A second location is the clearest signal that your MedSpa is winning. It is also the moment your technology decisions stop being background details and start determining whether the brand you built survives its own growth. The industry is expanding at a pace that rewards fast movers: AmSpa counted 10,488 med spas in the United States in 2023, up from 8,899 the year before, with average revenue per location climbing toward $1.4 million. Expansion capital is chasing that growth. What is not expanding at the same rate is the attention owners give to the systems that hold client photos, treatment histories, payment data, and health records across multiple sites.
We work with MedSpa owners through this exact transition, and the pattern repeats. The operational plan for location two is detailed down to the treatment menu and the injector schedule. The IT plan is a paragraph. We wrote about the bigger strategic picture in MedSpa Growth: Scaling to Multiple Locations Without Losing Sight of Security. This post is the working checklist that belongs beside your lease paperwork: ten questions to answer honestly before opening day, so you never have to fund the expensive rework that surprises multi-site operators six months in.
Why a Second Location Changes Your Risk Profile
At one location, informal IT can limp along. One practice management system, one internet connection, one person who knows the WiFi password. A second site multiplies every one of those informal arrangements and connects them, which means a weakness at either location becomes a weakness at both.
The stakes are not abstract. Healthcare has been the most expensive industry for data breaches for 14 consecutive years, with an average cost of $7.42 million per incident and 279 days to identify and contain, according to IBM's Cost of a Data Breach Report 2025. A two-location MedSpa will never pay the headline number, but the same cost categories scale down with brutal efficiency: notification, forensics, legal fees, regulatory exposure, and client churn. We walked through the itemized math for a small practice and the total lands well into six figures for practices a fraction of your size.
MedSpas carry an extra burden that the averages miss. Your clients chose you partly for discretion. Before-and-after photos, aesthetic treatment records, and payment histories are exactly the data people least want exposed. For a MedSpa, a breach is a brand event before it is an IT event.

The Ten Questions
1. Who actually owns our IT environment today?
Before you replicate an environment, document it. Who holds the administrator credentials for your practice management platform? Who can log into the firewall? Where do backups live and who has tested a restore? Many single-site MedSpas cannot answer these questions because the environment grew organically around whoever was helpful at the time. If you cannot name the owner of every administrative credential at one site, you are not ready to double the footprint. Write the inventory first. Everything else in this audit depends on it.
2. Do our practice management and EHR platforms support true multi-site access controls?
Multi-location mode is not just a second calendar. Your platform needs role-based access that can scope what each employee sees by role and by location, because HIPAA's minimum necessary standard does not pause while you scale. Run one test: should the front desk at the new site be able to open the complete treatment history and photo set of a client who has only ever visited your original location? If the software cannot enforce your answer, you have a platform decision to make before you have a grand opening to plan.
3. How will client data move between locations, and does that movement create new exposure?
A shared cloud platform with per-location controls is a defensible architecture. Staff texting client photos between sites because the systems do not talk to each other is not. Map every path client data will take between locations, then check each path against the HIPAA Security Rule's technical safeguards. We published a plain-language breakdown of all 18 technical safeguard specifications that works well as the reference document for this exercise.
4. Is each site's network designed or inherited?
Guest WiFi, laser and imaging equipment, payment terminals, and business systems should live on separate network segments so that a compromise of one cannot reach the others. Most single-site practices run flat networks where everything can see everything, and flat networks are how one infected device at location one becomes location two's problem by lunchtime. The segmentation principles we laid out for multi-site physician groups apply directly to a growing MedSpa, and they are far cheaper to implement during a buildout than after one.
5. Do we hold a business associate agreement with every vendor that touches client data?
Practice management software, cloud storage, marketing automation, VoIP, your IT provider: if a vendor creates, receives, maintains, or transmits protected health information on your behalf, HIPAA requires a business associate agreement, and a second location almost always adds vendors to the list. A BAA is the legal floor, not a risk program, a distinction we unpacked in BAAs and Vendor Risk: The Healthcare MSP's Obligations. Audit the list now, because discovering a missing BAA during a breach investigation is the worst possible time.
6. What happens at the new site on day one when something breaks?
Openings stress systems. The booking platform gets hammered, the payment terminal meets the new internet circuit for the first time, and the staff is too busy to troubleshoot. Decide in advance what happens when the internet drops mid-appointment or the scheduling system stalls: who gets called, what runs on paper, and how long you can operate degraded. That is a business continuity plan in miniature, and it is also why a structured new site activation process beats improvising with whoever wired the last tenant's space.
7. How do we onboard and offboard staff across two locations?
Injectors and estheticians will float between sites, and shared logins are the failure mode that follows them. Every staff member needs unique credentials with multi-factor authentication on anything touching client data, and offboarding must revoke access at both locations the same day someone departs. Write the checklist before you hire for the new site. Two locations mean more staff, more turnover, and more chances for a former employee's still-active login to become your incident report.
8. Are we ready for where the HIPAA Security Rule is heading?
In January 2025, HHS proposed the most significant update to the HIPAA Security Rule in two decades: mandatory multi-factor authentication, mandatory encryption of ePHI at rest and in transit, and a required written asset inventory with a network map. The rule is not final as of mid-2026, but the direction is unmistakable. Building your second location to the proposed standard now costs far less than retrofitting two locations later, and it puts you ahead of competitors who are waiting to be forced.
9. Does location two change our cyber insurance answers?
Your carrier priced your policy on the answers you gave about MFA, endpoint protection, backups, and staff counts. A second location changes those answers, and inaccurate application responses are grounds for claim denial exactly when you need coverage most. Notify your carrier, re-verify every control at both sites, and treat the renewal questionnaire as a security audit someone else was kind enough to write. Our guide to what underwriters now expect from healthcare practices shows which controls actually move premiums.
10. Who is accountable for security once we are a multi-site brand?
Somebody has to own this by name. At one location, the owner absorbs IT decisions between client appointments. At two, that stops working, and the gap between locations is exactly where accountability dissolves. Your realistic options are a dedicated hire, which few MedSpas can justify, or a managed partner with healthcare compliance readiness built into the engagement. Whichever you choose, choose before opening day. Security without an owner is a policy without a practice.
What to Do With Your Answers
Score yourself honestly. If three or more of these questions came back as some version of I do not know, the fix is a pre-expansion IT audit, not a longer to-do list for your office manager. The findings typically pay for themselves before the new lease starts, because correcting architecture on paper is cheap and correcting it across two live locations is not.
Techvera runs exactly these audits for healthcare practices across Dallas-Fort Worth and New York City, and we build the remediation plan around your opening date rather than our convenience. Schedule a consultation and bring your answers to these ten questions. The second location should multiply your revenue, not your risk.
Frequently Asked MedSpa IT Questions
Do med spas have to comply with HIPAA?
In most cases, yes. A MedSpa providing medical treatments under provider oversight creates protected health information, and once it transmits health data electronically for covered transactions it falls under the HIPAA Security Rule. State law can reach further: Texas HB300, for example, applies a broader covered entity definition than the federal baseline. The safe operating assumption is that treatment records, photos, and health histories are regulated data.
When should a MedSpa get an IT audit?
Three moments justify one: before opening an additional location, before a cyber insurance application or renewal, and after a turnover in whoever manages your technology. Expansion is the most important of the three because architectural decisions made during a buildout are inexpensive to change on paper and expensive to change across two operating sites.
What is the most common IT mistake multi-location med spas make?
Replicating the first location's informal setup instead of designing for two sites: flat networks where every device can reach every other, shared staff logins that follow employees between locations, and vendor lists without business associate agreements. Each is cheap to fix before opening day and costly to fix after an incident forces the issue.
About the Author
Team Techvera
Techvera Team
Articles written collaboratively by the Techvera team, combining expertise across cybersecurity, managed services, and digital transformation.
