Skip to Main Content
Usually yes. A med spa that provides medical treatment and transmits health information electronically for billing or claims is a HIPAA covered entity. Even a cash-only med spa is caught by Texas medical privacy law, which defines covered entity more broadly than HIPAA does and adds its own training duties.

Two Sets of Rules, Not One

Owners tend to ask about HIPAA and stop there. In Texas there are two layers. HIPAA applies to covered entities and their business associates. The Texas medical records privacy law applies to a much wider group: broadly, anyone who assembles, collects, analyses, uses, evaluates, stores, or transmits protected health information in the course of business. A cash-only aesthetic practice that files no insurance claims can sit outside HIPAA’s covered entity definition and still owe duties under Texas law.

Assume both apply, because the practical compliance steps overlap almost entirely, and the Texas layer adds a workforce training obligation with its own timing. Confirm the current training deadlines and refresh interval before you write them into your policy.

What Counts as Protected Health Information in a Med Spa

  • Intake forms, medical histories, and medication lists
  • Good faith exam documentation and treatment records
  • Before and after photographs, which are identifiable by nature
  • Appointment details tied to a named person and a treatment
  • Payment records that reveal the service received
  • Text messages and direct messages about a patient’s treatment, including on personal phones

That last item is where small practices leak information daily. Staff coordinate care by text, patients send photographs to a business social account, and none of it lands in the record system. A policy that ignores how your team actually communicates will not survive its first complaint.

What Compliance Requires in Practice

  1. Written privacy and security policies that match how your practice really operates.
  2. A documented security risk analysis, then remediation of what it finds.
  3. Workforce training at hire and at regular intervals, with attendance records kept.
  4. Business associate agreements with every vendor that touches patient information: EMR, billing, cloud storage, marketing platforms, answering services, and IT support.
  5. Access controls, unique logins, encryption of devices and backups, and a clean process for staff departures.
  6. A notice of privacy practices given to patients, and a records access process that meets the response deadlines.
  7. Written consent for marketing use of patient photographs, separate from treatment consent.
  8. A breach response plan, with the notification timelines and the regulators to notify written down before you need them.

Our HIPAA compliance checklist for Texas medical practices covers the underlying program, and the same structure applies to an aesthetic practice with a smaller vendor list.

Photographs and Marketing Are the Biggest Risk

Before and after images are the currency of aesthetic marketing and the most common source of med spa privacy complaints. Treatment consent is not marketing consent. A patient who agreed to clinical photography has not agreed to appear in an advertisement, and cropping a face does not necessarily de-identify an image that shows a distinctive tattoo or setting. Get a separate, specific, written authorization, record where the image may be used, and honor withdrawal of consent including removal from platforms you do not control.

Responding publicly to an online review is the other frequent failure. Confirming that someone was a patient, in a reply, discloses protected information. Answer without confirming treatment, and take the detail offline. Our roundup of the most common HIPAA violations covers the same pattern in other settings.

What Happens When It Goes Wrong

Federal penalties scale with culpability and can be significant even for a small practice, and Texas adds its own enforcement and penalty regime through the Attorney General. Beyond penalties, a privacy failure in an aesthetic practice does reputational damage that is hard to price, because the information involved is exactly what patients expected you to keep quiet.

Frequently Asked Questions

Is a cash-only med spa exempt from HIPAA?

It may fall outside HIPAA’s covered entity definition if it never transmits electronic health care transactions, but Texas medical privacy law defines covered entity far more broadly, so the practice still owes privacy duties.

Do we need a BAA with our marketing agency?

Yes, if the agency can access patient information, including photographs, review responses, or intake data. If it only receives de-identified material, document that boundary in the contract.

Can we post before and after photos on social media?

Only with a separate written authorization that covers marketing use, names the platforms or media, and explains that removal from third-party platforms may not be complete. Treatment consent alone is not enough.

Does HIPAA training apply to front desk staff?

Yes. Anyone in the workforce who may encounter patient information needs training, including front desk, sales, and cleaning staff who see schedules, charts, or screens.

Talk to a Texas Healthcare Lawyer

We build privacy programs sized for aesthetic practices, including photograph consent and vendor agreements. At Dike Law Group, healthcare law is the only thing we do. We work with physicians, nurses, and healthcare business owners across Texas, including Dallas, Frisco, Houston, Austin, and San Antonio.

Call (972) 290-1031 or visit our Texas med spa lawyer page to get started. Our office is at 6160 Warren Parkway, Ste. #100, Frisco, TX 75034.

Disclaimer: This article is intended for general educational purposes only and does not constitute legal advice. For guidance specific to your situation, please consult a qualified Texas healthcare attorney.

 

author avatar
Doris Dike Founder & Healtcare Attorney
Doris Dike, Esq., founder of Dike Law Group. Dike Law Group specializes in legal services for the healthcare industry, with a focus on MedSpa compliance, MSO structures, and regulatory matters for medical practices. Key search terms highlight their expertise in telehealth, IV hydration clinics, and medical contract review for entrepreneurs.