Notes from Pronk · No. 39 · July 2026Strategy

HIPAA Marketing Compliance for Med Spas: A Practical Guide

What HIPAA actually requires from your med spa marketing. Email, ads, website forms, CRM data, patient photos, and reviews with a compliance checklist.

By Matt Watsonfig. 20 min readfor the patient practitioner

Most med spa owners hear "HIPAA compliance" and think of two things: their EHR system and the stack of intake forms patients sign. They rarely think about their marketing.

That blind spot is where violations happen.

Your front desk staff knows not to discuss a patient's treatment in the waiting room. But your marketing team might be uploading patient email lists to Meta for ad targeting. Your CRM might be sending automated texts that reference specific treatments. Your website forms might be collecting health information over unencrypted connections. Each of those is a potential HIPAA violation, and the Office for Civil Rights does not care whether you knew the rules or not.

This guide covers what HIPAA actually requires from your marketing operations. Not the clinical side. Not the intake paperwork. The marketing side: email, ads, website forms, CRM data, patient photos, testimonials, and the tracking technologies that connect everything together.

We covered HIPAA-compliant Meta advertising in detail here. This post goes broader, covering every marketing channel where HIPAA applies and the specific mistakes that put med spas at risk.

Note

This article is educational content, not legal advice. HIPAA requirements interact with state laws and your specific practice setup. Work with a healthcare attorney who specializes in medical aesthetics for guidance tailored to your situation. The American Med Spa Association (AmSpa) publishes updated compliance resources regularly.

$50K
maximum HIPAA penalty per violation, up to $1.5M annually per category

What HIPAA actually covers in marketing (and what it does not)

HIPAA protects "protected health information" (PHI). PHI is any information that identifies a person and relates to their health condition, treatment, or payment for healthcare. Both pieces must be present: identity and health connection.

Here is where it gets practical for marketing teams:

Not PHI: A list of 5,000 email addresses collected through a general "subscribe to our newsletter" form that asks for name and email only. No health information is attached, so HIPAA does not apply.

PHI: That same list, segmented by treatment interest after someone fills out a form asking "What treatment are you interested in?" Now you have linked an identifiable person to a health-related interest. HIPAA applies.

Not PHI: A Google Analytics report showing 340 people visited your Botox page last month. Aggregate, anonymous data is not PHI.

PHI: A Meta Pixel sending data to Facebook showing that Jane Smith (matched via her email) visited your Botox page on Tuesday. Now an identifiable person is linked to a health interest, and that data was shared with a third party.

The line between PHI and non-PHI in marketing often comes down to one question: can this data link a specific person to a health condition or treatment? If yes, HIPAA governs how you collect, store, share, and use it.

Email marketing: what you can and cannot send

Email is the highest-ROI channel for patient retention in medical aesthetics. It is also one of the easiest places to accidentally violate HIPAA. The rules are more nuanced than "you cannot email patients."

What is compliant

General promotional emails sent to your full list that do not reference individual treatment history. "Spring Skincare Special: 20% off HydraFacials this month" sent to every subscriber is not a HIPAA issue. It does not contain PHI because it does not reference any individual's health information.

Educational content about treatments, skincare tips, and practice news. As long as the email content is the same for every recipient (or segmented by non-health criteria like geography or signup date), no PHI is involved.

Appointment reminders that do not include treatment details. "You have an appointment at 2pm on Thursday" is fine. "Your Botox appointment is at 2pm on Thursday" includes treatment information and requires HIPAA-compliant transmission.

What creates risk

Treatment-specific segmentation using clinical data. Pulling a list from your EHR of every patient who received Botox in the last 90 days, then emailing them a Botox rebooking reminder, uses PHI for marketing purposes. HIPAA requires prior written authorization from each patient before using their PHI for marketing communications.

Automated sequences triggered by treatment history. If your CRM sends "It's time for your next filler touch-up" based on a patient's last appointment record, that email references their treatment history. It contains PHI.

Using non-HIPAA-compliant email platforms. Your email platform needs to sign a Business Associate Agreement (BAA) if it processes any PHI. Major platforms like Mailchimp do not sign BAAs. Others like GoHighLevel, ActiveCampaign (with specific configurations), and some enterprise platforms will.

Tip

The workaround most practices miss: you can build email segments based on treatment interest expressed through marketing interactions (what someone clicked on, which lead magnet they downloaded) rather than their actual clinical records. A patient who clicked a link about neurotoxins in your last newsletter gets tagged as "interested in neurotoxins" from a marketing behavior, not from clinical data. That distinction matters for HIPAA.

The authorization exception

HIPAA's Privacy Rule includes a marketing exception for certain communications. You do not need prior authorization for communications about health-related products or treatments if:

  1. The communication is made face-to-face
  2. The communication involves a promotional gift of nominal value
  3. The communication is about your own treatments and is made for treatment or healthcare operations purposes

That third point is the one most practices misunderstand. A reminder to rebook a treatment that was part of an ongoing treatment plan can qualify as a "treatment communication" rather than "marketing" under HIPAA. But the line is thin, and the OCR has narrowed this exception over time. When in doubt, get authorization.

Patient testimonials and reviews

Patient reviews and testimonials are gold for med spa marketing. They are also a common source of HIPAA exposure. The rules differ based on who initiated the disclosure and where the content appears.

Public reviews the patient posted voluntarily

When a patient writes a Google review saying "I got amazing Botox results at this practice," they voluntarily disclosed their own health information. That disclosure is the patient's choice, and HIPAA restricts what covered entities do with PHI, not what patients do with their own information.

You can generally share a voluntarily posted public review in your marketing materials. However, your response to that review must not confirm or add to the patient's health information. Responding with "We're glad your Botox turned out great, Sarah!" confirms the individual received a specific treatment at your practice. That is a disclosure of PHI by the covered entity.

Safe response: "Thank you for sharing your experience. We appreciate your trust in our team."

Risky response: "So happy with your results! We will see you for your touch-up in October."

Solicited testimonials and case studies

When you ask a patient to provide a testimonial, you are actively seeking a disclosure of their health information for marketing purposes. This requires a signed HIPAA authorization that specifically covers:

  • What information will be used (written quote, video, photos)
  • Where it will be published (website, social media, paid ads, email, print)
  • How long the authorization lasts
  • The patient's right to revoke at any time

A general treatment consent form does not cover this. You need a separate marketing authorization form. We covered before-and-after photo consent in depth here.

Before-and-after photos

Before-and-after photos are PHI regardless of whether the patient's face is visible. The photos reveal that a specific person received a specific medical treatment. Even cropped photos showing only a treatment area can be PHI if they can be matched to an individual through metadata, context, or other identifying information.

Every before-and-after photo used in marketing requires a signed HIPAA authorization specifying the channels where the photo will appear. Keep signed authorizations on file and track which photos are cleared for which channels in your CRM or image management system.

Ready to grow your practice?

Get a custom strategy for your med spa

Schedule Your Strategy Session

No commitment required. No credit card.

Google Ads compliance for med spas

Google Ads presents fewer HIPAA pitfalls than Meta because Google's targeting relies primarily on search intent rather than personal data uploads. But compliance issues still exist.

HIPAA considerations

Conversion tracking. Google Ads conversion tracking works similarly to the Meta Pixel. If your conversion tag fires on a treatment-specific thank-you page and transmits that URL to Google alongside a user identifier, you are sending health-related data about an identifiable individual to a third party. Use server-side conversion tracking with URL filtering, just as you would with Meta.

Customer Match lists. Google's Customer Match feature lets you upload email lists for targeting. The same HIPAA rules apply as with Meta Custom Audiences: uploading a patient list shares PHI with a third party that does not have a BAA with your practice. Do not upload lists derived from your EHR or CRM that contain patient treatment data.

Google's healthcare advertising policies

Beyond HIPAA, Google has its own healthcare and medicines policy that restricts what med spas can promote:

  • Prescription drugs cannot be advertised without Google certification (relevant for semaglutide and other GLP-1 programs)
  • Unsubstantiated medical claims like "permanent wrinkle removal" or "guaranteed results" will get ads disapproved
  • Before-and-after imagery is generally allowed in Google Ads (unlike Meta), but the claims accompanying those images must be truthful and substantiated
  • Speculative language works better than guarantees: "patients typically see results within 2 weeks" passes review; "you will see results in 2 weeks" often does not
Tip

Google Ads restricts advertising for certain pharmaceutical products but allows advertising for the medical treatments that use those products. You cannot run a Google Ad for "semaglutide." You can run a Google Ad for "medical weight loss program" that mentions physician-supervised GLP-1 therapy on the landing page. The distinction is subtle but important for med spas offering weight loss programs.

Meta Ads: the short version

We wrote a complete guide to HIPAA-compliant Meta advertising that covers Custom Audiences, Pixel tracking, retargeting, creative restrictions, and compliant campaign architecture in detail. Here are the key points:

  • Do not upload patient lists for Custom Audiences. Use interest-based and geographic targeting instead.
  • Filter your Meta Pixel to prevent treatment-page URLs from reaching Meta's servers. Use the Conversions API with server-side filtering.
  • Avoid before-and-after imagery in paid ads (Meta rejects these). Use lifestyle and educational creative instead.
  • Build Lookalike Audiences from compliant sources: page engagement, video views, and filtered website visitors.
  • Use Meta Lead Forms when possible. Data collected in Lead Forms stays within Meta until you download it, reducing tracking exposure.

For the full breakdown, including campaign architecture templates and step-by-step Pixel filtering instructions, read the complete Meta HIPAA guide.

Website forms and data collection

Every form on your med spa website that collects a name (or email, or phone number) alongside health-related information creates PHI. This includes contact forms that ask about treatment interest, consultation request forms, quiz funnels, and appointment request widgets.

What makes a form HIPAA-compliant

Encrypted transmission. Your entire site should run on HTTPS (SSL/TLS encryption). Form submissions must be encrypted in transit. This is non-negotiable and also a basic Google ranking factor.

Secure storage. Form data must be stored in an access-controlled system with encryption at rest. If your form submissions land in a shared Gmail inbox that five staff members access from personal phones, that is not compliant.

Business Associate Agreement with your form processor. If you use a third-party form tool (Typeform, Jotform, Gravity Forms, a CRM's built-in forms), you need a BAA with that vendor if the form collects PHI. Not all form providers will sign BAAs. Verify before you build.

Access controls. Only authorized staff should access form submissions containing PHI. Role-based permissions in your CRM or form platform should limit who sees what.

Minimum necessary standard. Only collect the information you actually need. If your consultation request form asks for medical history, insurance information, and a detailed description of the patient's concerns, you are collecting more PHI than necessary for a marketing inquiry. Keep intake forms for the clinical side. Keep marketing forms simple: name, contact info, and general treatment interest at most.

Warning

Chat widgets and chatbots on your website create HIPAA risk when patients share health information through them. If your chat tool stores conversation logs that include health-related messages tied to identifiable users, that data is PHI. Make sure your chat provider signs a BAA, and train your chat flows to redirect clinical questions to secure channels rather than collecting health details in the chat interface.

CRM and patient data handling

Your CRM is the system most likely to blur the line between marketing data and clinical data. When marketing and clinical information live in the same platform, every contact record with a treatment tag or appointment note becomes PHI.

When marketing data becomes PHI

A lead captured through a Google Ad who submits a contact form with their name and email is not PHI on its own. That lead becomes PHI the moment you:

  • Add a tag indicating their treatment interest based on clinical interaction
  • Attach appointment notes or treatment history from your EHR
  • Record consultation details in their contact record
  • Link their CRM profile to their patient record in your EHR

This matters because every platform that stores PHI requires a BAA, every person who accesses PHI needs HIPAA training, and every data transfer involving PHI must be encrypted and logged.

CRM compliance requirements

BAA with your CRM vendor. GoHighLevel, HubSpot (enterprise), Salesforce Health Cloud, and several other platforms offer BAAs. Confirm yours is signed and current.

Access controls. Use role-based permissions. Your social media coordinator does not need access to contact records with treatment history. Your billing team does not need access to marketing campaign data.

Audit trails. Your CRM should log who accessed which records and when. If you ever face an OCR investigation, audit trails are the first thing they request.

Data retention policies. Define how long you keep marketing data and under what conditions it gets deleted. HIPAA does not mandate a specific retention period for marketing data, but your retention policy should be documented and consistent.

Integration security. If your CRM integrates with your EHR, email platform, ad platforms, or booking software, each integration point is a potential data exposure. Map every data flow and verify that PHI is encrypted at every handoff.

71%
of healthcare data breaches involve unauthorized access to electronic records (HHS breach portal data)

Common mistakes that get med spas in trouble

After working with dozens of med spa practices on their marketing compliance, these are the violations we see most often:

1. Uploading patient email lists to ad platforms

The most common and most dangerous mistake. Your patient list from your EHR or CRM contains PHI. Uploading it to Meta, Google, or any ad platform for audience targeting shares that PHI with a third party. Neither Meta nor Google will sign a BAA for advertising purposes.

Fix: Use platform-native targeting (demographics, interests, geography) and Lookalike Audiences built from non-PHI sources.

2. Running an unfiltered Meta Pixel on treatment pages

The standard Meta Pixel sends every URL a user visits to Meta's servers. When that includes "/botox-treatment" or "/coolsculpting-consultation," you have sent health-interest data about an identifiable person to a third party.

Fix: Implement the Conversions API with server-side filtering that strips treatment-specific URLs before data reaches Meta.

3. Sending treatment-specific emails without authorization

"Your Botox is wearing off! Time to rebook." This email, triggered by a treatment date in your CRM, uses PHI for marketing without authorization.

Fix: Build email segments based on marketing behavior (what they clicked or downloaded) rather than clinical data. Or obtain explicit HIPAA authorization for treatment-specific marketing communications.

4. Responding to reviews with treatment details

A patient leaves a Google review: "Love my lip filler results!" You respond: "We're so glad you love your new lips, Sarah! Dr. Patel did a beautiful job with the Juvederm." You just confirmed a specific patient received a specific treatment. That is a PHI disclosure by a covered entity.

Fix: Keep review responses generic. Thank the patient. Express appreciation. Never confirm, add to, or specify treatment details in a public response.

5. Collecting health information on non-compliant forms

Your website contact form asks "What treatment are you interested in?" and submits to a Google Sheet or generic email inbox. That data combines identity with health interest, making it PHI, and it is being stored without encryption, access controls, or a BAA.

Fix: Use a HIPAA-compliant form processor with a signed BAA that stores submissions in an encrypted, access-controlled system.

6. Skipping BAAs with marketing vendors

Your marketing agency manages your CRM, sends emails on your behalf, and has access to patient data. Without a signed BAA, they are handling PHI as an unauthorized third party. If they experience a data breach, your practice is liable.

Fix: Execute BAAs with every vendor that accesses, stores, or processes patient data. This includes your marketing agency, CRM vendor, email platform, SMS platform, and cloud storage provider.

7. Using personal devices for patient photos

Staff taking before-and-after photos on personal phones. Photos syncing to personal iCloud or Google Photos accounts. Images shared via personal text messages to the marketing team. Every step of that workflow violates HIPAA.

Fix: Use a dedicated device with encryption enabled, disable cloud sync, and transfer photos to your secure image management system through an encrypted channel.

Your HIPAA marketing compliance checklist

Use this checklist to audit your current marketing operations. If you cannot check every box, you have compliance gaps that need attention.

Email marketing

  • Email platform has a signed BAA on file
  • Promotional emails do not reference individual treatment history
  • Email segments are based on marketing behavior, not clinical data
  • Treatment-specific rebooking emails have patient authorization
  • Unsubscribe process is documented and functional
  • Email templates have been reviewed for accidental PHI inclusion

Advertising (Meta and Google)

  • No patient lists uploaded to any ad platform for targeting
  • Meta Pixel is filtered or removed from treatment-specific pages
  • Conversions API uses server-side filtering for health-related URLs
  • Google Ads conversion tracking strips treatment-specific page data
  • No Customer Match lists built from patient/EHR data
  • Ad creative does not make unsubstantiated medical outcome claims
  • Before-and-after photos used in ads have signed marketing authorization

Website

  • Entire site runs on HTTPS with valid SSL certificate
  • Forms collecting health-related info use a HIPAA-compliant processor
  • BAA is signed with form/hosting vendor if forms collect PHI
  • Chat widget provider has signed a BAA (if chat collects health info)
  • Privacy policy is current and accurately describes data practices
  • Cookie consent mechanism is implemented and functional

CRM and data handling

  • CRM vendor has a signed BAA on file
  • Role-based access controls limit who sees PHI
  • Audit logging is enabled for contact record access
  • Data retention policy is documented and followed
  • EHR-to-CRM integrations encrypt data in transit
  • Marketing data is separated from clinical data where possible

Patient content (photos, testimonials, reviews)

  • Separate marketing authorization form exists (not just treatment consent)
  • Signed authorizations specify channels (web, social, ads, email, print)
  • Before-and-after photos are stored in an encrypted, access-controlled system
  • Review responses never confirm or add treatment details
  • Staff knows not to use personal devices for patient photography
  • Photo consent tracking is integrated into CRM workflow

Vendor management

  • All marketing vendors with PHI access have signed BAAs
  • BAAs are reviewed annually and updated as needed
  • Marketing team members have completed HIPAA training
  • Incident response plan covers marketing-related breaches
  • Compliance officer reviews marketing campaigns quarterly

The bottom line

HIPAA marketing compliance is not about avoiding digital marketing. It is about building the right systems so your marketing works without creating legal exposure. The practices that get this right run email campaigns that feel personal without using clinical data. They run Meta Ads and Google Ads that generate leads without sharing PHI. They collect reviews and testimonials with proper authorization. And they sleep better knowing an OCR audit would not turn up marketing violations buried in their tech stack.

The technical setup matters. The vendor agreements matter. The daily workflows matter. If you are not sure whether your current marketing operations are compliant, schedule a strategy session and we will audit your setup, identify the gaps, and build compliant systems that still fill your treatment rooms.

Frequently Asked Questions

Ready to grow your practice?

Get a custom strategy for your med spa

Schedule Your Strategy Session

No commitment required. No credit card.

From the editor's deskNo. 39

If you'd like Pronk to run this for your practice, we work with one med spa per city. The first session is a working call, not a sales pitch.

Schedule a Strategy SessionNo commitment. No credit card.
Matt Watson, Founder of Pronk MedSpa Marketing

Matt Watson

Founder, Pronk MedSpa Marketing

23+ years in digital marketing. Helped develop the original SEO strategy for Ideal Image. Harvard Healthcare Strategy. MBA. PMP. Matt and the Pronk MedSpa Marketing team work with one med spa per city to build marketing systems that actually compound over time.

Your City Might Still Be Open

Ready to Stop Leaking Revenue?

Every month without a strategy is another month your competitors compound their advantage. Let's fix that.

Free strategy session. No commitment. You keep everything we share regardless.