HIPAA Compliance Guide

Is Mindbody HIPAA Compliant for Medical Spas?

Most answers to this question online say "yes, they offer a BAA" and leave it there. That's technically accurate and practically incomplete. Mindbody does offer a Business Associate Agreement. But the BAA covers Mindbody's data handling — not how your practice actually uses the platform. The gap between those two things is where medspa owners tend to have real risk. For the bigger picture on medspas and Grove, start here.

The short answer

What Mindbody actually offers

Quick answer

Mindbody offers a BAA, which is a legal requirement for HIPAA-covered entities using third-party software. But a BAA doesn't make your workflow HIPAA compliant — it only covers the vendor's handling of data you give them. The risk for most medspas is in how treatment information, before/after photos, and patient communications actually flow through the practice day to day.

Mindbody offers a Business Associate Agreement (BAA) to covered entities. This is table stakes for any healthcare-adjacent software vendor — it creates a legal agreement that Mindbody will handle your patient health information (PHI) according to HIPAA standards on their end.

What the BAA specifically covers:

  • Mindbody's servers and data storage — they're HIPAA-compliant in how they store what you give them
  • Transmission of data within their platform — encrypted in transit and at rest
  • Their employees' access to your data — covered by the BAA's handling requirements
  • Breach notification obligations — if their system has a breach, they're required to notify you

The BAA is real and it matters. It's also only part of the picture.

The gap

What the BAA doesn't cover

The BAA covers Mindbody's handling of PHI. It doesn't cover your practice's handling of PHI in workflows that run alongside or outside of Mindbody.

Treatment notes and charting

Mindbody has no native HIPAA-compliant charting for medical spas. If your NPs and APRNs are documenting treatments, patient histories, medication records, and consent notes — where are those records actually living? If the answer is a Word document, a Google Form, or a separate app that you set up yourself without a BAA in place, the Mindbody BAA doesn't cover that.

Before/after photos

Mindbody has no native photo gallery for clinical use. Most medspas store before/after photos on staff iPhones, share them via text message, and keep them in iCloud or Google Drive. None of those channels are HIPAA-compliant without specific configuration and covered agreements. The photo itself can contain PHI — patient identity, treatment area, date taken — and the transmission channel matters as much as the storage location.

Patient communications

Text messages and emails sent through platforms outside Mindbody need their own HIPAA analysis. If a staff member texts a client from a personal phone about a treatment result, that's PHI traveling through a non-covered channel — regardless of what your Mindbody BAA says.

Where to look

Where the real risk actually lives

The highest HIPAA risk in the average medspa is not in Mindbody's servers. It's in the gap between Mindbody's scheduling system and the clinical documentation systems the practice has built around it.

The pattern we see most often: a medspa uses Mindbody for scheduling and a separate platform — Aesthetic Record, Google Workspace, a shared Dropbox — for treatment notes and photos. Each system individually might have appropriate agreements in place. But the data flowing between them doesn't have consistent oversight.

The scenarios that create real exposure:

  • A staff member texts a before/after photo to the medspa owner for approval. The photo has the patient's name in the filename. That's PHI in a non-covered channel.
  • An NP emails herself treatment notes to work on from home. PHI in a personal email account, outside any covered agreement.
  • A medspa exports client data from Mindbody for analysis in Google Sheets. PHI in a consumer platform that doesn't have a HIPAA BAA by default.
  • A front-desk staff member texts a client to confirm an appointment and mentions the treatment in the message. PHI traveling through a personal device.

None of these scenarios are covered by the Mindbody BAA. All of them happen routinely in practices that believe they're compliant because they signed the BAA.

The specific problem

Before/after photos under HIPAA

Before/after photos are medical records under HIPAA. They contain PHI: the patient's likeness, the treatment date, the condition being treated, and in some cases the specific treatment administered. The image file itself is PHI — not just the record attached to it.

What common practices actually look like from a compliance standpoint:

  • Storing before/after photos on personal staff iPhones — not compliant without a managed device policy and Mobile Device Management (MDM) software covering those specific devices
  • Sharing photos via personal text message — not compliant regardless of how they're stored afterward
  • Storing photos in personal iCloud or Google Drive accounts without a BAA — not compliant
  • A shared Dropbox folder without a formal BAA with Dropbox — not compliant

What compliant photo management looks like:

  • A healthcare-specific photo storage system with a BAA in place — the covered agreement matters as much as the security features
  • A platform like Boulevard with a native photo gallery — photos are tied to the client record, stored within the covered system, and never need to travel through external channels for standard clinical workflows
  • An MDM-covered device policy with an enterprise photo management system and the appropriate BAAs on every platform that stores or transmits the images
A different approach

What Boulevard does differently

Boulevard addresses the before/after photo problem directly — it has a native photo gallery tied to the client record. Photos live in the platform, attached to the appointment and the patient record, accessible to authorized providers without leaving the covered system. NPs and APRNs who reviewed the platform specifically named the photo gallery as the feature that eliminated the iPhone workflow entirely.

On charting: Boulevard includes native HIPAA-compliant charting — treatment notes, consents, patient history, medication records, and provider sign-off — within the platform. For medspas currently running Mindbody alongside a separate charting app, this collapses the two-system gap into one covered system and removes the daily data transfer that creates exposure in between.

What this means in practice

A medspa on Boulevard can document a treatment, photograph the result, capture the patient's digital consent, and get MD sign-off — all within one platform under one BAA. The PHI never leaves the covered environment for standard clinical workflows. That's the meaningful difference from Mindbody plus a separate EMR plus a shared photo folder.

This doesn't mean Boulevard is the only compliant option. Aesthetic Record, PatientNow, and Jane App all offer HIPAA-compliant clinical documentation with their own BAAs. The difference with Boulevard is that it handles scheduling and clinical documentation in one platform — which eliminates the data-transfer gap that creates the most common compliance risk. See the full cost and feature comparison or the five-platform alternatives roundup for how these options stack up beyond HIPAA specifically.

What to do

Practical steps, regardless of platform

These apply whether you stay on Mindbody or switch. The BAA conversation is a starting point, not a destination. If what you're really asking is what happens to five years of patient records once you commit to a switch, that's a separate question from HIPAA — the medspa owner FAQ walks through it directly.

1

Audit where PHI actually lives in your practice

Not just in your software — in how your team communicates about patients day to day. Text messages, personal email, shared folders, phone apps. Map every place a patient's name, photo, or treatment information appears, and check whether each channel has a covered agreement.

2

Get a BAA with every vendor that touches PHI

Not just your booking platform — your email provider if it carries PHI, your cloud storage platform, your photo management tool, your text messaging service if it's used for clinical communication. The BAA must exist before PHI enters the system, not after.

3

Establish a before/after photo protocol

Either move to a platform with a native, compliant photo gallery (Boulevard, Aesthetic Record), or implement a formal MDM policy for staff devices and a covered storage system. The current workaround — personal iPhones, personal text, personal cloud storage — needs to stop before the next audit, not after.

4

Close the gap between scheduling and charting

If you're using Mindbody with a separate clinical documentation platform, confirm that both platforms have BAAs and that the method of data transfer between them is covered. A CSV export dropped into your email is not a covered transfer method, even if both endpoints are covered systems.

Grove is not a HIPAA compliance firm. This guide reflects what we observe working with medspa owners evaluating their software — not a formal legal audit. For a compliance review of your specific practice, consult a healthcare attorney or HIPAA compliance specialist. What we can tell you is which platform structures make compliance easier to maintain, and which ones create ongoing gaps.

If you're evaluating platforms for your medspa

The HIPAA question is usually part of a larger evaluation — what platform actually handles the clinical side, what it costs to get there, and whether the switch makes sense for your specific practice. Answer 8 questions and the free assessment below walks through your specific setup in about two minutes. Our medspa FAQ covers the other questions owners ask most before switching.

Grove only gets paid when a business switches through us to Boulevard. If that's not the right platform for your practice — because another platform handles your clinical needs better, or because the timing doesn't make sense — we'll tell you that.

Get my free assessment →

No email required. Results appear on the page in about 30 seconds.

Want to talk it through instead? Start with the assessment and you'll see the option to book a 20-min call after.