Verity MedSpa Compliance

Compliance & risk for medical spas

Patient care and patient data are the same problem.

Built and maintained by a clinician and a security practitioner working the same file. Not a portal. Not a template pack. The work, done.

The problem is split in two, and nobody owns the middle.

Compliance for this sector comes from two industries that do not speak to each other.

One side

Trade associations, law firms and aesthetics consultants cover scope of practice, delegation, protocols and consent.

The other

IT providers and compliance software cover HIPAA, risk analysis and vendor agreements.

Everything below sits on the seam

Three regulators, one iPhone

Before-and-after photos on a personal phone: a consent question, a marketing-substantiation question, and protected health information in a consumer cloud account. No owner.

The booking page that took a deposit

That quietly made you a card-accepting merchant, with payment-page and scanning obligations nobody mentioned when the page went up.

The pixel on your treatment pages

Federal guidance on tracking technologies was partly vacated in June 2024, and the FTC's amended Health Breach Notification Rule took effect the same year. The rules moved. Most treatment pages did not.

AHA v. Becerra, N.D. Tex., Jun 2024 · 16 CFR Part 318

87of 223 inspected

A state regulator inspected 223 med spas. It cited 87 of them.

New York's Department of State, working with the Department of Health and the State Education Department, announced the results of a statewide sweep on 8 January 2026 — a 39% citation rate, for issues including the unlawful practice of medicine. Inspectors found expired and suspected counterfeit products, controlled substances, used needles, and unlicensed individuals performing medical services.

Massachusetts is not New York. But the enforcement question it answers — could this practice show what it is allowed to do, and who is allowed to do it? — is the same one in every state.

Source: NY Department of State, 8 Jan 2026 · claim verified 10 Sep 2026

What we do

Four verbs, in order.

Assess

A two-perspective baseline across state practice rules, HIPAA, OSHA, FDA sourcing, PCI and FTC advertising and breach rules. Findings rated by severity and by effort to fix.

Build

Policies and procedures fitted to your state, service mix and technology. Written protocols, risk analysis, vendor register with executed agreements, training with competency records.

Implement

We write the specification and hold your IT provider, marketing agency and medical director to it. We do not hand you a portal and wish you luck.

Maintain

Named compliance and security officer of record. Chart and exam audits. Regulatory change alerts for your states. Annual refresh, mock inspection and carrier support.

Most practices start with the HIPAA gap analysis →

What we will not do

In a sector where nearly every vendor overclaims, our limits are the most useful thing we can publish.

  • We are not a law firm and we do not give legal advice.
  • We do not serve as your medical director, and we never take a fee for introducing one.
  • We do not become your IT provider — doing both would destroy the independence of the risk analysis we sign.
  • We take no commission on software, insurance or products.
  • We do not certify compliance, because no consultant can. What we provide is a documented program and the evidence that it was maintained, which is what regulators and carriers actually evaluate.

Start with the gaps.

A fixed-fee HIPAA gap analysis tells you which policies, procedures and records you should have, which you do not, and what it costs to fix them. Two to four weeks, four to six hours of your team's time.

Sources on this page. We cite everything we tell you, with the date we last checked it. If a claim here is out of date, it is a mistake — tell us and we will fix it.

New York Department of State, statewide med spa inspection sweep, 8 January 2026 — verified 10 Sep 2026 American Hospital Association v. Becerra, N.D. Tex., June 2024 (online tracking guidance partly vacated) — verified 10 Sep 2026 FTC Health Breach Notification Rule, 16 CFR Part 318, amended 2024 — verified 10 Sep 2026