◈ Field notes / Compliance

MedGrid

HIPAA basics for aesthetic and wellness clinics

MedGrid · · 6 min read

Many cash-pay aesthetic and wellness clinics assume HIPAA does not apply to them. Often it does. And when it does, it reaches beyond the chart to your booking widget, photo app, texting tool and marketing. Here are the basics as of September 2026.

Are you a covered entity?

A health care provider of any size is a HIPAA covered entity if it transmits health information electronically in connection with a transaction for which HHS has adopted a standard. Examples include claims, benefit eligibility inquiries and referral authorization requests.

  • Using email does not by itself make you a covered entity. The transmission has to be tied to a standard transaction.
  • It counts whether you send the transaction yourself or a billing service sends it for you.
  • A clinic that is cash-only for injectables but bills insurance electronically for other services, such as labs or medical visits, is a covered entity.

If you are not covered, that does not mean anything goes. The FTC says the FTC Act's ban on unfair or deceptive practices applies to health data held outside HIPAA. The FTC also enforces a Health Breach Notification Rule for vendors of personal health records. State privacy laws may apply as well. Many clinics adopt HIPAA-level practices either way.

Business associate agreements

A business associate is an outside party that creates, receives, maintains or transmits protected health information (PHI) on your behalf. Before it gets PHI, you need a business associate agreement (BAA). The BAA must define what the vendor may do with the PHI, require safeguards and require reporting of security incidents and breaches. The vendor's subcontractors that handle your PHI need BAAs with the vendor.

Business associates that HHS guidance identifies and that clinics commonly use include:

  • EHR and practice management vendors, and IT companies that support your systems.
  • Cloud storage, including photo apps. A cloud provider that stores your ePHI is a business associate even if the data is encrypted and it has no key.
  • Telehealth platforms. HHS says covered providers must use vendors that comply with HIPAA and will sign a BAA. COVID-era enforcement discretion ended in 2023.
  • Patient-facing tools, such as messaging apps or a portal chatbot that handles scheduling.
  • Billing companies, consultants, accountants and lawyers whose work involves PHI.
  • Tracking and marketing vendors that receive PHI (see below).

You do not need a BAA to disclose PHI to another provider for treatment. HHS's example is a physician sending PHI to a clinical laboratory, and the same logic covers a pharmacy filling a prescription. A narrow "conduit" exception covers services that only transmit PHI, such as the Postal Service. A vendor that regularly accesses PHI is not a conduit. If a vendor won't sign a BAA, don't give it PHI without the patient's authorization.

Minimum necessary

You must make reasonable efforts to use, disclose and request only the minimum PHI a task requires, and limit each role's access accordingly. The standard does not apply to disclosures to a provider for treatment, disclosures to the patient, or disclosures the patient authorizes. In practice, front-desk and marketing staff should not have full chart access, and vendors should get only the fields they need.

Patient photos

Clinical photos in the chart are PHI. HIPAA's de-identification standard lists full-face photos and comparable images as identifiers. It also lists any other unique identifying characteristic, so a tattoo or birthmark can identify a patient in a cropped photo.

  • Store photos in your EHR or in a vendor system covered by a BAA, not on staff members' personal camera rolls or in group texts.
  • Using photos or patient stories in marketing generally requires a signed HIPAA authorization. OCR's director said so in a September 2025 settlement over "success stories" posted online. The providers paid $182,000.
  • When you reply to an online review, don't confirm or discuss the patient's care. OCR settled with a provider in 2023 over disclosures in responses to negative reviews.

Texting and emailing patients

HHS says covered providers may email patients if they use reasonable safeguards, such as confirming the address and limiting what goes into an unencrypted message. The Privacy Rule does not prohibit unencrypted email for treatment communications, but the Security Rule still applies to ePHI in transit. Patients may ask you to contact them by other reasonable means. If a patient emails you first, you may assume email is acceptable unless they say otherwise, and you can warn them about the risks.

Texts on staff phones are ePHI on those phones. Use a platform covered by a BAA for clinical texting, and set written rules for personal devices.

Under HIPAA, messages to your own patients about your own services generally are not "marketing" that requires authorization. That changes if a third party whose product the message describes pays you to send it. Either way, the platform that holds your patient list and sends the messages handles PHI, so it needs a BAA.

Website tracking: where HHS guidance stands

OCR issued a bulletin on online tracking technologies in December 2022 and revised it in March 2024. On June 20, 2024, a federal court in Texas (American Hospital Association v. Becerra) vacated part of it. The vacated part said HIPAA applies when tracking links a visitor's IP address with a visit to an unauthenticated public page about specific health conditions or providers. HHS appealed, then moved to dismiss its appeal on August 29, 2024. The bulletin page now notes the court's order.

The rest of the bulletin still stands:

  • Tracking on logged-in pages, such as patient portals and telehealth platforms, generally has access to PHI.
  • A tracking vendor that receives PHI is a business associate and needs a BAA. HHS's example is a patient booking an appointment on a clinic website that sends the appointment details and IP address to a tracking vendor.
  • A cookie banner is not a HIPAA authorization, and a privacy policy notice does not permit the disclosure. A vendor's promise to remove PHI after receiving it is not enough.

Audit the pixels and scripts on your booking, intake, checkout and portal pages. If a tool receives PHI and its vendor won't sign a BAA, remove it.

Breach notification basics

An impermissible use or disclosure of PHI is presumed to be a breach. That presumption holds unless a risk assessment shows a low probability of compromise. The assessment must weigh at least the data involved, who received it, whether it was actually viewed or acquired, and mitigation. Only unsecured PHI triggers notice, so data encrypted according to HHS guidance is exempt.

  • Patients: Notify them without unreasonable delay and no later than 60 days after discovery.
  • Media: Notify prominent outlets if more than 500 residents of a state or jurisdiction are affected.
  • HHS: Report breaches affecting 500 or more people within 60 days. Report smaller breaches within 60 days after the end of the calendar year.
  • Business associates: They must notify you no later than 60 days after discovery.

Check your state's breach notification law as well.

What is changing

OCR proposed major Security Rule updates in January 2025. As of September 2026 they had not been finalized, and the federal regulatory agenda lists final action for July 2027. The current rule still applies, including the required security risk analysis. OCR runs a Risk Analysis Initiative and announced its 12th enforcement action under it in March 2026. A documented, current risk analysis is the place to start.

This article is general information, not legal advice. Rules vary by state; confirm specifics with your counsel and your state boards.

Sources

Put this to work on MedGrid.

Verified vendors, wholesale pricing and the regulations research behind every post. Free to join with your NPI.