Spa Software vs. Medspa Software: The Line Nobody Draws for You

Mindbody and a medspa CRM look similar on a demo call, but one was built for facials and one was built for PHI. The line between them isn't revenue or square footage — it's whether anyone in your building injects, charts a treatment, or captures a signed consent.

The Lumè team6 min read

Does anyone in your building inject, chart a treatment, or capture a signed consent for a procedure? If yes, you're generating PHI — protected health information — the moment that happens, regardless of whether you bill insurance, write prescriptions, or call yourself a medical practice. Treatment charting, dosages and lot numbers on the record, versioned consent — these are the markers. If none of that happens in your building, you're a salon-spa, full stop, and the ranking pages written for medspas aren't written for you.

Spa Management Software Is Salon-First — And That's Fine

Tools like Mindbody and Vagaro are built for day-spa and salon workflows — facials, waxing, hair, massage — and they're good at that job. Booking volume, calendar density, retail checkout: that's what they're optimized for.

None of these platforms were built around PHI, because the services they're built for don't generate any. A facial doesn't need a dosage logged. A haircut doesn't need a signed consent form with a device ID and timestamp attached to it. If that's your business, buying anything heavier is buying weight you don't need. The mistake isn't using salon software. The mistake is using it after your services start creating PHI.

Medical Spa Software Is the Same Backbone, Plus Clinical Depth

Medspa software keeps the scheduling, payments, and marketing backbone a salon tool has, and adds the layer a salon tool was never built to carry. Concretely, that means a single client record carrying treatment history, provider notes, dosages and lot numbers where relevant, and before/after photos — all on the same record as the booking and the invoice, not in a separate system you're reconciling by hand.

It means versioned e-signed consent — capturing name, timestamp, device or IP, and the exact form version signed — auto-sent on booking and stored on the chart, so you're not chasing a paper form before a neurotoxin appointment.

And it means HIPAA architecture underneath all of it: client data kept separate per spa, an append-only audit log on every PHI read, encryption in transit and at rest.

Clinical charting is not a certified EHR. A handful of practices write prescriptions and operate as full medical clinics — they need a certified EHR alongside whatever CRM they run. Most independent and small medspas don't live there. They live in between, and the software built for that middle ground is a different product than either a salon tool or a hospital EMR.

Why You End Up Looking at Mindbody, Vagaro, or Zenoti First

Search "best medspa software" and you'll land on a top-10 list almost every time. Most of those lists are advertising. Placement correlates with referral fees, not fit. Use them to build a shortlist if you want, then ignore the ranking entirely and judge each platform against your own workflow — the right tool for a solo nurse injector and the right tool for a five-location group are rarely the same product, no matter what order the list puts them in.

The Honest Signal You've Outgrown It

Forget the feature-grid checklist. The tell is this: you're holding PHI, running consent, and needing an audit trail a salon tool wasn't built to carry. If you're logging dosages and lot numbers on a chart, attaching before/after photos to a client record, and you can't tell a regulator who read a given client's chart and when — that gap is the signal. An append-only audit log on every PHI read is exactly the kind of piece a tool built for salons has no reason to include. Its customers never needed it.

If HIPAA Is a Paid Upgrade, the Base Product Doesn't Have It

Here's an opinion we'll say plainly because nobody else will: if compliance sits behind a paid tier, the base product doesn't have it. HIPAA and a BAA should be the floor, not an enterprise upgrade you chase once you can afford it. Tenant isolation and audit logging are structural decisions made on day one — not toggles flipped for customers on a higher plan.

That's why Lumè includes a Business Associate Agreement in the standard contract at every tier, and why the HIPAA architecture — tenant isolation, append-only audit log, encryption in transit and at rest — isn't gated to a higher plan. It's the floor every customer stands on, whether they're a solo injector or a small multi-location group.

No, You're Not Automatically Exempt Because You Don't Bill Insurance

Most medspas hear "HIPAA" and assume it doesn't apply to them because they don't file insurance claims. That's half a story. HIPAA applies to covered entities, and whether you are one turns on the health care transactions you conduct electronically, not only on insurance claims. State privacy laws can reach further than federal HIPAA itself.

We're not going to promise you a blanket legal guarantee, because no software vendor honestly can. What we can tell you is what a defensible, addressable posture looks like: a BAA, an append-only audit trail, and encryption in transit and at rest. That's the standard we build to. Whether it satisfies your specific state's overlay is a conversation for your attorney — the architecture underneath it isn't optional either way.

Who Is Each One Actually Built For?

Lumè is built for independent and small multi-location medspas — solo nurse injectors, single-location spas, growing practices adding providers and rooms, small multi-location groups. If you're a large enterprise chain, Zenoti is the right lane for that scale of problem — not ours.

The most common and most expensive mistake in choosing a CRM is buying a size up or down from your actual stage: a solo injector paying for reporting built for six locations, or a growing practice trying to force a single-location tool to hold several providers' schedules and a membership program.

Total Cost, Not the Sticker

The number on a pricing page is rarely the number you pay. Add the seats, the processing rate, the compliance tier you actually need, and "starting price" moves.

Broadly, medspa CRMs run from around $100/month for a single-location starter tier up to $600+/month for multi-location plans with AI and marketing bundled in. Standalone AI texting tools complicate the math further — Podium runs roughly $400–$600/month as an add-on layered on top of whatever CRM you're already paying for. Lumè's Pro tier is $349/month and includes the AI SMS agent alongside the full CRM, not a separate line item stacked on top. Compare the total system cost, not the headline number on the cheapest tier.

Six Questions to Ask Any Vendor Calling Itself "Medspa Software"

Before you sign anything, make the vendor answer these out loud:

  1. Is a BAA standard at every tier, or a paid add-on?
  2. Is there an append-only audit log on every PHI read?
  3. Is consent versioned and e-signed, capturing device or IP and timestamp?
  4. Does scheduling respect provider service eligibility, or can anyone book anything with anyone?
  5. If there's an AI agent, does it run a PHI-free system prompt with pre-send pattern scanning and human escalation?
  6. Is the quoted price the floor tier, or the total cost of actually running your practice on it?

Most vendors will answer four of these cleanly and go vague on the other two. The vague answers are the ones worth pushing on.

Frequently asked questions

How do I know if I need medspa software instead of salon software?
The test is PHI, not revenue or location count. If anyone in your business charts a treatment, logs a dosage or lot number, or captures a signed procedure consent, you're generating protected health information and need software built to carry it — regardless of whether you bill insurance or call yourself a medical practice.
Can I keep using Mindbody or Vagaro if I start offering injectables?
You can, but you'll be storing PHI — dosages, lot numbers, signed consents, before/after photos — in a system that wasn't built with HIPAA architecture, tenant isolation, or audit logging underneath it. The mistake isn't using salon software for salon services; it's continuing to use it once your services start generating PHI.
Does HIPAA apply to a medspa that only accepts cash payments?
It can. Not billing insurance doesn't automatically exempt a practice: HIPAA applies to covered entities, and that turns on whether you conduct certain health care transactions electronically, not only on insurance claims. State privacy laws can reach further than federal HIPAA. Confirm your status with a healthcare attorney.
Is a Business Associate Agreement (BAA) something I should have to pay extra for?
No. A BAA and core HIPAA architecture — tenant isolation, encryption, audit logging — should be included at every pricing tier, not gated behind an enterprise upgrade. If a vendor charges extra for compliance, that's a signal the base product wasn't built with it from day one.
What should I actually compare when evaluating medspa software pricing?
Compare total system cost, not the headline number on the cheapest tier. Factor in seats, payment processing rates, and whether compliance and AI features are included or sold as separate add-ons — standalone AI texting tools alone can add $400-$600/month on top of a base CRM subscription.
A 30-minute demo

See Lumè in action.

Get a personalized walkthrough using your real services, staff, and workflows. Plans start at $149 a month.

One business day to a calendar invite.