HIPAA-Compliant Marketing

Before & After Photos and HIPAA: What Practices Can Publish (2026)

HIPAA enforcement in the marketing era has been unambiguous: University of Rochester Medical Center paid $2.85M and Froedtert Health $2M over patient data flowing through marketing technology, and OCR has separately fined practices for using patient information in marketing and review responses without authorization. Before/after photos sit at the exact intersection of those cases — they are simultaneously the most persuasive marketing asset in aesthetics, dermatology, dental, and plastic surgery, and protected health information published to the open internet.

The good news for 2026: you can absolutely publish before/after photos. Practices do it compliantly every day. But the rules are stricter and more specific than most practices realize, and the two most common failure modes — "we cropped the face, so it's anonymous" and "they signed something at intake" — are both wrong.

Yes, photos are PHI — even without a name

HIPAA's de-identification standard lists 18 identifiers that must be removed for data to stop being PHI. Full-face photographs and any comparable images are identifier #17, by name. A full-face before/after is PHI, period, even if you never publish the patient's name.

And partial images don't automatically save you:

  • Cropping to the treatment area helps but doesn't guarantee de-identification. The standard also includes "any other unique identifying characteristic" — a distinctive tattoo, birthmark, scar, unusual jewelry, or even recognizable surroundings can make a cropped photo identifiable. A tummy-tuck photo with a one-of-a-kind tattoo is identifiable to everyone who knows that patient.
  • Context re-identifies. A photo of a rare procedure, posted the week it happened, in a small town, tagged to your location — people connect dots. Courts and regulators know they do.
  • Metadata travels. Image files can carry timestamps, device info, and even location data unless stripped.

The safe operating assumption: treat every clinical photo as PHI, and publish only with authorization. De-identification is a fallback argument, not a strategy.

The authorization that actually covers marketing

Publishing a patient's photo for marketing requires a signed, HIPAA-valid authorization specific to that use. The consent-to-treat and consent-to-photograph forms in your intake packet cover clinical documentation — not your website, not Instagram, not the ad campaign. A valid marketing authorization:

  • Describes the images and the use — which photos, and where they may appear (website gallery, social media, paid ads, print). Broader use needs broader language; "any and all media" boilerplate signed under time pressure at intake is exactly what regulators and plaintiff's attorneys pick apart.
  • Is signed voluntarily and unbundled. Treatment can't be conditioned on it, and it can't be buried as page 9 of the intake packet. Make it a standalone document presented after treatment, when the patient can see the actual photos.
  • Names an expiration or expiration event, and
  • Explains the right to revoke — and you must be able to execute a revocation. This is the operational trap: when a patient revokes, you need to find and remove every placement. If you can't inventory where a photo lives, you can't honor a revocation. Keep a register: photo → authorization → every published location.

Two more rules worth engraving: never publish first and paper later, and never reuse a photo beyond what its authorization says — a website authorization does not cover the Instagram ad your marketing intern boosted.

See it live on your own practice

EHR-integrated booking, HIPAA-safe tracking, and marketing that reports in kept appointments — in one platform.Book a Demo

Here's the part almost nobody covers, and where most compliant-on-paper practices are exposed in practice: the gallery infrastructure itself.

A typical WordPress before/after gallery uploads full-resolution clinical photos into the site's media library, where they get public, guessable URLs, are crawled and indexed by Google, and show up in Google Images — cropped out of context, stripped of your framing, next to the patient's town in the search suggestions. Patients who happily authorized a gallery on your site did not sign up to be a Google Images result for "gynecomastia before after." And once indexed, removal is slow and partial.

Our stack treats galleries as sensitive by design:

  • Patient galleries are noindexed by default. Photos are viewable by visitors browsing your site — which is the entire marketing point — but marked off-limits to search-engine indexing, so authorized images don't escape into image search and live forever beyond a revocation.
  • Galleries run on hardened, monitored WordPress. Fail-closed two-factor authentication on admin access, a nightly allow-list malware scanner (which has caught attackers' own backdoors planted as "allow-listed" files), and off-site GCS backups — because a compromised website full of clinical photos is a breach, not an inconvenience. The full build is documented in how we harden WordPress for medical practices.
  • Intake and booking never touch the site's database — the photo-consent workflow and patient records live in the BAA-covered platform, not in WordPress (the architecture).

No email gate. Ten items.

  1. Pull every published before/after — website, Instagram, Facebook, ads, print, TV screens in the lobby.
  2. Match each to a signed marketing authorization. No authorization on file = take it down today, then ask permission properly.
  3. Read the authorizations you have. Do they cover the actual placements (social, ads), or just "the website"?
  4. Check for identifying features in "anonymous" crops — tattoos, birthmarks, jewelry, backgrounds.
  5. Google your practice + "before after" and check Google Images. If clinical photos appear in image search, your gallery is indexed.
  6. Check gallery pages and image files for noindex handling. If you can't tell, assume indexed.
  7. Strip metadata on published images.
  8. Build the revocation register: photo → authorization → every location it appears.
  9. Verify who can upload/access clinical photos on the website and in staff phones' camera rolls (a policy problem as much as a technical one).
  10. Check your photo-consent capture at intakemed spa intake done right separates clinical photo consent from marketing authorization.

The same authorization logic governs testimonials — see HIPAA rules for patient reviews.

The do-marketing answer

Before/afters compliantly published are still the highest-converting content in aesthetics — so do the marketing properly: build authorization capture into your post-treatment workflow (patients thrilled with results say yes at remarkable rates when asked respectfully), organize galleries by procedure so they rank the pages while the photos stay noindexed, refresh quarterly, and pair every gallery with a booking path so the emotional peak converts.

PilotPractice runs this end to end — the hardened site, the noindexed gallery system, the consent workflow, and the marketing that turns results into booked consults — with SOC 2 and HIPAA controls documented at trust.pilotpractice.com. Full strategy in the 2026 HIPAA-compliant marketing guide, or book a demo and we'll review your gallery's exposure live.


PilotPractice security & compliance documentation: trust.pilotpractice.com

See it live on your own practice

EHR-integrated booking, HIPAA-safe tracking, and marketing that reports in kept appointments — in one platform.Book a Demo

Let’s Discuss Your Growth

Monthly Email Blast Cardiologist Marketing Company Banner
Virtual Patient Coordinator Impact
Client: Just Go Lipo in Scottsdale, AZ
Woman in blue bikini with text 'TOP MIAMI PLASTIC SURGERY CENTER' on dark blue background
Shirtless man with sunglasses at beach with text 'Look Good, Feel Good'
Woman's face showing eye makeup with velyss logo and 'SAY IT WITH YOUR EYES' text
Revive Surgical Institute website homepage showcasing cosmetic and plastic surgery services in Miami with before and after gallery and patient testimonials
Exert Clinic Website
New! Voice AI