HIPAA Compliance for Medical Spas Offering GLP-1s Programs
Medical spas offering GLP-1s programs are covered entities under HIPAA. Here is what compliance looks like in practice β from patient records to marketing to telehealth.
HIPAA Compliance for Medical Spas Offering GLP-1 Programs
Medical spas that offer GLP-1 weight management programs are healthcare providers under HIPAA. This means they are subject to the full range of HIPAA Privacy Rule and Security Rule requirements. For many med spa operators who came from the aesthetics side of the business, HIPAA compliance is an area where they may have gaps.
This post covers the key HIPAA requirements for medical spas offering GLP-1 programs.
Are You a HIPAA Covered Entity?
If your med spa:
- Has a licensed prescriber on staff or under contract
- Creates, receives, maintains, or transmits protected health information (PHI)
- Conducts any HIPAA-covered transactions (electronic billing, etc.)
...then you are a HIPAA covered entity and must comply with HIPAA.
Medical spas offering GLP-1 programs almost certainly meet this definition. The patient evaluations, prescriptions, and treatment records you create are PHI.
The Privacy Rule: Key Requirements
Notice of Privacy Practices
Every covered entity must provide patients with a Notice of Privacy Practices (NPP) that explains:
- How you use and disclose PHI
- Patient rights regarding their PHI
- Your privacy practices and policies
The NPP must be provided to patients at the first service encounter and posted in your facility and on your website.
Minimum Necessary Standard
When using or disclosing PHI, use only the minimum amount necessary to accomplish the purpose. This applies to:
- Staff access to patient records (staff should only access records they need for their job)
- Disclosures to third parties (share only what is needed)
- Internal communications (discuss patient information only when necessary)
Patient Rights
Patients have rights under HIPAA that you must honor:
- Right to access: Patients can request copies of their PHI
- Right to amend: Patients can request corrections to their PHI
- Right to accounting of disclosures: Patients can request a list of disclosures of their PHI
- Right to restrict: Patients can request restrictions on certain uses of their PHI
- Right to confidential communications: Patients can request communications by specific means
Marketing Restrictions
HIPAA has specific rules about using PHI for marketing. Key rules:
- Authorization required: Using PHI to market products or services generally requires patient authorization
- Treatment communications: Communications about treatment options (including GLP-1 programs) are generally permitted without authorization
- Refill reminders: Reminders about medication refills are permitted without authorization
Common mistake: Sending marketing emails to patients about new services without authorization. This is a HIPAA violation if it uses PHI (like the fact that the patient is a GLP-1 patient).
The Security Rule: Key Requirements
Administrative Safeguards
- Security officer: Designate a HIPAA security officer
- Risk analysis: Conduct a formal risk analysis of your electronic PHI (ePHI)
- Workforce training: Train all staff on HIPAA security
- Access controls: Implement policies for who can access ePHI
Physical Safeguards
- Facility access controls: Control physical access to areas where ePHI is stored or processed
- Workstation security: Secure workstations that access ePHI
- Device controls: Policies for mobile devices that access ePHI
Technical Safeguards
- Access controls: Unique user IDs and passwords for ePHI systems
- Audit controls: Log access to ePHI systems
- Encryption: Encrypt ePHI in transit and at rest
- Automatic logoff: Implement automatic logoff for ePHI systems
Telehealth and HIPAA
Telehealth GLP-1 prescribing creates specific HIPAA considerations:
Platform selection: Use a HIPAA-compliant telehealth platform. The platform vendor must sign a Business Associate Agreement (BAA) with you.
Video encryption: Telehealth encounters must use encrypted video platforms.
Recording: If you record telehealth encounters, the recordings are PHI and must be protected accordingly.
Patient consent: Obtain patient consent for telehealth encounters and document it.
Business Associate Agreements
Any vendor that creates, receives, maintains, or transmits PHI on your behalf is a Business Associate and must sign a BAA. This includes:
- EHR vendors
- Telehealth platforms
- Billing services
- Cloud storage providers
- IT support vendors
Failure to have BAAs in place is a common HIPAA violation.
Breach Response
If a breach of PHI occurs, HIPAA requires:
- Assessment: Determine the scope and nature of the breach
- Notification: Notify affected patients within 60 days
- HHS notification: Notify HHS (for breaches affecting 500+ individuals, notify immediately; for smaller breaches, report annually)
- Media notification: For breaches affecting 500+ individuals in a state, notify prominent media outlets
Common HIPAA Violations in Med Spas
- Posting before/after photos without proper authorization
- Discussing patient information in public areas
- Using patient email addresses for marketing without authorization
- Failing to have BAAs with vendors
- Inadequate access controls for patient records
- Failing to conduct a risk analysis
Contact us with compliance questions β
This content is for informational purposes only and does not constitute legal advice. Consult with a HIPAA compliance specialist regarding your specific obligations.
Explore Topics
Written by
Ian J.
Co-Founder & Managing Partner β Mass-Tort Pharma Background & Medical Operator
Ian is a co-founder of MedClinic Partners with over a decade of experience in mass-tort pharmaceutical matters and medical practice operations. He has personally overseen the launch and compliance infrastructure of multiple GLP-1 and peptide programs, and brings a unique legal-operational perspective to compounding supply chain management.
Editorial standards: All content on medclinicpartners.com is reviewed by licensed medical operators and compounding compliance specialists before publication. Articles are updated when regulatory guidance changes. This content is for licensed healthcare providers only and does not constitute medical advice.