Med Spa Medical Records & Retention: HIPAA & EMR Rules for 2026
What records a med spa must keep, how long to keep them by state, and how HIPAA governs storing, releasing, and destroying patient files — the documentation regulators and plaintiff attorneys actually ask for.
TL;DR
A med spa must keep a complete clinical chart for every patient — history, Good Faith Exam, consent, treatment notes, and before-and-after photos — plus its HIPAA compliance records. HIPAA does not set a patient-record retention period; your state does, typically six to ten years for adults and much longer for minors. HIPAA's Security Rule governs how you store, secure, release, and destroy those records. This guide covers what to keep, retention by state, EMR versus paper, consent and photo storage, patient access, secure destruction, and what happens when a provider leaves or the spa closes.
Every treatment a med spa performs generates a legal record — and that record outlives the appointment by years. A med spa medical record is not just clinical housekeeping; it is the single most important piece of evidence in a malpractice claim, a board complaint, or a state inspection. When something goes wrong, the first thing an attorney or investigator requests is the chart. If it is incomplete, missing, stored insecurely, or destroyed too early, the absence itself becomes the finding.
Yet records management is the compliance pillar most operators postpone. It has no glamour, no before-and-after photo, and no immediate revenue. This guide fixes that. It walks through exactly what records a med spa must keep, how long to keep them (with real numbers by state), whether you need an EMR, how HIPAA governs storage and security in 2026, how to handle consent forms and clinical photos, who can access and release records, how to destroy old files legally, and what happens to records when a provider leaves or the practice closes. For the wider framework these records live inside, see our guide to what med spa compliance actually requires in 2026.
- What to keep: Chart, history, Good Faith Exam, consent, treatment notes with lot numbers, photos, standing orders, plus HIPAA compliance records
- How long: Set by state law — typically 6–10 years for adults; longer for minors. Keep the longest applicable period
- HIPAA documents: 6 years for policies, risk analyses, and training logs (45 CFR 164.316)
- EMR required? Not by law, but strongly expected — and HIPAA's Security Rule applies to it
- Destruction: Shred or wipe only after retention ends; log every destruction event
What Counts as a Med Spa Medical Record?
Operators often picture "the record" as a single intake form. In reality, a med spa medical record is a bundle of documents that together tell the complete story of a patient encounter — who the patient is, why they were treated, that they consented, what was done, and how they responded. Regulators and courts read the chart as one continuous narrative, and a gap anywhere in that narrative is a liability. Here is what belongs in every patient's file.
The Clinical Chart and Treatment Notes
The core of the record is the clinical chart: patient demographics, a complete medical and medication history, allergies, and a dated treatment note for every visit. Each note should document the product used, the exact dose or device parameters, the lot number and expiration for injectables, the injection sites or treatment areas, the provider who performed the service, and the patient's tolerance and immediate response. Lot-number traceability matters more than operators expect — in a product recall or an adverse-event investigation, the chart is how you prove which vial went into which patient.
Intake, History, and the Good Faith Exam
Before any prescription treatment — including neuromodulators and fillers — most states require a documented Good Faith Exam establishing medical appropriateness. That exam is a record in its own right: it must show who performed it, when, what was assessed, and the resulting authorization to treat. The intake and history that feed the exam are equally discoverable. A chart that shows a signed consent but no underlying exam or history invites the question of whether the treatment was medically justified at all.
Consent Forms
Every treatment requires signed, treatment-specific informed consent documenting the risks, benefits, alternatives, and the patient's acknowledgment. Consent forms are part of the medical record and follow the same retention clock as the rest of the chart. For the full anatomy of a compliant consent — and the forms every service line needs — see our med spa consent forms guide.
Before-and-After Photos, Standing Orders, and Prescriptions
Clinical photographs document baseline condition and outcome and are treated as part of the record. Standing orders — the physician's written authorization allowing nurses to treat under defined conditions — and any prescriptions or medication orders also belong in your documentation system. So does adverse-event documentation: if a complication occurs, the incident report, the response taken, and the follow-up become some of the most scrutinized pages in the entire file.
What Records Does a Med Spa Legally Need to Keep?
It helps to split med spa records into two categories, because they answer different legal questions and each has its own retention clock. Clinical records prove you met the standard of care for a specific patient. Compliance records prove your practice as an organization met its legal and HIPAA obligations. A regulator inspecting your practice will ask for both; a plaintiff's attorney will subpoena both. The table below is the working inventory.
| Category | Records to Keep | Retention Clock |
|---|---|---|
| Clinical chart | Demographics, history, Good Faith Exam, treatment notes, dosing and lot numbers | State medical-record law |
| Consent & photos | Treatment-specific consent, photography consent, before-and-after images | Same as clinical chart |
| Orders & Rx | Standing orders, prescriptions, controlled-substance logs (if applicable) | State + DEA rules |
| Adverse events | Incident reports, complication response, follow-up, MedWatch filings | Longest applicable |
| HIPAA compliance | Privacy & security policies, risk analysis, BAAs, training logs, breach records | 6 years (45 CFR 164.316) |
| Operational | Destruction logs, access logs, equipment maintenance, staff license verification | Practice policy + state |
The most common mistake is keeping clinical charts diligently while neglecting the compliance column entirely. In an Office for Civil Rights investigation, the government does not start by reading patient charts — it asks for your risk analysis, your policies, your Business Associate Agreements, and your training logs. If those do not exist, you have a documentation failure before a single clinical question is asked. The med spa policy and procedure manual is where the compliance-side records are defined and maintained.
How Long Must a Med Spa Keep Medical Records?
This is the question operators get wrong most often, because they assume HIPAA sets the number. It does not. Understanding retention means separating two distinct rules that people constantly conflate.
The HIPAA 6-Year Rule — What It Actually Covers
HIPAA does contain a six-year retention requirement, at 45 CFR 164.316(b)(2)(i) — but it applies to HIPAA compliance documentation, not to patient charts. That six-year clock covers your written privacy and security policies, risk analyses, Business Associate Agreements, staff training records, authorizations, audit logs, and breach documentation. Keep those for six years from the date they were created or last in effect, whichever is later. Nothing in HIPAA tells you how long to keep a patient's actual medical record.
State Medical-Record Retention Periods
Patient-record retention is set by state law, and the periods vary widely. There is no national number. Adult medical records generally must be kept somewhere between five and ten years from the date of the last patient contact, though some states run shorter and Massachusetts hospitals famously run to twenty. Here are representative adult periods for large med spa markets:
| State | Adult Records (Physician/Practice) | Notes |
|---|---|---|
| Florida | 5 years from last contact | Hospitals 7 years; board rule 64B8-10.002 |
| Texas | 7 years from last treatment | Minors: until age 21 or 7 years, whichever is longer |
| California | 7 years (licensed facilities) | Minors: at least 1 year past age 18, min 7 years |
| New York | 6 years | Minors: until age 22 or 6 years, whichever is later |
| Illinois | ~10 years (hospitals) | Confirm the rule for your facility type |
Retention statutes change and vary by provider type and facility license. Always confirm the current rule for your exact license category with your state board or a healthcare attorney before setting a policy.
Minors — the Longer Clock
Records for patients treated as minors carry a much longer retention obligation. The typical structure is "age of majority plus a number of years" or "whichever is later" between a fixed period and the patient reaching a certain age. Because a med spa may treat a seventeen-year-old for acne management or laser hair removal, and because minors can bring claims after they reach adulthood, a chart opened for a minor may need to be preserved for a decade or more beyond the treatment date. Flag minor charts in your system so they are never destroyed on the adult schedule.
The Rule When Federal and State Periods Differ
When more than one requirement applies to the same record, keep it for the longest period any applicable rule demands. Federal law sets a floor but does not preempt a longer state period, and a longer retention obligation from a malpractice-defense standpoint can exceed both. Because a claim or board complaint can surface years after the last visit — and the statute of limitations sometimes runs from the date of discovery, not the date of treatment — most med spas adopt a conservative uniform standard (commonly ten years for adults) rather than trying to run a different clock for every chart. A single, documented, defensible retention policy is far safer than an improvised one.
Do Med Spas Need an EMR?
No statute explicitly forces a med spa to adopt an electronic medical record. A meticulously kept paper system can technically satisfy documentation requirements. But that framing misses how the market and regulators actually behave in 2026.
EMR vs. Paper — the Practical Reality
Nearly every compliant med spa uses an EMR or EHR, because software enforces the discipline that paper leaves to chance. An EMR mandates required fields, prompts for consent capture before a treatment can be booked, timestamps every entry, restricts who can see what, and automatically backs data up. A paper binder does none of that — and a paper chart that is illegible, undated, or altered is worth little in litigation. Electronic records also make patient-access requests, audits, and retention scheduling dramatically easier to manage.
What an EMR Must Do to Be Compliant
If you use an EMR, that electronic protected health information falls squarely under HIPAA's Security Rule, so the platform itself must support compliant safeguards: unique user accounts, role-based access, audit logging, automatic session timeout, encryption, and reliable backup. Critically, the EMR vendor is a Business Associate, which means you must have a signed Business Associate Agreement (BAA) on file before any patient data goes in. A polished interface does not make a platform HIPAA-compliant — the safeguards and the BAA do. Whether your records live on paper or in software, the underlying requirement is the same: legible, complete, tamper-evident, and retained for the full state period.
How Should a Med Spa Store Patient Records Under HIPAA?
Storage is where records management meets the HIPAA Security Rule. The standard is straightforward to state and easy to fail: only authorized people should be able to reach protected health information, and every access should be traceable. HIPAA organizes the requirements into three families of safeguards.
Administrative, Physical, and Technical Safeguards
Administrative safeguards are the policies and people side: a named security official, a documented risk analysis, workforce training, and access-management procedures. Physical safeguards control the physical environment — locked record rooms, screen positioning away from public view, facility access controls, and secure disposal areas. Technical safeguards live in your systems: unique user IDs, automatic logoff, audit controls, and encryption. Paper charts are not exempt; they need a locked, access-controlled room and a written policy governing who may retrieve them and when. For the full privacy-and-security picture, our HIPAA compliance guide breaks down every safeguard a med spa must implement.
Access Controls and Audit Logs
The single most important storage principle is the minimum necessary standard: each staff member should have access only to the records their role requires. A front-desk coordinator does not need the same access as an injector. Role-based permissions, unique logins (never shared passwords), and audit logs that record who opened which chart and when are what turn "we keep records securely" from a claim into something you can prove. If an insider improperly views a record, the audit log is how you detect it — and its absence is how OCR concludes you had no controls at all.
The 2026 Security Rule Proposal
Operators should know where the rules are heading. In late 2024, HHS Office for Civil Rights issued a Notice of Proposed Rulemaking to strengthen the HIPAA Security Rule; it was published in the Federal Register in January 2025 with a comment period that closed in March 2025. The proposal would, among other things, make encryption of ePHI at rest and in transit mandatory (removing the current "addressable" flexibility), require multi-factor authentication, and mandate regular vulnerability scanning. As of mid-2026 the rule remains proposed, not final — but the direction is clear, and med spas that already encrypt data and enforce MFA are positioned for whatever version is adopted. Build toward it now rather than scrambling later.
Business Associate Agreements for Every Vendor
Any outside vendor that creates, receives, stores, or transmits your patients' PHI is a Business Associate and needs a signed BAA before it touches data: your EMR host, cloud-backup provider, billing service, secure-messaging tool, and shredding or IT-disposal vendor. Missing BAAs are one of the most common — and most easily avoided — findings in a HIPAA investigation. Keep an inventory of every vendor with PHI access and a corresponding signed agreement for each.
Records and retention, handled.
The Operations & Compliance Kit includes records-management and retention SOPs, HIPAA safeguards, consent storage workflow, and destruction logs — the documentation regulators ask for.
View Operations Kit — $197How Long Do You Keep Consent Forms and Before-and-After Photos?
Consent forms and clinical photographs raise a recurring point of confusion, because a photo can serve two entirely different purposes — clinical documentation and marketing — and each carries its own rules.
Consent Forms and Clinical Photos as Part of the Record
Signed treatment consent and clinical before-and-after photographs are part of the medical record. They follow the same retention clock as the rest of the chart: the longest of your state's medical-record period or any applicable federal rule — commonly six to ten years for adults and longer for minors. Do not file consents and photos in a separate system with a shorter lifespan; if the chart survives, they must survive with it, because a consent that cannot be produced is, for legal purposes, a consent that did not exist.
Marketing Use Requires Separate, Documented Authorization
Using a patient's before-and-after photo in advertising, on social media, or on your website is not covered by clinical treatment consent. Marketing use of an identifiable image is a HIPAA disclosure that requires its own written marketing or media-release authorization, freely revocable by the patient. Keep that release for as long as the image is in use, plus your standard retention period afterward, so you can always prove permission existed. Publishing a patient photo on the strength of a clinical consent alone is one of the fastest ways a med spa turns a happy result into a privacy complaint. Our guide to testimonial and marketing consent under HIPAA walks through exactly how to capture and store these releases.
Who Can Access and Release Med Spa Records?
Retention answers how long you keep records; access governs who is allowed to see them and how you respond when someone asks for a copy. Both patients and third parties have defined rights, and mishandling a request is itself a HIPAA violation.
The Patient Right of Access
Under HIPAA, patients have a right to access and obtain a copy of their own records, and covered entities must generally respond within 30 days. You may charge a reasonable, cost-based fee, but you cannot withhold records because a bill is unpaid, and you cannot impose unreasonable barriers. Right-of-access failures have become one of OCR's most-enforced categories, with a long run of settlements against practices that stonewalled or delayed patients. Build a simple, documented request-and-fulfillment workflow so every access request is logged, tracked, and answered on time.
Releasing Records to Third Parties
Releasing records to anyone other than the patient — another provider, an attorney, an insurer, a family member — requires a valid, signed authorization from the patient (with narrow exceptions such as treatment, payment, or operations, or a lawful subpoena). Verify the identity of the requester, confirm the authorization covers exactly what is being disclosed, apply the minimum-necessary standard, and log the disclosure. An accounting of disclosures is itself a record patients can request, so tracking what you released, to whom, and when is not optional.
Get the Free Med Spa Compliance Checklist
A printable, section-by-section checklist covering records, retention schedules, HIPAA safeguards, consent storage, and destruction logs — so you can see exactly which documentation your practice is missing before a state board or malpractice carrier does.
It usually lands in your Promotions tab (or spam) — move it to your inbox and add MedSpa Standards to your contacts so you don't miss the follow-ups.
Join 200+ med spa professionals. Unsubscribe anytime.
How Should a Med Spa Destroy Old Records?
Destroying records correctly is the mirror image of retaining them. Keep too short and you have destroyed evidence; destroy carelessly and you have breached PHI. Both are findings. The rule is simple: destroy only after the full retention period has passed, and only by a method that renders the information unreadable and unrecoverable.
Secure Destruction Methods
For paper, that means cross-cut shredding or incineration — never dropping charts in a general trash or recycling bin, which is one of the most-cited HIPAA disposal failures. For electronic records, deleting a file or emptying a recycle bin is not destruction; the data is still recoverable. Use software that overwrites or cryptographically erases the data, and physically destroy retired hard drives, backup media, and old devices before they leave your control. If you use a shredding company or IT-disposal vendor, they are Business Associates: sign a BAA and obtain a certificate of destruction for every batch.
Destruction Logs
Every destruction event must be documented. A destruction log should record what was destroyed (record type and patient identifiers or date range), the date range the records covered, the method used, the vendor and certificate reference if applicable, and who authorized the destruction. That log is itself a compliance record and should be retained long-term. If a patient or attorney later asks for a record you legitimately destroyed on schedule, the destruction log is your proof that the record's absence was routine and lawful — not spoliation.
What Happens to Records When a Provider Leaves or the Spa Closes?
Records outlast staff and, sometimes, the business itself. The two transitions operators handle worst are a provider departing and the practice closing — and both create real custody and continuity obligations.
When a Provider Leaves
In nearly every case, the practice or entity that created the records owns them — not the individual provider who charted them. When an injector, physician, or medical director leaves, the original records stay with the med spa, which remains the legal custodian and must continue to retain and safeguard them for the full statutory period. The departing provider may be entitled to copies of records for patients they personally treated, subject to your policies and state law. The way to avoid a dispute is to settle it in advance: your employment agreements and your medical-director agreement should state, in writing, who owns records, who may take copies, and how continued patient access is guaranteed after a departure.
When the Med Spa Closes
Closing the doors does not end the retention obligation. When a practice closes, someone must remain responsible for storing records for the balance of the retention period and for responding to patient-access requests. Most states require closing practices to notify patients of how to obtain their records, arrange for a custodian, and preserve the files rather than destroy them early. Plan this before you need it — a records-custodian arrangement and a patient-notification plan should be part of any wind-down. Records left orphaned when a spa closes are both a HIPAA exposure and, in many states, a licensing violation for the physician of record.
What Are the Most Common Med Spa Records Mistakes?
The failures that surface in inspections and lawsuits are rarely exotic. They are the same handful of predictable gaps, repeated across practices that never wrote down a records policy. Knowing them lets you audit your own program before someone else does.
- Charting the treatment but not the exam or consent. A treatment note with no underlying Good Faith Exam or no signed consent reads as an unauthorized procedure. The three must appear together in every chart.
- Missing lot numbers. Injectable records without lot and expiration data leave you unable to respond to a recall or trace a product-related adverse event — a documentation failure and a patient-safety gap at once.
- Treating clinical consent as marketing permission. Publishing a before-and-after photo on the strength of a treatment consent is a HIPAA disclosure without authorization. Marketing use always needs its own release.
- No Business Associate Agreements. Using an EMR, cloud backup, or shredding vendor without a signed BAA is one of the most common — and most avoidable — findings in an OCR investigation.
- Destroying records too early, or too casually. Shredding on an adult schedule when a minor clock applies, or tossing charts in the trash, converts routine housekeeping into spoliation or a breach.
- No destruction log. When you cannot prove a legitimately destroyed record was disposed of on schedule, its absence looks like concealment rather than compliance.
Every one of these is cheap to prevent and expensive to explain after the fact. A written program that assigns each of these points an owner and a procedure is what separates a practice that passes an inspection from one that scrambles through it.
Turning This Into an SOP: Your Records-Management Policy
Everything above becomes real only when it is written down as a policy your staff can follow and a regulator can inspect. A verbal understanding of "we keep records for a while and shred the old ones" is exactly the gap that turns a routine inspection into a citation. A compliant records program is documented as a set of standard operating procedures, and it should specify at minimum:
- A written retention schedule — the exact period you keep each record type, tied to your state's law, with the longer minor clock called out separately
- A storage and security policy — administrative, physical, and technical safeguards, access roles, and the minimum-necessary standard
- A patient-access workflow — how requests are received, verified, logged, and fulfilled within 30 days
- A disclosure-and-release procedure — authorization verification, minimum necessary, and an accounting of disclosures
- A destruction policy and log — approved methods, vendor BAAs, certificates of destruction, and a permanent destruction log
- A departure-and-closure plan — custody terms, copy rights, custodian arrangements, and patient notification
Most operators do not want to draft these from a blank page — and they shouldn't have to. Pre-written, physician-reviewable SOPs give you a records-management policy, a retention schedule, HIPAA safeguards, consent-storage workflow, and destruction logs that already reflect the requirements above, ready for your medical director to review and sign. You can also browse the full med spa compliance SOP library to see how records management fits alongside the consent, HIPAA, and emergency documentation your practice needs. However you build it, the goal is the same: a single, documented, defensible records program you can hand an inspector on the day they ask — not the week after.
Every record, every protocol, one library.
All 62 SOPs across every service line — including the documentation and consent frameworks your records program depends on.
View Complete Suite — $997