Cybersecurity: 24/7/365

The practice operates a high-end practice in Santa Monica, California. They offer Botox, dermal fillers, laser skin resurfacing, body contouring, IV therapy, and medical-grade skincare. The owner — a licensed nurse practitioner and certified aesthetician — built the business from scratch over six years. She focused on clinical excellence and patient experience. Everything else, she figured out as she went.
That approach worked for growth. It did not work for compliance, security, or operations.
When a competing med spa two blocks away received a $175,000 HIPAA fine after a patient complaint, The owner got the wake-up call she'd been ignoring. The complaint was simple — a patient found their before-and-after photos on the spa's social media without written consent. The investigation uncovered a cascade of violations: no risk assessment, no policies, no training records, no Business Associate Agreements. The fine was for the systemic failures, not just the photos.
The owner took an honest look at the practice and realized the same thing could happen to her. There was no written security risk assessment — the single most common deficiency in OCR enforcement actions. There were no signed BAAs with any of their 9 vendors who handle patient data. No documented HIPAA training for the 16 employees. No breach response plan. No policies governing data access, device management, or social media use.
Patient intake forms collected health history, medications, allergies, and skin conditions on paper clipboards in the waiting room — visible to other patients sitting nearby. After treatment, clinicians recorded notes in the practice management system, but the before-and-after photos lived somewhere else entirely.
Before-and-after photography is core to a medical spa's business. It drives consultations, builds social proof, and documents clinical outcomes. The practice took thousands of patient photos per year. The problem was how they stored and shared them.
All photos lived on a shared Dropbox account. Every employee with the link could access every patient's images — including front desk staff who had no clinical reason to see them. Photos were organized by date, not by patient, making it impossible to pull a specific patient's complete image history without scrolling through hundreds of files.
Staff regularly downloaded photos to personal phones for social media posts. Three employees had patient images on their personal iCloud and Google Photos accounts — backed up automatically, synced across personal devices, and completely outside the practice's control. If any of those personal accounts were compromised, patient photos would be exposed.
Two aestheticians used personal cell phones to text appointment reminders that included procedure details. "Hi Sarah — reminder about your Botox appointment tomorrow at 2 PM, we'll also do the lip filler consult." Texts like that are PHI transmitted on an unencrypted, unmanaged channel. Every one is a HIPAA violation.
The practice operated on a single consumer Wi-Fi network. Patient credit card transactions, the practice management system, the Dropbox sync, guest Wi-Fi in the waiting room, and staff personal devices all shared the same network. There was no segmentation, no firewall beyond the router's default settings, and no monitoring of any kind.
Workstations had no endpoint protection beyond Windows Defender. Three machines ran Windows 10 that hadn't received a security patch in seven months. The practice management system stored patient records, treatment histories, health questionnaires, consent forms, and billing data. If an attacker gained access to any device on the network, they could reach everything.
Nobody at the practice thought of themselves as a target. "We're a med spa, not a hospital" was the common assumption. But med spas store the same categories of protected health information as any other healthcare provider — and OCR enforces the same rules regardless of practice type or size.
The practice received 60 to 80 phone calls per day. Prospective patients called about pricing, procedure details, downtime expectations, package options, and consultation availability. Existing patients called about appointments, post-treatment questions, product refills, and follow-ups. Two front desk employees managed the phones while greeting walk-ins, processing payments, and handling scheduling.
Calls stacked up. Hold times stretched past two minutes during peak hours. Voicemails accumulated — 15 to 20 per day — and callbacks often happened 24 to 48 hours later. For a business that sells elective procedures to high-end clients, slow response is a deal-killer. Prospective patients who can't get through don't leave a voicemail. They call the next med spa on their list.
After 6 PM and on weekends, every call went to voicemail. The owner knew this was a problem because 40% of her consultation bookings came from people who first researched treatments in the evening — browsing Instagram, reading reviews, then picking up the phone. Those calls went unanswered until Monday morning, if the patient bothered to call back at all.
We started with a comprehensive assessment that covered compliance, security, IT infrastructure, and front desk operations. Over four days, our team audited every device, every network path, every vendor relationship, every data workflow, and every piece of compliance documentation — or in the practice's case, the absence of it.
The assessment report identified 23 critical vulnerabilities, zero HIPAA-compliant documentation, patient photo storage that violated multiple HIPAA provisions, and a front desk losing consultations every day. We designed a 90-day remediation plan that addressed all four areas simultaneously.
We deployed an AI-powered phone receptionist designed for the med spa's unique call patterns. Unlike a dental practice or urgent care, a med spa's phone traffic is heavily sales-oriented — prospective patients comparing providers, asking about pricing, and deciding whether to book a consultation.
The full deployment — HIPAA compliance, cybersecurity, managed IT, and AI receptionist — was completed in 90 days. Every piece was adapted for the specific needs of a medical aesthetics practice. Plans and monthly rates are posted on our pricing page.
Med spas sit in an awkward place — clinical enough to hold protected health information, retail enough that compliance often gets treated as optional. The engagement closes that gap: a real risk assessment, written policies, signed BAAs, documented training, and a defensible answer for the clinical photography that template compliance kits ignore entirely.
Photo handling is the piece most practices get wrong, and it is the piece most likely to appear in a complaint.
Before-and-after photography moves off staff phones and into an encrypted, access-controlled system with audit logging. Email filtering, endpoint protection and MFA close the routes that actually get used against small practices.
Unplanned downtime stops being part of the week, and IT cost becomes a flat monthly figure instead of an unpredictable range that depends on what broke. The owner can plan against it.
A large share of consultation enquiries arrive after 6 PM and at weekends — exactly when the phone used to go to voicemail. The AI receptionist answers, qualifies, and books, so enquiries convert instead of evaporating into a callback queue that reaches them a day later.
Running a medical spa with patient photos on personal devices and calls going to voicemail? Book a free consultation and we'll assess your compliance, security, IT, and front office operations.
“I built this practice on patient experience. But I was losing patients before they walked through the door — to hold times, voicemail, and unanswered weekend calls. Now every person who picks up the phone gets an immediate, helpful response.”
Owner, Nurse Practitioner — medical spa, Santa Monica, CA
Yes — if you provide any medical service, prescribe medications, or bill insurance, you're a covered entity under HIPAA. Medical spas that perform procedures like Botox, laser treatments, or IV therapy all handle protected health information. Before-and-after photos are PHI. Treatment notes are PHI. The fines for non-compliance apply equally regardless of practice size. OCR has fined med spas specifically for photo storage and social media violations.
We migrate photos from consumer platforms like Dropbox or Google Drive to a HIPAA-compliant, encrypted storage system with role-based access controls. Only authorized clinicians can view their own patients' images. Every access is logged for audit purposes. We also help establish photography consent workflows and social media policies so your marketing team can use patient photos legally and safely.
Med spa inquiries are actually an ideal fit because most calls follow predictable patterns — pricing, procedure details, downtime expectations, package options, and booking. The AI provides helpful, accurate information that moves callers toward booking a consultation. For complex clinical questions, it routes to the right provider with full context. Practices that deploy it typically see consultation bookings increase because every call gets answered instantly — no hold times, no voicemail, no lost leads.
Audits can be triggered by patient complaints to HHS (including complaints about photo use), random selection by the Office for Civil Rights, state licensing board reviews, or as a follow-up to a reported breach. You can't predict when one will happen. The practices that survive audits are the ones with documentation ready before the notice arrives — not the ones who scramble to create it after.