Reviewed: September 30, 2026
A US med spa website can advertise treatments, explain prices and help patients book consultations. But its legal obligations depend on more than its location. The practitioners involved, the services advertised, the information collected and the states where the business operates or targets consumers all matter.
A before-and-after gallery, a Google review widget and an appointment form each raise different questions. Patient permission to publish a photograph does not establish that the image is a truthful advertisement. A privacy policy does not authorize every disclosure to an advertising platform. And compliance with federal law does not override a stricter state professional rule.
This guide covers the main federal requirements and selected state provisions that affect aesthetic clinic and med spa websites. It is general information, not legal advice or a 50-state survey. References identify legislation, regulations, a court decision and official regulatory material; guidance and practical recommendations are distinguished from binding rules.
The quick website check
Before publishing or updating a US clinic website, check:
- Who provides the medical service: the legal entity, treating practitioners, licenses, professional titles and supervision arrangements.
- Where the clinic operates and advertises: professional and privacy rules vary by state, and some privacy laws can apply when a business targets the state's consumers.
- What every claim promises: objective claims about results, duration, safety and comparative superiority need appropriate support before publication.
- How FDA status is described: “approved,” “cleared,” “authorized,” “registered” and “listed” are not interchangeable.
- Whether a use is off-label: a clinician may lawfully prescribe a drug off-label in appropriate circumstances, but the website must not present that use as FDA-approved.
- How patient results are shown: consent, advertising accuracy, comparable photography and expected-results disclosures are separate questions.
- Whether reviews may be republished: FTC rules apply nationally, while some professional rules are stricter; New York's physician rule expressly addresses testimonials.
- What the website sends to vendors: inspect forms, booking tools, chat, pixels, analytics and session replay at data-field level.
- Which privacy regime covers each dataset: HIPAA, state medical-confidentiality laws and consumer privacy laws have different scopes and exemptions.
- Whether patients can use the site: include accessibility in forms, media, navigation and third-party booking journeys.
Start with the practice and its practitioners
Before reviewing the website, identify the legal entity providing medical care, the professionals delivering it and the states in which they practice. A business name such as “med spa” does not answer those questions.
For website planning, verify:
- each practitioner's legal name and professional title;
- the state and status of each relevant license;
- the practitioner's actual role and scope of practice;
- any claimed specialty certification and the full name of the certifying body; and
- how supervision or medical direction is described.
Present these details without using one doctor's credentials to imply that every team member has the same qualifications.
California illustrates why wording matters. Its Medical Board explains that physicians may advertise board certification only through qualifying boards under Business and Professions Code § 651(h)(5). A short training-course certificate is not automatically a qualifying specialty certification.[1]
The statute also requires California Medical Board licensees using “board certified” to give the full certifying board's name comparable prominence. Naming the specialty and board helps patients understand what the credential actually covers.[2]
These provisions concern specified California licensees. Other states and professional boards require their own review. Website wording cannot resolve an unlawful ownership, delegation or scope-of-practice arrangement.
Treatment claims need support before publication
Section 5 of the Federal Trade Commission Act prohibits unfair or deceptive acts or practices within the FTC's jurisdiction. State professional advertising laws operate alongside this federal framework.[3]
The FTC's Health Products Compliance Guidance explains that advertisers must substantiate objective claims before publishing them. It considers the overall impression created by words, images and omissions, including benefits suggested indirectly. For health-related products, safety and efficacy claims generally require competent and reliable scientific evidence. This document explains the FTC's approach; it is guidance, not a separate statute.[4]
For an aesthetic treatment page, review statements such as:
- “permanent fat removal”;
- “clinically proven skin tightening”;
- “painless” or “no downtime”;
- “safe for everyone”; and
- “no risk of complications.”
The evidence must be relevant to the actual product or device, treatment protocol, patient group and outcome claimed.
Keep an evidence record for each significant outcome claim. Record:
- what product, device or protocol was studied;
- the study population and number of participants;
- the treatment schedule and any combined interventions;
- the outcome measured; and
- the follow-up period.
A supplier's marketing brochure or a study on a different device should not become an unsupported promise about the clinic's service.
Explain likely benefits, limitations, suitability and important risks in language patients can understand. Avoid relying on a small footer disclaimer to qualify a much stronger promise at the top of the page.
Botox advertising: separate the service from the drug-promotion rules
US law provides a framework for consumer prescription-drug advertising; it does not impose a general federal prohibition on naming a prescription medicine in public advertising. The governing provisions include 21 U.S.C. § 352(n) and 21 CFR § 202.1.[5,6]
However, a pharmaceutical manufacturer's product advertisement and an independent clinic's description of its treatment services should not automatically be treated as legally identical. Section 202.1 expressly addresses advertisements issued or caused to be issued by a drug's manufacturer, packer or distributor. Whether a particular clinic communication falls within that framework requires assessment of the facts.[6]
Where applicable, the regulation addresses misleading claims, the presentation of benefits and risks, and required drug information. Its specific television and radio provisions should not be casually presented as a universal checklist for every clinic webpage.[6]
For clinic content:
- use the correct product name;
- describe the service and treating professional accurately;
- verify any FDA-approval statement against the product's current labeling;
- distinguish an approved indication from an off-label use; and
- check the relevant state professional advertising rules.
Off-label use is another distinction. FDA explains that healthcare professionals generally may prescribe an approved drug for an unapproved use when medically appropriate. That does not mean FDA has established safety and effectiveness for that use.[7] If a clinic describes an off-label treatment, it should avoid implying that the particular use is FDA-approved.
“FDA-approved,” “FDA-cleared” and “FDA-registered” mean different things
FDA explains that establishment registration and device listing do not establish a device's approval, clearance or authorization. A registration certificate is not an FDA endorsement.[8]
Check:
- the exact device and model;
- the manufacturer named in the FDA record;
- whether the record is an approval, clearance, authorization, registration or listing;
- the stated indication or intended use; and
- whether the website claim stays within that scope.
A clearance for one purpose should not become a claim that every service performed with the device has FDA clearance.
FDA's 510(k) training material specifically cautions that 510(k) clearance should not be described as FDA approval.[9] Approval or clearance of a product also does not amount to FDA approval of the clinic or its practitioners.
This matters on laser, radiofrequency and body-contouring pages, where a regulatory badge can otherwise imply more than the underlying record supports.
Compounded GLP-1 pages require particular care
For clinics offering medical weight management, 21 U.S.C. § 352(bb) provides that a compounded drug is misbranded if its advertising or promotion is false or misleading.[5]
In a February 20, 2026 warning letter to Better Health Labs, doing business as Measured, FDA challenged website claims about compounded semaglutide and tirzepatide. The agency said the presentation implied FDA approval or evaluation for safety and effectiveness, and also challenged representations suggesting the business was the compounder.[10]
A warning letter states the agency's findings and position; it is not a final court judgment. Nevertheless, it shows how FDA applies the statutory rule to website content.
FDA confirms that compounded drugs are not FDA-approved.[11] A clinic should identify the product accurately and avoid presenting a compounded preparation as an approved branded medicine or implying that the branded medicine's approval extends to it. Website claims and the legal conditions for supplying a compounded drug are separate issues requiring review.
Before-and-after photographs have two separate compliance questions
First, is publication permitted under patient privacy and other applicable law? Second, does the presentation comply with advertising rules? Both need an answer.
California's § 651(b)(3) is unusually specific. For covered healing-arts licensees, results images must identify the procedures performed prominently and legibly. Before-and-after views must be comparable, without favorable poses, lighting or presentation distorting the result, and include a statement that the same results may not occur for all patients. Images must accurately depict results; the provision also addresses altered images. Images of models require prominent identification as models.[2]
At federal level, the FTC's Endorsement Guides explain that a consumer's reported outcome can imply what others will generally achieve. Where that implication is unsupported, the guides call for a clear disclosure of generally expected performance, supported by evidence. A generic “results not typical” disclaimer may be insufficient.[12]
For each results image or pair, document:
- the procedure or procedures performed;
- the date or interval between treatment and the “after” image;
- any combined treatments;
- whether the person is an actual patient or a model;
- the patient's publication authorization where required; and
- the original, unedited image files.
Review the gallery's overall impression, including captions and nearby headlines. A disclaimer does not automatically cure a misleading presentation.
Patient authorization is more than treatment consent
For a HIPAA-covered clinic, public promotional use of identifiable patient information generally requires a valid authorization under 45 CFR § 164.508. Ordinary consent to treatment is not that authorization.[13]
The regulation requires a valid authorization to include, among other elements:
- a specific description of the information to be used or disclosed;
- who may make the disclosure and who may receive it;
- the purpose of the use or disclosure;
- an expiration date or expiration event;
- the individual's signature and date;
- required statements about revocation and possible redisclosure; and
- plain language and a copy for the individual.[13]
A clinic generally cannot condition treatment on signing a promotional authorization.[13]
For website planning, make the intended publication channels clear. A permission limited to one use should not silently become approval for a website gallery, paid ads and social posts.
Testimonials: check the state rule before adding a review widget
There is no single permission to publish patient testimonials across all US medical practices.
New York is a significant example. Education Law § 6530(27)(a)(iii), within the physician professional-misconduct framework, expressly identifies advertising that uses testimonials as advertising not in the public interest. Adjacent subparagraphs of § 6530(27)(a) address undue pressure, guarantees and unsubstantiated claims.[14]
This provision should not be generalized to every profession or every independent third-party review. But a physician practice should not assume it can select patient reviews and republish them as website advertising simply because the reviews already appear on Google. Embedding a review widget also warrants review under the applicable professional rule.
At federal level, the binding FTC Consumer Reviews and Testimonials Rule, 16 CFR Part 465, prohibits specified conduct involving:
- fake or false consumer reviews, consumer testimonials and celebrity testimonials;
- compensation or incentives conditioned on a positive or negative sentiment;
- certain undisclosed reviews and testimonials from company insiders;
- company-controlled review websites or entities falsely presented as providing independent reviews or opinions;
- unfounded threats or intimidation used to suppress reviews;
- misrepresenting a selectively displayed set as all or most submitted reviews; and
- fake indicators of social-media influence.[15]
For example, offering a benefit in return for a five-star review raises a different issue from inviting honest feedback without requiring a positive opinion. The FTC explains that sentiment-neutral incentives are not prohibited by § 465.4 itself, although undisclosed incentives can still violate the FTC Act.[16]
Paid or gifted influencer endorsements also require attention to material connections under the FTC's endorsement guidance.[17] Disclosure does not resolve a state prohibition on the testimonial itself.
Responding to a review can disclose patient information
A patient's public review is not blanket permission for the clinic to disclose additional information about their care.
HHS's New Vision Dental settlement concerned disclosures of protected health information in responses to online reviews. The practice paid $23,000 and agreed to a corrective action plan.[18]
Our practical recommendation is to keep public replies general and move care-related discussion into an appropriate private channel. Staff should avoid confirming treatment details, diagnoses, appointment history or other information from the clinical record while defending the business online.
Prices and special offers need a state-specific check
California § 651(c) requires price advertising to be exact and prohibits phrases such as “as low as” and “and up.” Separately, § 651(b)(4) treats a statement or claim relating to fees—other than a standard consultation fee or a range of fees for specific types of services—as false, fraudulent, misleading or deceptive if it does not fully and specifically disclose all variables and other material factors.[2]
Florida Statutes § 456.062 requires specified health practitioners advertising free or discounted services, examinations or treatments to include a prescribed, clearly distinguishable capitalized statement. It concerns the patient's right to refuse payment, cancel payment or obtain reimbursement for certain other services performed as a result of, and within 72 hours of responding to, the advertisement.[19]
The statute contains a limited classified-directory exception. A brief “terms apply” link should not be assumed to replace its prescribed statement.
Before publishing an offer, identify:
- the exact service included;
- the practitioner or professional category providing it;
- what the price covers;
- foreseeable additional charges;
- eligibility and exclusions;
- the offer period; and
- any state-prescribed disclosure.
Review consultation offers, injectable promotions and treatment packages before putting them into reusable website banners. A national campaign may require state-specific versions.
HIPAA does not automatically apply to every med spa
The definition of a covered healthcare provider turns on transmitting health information electronically in connection with a transaction covered by the HIPAA regulations. Being a healthcare business, having a website or accepting electronic payments does not by itself answer that test.[20,21]
A cash-pay practice should assess its actual activities rather than assume either that HIPAA applies to everything or that it is automatically exempt. Where HIPAA applies, identifiable information about healthcare enquiries can require protection even before a person becomes an established patient.[20]
HIPAA status also affects vendors. A vendor handling protected health information on a covered clinic's behalf may be a business associate. The legal definitions and organizational requirements determine that relationship.[20,22]
If HIPAA does not apply, state confidentiality and consumer privacy requirements may still apply. The website's own privacy promises also need to be accurate.
A website privacy policy and a HIPAA notice serve different purposes
Under 45 CFR § 164.520(c)(3)(i), a covered entity maintaining a website that provides information about its customer services or benefits must prominently post its Notice of Privacy Practices and make it available electronically.[23]
A website privacy policy describes online data practices. A HIPAA Notice of Privacy Practices explains the covered entity's uses and disclosures of protected health information and individuals' rights. One generic document should not be assumed to satisfy both sets of obligations.
Forms, booking tools, chat and AI assistants
A contact box can receive medication lists, symptoms or patient photographs even when the clinic intended it only for booking questions.
For HIPAA-regulated information, 45 CFR § 164.306 requires protection of the confidentiality, integrity and availability of electronic protected health information, alongside the applicable administrative, physical and technical safeguards.[24]
Where a supplier performs services involving protected health information on the clinic's behalf, assess business-associate obligations and the required contract under § 164.504. A business associate agreement does not authorize uses that would otherwise violate the Privacy Rule.[22]
HHS's current business-associate guidance specifically includes an example of a third-party AI chatbot on a patient portal providing services involving patient information, such as symptom assessment or appointment scheduling.[25] A public assistant restricted to general information needs its own factual assessment; the word “AI” alone does not determine HIPAA status.
For every form, booking tool, chat or AI assistant, map:
- the fields collected and information a patient can enter or upload;
- where submissions and transcripts are stored;
- who receives notification emails or has dashboard access;
- which suppliers and subcontractors receive the data;
- the retention and deletion settings;
- whether data is reused for analytics, advertising or model training; and
- which contract and legal permission support each disclosure.
Keep general enquiries focused and provide an appropriately reviewed route for clinical information. A warning asking visitors not to enter medical details does not replace this assessment.
Pixels and analytics: understand what the court actually decided
In American Hospital Association v. Becerra, the Northern District of Texas vacated part of HHS's tracking guidance on June 20, 2024. The challenged position linked an individual's IP address with a visit to an unauthenticated public webpage about health conditions or healthcare providers. The order expressly preserved the legal operability of the guidance's other parts.[26]
It would therefore be inaccurate to describe every identifiable public-page visit as automatically protected health information on that basis. It would also be inaccurate to say the ruling authorized all healthcare website tracking.
HHS's bulletin distinguishes general public pages from situations where a tracker receives protected information through portals, appointment scheduling or information entered by a visitor. It also explains that a cookie-banner acceptance is not a HIPAA authorization, and that a business associate agreement alone does not make an otherwise impermissible disclosure lawful.[27]
Inspect the actual data sent by pixels, analytics and session-replay tools, including:
- page URLs and treatment names;
- IP addresses and device identifiers;
- button clicks and treatment selections;
- form fields and free-text entries;
- appointment details and confirmation pages; and
- information used to build or retarget advertising audiences.
Remove or reconfigure tools where a lawful disclosure cannot be established, and check state privacy law independently of HIPAA.
State privacy laws can reach data outside HIPAA
Washington: consumer health data
Washington's My Health My Data Act, chapter 19.373 RCW, covers specified businesses operating in Washington or targeting Washington consumers. Its definitions reach reasonably linkable information identifying health status, including certain information about seeking healthcare.[28]
For covered, nonexempt data, the Act requires:
- a consumer health data privacy policy linked prominently from the homepage;
- consent to collection unless collection is necessary to provide a product or service the consumer requested;
- separate consent to sharing unless sharing is necessary to provide that requested product or service;
- mechanisms for the Act's consumer rights;
- appropriate processor arrangements; and
- a valid authorization for a sale of consumer health data.[28]
Small businesses are covered rather than automatically excluded. The exemptions include defined categories of protected information; being a HIPAA-covered organization does not establish that every website dataset is exempt.[28]
California: website disclosures and consumer privacy
California's Online Privacy Protection Act, Business and Professions Code § 22575, requires operators within its scope to post a privacy policy conspicuously when collecting personally identifiable information online about California consumers. Required disclosures include information categories, categories of recipients, the policy's effective date and specified tracking practices.[29]
The CCPA adds obligations for businesses meeting its applicability criteria. Its medical-information exemptions are qualified; Civil Code § 1798.145(c) should not be read as a blanket exemption for every dataset a healthcare business collects.[30]
The California Attorney General has published an enforcement example involving a telehealth business whose separate public-facing website was subject to the CCPA.[31] For covered activities, review:
- the notice at collection;
- the privacy policy and required rights disclosures;
- methods for access, correction and deletion requests;
- sale or sharing opt-outs;
- sensitive-personal-information rules; and
- applicable Global Privacy Control requirements.[32]
A US website should therefore assess the particular data and applicable laws before choosing consent or opt-out controls. A standard cookie banner is not a complete privacy assessment.
Follow-up email and texts have their own rules
CAN-SPAM, including 15 U.S.C. § 7704, governs commercial email. Requirements include accurate sender information, nondeceptive subject lines, applicable advertising identification, a valid postal address and an effective opt-out. Requests generally must be honored within ten business days.[33]
Appointment messages and promotional campaigns should be assessed separately. The FTC explains that the primary purpose of a mixed message matters; adding substantial promotional content can change its classification.[34]
For calls and texts, 47 CFR § 64.1200 includes consent and do-not-call requirements. Certain automated or artificial/prerecorded telemarketing communications require prior express written consent, subject to the rule's scope and exceptions.[35]
For promotional messages:
- distinguish appointment or care communications from advertising;
- make the requested marketing permission clear;
- record how and when consent was obtained;
- review the sending technology and recipient list;
- provide and honor the required opt-out; and
- check the relevant state rules.
Providing a phone number to request a consultation should not be treated as universal permission for future marketing. HIPAA's restrictions on using protected information for marketing require a separate assessment.[36]
Accessibility belongs in the website review
ADA Title III prohibits disability discrimination by covered public accommodations. The Department of Justice identifies medical offices among covered businesses and takes the position that their online services must be accessible.[37,38]
The DOJ's website guidance points to WCAG as a useful technical reference. Its specific Title II web rule for state and local governments should not be presented as the rule governing every private med spa.[38]
Test:
- keyboard navigation and visible focus;
- headings, link purpose and form labels;
- instructions and error messages;
- text contrast and text resizing;
- alternatives for meaningful images;
- captions and transcripts for media; and
- the complete booking journey, including third-party tools.
Providers subject to additional federal funding or healthcare nondiscrimination requirements need a separate review of those obligations.
How iGlowly approaches a US clinic website
We connect treatment information, practitioner profiles and booking routes so patients can understand the services and find the right next step. During content and website planning, we flag outcome claims, results imagery, testimonials, credentials, offers and data-collection tools for review.
The clinic and its practitioners verify clinical details and approve content. State-specific legal questions, patient authorizations and vendor data arrangements need assessment for the actual practice. A website template cannot establish compliance for every US clinic.
Explore iGlowly's aesthetic clinic website design and management service, or compare our guides to UK website rules, Belgium' and France's website rules.