MedClinic Partners

HIPAA Compliance for Medical Spas Offering GLP-1s Programs | MedClinic Partners

503A/503B Compounding Compliance & Regulations

HIPAA Compliance for Medical Spas Offering GLP-1s Programs

Medical spas offering GLP-1s programs are covered entities under HIPAA. Here is what compliance looks like in practice β€” from patient records to marketing to telehealth.

I
Ian J.Co-Founder & Managing Partner β€” Mass-Tort Pharma Background & Medical Operator
5 min read
Reviewed & updated:
HIPAA Compliance for Medical Spas Offering GLP-1s Programs β€” MedClinic Partners

HIPAA Compliance for Medical Spas Offering GLP-1 Programs

Medical spas that offer GLP-1 weight management programs are healthcare providers under HIPAA. This means they are subject to the full range of HIPAA Privacy Rule and Security Rule requirements. For many med spa operators who came from the aesthetics side of the business, HIPAA compliance is an area where they may have gaps.

This post covers the key HIPAA requirements for medical spas offering GLP-1 programs.

Are You a HIPAA Covered Entity?

If your med spa:

  • Has a licensed prescriber on staff or under contract
  • Creates, receives, maintains, or transmits protected health information (PHI)
  • Conducts any HIPAA-covered transactions (electronic billing, etc.)

...then you are a HIPAA covered entity and must comply with HIPAA.

Medical spas offering GLP-1 programs almost certainly meet this definition. The patient evaluations, prescriptions, and treatment records you create are PHI.

The Privacy Rule: Key Requirements

Notice of Privacy Practices

Every covered entity must provide patients with a Notice of Privacy Practices (NPP) that explains:

  • How you use and disclose PHI
  • Patient rights regarding their PHI
  • Your privacy practices and policies

The NPP must be provided to patients at the first service encounter and posted in your facility and on your website.

Minimum Necessary Standard

When using or disclosing PHI, use only the minimum amount necessary to accomplish the purpose. This applies to:

  • Staff access to patient records (staff should only access records they need for their job)
  • Disclosures to third parties (share only what is needed)
  • Internal communications (discuss patient information only when necessary)

Patient Rights

Patients have rights under HIPAA that you must honor:

  • Right to access: Patients can request copies of their PHI
  • Right to amend: Patients can request corrections to their PHI
  • Right to accounting of disclosures: Patients can request a list of disclosures of their PHI
  • Right to restrict: Patients can request restrictions on certain uses of their PHI
  • Right to confidential communications: Patients can request communications by specific means

Marketing Restrictions

HIPAA has specific rules about using PHI for marketing. Key rules:

  • Authorization required: Using PHI to market products or services generally requires patient authorization
  • Treatment communications: Communications about treatment options (including GLP-1 programs) are generally permitted without authorization
  • Refill reminders: Reminders about medication refills are permitted without authorization

Common mistake: Sending marketing emails to patients about new services without authorization. This is a HIPAA violation if it uses PHI (like the fact that the patient is a GLP-1 patient).

The Security Rule: Key Requirements

Administrative Safeguards

  • Security officer: Designate a HIPAA security officer
  • Risk analysis: Conduct a formal risk analysis of your electronic PHI (ePHI)
  • Workforce training: Train all staff on HIPAA security
  • Access controls: Implement policies for who can access ePHI

Physical Safeguards

  • Facility access controls: Control physical access to areas where ePHI is stored or processed
  • Workstation security: Secure workstations that access ePHI
  • Device controls: Policies for mobile devices that access ePHI

Technical Safeguards

  • Access controls: Unique user IDs and passwords for ePHI systems
  • Audit controls: Log access to ePHI systems
  • Encryption: Encrypt ePHI in transit and at rest
  • Automatic logoff: Implement automatic logoff for ePHI systems

Telehealth and HIPAA

Telehealth GLP-1 prescribing creates specific HIPAA considerations:

Platform selection: Use a HIPAA-compliant telehealth platform. The platform vendor must sign a Business Associate Agreement (BAA) with you.

Video encryption: Telehealth encounters must use encrypted video platforms.

Recording: If you record telehealth encounters, the recordings are PHI and must be protected accordingly.

Patient consent: Obtain patient consent for telehealth encounters and document it.

Business Associate Agreements

Any vendor that creates, receives, maintains, or transmits PHI on your behalf is a Business Associate and must sign a BAA. This includes:

  • EHR vendors
  • Telehealth platforms
  • Billing services
  • Cloud storage providers
  • IT support vendors

Failure to have BAAs in place is a common HIPAA violation.

Breach Response

If a breach of PHI occurs, HIPAA requires:

  • Assessment: Determine the scope and nature of the breach
  • Notification: Notify affected patients within 60 days
  • HHS notification: Notify HHS (for breaches affecting 500+ individuals, notify immediately; for smaller breaches, report annually)
  • Media notification: For breaches affecting 500+ individuals in a state, notify prominent media outlets

Common HIPAA Violations in Med Spas

  • Posting before/after photos without proper authorization
  • Discussing patient information in public areas
  • Using patient email addresses for marketing without authorization
  • Failing to have BAAs with vendors
  • Inadequate access controls for patient records
  • Failing to conduct a risk analysis

Contact us with compliance questions β†’

This content is for informational purposes only and does not constitute legal advice. Consult with a HIPAA compliance specialist regarding your specific obligations.

Explore Topics

#HIPAA#compliance#med spa#GLP-1s#patient privacy#telehealth
I

Written by

Ian J.

Co-Founder & Managing Partner β€” Mass-Tort Pharma Background & Medical Operator

Ian is a co-founder of MedClinic Partners with over a decade of experience in mass-tort pharmaceutical matters and medical practice operations. He has personally overseen the launch and compliance infrastructure of multiple GLP-1 and peptide programs, and brings a unique legal-operational perspective to compounding supply chain management.

Healthcare Compliance503A/503B RegulatoryMedical Practice M&AGLP-1 Supply Chain

Editorial standards: All content on medclinicpartners.com is reviewed by licensed medical operators and compounding compliance specialists before publication. Articles are updated when regulatory guidance changes. This content is for licensed healthcare providers only and does not constitute medical advice.

GLP Supply Access

Ready to source compliant compounded GLP's for your practice?

Get introduced to vetted 503A and 503B compounding partners. Real human support, all 50 states.