๐Ÿš€ Decoda raises $4.5M, led by Y Combinator. Read more

Journal/Reference library
Updated August 25, 2026ยท7 min read
NY's 223-Inspection Med Spa Sweep: Key Signals for Operators Aug 2026

NY's 223-Inspection Med Spa Sweep: Key Signals for Operators Aug 2026

NY's med spa enforcement sweep cited 87 operators for violations. Learn what documentation failures put practices at risk as of August 2026.

Kevin Cheng
Co-Founder & CPO, Decoda Health

TL;DR

5 key points
  • 01New York's 223-inspection sweep cited 87 med spas for violations; every location in the NYC pilot had at least one.
  • 0293% failed to properly display required licensing and 60% lacked liability insurance, making documentation gaps the most consistently cited category after unlicensed practice itself.
  • 03"Ghost director" arrangements are now a primary enforcement target across Rhode Island, Indiana, and Texas.
  • 04Scope of practice violations carry criminal exposure: unlicensed practice of medicine was the leading cited category in New York's statewide sweep.
  • 05Decoda Health's AI Scribe, role-based permissions, and per-visit digital consent storage close the exact documentation gaps regulators flag most.
Text size

The New York Enforcement Sweep: What Actually Happened

New York's crackdown unfolded in two coordinated waves. In December 2025, the NYC Council's Oversight and Investigations Division published findings from a joint inspection of 15 med spas across the five boroughs, carried out with the State Department of Health and Department of State (NYC Council, December 2025). Every single one had violations.

Then came the statewide sweep. On January 8, 2026, the New York Department of State announced results from 223 inspections of appearance enhancement businesses conducted with the Department of Health and State Education Department. Eighty-seven were cited for possible violations, including the unlawful practice of medicine. Investigators found expired drugs, suspected counterfeit products, controlled substances, used needles, and unlicensed individuals performing medical procedures.

The consequences were concrete: fines, license suspensions, and full revocations. The NYC Council report noted that the first four completed city-level cases all ended in license revocations.

Why New York's Numbers Are a National Signal

The 15-spa NYC pilot found violations at every location inspected. That's not a bad-luck sample. When every location in a 15-site sample fails inspection, the data stops describing a handful of rogue operators and starts describing an industry-wide gap.

Regulators outside New York have noticed. Holland & Knight's August 2026 enforcement alert flagged that federal agencies and multiple states have launched their own enforcement actions, with violations appearing consistently: unlicensed practice, inadequate medical oversight, counterfeit products, and documentation failures. The same categories, different states. If inspectors showed up at your location tomorrow, the question isn't whether your state has caught up to New York yet. It's whether your records would hold up when it does.

The "Ghost Director" Problem Regulators Are Targeting

For years, a physician's name on the website was enough. Sign an agreement, file it somewhere, and move on. Regulators have grown impatient with that arrangement.

"In 2026, that approach looks much riskier. Across multiple states, the direction of regulation is becoming clearer: regulators want active medical director involvement, not a distant physician who has little real connection to the clinic." (WellnessMD Group)

State-level regulatory changes are concrete. Rhode Island's Medical Aesthetic Practices Safety Act, effective 2026, requires licensed medical directors (part of a broader wave of new med spa laws in 2026), documented supervision arrangements, and written competency expectations. Indiana moved to a registration model that requires a designated responsible practitioner with prescriptive authority and real oversight of staff and compounded drug use, key considerations covered in the med spa ownership and licensing checklist. Texas has tightened written protocol and delegation requirements for elective procedures.

The name-on-the-wall model is now a primary enforcement target.

Federal Enforcement Is Arriving Alongside State Action

State boards are not the only ones paying attention. The FDA issued its Drug Supply Chain Security Act Form 483 to a Texas med spa after inspectors found a mismatch between the volume of Botox purchased from authorized suppliers and the amount administered to patients. That discrepancy pointed to one conclusion: product sourced outside legitimate channels.

The FTC health data rules for med spas have separately increased scrutiny of deceptive marketing claims in the aesthetics space. Holland & Knight's August 2026 enforcement alert observed that violations across both federal and state actions are "strikingly consistent": unlicensed practice, absent medical oversight, counterfeit or unlawfully compounded products, deceptive marketing, sanitation failures, and documentation gaps. When federal and state investigators are independently finding the same problems, the pattern reflects a coordinated enforcement reality, not coincidence.

What Regulators Are Actually Looking For

Across every enforcement action described above, investigators keep finding the same failures. These are the most common deficiencies cited at inspected locations.

Violation Category

What Investigators Flag

Scope of practice

Procedures performed by staff without the required license or delegation authority

Medical director oversight

Physician name on file but no documented supervision, written protocols, or physical presence requirements met

Written SOPs

Missing or unsigned standard operating procedures for specific treatments offered

Emergency protocols

No documented emergency response plan; required safety equipment absent

HIPAA and infection control

Missing privacy documentation, sanitation failures, improperly stored or labeled medications

The NYC pilot put numbers to this: 93% failed to properly display required licensing, 73% had no medical professional present during procedures, and 60% carried no liability insurance. These are the baseline findings, not outliers.

Scope of Practice: The Violation That Creates Criminal Exposure

Scope of practice is where regulatory citations turn into criminal exposure. In New York's statewide sweep, unlawful practice of medicine was the leading cited violation category, meaning someone performed a medical procedure without legal authority to do so.

In the med spa context, that line runs between treatments. Botox injections, dermal fillers, and laser procedures that penetrate below the epidermis generally require physician performance or explicit, documented delegation to a licensed mid-level provider. An esthetician performing injectables, or an RN administering treatment without a standing order or patient-specific authorization from a supervising physician, crosses it regardless of how long that arrangement has existed.

A verbal sign-off is not documentation. Regulators want written delegation authority, specific to the procedure, signed by a physician with a current license and a real supervision arrangement. Without that paper trail, the practitioner faces unlicensed practice charges and the owner faces the same exposure for allowing it.

Documentation: The Difference Between a Warning and a Revocation

When investigators find a scope-of-practice issue, documentation doesn't change what happened. But when the violation is ambiguous, what's on paper determines the outcome almost entirely.

Corrective action plans go to practices with policies, signed protocols, and current staff credential files. Revocations go to practices where those things don't exist. The clinical work may be identical.

The records that matter most during an inspection:

  • Written clinical protocols signed by the medical director, specific to each procedure offered
  • Staff credentialing files with current licenses and any delegation agreements
  • Treatment-specific informed consent forms, signed per visit
  • Before-and-after photo authorization records
  • HIPAA-compliant communication policies and breach response procedures

The NYC pilot found 93% of locations failing to properly display required licensing and 60% without liability insurance. Those weren't all bad actors. Many were running on verbal agreements and informal habits that worked fine until an investigator walked in.

"If it's not charted, it didn't happen" applies here exactly as it does in clinical notes. A standing order sitting in someone's email inbox isn't a standing order.

The New Compliance Baseline: What "Inspection-Ready" Actually Requires

Being able to say you're compliant and being able to prove it are two very different positions when an investigator is standing in your lobby.

Practices that walk away with corrective action plans instead of revocations share one trait: organized, current documentation they can produce on the spot.

  • A credential file for every staff member, with license expiration dates tracked and renewal reminders built in
  • Written clinical protocols signed by your medical director, updated whenever your service menu changes
  • Product sourcing records that match purchase invoices to patient administration logs (the Texas FDA action started with a Botox volume mismatch), a concern that intersects with high-risk med spa payment processing
  • Signed informed consent forms filed per visit, not per patient
  • A documented staff training log showing when training happened and who completed it

A quarterly internal audit against this list is the difference between finding gaps yourself and having a regulator find them for you. Annual reviews alone leave too much time for drift.

How Decoda Health Helps Elective-Care Practices Stay Inspection-Ready

Compliance readiness is fundamentally a documentation problem. The practices that survive inspections are running operations where the records exist, are current, and can be produced immediately.

Decoda Health's infrastructure is built around exactly what investigators ask for. Decoda Health's AI Scribe generates structured SOAP notes in real time, creating the auditable clinical paper trail regulators expect to see. Digital consent forms are dispatched automatically before each appointment, arrive date-stamped, and are stored per visit by default. When an investigator asks for signed informed consent from a specific procedure date, it's retrievable in seconds.

GFE compliance and role-based permissions handle scope-of-practice controls at the software level. Access to clinical dose records can be restricted by staff role, which means an esthetician physically cannot modify an injectable dose entry that only a licensed provider should touch. The control is structural, not procedural.

Staff credential tracking, intake records, and clinical documentation (including med spa EMR lab ordering) all live in one system. Clinic partners see an average 80% reduction in check-in time because intake and consent, along with med spa EMR superbills, are completed digitally before patients arrive, which has a useful side effect: those records are audit-ready before the appointment even starts.

Final Thoughts on What the Med Spa Enforcement Wave Means for Independent Practices

Enforcement has moved past warning signs and into license revocations. The gap between a corrective action plan and a revocation is almost always documentation, not clinical quality. Your practice may be doing everything right, but if the records do not show it, that distinction disappears the moment an investigator walks in. Keep your documentation inspection-ready with Decoda Health before you need it to be.

Frequently Asked Questions

What specific documentation do med spa regulators look for during an inspection?

Inspectors consistently ask for the same records: written clinical protocols signed by your medical director and tied to each procedure you offer, staff credential files with current license copies and any delegation agreements, signed informed consent forms filed per visit, product sourcing logs that match purchase invoices to patient administration records, and a documented staff training log. Missing any one of these is what separates a corrective action plan from a license revocation.

What software do med spas use to handle HIPAA compliance and patient records during the 2026 enforcement crackdown?

Practices that have held up under inspection are running documentation through purpose-built medical EMR systems, not general-purpose scheduling tools. Decoda Health generates structured SOAP notes through AI Scribe in real time, auto-dispatches date-stamped digital consent forms per visit, and stores everything in a single searchable record, so when an investigator asks for a signed consent from a specific procedure date, staff can retrieve it in seconds instead of digging through folders.

Should my med spa use role-based permissions in our EMR to control who can modify injectable dose records?

Yes, and in a 2026 enforcement environment, making it structural instead of procedural is the safer approach. When only licensed providers can physically access and edit clinical dose entries, you remove the human error variable entirely. Decoda Health's role-based permission controls restrict access to dose records by staff role at the software level, which means the control holds even on a busy Saturday with a new esthetician in the room.

What's the "ghost director" problem regulators are cracking down on in 2026, and how do I know if my practice is exposed?

A ghost director arrangement is one where a physician's name appears in your licensing paperwork but that physician has no real connection to your day-to-day clinical operations: no documented supervision, no signed protocols, no physical presence requirements met. Rhode Island, Indiana, and Texas have all moved to require active, documented medical director involvement in 2026. If your physician cannot produce signed written protocols specific to each procedure you offer and a documented supervision arrangement, your practice fits the profile regulators are targeting.

How do I build an audit-ready compliance record before New York-style med spa enforcement reaches my state?

Run a quarterly internal audit against the five checkpoints laid out in the compliance baseline section above. Annual reviews leave too much time for drift, and practices that survive inspections are the ones that find their own gaps first.

What happened to every med spa inspected in New York City's 2026 pilot sweep?

Every one of the 15 med spas inspected in the NYC pilot had at least one violation, and the first four completed city-level cases all ended in license revocations. That result means the enforcement failures found were not isolated to a few bad actors but reflected widespread gaps across the industry.

How does unlicensed practice of medicine exposure actually happen at a med spa, and what does criminal liability look like?

Criminal exposure typically results when a procedure that legally requires physician performance or explicit written delegation to a licensed mid-level provider is performed by someone without that authority, such as an esthetician administering injectables or an RN treating patients without a patient-specific standing order. In New York's statewide sweep, unlawful practice of medicine was the leading cited violation category, which means the charge applies regardless of how routine the arrangement has felt internally.

What is the difference between a corrective action plan and a license revocation in a med spa enforcement context?

The determining factor is almost always documentation. Practices with organized credential files, signed protocols, and per-visit consent records on hand when inspectors arrive tend to receive corrective action plans; practices missing those records receive revocations, even when the underlying clinical work was similar. The outcome shifts based on what you can produce on the spot, not what you believe you were doing correctly.

Should my med spa store signed informed consent forms per visit or per patient?

Per visit, and regulators are explicit about this distinction. A single consent form on file for a returning patient does not satisfy the documentation standard when an investigator asks for proof that a patient consented to a specific procedure on a specific date. Decoda Health's digital consent system auto-dispatches and stores forms per visit by default, with date stamps that make retrieval immediate during an audit.

What did the Texas FDA Form 483 action mean for med spas that source Botox outside authorized channels?

The FDA issued a Drug Supply Chain Security Act Form 483 to a Texas med spa after inspectors found a mismatch between the volume of Botox purchased from authorized suppliers and the volume documented as administered to patients, pointing to product sourced outside legitimate channels. For any practice, the practical takeaway is that product purchase invoices must match patient administration logs exactly, because federal investigators are now cross-referencing both.

How does an AI-native EMR for med spas differ from traditional med spa software that adds AI features on top?

Legacy systems were built around manual data entry and forms; when they add AI, the intelligence can only operate within that rigid structure. A purpose-built AI-native system like Decoda Health has AI woven into every workflow from the start, so the AI Scribe, front desk automation, and clinical documentation all share the same patient record and compound in value the more the system is used, rather than functioning as separate disconnected add-ons.

How granular can role-based permissions get in a med spa EMR for multi-staff practices?

In Decoda Health, role-based controls operate at the individual action level, including separate Create, Edit, and Delete permissions on clinical dose records, scheduling overbooking authority, access to revenue and performance analytics, and visibility into reputation management data like patient chart ratings. This means a front desk receptionist and a licensed injector can work in the same system with entirely different access footprints determined by their role, which closes the scope-of-practice documentation gap regulators flag.

Which states beyond New York have enacted new med spa laws or enforcement actions that operators should track right now?

Rhode Island's Medical Aesthetic Practices Safety Act took effect in 2026, requiring licensed medical directors, documented supervision arrangements, and written competency expectations. Indiana moved to a registration model requiring a designated responsible practitioner with prescriptive authority and real oversight of staff and compounded drug use. Texas has tightened written protocol and delegation requirements for elective procedures. Holland and Knight's August 2026 enforcement alert confirmed that federal agencies have also launched actions with violation categories that mirror state findings.

What does a quarterly internal compliance audit for a med spa actually involve?

A quarterly audit checks five areas: that every staff member's credential file is current with license expiration dates tracked, that written clinical protocols are signed by your medical director and reflect your current service menu, that product sourcing records match purchase invoices to patient administration logs, that signed informed consent forms are filed per visit, and that a staff training log documents when training occurred and who completed it. Quarterly reviews close gaps before an investigator does; annual reviews leave too much time for drift.

Can Decoda Health's AI Scribe generate documentation that would hold up during a 2026 med spa enforcement inspection?

Decoda Health's AI Scribe generates structured SOAP notes in real time during the appointment, producing the auditable clinical paper trail regulators expect to see. Because the notes are generated and stored within the same system as digital consent forms, credential records, and intake data, a practice can pull a complete visit record for a specific procedure date in seconds, which is the retrieval speed that matters when an investigator is standing at the front desk.