Most answers to this question online say "yes, they offer a BAA" and leave it there. That's technically accurate and practically incomplete. Mindbody does offer a Business Associate Agreement. But the BAA covers Mindbody's data handling — not how your practice actually uses the platform. The gap between those two things is where medspa owners tend to have real risk. For the bigger picture on medspas and Grove, start here.
Mindbody offers a BAA, which is a legal requirement for HIPAA-covered entities using third-party software. But a BAA doesn't make your workflow HIPAA compliant — it only covers the vendor's handling of data you give them. The risk for most medspas is in how treatment information, before/after photos, and patient communications actually flow through the practice day to day.
Mindbody offers a Business Associate Agreement (BAA) to covered entities. This is table stakes for any healthcare-adjacent software vendor — it creates a legal agreement that Mindbody will handle your patient health information (PHI) according to HIPAA standards on their end.
What the BAA specifically covers:
The BAA is real and it matters. It's also only part of the picture.
The BAA covers Mindbody's handling of PHI. It doesn't cover your practice's handling of PHI in workflows that run alongside or outside of Mindbody.
Mindbody has no native HIPAA-compliant charting for medical spas. If your NPs and APRNs are documenting treatments, patient histories, medication records, and consent notes — where are those records actually living? If the answer is a Word document, a Google Form, or a separate app that you set up yourself without a BAA in place, the Mindbody BAA doesn't cover that.
Mindbody has no native photo gallery for clinical use. Most medspas store before/after photos on staff iPhones, share them via text message, and keep them in iCloud or Google Drive. None of those channels are HIPAA-compliant without specific configuration and covered agreements. The photo itself can contain PHI — patient identity, treatment area, date taken — and the transmission channel matters as much as the storage location.
Text messages and emails sent through platforms outside Mindbody need their own HIPAA analysis. If a staff member texts a client from a personal phone about a treatment result, that's PHI traveling through a non-covered channel — regardless of what your Mindbody BAA says.
The highest HIPAA risk in the average medspa is not in Mindbody's servers. It's in the gap between Mindbody's scheduling system and the clinical documentation systems the practice has built around it.
The pattern we see most often: a medspa uses Mindbody for scheduling and a separate platform — Aesthetic Record, Google Workspace, a shared Dropbox — for treatment notes and photos. Each system individually might have appropriate agreements in place. But the data flowing between them doesn't have consistent oversight.
The scenarios that create real exposure:
None of these scenarios are covered by the Mindbody BAA. All of them happen routinely in practices that believe they're compliant because they signed the BAA.
Before/after photos are medical records under HIPAA. They contain PHI: the patient's likeness, the treatment date, the condition being treated, and in some cases the specific treatment administered. The image file itself is PHI — not just the record attached to it.
What common practices actually look like from a compliance standpoint:
What compliant photo management looks like:
Boulevard addresses the before/after photo problem directly — it has a native photo gallery tied to the client record. Photos live in the platform, attached to the appointment and the patient record, accessible to authorized providers without leaving the covered system. NPs and APRNs who reviewed the platform specifically named the photo gallery as the feature that eliminated the iPhone workflow entirely.
On charting: Boulevard includes native HIPAA-compliant charting — treatment notes, consents, patient history, medication records, and provider sign-off — within the platform. For medspas currently running Mindbody alongside a separate charting app, this collapses the two-system gap into one covered system and removes the daily data transfer that creates exposure in between.
A medspa on Boulevard can document a treatment, photograph the result, capture the patient's digital consent, and get MD sign-off — all within one platform under one BAA. The PHI never leaves the covered environment for standard clinical workflows. That's the meaningful difference from Mindbody plus a separate EMR plus a shared photo folder.
This doesn't mean Boulevard is the only compliant option. Aesthetic Record, PatientNow, and Jane App all offer HIPAA-compliant clinical documentation with their own BAAs. The difference with Boulevard is that it handles scheduling and clinical documentation in one platform — which eliminates the data-transfer gap that creates the most common compliance risk. See the full cost and feature comparison or the five-platform alternatives roundup for how these options stack up beyond HIPAA specifically.
These apply whether you stay on Mindbody or switch. The BAA conversation is a starting point, not a destination. If what you're really asking is what happens to five years of patient records once you commit to a switch, that's a separate question from HIPAA — the medspa owner FAQ walks through it directly.
Not just in your software — in how your team communicates about patients day to day. Text messages, personal email, shared folders, phone apps. Map every place a patient's name, photo, or treatment information appears, and check whether each channel has a covered agreement.
Not just your booking platform — your email provider if it carries PHI, your cloud storage platform, your photo management tool, your text messaging service if it's used for clinical communication. The BAA must exist before PHI enters the system, not after.
Either move to a platform with a native, compliant photo gallery (Boulevard, Aesthetic Record), or implement a formal MDM policy for staff devices and a covered storage system. The current workaround — personal iPhones, personal text, personal cloud storage — needs to stop before the next audit, not after.
If you're using Mindbody with a separate clinical documentation platform, confirm that both platforms have BAAs and that the method of data transfer between them is covered. A CSV export dropped into your email is not a covered transfer method, even if both endpoints are covered systems.
The HIPAA question is usually part of a larger evaluation — what platform actually handles the clinical side, what it costs to get there, and whether the switch makes sense for your specific practice. Answer 8 questions and the free assessment below walks through your specific setup in about two minutes. Our medspa FAQ covers the other questions owners ask most before switching.
Grove only gets paid when a business switches through us to Boulevard. If that's not the right platform for your practice — because another platform handles your clinical needs better, or because the timing doesn't make sense — we'll tell you that.
No email required. Results appear on the page in about 30 seconds.
Want to talk it through instead? Start with the assessment and you'll see the option to book a 20-min call after.