Wellness and aesthetic practices handle health information every day: medical histories, medications, photos, treatment notes. Before any of that goes near an AI tool, you need to know where it is stored, who can see it, and whether the vendor will sign the agreements your practice needs.
Questions to ask every vendor
Where is the data stored? Is it used to train the vendor's models? Can you delete it? Will they sign a business associate agreement if your practice is covered by HIPAA?
Check whether HIPAA applies to you
HIPAA doesn't cover every practice. A health care provider is covered only if it sends health information electronically for transactions like insurance claims. Many cash-pay med spas and holistic practices don't, though state privacy laws may still apply. If your practice is covered, you need a written business associate agreement with any vendor that handles protected health information for you, and that includes AI tools. If a vendor won't sign one, keep client data out of that tool.
Keep a list of what stays out
Write a short rule for your staff about what never goes into a general-purpose AI chat: names with diagnoses, photos, anything from a chart. Most useful AI work at a practice, like drafting marketing emails or summarizing a policy, doesn't need client data at all.
This article is general information, not legal advice. Ask a healthcare attorney or compliance advisor what applies to your practice.


