Type "best medspa software" into a search bar and you'll get ten lists that disagree with each other in ways that should embarrass everyone involved. One crowns a scheduling tool. One crowns itself. None of them tell you what the software actually has to do, which is the only question worth answering before you look at a single price.
What jobs does medspa management software have to do?
Strip away the marketing and a medspa runs on one thing: a client record that has to carry seven different jobs without falling apart. Scheduling and online booking — someone has to hold the calendar and take deposits. Client charts and treatment records — someone has to remember what was injected, where, and when. E-signed consent — someone has to prove the client agreed to the specific procedure, on the specific day. Integrated payments — someone has to move money and post it to the right invoice. Memberships and packages — someone has to track what's been paid for and what's left. Marketing on live data — someone has to know who's booked and who's gone quiet. Retention automations — someone has to actually send the reminder instead of just knowing it's needed.
That's seven jobs, one record. Most medspas run them across six or seven tools instead — a scheduling app, a separate charting tool, a payment processor, an email platform, a text blast service — stitched together with exports and good intentions. Every seam is a place data goes stale.
Do medspas need a certified EHR?
A CRM runs the relationship — booking, payment, marketing, rebooking. An EMR holds the clinical record. Most medspas live in the gap between them and need enough clinical depth to practice safely without hospital-grade overhead.
That means treatment notes with an addendum trail, units and lot numbers recorded where it matters, before/after photos attached to the chart, and consent that's actually defensible — versioned, e-signed, capturing a timestamp, IP address, device, and the exact form version the client signed. That's clinical depth. It is not a certified EHR, and we don't pretend otherwise. Certification matters mainly for practices that bill insurance programs or prescribe electronically.
If your practice is injectable-driven and cash-pay, you likely need the former. If you bill insurance or prescribe electronically, you likely need both — and if you prescribe, check your state's rules.
Why "on one record" is the actual product, not a slogan
The automations are where "one record" stops being an architecture decision and starts being revenue. An appointment reminder, a text offering to rebook after a missed visit, a win-back text when a client hasn't been back in a while, a birthday message — each one fires off the record, because the record knows who's booked, who missed, and who's gone quiet.
Marketing works the same way. Segmenting by last visit, new clients, and the tags your team keeps only means something if the list is live — not a CSV someone exported last Tuesday and is already wrong about three clients.
Retention is growth in disguise. A CRM doesn't pay for itself by looking good on a sales call — it pays for itself on the win-back that goes out automatically because the system noticed before the front desk did. Paid ads are the expensive way to replace a client who should have been rebooked.
If compliance is a paid tier, the base product doesn't have it
If compliance is something you upgrade into, the base product was never built on it. It was retrofitted.
That's a real problem for a category that handles PHI by default. HIPAA architecture isn't a feature you bolt on later: each practice's records walled off from every other customer's, an append-only audit log of every PHI read, encryption in transit and at rest — the audit controls and encryption the HIPAA Security Rule asks for. That's the floor, not the ceiling, and a Business Associate Agreement should be in the standard contract at every tier — not reserved for whoever pays more.
To be precise about what that buys you: there's no guarantee to sell here, and we won't pretend otherwise. What you're building is a defensible, addressable posture — architecture and process that holds up if you're ever asked to show your work.
The sizing mistake: buying a salon tool, or buying an enterprise chain's tool
Buying up or down a size is the most common and most expensive mistake in choosing a CRM, and it runs in both directions.
Undersized: a salon-spa-first tool with no PHI handling and no real clinical charting, because it was built for haircuts and waxing, not neurotoxin and filler. It works until the day you need a defensible consent record or an audit trail on who read a chart, and then it doesn't work at all.
Oversized: an enterprise platform built for chains with dozens of locations, benchmarking across a national network, running payroll and inventory at a scale a solo injector will never touch. You pay for complexity you don't need and spend months configuring features aimed at a different business.
A tool built for a solo nurse injector and a tool built for a five-location group are almost never the same product — and we say that about our own lane too. We're built for solo injectors, single-location spas, practices adding providers and rooms, and small multi-location groups. Lumè is not the right call for a large enterprise chain. That's a different lane.
How do you compare medspa software pricing?
The headline price on any pricing page is close to meaningless on its own. The real number is usually built out of add-ons, not one line item. Forms cost extra. SMS marketing costs extra. A second location costs extra. A texting tool bought as a bolt-on runs its own monthly line, on top of whatever you're already paying for scheduling and charting.
That's the comparison that actually matters: total cost, not the sticker. In Lumè, forms and clinical notes ship in Starter at $149 a month. Our AI SMS agent is included in Pro at $349 a month, alongside the full CRM — not sold as a separate add-on. Pro includes 1,500 texts a month; beyond that, texts are billed per message. See pricing.
The AI SMS agent is part of the back office, not a chatbot bolt-on
Our AI SMS agent answers inbound texts and books against the real-time schedule — it reads live availability, provider hours, and which providers perform the service through structured, audited tool calls. It isn't guessing. It also isn't carrying PHI in its system prompt, by design.
Before anything goes out, a pre-send pattern scan checks for sequences that look like a Social Security number, a date of birth, or a payment card number. A match blocks the send and escalates to a person. Staff can pause any single conversation from the inbox without touching the rest of the system, there's a daily send cap, and anything clinical or payment-related escalates to a human rather than getting handled by text.
SMS itself isn't end-to-end encrypted. Keeping AI-generated texts to booking logistics is the correct boundary, not a missing feature.
The honest shortlist
Treat top-10 medspa CRM lists with care: many are written by a vendor on the list, or earn a referral fee from the tools they rank.
Use those lists to build a shortlist of names worth looking at. Then ignore the ranking entirely and judge each one against your own workflow: does it run all seven jobs off one record, is HIPAA architecture and a BAA built into every tier instead of sold as an upgrade, and is it sized for what you actually are — not a salon, not a chain. That's decided per practice, by what you actually bill, store, and transmit — not by a listicle.