HIPAA-Compliant Intake Forms for Med Spas & Aesthetics (2026)
Two health systems — University of Rochester Medical Center ($2.85M) and Froedtert Health ($2M) — have now paid seven figures over how patient data moved through their marketing stacks, and platforms like Klaviyo responded to the era by deplatforming health businesses outright rather than carry the risk. Med spas tend to read those headlines and think that's hospitals, not us. That instinct is exactly the industry's biggest compliance blind spot.
If your med spa has a medical director and performs injectables, lasers, IV therapy, or prescription-grade treatments, you are a healthcare provider — whether the lobby feels like a spa or not. The Botox consult form on your website, with its medication list and pregnancy question, is medical intake. And in most med spas, it's being handled like a newsletter signup.
The cosmetic/medical gray zone, settled
The "we're cosmetic, HIPAA doesn't apply" argument fails on several fronts at once:
- HIPAA doesn't care whether treatment is elective. A rhinoplasty and a filler appointment are both healthcare. If your practice is a covered entity — and med spas that bill insurance for anything, accept HSA/FSA payments, or operate under a physician's practice almost always are — HIPAA applies to your patient data, cosmetic or not.
- Even if you somehow fall outside HIPAA, you don't fall outside the law. State medical-privacy statutes (California's CMIA, Texas's HB 300, Washington's My Health My Data, and a growing list) cover consumer health data with definitions broad enough to catch every med spa in America — several with private rights of action, meaning patients can sue directly. And the FTC has shown, through the Cerebral era, that it will pursue health businesses for data practices regardless of HIPAA status.
- Your medical director's license doesn't grade on a curve. State medical boards expect medical-record handling standards wherever medicine is practiced. "The consult forms were in the website database" is not a sentence any medical director wants to say to their board.
The practical rule for 2026: run your intake data like the medical practice you are. It's cheaper than litigating the gray zone.
What med spa intake forms actually collect (and why it's all PHI)
Look at a typical aesthetics consult form: current medications and supplements (blood thinners matter for injectables), allergies, pregnancy and breastfeeding status, medical history, prior treatments and complications, treatment areas of concern. Attach a name and phone number and every line is protected health information — pregnancy status alone is among the most sensitive data a business can hold. If those submissions sit in your WordPress database or a generic form tool with no BAA, every one is an exposure.
Photo consent deserves its own paragraph. Before/after photos are the lifeblood of aesthetics marketing, and they are PHI — a full-face photo is a HIPAA identifier all by itself. Using a patient's photos in marketing requires a signed HIPAA authorization specific to marketing use: what images, where they may appear, and the right to revoke. A checkbox buried in the intake packet ("I consent to photos") covers clinical documentation, not your Instagram. Build photo authorization as its own document with its own signature line — and read our full guide on what practices can actually publish before your next post.
Separate marketing consent from treatment consent. Med spas live on memberships, packages, and promos — great business, but the consent to treat someone is not consent to market to them. Capture marketing opt-in (email and SMS) as its own explicit, unbundled choice, honor opt-outs instantly, and never make treatment contingent on it. Under HIPAA's marketing rules and the TCPA, bundled consent is the pattern that turns a promo blast into a violation.
The architecture: intake that never touches your website's database
The design rule we apply across every aesthetics client is simple: the website is a hallway, not a filing cabinet. A consult submission should pass through your site and land only in a system built to hold medical data.
Concretely, that means the form's answers are relayed machine-to-machine — the moment a visitor hits submit, your web server hands the entry straight to app.pilotpractice.com over an authenticated connection, and no copy is ever written to WordPress. The medication list, the pregnancy answer, the "prior filler complications" note: none of it exists where your host, your nightly backups, or a contractor with wp-admin could reach it. The receiving platform operates under a signed BAA, encrypts at the field level, and logs every access. (Curious how this works with the most popular WP form plugin? See Is Gravity Forms HIPAA Compliant?)
Two properties of that handoff matter more than they look:
- Each site holds its own credential. Authentication is per-site, so a submission is provably from your website — and if one property in a multi-location group is ever compromised, that single credential gets revoked while everything else keeps running.
- Junk dies at the door. Automated and bot submissions are screened out before a record is ever created, which keeps your consult-request metrics honest and keeps garbage out of a system that holds patient data.
And because people will paste literally anything into a text box — account passwords included — the platform is engineered so a password cannot persist: it's rejected at ingest, stripped again at the data-model layer, and swept from historical records on top of that. Defense in depth, not a policy memo.
See it live on your own practice
EHR-integrated booking, HIPAA-safe tracking, and marketing that reports in kept appointments — in one platform.Book a Demo
The ungated checklist: med spa intake audit
No email gate. Run it this afternoon.
- Submit a test consult request, then check your website's form-entries screen. If it's there, medical intake is stored in your site database today.
- Inventory the medical fields — medications, allergies, pregnancy, history. Each raises the stakes on wherever answers are stored.
- Ask every tool in the chain for a BAA: form tool, CRM, email platform, booking tool, host. No BAA, no PHI — full stop.
- Find your photo authorization. Is it a standalone signed document specifying marketing use and revocation — or a checkbox?
- Audit published before/afters against signed authorizations. Any photo without one comes down now.
- Check consent bundling. Is marketing opt-in its own unchecked box, separate from treatment consent?
- Check your SMS promos for proper consent capture and working opt-out — TCPA damages are per message.
- Check pixels on intake and booking pages. Meta and TikTok scripts on a consult form leak treatment interest to ad platforms (med spa Facebook ads, done compliantly).
- Check who receives notification emails and whether they contain full submissions.
- Verify deletion of legacy entries — including backups — after migrating to server-to-server intake.
Design notes: convert like a spa, protect like a practice
Keep the public form short — name, contact, treatment interest, "anything we should know?" — and save the deep medical history for the confirmed-appointment stage, delivered through the compliant platform. Put a consult-request form or live booking on every treatment page, not just Contact. And let people book real slots: aesthetics demand peaks at night, and an EHR-integrated booking flow captures it while your competitors' phones ring unanswered.
The do-marketing answer
Compliance is the floor. Growth comes from the machine around the form: treatment pages that rank, ads that convert without leaking PHI, before/afters published with real authorizations, membership campaigns sent only to genuinely opted-in lists, and attribution that tells you whether the filler patients came from Instagram or Google — all inside one BAA-covered system.
That's what PilotPractice runs for med spas and aesthetics practices end to end — website, server-to-server intake, EHR-integrated booking, and the marketing itself — with SOC 2 and HIPAA controls documented at trust.pilotpractice.com. Start with the 2026 HIPAA-compliant marketing guide, or book a demo and we'll audit your intake and photo-consent stack live.
PilotPractice security & compliance documentation: trust.pilotpractice.com
See it live on your own practice
EHR-integrated booking, HIPAA-safe tracking, and marketing that reports in kept appointments — in one platform.Book a Demo





