MedspaPhotos Pricing

What makes a before and after photo app HIPAA compliant

The short version: "HIPAA compliant" on a software marketing page is a claim, not a feature. What you can actually verify is mechanics: encryption at rest and in transit, per-user logins, audit logs, a vendor who signs a Business Associate Agreement, photos kept off personal camera rolls, and written patient authorization before any marketing use.

This page is the checklist, usable against any vendor. Medspa Photos was built to pass it: encrypted storage, staff PINs, logged actions, a BAA for covered practices, and a server that blocks any export the patient's signed consent does not cover. $99 a month flat, 14-day trial, no sales call.

The checklist, and where it comes from

HIPAA's Security Rule requires safeguards for electronic protected health information: access control, audit controls, and transmission security among them [1]. The Privacy Rule requires written authorization before a covered entity uses identifiable patient photos for marketing [2]. Translated into things you can check on a demo or a trial:

The part most apps skip: enforcement

Most vendors in this category store a consent form and stop there. The compliance failure almost never happens at signing; it happens months later, when someone posts a photo the consent never covered. A stored form does not prevent that. A gate does.

In Medspa Photos, the patient signs a photo consent on the clinic device and chooses what they allow: clinical record only, or social media too, identifiable or not. The signed record is stored with the photos, versioned and time-stamped. When staff hit export, the server checks that consent. No matching authorization, no export. If a patient revokes, future exports are blocked immediately and existing exports are pulled the same minute.

How Medspa Photos meets the checklist

Our implementation against the checklist above.
Requirement How it is met
Encryption Photos and consents encrypted at rest and in transit, stored in infrastructure built for regulated health data
Access control Each staff member signs in with their own PIN on the shared clinic device
Audit logs Every capture, view, and export is logged with who did it and when
BAA Signed for covered practices, at no extra cost. Ask before your trial ends
Camera roll Capture to export happens inside the app. Photos never touch the device camera roll
Marketing authorization Scoped, signed photo consent per patient; the server blocks any export it does not cover
Third-party code No analytics SDKs, no crash trackers, no third-party code near a patient photo

What no app can do for you

Honesty matters more on this page than anywhere else. Software covers the technical safeguards and the paperwork trail. It does not decide whether your practice is a covered entity, train your staff, write your policies, or stop someone from photographing a patient on a personal phone in the hallway. Compliance is a property of your practice. Good software just makes the compliant path the easy one.

Run the checklist against us for free. 14 days, set up the same day, no sales call.

Start your 14-day free trial

$99 per month per location after the trial. Card required, cancel anytime. Or read more on the product page.

Common questions

Can an app itself be HIPAA compliant?

Not by itself. Software can meet the technical safeguards and the vendor can sign a BAA, but compliance belongs to your practice: policies, training, and how photos are actually handled. Any vendor that says their app makes you compliant is overclaiming.

Is my med spa a covered entity?

It depends on how you bill and operate; many cash-pay med spas are not, while practices billing insurance electronically generally are. Ask your attorney. The safe practices are the same either way.

Does HIPAA allow before and afters on social media?

For covered entities, marketing use of identifiable photos requires prior written authorization; a treatment consent does not substitute. The safe pattern for any practice: photo-specific, signed, scoped consent, enforced by the software at export.

Are staff camera rolls really a problem?

They are the biggest one. A patient photo on a personal phone is unencrypted PHI outside your control: it syncs to personal clouds and survives employee departures. Keep capture, storage, and export inside one controlled system.

Will Medspa Photos sign a BAA?

Yes, for covered practices, at no extra cost. Ask before your trial ends.

Sources

  1. HIPAA Security Rule technical safeguards, 45 CFR 164.312 (access control, audit controls, integrity, transmission security), hhs.gov, accessed July 31, 2026.
  2. HIPAA Privacy Rule authorization requirements for marketing, 45 CFR 164.508(a)(3), hhs.gov, accessed July 31, 2026.

This page is general information, not legal advice. If any of it is out of date, tell us at hello@consentshot.com and we will correct it.