Our Commitment
AestheticSuite is built for healthcare. Protecting the confidentiality, integrity, and availability of protected health information (“PHI”) is central to how we design, operate, and maintain the platform. This page summarizes the safeguards we apply under the Health Insurance Portability and Accountability Act of 1996 (“HIPAA”) and the HITECH Act.
Our Role as a Business Associate
When a practice uses AestheticSuite to process the health information of its patients, the practice is the “covered entity” and AestheticSuite acts as its “business associate.” We enter into a Business Associate Agreement (“BAA”) with each practice that processes PHI through the Service, and we use and disclose PHI only as permitted by that agreement and applicable law. A BAA is available to practices on request.
Administrative Safeguards
- Documented security policies and assigned responsibility for information security.
- Workforce training on privacy and security, with access granted on a least-privilege, need-to-know basis.
- Periodic risk assessments and a defined process for responding to security incidents.
- Due-diligence and written agreements with subprocessors that may handle PHI.
Technical Safeguards
- Encryption of PHI in transit (TLS) and at rest.
- Role-based access controls and authentication to limit access to authorized users.
- Audit logging of access to and activity involving sensitive records.
- Automatic safeguards against unauthorized access, including monitoring and alerting.
Certifications & Standards
EPCS — Electronic Prescribing of Controlled Substances. AestheticSuite’s controlled-substance e-prescribing is delivered through an integration with DoseSpot 8.0, a Drummond Group–certified EPCS module. In June 2026, Drummond Group completed an integration review of AestheticSuite (v6.2026) and concluded the application meets the intent of 21 CFR § 1311 and can be used for the creation and electronic transmission of controlled-substance prescriptions — across identity proofing, two-factor authentication for signing, logical access controls, audit trails, and reporting.

Drummond Group’s integration review is not a legal determination of certification; practices remain responsible for following 21 CFR § 1311 in their own operations.
Physical Safeguards
The Service is hosted with established cloud infrastructure providers whose data centers maintain physical security controls and industry certifications. Access to production systems is restricted and monitored.
Breach Notification
We maintain procedures to detect, investigate, and respond to security incidents. In the event of a breach of unsecured PHI, we will notify the affected practice without unreasonable delay and in accordance with our BAA and applicable law, so the practice can meet its notification obligations.
Patient Rights
Patients have rights under HIPAA regarding their health information, including rights to access and request amendments. Because AestheticSuite processes PHI on behalf of practices, patients should direct such requests to the practice that provides their care. We support practices in responding to valid requests.
Subprocessors
We engage a limited set of vetted vendors (for example, infrastructure hosting, transactional email, and error monitoring) to operate the Service. Where a subprocessor may handle PHI, we require a Business Associate Agreement and appropriate safeguards.
Reporting a Concern
To request a Business Associate Agreement, report a security concern, or ask about our HIPAA practices, contact us at concierge@aestheticsuite.ai or through our contact page. For details on how we handle information generally, see our Privacy Policy.