Skip to main content
Guide

Med Spa Photo Consent: Ad-Ready Release Language

What a med spa before-and-after photo consent has to cover before the image can run in ads: the elements, the scope terms, and the revocation problem.

11 min read

A med spa photo consent is only ad-ready when it does two separate jobs at once: it authorizes the disclosure of a patient's health information under HIPAA, and it grants a commercial publicity license to use that person's likeness in paid advertising, and Curve is the HIPAA-compliant tracking layer that keeps the campaign around those images from leaking the same information the release was supposed to control. Most med spa forms do one job and assume the other. The elements below are what a release has to name explicitly. This article describes those elements. It is not a template and it is not legal advice.

The reason this matters more for med spas than for a general marketing team is that a before-and-after photo is not a lifestyle image. It is a record of a treatment performed on an identifiable person by a provider. If your practice provides or bills for medical services, that record is protected health information, and a signed marketing release that never mentions HIPAA does not authorize you to publish it.

A treatment photo is two legal objects in one file

Split them apart in your head, because the two objects have different requirements, different expiry behavior, and different failure modes.

The HIPAA authorization. A med spa that provides or bills for medical services can be a covered entity. Using a patient's image for marketing is a disclosure of PHI, and marketing disclosures require a written authorization that meets specific content requirements. The authorization is not implied by the treatment consent the patient signed before the injection. It is a separate permission with its own required elements.

The publicity release. Separately, state right-of-publicity and appropriation-of-likeness law governs the commercial use of a person's face and body. This is contract and tort territory, not HIPAA. A HIPAA authorization tells you the disclosure is permitted; it does not by itself give you a license to run the image as paid creative on Meta for the next three years.

A release that covers one and not the other is the most common defect we see. A marketing-department model release is silent on PHI. A clinical-consent form authorizes disclosure but says nothing about paid media, editing, or duration. Ad-ready means both, in one signed document or two documents signed together.

The elements an ad-ready release has to name

What follows is a checklist of coverage areas, not drafting language. Have counsel in your state write the actual words.

Who and what, described specifically

  • The specific images. Identify what is being released. A release that covers "photographs taken during treatment" without a date, a session reference, or an attached set is ambiguous the moment a dispute starts.
  • The named parties. Who is authorized to use the images, and whether that includes agencies, franchisees, affiliated locations, and platform partners. If your marketing agency will upload the creative, it needs to be inside the grant.
  • The information being disclosed. HIPAA authorizations require a description of the information covered. For a before-and-after, that is the image plus whatever the caption reveals: the treatment performed, the areas treated, the number of sessions, the product used.

Scope of use, stated in the terms media actually works in

  • Paid advertising specifically. "Marketing materials" is not clearly the same as paid social ads, and a patient who imagined a brochure did not knowingly consent to a targeted Instagram campaign. Name paid media.
  • The channels. Website, social organic, paid social, search, display, email, print, in-clinic screens, third-party review sites. Enumerate them.
  • Editing and derivative use. Cropping, zooming, color correction, side-by-side composition, overlay text, and inclusion in video. If you will animate a slider between the two states, that is a derivative use.
  • Geography and duration. An unlimited perpetual worldwide grant is easy to draft and hard to defend if it was never explained. A defined term with a renewal path holds up better.
  • Whether the patient will be identified. By first name, initials, city, or not at all. A face that is recognizable identifies the person whether or not you print a name.

The HIPAA-specific elements

  • An expiration date or expiration event. HIPAA authorizations require one. "Until revoked" is a recognized form, but a bare document with no expiry language at all is defective.
  • The right to revoke, and how. The authorization has to tell the patient they can revoke, describe the process, and describe the limits, including the reality that you cannot claw back what has already been published.
  • A statement that treatment is not conditioned on signing. Care cannot be conditioned on agreeing to be in your ads. If your intake flow presents the photo release alongside the treatment consent as one bundle, you have a conditioning problem in appearance even if not in intent.
  • Disclosure that the recipient may re-disclose. Once the image is on a public platform, HIPAA protections no longer follow it.
  • A statement that the use is marketing, and whether the practice receives any remuneration in connection with it.
  • Signature and date, plus authority documentation if signed by a personal representative.

Compensation, and why it changes the analysis

If the patient receives a discount, free treatment, or payment in exchange for the photos, say so in the document. Compensated endorsements also pull in FTC advertising rules about material connections, which require disclosure in the ad itself, not only in the file. A "model patient" program that trades treatments for content is an endorsement program whether or not you call it one.

Where med spa photo releases fail in practice

The defects are consistent across practices, and none of them are exotic.

Consent captured after the photo. The image exists before the paperwork does, and the shoot happens in the treatment room where the patient is not in a strong position to decline. Capture the release before the camera comes out.

Verbal consent, remembered. "She was fine with it" is not a record. Two years later the staff member who remembers has left.

Scope creep from organic to paid. A patient agreed to a post on the practice's Instagram. Six months later the post is boosted, then cut into a paid carousel, then used by a franchise location in another state. Each step went past the grant.

Revocation with no operational path. The release grants a revocation right that nobody can actually execute, because there is no inventory mapping each patient to the creative assets and ad sets their image appears in. When the revocation arrives, the practice cannot answer the simple question of where the image currently runs.

The caption discloses more than the photo. The image might be a cropped lower face. The caption says the treatment, the product, the units, and the timeline. Captions are disclosures too.

Minors and personal representatives. Parent or guardian signature, plus the practical question of what happens when the patient reaches majority and the image is still running.

The photo release does not cover your tracking

Here is the part med spas consistently miss, and it is the reason this article exists on a tracking company's site.

A patient signs a release permitting you to publish their before-and-after. That release says nothing about the visitors who come to look at it. When someone lands on your gallery page for a specific treatment, a client-side pixel fires with the page URL, the page title, and browser identifiers. The URL frequently names the treatment. The ad platform now holds a record that an identifiable browser viewed a page about a specific procedure at a medical practice. No patient signed anything covering that, because the disclosure is about the visitor, not the patient in the photo.

This is the same mechanism behind healthcare pixel litigation, where settlements have cumulatively crossed $100 million. Before-and-after galleries are among the highest-intent pages on a med spa site, which means they are among the most heavily tracked. Meta and Google do not sign BAAs for their advertising products, so there is no contractual cover for what those tags collect. State consumer health privacy laws, including Washington's My Health My Data Act, reach beyond HIPAA and apply to consumer health data regardless of whether you are a covered entity.

You can have a flawless release and still have this problem. They are different disclosures with different subjects.

How Curve keeps the gallery from leaking

Curve is HIPAA-compliant ad tracking, attribution, and analytics for healthcare. The tracking script installs in place of the Meta Pixel or the Google tag, and events go to Curve's US-hosted infrastructure instead of straight to an ad platform. That single structural change creates a decision point that a browser pixel does not have.

Four mechanisms matter for gallery and consultation pages.

Per-destination field mapping. Only fields you explicitly map are forwarded to a given destination. The default is that nothing goes. A treatment-specific page URL is not on the map unless you put it there, and you should not.

Neutral event aliases. The ad platform sees a neutral event name rather than the service line. An event called consult_request tells Meta a conversion happened. An event called filler_gallery_lead tells Meta what the person was interested in, permanently, in an interface your whole agency can read.

Identifier hashing. Contact identifiers are SHA-256 hashed to each platform's conversion API requirements before they leave.

PHI-pattern detection. Curve inspects payloads for PHI-shaped values such as MRN-style identifiers, dates, and long numeric sequences, and flags them. This is a monitoring layer, not redaction. The protection comes from mapping and hashing. Detection is how you find out that someone added a treatment field to a form last month.

A signed BAA is included on every Curve plan. If you want to see what your current gallery pages are sending today, the free compliance scanner reads any healthcare site and reports the tracking it finds. For the underlying mechanics, see why client-side pixels create the exposure server-side tracking removes.

Operational controls that make the release real

  1. One consent record per image set, stored with the images. Not in a filing cabinet, not in a staff member's memory.
  2. An asset inventory that maps patient to creative to campaign. This is what makes revocation executable. Build it before you need it.
  3. A review step before any organic asset becomes paid creative. The grant is checked at the moment of escalation, not at the moment of posting.
  4. Caption review as a compliance step. Treat the caption as part of the disclosure, because it is.
  5. Neutral URLs and event names on gallery and consultation pages. Decide these before you build, because renaming events after launch loses history in the ad platforms.
  6. A revocation runbook with a named owner and a time target. Pull from paid first, then organic, then the site.

Frequently asked questions

Does a signed model release let me run before-and-after photos in ads?

Not on its own if your practice provides or bills for medical services. A standard model release addresses likeness rights. It does not meet HIPAA's authorization requirements for a marketing disclosure, and it typically omits expiration, revocation, and the statement that treatment is not conditioned on signing.

Can I skip consent if I crop the face out?

Cropping reduces risk but does not reliably deidentify. Tattoos, jewelry, scars, and distinctive features identify people, and context in the caption or the campaign can close the gap. Get the release regardless, and treat cropping as a courtesy to the patient rather than a legal strategy.

What happens when a patient revokes?

You stop future use. You cannot retrieve what has already been distributed, and the authorization should say so plainly. Practically, you need an inventory that tells you every ad set, landing page, and organic post the image appears in, or you cannot honor the revocation on any credible timeline.

Do platform policies restrict before-and-after images?

Yes, independently of HIPAA. Meta restricts before-and-after imagery, particularly around body and weight, and rejects most of it in the weight-loss category. Platform rejection is an advertising policy question, not a privacy one, and an image can be fully consented and still non-servable.

Does the release cover the tracking on my gallery page?

No. The release is a permission from the patient in the photo. Your tracking discloses information about the visitors viewing the page, who signed nothing. Those are different people and different disclosures, which is why the fix is server-side collection with mapped fields rather than better paperwork.

Are we a covered entity if we only do cosmetic work?

It depends on what you provide and how you bill, and it is worth an actual legal answer rather than an assumption. Med spas that provide or bill for medical services can be covered entities. Separately, state consumer health privacy laws apply to consumer health data whether or not HIPAA does, so a negative answer on covered entity status does not end the analysis.

Should the photo release be part of the treatment consent packet?

Keep them separable. Bundling invites the appearance that care was conditioned on agreeing to appear in advertising. Present the photo release as an optional document with its own signature.

Where to start

Take your current release to counsel with one question: does this document contain HIPAA's required authorization elements and a publicity grant broad enough for paid media across the channels we actually run. Most med spa releases fail on expiration, revocation mechanics, or the paid-media scope, and all three are cheap to fix before the campaign rather than after a complaint.

Then fix the half the release was never going to cover. Curve replaces the client-side pixel on your gallery and consultation pages with server-side collection, forwards only explicitly mapped fields to each destination, hashes identifiers, sends neutral event names instead of treatment names, and monitors for PHI-shaped values. A signed BAA is included on every plan. See how compliant conversion tracking is set up across Google, Meta, and Microsoft, read the med spa specific guidance on consultation requests from Facebook Lead Ads, or visit curvecompliance.com to walk through your current setup.

Reviewed August 2026. This article describes consent elements for planning purposes and is not legal advice. Photo release requirements vary by state, and platform advertising policies change frequently. Have counsel licensed in your state draft and review your release.

Stay Compliant. Scale Confidently.

Join healthcare innovators who trust Curve for HIPAA-compliant ad tracking.Launch in hours, not months. Your growth stack, now HIPAA-safe.

Book a free tracking audit