MedSpa Engine by HeadPills
Book a call

Guide · Compliance

Before/After Photo Rules for Med Spas

Updated July 2026. Educational overview, not legal advice. Confirm specifics with your state attorney.

This page summarizes common industry practice compiled from public compliance resources (including HIPAA Journal, ByrdAdatto and Little Health Law). It is not a substitute for advice from a licensed attorney familiar with your state's regulations.

1. Treat every before/after photo as PHI

A photo that shows a patient's face, or any combination of features that could identify them (a distinctive tattoo, piercing, birthmark, jewelry), tied to a specific treatment, is protected health information under HIPAA. This is true even if you never publish the patient's name.

2. Get a separate, written marketing authorization

General treatment consent does not cover marketing use. You need a distinct authorization form that specifies: exactly which photos or videos, where they will be used (website, Instagram, print, ads), for how long, and confirmation the patient can revoke consent. Keep signed authorizations on file for at least six years, matching standard HIPAA record retention.

3. Watch for indirect identification

Cropping out a face is not automatically sufficient. Tattoos, distinctive scars, jewelry the patient always wears, or even a recognizable room/background combined with a public social post can re-identify a patient. When in doubt, get explicit sign-off on the exact final image, not just the photo shoot in general.

4. Drug and brand names

Using a specific injectable brand name (Botox, Juvederm, etc.) in advertising typically requires LegitScript certification or direct manufacturer permission, depending on the platform and channel. The safer default across most marketing is to use general clinical terms: "neuromodulator" instead of the specific brand, "dermal filler" instead of the specific product line, unless you have confirmed the specific permission required.

5. Platform-specific rules (Meta/Instagram)

6. Never publicly confirm a patient's status

Do not confirm, even in a comment reply, that a specific named person is or was a patient. This applies to testimonials, tagged photos and DMs alike, patient status itself is protected information.

7. State-by-state variation

Requirements around medical advertising, testimonial use and injector licensing vary meaningfully by state (California, New York and Florida each have distinct rules for aesthetic advertising). Build a checklist specific to the state(s) you operate in and review it with your state attorney annually, since rules shift.

8. If you use a chatbot or AI tool that touches photos or health details

Any AI vendor processing patient photos or health information needs a signed Business Associate Agreement (BAA). See our AI automation service for how we scope this correctly.

Need a compliance-safe content plan?

We build before/after and social content workflows with authorization tracking built in.

No spam. We never share your info. Response within one business day.