The math The app Your numbers AI search Pricing Blog Book a walkthrough
Compliance

What HIPAA actually requires from your medspa's app

If your app stores a patient's name next to a treatment, it holds protected health information. Here is what that obligates you to do, what a Business Associate Agreement covers, and the questions to ask any app vendor.

August 20, 2026·4 min read·By A to Z

Medspas sit in an awkward place. Half the business feels like a salon, and half of it is medicine. The moment an app records that a named patient had a neurotoxin treatment on a given date, it's the medicine half, and HIPAA applies. This guide is written for owners and practice managers, not lawyers. It's not legal advice, and your compliance officer or counsel should confirm how it applies to your practice.

First, what counts as PHI in an app

Protected health information is any individually identifiable information about a patient's health, treatment, or payment for treatment. In a clinic app that includes:

  • A patient's name, phone, or email connected to a treatment or appointment.
  • Appointment history ("Neurotoxin touch-up, Jul 10, Dr. Park").
  • Before-and-after photos tied to a patient.
  • Notes, consent forms, intake questionnaires.
  • Payment records that show what was purchased.

Almost everything useful an app does involves PHI. So the question isn't whether HIPAA applies. It's whether the app was built by people who assumed it would.

The three things HIPAA requires you to have

At the practical level, the HIPAA Security Rule asks for three categories of safeguards.

1. Technical safeguards

  • Encryption of data in transit (between the phone and the server) and at rest (in the database and backups).
  • Access control: each staff member sees only what their role requires. The front desk doesn't need clinical notes; a provider doesn't need the marketing list.
  • Audit logs: a record of who accessed or changed what, and when.
  • Automatic logoff and authentication on any device that can see patient data.

2. Administrative safeguards

  • A risk assessment that identifies where PHI lives and what could go wrong.
  • Policies and training so staff know what they can and can't do (no screenshots of the schedule in a group chat, for instance).
  • Business Associate Agreements with every vendor that touches PHI. This is the one clinics most often miss.

3. Physical safeguards

Workstation and device security, which for an app mostly means: don't leave a logged-in tablet on the front desk.

The Business Associate Agreement

Any vendor that stores, transmits, or processes PHI on your behalf is a "business associate" under HIPAA. Your app provider is one. Your booking software is one. Your cloud storage is one. Each needs to sign a Business Associate Agreement (BAA), a contract in which the vendor accepts its own obligations to protect the data and to notify you of a breach.

A vendor that won't sign a BAA is telling you, in writing, that they are not built for medical data. That includes most no-code app builders and most general-purpose marketing tools. Don't put patient information into a system whose vendor won't sign.

Marketing is where clinics get into trouble

The most common HIPAA mistake in aesthetic medicine isn't a hack. It's a marketing email. Under HIPAA, using PHI for marketing generally requires patient authorization, and sending "It's been 3 months since your Botox, time to rebook!" to a patient's email is arguably a use of PHI. The rules around what counts as treatment communication versus marketing are detailed, and this is exactly the point to involve counsel.

Practically, a well-built app handles this two ways:

  • Treatment-cycle reminders are sent inside the app the patient chose to install and consented to, as part of their care, not blasted to a purchased list.
  • Analytics and campaign data are separated from PHI. The dashboard can tell you "37 quiet slots were filled by reminders" without the marketing pipeline ever holding a diagnosis.

Questions to ask any app vendor

  1. Will you sign a BAA? (If no, stop here.)
  2. Is data encrypted in transit and at rest? Where are the servers?
  3. Is access role-based, and is there an audit log I can export?
  4. How is PHI separated from marketing and analytics data?
  5. What is your breach notification process and timeline?
  6. Who applies security patches when iOS, Android, or your platform changes, and how quickly?
  7. Do you hold any certifications (SOC 2, HITRUST), or are they on your roadmap?

What "HIPAA-compliant app" really means

There is no government certification for HIPAA compliance. A vendor can't hand you a certificate. What they can do is build the technical safeguards in, sign the BAA, and document their practices. "HIPAA-ready" is the honest term: the platform has what the rule requires, and the agreement makes the vendor accountable for their part. Your part, the policies, training, and risk assessment, stays with you.

How A to Z handles this: encryption in transit and at rest, role-based access with audit logs, PHI kept separate from marketing and analytics data, security patches applied by our team, and a BAA signed with every clinic. SOC 2 Type II and HITRUST are on our roadmap. This article is general information, not legal advice.

Keep reading

Pricing

How much does a medspa app cost in 2026?

Agencies quote $30K to $200K. App builders quote $50 a month. Neither number is the real one. Here is what a branded clinic app actually costs to build, launch, and keep running, and how to compare the options.

September 10, 2026 · 4 min read
Retention

Why medspa patients don't rebook, and what actually fixes it

Most aesthetic patients like their results and still don't come back on schedule. It isn't a loyalty problem. It's a reminder problem. Here is the math of the treatment cycle and the three fixes that move rebooking rates.

September 3, 2026 · 4 min read
Memberships

Medspa membership programs, the math behind the ones that work

A membership is the closest thing an aesthetic clinic has to recurring revenue. Here is how to price one, what to include, why members visit more, and how to sell it without a pitch.

August 27, 2026 · 4 min read