July 2026 Updated September 20, 2026 22 min read

Med Spa Testimonial & Marketing Consent: The HIPAA Rules (2026)

Patient testimonials, before-and-after photos, and glowing reviews are the most persuasive marketing a med spa has — and the fastest way to a HIPAA violation. This is the artifact guide: when you need a signed authorization, exactly what the form must contain, and how to store it.

In short

A patient testimonial or before-and-after photo is protected health information, and using it to promote your practice is "marketing" under HIPAA — which means you need a signed authorization that meets 45 CFR 164.508 before you post. That authorization must be separate from intake consent, must list specific required elements, and must be stored for years. This guide gives you the checklist, the storage rules, the review-response script, and the takedown workflow — the documentation artifacts your consent library needs.

Nothing sells aesthetic treatments like proof. A jawline before and after filler, a patient describing how semaglutide changed her year, a five-star review that names the injector — these convert browsers into bookings better than any ad you can buy. Which is why med spas reach for them constantly, and why the Office for Civil Rights keeps writing settlement checks into the record.

Here is the truth most owners never hear until a complaint lands: a testimonial and a before-and-after photo are protected health information (PHI), and using PHI to promote your business is "marketing" under HIPAA. That triggers a specific federal requirement — a signed, compliant authorization under 45 CFR 164.508 — that a checkbox in your intake packet or a verbal "sure, use my photo" does not satisfy.

This is a documentation-artifact guide. It covers when marketing use crosses into HIPAA territory, the exact elements a valid authorization must contain, why you cannot bundle it into intake paperwork, how to store and retain the signed forms, how to answer reviews without confirming anyone is a patient, and how the FTC's rules on before-and-after imagery stack on top. For the underlying privacy framework, our med spa HIPAA compliance guide covers covered-entity basics; this post is the marketing-and-consent layer on top of it.

Quick Answer: Marketing Consent Under HIPAA
  • Testimonials & before/after photos = PHI. Using them to promote the practice is "marketing" and needs a signed authorization.
  • Does HIPAA apply to you? Only if you are a covered entity — you transmit health information electronically for a standard transaction. Most med spas are; build to the standard either way.
  • Governing rule: 45 CFR 164.508 — core elements plus required statements (revocation, no-conditioning, re-disclosure).
  • Cannot be bundled into intake or treatment consent — marketing authorization must stand alone.
  • Reviews: never confirm someone is a patient or reveal any visit detail in a public reply — OCR has fined practices for this.
  • Retention: keep signed authorizations at least 6 years (HIPAA) or longer under state records law — whichever is greater.

Do Med Spas Have to Be HIPAA Compliant?

Most must, but not automatically. HIPAA binds your practice only if it is a covered entity: a health care provider that transmits health information electronically in connection with a HIPAA standard transaction, such as an insurance claim or an eligibility check. Any med spa that bills insurance is covered. A strictly cash-pay practice may not be.

The two-part covered-entity test

That nuance matters because it is the single most misreported point in med spa compliance content. You will see it asserted that keeping electronic patient charts, or simply storing ePHI, makes you a covered entity. It does not. Storage is not the test — the transaction is. A practice can hold a server full of patient photographs and still fall outside HIPAA's direct reach if it never runs a covered electronic transaction.

Work through both halves. You are a HIPAA covered entity as a health care provider when:

  • You furnish health care. Prescription injectables, medical-grade lasers, weight-loss pharmacotherapy, hormone therapy, and anything requiring a good faith exam are health care. This half is satisfied by nearly every med spa operating lawfully.
  • You transmit health information electronically in connection with a covered transaction. These are the standardized administrative transactions — claims, eligibility inquiries, prior authorization requests, claim status, remittance advice, coordination of benefits. Submitting one, or having a billing service or clearinghouse submit one on your behalf, satisfies this half.

In practice, the second half catches more med spas than owners expect. One eligibility check for a covered service line, or a mixed book with a dermatology or wellness line under the same tax ID, brings the whole entity in.

If you are genuinely not a covered entity, what still binds you?

A great deal. Falling outside HIPAA is not the same as being unregulated:

  • State privacy and medical-records law, which generally applies to licensed practitioners regardless of federal covered-entity status, and which in several states is stricter than HIPAA.
  • Your medical director's own licensure obligations. The supervising physician's duty of confidentiality follows the license, not the billing model.
  • The FTC, which reaches deceptive advertising and, separately, health-data practices at entities HIPAA does not cover.
  • Contract and tort. A patient who never consented to appear in your advertising has claims that do not depend on HIPAA at all — invasion of privacy, misappropriation of likeness, breach of confidence.

This is why the practical advice for a cash-pay med spa is the same as for a covered one: build the marketing authorization to the HIPAA standard anyway. It is the most demanding template available, it satisfies the state and common-law exposure at the same time, and it costs you nothing but a signature. The rest of this guide assumes you are doing exactly that.

Do You Need a HIPAA Authorization to Post a Patient Testimonial?

Yes, in nearly every case. A testimonial that identifies the patient and refers to care they received at your practice is protected health information, and publishing PHI to promote the practice is marketing under HIPAA. That requires a signed authorization meeting 45 CFR 164.508 before you post — not a verbal yes, not an intake checkbox.

Why a testimonial is PHI in the first place

The word "marketing" makes this feel like a branding question. It is not — it is a privacy question, and it starts with recognizing that the material you want to publish is PHI in the first place.

PHI is any individually identifiable health information held by a covered entity that relates to a person's condition, the care they received, or payment for it. When a patient sits for a testimonial about her Botox results, or you shoot a before-and-after of a filler treatment, the content ties an identifiable person to the fact and detail of care they received at your practice — the textbook definition of PHI.

The three-part test that makes content PHI

Content becomes PHI — and therefore governed by HIPAA when you use it for marketing — when all three of these are true:

  • It is individually identifiable. A name, a face, a voice, a tattoo, a distinctive feature, or even a combination of details that lets someone recognize the person. A cropped chin is less identifiable than a full face, but "less" is not "not."
  • It relates to health care. The content reveals that the person received a treatment, sought aesthetic care, or has a condition you addressed. A before-and-after inherently does this; so does a testimonial describing a procedure.
  • Your practice holds or created it as a covered entity. The photo taken in your treatment room, the review response you write, the testimonial you filmed — these flow from the treatment relationship, not from a stranger on the street.

Here is the distinction that confuses people: when a patient independently posts "I love Dr. Lee, my lips look amazing," that patient is disclosing their own information — HIPAA restricts what the covered entity discloses, not what a patient says about themselves. But the moment your practice collects, edits, or reposts that content to promote itself, you are the one disclosing PHI for marketing, and the authorization requirement attaches to you.

Why a smiling face is still PHI

Owners often assume a flattering photo could not be a privacy problem — the patient looks great, what is there to protect? HIPAA does not care whether a disclosure is embarrassing. Identifiability plus a health-care connection is enough. A beaming before-and-after that proves someone had a cosmetic procedure is PHI in exactly the same way a diagnosis is; the favorable tone is irrelevant to the legal analysis.

Consent vs. HIPAA Authorization: The Distinction That Trips Up Med Spas

The single most common mistake we see is treating "consent" and "authorization" as the same document. They are not, and the difference is the entire ballgame.

Consent, in the clinical sense, is permission to treat — informed consent for the Botox, the laser, the GLP-1 program. It covers risks, benefits, and alternatives, and it lets you use PHI for treatment, payment, and health care operations. Our med spa consent forms guide and our Botox consent forms breakdown cover that treatment-consent layer in depth. Treatment consent does not authorize you to put the patient in an ad.

Authorization is the HIPAA-specific, written permission required for uses that fall outside treatment, payment, and operations — and marketing is the classic example. HIPAA generally requires a valid authorization before a covered entity uses or discloses PHI for marketing. An authorization is a heavier, more formal instrument than consent: the regulation dictates its contents down to the required statements.

When simple consent is enough

You can rely on ordinary permissions — no 164.508 authorization — for a narrow set of communications HIPAA carves out of "marketing," including:

  • Face-to-face communications you make directly to a patient (recommending a product during a visit).
  • Promotional gifts of nominal value.
  • Communications about the patient's own treatment, care coordination, or alternatives — describing a service to the person receiving it.

When a HIPAA authorization is mandatory

You need a signed 164.508 authorization whenever you use identifiable patient content to promote the practice to an audience, including:

  • Posting a named or identifiable testimonial on your website, Google Business Profile, or social media.
  • Publishing before-and-after photos in any channel — feed, stories, ads, brochures, your homepage.
  • Featuring a patient in a video, email campaign, or paid advertisement.
  • Any disclosure of PHI for marketing that involves payment from a third party (which then also requires a remuneration statement).

If you are unsure which bucket a use falls into, default to the authorization: the cost of an extra signature is a minute of a patient's time; the cost of guessing wrong is an OCR investigation. For where this sits among your other duties, see what med spa compliance actually requires in 2026.

What Does 45 CFR 164.508 Require for Marketing Photographs?

The same authorization it requires for any other marketing use of PHI: six core elements plus three required statements, in one signed document. The core elements identify the images, who discloses them, who receives them, the purpose, an expiration date or event, and the patient signature. A remuneration statement is added when a third party pays you.

The required elements, line by line

There is no separate photograph rule in the regulation. A before-and-after image is simply PHI, and 164.508 governs every marketing use of PHI identically — which is good news, because it means one well-built form covers stills, video, written testimonials, and voice.

A marketing authorization is valid only if it contains every element 45 CFR 164.508 requires. Miss one and the document is defective — in a dispute, legally the same as no authorization at all. Use the table below to build your form.

Required Element What It Means for a Med Spa
Specific description of the PHI Identify the information in a specific, meaningful way — e.g., "before-and-after photographs of my face and jawline taken on [date]" or "video testimonial describing my weight-loss treatment." Not "any and all information."
Who is authorized to disclose Name your practice as the entity making the disclosure.
Who may receive the PHI Identify the recipients or class — e.g., "the general public via the practice's website, social media accounts, and advertising."
Purpose of the use/disclosure State it plainly: "marketing and promotion of the practice's services." "At the request of the individual" is not adequate here.
Expiration date or event A date, or an event tied to the individual/purpose — e.g., "expires 3 years from signature" or "until I revoke in writing."
Signature and date The patient's signature and the date signed (or a personal representative's, with authority described).
Right to revoke — statement Tell the patient they can revoke in writing, how to do it, and any exceptions (uses already made in reliance).
No-conditioning statement State that treatment is not conditioned on signing — the patient can decline and still receive care.
Re-disclosure warning Warn that PHI disclosed under the authorization may be re-disclosed by the recipient and may no longer be protected by HIPAA.
Remuneration statement (if applicable) If marketing involves payment to your practice from a third party, the authorization must say so.

The core elements vs. the required statements

Hold two groups in your head. The first six rows are the core elements — the who, what, why, when, and signature. The last four are the required statements — the notices HIPAA insists the patient receive so their permission is genuinely informed. A form can look complete and still be invalid if it has the core elements but omits, say, the re-disclosure warning. Regulators read for both. Two more rules round it out: the authorization must be in plain language, and you must give the patient a copy of the signed form.

What makes an authorization defective

An authorization is not judged only at signing. Under 164.508 it is defective — treated as though it does not exist — in several situations a med spa can walk into without noticing:

  • The expiration date has passed, or the expiration event has occurred. A form written to expire three years from signature stops working silently on its anniversary while the gallery stays up.
  • It is not filled out completely. A blank description field, an unsigned line, a missing date. Audit your files for these; they are common.
  • You know it has been revoked. Continuing to run an ad after a revocation lands is the clearest version of this.
  • It improperly conditions treatment on signing, or is improperly combined with another document — the bundling problem covered in the next section.
  • Material information in it is known to be false.

The operational consequence is that a marketing authorization is a perishable record. Your usage log needs to carry the expiration date next to the content, so that content comes down or gets re-authorized when the form lapses.

How we sourced this section

The requirements above describe 45 CFR 164.508, a federal regulation that has been stable for years and that our own compliance reviewers have previously verified for this guide. In preparing this September 2026 update we were unable to open the primary text — eCFR, HHS.gov and GovInfo were all unreachable from our research environment on the day of writing. We have therefore restated only long-settled requirements and have not added any new citation, effective date, or subsection number that we could not confirm. Before you finalise a form, read the current regulation yourself at eCFR 45 CFR 164.508 and have counsel confirm it.

Why You Cannot Bundle Marketing Consent Into Intake Paperwork

The instinct to fold "you can use my photos" into the intake packet is understandable — one signature, done. It is also the single most reliable way to make your marketing permission unenforceable.

HIPAA prohibits conditioning treatment on signing a marketing authorization. When the photo release lives inside the same stack of forms a patient must sign to be treated, you have — in appearance and often in practice — conditioned care on the authorization. A patient signing a wall of intake documents to get their appointment has not given the free, specific, informed permission a marketing authorization is supposed to represent. A regulator or plaintiff's attorney will argue it was coerced by the treatment relationship, and the document collapses.

Bundling fails for several compounding reasons:

  • It looks conditioned. Even if you would treat the patient regardless, embedding the authorization in mandatory paperwork undermines the no-conditioning requirement.
  • It is not specific. A one-line "I consent to use of my images" tucked into intake almost never contains the ten required elements above — no purpose, no expiration, no revocation statement, no re-disclosure warning.
  • It muddies revocation and is easy to disprove. A standalone, separately dated authorization is clean evidence of informed permission; a checkbox in a fifteen-page packet is the opposite.

The fix is structural: make the marketing authorization a separate, standalone document the patient signs at a separate moment — ideally after treatment, when they are enthusiastic and there is no pressure of getting care that day. Keep it out of the intake and treatment-consent stack. This is exactly the documentation discipline the Operations & Compliance Kit is built to standardize.

What Must a Med Spa Before-and-After Photo Consent Form Include?

Every element 45 CFR 164.508 requires, plus photo-specific detail. That means a description of the images, the exact channels where they may appear, the purpose, an expiration date or event, the patient signature and date, and three statements: how to revoke, that treatment is not conditioned on signing, and that shared images may be re-disclosed.

The element checklist

This is the section most operators are actually looking for, so here it is as a build list. Work down it with your own form open. Anything you cannot point to is a gap.

  1. Patient identification. Full legal name and date of birth, so the signed form can be matched to a chart years later. If a personal representative signs, capture their name and a description of their authority.
  2. A specific description of the images. Not "my photos." Something a stranger could match to a file: "before-and-after photographs of my face, jawline and neck taken on or around [date] in connection with dermal filler treatment." Name the body areas and the treatment.
  3. Whether the images show the face, and whether they may be published uncropped. Give the patient a real choice here — a separate initial line for "face may be shown" and "face must be obscured" is the single most useful addition you can make to a stock form.
  4. Who is disclosing. Your practice, by legal entity name.
  5. Who may receive the images. Identify the recipients or the class: "the general public, via the practice's website, social media accounts, paid advertising, and printed materials."
  6. The specific channels, itemised. Website gallery, Instagram feed, Instagram stories, Facebook, TikTok, paid ad campaigns, email newsletters, in-office screens, print brochures, trade-show material, third-party directories. A patient who agreed to a website gallery did not necessarily agree to a paid ad.
  7. The purpose. State it plainly: "marketing and promotion of the practice's services." "At the request of the individual" is not adequate for a marketing authorization.
  8. An expiration date or event. A fixed term, or "until I revoke this authorization in writing."
  9. The right to revoke, in writing, and exactly how. Give a named recipient and an address or email. A revocation right the patient cannot find a channel for is not a real right.
  10. A no-conditioning statement. Treatment is not conditioned on signing; the patient may decline and still receive care.
  11. A re-disclosure warning. Once published, images may be copied, screenshotted, and re-shared by third parties, and information disclosed under the authorization may no longer be protected by HIPAA.
  12. A remuneration statement, if applicable. If a third party is paying your practice in connection with the marketing, say so.
  13. Signature and date. The patient's own, dated — and separate from every treatment-consent signature in the file.
  14. Acknowledgement that a copy was provided. HIPAA requires you to give the patient a copy; a line confirming you did is your proof.

The clauses HIPAA does not require but your form should carry anyway

The regulation sets a floor, not a good form. These additions cost nothing at signing and resolve most of the disputes that actually arise:

  • A no-compensation acknowledgement, or a clear statement of what the patient is receiving. If you discounted a treatment in exchange for photo rights, that is a material connection the FTC expects disclosed in the advertisement itself.
  • An image-alteration clause. State whether images may be cropped, resized, or colour-corrected, and commit that they will not be retouched in a way that changes the apparent result. This protects the patient and disciplines your own marketing.
  • A likeness and publicity release. HIPAA governs privacy; it does not grant you commercial image rights. One combined document should do both.
  • A no-obligation-to-publish clause, so a patient who signs has no claim that you must use their photos.
  • A stated takedown window — for example, that you will remove content you control within a set number of days of a written revocation. It converts a vague duty into a measurable one.

The identifiability problem

A before-and-after is PHI whenever the person is identifiable — and faces are the least of it. Distinctive features, tattoos, jewelry, and background details in the treatment room can all identify a patient. Cropping out the face reduces identifiability but rarely eliminates it. Treat any patient image as identifiable unless you have genuinely de-identified it, and get a signed authorization that describes the images and the channels where they will appear.

Metadata and reverse-image risk

Two technical hazards catch practices off guard. First, image metadata — EXIF data embedded in a photo file can include timestamps, device identifiers, and sometimes GPS location, which can help re-identify an image you thought was anonymous. Strip metadata before publishing. Second, reposting is permanent: once a before-and-after is on Instagram it can be screenshotted and re-shared beyond your control. Your authorization should warn the patient that public content may be copied, and that revocation stops your future use but cannot recall what others have saved — a warning that maps to the re-disclosure statement HIPAA already requires.

Photo release vs. HIPAA authorization

A stock "photo release" borrowed from a photographer or a general business template grants image rights but almost never contains the HIPAA-required elements. Because a treatment before-and-after is PHI, that release alone does not make you compliant. What you want is a single combined document — a HIPAA marketing authorization that also grants image and likeness rights — so one signature covers both the privacy law and the intellectual-property/publicity angle. Do not rely on a generic release to carry a HIPAA obligation it was never written for.

State law stacks on top of the federal form

HIPAA is a floor. State medical-privacy statutes often apply to licensed practitioners regardless of federal covered-entity status, and state biometric-privacy statutes — Illinois' Biometric Information Privacy Act being the most-litigated, because it carries a private right of action — add a separate layer for facial imagery.

We are not going to tell you how BIPA applies to your gallery, because the honest answer is that it is unsettled. Its treatment of ordinary photographs versus scans of facial geometry has been contested in litigation, and we could not open the statutory text or the case law from our research environment while preparing this update. The operational conclusion we can offer: if you practise in Illinois — or use any tool that performs facial mapping, automated skin analysis, or AI-driven outcome simulation on patient images — treat that as a separate consent question and get state-specific advice. A federal marketing authorization does not resolve it. Our Illinois med spa compliance hub covers the state's other requirements.

DOCUMENTATION DONE RIGHT

Get the consent and documentation SOPs done right.

The Operations & Compliance Kit includes documentation standards, records management, and the policy framework your consent library plugs into — including marketing authorization workflow.

View Operations Kit — $197
30-Day Money-Back Guarantee · Instant Download

Can a Med Spa Run Before-and-After Ads on Meta or Instagram?

Yes, but you need two separate permissions. HIPAA requires a signed 164.508 authorization from the patient before the image leaves your practice, and Meta's own advertising policies independently govern what before-and-after imagery an ad may show. Clearing one does not clear the other, and the platform rules change without notice.

Two rulebooks, both binding, enforced by different people

Operators conflate these constantly, usually because both get called "the rules." They are not the same kind of thing at all:

  HIPAA Platform advertising policy
What it is Federal law A private company's terms of service
What it governs Whether you may disclose the patient's PHI at all Whether that particular creative may run on that platform
Who enforces it HHS Office for Civil Rights; state AGs Automated ad review inside the platform
What it costs you Investigation, settlement, corrective action plan Ad rejection, and at the limit loss of the ad account
How it changes Rulemaking, slowly and publicly Unilaterally, sometimes without announcement

The asymmetry worth internalising: an approved ad is not a compliant ad. Meta's review system has no idea whether you hold an authorization, and it will happily run a before-and-after you had no right to publish. The approval tells you nothing about your HIPAA position.

Meta is not your business associate

This is the point that reframes the whole question. When you upload a patient's before-and-after to an ad platform, you are disclosing PHI to a third party that has not signed a business associate agreement with you and will not sign one. There is no vendor contract standing between you and that disclosure. The only thing making it lawful is the patient's authorization — which is why the authorization must name paid advertising as a channel, not merely "social media," and why an authorization that predates your ad strategy may not cover it.

Why we are not quoting Meta's current rule

Meta's advertising standards restrict health, weight-loss, and appearance-related creative, and before-and-after imagery has been treated differently at different times under those standards. We deliberately are not reproducing a specific current prohibition here. We could not open Meta's policy documentation from our research environment while preparing this update, the secondary sources we could see disagreed with each other on what the current rule is, and platform policy in this category has changed repeatedly.

Publishing a confident but stale platform rule would be worse than publishing nothing, because you would build a campaign on it. So the durable operator guidance instead:

  • Read the live policy before each campaign build, not once a year. Meta publishes its advertising standards and its health-and-wellness sections in its Transparency Center; that is the only authoritative statement of what is allowed today.
  • Get the HIPAA authorization regardless of what the platform permits. Platform permission is not patient permission, and the platform rule is the one that can loosen. HIPAA is the one that will not.
  • Assume rejection is possible and build creative that survives it — results-free lifestyle imagery, credential and safety messaging, educational content. Practices whose entire funnel depends on before-and-after creative are one policy update from a dead ad account.
  • Keep the FTC layer in view. Even a platform-approved, HIPAA-authorized ad must still be truthful, substantiated, and clear about typical results and material connections.
Free Download — No Credit Card

Get the Free Med Spa Compliance Checklist

A printable, section-by-section checklist covering consent, HIPAA, marketing authorization, and records — so you can see exactly which documents your practice is missing before a regulator or a plaintiff's attorney does.

Join 200+ med spa professionals. Unsubscribe anytime.

Handling Revocation: The Takedown Workflow

A right to revoke that your practice cannot actually execute is a liability, not a safeguard. Because every authorization must promise the patient they can revoke in writing, you need a real workflow that turns that promise into a completed takedown — and documents it.

What revocation does and does not undo

Revocation is prospective. When a patient revokes, you must stop future use and remove what you still control. It does not unwind uses your practice already made in good-faith reliance on the authorization — a print brochure already mailed, an ad that already ran. But everything still under your control — the website gallery, the Instagram post, the active ad campaign, the Google profile — must come down. "It's already out there" is not a defense for content you can still remove.

The five-step takedown workflow

  1. Receive and timestamp. Accept the written revocation, record the date received, and acknowledge it to the patient. Give staff a standing instruction that any "take my photo down" request routes immediately to the privacy officer.
  2. Inventory every location. Maintain a usage log that lists where each patient's content lives — website URLs, each social platform, ad sets, email templates, in-office screens, printed materials. You cannot take down what you never tracked.
  3. Remove promptly. Delete or unpublish from every channel you control — do not just "unfeature." Third parties who already saved the content are beyond your reach.
  4. Document completion. Record the date takedown was finished for each location — your proof that you honored the revocation.
  5. File it with the original. Keep the signed revocation stapled (physically or digitally) to the original authorization, and mark the authorization as revoked so no one re-uses the content later.

The usage log in step 2 is the piece practices skip and later regret. Without it, a revocation triggers a frantic hunt across five platforms and someone always misses the ad set that keeps running.

Storing Signed Consent Forms the HIPAA-Compliant Way

Collecting a perfect authorization and then storing it carelessly recreates the risk you were trying to close. Signed authorizations are themselves records that must be retained, secured, and produceable on demand — the storage-and-retention question that sends operators searching.

Retention periods: HIPAA floor and state ceiling

HIPAA requires a covered entity to retain signed authorizations (and related documentation) for at least six years — measured from the date the authorization was last in effect, not the date it was signed. That is the federal floor. State medical-record laws frequently require longer for the underlying chart, and you follow whichever period is greater, because HIPAA only preempts state rules that are shorter than six years.

Source of Rule Typical Retention (Ballpark) Notes
HIPAA (federal floor) 6 years From when the authorization was last in effect, not when signed.
Florida (physicians) ~5 years After last patient contact; hospitals longer (~7). Apply the longer of state vs. HIPAA.
Texas (physicians) ~7 years After last contact; longer for minors. Exceeds the HIPAA floor.
Most states (range) 5–10 years Varies; minors' records often held until age of majority plus a set period.

Ballpark figures above are for orientation, not legal advice — confirm your own state's rules. The practical policy: keep every signed authorization and photo release for the life of the record plus your state's longest applicable window, and never destroy an authorization while the marketing use is still live. Our Florida consent forms guide covers one state's specifics.

Access controls and physical/digital safeguards

Signed authorizations contain PHI, so the Security and Privacy Rules govern how you store them:

  • Restrict access under the minimum-necessary standard — only staff who need to manage marketing consent should reach these files.
  • Encrypt digital storage and keep authorizations in your secured EHR or a HIPAA-compliant document system, not a shared marketing drive or a folder on a personal laptop.
  • Lock physical originals in a secured cabinet with controlled access if you keep paper.
  • Sign a BAA with any vendor that touches these files — your document-management platform, your EHR, any agency that handles the content.
  • Log and audit who accesses the files, and dispose of expired records by secure shredding or certified digital destruction.

A marketing authorization sitting in a public Google Drive folder shared with a freelance social-media manager is a breach waiting to be found. Treat these forms with the same rigor as clinical charts — legally they are the same category of record, one slice of the broader records-management discipline in a full policy and procedure manual.

Responding to Online Reviews Without Violating HIPAA

This is the classic violation — the one OCR has repeatedly turned into settlements — and it is worth its own section because owners commit it while trying to protect their reputation.

The rule is stark: in a public reply, you may not confirm the person is a patient or disclose any detail about their visit, treatment, dates, condition, insurance, or payment — even if the reviewer revealed those details first, and even to correct a false claim. The patient waived their own privacy by posting; your covered-entity obligations did not disappear because they did.

The enforcement record is unambiguous. In one OCR settlement, a dental practice responded to Yelp reviews and disclosed patient names — including where a patient had used only a pseudonym — with treatment and insurance details; it paid a $23,000 resolution, accepted a two-year corrective action plan, and had to remove the posts and issue breach notices (HHS/OCR). In an earlier case, a Dallas dental practice disclosed a patient's last name and treatment details in a Yelp reply and settled for $10,000. Aesthetic practices sit in exactly the same exposure. OCR's message was blunt: disclosing PHI to answer a negative review is "a clear NO."

The one safe response — use it every time

The defense is a single, generic reply you use for everyone, positive or negative, that never acknowledges a treatment relationship:

"Thank you for taking the time to share feedback. We take all concerns seriously and are committed to providing every client with a safe, professional experience. We'd welcome the chance to speak with you directly — please contact our office so we can help."

Notice what it does not do: it never says "as our patient" and never references a date or service. It moves the conversation offline, where — with the patient's participation — you can address specifics privately. Train every person with login access to your review profiles to use this script and nothing else. A single well-meaning "but you responded great to your Botox!" reply is a reportable disclosure.

Staff social media rules

The same logic governs what your team posts. Build these rules into your social-media policy and your staff HIPAA training:

  • No patient content without a signed authorization on file — no exceptions, no "just this once" stories.
  • No personal-device photos in treatment areas. Faces, charts, screens, and other patients can be captured in the background.
  • No confirming patient status in comments, DMs, or replies — staff cannot acknowledge that a commenter is a client.
  • No "day in the life" clips that incidentally show identifiable patients, schedules, or chart screens.
  • Route all patient-facing content through the person who verifies a valid authorization exists before it posts.

The FTC Layer: Truthful Before/After Marketing

HIPAA governs whether you may use the content. The Federal Trade Commission governs whether the claims the content makes are truthful. Both apply at once, and clearing HIPAA does not clear the FTC.

The FTC's updated Endorsement Guides (revised in 2023) treat before-and-after imagery and testimonials as endorsements that imply a typical result. If a before-and-after suggests a result most patients will not achieve, the ad can be deceptive unless you clearly disclose typical results — and a tiny "results not typical" disclaimer is not sufficient. Key principles for med spas:

  • Results must be representative or accompanied by a clear, conspicuous disclosure of what patients can generally expect.
  • Claims need substantiation. A patient testimonial is not, by itself, scientific evidence for a treatment claim; you must be able to back up any express or implied health claim independently.
  • Disclose material connections. If a patient was paid, given free treatment, or is a staff member, that connection must be clearly disclosed near the endorsement.
  • No fake or edited reviews. Suppressing negative reviews, posting fake positive ones, or heavily editing testimonials to distort meaning is squarely targeted by the 2023 guides.
  • No misleading retouching of before-and-after photos that overstates the outcome.

We cover the advertising-claims side in depth in our FTC before-and-after photo rules for med spas. The takeaway here: get the HIPAA authorization and make sure the claim the content makes is truthful and substantiated. Both boxes, every time.

Building This Into Your Consent-Form Library

Everything above becomes manageable the moment you turn it from a series of one-off decisions into a standing part of your documentation system. Marketing authorization is a compliance artifact that lives alongside your treatment consents, HIPAA policies, and records-retention schedule. A practice that has this handled runs a simple, repeatable workflow:

  1. A standalone marketing authorization form built to the 164.508 checklist above, kept out of the intake stack, that doubles as a photo/likeness release.
  2. A collection point after treatment — not at intake — where an enthusiastic patient signs freely, receives a copy, and understands they can revoke.
  3. A usage log that tracks where every piece of patient content is published, so revocation and audits are fast.
  4. A retention and storage policy that secures the signed forms for the longer of six years or your state's requirement, with access controls and BAAs.
  5. A review-response script and a staff social-media policy so the people posting never turn a good day into a disclosure.
  6. An FTC-truthfulness check layered on top before anything goes live.

Writing all of that from scratch — and getting the regulatory language right — is the work most owners underestimate. If you would rather start from a professionally built foundation, browse the full med spa compliance SOP library to see how the consent, HIPAA, and records frameworks fit together, or go straight to the operations kit that houses this marketing-authorization workflow.

Last reviewed September 20, 2026. This article is educational and does not constitute legal advice; sample form structures are described for illustration only. Confirm HIPAA authorization language and records-retention periods with qualified counsel and your state medical board. Content is reviewed whenever federal or state regulations change. Material corrections to this page are recorded in our corrections log.

Frequently Asked Questions

Common questions about testimonial, photo, and marketing consent under HIPAA.

Do med spas have to be HIPAA compliant? + −
Most do, but not automatically. HIPAA applies to your practice only if it is a covered entity — a health care provider that transmits health information electronically in connection with a HIPAA standard transaction, such as an insurance claim, an eligibility check, or a prior authorization request. Any med spa that bills insurance, directly or through a billing service or clearinghouse, meets that test. A strictly cash-pay practice that never runs a covered electronic transaction may fall outside HIPAA's direct reach. Note that simply storing electronic patient records is not the test, contrary to what is widely claimed — the covered transaction is. Even outside HIPAA, state medical-privacy law, your medical director's licensure duties, FTC authority, and ordinary privacy and likeness claims still apply, so the practical answer is to build your marketing authorization to the HIPAA standard either way.
Do med spas need HIPAA authorization for testimonials? + −
Yes, in almost every case. A patient testimonial that names or identifies the patient and refers to the care they received discloses protected health information (PHI). Using that PHI to promote your practice is marketing under HIPAA, and 45 CFR 164.508 requires a signed, HIPAA-compliant authorization before you can use or disclose it. A generic star rating a patient posts themselves is different — the patient chose to make it public. But when your med spa collects, edits, and publishes a named testimonial for promotional purposes, you need a valid written authorization on file first, not just verbal agreement or a checkbox buried in intake paperwork.
What must a HIPAA marketing authorization include? + −
Under 45 CFR 164.508, a valid authorization must contain a specific description of the information being used, the name of the person or practice authorized to disclose it, the name of who receives it, the purpose of the disclosure, an expiration date or event, and the patient's signature and date. It must also carry required statements: the patient's right to revoke in writing and how, a note that treatment cannot be conditioned on signing, and a warning that information disclosed may be re-disclosed and lose HIPAA protection. If financial remuneration from a third party is involved, that must be stated. Missing any element makes the authorization invalid.
Can a med spa post before-and-after photos on Instagram? + −
Only with a signed HIPAA marketing authorization from the patient that specifically covers social media use. A before-and-after photo is PHI because it connects an identifiable person to the fact they received treatment — and faces, tattoos, and distinctive features often make even a cropped image identifiable. The authorization should name the platforms, describe the images, state that posts may be shared or screenshotted beyond your control, and note that the patient can revoke going forward. Cropping to remove the face reduces but does not eliminate identifiability, and metadata can re-identify an image, so a signed authorization is still the safe standard before anything is posted.
Can a med spa respond to Google reviews? + −
Yes, but you cannot confirm the person was a patient or reveal any detail about their visit, treatment, dates, diagnosis, or payment — even if they disclosed it first, and even to defend your reputation. OCR has fined practices thousands of dollars for exactly this. Doctors and staff replying to negative Yelp and Google reviews disclosed patient names and treatment details and were cited for impermissible PHI disclosure. The safe response is generic and identical for everyone: thank the reviewer for the feedback, state your commitment to quality care, and invite them to contact the office directly. Never acknowledge a specific relationship in a public reply.
How long must med spas keep signed consent forms? + −
HIPAA requires covered entities to retain signed authorizations for at least six years from the date the authorization was last in effect, not from the date it was signed. State medical-record laws often require longer and control the underlying chart: many states set five to ten years after the last patient contact — for example five years for physicians in Florida and seven years in Texas. Because HIPAA preempts only shorter state periods, you follow whichever rule is longer. Practically, keep signed marketing authorizations and photo releases for the life of the record plus the longest applicable retention window, and never destroy one while the marketing use is still live.
Can patients revoke consent for marketing photos? + −
Yes. Every HIPAA authorization must tell the patient they can revoke it in writing, and med spas must honor a revocation going forward. Revocation does not undo uses your practice already made in good-faith reliance on the authorization — a printed brochure already distributed, for example — but it does require you to stop future use and take down what you still control. When a patient revokes, remove their photo or testimonial from your website, social profiles, and ad campaigns promptly, document the date you received the request and the date you completed takedown, and keep the signed revocation with the original authorization. A clear takedown workflow is what turns the legal right into an actual removal.
Is a photo release the same as a HIPAA authorization? + −
Not necessarily. A generic photo or model release borrowed from photography or general business use grants image rights but usually omits the elements HIPAA requires — the specific description of PHI, the purpose, the expiration, the revocation statement, the no-conditioning statement, and the re-disclosure warning. Because a before-and-after image tied to treatment is PHI, a plain photo release is not enough on its own. The document you need is a HIPAA-compliant marketing authorization that also functions as a photo release: it should grant image and likeness rights and satisfy all of 45 CFR 164.508. When in doubt, use one combined authorization built to the HIPAA standard rather than a stock release.
COMPLETE COMPLIANCE DOCUMENTATION

Every consent form and protocol, one library.

62 SOPs including consent frameworks for every service line — injectables, laser, weight loss, and the marketing authorization workflow in this guide.

30-Day Money-Back Guarantee · Instant Download · Medical Director Ready