Medical Spa Owner FAQ

What Medspa Owners Ask Before They Switch

The questions medspa owners ask are different from what salon owners ask. The concerns are more clinical — patient data, HIPAA exposure, what happens to five years of treatment records. These answers are based on what we see in practice working with medspa owners who are evaluating a switch from Mindbody. For the bigger picture, start with our medspa overview.

Question 1

Is Mindbody HIPAA compliant?

Mindbody offers a Business Associate Agreement (BAA), which is a HIPAA requirement for third-party software vendors that handle patient health information. What the BAA covers is Mindbody's own data handling — their servers, encryption, and breach notification obligations. What it doesn't cover is your practice's workflows around that platform.

The real HIPAA exposure for most medspas isn't in Mindbody's servers. It's in how treatment notes are stored — often in a second system that may or may not have its own BAA in place. It's in how before/after photos travel between staff members — often via personal iPhone, via text message, into iCloud. And it's in how patient data moves between Mindbody and whatever EMR or charting tool is running alongside it.

A BAA with Mindbody means Mindbody handles your data properly on their end. It doesn't mean your practice's overall workflows are compliant.

For a detailed breakdown of what the BAA covers and where the gaps actually are, see the dedicated HIPAA compliance guide.
Question 2

Does Mindbody have native charting for medical spas?

No. Mindbody has no native HIPAA-compliant charting — no treatment notes, no consent forms, no medication records, no before/after photo gallery within the platform. Services are scheduled through Mindbody, but the clinical documentation happens somewhere else entirely.

Most medspas compensate by running a second system alongside Mindbody. Aesthetic Record, Jane App, and PatientNow are the most common. The two-system setup works, but it creates a synchronization problem that shows up every single day: a staff member opens both systems at the start of the morning and makes sure they match. We've heard owners describe this as 45 minutes of reconciliation before the first patient walks in.

Platforms like Boulevard, PatientNow, and Aesthetic Record are designed to close this gap — clinical documentation is native, not an integration into a third party. The difference in daily friction is significant.

Question 3

What EMR systems integrate with Mindbody?

Mindbody has API-based connections with some EMR systems, but none of these integrations are native in the way medspa owners need them to be. The connections primarily sync appointment data — not clinical documentation. Setting them up requires technical configuration, and maintaining them requires ongoing attention when either platform updates.

In practice, what most medspas call a "Mindbody-EMR integration" is a staff member opening both systems at the start of the day and manually confirming that the appointment and patient records match. That's not a technical integration — it's a manual process that lives between two systems, dependent on whoever does it not making a mistake.

The question worth asking: if you had to document exactly how patient data moves between Mindbody and your clinical system today, could you describe it clearly? If the answer involves someone's memory, a morning routine, or a spreadsheet — that's the integration.

Platforms built specifically for aesthetic medicine — Boulevard, Aesthetic Record, PatientNow — are designed so the scheduling and clinical documentation live in the same system, removing the transfer problem rather than trying to automate around it.

Question 4

How do medspa owners handle before/after photos on Mindbody?

Most do it outside the platform entirely, because Mindbody has no native photo gallery for clinical use. The patterns we see most often: photos taken on a personal iPhone, sent to a group text or email thread, then downloaded into a shared Google Drive or Dropbox folder organized by client name. Some practices use a dedicated aesthetic photo app alongside Mindbody as a third system.

Each step in that chain has HIPAA implications that most practice owners haven't mapped. Before/after photos are Protected Health Information — they contain the patient's likeness, the date of the treatment, the condition being addressed, and in many cases the treatment administered. The image file itself is PHI.

  • Personal iPhone storage without a Mobile Device Management policy: not covered
  • Sharing via personal iMessage or SMS: not covered
  • Consumer Google Drive or Dropbox without a BAA with those providers: not covered
  • Group email threads with patient photos: not covered

The reason NPs and APRNs reviewing Boulevard specifically called out the photo gallery in their reviews is that it eliminates this workflow entirely. Photos are taken, stored, and attached to the client record inside the platform, in a HIPAA-covered system, without ever touching a personal device or traveling through an external channel for standard workflows.

Question 5

Can Boulevard replace my EMR?

For most aesthetic medspas: yes. Boulevard's HIPAA-compliant charting covers treatment notes, consent forms, medication records, patient health history, provider sign-off, and before/after photos. For practices currently running Mindbody plus Aesthetic Record, Jane App, or a similar clinical documentation tool, Boulevard's platform consolidates both into one system and eliminates the daily synchronization work.

The exception is real, and worth naming directly: practices with complex medical record needs that go beyond aesthetic documentation. Plastic surgery-adjacent medspas, practices with heavy MD oversight across every treatment type, and practices that need ICD-10 coding integration or insurance billing workflows are in a different category. For those, a purpose-built clinical system — PatientNow, or a full healthcare EMR — is still the right infrastructure for the clinical side. Boulevard handles scheduling and the client experience layer; it's not designed to be Epic.

The practical check: Sit down with your NP or PA and walk through a typical patient visit from a documentation standpoint. What fields do they fill in? Where does that data need to live for a provider review? If the answer is treatment notes, consents, photos, and a provider sign-off — Boulevard covers it. If the answer includes ICD-10 billing codes, e-prescribing, or insurance adjudication — that's outside what Boulevard does.

For the full cost and feature breakdown side by side, see our Mindbody vs Boulevard comparison for medspas, or the five-platform alternatives roundup if you're still weighing options beyond Boulevard.

Question 6

What does Boulevard's HIPAA charting actually include?

The features most relevant to aesthetic practice documentation:

  • Treatment notes — freeform and templated, configurable per treatment type
  • Digital consent forms — signed electronically, stored in the client record, timestamped
  • Before/after photo gallery — attached directly to the appointment and client, not a separate system
  • Patient health history intake forms — collected before the appointment, stored in the record
  • Medication and allergy records — accessible to providers during the appointment
  • Provider sign-off workflow — MD review of NP/APRN notes before finalization
  • SOAP note formatting — available for providers who use that structure

What it doesn't include, and what to be clear-eyed about before committing:

  • ICD-10 or CPT coding
  • Insurance billing or claims management
  • E-prescribing
  • Full EMR-level clinical decision support

Boulevard is designed for aesthetic medicine documentation — the records, photos, consents, and provider workflow that a medspa generates in the course of running appointments. It's not designed for general medical practice management, and it doesn't try to be.

Question 7

How long does a medspa migration from Mindbody to Boulevard take?

Realistically, 4–6 weeks from decision to go-live. Medspa migrations take longer than salon migrations because the clinical configuration layer — charting templates, consent forms, room assignments, provider permissions — adds meaningful setup time on top of the standard scheduling and data work.

Weeks 1–2
Configuration
Boulevard account setup — charting templates, consent forms, service menus, room and resource assignments, staff accounts, and provider permission levels. This is the phase that takes longer for medspas. Get it right before moving on.
Week 3
Data migration
Client records, appointment history, gift card balances, and active packages from the Mindbody export. Boulevard's implementation team handles the import; your job is to validate that the data looks right in the new system before training begins.
Week 4
Staff training
Scheduling workflows for front desk; charting workflows for NPs and APRNs. Run both systems in parallel this week — don't accept new bookings in both simultaneously, but use this window to practice documentation flows in Boulevard while Mindbody is still active.
Week 5
Go-live
Communicate the new booking link to active patients — website, Google Business profile, automated reminders. Cancel Mindbody after the last active appointment in the old system clears. Don't cancel before that appointment clears.
Week 6
Buffer
First full billing cycle on Boulevard. Review for anything that didn't import cleanly, staff documentation questions that surfaced in practice, and charting template adjustments. This week exists so problems discovered in week five don't derail operations.
Practices that compress this into two weeks tend to have rough go-lives — specifically in the charting configuration layer. A front desk that hasn't trained on Boulevard before go-live day will figure it out. A provider who hasn't configured their charting templates before the first clinical appointment is a patient-care problem, not just an operational one.
Question 8

What happens to my patient records during the switch?

There are two separate record sets, and they require two separate processes.

The Mindbody side — appointment history, client contact data, gift card balances, active packages — transfers through the Mindbody data export process. The fee for this export is $499. We'll tell you upfront whether it's avoidable for your specific timing and setup; the actual transfer is handled by the receiving platform's team, not by us.

The clinical records side — treatment notes, charting, consent forms, before/after photos — lives in whatever system you've been using alongside Mindbody. Aesthetic Record, Jane App, PatientNow, or a custom setup. That export is a separate process, from that system, and it's not part of the Mindbody export at all.

What this looks like in practice: most medspas export their clinical records as PDFs and maintain them in a secure, HIPAA-compliant archive. For high-value active patients — anyone with ongoing treatment plans or recent records that providers will need during appointments — some practices re-enter that history into Boulevard's charting system before go-live.

No migration gets every record perfectly into the new system — that's true of every platform switch, not just this one. The goal is to ensure active patients have their current records in the live system and accessible to providers, while historical records are archived in a compliant way. Every practice draws that line at a different point based on how far back their records go and how active those patients are.
Question 9

Does Boulevard support IV therapy and injection scheduling?

Yes. Boulevard's resource scheduling handles room assignment and provider scheduling for IV therapy, injection appointments, and other time-and-room-specific treatments. You configure treatment room capacity, assign specific providers to specific rooms, and set service-specific timing that reflects how long each treatment actually occupies a chair.

What this means in day-to-day scheduling: a 90-minute IV infusion blocks the chair for 90 minutes for that provider. Resource conflicts — two appointments both assigned to the same treatment room — surface in the scheduling view before they become an operational problem. Double-booking a laser suite shows up immediately rather than at the start of the appointment.

The configuration requires attention to set up correctly. Each treatment type needs to be mapped to the resources it uses — room type, equipment, whether a provider needs to be present continuously or just for specific phases. This is part of the setup work in weeks one and two of the migration. Once configured, the schedule reflects how the practice actually operates rather than requiring staff to manually track resource availability alongside the booking system.

Ask your Boulevard implementation contact specifically about medspa resource configuration. IV therapy suites, laser rooms, and injection chairs all have different occupancy models. A good implementation lead will have done this before.
Question 10

What should I ask Boulevard during a demo?

The standard demo shows the scheduling calendar, the client profile, and a few marketing features. It doesn't show the clinical layer unless you specifically ask for it. These are the questions that surface what you actually need to see:

"Can you walk me through charting a botox appointment — from injection notes to provider sign-off?"

This shows you whether the clinical workflow is actually built for aesthetics or whether it's a generic note-taking layer with an aesthetic skin on top. The path from NP's injection notes to MD review sign-off should take under two minutes in a well-configured system.

"How does the photo gallery attach photos to a specific appointment versus just a client record?"

If your providers need to compare before/after photos across specific treatment visits — which most do — the attachment needs to be appointment-specific, not just client-level. A photo attached to the client record only is harder to use in a clinical context.

"Who's my implementation contact, and do they have medspa experience specifically?"

Boulevard's onboarding quality varies by implementation lead. An implementation contact with salon experience and no medspa background will set up the scheduling correctly and miss the clinical configuration entirely. Ask before you're assigned.

"What happens to my data if I leave Boulevard — and is there a fee to export it?"

Good platforms answer this immediately and directly. If the answer is hedged, ask again. For reference: the $499 Mindbody data export fee is a documented reason many practices didn't evaluate alternatives earlier than they should have.

"Can you show me how resource scheduling works for a two-chair IV therapy suite?"

If IV therapy is part of your service menu, see it in the demo — not just described. The configuration should make sense visually. If the demo contact isn't sure how to show it, that's useful information about their medspa implementation experience.

Walk through your clinical setup with us

Medspa evaluations take longer than salon evaluations because the clinical layer adds complexity — what you're charting, where it currently lives, what the HIPAA exposure looks like, what happens to five years of patient records. The free assessment walks through your specific setup in about two minutes.

Grove only gets paid when a business switches through us to Boulevard. If Boulevard isn't the right fit for your clinical needs, we'll tell you that in the assessment — not after you've already started the process.

Get my free assessment →

No email required. Results appear on the page in about 30 seconds.

Want to talk it through instead? Start with the assessment and you'll see the option to book a call after, for $97.