How your records are protected.
Every line on this page is a fact you can ask us to demonstrate. None of it is a compliance claim, because there is no certificate to hold.
Last updated 17 September 2026
The five things the rules actually name
The federal Security Rule names five technical safeguards for electronic health records. It is the clearest checklist anyone has published, so here it is, with what this software does for each. Nothing below is a compliance claim. Every line is a fact you can ask us to demonstrate.
| What the rule names | What the software does |
|---|---|
| Access control Unique accounts, automatic logoff | Six roles, and capabilities set per person. Nobody shares a login. Sitting idle signs you out after two hours, on the desk and on the treatment room iPad |
| Audit controls Record and examine activity | Two records, not one. One logs who looked at a client. The other logs who changed something, with the before and the after, and a reason |
| Integrity Protect records from improper alteration | A signed clinical note can never be edited. A correction is a dated, signed addendum. What a client signed is frozen exactly as it was signed, so changing a phone number cannot rewrite the form somebody put their name to |
| Authentication Verify who is who | Named accounts, sessions that expire, and lockout after repeated failed sign-ins. A device has to be approved before it can be used |
| Transmission security Protect information in transit | Every connection is over HTTPS, enforced rather than offered |
The integrity one is worth pausing on. In a lot of systems an administrator can quietly edit a signed note. Here nobody can, including us. That is not a feature we added for a checklist; it is a rule the clinical record was built around from the first day.
What we do beyond the checklist
- Encrypted off-site backups, every day. Encrypted before they leave the server, with the key held separately, so the company storing them holds nothing readable
- Approved devices. A new device has to be allowed in before it can be used, and the list is yours to manage
- The role changes what you can DO, never what you can SEE. Everyone gets the schedule, the client record, the packages and the prices. Charting is the one line, because a front desk is not a provider
- Warnings never block. An off-grid time or a double booking is flagged and still allowed. The person in the room is the one who knows
- A payment method's identity never changes, so a figure in a report two years from now still means what it meant when it was recorded
Which rules apply to a med spa
Less obvious than most owners expect, and worth getting right.
The federal rules may not reach you at all
HIPAA applies to a health care provider who transmits health information electronically in connection with a transaction covered by the federal rules. Those transactions are a fixed list and every one of them runs between a provider and a health plan: a claim, an eligibility check, a prior authorization, a remittance.
Keeping records in a system is not one of them. A client signing an intake form on an iPad is not one of them. An appointment reminder is not one of them. A spa that never sends anything electronically to a health plan may not be a covered entity at all.
Two things catch people out. A transaction someone conducts on your behalf counts, so a billing service checking eligibility counts. And one transaction, ever, is enough.
State law applies either way
This is the part that gets missed. Most states protect medical information regardless of whether anyone bills a health plan, and several protect it more strictly than the federal rules do.
- California reaches providers of health care and the businesses holding medical information for them
- Washington lets a resident bring a claim directly
- Nevada and Connecticut have their own consumer health data laws
- Texas defines a covered entity more broadly than the federal rules
Which one applies depends on where your client is, not where you are. Rather than doing the minimum in each state, we hold to the strictest standard that applies anywhere, for every spa on the system.
We do not claim HIPAA compliance or certification, and we never will. There is no certificate to hold, and no spa was ever made compliant by the software it bought. Compliance is a property of how you run your business. What software can do is not get in your way, and keep the evidence, and this one does both.
Which rules reach your spa is a question for your attorney, not for a vendor's marketing page. The paragraphs above are the test, not advice about your situation.
Who else touches your records
| Who | What for |
|---|---|
| Amazon Web Services | The servers the software runs on, and sending the three messages it sends |
| Cloudflare | The domain, protecting the connection, encrypted off-site backups, forwarding email sent to us, and counting visits to this website |
Nobody else. No advertising network, no data enrichment, no marketing platform. We do not sell your records and we do not use them for advertising.
This website counts page visits with Cloudflare Web Analytics, which sets no cookies and does not follow anyone between sites. Nothing of the kind runs inside the software. What a spa does in MD Spa Mentor is not measured, reported or sent anywhere.
The full picture is on the Privacy Policy.
When something goes wrong
No system is perfect and any company that tells you otherwise is selling something.
If we find a problem
We tell the affected spa promptly and plainly: what we know, what we do not yet know, and what we are doing about it. Not a carefully worded notice three weeks later.
If you find one
Tell us at hello@mdspamentor.com and we will take it seriously. If you are a security researcher, we will not threaten you for reporting something in good faith.
The honest limits
- We are a small company. We do not have a 24-hour security operations center and we are not going to pretend we do
- We do not hold a SOC 2 report or an ISO certificate today
- We do not sign Business Associate Agreements today. If you conduct electronic transactions with a health plan, talk to us before you sign up
Saying that plainly is worth more than a badge. Everything on this page is checkable, and we would rather be held to a short list of true things than a long list of impressive ones.