through tattoos, jewelry or backgrounds. Store them in the practice's clinical system or an approved photo app and get a separate written authorization before using them in marketing.

Can a nurse injector use her personal phone to take patient photos?

Only if practice policy allows it and the photos go straight into an approved app that keeps them out of the phone's camera roll and cloud backup, with a passcode, encryption and remote sign-out. Photos sitting in a personal camera roll that syncs to a personal cloud account are a common source of exposure.

Can providers post patient results on their own Instagram?

Only with a signed HIPAA authorization that covers that use, and only if the practice approves. Posting on a personal account does not change the rule. State medical board advertising rules and FTC rules on endorsements may also apply.

Is a med spa covered by HIPAA if it does not take insurance?

HIPAA applies to health care providers that conduct certain standard transactions electronically, such as insurance claims. A purely cash-pay med spa may fall outside that definition, but state laws can still apply; Texas, for example, defines covered entity far more broadly and requires employee training within 90 days of hire. Most practices follow HIPAA practices regardless, and patients expect it.

Do providers need to sign a BAA?

Not usually. Employed providers and those working under the practice's direct control are workforce members, so they sign a confidentiality agreement and complete training. A separate provider group or independent contractor company performing services for the practice may be a business associate or a separate covered entity, depending on the arrangement.

What should a provider say if a reporter asks about a patient?

Nothing about the patient. Refer the reporter to the practice's designated spokesperson or privacy official. HIPAA does not let a provider disclose PHI to defend their reputation in the media, and OCR has penalized a practice for exactly that.

A note on this guide: it explains marketing practice, not legal advice. Rules on privacy, advertising and insurance change and vary by state, so confirm anything compliance-related with your own counsel.

Want to use patient results in marketing the right way?

A 30-minute call with the Ichelon Consulting US team on photo consent, testimonials and content that stays inside HIPAA and board rules. BAA signed before we start.

Chat with Sr. Leadership
🎯 Goals-Driven engagements · Performance-Linked Payout Models
Chat with Sr. Leadership