Practitioner Playbook: Med Spa Before and After Rules for U.S. Owners

Practitioner reviewing patient marketing authorization

You need a separate, written marketing authorization that names exact uses, identifies vendors, and expires on a defined date, plus plain-language typicality disclosures on every result claim and a secure, BAA-backed storage workflow for the images themselves. Skip any one of those three pieces and you’re carrying legal exposure, whether the photos ever get flagged or not.


TL;DR:

  • A valid marketing authorization must specify the practice, recipients, expiration or triggering events, and revocation procedures to avoid legal exposure.
  • Compliance requires both FTC substantiation and HIPAA authorization, which do not substitute for each other, and disclosures alone often fail to prevent misleading impressions.
  • State-specific guidelines vary in enforcement, scope-of-practice, ownership, and advertising oversight; practitioners should verify guidance from their state medical board regularly.
  • Secure image handling involves using practice-owned devices, encrypted uploads, and signed BAAs with vendors to protect patient PHI and meet HIPAA requirements.
  • Building a compliant marketing program depends on clear procedural steps, designated approval responsibilities, and integrating BAA workflows into digital infrastructure without harming conversion.

Adjetmarketing
Build More Compliant Patient Marketing
AdJet Marketing helps healthcare practices use SEO, Google Ads, and conversion-focused websites to generate patient leads with industry best practices.

Explore marketing support

Table of Contents

What the FTC and HIPAA require for before-and-after photos

Two separate federal frameworks govern your before-and-after photos, and they don’t overlap as neatly as most owners assume. The FTC cares about whether your advertising misleads a patient into expecting results they probably won’t get. HIPAA cares about whether you had permission to use a patient’s protected health information for marketing in the first place. A photo can clear one test and fail the other.

On the advertising side, the FTC’s Endorsement Guides require advertisers to have adequate substantiation for any performance claim, and if the result shown isn’t typical, you must disclose what patients can generally expect instead. A dramatic transformation photo, without context, invites the assumption that most patients see the same outcome. That assumption is exactly what the FTC guidance is built to prevent.

On the privacy side, HHS explains that using a patient’s photo for marketing generally requires a written authorization under the HIPAA Privacy Rule, separate from any general consent to treatment. A before-and-after photo counts as protected health information the moment it’s tied to a specific patient and a specific procedure, even without a name attached.

Here’s where it gets tricky for practice owners: these two obligations stack, they don’t substitute for each other.

  • Truthful but undisclosed: a real result, shown without a typicality disclosure, can still mislead under FTC standards.
  • Authorized but overstated: a properly consented photo used with exaggerated captions still creates FTC risk.
  • Compliant caption, no authorization: accurate, well-disclosed marketing copy doesn’t fix a missing HIPAA authorization.

Disclosures alone often aren’t enough to protect a consumer’s impression. An FTC consumer study found that even prominent disclosures frequently fail to neutralize the efficacy impression created by multiple testimonials shown together. That’s a strong argument for pairing every disclosure with real substantiation data rather than relying on a disclaimer to do the work alone.

Which rules change by state and how to verify your state board’s guidance

Federal rules set the floor, but your state medical board and scope-of-practice statutes decide a lot of the details that actually determine what you can publish and who can perform the treatment behind the photo.

Three areas tend to vary the most from state to state:

  1. Advertising enforcement emphasis. Some boards actively police before-and-after claims and testimonial language; others rarely touch marketing unless a complaint triggers a review.
  2. Corporate practice of medicine (CPOM) and ownership limits. States differ on who can own a med spa and how much oversight a medical director must exercise, which affects who is legally responsible for approving marketing content.
  3. Scope-of-practice rules. These determine which staff members can legally perform the procedure shown in the photo and, in some states, who is allowed to make or approve advertised claims about it.

To verify your state’s current position, search your state medical board’s website for “advertising guidelines,” “med spa” or “aesthetic services,” and any published advisory opinions. Save a dated copy or screenshot of whatever you find; boards revise guidance without much notice, and having your own timestamped record matters if a question ever comes up.

Escalate to a healthcare attorney when you hit conflicting guidance between your state board and a professional association, when you’re adding a newer service category such as GLP-1 medications or injectables that your state hasn’t clearly addressed, or when board language is vague enough that two reasonable readings lead to different marketing decisions.

Designing a compliant marketing authorization: required elements and sample checklist

A general treatment consent form does not cover marketing use of a patient’s image, and treating it as if it does is one of the most common gaps we see when reviewing a new client’s intake paperwork. The eCFR text for 45 CFR 164.508 lays out the core elements a valid marketing authorization needs, and a form missing any of them won’t hold up under an audit.

Your authorization should include:

  • The practice’s identity and a plain-language description of what the photo will be used for.
  • Named recipients, meaning your in-house marketing team, any outside agency, and the specific platforms (website, Instagram, Google Ads) where the image may appear.
  • An expiration date or triggering event, since an open-ended authorization is harder to defend and easier to challenge.
  • A clear revocation process, so the patient knows exactly how to withdraw permission and what happens to images already published.
  • Signature and date, kept with the record, not just referenced in a chart note.

A marketing authorization missing named third-party recipients or an expiration event will not meet the core-element guidance under 45 CFR 164.508; both details close a gap auditors specifically look for.

Element Why it matters
Named recipients Confirms the patient knew which parties would see or handle the image
Expiration or event Prevents indefinite use without renewed consent
Revocation process Gives the patient a real, documented way to withdraw permission
Editing limits Sets boundaries, such as cropping only, no retouching
Remuneration disclosure Discloses any payment or discount tied to the patient’s participation

If a patient receives a discount or free treatment in exchange for appearing in your marketing, that arrangement needs to be disclosed in the authorization itself, not buried in a separate agreement. Store the signed form alongside a retention and redaction policy, and log every time the image is published or a revocation is processed. That audit trail is what protects you if a patient later disputes how their photo was used.

Secure capture, storage, transfer, and vendor management: BAAs and platform checks

Any agency, CMS, or software vendor that touches a patient photo tied to a procedure is handling protected health information, and that triggers the need for a Business Associate Agreement. A BAA should specify who can access the images, require encryption both at rest and in transit, and spell out breach notification timelines if something goes wrong.

A safe photo workflow generally follows this sequence:

  1. Capture the image on a practice-owned device, never a personal phone.
  2. Upload immediately to an encrypted, practice-managed server or HIPAA-compliant vendor platform.
  3. Delete the local copy from the capture device once the upload is confirmed.
  4. Store and log the file with a timestamp and the uploader’s identity, so you have a clean audit trail if questions arise later.

Before signing with any vendor, confirm they can show encryption at rest and in transit, documented access controls, a stated retention policy, a written incident response plan, and a signed BAA on file, not just a verbal assurance. HIPAA enforcement activity has repeatedly centered on covered entities that let third-party vendors host patient data without adequate security controls or a proper BAA in place, so this step isn’t optional paperwork.

Pro Tip: Never let staff post before-and-after photos directly from personal social accounts, even “just to save time.” That single habit is one of the fastest ways to lose control of both image rights and PHI security.

How to disclose typicality and substantiate visual claims to reduce FTC risk

The safest disclosure language ties directly to data you can produce if asked, something like “results shown are from a single patient after three sessions; individual results vary based on skin type and treatment plan,” rather than a vague “results may vary” tag. Regulators have been moving toward expecting disclosure of generally expected performance, not just a blanket disclaimer, which means the more specific your language, the better protected you are.

Place the disclosure where a patient will actually see it before forming an impression, not buried at the bottom of a long caption. That means directly under the image, as a visible overlay on video content, or immediately adjacent to the claim on a landing page rather than several scrolls away.

  • Internal outcome logs: track how many patients achieved a comparable result under similar conditions.
  • Clinic-run audits: periodically review your own before-and-after archive against the claims you’re making.
  • Peer-reviewed studies: cite them only when they directly support the specific claim, not as general credibility filler.

A single testimonial’s dramatic result rarely reflects the typical patient outcome, and the FTC’s guidance treats that gap as a substantiation problem, not a marketing style choice. Document your evidence with dates, so you can show what you knew and when if a claim is ever challenged.

Enforcement patterns: HIPAA fines, FTC action triggers, and state board discipline

Noncompliance rarely announces itself with a single dramatic event. More often it surfaces as a patient complaint, a routine audit, or a competitor’s tip that snowballs into a formal inquiry.

  • HIPAA violations typically move through tiered penalties tied to the level of negligence, alongside breach notification duties; OCR investigations often end in a corrective action plan rather than an immediate maximum fine.
  • FTC scrutiny tends to focus on misleading typicality claims, dramatic results shown without substantiation, or paid endorsements presented without a clear disclosure.
  • State medical boards typically respond with cease-and-desist letters, mandated corrective advertising, or consent decrees requiring specific changes to marketing practices going forward.

None of these outcomes require intent to deceive. A well-meaning practice that never built a substantiation file or never asked for a specific marketing authorization faces the same exposure as one that knowingly cut corners.

Operational playbook: capture, approval, and audit steps to keep your before-and-after program compliant

A workable before-and-after program runs on a short, repeatable sequence rather than a policy binder nobody reads.

  1. Intake: obtain the separate marketing authorization before any photo is taken for promotional use.
  2. Capture and upload: follow the secure device-to-server workflow outlined earlier, with no local copies retained.
  3. Substantiation check: a designated staff member confirms the result falls within your documented typical range before it’s approved for publication.
  4. Disclosure review: marketing copy gets checked against your standard typicality language before it goes live.
  5. Publication log: record where and when the image was used.
  6. Retention and revocation audit: review consents on a set schedule and process any withdrawal requests promptly.

Pro Tip: Assign one person, not a rotating shift, as the final approver for before-and-after content. Diffuse ownership is how disclosure language quietly disappears from a caption over time.

Train staff with a short script: no photo leaves the building without a signed authorization on file, no caption ships without an approved disclosure line, and any doubt gets escalated to the practice manager before publication, not after.

Vendor role, BAAs, and compliant marketing that still converts

Many clinics come to some marketing agencies after a previous vendor mishandled patient images or skipped the BAA conversation entirely, usually discovered only when a compliance question forces a review of old contracts. Any marketing agency handling before-and-after photos tied to identifiable patients is functioning as a business associate under HIPAA, and that relationship needs a signed BAA before a single image changes hands.

Before a marketing agency takes on image work for a med spa client, it is important to have a documented authorization process already in place, a limited and defined scope for what PHI will be handled, and a secure CMS rather than shared folders or email attachments. We build HIPAA-aware landing pages, manage secure image galleries, and help clients organize the substantiation records that support their disclosure language, all without slowing down the funnel that turns a visitor into a booked consultation.

Secure workflow for authorized healthcare images

The most common mistake isn’t malice, it’s speed: a practice wants a campaign live by Friday and skips the authorization paperwork to hit the date. Building compliance into the timeline from the start, rather than retrofitting it after a campaign launches, changes very little about the creative and a great deal about your risk exposure.

What most med spa owners get wrong about before-and-after compliance

The advice you’ll find most often treats “get a signed consent” as the finish line, and that’s where a lot of practices stop. The research tells a different story: a signature alone doesn’t protect you if the authorization is vague, if the disclosure language is generic, or if the images sit in an unsecured vendor folder with no BAA behind them.

The gap most owners underestimate is substantiation. It’s easy to get a patient to sign a form. It’s harder to build the habit of tracking outcomes so your “most patients see X” claim actually means something if challenged. That’s also the piece most templates skip entirely, because it takes ongoing work rather than a one-time form.

If you do only one thing after reading this, audit your current photo vendor relationships before you touch your consent forms. A perfect authorization doesn’t help you if the images end up in a tool with no BAA and no access controls behind it.

— Felix

Compliant marketing that still fills your calendar

Building a before-and-after program that meets federal and state expectations doesn’t have to slow down your booking rate, but it does require the right infrastructure behind your campaigns. Some marketing agencies design med spa landing pages and image galleries with secure handling built in from the start, not bolted on after a compliance scare.

  • Custom med spa landing pages built around your authorized before-and-after content and disclosure language.
  • Secure gallery integrations designed to keep patient images off unsecured platforms.
  • Google Ads management that keeps your creative compliant while still driving qualified consultation requests.

If you want a partner who treats patient privacy and lead generation as the same job rather than competing priorities, take a look at our med spa marketing services to see how a scoped engagement, BAA included, typically starts.

Authoritative primary sources for verification and deeper reading

This article is general information, not a substitute for advice from a qualified lawyer. Consult a qualified legal professional about your own circumstances before acting on anything here.

Sources

FAQ

What are the requirements for a med spa?

Requirements vary by state and typically cover medical director oversight, scope-of-practice limits on who can perform treatments, and business licensing rules. Because these details differ significantly across states, check your specific state medical board’s advertising and ownership guidance before opening or expanding services.

Do med spas have to comply with HIPAA?

Yes, any med spa that creates, stores, or transmits protected health information, including before-and-after photos tied to a specific patient, must follow HIPAA. That includes obtaining proper written authorization for marketing uses and securing any vendor relationships with a signed BAA.

In what states can a RN own a med spa?

Ownership rules depend on each state’s corporate practice of medicine laws, and they change frequently enough that a general answer isn’t reliable. Verify current ownership requirements directly with your state medical board or a healthcare attorney licensed in your state before finalizing any ownership structure.

How should a med spa disclose that results are not typical?

The clearest approach states what most patients can expect under specific conditions, placed directly next to the image or claim rather than in fine print. This approach aligns with FTC guidance requiring disclosure of generally expected performance when a shown result isn’t typical.

It should name the practice, list every recipient of the image including any marketing vendor, state an expiration date or event, and explain how a patient can revoke consent. These elements reflect the core requirements under 45 CFR 164.508 for a valid marketing authorization.

Get The Results Your Business Deserves.
Let's Chat.

No marketing material will be sent. Our digital team will contact you within 24 hours.

Request a Call Back, Email or Free Site Audit.