Limited offerGet 10% OFFon the snapshotEnds in00d00h00m00s
Blog · Spa Owner Playbook

Spa Marketing and the Law: What You Can Legally Text, Post, and Email in 2026

A plain-English rulebook for day spas and med spas: whether HIPAA applies to you, what the FTC review rule bans, how to post before-and-afters, and how to text clients without breaking TCPA.

September 14, 2026 · 16 min read · by Camila Reyna

#Tier 4#Compliance#hipaa#ftc#tcpa#reviews#marketing-compliance#med-spa#day-spa#national
Infographic titled Spa Marketing and the Law 2026, with four cards: HIPAA (most day spas are not covered entities), FTC review rule (fake reviews up to $51,744 per violation), Before and After (written consent plus honest results), and TCPA texting (get consent, honor STOP)

It is a slow Tuesday and you finally have ten minutes. You post a gorgeous lip-filler before-and-after to Instagram, text twelve regulars a “we miss you, 20% off” blast, and reply to a one-star review by telling the world she never even showed up. Three quick wins. Also, potentially, three separate ways to get fined.

Here is the short answer, because you are busy. Most day spas are not HIPAA covered entities and never will be. Most med spas can post results and text clients too, but there are real rules on all of it, and one of them, the FTC’s review rule, now carries penalties of up to $51,744 per violation (Federal Trade Commission). This is the plain-English rulebook: what applies to you, what does not, and the exact wording you can copy into your forms and texts.

None of this is legal advice. It is an operator’s map of where the landmines are so you know which ones to walk your lawyer toward.

Are you even a HIPAA covered entity?

This is the question that causes the most panic and the most wasted money, so let’s settle it first.

HIPAA does not apply to every business that touches a body. Under the rule, a health care provider is a “covered entity” only when it transmits health information electronically in connection with a HIPAA standard transaction, the classic one being an electronic insurance claim (HHS.gov). HHS is explicit that using ordinary technology like email does not, by itself, make you a covered entity. The trigger is the electronic standard transaction, not the fact that you have a computer.

Most are not
Day spas that are HIPAA covered entities
Electronic insurance claims
The real trigger
Usually outside HIPAA
Cash-pay only, no e-claims

A pure day spa doing facials, waxing, massage, nails, and lashes, staffed by cosmetologists and estheticians, is not billing insurance. There is no protected health information and no covered transaction. It is almost never a HIPAA covered entity. You could stop reading the HIPAA section here.

A med spa is where it gets interesting. Add licensed medical providers doing medical procedures (Botox, dermal fillers, medical-protocol lasers, deeper chemical peels) and you now handle intake forms, consult notes, and clinical photos that look and feel like medical records. But you still only become a HIPAA covered entity when you also run a covered transaction, meaning you bill insurance electronically. A great many med spas are cash-pay or card-pay only. On the strict letter of the rule, a cash-only med spa that never files an electronic claim can fall outside covered-entity status.

How the HIPAA question breaks in real life

The failure mode is almost never a federal audit. It is smaller and more embarrassing. A front-desk hire texts a client her post-treatment photos from a personal phone. Someone posts a “healing nicely!” story with the client’s face and a visible chart in the background. Either can breach state privacy law, your medical director’s board obligations, or a client’s trust badly enough to end the relationship, HIPAA or not.

The fix is boring and permanent. Keep clinical intake, photos, and notes inside a secured system with real access controls, not in a group text or a shared inbox. If you want the detail on how a compliant med spa build handles data separation, that is exactly what a HIPAA-ready GoHighLevel build is for.

Decision flow diagram titled Are You a HIPAA Covered Entity: Your Spa leads to the question do you bill insurance electronically, No means generally not a covered entity (most day spas and cash-pay med spas), Yes means likely a covered entity with full HIPAA rules, and either way treat intake forms, photos and consult notes as private

What getting it wrong actually costs

Compliance feels abstract until you see the number attached to it. The FTC’s review rule is the one with teeth for spa owners right now.

The Federal Trade Commission’s Rule on the Use of Consumer Reviews and Testimonials became effective on October 21, 2024 and authorizes civil penalties of up to $51,744 per violation (FTC). “Per violation” is the scary part: a stack of fake five-star reviews is not one problem, it is potentially many.

This is not theoretical. In December 2025 the FTC took its first enforcement step under the rule, sending warning letters about potential violations and cautioning that continued noncompliance could lead to substantial penalties (Morgan Lewis). The grace period is over.

  1. •
    Aug 2024

    Final rule announced

    FTC finalizes the Consumer Reviews and Testimonials Rule.

  2. •
    Oct 21, 2024

    Rule takes effect

    Fake reviews, paid reviews, and review suppression become enforceable violations.

  3. •
    Dec 2025

    First enforcement

    FTC issues warning letters and signals substantial penalties for continued violations.

  4. •
    2026

    Business as usual

    The rule is now a normal part of running a review program. Plan around it.

The FTC review rule: can you still ask happy clients for reviews?

Yes. Asking a satisfied client for an honest review is completely fine, and you should. What the rule bans is manipulating the pool. Here is the line, in plain terms.

The rule prohibits creating or buying fake reviews (including AI-generated ones), buying positive or negative reviews, insiders reviewing your own business without disclosing the relationship, and using unfounded legal threats, physical threats, or intimidation to suppress or scrub honest negative reviews (FTC). It also bans misrepresenting that reviews come from independent, real customers when they do not.

The trap most spas fall into is “review gating,” and it is worth being precise about it. Asking every client for feedback is fine. Routing only the happy ones to Google while quietly steering unhappy ones to a private form so their reviews never go public is the pattern that gets you into deception territory, and it is separately against Google’s own review policies. Ask everyone. Let the reviews land where they land. Then out-work the occasional bad one with a steady stream of honest reviews and genuinely good replies.

That volume matters because reviews are now the deciding factor for local buyers.

024.2548.572.759797Read reviews first85Swayed by positives77Put off by negatives

Percent of US consumers, BrightLocal Local Consumer Review Survey 2026 (source). 97% read reviews before choosing a local business, 85% are more likely to use a business after positive reviews, and 77% are put off by negative ones.

Steal this: a compliant review request

You do not need clever wording. You need honest wording that goes to everyone. Send this by text a few hours after the appointment, once you have consent to text (more on that below).

Hi {first name}, it’s Camila at {spa name}. Thank you for coming in today. If you have 30 seconds, an honest review really helps other clients find us: {review link}. And if anything was less than perfect, reply here and I’ll make it right. Reply STOP to opt out.

Three things make that compliant. It goes to every client, not just the ones you think will rave. It invites honest feedback, not only five stars. And it never offers money or a discount in exchange for a positive review specifically. You can thank a reviewer, you just cannot pay for the sentiment.

Before-and-after photos and the “results not typical” trap

Before-and-afters are your best marketing and your second-biggest compliance risk. Two separate rules apply.

First, consent. Every photo of a client, especially a medical result, needs written permission that specifically covers marketing use: your website, social, and ads. A general intake signature is not enough. Spell out where the image can appear and let the client opt in by channel.

Second, the FTC endorsement rules. If you show a dramatic result that is better than what a typical client gets, you cannot present it as the normal outcome. The FTC’s endorsement guides expect featured results to reflect what people can generally expect, or a clear disclosure of the generally expected result (FTC endorsement guidance). Here is the part most spa owners missed: the 2023 revision of the guides removed the old “results not typical” safe harbor (16 CFR Part 255). A tiny “individual results may vary” line at the bottom no longer cleans up a misleading before-and-after. The fix is to show results that are actually representative, and to describe honestly what was done to get them.

Steal this: a before-and-after caption that holds up

Real client, treated over 3 sessions, photographed at 6 weeks. Unretouched. Results vary by skin type, treatment plan, and aftercare. Shared with written consent.

That one line handles typicality, disclosure, and consent in a sentence a normal person actually reads. Keep the raw consent form on file. If a client withdraws consent later, you need to be able to pull the image fast, so store which asset maps to which client somewhere you can search, not in a folder called “insta pics final FINAL.”

Texting clients without breaking TCPA

Text is the highest-return channel a spa has and the one with the clearest consent rules. The Telephone Consumer Protection Act governs marketing texts. The two rules you cannot skip: get consent before you send marketing messages, and honor opt-outs immediately when someone replies STOP.

There has been genuine confusion here, so let’s be current. The FCC had adopted a stricter “one-to-one consent” rule that was set to reshape how businesses collect texting permission, but it was vacated by a federal appeals court in early 2025 before it took effect, which means the pre-existing consent framework still governs (FCC / TCPA background). Practically, that does not give you a free pass. You still need clear consent to send marketing texts, and STOP still has to work the moment a client sends it.

Put this next to a real, unchecked checkbox on every booking and intake form:

I agree to receive appointment reminders and occasional offers by text from {spa name}. Message and data rates may apply. Message frequency varies. Reply STOP to unsubscribe, HELP for help. Consent is not a condition of any purchase.

And the first text a new contact ever gets should confirm the relationship and the exit:

{Spa name} here. You’re set for text updates and reminders. Reply STOP anytime to opt out.

The failure mode with texting is not usually a lawsuit, it is a slow poisoning of your list. Blast people who never opted in, or ignore a STOP, and your carrier reputation tanks, your delivery rate drops, and your legitimate reminders stop landing. Consent is not just legal hygiene, it is what keeps the channel working. If you want the reminder-and-consent flow built correctly, that is the point of a proper SMS automation setup, and we go deeper on it in the complete 2026 SMS playbook.

Compliant review, text, and reminder flows, built in

Ask every client for honest reviews, capture real texting consent, and route negative feedback the right way, without gluing five tools together. It is all wired into the Beauty & Spa Snapshot.

“Medical grade,” “FDA-approved,” and words that get you a board letter

This one is quiet until a state board or a competitor complains, then it is not quiet at all.

State cosmetology and medical boards, plus the FTC, take a dim view of marketing language that overstates what a treatment or product does. “Medical grade” implies a standard that may not exist for your product. “FDA-approved” is a specific regulatory status that most devices and skincare lines do not have, many are FDA-cleared, which is different, and some are neither. Calling a facial “a treatment for rosacea” can cross from beauty service into a medical claim you are not licensed to make.

You do not have to write boring copy. You have to write true copy.

Steal this: safer phrasing that still sells

Say this, not that

PlanRisky claim Safer, still persuasive recommended
PriceAvoidUse
Feature 1"Medical-grade results""Professional-strength formulas"
Feature 2"FDA-approved device""FDA-cleared device" (only if true)
Feature 3"Cures acne" / "treats rosacea""Helps improve the look of breakouts / redness"
Feature 4"Permanent fat loss""Long-lasting results for many clients"

The rule of thumb: describe the experience and the visible, honest outcome, not a diagnosis or a regulatory badge you cannot back up. When in doubt, your medical director or the device manufacturer’s approved claims list is the source of truth, not your caption inspiration.

The same rules, three different spas

The framework does not change. The exposure does. Here is how the whole picture looks for three real operator profiles.

The solo day spa (1 to 3 chairs, no medical services). You are almost certainly outside HIPAA. Your live risks are the FTC review rule and TCPA texting. Get your review request going to every client, fix your booking form consent line, and you have handled 90% of your exposure in an afternoon. Before-and-afters of nails, lashes, or brows still need photo consent, but there is no medical-claim minefield.

The mid-size cash-pay med spa (injectables and lasers, no insurance billing). You are probably not a federal covered entity, but you handle clinical photos and consult notes, so run the PHI-adjacent playbook anyway. Every rule bites here: review compliance, before-and-after consent and typicality, TCPA consent, and the “medical grade / FDA” language check on every caption. Have your medical director sign off on claims. This profile gains the most from systematizing it.

The multi-location group that bills insurance electronically. Now you likely are a HIPAA covered entity, and everything above sits on top of full HIPAA obligations: business associate agreements with any vendor that touches client data, access controls, breach procedures, the works. At this size, compliance is not a blog post, it is a standing line item with a lawyer and secured infrastructure. The upside is that a custom, HIPAA-ready build can enforce a lot of it automatically instead of relying on staff to remember.

Common objections, answered

“I’ve posted before-and-afters for years and nothing happened.” Enforcement is not the only cost. A client who never consented, then sees her face in your ad, can leave, complain to a board, or post about it. Consent is cheap insurance against a very cheap mistake.

“Isn’t HIPAA only for doctors and hospitals?” Largely, yes, and that is the point. Most day spas are not covered, and even many cash-pay med spas technically are not. The danger is assuming that means client data does not matter. State law and client trust do not care about the federal definition.

“Won’t asking everyone for reviews get me bad ones?” A few, yes. And a steady stream of honest reviews with thoughtful replies beats a suspicious wall of flawless five-stars every time, both with buyers and with the FTC. The gating shortcut is the actual risk, not the occasional three-star.

“Do I really need consent to text clients I already know?” Yes. Knowing someone is not the same as having documented permission to market to them by text. The good news is one fixed booking-form line solves it going forward, and it takes minutes.

“This sounds like a job for enterprise software.” It is not. Every fix here is a form field, a message template, and a consistent habit you can run from your phone. The done-for-you system simply ships the templates and flows already built so you are not authoring consent language at 9pm.

The 20-minute compliance checkup

You do not need a project plan, just one focused block. Fix the consent line on your booking form. Make sure your review request goes to everyone and invites honest feedback. Confirm you have written marketing consent on file for your last three before-and-afters. Search your captions for “medical grade” and “FDA-approved” and fix anything that is not literally true. Confirm STOP actually removes someone from your texts. That is the whole audit. Do it once, build it into your system, and get back to running the business.

Full rooms come from good marketing. Staying open comes from marketing that does not get you fined. You can have both, and it mostly comes down to the wording you use and where you point it.

Is my day spa a HIPAA covered entity?

Almost certainly not. A day spa doing facials, massage, waxing, nails, and lashes does not bill insurance electronically and handles no protected health information, so it does not meet the HIPAA covered-entity trigger, which is transmitting health information electronically in connection with a standard transaction like an insurance claim.

Can I still ask happy clients for Google reviews in 2026?

Yes. Asking any client for an honest review is fine and encouraged. What the FTC review rule bans is fake reviews, paid reviews, and suppressing negative ones. The compliant approach is to ask every client, invite honest feedback, and never pay for positive sentiment specifically.

What is 'review gating' and is it illegal?

Review gating means routing happy clients to public review sites while steering unhappy ones to a private channel so their reviews never post. It moves you into deceptive-practice territory under FTC guidance and separately violates Google's review policies. Ask everyone the same way instead.

Do I need written consent to post a client's before-and-after?

Yes. Use written consent that specifically covers marketing use by channel, not just a general intake signature. Because the FTC removed the old 'results not typical' safe harbor in 2023, a small disclaimer no longer cures a misleading result, so show representative outcomes and describe honestly how they were achieved.

What are the current TCPA rules for texting spa clients?

Get clear consent before sending marketing texts and honor STOP opt-outs immediately. The FCC's stricter one-to-one consent rule was vacated by a federal appeals court in early 2025 before taking effect, so the prior consent framework still governs, but consent and working opt-outs remain mandatory.

Can I say a treatment is 'medical grade' or 'FDA-approved'?

Only if it is literally true, and most are not. Many devices are FDA-cleared rather than approved, which is a different status, and 'medical grade' often implies a standard that does not exist. Use honest phrasing like 'professional-strength' and confirm any regulatory claim against the manufacturer's approved language.

✦Ready to put this into practice?✦

Install the Beauty & Spa Snapshot in 24 hours

Every workflow above — already built, refined across 40+ spa and beauty studios, installed for you for $997 one-time.