Notes from Pronk · No. 31 · June 2026Advertising

HIPAA-Compliant Med Spa Marketing: Ads, Email, CRM & Checklist

HIPAA rules for every med spa marketing channel: Meta Ads, Google Ads, email, CRM, patient photos, review responses. Plus a 30-point compliance checklist.

By Matt Watsonfig. 28 min readfor the patient practitionerUpdated
HIPAA-Compliant Med Spa Marketing: Ads, Email, CRM & Checklist

Most med spa owners hear "HIPAA compliance" and think of two things: their EHR system and the stack of intake forms patients sign. They rarely think about their marketing.

That blind spot is where violations happen.

Your front desk staff knows not to discuss a patient's treatment in the waiting room. But your marketing team might be uploading patient email lists to Meta for ad targeting. Your CRM might be sending automated texts that reference specific treatments. Your website forms might be collecting health information over unencrypted connections. Each of those is a potential HIPAA violation, and the Office for Civil Rights does not care whether you knew the rules or not.

This guide covers what HIPAA actually requires from your marketing operations. Not the clinical side. Not the intake paperwork. The marketing side: Meta Ads, Google Ads, email, website forms, CRM data, patient photos, testimonials, and the tracking technologies that connect everything together.

Note

This article is educational content, not legal advice. HIPAA requirements interact with state laws and your specific practice setup. Work with a healthcare attorney who specializes in medical aesthetics for guidance tailored to your situation. The American Med Spa Association (AmSpa) publishes updated compliance resources regularly.

$50K
maximum HIPAA penalty per violation, up to $1.5M per year per category

What HIPAA actually covers in marketing (and what it does not)

HIPAA applies to med spa marketing whenever data links an identifiable person to a health condition, treatment, or payment. An email list with names alone is not protected. That same list segmented by treatment interest becomes protected health information (PHI) because it connects identity to a health-related concern. Both pieces must be present: identity and health connection.

Here is where it gets practical for marketing teams:

Not PHI: A list of 5,000 email addresses collected through a general "subscribe to our newsletter" form that asks for name and email only. No health information is attached, so HIPAA does not apply.

PHI: That same list, segmented by treatment interest after someone fills out a form asking "What treatment are you interested in?" Now you have linked an identifiable person to a health-related interest. HIPAA applies.

Not PHI: A Google Analytics report showing 340 people visited your Botox page last month. Aggregate, anonymous data is not PHI.

PHI: A Meta Pixel sending data to Facebook showing that Jane Smith (matched via her email) visited your Botox page on Tuesday. Now an identifiable person is linked to a health interest, and that data was shared with a third party.

The line between PHI and non-PHI in marketing often comes down to one question: can this data link a specific person to a health condition or treatment? If yes, HIPAA governs how you collect, store, share, and use it.

Meta Ads: the two compliance layers

Med spa Meta Ads must satisfy two separate compliance requirements at the same time: HIPAA (which governs how you handle patient data in targeting and tracking) and Meta's own advertising policies (which restrict healthcare claims, before-and-after imagery, and audience targeting options). A campaign that passes Meta's review but violates HIPAA still exposes your practice to federal penalties up to $50,000 per incident.

HIPAA governs how you handle patient data. Any information that can identify a patient and relates to their health condition, treatment, or payment is protected health information (PHI). HIPAA restricts how you collect, store, share, and use PHI. When you upload a patient email list to Meta for a Custom Audience, you are sharing PHI with a third party. That requires either a Business Associate Agreement (BAA) with Meta (which Meta does not sign for advertising) or explicit patient authorization.

Meta's ad policies govern what you can say and how you can target. Meta classifies certain ad categories as "Special Ad Categories" and restricts targeting options. Healthcare ads face additional scrutiny on claims, imagery, and audience targeting. Meta's automated review system scans ad creative for policy violations, and human reviewers can flag accounts for manual review.

You need to satisfy both layers simultaneously. A campaign that is HIPAA-compliant but violates Meta's policies gets rejected. A campaign that passes Meta's review but violates HIPAA exposes your practice to federal penalties.

What you cannot do with Meta Ads (the hard restrictions)

Upload patient lists as Custom Audiences

This is the most common HIPAA violation in med spa advertising. Your CRM contains patient names, emails, phone numbers, and treatment history. That is PHI. Uploading that list to Meta for Custom Audience targeting shares PHI with a third party that does not have a BAA with your practice.

Meta hashes the data before matching, but hashing is not encryption. The HHS guidance on de-identification does not consider hashing alone sufficient for de-identification under the Safe Harbor method. The data is still traceable to individual patients.

The compliant alternative: Use Meta's interest-based and geographic targeting instead of Custom Audiences built from patient data. You can target by age, location, income, and interests without touching PHI.

Retarget based on specific treatment page visits

Standard Meta Pixel implementation fires on every page a visitor views, including treatment-specific pages like "/botox" or "/coolsculpting." When that browsing data reaches Meta's servers, it associates a specific person with a specific health interest. That is health-related data about an identifiable individual, which makes it PHI under the HHS bulletin on tracking technologies.

The compliant alternative: Configure server-side tracking that filters out health-related page URLs before data reaches Meta. Or retarget all website visitors as a single audience without segmenting by treatment interest. You lose some targeting precision, but you eliminate the HIPAA exposure.

Use before-and-after transformation imagery

Meta's advertising policies prohibit imagery that implies a specific medical outcome. A side-by-side before-and-after photo of a Botox patient violates this policy. So does any creative that implies "this treatment will make you look like this."

The compliant alternative: Show the treatment experience, not the result. A patient in a comfortable treatment room. A provider consulting with a patient. A lifestyle shot of someone feeling confident. Video content that walks through what a treatment visit looks like. These formats convey quality and professionalism without making outcome claims.

Make specific medical claims without clinical backing

"Lose 20 pounds with our semaglutide program." "Eliminate your wrinkles permanently." "Look 10 years younger." These claims trigger both Meta's ad review system and FTC scrutiny. Unless you are citing published clinical trial data with proper attribution, specific outcome claims are off-limits.

The compliant alternative: Frame results as possibilities, not guarantees. "Patients in clinical trials lost an average of 15% body weight" (with citation) is compliant. "Our GLP-1 program helps patients reach their weight loss goals with physician oversight" is compliant. The specificity of the claim determines the risk.

Ready to grow your practice?

Get a custom strategy for your med spa

Schedule Your Strategy Session

No commitment required. No credit card.

What you can do with Meta Ads (and should be doing)

Geographic and demographic targeting

Meta's location targeting lets you reach people within a specific radius of your practice. Layer on age ranges (25 to 55 for most med spa services), income targeting, and interest categories like beauty, skincare, wellness, and fitness. This reaches your ideal patient profile without any PHI.

Lookalike Audiences built from non-PHI sources

You cannot upload your patient list, but you can build a Lookalike Audience from your website visitors (using compliant tracking) or from people who engaged with your Instagram or Facebook page. These seed audiences contain no PHI because they are based on public platform interactions, not your clinical records.

Educational content campaigns

The highest-performing med spa Meta campaigns in 2026 lead with education, not promotion. A 30-second video of your provider explaining how neurotoxins work. A carousel post walking through the five steps of a CoolSculpting treatment. An infographic showing the difference between dermal fillers and neurotoxins.

Educational content builds trust, generates engagement, and avoids the compliance issues that come with outcome-focused creative. It also performs better. Patients in the consideration phase want information, not sales pitches.

Testimonial quotes (without transformation photos)

Patient testimonials are powerful social proof, and they are compliant when handled correctly. Use written quotes with patient consent. "I finally feel confident without makeup" over a clean branded graphic works. What does not work: pairing that quote with a before-and-after photo.

Video testimonials where the patient describes their experience (not their specific medical outcome) perform well and typically pass Meta's review.

Compliant retargeting with server-side filtering

You can retarget website visitors if your tracking infrastructure filters out health-related data before it reaches Meta. This means:

  1. Implement server-side tracking (Meta Conversions API) instead of relying solely on the client-side Pixel
  2. Strip treatment-page URLs from the data sent to Meta
  3. Send only generic events (PageView, Lead) without treatment-specific parameters
  4. Retarget all visitors as a single audience rather than segmenting by treatment interest

This approach preserves retargeting capability (which typically increases conversion rates by 30 to 40 percent) without creating HIPAA exposure.

The Meta Pixel problem (and how to solve it)

The standard Meta Pixel is a JavaScript snippet that fires on every page load and sends browsing data to Meta's servers. For a med spa website, that means Meta receives data showing that a specific person viewed your Botox page, your semaglutide page, or your pricing page. Under the HHS guidance on tracking technologies issued in 2022 (and upheld in subsequent updates), this constitutes sharing PHI with a third party.

The solution is the Meta Conversions API (CAPI), configured with server-side filtering:

Step 1: Remove the standard Meta Pixel from treatment-specific pages, or configure it to fire only generic PageView events without URL parameters.

Step 2: Implement the Conversions API on your server. This gives you control over exactly what data reaches Meta.

Step 3: Filter the data server-side. Strip treatment-specific page paths, remove any form fields that could contain health information, and send only the minimum data needed for ad optimization.

Step 4: Test thoroughly. Use Meta's Event Manager to verify that treatment-specific URLs are not appearing in the data Meta receives.

This setup requires technical implementation, but it is the only way to run Meta retargeting campaigns without HIPAA risk. A generalist marketing agency will not know how to do this. A med spa marketing specialist will.

Meta campaign architecture that works within the rules

Here is how to structure a compliant Meta advertising program that still generates booked treatments:

Top of funnel: awareness campaigns

Objective: Reach new potential patients in your market. Targeting: Geographic radius + age + income + interests (beauty, skincare, wellness). Creative: Educational videos, provider introductions, practice tour content. Compliance status: No PHI involved. No medical claims. Fully compliant.

Middle of funnel: engagement retargeting

Objective: Re-engage people who interacted with your social content. Targeting: Custom Audiences built from Instagram/Facebook engagement (likes, comments, video views, profile visits). These are platform-native interactions, not PHI. Creative: Deeper educational content, patient testimonials (quote-based), treatment explainers. Compliance status: No PHI involved. Engagement data stays within Meta's platform.

Bottom of funnel: website visitor retargeting (compliant)

Objective: Bring back website visitors who did not book. Targeting: All website visitors as a single audience (no treatment-page segmentation), using filtered server-side tracking. Creative: Consultation CTAs, limited-time offers, social proof compilations. Compliance status: Compliant when server-side filtering strips health-related data.

Conversion: lead generation

Objective: Capture consultation requests. Format: Meta Lead Forms (data stays within Meta's platform) or traffic campaigns to your booking page. Compliance note: If using Lead Forms, the data collected stays within Meta until you download it. Once you import leads into your CRM, they become part of your clinical record system and HIPAA applies.

30-40%
conversion rate improvement from compliant retargeting vs. no retargeting

Google Ads compliance for med spas

Google Ads carries lower HIPAA risk than Meta because targeting relies on search keywords rather than patient data uploads. The two main compliance issues are conversion tracking (which can send treatment-page URLs to Google alongside user identifiers) and Customer Match lists (which share PHI if built from patient records). Server-side conversion tracking with URL filtering solves the first. Avoiding CRM-sourced uploads solves the second.

HIPAA considerations

Conversion tracking. Google Ads conversion tracking works similarly to the Meta Pixel. If your conversion tag fires on a treatment-specific thank-you page and transmits that URL to Google alongside a user identifier, you are sending health-related data about an identifiable individual to a third party. Use server-side conversion tracking with URL filtering, just as you would with Meta.

Customer Match lists. Google's Customer Match feature lets you upload email lists for targeting. The same HIPAA rules apply as with Meta Custom Audiences: uploading a patient list shares PHI with a third party that does not have a BAA with your practice. Do not upload lists derived from your EHR or CRM that contain patient treatment data.

Google's healthcare advertising policies

Beyond HIPAA, Google has its own healthcare and medicines policy that restricts what med spas can promote:

  • Prescription drugs cannot be advertised without Google certification (relevant for semaglutide and other GLP-1 programs)
  • Unsubstantiated medical claims like "permanent wrinkle removal" or "guaranteed results" will get ads disapproved
  • Before-and-after imagery is generally allowed in Google Ads (unlike Meta), but the claims accompanying those images must be truthful and substantiated
  • Speculative language works better than guarantees: "patients typically see results within 2 weeks" passes review; "you will see results in 2 weeks" often does not
Tip

Google Ads restricts advertising for certain pharmaceutical products but allows advertising for the medical treatments that use those products. You cannot run a Google Ad for "semaglutide." You can run a Google Ad for "medical weight loss program" that mentions physician-supervised GLP-1 therapy on the landing page. The distinction is subtle but important for med spas offering weight loss programs.

Email marketing: what you can and cannot send

Med spas can send promotional emails to their full patient list without HIPAA issues as long as the content does not reference any individual's treatment history. A general "20% off HydraFacials" email is compliant. An email saying "it has been 90 days since your Botox treatment" uses PHI for marketing and requires prior written patient authorization. The line between compliant and non-compliant comes down to whether the email content links a specific person to a specific treatment.

What is compliant

General promotional emails sent to your full list that do not reference individual treatment history. "Spring Skincare Special: 20% off HydraFacials this month" sent to every subscriber is not a HIPAA issue. It does not contain PHI because it does not reference any individual's health information.

Educational content about treatments, skincare tips, and practice news. As long as the email content is the same for every recipient (or segmented by non-health criteria like geography or signup date), no PHI is involved.

Appointment reminders that do not include treatment details. "You have an appointment at 2pm on Thursday" is fine. "Your Botox appointment is at 2pm on Thursday" includes treatment information and requires HIPAA-compliant transmission.

What creates risk

Treatment-specific segmentation using clinical data. Pulling a list from your EHR of every patient who received Botox in the last 90 days, then emailing them a Botox rebooking reminder, uses PHI for marketing purposes. HIPAA requires prior written authorization from each patient before using their PHI for marketing communications.

Automated sequences triggered by treatment history. If your CRM sends "It's time for your next filler touch-up" based on a patient's last appointment record, that email references their treatment history. It contains PHI.

Using non-HIPAA-compliant email platforms. Your email platform needs to sign a Business Associate Agreement (BAA) if it processes any PHI. Major platforms like Mailchimp do not sign BAAs. Others like GoHighLevel, ActiveCampaign (with specific configurations), and some enterprise platforms will.

Tip

The workaround most practices miss: you can build email segments based on treatment interest expressed through marketing interactions (what someone clicked on, which lead magnet they downloaded) rather than their actual clinical records. A patient who clicked a link about neurotoxins in your last newsletter gets tagged as "interested in neurotoxins" from a marketing behavior, not from clinical data. That distinction matters for HIPAA.

The authorization exception

HIPAA's Privacy Rule includes a marketing exception for certain communications. You do not need prior authorization for communications about health-related products or treatments if:

  1. The communication is made face-to-face
  2. The communication involves a promotional gift of nominal value
  3. The communication is about your own treatments and is made for treatment or healthcare operations purposes

That third point is the one most practices misunderstand. A reminder to rebook a treatment that was part of an ongoing treatment plan can qualify as a "treatment communication" rather than "marketing" under HIPAA. But the line is thin, and the OCR has narrowed this exception over time. When in doubt, get authorization.

Patient testimonials and reviews

Patient reviews and testimonials are gold for med spa marketing. They are also a common source of HIPAA exposure. The rules differ based on who initiated the disclosure and where the content appears.

Public reviews the patient posted voluntarily

When a patient writes a Google review saying "I got amazing Botox results at this practice," they voluntarily disclosed their own health information. That disclosure is the patient's choice, and HIPAA restricts what covered entities do with PHI, not what patients do with their own information.

You can generally share a voluntarily posted public review in your marketing materials. However, your response to that review must not confirm or add to the patient's health information. Responding with "We're glad your Botox turned out great, Sarah!" confirms the individual received a specific treatment at your practice. That is a disclosure of PHI by the covered entity.

Safe response: "Thank you for sharing your experience. We appreciate your trust in our team."

Risky response: "So happy with your results! We will see you for your touch-up in October."

Solicited testimonials and case studies

When you ask a patient to provide a testimonial, you are actively seeking a disclosure of their health information for marketing purposes. This requires a signed HIPAA authorization that specifically covers:

  • What information will be used (written quote, video, photos)
  • Where it will be published (website, social media, paid ads, email, print)
  • How long the authorization lasts
  • The patient's right to revoke at any time

A general treatment consent form does not cover this. You need a separate marketing authorization form. We covered before-and-after photo consent in depth here.

Before-and-after photos

Before-and-after photos are PHI regardless of whether the patient's face is visible. The photos reveal that a specific person received a specific medical treatment. Even cropped photos showing only a treatment area can be PHI if they can be matched to an individual through metadata, context, or other identifying information.

Every before-and-after photo used in marketing requires a signed HIPAA authorization specifying the channels where the photo will appear. Keep signed authorizations on file and track which photos are cleared for which channels in your CRM or image management system.

Website forms and data collection

Every form on your med spa website that collects a name (or email, or phone number) alongside health-related information creates PHI. This includes contact forms that ask about treatment interest, consultation request forms, quiz funnels, and appointment request widgets.

What makes a form HIPAA-compliant

Encrypted transmission. Your entire site should run on HTTPS (SSL/TLS encryption). Form submissions must be encrypted in transit. This is non-negotiable and also a basic Google ranking factor.

Secure storage. Form data must be stored in an access-controlled system with encryption at rest. If your form submissions land in a shared Gmail inbox that five staff members access from personal phones, that is not compliant.

Business Associate Agreement with your form processor. If you use a third-party form tool (Typeform, Jotform, Gravity Forms, a CRM's built-in forms), you need a BAA with that vendor if the form collects PHI. Not all form providers will sign BAAs. Verify before you build.

Access controls. Only authorized staff should access form submissions containing PHI. Role-based permissions in your CRM or form platform should limit who sees what.

Minimum necessary standard. Only collect the information you actually need. If your consultation request form asks for medical history, insurance information, and a detailed description of the patient's concerns, you are collecting more PHI than necessary for a marketing inquiry. Keep intake forms for the clinical side. Keep marketing forms simple: name, contact info, and general treatment interest at most.

Warning

Chat widgets and chatbots on your website create HIPAA risk when patients share health information through them. If your chat tool stores conversation logs that include health-related messages tied to identifiable users, that data is PHI. Make sure your chat provider signs a BAA, and train your chat flows to redirect clinical questions to secure channels rather than collecting health details in the chat interface.

CRM and patient data handling

A CRM contact record becomes protected health information the moment you attach treatment history, consultation notes, or clinical data to it. A lead with just a name and email is not PHI. That same lead tagged with "received Botox 6/15" is PHI, which triggers BAA requirements with your CRM vendor, access controls, audit logging, and encrypted data storage. Your CRM is the system most likely to blur the line between marketing data and clinical data.

When marketing data becomes PHI

A lead captured through a Google Ad who submits a contact form with their name and email is not PHI on its own. That lead becomes PHI the moment you:

  • Add a tag indicating their treatment interest based on clinical interaction
  • Attach appointment notes or treatment history from your EHR
  • Record consultation details in their contact record
  • Link their CRM profile to their patient record in your EHR

This matters because every platform that stores PHI requires a BAA, every person who accesses PHI needs HIPAA training, and every data transfer involving PHI must be encrypted and logged.

CRM compliance requirements

BAA with your CRM vendor. GoHighLevel, HubSpot (enterprise), Salesforce Health Cloud, and several other platforms offer BAAs. Confirm yours is signed and current.

Access controls. Use role-based permissions. Your social media coordinator does not need access to contact records with treatment history. Your billing team does not need access to marketing campaign data.

Audit trails. Your CRM should log who accessed which records and when. If you ever face an OCR investigation, audit trails are the first thing they request.

Data retention policies. Define how long you keep marketing data and under what conditions it gets deleted. HIPAA does not mandate a specific retention period for marketing data, but your retention policy should be documented and consistent.

Integration security. If your CRM integrates with your EHR, email platform, ad platforms, or booking software, each integration point is a potential data exposure. Map every data flow and verify that PHI is encrypted at every handoff.

71%
of healthcare data breaches involve unauthorized access to electronic records (HHS breach portal data)

Common mistakes that get med spas in trouble

After working with dozens of med spa practices on their marketing compliance, these are the violations we see most often:

1. Uploading patient email lists to ad platforms

The most common and most dangerous mistake. Your patient list from your EHR or CRM contains PHI. Uploading it to Meta, Google, or any ad platform for audience targeting shares that PHI with a third party. Neither Meta nor Google will sign a BAA for advertising purposes.

Fix: Use platform-native targeting (demographics, interests, geography) and Lookalike Audiences built from non-PHI sources.

2. Running an unfiltered Meta Pixel on treatment pages

The standard Meta Pixel sends every URL a user visits to Meta's servers. When that includes "/botox-treatment" or "/coolsculpting-consultation," you have sent health-interest data about an identifiable person to a third party.

Fix: Implement the Conversions API with server-side filtering that strips treatment-specific URLs before data reaches Meta.

3. Sending treatment-specific emails without authorization

"Your Botox is wearing off! Time to rebook." This email, triggered by a treatment date in your CRM, uses PHI for marketing without authorization.

Fix: Build email segments based on marketing behavior (what they clicked or downloaded) rather than clinical data. Or obtain explicit HIPAA authorization for treatment-specific marketing communications.

4. Responding to reviews with treatment details

A patient leaves a Google review: "Love my lip filler results!" You respond: "We're so glad you love your new lips, Sarah! Dr. Patel did a beautiful job with the Juvederm." You just confirmed a specific patient received a specific treatment. That is a PHI disclosure by a covered entity.

Fix: Keep review responses generic. Thank the patient. Express appreciation. Never confirm, add to, or specify treatment details in a public response.

5. Collecting health information on non-compliant forms

Your website contact form asks "What treatment are you interested in?" and submits to a Google Sheet or generic email inbox. That data combines identity with health interest, making it PHI, and it is being stored without encryption, access controls, or a BAA.

Fix: Use a HIPAA-compliant form processor with a signed BAA that stores submissions in an encrypted, access-controlled system.

6. Skipping BAAs with marketing vendors

Your marketing agency manages your CRM, sends emails on your behalf, and has access to patient data. Without a signed BAA, they are handling PHI as an unauthorized third party. If they experience a data breach, your practice is liable.

Fix: Execute BAAs with every vendor that accesses, stores, or processes patient data. This includes your marketing agency, CRM vendor, email platform, SMS platform, and cloud storage provider.

7. Using personal devices for patient photos

Staff taking before-and-after photos on personal phones. Photos syncing to personal iCloud or Google Photos accounts. Images shared via personal text messages to the marketing team. Every step of that workflow violates HIPAA.

Fix: Use a dedicated device with encryption enabled, disable cloud sync, and transfer photos to your secure image management system through an encrypted channel.

Your HIPAA marketing compliance checklist

Use this checklist to audit your current marketing operations. If you cannot check every box, you have compliance gaps that need attention.

Email marketing

  • Email platform has a signed BAA on file
  • Promotional emails do not reference individual treatment history
  • Email segments are based on marketing behavior, not clinical data
  • Treatment-specific rebooking emails have patient authorization
  • Unsubscribe process is documented and functional
  • Email templates have been reviewed for accidental PHI inclusion

Advertising (Meta and Google)

  • No patient lists uploaded to any ad platform for targeting
  • Meta Pixel is filtered or removed from treatment-specific pages
  • Conversions API uses server-side filtering for health-related URLs
  • Google Ads conversion tracking strips treatment-specific page data
  • No Customer Match lists built from patient/EHR data
  • Ad creative does not make unsubstantiated medical outcome claims
  • Before-and-after photos used in ads have signed marketing authorization

Website

  • Entire site runs on HTTPS with valid SSL certificate
  • Forms collecting health-related info use a HIPAA-compliant processor
  • BAA is signed with form/hosting vendor if forms collect PHI
  • Chat widget provider has signed a BAA (if chat collects health info)
  • Privacy policy is current and accurately describes data practices
  • Cookie consent mechanism is implemented and functional

CRM and data handling

  • CRM vendor has a signed BAA on file
  • Role-based access controls limit who sees PHI
  • Audit logging is enabled for contact record access
  • Data retention policy is documented and followed
  • EHR-to-CRM integrations encrypt data in transit
  • Marketing data is separated from clinical data where possible

Patient content (photos, testimonials, reviews)

  • Separate marketing authorization form exists (not just treatment consent)
  • Signed authorizations specify channels (web, social, ads, email, print)
  • Before-and-after photos are stored in an encrypted, access-controlled system
  • Review responses never confirm or add treatment details
  • Staff knows not to use personal devices for patient photography
  • Photo consent tracking is integrated into CRM workflow

Vendor management

  • All marketing vendors with PHI access have signed BAAs
  • BAAs are reviewed annually and updated as needed
  • Marketing team members have completed HIPAA training
  • Incident response plan covers marketing-related breaches
  • Compliance officer reviews marketing campaigns quarterly

The bottom line

HIPAA marketing compliance is not about avoiding digital marketing. It is about building the right systems so your marketing works without creating legal exposure. The practices that get this right run email campaigns that feel personal without using clinical data. They run Meta Ads and Google Ads that generate leads without sharing PHI. They collect reviews and testimonials with proper authorization. And they sleep better knowing an OCR audit would not turn up marketing violations buried in their tech stack.

The technical setup matters. The vendor agreements matter. The daily workflows matter. If you are not sure whether your current marketing operations are compliant, schedule a strategy session and we will audit your setup, identify the gaps, and build compliant systems that still fill your treatment rooms.

Frequently Asked Questions

Ready to grow your practice?

Get a custom strategy for your med spa

Schedule Your Strategy Session

No commitment required. No credit card.

From the editor's deskNo. 31

If you'd like Pronk to run this for your practice, we work with one med spa per city. The first session is a working call, not a sales pitch.

Schedule a Strategy SessionNo commitment. No credit card.
Matt Watson, Founder of Pronk MedSpa Marketing

Matt Watson

Founder, Pronk MedSpa Marketing

23+ years in digital marketing. Helped develop the original SEO strategy for Ideal Image. Harvard Healthcare Strategy. MBA. PMP. Matt and the Pronk MedSpa Marketing team work with one med spa per city to build marketing systems that actually compound over time.

Your City Might Still Be Open

Ready to Stop Leaking Revenue?

Every month without a strategy is another month your competitors compound their advantage. Let's fix that.

Free strategy session. No commitment. You keep everything we share regardless.