September 3, 2026

Zac Degraide

A form is not HIPAA compliant because it says it is. Compliance depends on where the data travels, who can read it in transit and at rest, whether the vendor will sign a Business Associate Agreement, and whether the submission lands somewhere access-controlled rather than in an inbox. Many aesthetic practices collecting intake online are using a tool that fails at least one of those tests, usually the email notification. This guide covers what actually makes a form compliant, the specific ways common tools break, what changes when patients attach photos, and the questions to ask a vendor before you switch anything on.
Six things, and a tool has to satisfy all of them rather than most.
A signed Business Associate Agreement. Any vendor that creates, receives, stores, or transmits PHI for your practice is a business associate, and you need a BAA before a single patient submission arrives. This is the fastest disqualifying test. If a vendor will not sign one, or offers it only on a plan your clinic is not on, the tool cannot be used for aesthetic intake regardless of its security features.
Encryption in transit and at rest. HTTPS on the form page covers the journey. Encryption at rest covers the database where the submission sits afterwards, which is the part practices rarely ask about.
Access controls with individual accounts. Every person who can read submissions needs their own login, including front desk, injectors, and your medical director. Shared logins, which are common in small aesthetic practices, make it impossible to know who accessed which patient's intake, and that defeats the audit requirement underneath.
Audit logging. A record of who viewed, downloaded, edited, or exported a submission, retained and reviewable. This is what turns "we think only the right people saw it" into something you can evidence.
Controlled retention and deletion. You need to know how long patient submissions are kept, where backups live, and how to permanently delete a record when a patient requests it or your state's retention period ends.
Notifications that carry no PHI. Covered below, because it is the failure almost everyone has.
The tools aesthetic practices reach for first fail in predictable places. Knowing which failure you are dealing with is most of the fix.
Some will not sign a BAA at all on standard plans, which ends the conversation. Others will sign one but only on a specific tier, so a practice that built its intake on the free plan is out of compliance without any visible change to the form. Several store submissions indefinitely with no documented deletion path, which becomes a problem the first time you need to honor a record request.
The most common failure by far is the email notification. A form that emails the clinic on submission, with the patient's answers in the body, has just transmitted PHI through a channel usually covered by no BAA, into inboxes on staff personal phones, where it sits indefinitely and gets forwarded to whoever is covering reception. The form itself can be encrypted, hosted correctly, and access-controlled, and the notification undoes all of it.
The compliant pattern is a notification that says a new submission has arrived and nothing else. The staff member logs in to read it. That single change fixes the most common gap we see in aesthetic practices, and it costs nothing.
Two more worth checking. Analytics and tracking scripts on the form page can transmit form field contents or URL parameters to third parties who have signed nothing; the FTC's 2023 actions against GoodRx and BetterHelp and the HHS Office for Civil Rights bulletin on tracking technologies (December 2022) were about exactly this. And form data flowing into a spreadsheet, a project tool, or a general-purpose CRM inherits that destination's controls, which are usually weaker than the form's.
Photo submissions raise the stakes, because an image is harder to de-identify than a text field and much easier to mishandle.
The image is PHI as soon as it can identify the patient, and it needs the same encryption, access control, and audit logging as the rest of the submission. The difference is in the failure modes. Photos get downloaded to look at properly, and once a copy is on a laptop or a phone it has left the controlled system. Photos get forwarded to a provider for an opinion, usually by text or email. Photos submitted by patients arrive with metadata attached, including in some cases location data, which is worth stripping on ingest.
There is also a consent question that text intake does not raise. A photo submitted for a consultation is authorized for that clinical purpose. It is not authorized for marketing, and the two need to be separate permissions with separate records. A practice that treats the consultation photo library as a marketing asset library is publishing images that were never cleared for it.
The practical requirements for photo intake are that the image goes straight into an access-controlled clinical system rather than into a general file store, that viewing does not require downloading, that sharing with a provider happens inside the system rather than over text, and that consent status is attached to the image rather than tracked separately.
This is the question that decides compliance, and the one most often left unanswered.
Trace the whole path before you approve a form for patient use. The patient submits. Where is the data written first? Who at the vendor can access that store? What notification fires, and what does it contain? Does the submission sync anywhere else, into the chart, your practice management system, a marketing CRM, a spreadsheet someone built? Does anyone download it, and where does that copy live? What happens to the original once the patient has been seen?
Most practices can answer the first step and not the rest. The gaps are almost always downstream: a Zapier connection into a shared sheet, a nightly export nobody remembers setting up, an integration built during onboarding by someone who has since left. Each of those is a copy of PHI in a place with its own access rules, and each needs its own BAA if a vendor is involved.
The strongest position is fewest copies. A submission that lands directly in the clinical system, is read there, and never leaves has one place to secure and one place to audit. Every additional hop is another agreement, another access list, and another thing to remember during a record request.
Bring these to any intake vendor pitching your practice, including ours, and get the answers in writing.
A vendor built for healthcare answers all nine quickly. A general-purpose form tool with a healthcare landing page starts qualifying the answers around question three, which is your signal that aesthetic patient data is not what it was designed to hold.
Compliance sets the floor. A few design choices decide whether the form actually gets completed.
Ask for the minimum you need before the visit. Long forms get abandoned, and every extra field is more PHI to protect for no clinical gain. Split intake into what must arrive before the appointment and what can be captured in the room. Make it work properly on a phone, because that is where most patients will fill it in, including the photo upload. And tell patients plainly that the form is secure and why, since aesthetic patients are often being asked to send sensitive images to a practice they have not visited yet, and a sentence of reassurance improves completion.
One workflow note. Forms that write straight into the chart save staff the retyping step, which is not only faster but removes a transcription error path and one more copy of the data sitting in a temporary place.
RxPhoto keeps the part of intake that general form tools handle worst, patient photographs, inside the clinical record.
Intake and consent forms are built in RxPhoto and attach to the correct patient record automatically, and photos live in the same HIPAA-compliant, access-controlled environment rather than an inbox or a shared drive. Access is logged, so who looked at what is answerable. Consent status travels with the image, so a consultation photo does not quietly become a marketing asset. And photos taken in clinic are captured with on-screen guides, so angles and framing match across providers and visits.
For practices already running text intake somewhere compliant, the photo path is usually the remaining gap, and the one with the most exposure.
Not in the standard consumer version, and not without a BAA that covers it. Some Google Workspace configurations can be brought under a BAA, but this depends on the specific edition, the services included, and the configuration, and the default setup most practices use is not covered. Treat any form tool as non-compliant until you have a signed BAA naming the service you are actually using.
Standard email is not an appropriate channel for PHI in either direction. A patient may choose to email you their own information, and receiving it is not a violation, but you should not request it that way or reply with PHI attached. The compliant version is a secure portal or form the patient submits into, with a notification that contains no clinical detail.
Probably yes. Contact details collected in the context of seeking treatment are identifiable health information, because the fact of the enquiry is itself health-related. The safer default is to treat anything collected through a clinical intake path as PHI and to have the agreement in place.
SMS is not encrypted, and messages sit on devices you do not control. Reminders that contain no clinical detail are common practice and low risk. Requesting or receiving photos by text is a different matter, and it puts patient images on staff phones, which is the exposure most practices are trying to eliminate. Send a secure link instead of asking for a reply attachment.
Completed intake becomes part of the medical record and follows your state's retention rules, which commonly run several years and longer for minors. The requirement to retain is a reason to keep records in a system with controlled access and a documented deletion path, rather than in a form tool chosen for convenience.
If patient photos are the part of intake you are least sure about, book a walkthrough of how RxPhoto handles capture, access, and consent.
This guide is general information about HIPAA and intake workflows. It is not legal advice, and state requirements vary.

Capture consistent photos, streamline documentation, and deliver clearer consultations with tools designed specifically for aesthetic practices.
Walk through how RxPhoto fits into your current workflow.