๐Ÿš€ Decoda raises $4.5M, led by Y Combinator. Read more

Journal/Reference library
Updated September 4, 2026ยท10 min read
What Happens to Med Spa Patient Data During Migration September 2026

What Happens to Med Spa Patient Data During Migration September 2026

Find out what happens to patient records, photos, and balances during a med spa data migration. Updated September 2026.

Kevin Cheng
Co-Founder & CPO, Decoda Health

TL;DR

5 key points
  • 01Clinical notes and treatment photos transfer as static PDFs, not searchable records you can pull into new notes.
  • 02Credit card data cannot transfer due to PCI compliance; collect new cards from all active members before the next billing cycle.
  • 03A 1-3 week gap between your data pull and go-live means records created during that window won't exist in your new system without manual entry.
  • 04Require a signed BAA, encrypted transfer confirmation, and a post-migration audit log before any patient data leaves your current system.
  • 05Decoda Health manages the full transfer with a 3-4 week timeline from contract signing to go-live, with patient records remaining yours throughout.
Text size

What Med Spa Data Migration Actually Involves

A med spa data migration is a sequenced project with distinct phases, and skipping any one of them is where things fall apart.

The basic arc runs like this: audit your existing data, map it to the new system's structure, execute the transfer, validate accuracy, then go live. Each phase has its own failure modes. A botched audit means incomplete records arrive in the new system. Poor mapping means clinical notes land in the wrong fields. A rushed validation means you find the errors after patients are already through the door.

The scope is genuinely wide. You are moving patient demographics, clinical histories, treatment photos, signed consents, package balances, membership statuses, and appointment histories. Each of these lives in a different part of your current medical spa software and needs to arrive intact and correctly structured on the other side.

What Data Actually Transfers When You Switch EMR Systems

Structured data moves cleanly: patient demographics, contact details, appointment history, and basic billing records all exist as discrete database fields that translate well between systems.

Clinical notes, consent forms, and treatment photos are a different story. They typically arrive as PDFs or static file attachments, not editable, searchable records. Your new system can store them, but a provider can't search across them or pull them into a new note the way they could with natively created records.

Package balances and membership statuses sit somewhere in the middle. Dollar amounts and session counts usually transfer, but the rule logic behind them often doesn't. Plan to reconfigure how those balances behave in the new system on day one, including all membership billing rules.

Data Type

Transfer Outcome

What You Need to Do

Patient demographics & contact details

Transfers cleanly as structured database fields

Verify record count matches after import

Appointment history & billing records

Transfers cleanly as structured database fields

Spot-check a sample after migration closes

Clinical notes & consent forms

Arrives as static PDFs or file attachments; not searchable or editable

Store as reference files; rebuild templates natively in the new system

Treatment photos

Arrives as static file attachments

Attach to patient charts manually in the new system

Package balances & session counts

Dollar amounts and counts usually transfer; rule logic does not

Reconfigure all membership billing rules before first billing cycle

Credit card/payment tokens

Does not transfer (PCI compliance)

Collect new card-on-file details from all active members before next billing date

Note templates & intake form layouts

Does not transfer

Rebuild in new system before go-live

Third-party integrations (labs, loyalty, pharmacy)

Does not transfer

Reconnect each integration after go-live

What Typically Does Not Transfer

Payment credentials are the clearest case. Raw cardholder data may not be transferable due to PCI compliance, and stored tokens belong to your current processor rather than to you, so they rarely move either, a constraint that also affects high-risk med spa payment processing more broadly. For a practice with 200 active members, that means a manual card re-collection project before the next billing cycle.

Beyond payment data, expect to lose:

  • Custom intake form layouts and field configurations built inside the old system
  • Note templates, which need to be rebuilt in the new system before go-live
  • Third-party integration connections such as labs, loyalty programs, and compounding pharmacies
  • Telehealth session logs and any linked video records

Rebuilding templates before your first day live, not after, is what separates a functional first week from a chaotic one.

The Data Gap Between Your Migration Pull and Go-Live

Most migrations extract data from your old system at a fixed point in time. That snapshot becomes the dataset your new EMR is built on. But your practice keeps running between that extraction date and your actual go-live date, and every patient seen, every note written, and every package sold during that window only exists in the old system.

The gap is usually one to three weeks, which is long enough to accumulate meaningful activity that your new system won't have on launch day.

The fix is practical. Run both systems in parallel during that window, or freeze new clinical documentation in the old system and route it manually to the new one after go-live. A few specifics worth tracking:

  • New patients created after the data pull will need to be entered manually in the new system.
  • Appointments booked in the old system need to be mirrored into the new calendar before go-live.
  • Any package or med spa membership sold during the gap needs a corresponding balance entry in the new system on day one.
  • Clinical notes written after the pull date should be exported and attached to the patient's chart in the new system.

Ask your migration team exactly when the data pull occurs and what the handoff protocol is for records created after that date. If the vendor has no clear answer, that's a process gap worth pressing on before you sign.

HIPAA Compliance During a Med Spa EMR Migration

Before a single patient record moves, four HIPAA requirements apply regardless of which medspa EHR software systems are involved.

The receiving vendor must sign a Business Associate Agreement. Without it, handing over PHI is a HIPAA violation even if the migration goes perfectly. Verify this before the data pull is scheduled.

As HIPAA-compliant EHR migration guidance makes clear, you also need end-to-end encryption, rigorous identity and access management, and complete audit documentation covering who accessed or moved PHI at every step. Ask your vendor what gets logged and whether you can request that audit trail after migration closes.

The Minimum Necessary Standard applies here too. Only staff who need access to complete the migration should have it. If a third-party migration vendor is involved, their access should be scoped to exactly what the transfer requires and revoked when it ends.

For practice owners without a technical background, the practical checklist is short:

  • BAA signed before data export begins
  • Written confirmation that data is encrypted in transit and at rest
  • A named point of contact responsible for access controls during the migration window
  • A post-migration audit log you can retain for your records

Any vendor unwilling to answer these questions directly is a vendor worth reconsidering.

Data Security Risks to Understand Before You Migrate

The migration window is one of the riskier periods in a practice's data lifecycle. Patient records are in motion, access is temporarily wider than usual, and a vendor's security controls are doing more work than they normally would.

Healthcare breaches averaged $7.42 million each in 2025, the highest of any industry for 14 consecutive years (IBM). Practices already managing med spa adverse event reporting requirements face compounded compliance exposure during migration, and breaches take an average of 279 days to identify and contain. A breach during migration is harder to detect because data movement looks normal.

Before the data pull starts, get clear answers on these four points:

  • Is data encrypted in transit and at rest during the transfer?
  • Who holds credential access during the migration window, and when exactly is it revoked?
  • Does the vendor carry cyber liability insurance?
  • Will you receive a post-migration audit log?

Treat any vague answer as a gap to resolve first.

How to Audit Your Data Before Migration Starts

Categorize before you export. Sort records by type: demographics, clinical notes, imaging, billing (including records tied to office-based surgery rules). Identify which are active versus archived and flag anything stored in non-standard formats. Skipping this step is how practices find out mid-migration that a share of their records are duplicates or in a format the new system can't read.

Check your export formats early. Most systems offer CSV for structured data, PDF for documents, and sometimes CCD/CCDA or FHIR for clinical records. Your new vendor needs to confirm which they can ingest before the pull happens.

A pre-migration audit should cover:

  • Active vs. archived patients, since archived records may only need PDF storage instead of a full structured import
  • Duplicate patient profiles that need merging before export
  • Clinical notes or consents stored as scanned images instead of text
  • Any records flagged incomplete that should be resolved in the old system first

Questions to Ask Any EMR Vendor About Data Portability

Vendor promises sound identical until you ask the wrong question. Data portability reveals more about a vendor's intentions than any feature demo. A few direct questions, asked before signing, will tell you whether your data is treated as yours or as collateral.

Here are the questions worth asking every EMR vendor before you commit:

  • Is data export included in the contract, or billed separately? Some vendors charge thousands of dollars to release records when you leave. Get the answer in writing.
  • What formats does the export support? Ask for CSV for structured data, PDF for documents, and whether FHIR or CCD is available for clinical records.
  • Do historical records remain accessible after migration closes? Some systems archive older records in formats your new vendor can't ingest.
  • How long does the vendor retain your data after the contract ends, and at what cost?
  • Are there exit fees tied to data release, or clauses that delay export until invoices are settled?

If a vendor hedges on any of these, that's the answer. Data portability language written explicitly into a contract is a trust signal worth requiring, not requesting, much like reviewing state med spa registration requirements before committing to a new practice structure.

The Med Spa Migration Checklist

Before running a single export, it helps to have a clear sequence of what needs to happen and when. The three phases below cover what to do before the data moves, during the gap window, and once you're live.

Pre-Migration

  • Pull a full patient record count from your current system and confirm it matches what the new vendor receives after the export.
  • Categorize records by type: demographics, clinical notes, treatment photos, consents, billing history.
  • Merge duplicate patient profiles before export, not after.
  • Confirm the receiving vendor has signed a BAA before any data leaves your system.
  • Create a complete backup of your data independently, separate from whatever the vendor pulls.
  • Document all active membership rules, session balances, package configurations, and medication inventory records so you can rebuild them on the other side.

During Migration

  • Review the data mapping your vendor proposes before approving the pull; verify that clinical note fields are landing in the right locations.
  • Record the exact date and time of the data extract so your team knows which records fall into the gap window.
  • Keep a manual log of every patient seen, note written, and package sold between the pull date and go-live.
  • Maintain read access to the old system through go-live so providers can reference records created after the pull date.
  • Mirror any appointments booked in the old system into the new calendar before the first day live.

Post-Migration

  • Run a record count comparison: total patients, total appointments, and total open package balances in the old system versus the new one. These figures also serve as baseline med spa KPI tracking benchmarks going forward.
  • Spot-check a sample of clinical notes to confirm they arrived intact and are attached to the correct patient profiles.
  • Rebuild all note templates and intake form configurations before the first appointment.
  • Collect new cards from all active members before the next billing date; a missed cycle creates immediate revenue disruption.
  • Verify that membership billing rules are configured correctly in the new system before the next billing date hits.
  • Complete staff training on the new system before go-live, not during the first week of live appointments.

How Decoda Health Handles Migration for Elective-Care Practices

Migration fear is the most common objection we hear from independent practice owners considering a switch. The concern is legitimate: the checklist above is long, and most owners have been burned by a vendor who made things sound simple before they fell apart.

Decoda Health manages the full transfer: data migration, appointment setup, and team training, with a 3- to 4-week timeline from contract signing to go-live. One caveat worth planning around: credit card information cannot be transferred due to PCI compliance constraints. Any practice with active members needs to collect new card-on-file details before the next billing date. We flag this early so it never surfaces mid-cycle.

Your patient records are yours, always. Several practices have come to us after finding out their previous vendor charged to release data or delayed exports until outstanding invoices were settled. That is not how we operate.

Final Thoughts on EMR Data Portability for Med Spas

Your patient data belongs to you, and any vendor worth working with treats it that way. A well-run migration comes down to asking the right questions early, filling the gap window carefully, and rebuilding templates before your first live appointment. Book an intro call with Decoda Health if you want to see how the process works in practice.

Frequently Asked Questions

Will my patient records, treatment photos, and package balances actually transfer when I switch EMR systems?

Structured records โ€” demographics, appointment history, billing โ€” transfer cleanly. Treatment photos and clinical notes typically arrive as PDFs or static attachments rather than searchable, editable records. Package balances and session counts usually carry over, but the rule logic behind them needs to be rebuilt in the new system before your first billing cycle runs.

What happens to patient data created between the migration pull date and my go-live date?

The data pull captures a snapshot of your records at one fixed moment, and your practice keeps running for one to three weeks after that. Every patient seen, note written, or package sold during that window only exists in the old system. Track those records in a manual log and mirror appointments into the new calendar before day one โ€” or keep read access to the old system through go-live so providers can reference records that fall into the gap.

How do I know if my med spa data migration is HIPAA compliant?

Four requirements apply before any patient records move: the receiving vendor must sign a Business Associate Agreement, data must be encrypted in transit and at rest, access during the migration window must be scoped to only the staff who need it, and a full audit log must be available after the transfer closes. Get written confirmation on all four before the data pull is scheduled.

What's on a medical spa migration checklist before the data export begins?

Run a full patient record count, merge duplicate profiles, categorize records by type (demographics, clinical notes, photos, consents, billing), document all active membership rules and package balances, create an independent backup separate from the vendor's pull, and confirm the BAA is signed. Do this before the export โ€” not after โ€” because errors discovered mid-migration are significantly harder to fix.

Can I migrate patient records from AestheticsPro or Zenoti to a new EMR without losing membership and payment data?

Membership session counts and dollar balances typically transfer, but payment tokens from your old processor do not move due to PCI compliance constraints. For any practice with active members on AestheticsPro, Zenoti, or any other system, plan a manual card re-collection project before the next billing date. Membership rule logic also needs to be reconfigured in the new system rather than imported โ€” document every active plan configuration before the export so you can rebuild accurately on day one.

How long does a med spa data migration actually take from contract signing to go-live?

Most practices reach go-live within 3 to 4 weeks from contract signing when a vendor manages the full migration. The timeline depends on record volume, how many active memberships need reconfiguration, and whether your current system exports structured data or only PDFs.

If I leave my current EMR, can they charge me to release my patient data?

Some vendors include data export fees or delay releases until outstanding invoices are cleared โ€” and they can enforce this if it's written into your contract. Before signing with any EMR, ask in writing whether data export is included, what formats are supported, and whether exit fees apply to data release.

What export formats should I ask my current EMR to provide before switching?

Request CSV files for structured data like demographics and billing, PDFs for clinical notes and consents, and ask whether FHIR or CCD export is available for clinical records. Confirming format compatibility with your receiving vendor before the pull prevents the situation where data arrives in a format the new system can't read.

Do I need to retrain my entire staff when migrating to a new med spa EMR?

Staff training should be completed before your first live appointment, not during the first week of seeing patients. A well-run migration includes scheduled training sessions in the new system while the old one is still running, so the team is ready on day one rather than learning mid-shift.

What should I do about active memberships and billing cycles during an EMR switch?

Document every active membership plan, including billing frequency, session balances, and rollover rules, before the data export runs. Membership rule logic does not carry over automatically โ€” it needs to be rebuilt in the new system โ€” and a missed billing cycle creates immediate revenue disruption for your members.

Is it possible to migrate patient photos and before-and-after images to a new EMR, and will they stay linked to the right charts?

Treatment photos typically migrate as static file attachments rather than natively structured records. They can be stored in the new system, but verifying that each image is attached to the correct patient profile is a post-migration audit step that should not be skipped โ€” a sample spot-check of patient photos against their charts catches mismatches before a provider encounters them during a visit.

What's the best way to handle the data gap window when my practice is still seeing patients between the migration pull and go-live?

Keep a manual log of every patient seen, note written, and package sold between the extraction date and go-live. Maintain read access to the old system through launch day so providers can reference records from that window, and mirror any appointments booked in the old system into the new calendar before the first day live.

Should I be worried about data security risks during an EMR migration?

The migration window is one of the higher-risk periods in a practice's data lifecycle because records are in motion and access is temporarily wider than normal. Before the data pull starts, confirm that data is encrypted in transit and at rest, get a clear answer on who holds credential access and when it's revoked, and request a post-migration audit log you can retain for your own records.

How do I verify that all my patient records actually arrived correctly after the migration is complete?

Run a record count comparison between the old system and the new one, covering total patients, total appointments, and all open package balances. Then spot-check a sample of clinical notes to confirm they arrived intact and are attached to the right profiles. These steps catch the most common migration errors before a provider or front desk team member stumbles across them during a live appointment.

What happens to my note templates and intake forms when I switch EMR systems?

Note templates and intake form configurations do not migrate โ€” they need to be rebuilt from scratch in the new system. Rebuilding them before your first appointment is one of the most practical things you can do to avoid a chaotic first week, since providers without their standard templates will either skip documentation or improvise, both of which create problems downstream.