HIPAA + GDPR WhatsApp for dermatology
A practical compliance guide for dermatology clinics handling skin photos, lesion images, prescriptions and aesthetic before/afters over WhatsApp.
- BAA on request
- End-to-end encryption
- Photo PHI controls
- Audit logs
Key things to know
BAA on request
For HIPAA-covered entities.
End-to-end encryption
Official Meta WhatsApp Business API.
PHI access controls
Role-based — only authorised staff view photos.
Consent capture
Built-in opt-in at first message.
People also ask
Q.Is WhatsApp itself HIPAA-compliant?
Meta's API is encrypted but Meta itself is not a Business Associate. Compliance comes from how your platform handles PHI on top — that's what LandinChat enforces.
Q.Can patient photos be stored?
Yes — only in your encrypted tenant with role-based access. Never on a staff phone.
Q.How do I capture consent?
Built-in template fires on first inbound message; logged with timestamp.
Q.What about right-to-erasure?
One-click patient erasure removes photos, messages and metadata.
Q.Can I export the audit log?
Yes — CSV or API.
Q.Does Meta see patient data?
Meta handles encrypted transit; LandinChat handles storage and access in your tenant.
Why dermatology compliance is photo-heavy
Other specialties send text. Dermatology sends photos — and a face photo plus a name is PHI under HIPAA and personal data under GDPR / DPDP. That makes photo handling the single biggest compliance risk for derm clinics on WhatsApp.
LandinChat enforces server-side PHI controls: patient photos never land on a staff phone, all access is logged, and consent is captured before any image is requested.
Built for serious growth teams
BAA on request
For HIPAA-covered entities.
End-to-end encryption
Official Meta WhatsApp Business API.
PHI access controls
Role-based — only authorised staff view photos.
Consent capture
Built-in opt-in at first message.
Audit log
Every view / send / export logged.
GDPR / DPDP
Data residency and erasure flows supported.
Get live in days, not months
- 1
Sign BAA / DPA
Standard contracts.
- 2
Configure PHI roles
Who sees photos, who doesn't.
- 3
Enable audit log
On by default.
- 4
Train staff
15-minute SOP covers 95% of risk.
What teams ship with this
US clinics
HIPAA + BAA.
EU / UK clinics
GDPR + UK GDPR with EU data residency.
India
DPDP-aligned consent and retention.
UAE / KSA
PDPL with regional residency on request.
Frequently asked questions
Related guides & pages
Compliance shouldn't slow you down
Ship dermatology workflows that are fast for staff and safe for auditors.