AI Governance for Salons and Med Spas: State Boards, HIPAA, and Consent
A practical compliance stack for med spas and salons running AI across intake, marketing, and clinical-adjacent workflows.
- PUBLISHED
- May 13, 2026
- READ TIME
- 8 MIN
- AUTHOR
- ONE FREQUENCY
- Topic
- med spa AI compliance, salon HIPAA, state board AI
- Industry
- salons-spas
- Published
- May 13, 2026
- Read time
- 8 min
- Word count
- 1,492
AI compliance for a salon, day spa, or med spa is not a single problem. It is four overlapping problems: state cosmetology board rules, HIPAA exposure for med spa services, payment card compliance (PCI DSS), and consumer privacy law (CCPA, state-level analogs). Each one has a small but specific footprint in the AI stack. Most salons we audit have done none of the work, which means a single complaint to the state board or a single bad-actor breach is enough to trigger a license review.
The good news: the governance work that protects a salon or spa AI deployment fits on a single page, signed by the owner, kept in the safe with the EIN paperwork. The bad news: most vendor contracts are silent on the things that matter. This guide is the practical compliance posture. It pairs with the salon AI playbook and the broader AI enablement framework. The practice overview is at AI for salons and spas.
The four compliance domains
1. State cosmetology board
Every state regulates cosmetology, esthetics, and barbering through a state board. The rules vary widely on the AI-adjacent items:
- Licensure display and claim. The AI receptionist, intake form, and marketing copy must not imply licenses the salon does not have. "Our stylists are board-certified colorists" is fine if true. "Our AI assistant is licensed" is not — AI is not licensed.
- Sanitation log retention. Most states require sanitation logs to be retained for 2 to 5 years. AI can generate the daily log template and remind the front desk to file; the actual log entry is a human signature.
- Scope of practice. Estheticians cannot perform procedures reserved for medical staff. The AI must not book an esthetician for a service the board does not permit (laser tattoo removal in some states, microneedling deeper than 0.3mm in others, etc.).
- Chemical safety disclosures. The AI's intake should capture allergy history accurately for color services. A failure here is both a board issue and a liability issue.
2. HIPAA (med spa only)
Med spas operating under a supervising physician are HIPAA-covered entities the moment a treatment is medical (Botox, filler, prescription-strength peels, laser hair removal under physician supervision, body contouring under physician supervision). The implications for AI:
- Business Associate Agreement (BAA). Every AI vendor that touches PHI must sign a BAA. This includes the booking platform's AI, the receptionist vendor, the intake form provider, and any analytics platform.
- PHI in transit. Voice recordings and SMS containing PHI must be encrypted in transit. Most major platforms (Boulevard, Mindbody, Jane App) handle this.
- PHI at rest. Stored intake records, photos, and chart notes must be encrypted at rest. Verify in the vendor contract.
- Minimum necessary access. AI agents access only the PHI required for the task. A scheduling agent does not need to see the full medical history.
- Breach notification. A breach involving PHI triggers federal notification requirements within 60 days. The vendor's incident response process must be documented.
- Audit trail. Every PHI access by AI or human must be logged for 6 years.
The penalty for a HIPAA violation runs $100 to $50,000 per record exposed. A single breach of 500 records can end a med spa.
3. PCI DSS (all salons taking card payments)
PCI compliance for salons is mostly about not handling raw card numbers. The AI workflow must:
- Never receive a full PAN over voice or SMS. If a guest tries to read a card number to the AI, the AI redirects to a tokenized payment link.
- Use tokenized card-on-file flows. Boulevard, Mindbody, Vagaro, and Phorest all support tokenized cards; the AI references the token, never the raw number.
- Document the SAQ. Most salons fall under SAQ-A (using only validated third-party processors). The owner signs the SAQ-A annually.
4. Consumer privacy (CCPA and state analogs)
California (CCPA), Virginia (VCDPA), Colorado (CPA), and several other states regulate consumer data. The footprint for salons:
- Disclosure at collection. The intake form must disclose what data is collected and how it is used.
- Right to delete. Guests can request deletion of their record. The booking platform must support this (most do).
- Right to opt out of sale. Salons that sell guest data (this should be never) must offer an opt-out. Most salons do not sell data; the disclosure should make this explicit.
- SMS consent. TCPA requires explicit opt-in for marketing SMS. The intake form's marketing-consent checkbox handles this — but the checkbox must not be pre-checked.
The one-page salon AI governance policy
Every salon we work with adopts a one-page policy covering eight items. The whole thing is signed by the owner, posted in the back office, and reviewed annually.
- Approved AI vendors. The named list of vendors with current contracts.
- PHI handling. Whether the salon performs HIPAA-covered services and which vendors have BAAs.
- Voice recording disclosure. The AI receptionist's opening line includes the recording disclosure required by two-party consent states.
- Card payment policy. AI never receives raw PANs; tokenized links only.
- Guest deletion procedure. How a guest's record gets deleted on request and how long the deletion takes.
- SMS opt-in policy. Marketing SMS requires explicit opt-in at intake; opt-out is honored within 10 minutes.
- Stylist AI use. Stylists' personal AI tools are not connected to the salon's brand or to guest records.
- Annual review. The policy is reviewed by the owner and the salon's attorney every January.
The policy fits on one page. The annual legal review costs $400 to $900 and is the cheapest insurance the salon buys.
What the AI vendor contract must say
Most off-the-shelf AI vendor contracts are silent on the things that matter. Negotiate the following into every contract:
- Data ownership. The salon owns the data; the vendor uses it only to provide the service.
- Data deletion on termination. Within 30 days of contract end, all guest data is deleted from the vendor's systems.
- No model training on salon data. The vendor does not use the salon's guest data to train models.
- Subprocessor disclosure. The vendor lists all subprocessors (the cloud they run on, the model provider, the SMS gateway).
- BAA. For med spa workflows, signed BAA on file.
- Incident response SLA. Vendor notifies the salon within 24 hours of any suspected breach.
If a vendor will not sign these terms, walk away. Plenty of vendors will.
What good looks like
- Vendor contracts. 100% of AI vendors signed under the eight-clause framework above.
- BAA execution. Every med spa AI vendor has a current BAA.
- Policy posted. One-page governance policy posted in the back office, signed by owner.
- Annual review. Last review date within 12 months, attorney sign-off documented.
- State board posture. Salon has confirmed no AI use crosses the scope-of-practice line in the operating state.
- Incident response. Owner knows the steps to take if a vendor reports a breach; phone numbers are documented.
Pitfalls
- Do not assume the vendor has a BAA. Verify. Many salon AI vendors will sign one only if you ask.
- Do not let the AI quote drug or treatment information. "How long does Botox last?" is fine general info; "should I take ibuprofen before my appointment?" is medical advice and must route to the NP.
- Do not skip the recording disclosure. Two-party consent states require it; the cost of a complaint is high.
- Do not run AI tools the staff cannot explain. If the front desk cannot tell a guest what data the AI captures, the salon has a compliance gap.
FAQ
Is my hair salon HIPAA-covered?
No, unless you offer medical services under a supervising physician. Hair, color, lash, brow, makeup, and standard waxing are not HIPAA-covered.
What about facials and microdermabrasion?
Generally not HIPAA-covered unless they involve a medical device or physician supervision. Microneedling above 0.3mm is medical in most states; verify with the state board.
Do I need a BAA with my booking platform?
Only if you offer HIPAA-covered services. Boulevard, Mindbody, and Jane App offer BAAs; ask in writing.
What about my AI receptionist vendor?
Same answer. If the AI handles PHI (med spa intake, treatment-related conversations), the vendor must sign a BAA.
How much does this compliance work cost?
$1,500 to $4,000 in one-time setup (policy drafting, vendor contract negotiation, attorney review). Then $400 to $900 per year for the annual review.
What is the worst-case scenario?
A state board complaint that triggers a license review for the owner. Even when the complaint is resolved, the owner spends 40 to 80 hours and $5,000 to $15,000 in legal fees defending. Prevention is cheap.
Want a compliance review of your salon's AI stack? Talk to our team or read the broader AI for salons and spas practice page.
Cited and consulted.
- 01American Salon — Salon Compliance Coverageamericansalon.com · accessed May 8, 2026
- 02Modern Salon — Cosmetology Board and Regulationmodernsalon.com · accessed May 8, 2026
- 03Mindbody Business Education — Med Spa Compliancemindbodyonline.com · accessed May 8, 2026
- 04Boulevard Blog — Med Spa Operations and HIPAAboulevard.io · accessed May 8, 2026
Ready to ship the next outcome?
One Frequency Consulting brings 25+ years of technology leadership and military discipline to every engagement. First call is operator-grade scoping — sixty minutes, no charge.