MedSpaForms

GUIDE

HIPAA Compliance Checklist for Med Spas and Wellness Clinics

Updated August 24, 2026 · MedSpaForms

A HIPAA compliance checklist for a med spa has five working parts: confirming whether you are a covered entity at all, completing and documenting a security risk analysis, adopting written policies with a named privacy and security official, papering your vendors with business associate agreements, and being able to execute breach notification on a 60-day clock. Everything else on this page hangs off those five. Work through them in order, because the risk analysis determines which safeguards are reasonable and appropriate for your specific practice.

HIPAA Forms Pack

HIPAA Forms Pack

A plain-language Notice of Privacy Practices built on the 45 CFR 164.520 element set, the patient acknowledgment, and a release authorization — the HIPAA paperwork trio every covered practice needs.

See what's inside — $27

Step zero: confirm whether HIPAA applies to you

Most checklists skip this and they are wrong to. A health care provider is a HIPAA covered entity only if it transmits health information electronically in connection with a transaction for which HHS has adopted a standard under 45 CFR Part 162. Those transactions are almost entirely insurance-facing: claims, eligibility verification, prior authorization, claim status, coordination of benefits, and electronic remittance.

A med spa that operates strictly cash-pay, never submits a claim, and never runs an eligibility check frequently is not a covered entity. That status is fragile. Billing a plan for a single medically indicated service, or letting an outside biller transmit on your behalf, brings you in. Running an in-house pharmacy or dispensing function may bring you in through a different door. HHS publishes a covered entity decision tool, and your conclusion should be written down and dated, not assumed.

Being outside HIPAA is not being outside privacy law. You may still be a business associate of a supervising physician group or telehealth prescriber, which imposes the Security Rule and much of the Privacy Rule by contract. State law applies regardless: California's Confidentiality of Medical Information Act binds providers directly, Washington's My Health My Data Act was built for health data HIPAA does not reach, and state medical, nursing, and cosmetology boards impose confidentiality duties on your licensees. The pragmatic answer for nearly every med spa is to adopt HIPAA-equivalent standards and document that you have chosen to do so.

The administrative backbone

These are the items that exist as paper and that an investigator will ask to see on day one.

RequirementWhat it means in practiceWhere it lives in your paperwork
164.530(a) privacy officialOne named person responsible for policies, plus a contact for complaintsDesignation letter in the policy manual
164.308(a)(2) security officialOne named person responsible for security policies and proceduresDesignation letter in the policy manual
164.530(i) policies and proceduresWritten policies matching what you actually do, reviewed and datedPolicies and procedures manual
164.530(b) workforce trainingRole-based training at hire and after material changesCurriculum plus signed attestations
164.530(e) sanctions policyWritten, graduated consequences that are actually appliedEmployee handbook
164.530(f) mitigationDuty to mitigate known harmful effects of an improper disclosureIncident response procedure
164.530(g) no retaliationNo adverse action against someone who complains or cooperatesEmployee handbook
164.530(h) no waiverYou cannot condition treatment on waiving HIPAA rightsConsent and intake forms
164.530(c) safeguardsAdministrative, technical, and physical safeguards for PHI in every form, paper includedPolicy manual and facility procedures
164.530(j)(2) documentation retentionSix years from creation or from last effective date, whichever is laterRecords retention schedule

The safeguards standard at 164.530(c) is broader than the Security Rule because it covers paper and speech, not just electronic data. In a med spa that means the sign-in sheet at the front desk, the printed chart left on a counter, the schedule visible on a monitor from the waiting area, and consultations audible through a treatment room door.

The Security Rule checklist

If you hold electronic protected health information, and any practice with an EMR, tablet intake, a shared drive, or a phone full of treatment photos does, the Security Rule applies in full.

Start with the risk analysis at 45 CFR 164.308(a)(1)(ii)(A), which requires an accurate and thorough assessment of the potential risks and vulnerabilities to the confidentiality, integrity, and availability of ePHI held by the organization. It is a required specification. Its companion at 164.308(a)(1)(ii)(B), risk management, requires you to implement measures sufficient to reduce risk to a reasonable and appropriate level. A generic downloaded template with your name typed on it does not satisfy either. The analysis has to inventory your actual systems, devices, workflows, and vendors. HHS and ASTP publish a free Security Risk Assessment Tool built for small practices, which is a defensible starting point.

From there, work the three safeguard families. Administrative safeguards at 164.308 include information system activity review, workforce authorization and termination procedures, security awareness and training under 164.308(a)(5), and a contingency plan under 164.308(a)(7) whose data backup, disaster recovery, and emergency mode operation specifications are all required. Physical safeguards at 164.310 cover facility access, workstation use and security, and device and media controls including how you dispose of and reuse hardware. Technical safeguards at 164.312 cover access control with unique user identification as a required specification, audit controls, integrity, person or entity authentication, and transmission security. Documentation under 164.316(b)(2)(i) is kept six years.

Two practical notes. Unique user IDs are required, so the shared front-desk login has to go. And while encryption is an addressable specification at 164.312(a)(2)(iv) and 164.312(e)(2)(ii), encrypting to current HHS-recognized standards renders PHI unsecured no longer, which means an encrypted lost laptop generally does not trigger breach notification at all. That single control has more risk-reduction value per dollar than anything else on this list.

Addressable never means optional. Under 164.306(d)(3) you must assess each addressable specification, implement it if reasonable and appropriate, and if not, document the reason and adopt an equivalent alternative where reasonable. An undocumented skip is simply a finding waiting to happen.

Worth watching: OCR published a proposed Security Rule overhaul in the Federal Register on January 6, 2025 that would convert many addressable specifications into requirements, including multifactor authentication, encryption, asset inventories, and vulnerability scanning. As of August 2026 it is still a proposal with no final rule published and the regulatory agenda pushed out. Do not implement it as law, but the direction of travel is obvious and none of those controls would be wasted effort.

Patient-facing Privacy Rule obligations

Give the Notice of Privacy Practices no later than first service delivery, post it in the office, publish it on your website, and make a good faith effort at written acknowledgment, per 45 CFR 164.520(c). Apply minimum necessary under 164.502(b) and 164.514(d), so the front desk sees scheduling data and not full clinical charts.

Honor the individual rights, each with its own deadline. Access to records under 164.524 within 30 days, with one 30-day extension and only reasonable cost-based fees. Amendment requests under 164.526 within 60 days, with one 30-day extension. Accounting of disclosures under 164.528, reaching back six years. Requests for restrictions under 164.522(a), including the one you must grant under 164.522(a)(1)(vi) when a patient pays out of pocket in full and asks you not to tell their health plan. Confidential communications under 164.522(b), which is why the intake form should capture how the patient wants to be contacted.

Use a proper 164.508 authorization for anything outside treatment, payment, and operations. Marketing is the one that catches aesthetics practices, and before and after photos used to promote the practice are marketing.

Vendors, and the first 48 hours after an incident

Under 164.502(e) and 164.308(b), you need a signed business associate agreement with anyone who creates, receives, maintains, or transmits PHI for you. In a med spa that usually means the EMR or practice management platform, cloud storage, the IT provider, the answering or scheduling service, the transcription tool, the document shredding company, and any marketing agency that can see patient data. Consumer-grade tools are the trap: a personal cloud account or a free messaging app will not sign a BAA, so putting patient photos there is a violation before anything goes wrong. Keep every executed BAA and know its renewal date.

For breaches, 45 CFR 164.402 presumes an impermissible use or disclosure is a breach unless you demonstrate a low probability that PHI was compromised, using a documented four-factor risk assessment: the nature and extent of the PHI involved, who used or received it, whether it was actually acquired or viewed, and the extent to which the risk has been mitigated. Individual notice is due without unreasonable delay and within 60 days of discovery under 164.404. If 500 or more individuals are affected, notify HHS within 60 days under 164.408 and notify prominent media in the state or jurisdiction under 164.406. Smaller incidents go into a log and are reported to HHS annually, within 60 days after the calendar year ends, meaning a March 1 deadline in most years. Do the four-factor assessment in writing even when you conclude there was no breach, because the written conclusion is the defense.

The bottom line

Start by settling whether HIPAA applies to your practice and writing that determination down, because a cash-only med spa may not be a covered entity while still being bound by state privacy law. Then treat the security risk analysis at 164.308(a)(1)(ii)(A) as the anchor of the whole program, since every safeguard decision is supposed to follow from it. Name a privacy official and a security official, adopt written policies you genuinely follow, train the workforce, and get BAAs signed before any vendor touches patient data. Keep all of it for six years, and rehearse breach response before you need it, because 60 days moves quickly once a laptop goes missing.

Frequently asked questions

What is the single most important item on a HIPAA compliance checklist?

The security risk analysis required by 45 CFR 164.308(a)(1)(ii)(A). It is a required implementation specification, not an addressable one, and it is the item OCR asks for first in almost every investigation. Every other safeguard decision you make is supposed to follow from what that analysis found.

Does a med spa need business associate agreements?

Yes, with any vendor that creates, receives, maintains, or transmits protected health information on your behalf, as required by 45 CFR 164.502(e) and 164.308(b). That typically covers your EMR, cloud storage, IT support, shredding company, answering service, and any marketing agency with access to patient data. Payment processors handling only card transactions and couriers acting as mere conduits generally do not need one.

How long do I have to report a HIPAA breach?

Individual notice must go out without unreasonable delay and no later than 60 days after discovery, under 45 CFR 164.404. Breaches affecting 500 or more individuals must be reported to HHS within that same 60 days, while smaller breaches are logged and reported annually, within 60 days after the end of the calendar year.

Related templates

Free template for your practice

Get a ready-to-edit version of the document this guide describes, plus new templates as we publish them. One useful email now and then, no spam.

Unsubscribe anytime.

This guide is educational and is not legal or medical advice. Verify requirements with your own advisors and your state board before applying them in your practice.