How to display before/after photos on your website legally
A plain-English guide to HIPAA, consent, and photo storage for plastic surgeons and med spas — without the legal jargon.
Before/after photos are your most powerful marketing asset. They're also one of the areas where plastic surgery practices most commonly get the legal side wrong — not out of carelessness, but because the rules aren't clearly explained anywhere.
This guide covers what you actually need to know, in plain English. It is not legal advice — it's a practical overview. For anything specific to your practice, consult a healthcare attorney.
Are before/after photos PHI?
Yes, in most cases. HIPAA defines Protected Health Information (PHI) as any information that relates to an individual's health condition and could reasonably identify them.
A face photo combined with the name of your practice and the procedure performed easily meets that standard. Even body photos — without a face — can qualify as PHI if combined with enough identifying context.
The practical implication: you should treat every patient photo you take as PHI until you've taken specific steps to change that.
What consent do you actually need?
You need written consent from the patient that specifically authorizes the use you intend. A general consent to treatment form does not cover photo use. The consent needs to address:
- That photos will be taken
- How they'll be used (website display, social media, marketing materials — these are different authorizations)
- That the patient can withdraw consent and have photos removed
The consent should be signed before photos are taken and before they appear anywhere publicly. "I'll get them to sign something later" is not a compliant approach.
Where can you store the photos?
This is where most practices have problems. The three common storage methods and their compliance status:
Your website's media library — not appropriate for PHI. Most WordPress media libraries, Squarespace asset managers, and general-purpose cloud storage don't provide the access controls or audit logging required under HIPAA.
Google Drive or Dropbox — not compliant without a Business Associate Agreement (BAA) with Google or Dropbox, and even with a BAA, these are general-purpose tools without HIPAA-specific access controls.
A storage provider that will sign a BAA — the correct approach. This means encrypted storage at rest and in transit, access controls that limit who can view the files, and a signed BAA with your provider.
What is a BAA and do you need one?
A Business Associate Agreement is a contract between your practice (the covered entity) and any vendor that stores, transmits, or processes PHI on your behalf (the business associate).
If your practice is a HIPAA covered entity and you use a third-party tool to store or display patient photos, that vendor is your business associate. You need a signed BAA with them before uploading any real patient photos.
Vendors who sign BAAs are taking on legal responsibility for protecting the data. Vendors who don't offer BAAs — or who you haven't executed one with — should not have access to your patient photos.
The practical checklist
Before displaying any before/after photos on your website:
- ✓ Signed patient consent form authorizing website display specifically
- ✓ Photos stored in encrypted storage covered by a signed BAA
- ✓ Signed BAA with your storage/gallery provider
- ✓ Access controls so only authorized staff can manage photos
- ✓ Ability to quickly remove a photo if a patient withdraws consent
- ✓ Audit log showing who accessed or modified photos
What about de-identified photos?
HIPAA provides a "safe harbor" de-identification standard — if 18 specific types of identifiers are removed from a record, it's no longer considered PHI. For photos, this typically means the face must be obscured and no other identifying information can be present.
The practical challenge: most before/after results are most compelling when the patient's face is visible. De-identifying facial surgery results defeats much of the marketing purpose. Body procedure results are easier to de-identify, but you still need to confirm that the resulting image couldn't identify the patient in context.
De-identification is a valid option for some practices and some procedure types. It's not a blanket exemption.
Common mistakes to avoid
Using a general gallery plugin without BAA-covered storage. WordPress gallery plugins typically store images in your media library, which isn't covered by a BAA or set up for protected health information.
Getting consent too broadly or too vaguely. "I consent to use of my photos" without specifying website display, social media, and marketing as separate authorizations is not sufficient.
Not having a BAA with your website platform. Squarespace, Wix, and most standard website builders don't offer BAAs. If your photos are stored on their servers, you have a compliance gap.
No process for consent withdrawal. If a patient later asks to have their photos removed, you need to be able to do it quickly and document that you did.
Proova gives you private, encrypted storage and a consent confirmation log for every case. Standard plans don't include a BAA; contact us if you need one for a HIPAA-covered practice. Start for free and see how it works.
Ready to try proova?
Start free — 1 case, no credit card. Be live on your website in under an hour.
Start free — no card required