Before-and-after photographs from laser therapy or body sculpting treatments should be treated as sensitive health information, not ordinary marketing content. In the United States, HIPAA may classify identifiable treatment photographs as Protected Health Information (PHI) when a covered healthcare provider or business associate creates, receives, stores, or transmits them. Clinics generally need appropriate written authorization for uses beyond treatment, payment, and healthcare operations, while applicable state, biometric-privacy, consumer-protection, and international privacy laws may impose additional requirements.
The central rule is purpose and identifiability: document images securely for legitimate clinical purposes, obtain specific written authorization before using them for marketing, education, publication, or other external purposes, and do not assume that cropping out the eyes makes a person anonymous.
Why Treatment Photographs Are Regulated
The photograph can reveal health information
A before-and-after image may disclose that a person received laser therapy, body contouring, skin treatment, or another procedure. It can also reveal the treated body area, treatment results, physical characteristics, and the timing of care.
When the image is connected to a client, treatment record, appointment, account, or other identifier, it can become Protected Health Information under HIPAA.
Identifiability is broader than a full face
A full face is not required for an image to be identifiable. Facial structure, tattoos, scars, birthmarks, body shape, distinctive marks, and contextual details may permit recognition.
Removing the eyes or cropping the image may reduce identifiability, but it does not automatically eliminate privacy obligations or legal risk.
HIPAA depends on the organization and use
HIPAA applies primarily to covered entities, such as qualifying healthcare providers, and their business associates. A cosmetic or wellness business is not automatically subject to HIPAA merely because it performs treatments; its legal status and relationships with healthcare providers matter.
Even when HIPAA does not apply, other privacy and consumer-protection laws may still govern the collection, storage, disclosure, and advertising use of the photographs.
Which Permissions Are Needed
Clinical documentation is different from marketing
Photographs maintained as part of a client’s medical or treatment record may be used for treatment, payment, and certain healthcare operations under HIPAA without a separate marketing authorization in every situation. The clinic must still provide required privacy notices, limit access, protect the information, and comply with applicable state law.
A separate authorization is generally needed when the clinic wants to use identifiable images for marketing, including advertisements, websites, social media, brochures, testimonials, or promotional campaigns.
Authorization must describe the intended use
A written authorization should state, in understandable language:
- What images or information may be used
- The specific purpose of the use
- Whether the images may appear in advertising, education, publications, social media, or clinical training
- Who may use or receive the images
- How long the permission remains effective
- How the client may revoke permission
- Any relevant treatment, compensation, or publication conditions
A single broad statement such as “permission to use photographs” may be inadequate when the clinic intends to use the images for several materially different purposes.
Publication and education require care
Professional publications, conference presentations, training materials, and educational websites may expose images to a wider audience than ordinary internal treatment documentation. Written permission should be obtained before using identifiable treatment photographs in these settings.
De-identification may reduce the need for authorization in some contexts, but the clinic must assess whether a reasonable person could still identify the client from the image or surrounding information.
Consent to treatment is not enough
A client’s consent to undergo laser therapy or body sculpting does not automatically authorize photography, storage, publication, or marketing use. Those are separate activities and should be addressed separately in the intake and authorization process.
How Clinics Should Protect the Images
Standardize the clinical process
Consistent photography improves both clinical usefulness and privacy control. Clinics should use consistent camera angles, distance, lighting, positioning, background, and views, such as at least two standardized perspectives when clinically appropriate.
The workflow should also document when the image was taken, what treatment it relates to, and where it belongs in the client’s record.
Encrypt transmission and storage
Client images and associated treatment records should be transmitted through encrypted communication channels and stored in secure systems with access restrictions. Ordinary personal email, consumer messaging applications, unsecured cloud folders, and unencrypted removable drives create avoidable exposure risks.
The storage system should support authentication, access controls, audit logs, backups, and secure deletion where appropriate.
Limit access by role
Only personnel with a legitimate need should be able to view or handle treatment photographs. Reception staff, clinicians, contractors, marketing personnel, and external vendors may require different permissions.
Access should be removed promptly when a worker changes roles or leaves the organization.
Manage vendors as part of the privacy program
Cloud storage providers, photography platforms, electronic health record vendors, marketing agencies, and other service providers may handle the images. If HIPAA applies, the clinic may need a Business Associate Agreement with a qualifying vendor.
Contracts should address confidentiality, security safeguards, breach reporting, permitted uses, retention, deletion, and return of the images.
Regulations Beyond HIPAA
State medical-privacy laws
Many states regulate medical information more broadly than HIPAA or impose additional consent, disclosure, retention, or breach-notification requirements. A clinic must evaluate the laws of every state in which it operates and, in some cases, the state where the client resides.
State rules may apply even when the business is not a HIPAA-covered entity.
Biometric-privacy laws
Some laws regulate biometric identifiers or biometric information, including certain facial geometry or systems used to identify individuals. This is particularly relevant if a clinic uses facial recognition, automated matching, facial measurements, or other identification technology.
The legal treatment of an ordinary photograph varies by jurisdiction, so clinics should not assume that every image is covered or excluded without reviewing the applicable statute.
GDPR and similar international regimes
For clients in the European Economic Area, the United Kingdom, or other jurisdictions with comprehensive privacy laws, treatment photographs may involve health data, personal data, or biometric data. These categories can require a lawful basis, enhanced safeguards, transparency notices, data-minimization practices, retention limits, and potentially explicit consent.
The clinic’s location alone may not determine whether these laws apply; offering services to or monitoring individuals in another jurisdiction can also matter.
Advertising and consumer-protection rules
A clinic’s use of before-and-after images in advertising must not be misleading. Claims about expected results, typical outcomes, permanence, safety, or effectiveness should be accurate and supportable.
A client’s authorization to publish an image does not protect a clinic from liability for deceptive advertising or unsupported treatment claims.
Understanding the Trade-offs
Clinical value versus privacy exposure
Standardized photographs can provide a useful baseline and support objective side-by-side comparison after treatment. However, each additional copy, transfer, user, or publication increases the chance of unauthorized access or identification.
Clinics should collect only the views and information necessary for the stated clinical purpose.
Marketing value versus irreversible disclosure
Before-and-after images can make treatment outcomes easier for prospective clients to understand. Once an image appears online, however, screenshots, downloads, reposts, search indexing, and third-party archives may make complete removal impossible.
Marketing authorization should therefore be specific and freely given, and clients should understand the practical difficulty of withdrawing an image after publication.
De-identification versus false confidence
Cropping, blurring, masking, or removing names can reduce risk and may support certain internal or educational uses. These techniques are not a guarantee of anonymity when distinctive physical features or accompanying details remain visible.
The clinic should evaluate the complete context, not just the face.
Consent versus operational security
Written permission does not make insecure handling lawful. A clinic can have valid authorization and still violate privacy obligations by sending images through an unsecured channel, granting excessive access, or retaining them indefinitely without a defensible reason.
Permission and security are separate requirements.
Common Pitfalls to Avoid
Combining all purposes into one vague form
Clinical records, staff training, academic publication, website galleries, social media, and paid advertising involve different audiences and risks. Treating them as one undifferentiated purpose makes the client’s choice less meaningful and may not satisfy applicable authorization requirements.
Making publication a condition of treatment
A client should not be pressured to authorize marketing use as a condition of receiving medically appropriate treatment. The authorization process should distinguish necessary treatment documentation from optional promotional use.
Assuming verbal permission is sufficient
Verbal agreement may be difficult to prove and may not satisfy HIPAA authorization or other written-consent requirements. Use a documented written process before capturing or disclosing images for the intended purpose.
Retaining images without a defined policy
Retention should be based on clinical, legal, contractual, and business requirements. The clinic should define retention periods, review stored images periodically, and securely delete images that are no longer needed, subject to applicable recordkeeping obligations.
How to Apply This to Your Practice
Use a written policy that separates clinical photography from external disclosure and assigns clear controls to each stage of the image lifecycle.
- If your primary focus is clinical documentation: Capture only necessary views, link each image to the correct treatment record, restrict access by role, and store the files in an approved encrypted system.
- If your primary focus is marketing: Obtain a specific written authorization covering each intended channel and purpose before publication, and explain that online distribution may be difficult to reverse.
- If your primary focus is education or publication: Use de-identified images where possible, obtain written permission for identifiable images, and review captions and surrounding details for indirect identifiers.
- If your primary focus is regulatory compliance: Determine whether HIPAA, state privacy laws, biometric rules, international privacy laws, and advertising requirements apply to your organization and clients.
- If your primary focus is vendor management: Use vetted providers, execute required agreements, enforce access controls, and confirm encryption, auditability, breach reporting, retention, and deletion capabilities.
A privacy-aware photography process protects clients, preserves clinical value, and gives the clinic a defensible basis for every use of the image.
Summary Table:
| Aspect | Key Points |
|---|---|
| Regulations | HIPAA, state privacy laws, biometric laws, GDPR, advertising rules |
| Consent | Written authorization for marketing, separate from treatment consent |
| Security | Encrypt transmission/storage, restrict access, manage vendors |
| Best Practices | Standardize photography, limit data collection, define retention periods |
Ensure your clinic meets all privacy regulations and protects client trust. Contact BELIS today for expert guidance on HIPAA-compliant photo management and advanced aesthetic technology solutions. Get in touch now!