What makes a before and after photo app HIPAA compliant
Updated July 31, 2026. Sources at the end. General information, not legal advice.
The short version: "HIPAA compliant" on a software marketing page is a claim, not a feature. What you can actually verify is mechanics: encryption at rest and in transit, per-user logins, audit logs, a vendor who signs a Business Associate Agreement, photos kept off personal camera rolls, and written patient authorization before any marketing use.
This page is the checklist, usable against any vendor. Medspa Photos was built to pass it: encrypted storage, staff PINs, logged actions, a BAA for covered practices, and a server that blocks any export the patient's signed consent does not cover. $99 a month flat, 14-day trial, no sales call.
The checklist, and where it comes from
HIPAA's Security Rule requires safeguards for electronic protected health information: access control, audit controls, and transmission security among them [1]. The Privacy Rule requires written authorization before a covered entity uses identifiable patient photos for marketing [2]. Translated into things you can check on a demo or a trial:
- Encryption at rest and in transit. Ask where photos physically live and how they move. "HIPAA compliant cloud" without specifics is not an answer.
- Individual logins. Every staff member acts under their own identity, even on a shared clinic iPad. A shared password voids your audit trail.
- Audit logs. Who captured, viewed, and exported each photo, and when. If the vendor cannot show you the log, it does not exist.
- A signed BAA. If you are a covered entity, the vendor storing your photos is a business associate and must sign one. "We are HIPAA compliant" without a BAA offer is a red flag.
- No camera roll, ever. Capture, storage, comparison, and export all happen inside the controlled system. The moment a photo lands in a personal camera roll, you have lost custody of PHI.
- Authorization before marketing use. The system should record what each patient agreed to, and ideally refuse to export what they did not.
The part most apps skip: enforcement
Most vendors in this category store a consent form and stop there. The compliance failure almost never happens at signing; it happens months later, when someone posts a photo the consent never covered. A stored form does not prevent that. A gate does.
In Medspa Photos, the patient signs a photo consent on the clinic device and chooses what they allow: clinical record only, or social media too, identifiable or not. The signed record is stored with the photos, versioned and time-stamped. When staff hit export, the server checks that consent. No matching authorization, no export. If a patient revokes, future exports are blocked immediately and existing exports are pulled the same minute.
How Medspa Photos meets the checklist
| Requirement | How it is met |
|---|---|
| Encryption | Photos and consents encrypted at rest and in transit, stored in infrastructure built for regulated health data |
| Access control | Each staff member signs in with their own PIN on the shared clinic device |
| Audit logs | Every capture, view, and export is logged with who did it and when |
| BAA | Signed for covered practices, at no extra cost. Ask before your trial ends |
| Camera roll | Capture to export happens inside the app. Photos never touch the device camera roll |
| Marketing authorization | Scoped, signed photo consent per patient; the server blocks any export it does not cover |
| Third-party code | No analytics SDKs, no crash trackers, no third-party code near a patient photo |
What no app can do for you
Honesty matters more on this page than anywhere else. Software covers the technical safeguards and the paperwork trail. It does not decide whether your practice is a covered entity, train your staff, write your policies, or stop someone from photographing a patient on a personal phone in the hallway. Compliance is a property of your practice. Good software just makes the compliant path the easy one.
Run the checklist against us for free. 14 days, set up the same day, no sales call.
Start your 14-day free trial$99 per month per location after the trial. Card required, cancel anytime. Or read more on the product page.
Common questions
Can an app itself be HIPAA compliant?
Not by itself. Software can meet the technical safeguards and the vendor can sign a BAA, but compliance belongs to your practice: policies, training, and how photos are actually handled. Any vendor that says their app makes you compliant is overclaiming.
Is my med spa a covered entity?
It depends on how you bill and operate; many cash-pay med spas are not, while practices billing insurance electronically generally are. Ask your attorney. The safe practices are the same either way.
Does HIPAA allow before and afters on social media?
For covered entities, marketing use of identifiable photos requires prior written authorization; a treatment consent does not substitute. The safe pattern for any practice: photo-specific, signed, scoped consent, enforced by the software at export.
Are staff camera rolls really a problem?
They are the biggest one. A patient photo on a personal phone is unencrypted PHI outside your control: it syncs to personal clouds and survives employee departures. Keep capture, storage, and export inside one controlled system.
Will Medspa Photos sign a BAA?
Yes, for covered practices, at no extra cost. Ask before your trial ends.
Sources
- HIPAA Security Rule technical safeguards, 45 CFR 164.312 (access control, audit controls, integrity, transmission security), hhs.gov, accessed July 31, 2026.
- HIPAA Privacy Rule authorization requirements for marketing, 45 CFR 164.508(a)(3), hhs.gov, accessed July 31, 2026.
This page is general information, not legal advice. If any of it is out of date, tell us at [email protected] and we will correct it.