Good faith exam records stay HIPAA compliant when they're encrypted at rest and in transit, stored behind unique staff logins with minimum-necessary access, backed by a signed Business Associate Agreement with every vendor who touches the file, and retained on a schedule your state medical board actually requires. The part most medspas miss isn't the exam itself — it's what happens to the chart afterward, especially when a chart reviewer, a collaborating physician, or a telehealth platform is in the loop.
- Good faith exam HIPAA compliance in 2026 rests on encryption, access logs, and a signed BAA with every vendor touching the record.
- Telehealth good faith exams carry extra documentation risk because the record crosses more systems than an in-person visit.
- State retention rules, not HIPAA itself, usually set how long you keep a good faith exam chart — often 5 to 10 years.
- US Medical Directors builds chart review and documentation workflows that hold up under a state board audit.
Why this matters
A good faith exam is the physical assessment that has to happen before a nurse or injector can legally provide certain aesthetic treatments in most states. The exam creates a medical record the moment it's documented, and that record falls under HIPAA the second it includes identifiable patient health information — name, diagnosis, treatment plan, photos.
Medspas get flagged less often for the exam itself and more often for how the resulting chart is stored, shared, or forgotten in an old spreadsheet or unsecured email thread. A HIPAA violation tied to a good faith exam record usually starts with a storage shortcut, not a bad exam.
How do you keep good faith exam records HIPAA compliant?
You keep good faith exam records HIPAA compliant by treating them exactly like any other protected health information: encrypted storage, controlled access, a documented retention schedule, and a signed agreement with anyone outside your practice who reviews or stores the file. The table below breaks down each requirement against what it actually looks like in day-to-day medspa operations in 2026.
| HIPAA requirement | What it means for good faith exam records | Common gap |
|---|---|---|
| Encryption at rest and in transit | Charts stored in an EHR or encrypted cloud folder, never plain email or shared drives | Emailing signed exam forms as unencrypted PDFs |
| Minimum necessary access | Only staff who need the chart for treatment or billing can open it | Front desk staff with full read access to clinical notes |
| Business Associate Agreement | Signed BAA with the chart review service and every software vendor holding PHI | Telehealth exam vendor with no BAA on file |
| Audit logging | System tracks who viewed or edited the record and when | Shared logins with no individual audit trail |
| Retention schedule | Records kept per state medical board rules, not deleted early | No written policy, records lost at software migration |
Getting telehealth good faith exam documentation right matters more than in-person exams here, because the record typically moves through a video platform, an EHR, and a reviewing physician's inbox — three separate systems where a BAA gap can exist.
Where good faith exam records break HIPAA compliance most often
A handful of failure points show up again and again:
- Unsecured file sharing — sending signed exam PDFs by regular email instead of a HIPAA-compliant portal
- No BAA with the exam software vendor — a telehealth or e-signature platform storing PHI without a contract in place
- Shared logins — one front desk account used by three staff members, which kills your audit trail
- No retention policy — records deleted or lost during a software switch instead of migrated under a written plan
- Chart reviewers without agreements — a contracted reviewer accessing charts with no BAA on file
Each of these is a documentation problem, not a clinical one — which is exactly why they're fixable with a better workflow instead of more training.
Why HIPAA requirements vary by state and by practice
HIPAA sets the floor, but how you meet it depends on several practice-specific factors:
- State medical board retention rules — some states require 5 years, others up to 10, and minors' records often need to be kept longer
- Whether you use telehealth for the exam — more systems in the chain means more BAAs to track
- Number of locations — multi-location medspas need identical access controls at every site, not just the flagship
- Whether a third-party chart reviewer is involved — chart review documentation has to show who reviewed what and when, separate from the exam record itself
- Your EHR vendor's own posture — not every EHR marketed to medspas signs a BAA by default
- Staff turnover — access gets revoked the day someone leaves, not at the next audit
Verdict: if your good faith exam records live in more than one system — telehealth platform, EHR, chart reviewer inbox — you need a written map of every BAA in that chain, or you're carrying HIPAA risk you can't see.
“A HIPAA violation tied to a good faith exam record usually starts with a storage shortcut, not a bad exam.”
Do you need a Business Associate Agreement with your good faith exam software vendor?
Yes, a Business Associate Agreement is required with any vendor that stores, transmits, or processes good faith exam records containing PHI. That includes telehealth platforms, e-signature tools, cloud storage, and third-party chart review services — not just your primary EHR.
How long do you have to keep good faith exam records?
Most states require 5 to 10 years of retention for adult patient records in 2026, with longer periods common for minors. HIPAA itself doesn't set a federal retention length for most providers — your state medical board's rule governs the timeline, so check it directly rather than assuming a default.
Can a chart reviewer access good faith exam records under HIPAA?
A chart reviewer can access good faith exam records only under a signed BAA that defines what they can view, for how long, and for what purpose. Without that agreement, sharing the chart for review creates a HIPAA gap regardless of how careful the review process looks otherwise.
This is where a medical director program earns its keep. US Medical Directors structures chart review and good faith exam oversight with documented access and signed agreements built in, so the paperwork holds up if a state board asks to see it in 2026 — worth reviewing alongside your own good faith exam compliance requirements.
Get your records audit-ready
Medical director oversight built around documented, HIPAA-compliant chart workflows.
FAQ
What makes a good faith exam record HIPAA compliant?
A good faith exam record is HIPAA compliant when it’s encrypted, access-controlled, backed by a signed BAA with every vendor involved, and retained per your state’s schedule. Missing any one of these creates exposure even if the exam itself was done correctly.
Is email an acceptable way to send good faith exam records?
Standard email is not HIPAA compliant for sending good faith exam records unless it is encrypted end-to-end through a compliant portal. Plain email transmission of signed exam forms is one of the most common gaps found in medspa record handling.
Do telehealth good faith exams carry more HIPAA risk than in-person exams?
Telehealth good faith exams carry more HIPAA risk because the record typically passes through a video platform, an EHR, and a reviewing physician’s system, tripling the number of BAAs that need to be in place. In-person exams usually involve fewer systems and fewer gaps.
How long should a medspa keep good faith exam records?
A medspa should keep good faith exam records for roughly 5 to 10 years depending on the state, with longer retention typically required for minors. The exact number comes from your state medical board, not from HIPAA itself.
Does a collaborating physician need a BAA to review good faith exam charts?
Yes, a collaborating physician needs a signed BAA if they’re accessing good faith exam charts stored in a system separate from their own practice’s records. The same requirement applies to any third-party chart reviewer.
What happens if a good faith exam record is stored without encryption?
Storing a good faith exam record without encryption is a compliance failure regardless of whether a breach ever occurs, because HIPAA is about safeguards in place, not just outcomes. It is one of the first things flagged in a 2026 records review.
Can staff share one login to access good faith exam records?
Shared logins for good faith exam records break the minimum-necessary and audit-logging principles under HIPAA, since there’s no way to trace who viewed or edited a chart. Every staff member needs an individual, role-based login.
Who is responsible if a good faith exam record is breached?
The practice holding the record is responsible as the covered entity, and the vendor is responsible as a business associate if a BAA exists. Without a BAA, the practice absorbs the full exposure on its own.
One last thing
The fastest way to fail a records review on good faith exams isn't a missing signature — it's a software switch done without a written data migration and BAA transfer plan. Records get orphaned in the old system, access controls reset incorrectly, or a vendor agreement lapses mid-transition, and nobody notices until an inspector asks for a chart from 18 months ago. Write the migration plan before you sign the new software contract, not after.
Related guides
- How to transition good faith exam records during a software switch
- Good faith exams for medspas
- How to prepare for a state board inspection with your medical director



