A med spa blends a medical practice with a consumer brand. It takes bookings online, keeps client intake forms and treatment photos, sells packages and memberships, advertises on social media, and often depends on a handful of software tools for scheduling, payments and messaging. Every one of those tools has a login, and every login is something a phishing message can try to capture. This guide covers phishing protection for med spas in plain language: where the risks are, which rules may apply, and what to do about it.
The basics: what phishing is
Phishing is a deceptive message that appears to come from a trusted person or company and tries to get you to click a link, open an attachment, reveal a password or send money. The U.S. Federal Trade Commission notes that phishing messages often look like they come from a company you know, claim there is a problem with your account or payment, and ask you to click a link or confirm information. The goal is usually one of three things: steal a login, install malicious software, or redirect a payment.
Where a med spa is exposed
The following are illustrations of how the technique could play out, not descriptions of specific events.
The booking and payment platform alert. Med spas rely on scheduling and payment software. A fake notice, "Your payout is on hold, verify your account," links to a page imitating the real login. Anyone who types their credentials there hands them over. If the same password is used elsewhere, the damage spreads.
Social media direct messages. A med spa's public profile invites messages. A scammer can send a message that looks like a collaboration offer, a copyright complaint, or a warning that the business page will be removed unless you click a link. The safe rule is the same everywhere: go to the platform directly, not through the message.
A fake client inquiry with an attachment. An email from a "prospective client" asks about a treatment and includes a file or link described as "my medical history" or "photos." CISA notes that an unsolicited email asking you to download and open an attachment is a common delivery mechanism for malware. Ask for information through your own intake form instead.
Supplier and equipment invoices. Devices, consumables and skincare products come from specific suppliers. A message that mimics a supplier and says payment details have changed is classic business email compromise, which the FBI describes as a scam aimed at organizations that make payments, often by impersonating vendors or executives. The cure is a phone call to a known number.
A message from "the medical director" or owner. Staff are used to quick requests from leadership. A fake message from the medical director or owner that asks someone to buy gift cards, share a login or pay an invoice relies on that habit. Confirm by another channel.
Text messages. Appointment reminders by text are normal, so a fake text is believable. Our article on SMS phishing scams explains how to recognize them, and how to spot phishing emails covers the email equivalents.
Does HIPAA apply?
It depends on the business. The HIPAA regulations apply to "covered entities": health plans, health care clearinghouses, and health care providers who transmit health information in electronic form in connection with certain standard transactions, such as billing a health plan. A cosmetic practice that is paid entirely by clients, and does not conduct those electronic transactions, may not be a covered entity, while a practice that also bills insurance for some services may be. CMS publishes a covered-entity decision tool, and a healthcare attorney can give a definitive answer for your situation.
Two points hold either way:
- If you are a covered entity, the Security Rule expects a risk analysis and a security awareness and training program for the workforce, and the Breach Notification Rule sets deadlines for telling affected people, generally no later than 60 days after discovery.
- If you are not, you may still be subject to state laws on notifying people when their personal information is exposed. The National Conference of State Legislatures summarizes state breach notification laws.
Client intake forms, photos and treatment notes are sensitive in any case. Treat them that way whether or not a particular law requires it.
Controls that deliver the most
Start at the top of this list.
- Multi-factor authentication everywhere it is offered. Email, scheduling, payments, social media and cloud storage. CISA explains that text-message and voice codes and push approvals are vulnerable to phishing or related attacks, while FIDO/WebAuthn security keys are phishing-resistant. Choose the strongest method each tool supports. We cover the differences in multi-factor authentication against phishing.
- Use a password manager and unique passwords. The UK National Cyber Security Centre notes that a good password manager only offers a saved login on the correct website, which helps against lookalike pages. Reusing one password across tools lets one phishing success unlock many accounts.
- Limit who has access. A front-desk coordinator needs the schedule, not the accounting system. A contractor should not share an employee's login.
- Lock down social accounts. Use multi-factor authentication on the business profile, keep the list of people with admin rights short, and remove former staff immediately.
- Protect your domain's email identity. SPF, DKIM and DMARC let receiving mail servers check whether messages claiming to be from your domain are real. DMARC is now defined in RFC 9989 (published May 2026, replacing RFC 7489), and Google publishes setup instructions for Workspace administrators. Done well, this makes it harder for scammers to send fake messages that appear to come from your med spa.
- Payment-change rule. No change to bank details or unusual payment without a call to a known number.
- Keep devices and software updated. Tablets at reception, staff phones used for scheduling, and the office computer should receive security updates.
- Train in small, regular doses. Our guide to phishing prevention programs for employees shows how to run short sessions that stick.
When something goes wrong
Have a plan before you need one.
- Contain: disconnect the affected device from the network (unplug it or take it off Wi-Fi) and tell the owner or manager immediately.
- Secure accounts: immediately change any passwords that may have been revealed, and anywhere else the same password was used. If you clicked a link or opened an attachment, update your security software and run a scan.
- Money: call the bank at once if a payment was sent.
- Notify the platform: payment and scheduling providers often have a process for compromised accounts.
- Document: note times, messages and actions. If client information may have been exposed, you will need this for your legal review.
- Report: use ReportFraud.ftc.gov and forward phishing emails to reportphishing@apwg.org.
Our guide to building a phishing response plan offers a template to adapt.
A simple routine for the treatment-room corkboard
- Reach logins through bookmarks, never through messages.
- Treat urgent, secret or unusual payment requests as warning signs.
- Verify bank-detail changes by phone.
- Confirm requests from leadership through a second channel.
- Report suspicious messages, even if you already clicked.
A med spa's reputation rests on trust. Protecting the accounts and records that clients entrust to you is part of the same promise, and a few consistent habits do most of the work.
Sources
- FTC, How to Recognize and Avoid Phishing Scams: https://consumer.ftc.gov/articles/how-recognize-and-avoid-phishing-scams
- CISA, Avoiding Social Engineering and Phishing Attacks: https://www.cisa.gov/news-events/news/avoiding-social-engineering-and-phishing-attacks
- CISA, #StopRansomware Guide (isolating devices): https://www.cisa.gov/stopransomware/ransomware-guide
- UK NCSC, Password managers: https://www.ncsc.gov.uk/collection/top-tips-for-staying-secure-online/password-managers
- FTC, ReportFraud: https://reportfraud.ftc.gov/
- Anti-Phishing Working Group, report phishing: https://apwg.org/reportphishing/
- FBI, Business Email Compromise: https://www.fbi.gov/how-we-can-help-you/scams-and-safety/common-frauds-and-scams/business-email-compromise
- eCFR, 45 CFR 160.103 (HIPAA definitions of covered entity, health information and individual): https://www.ecfr.gov/current/title-45/subtitle-A/subchapter-C/part-160/subpart-A/section-160.103
- CMS, Are You a Covered Entity? (Covered Entity Decision Tool): https://www.cms.gov/about-cms/what-we-do/administrative-simplification/hipaa/covered-entities
- HHS, The HIPAA Security Rule: https://www.hhs.gov/hipaa/for-professionals/security/index.html
- HHS, Breach Notification Rule: https://www.hhs.gov/hipaa/for-professionals/breach-notification/index.html
- NCSL, Security Breach Notification Laws: https://www.ncsl.org/technology-and-communication/security-breach-notification-laws
- CISA, Implementing Phishing-Resistant MFA fact sheet: https://www.cisa.gov/sites/default/files/publications/fact-sheet-implementing-phishing-resistant-mfa-508c.pdf
- IETF, RFC 9989 (DMARC; obsoletes RFC 7489): https://www.rfc-editor.org/rfc/rfc9989
- Google Workspace Admin Help, Set up DMARC: https://support.google.com/a/answer/2466580


