LandinChat — WhatsApp marketing softwareLandinChat
Compliance

HIPAA + GDPR WhatsApp for dermatology

A practical compliance guide for dermatology clinics handling skin photos, lesion images, prescriptions and aesthetic before/afters over WhatsApp.

  • BAA on request
  • End-to-end encryption
  • Photo PHI controls
  • Audit logs

Key things to know

  • BAA on request

    For HIPAA-covered entities.

  • End-to-end encryption

    Official Meta WhatsApp Business API.

  • PHI access controls

    Role-based — only authorised staff view photos.

  • Consent capture

    Built-in opt-in at first message.

People also ask

Q.Is WhatsApp itself HIPAA-compliant?

Meta's API is encrypted but Meta itself is not a Business Associate. Compliance comes from how your platform handles PHI on top — that's what LandinChat enforces.

Q.Can patient photos be stored?

Yes — only in your encrypted tenant with role-based access. Never on a staff phone.

Q.How do I capture consent?

Built-in template fires on first inbound message; logged with timestamp.

Q.What about right-to-erasure?

One-click patient erasure removes photos, messages and metadata.

Q.Can I export the audit log?

Yes — CSV or API.

Q.Does Meta see patient data?

Meta handles encrypted transit; LandinChat handles storage and access in your tenant.

SOC 2
Aligned
E2EE
Meta API
RBAC
PHI access
100%
Audit trail
Overview

Why dermatology compliance is photo-heavy

Other specialties send text. Dermatology sends photos — and a face photo plus a name is PHI under HIPAA and personal data under GDPR / DPDP. That makes photo handling the single biggest compliance risk for derm clinics on WhatsApp.

LandinChat enforces server-side PHI controls: patient photos never land on a staff phone, all access is logged, and consent is captured before any image is requested.

Capabilities

Built for serious growth teams

BAA on request

For HIPAA-covered entities.

End-to-end encryption

Official Meta WhatsApp Business API.

PHI access controls

Role-based — only authorised staff view photos.

Consent capture

Built-in opt-in at first message.

Audit log

Every view / send / export logged.

GDPR / DPDP

Data residency and erasure flows supported.

How it works

Get live in days, not months

  1. 1

    Sign BAA / DPA

    Standard contracts.

  2. 2

    Configure PHI roles

    Who sees photos, who doesn't.

  3. 3

    Enable audit log

    On by default.

  4. 4

    Train staff

    15-minute SOP covers 95% of risk.

Use cases

What teams ship with this

US clinics

HIPAA + BAA.

EU / UK clinics

GDPR + UK GDPR with EU data residency.

India

DPDP-aligned consent and retention.

UAE / KSA

PDPL with regional residency on request.

FAQ

Frequently asked questions

Related guides & pages

Compliance shouldn't slow you down

Ship dermatology workflows that are fast for staff and safe for auditors.