Our Work / South Florida Med Spa Group
Zay CustomHIPAA-TierHealthcareCustom CRMMed Spa

21% NO-SHOWS
TO 6%.
HIPAA-clean.

A 5-location med spa group needed a CRM that could handle HIPAA intake forms, BAA signing, before/after image consent, and clinical SMS reminders. Every off-the-shelf option failed at least one of those. Zay Custom built a HIPAA-tier custom CRM. No-show rate dropped from 21% to 6%. Intake-to-treatment time halved.

South Florida · 5 locations · Med Spa · HIPAA-tier
-71%
No-Show Rate
-50%
Intake-to-Treatment
BAA
Signed in 8 Minutes
The Problem

Every off-the-shelf CRM failed compliance.

Generic CRMs Could Not Sign BAAs

HubSpot, Pipedrive, Salesforce small-business tier did not offer signed Business Associate Agreements. Storing patient PHI in any of them was an out-of-the-box HIPAA violation.

Medical EMRs Were Wrong for Marketing

EMRs like Athena and DrChrono handled clinical compliance but had no marketing pipeline, no lead nurture, no campaign attribution. The marketing team was running a parallel Google Sheet of leads.

12 Paper Forms Per Patient

Each new patient signed 12 paper forms, scanned into a shared drive by the front desk, then manually keyed into the EMR. 25 minutes per intake. Errors common.

21% No-Show Rate, Bleeding Revenue

On a $400 average treatment, every no-show was $400 of empty chair time plus the cost of the booked-out staff. Across 5 locations, ~$240k a year in no-show revenue lost.

"We needed a marketing CRM that did not violate HIPAA. Nobody sold one. ZRG built one. Eight weeks from spec to live across all 5 locations."

Dr. Patel, Medical Director
No-Show Rate

21% to 6%.
~$170k/yr recovered.

Two-way SMS reminders sent 48h, 24h, and 2h before each appointment did most of the work. Reschedules happened inside SMS without a front-desk call.

21%
M1
No-show: 21%
M1
19%
M2
No-show: 19%
M2
15%
M3
No-show: 15%
M3
12%
M4
No-show: 12%
M4
9%
M5
No-show: 9%
M5
7%
M6
No-show: 7%
M6
6%
M7
No-show: 6%
M7
6%
M8
No-show: 6%
M8
21%
Baseline
6%
Steady State
~$170k
Annual Revenue Recovered
Intake-to-Treatment Days

Two weeks to one week.

Digital intake meant patients filled forms before they arrived. Front desk no longer scanned, keyed, and waited on consent signatures.

14d
M1
13d
M2
11d
M3
10d
M4
9d
M5
8d
M6
7d
M7
7d
M8
Monthly Visit Volume

More throughput, less front-desk strain.

Same staffing. 81% more visits handled. The intake time savings unlocked capacity nobody knew was there.

320
M1
345
M2
390
M3
420
M4
465
M5
510
M6
548
M7
580
M8
Before and After

Every compliance + ops
metric moved.

Metric
Before
After
Change
No-Show Rate
21%
6%
-71%
Intake-to-Treatment
14 days
7 days
-50%
Forms on Paper
12 per patient
0
-100%
BAA Signing Time
3 days
8 minutes
-99.8%
SMS Compliance Risk
High
Audited
Resolved
What Zay Custom Built

Six core modules. All HIPAA-audited.

HIPAA Intake Forms

Digital intake forms with encrypted at-rest storage, signed BAAs auto-attached to each patient record, audit log on every field edit.

BAA Signing Flow

Patients sign Business Associate Agreement in under 2 minutes via DocuSign integration. Auto-filed to patient record with timestamp + IP.

Before/After Image Vault

Tagged image storage with patient-consent tracking. Images cannot be used in marketing without explicit re-consent. Audit log on every view and export.

SMS Reminders

Two-way SMS confirmations 48h, 24h, and 2h before. Doctor-licensed staff only could initiate clinical messages. Compliance log built in.

Role-Based Access

Front desk, MA, RN, NP, MD each see only what they are licensed to see. Audit log per role per action.

Insurance + Payments

Stripe Connect for cards, manual entry for cash/check, payment plans built in. Receipts auto-attached to chart.

The Numbers
  • $25,000 setup — full build, integration, training, HIPAA audit by third party.
  • $1,500/month HIPAA hosting — dedicated VPC, encrypted at rest, full audit log retention, BAA-covered infra.
  • 8 weeks spec to live — from kickoff to all 5 locations operational.
  • 100% client-owned — code, database, hosting all owned by the med spa group. No vendor lock.
The Result

A med spa that runs on its own software.

No-shows at 6%

Industry average is 18-22%. The group now operates well under industry baseline. Two-way SMS plus deposit-on-booking did the heavy lifting.

HIPAA-audited and signed

Third-party HIPAA audit completed at month 3. All BAAs in place. No more PHI living in marketing spreadsheets or generic CRMs.

Throughput up 81%

Same square footage, same staff count, 81% more visits handled. The biggest unlock was the front desk reclaiming 25 minutes per intake.

Keep Reading
Presented by Abdallah, CEO, (321) 666-1102

Need a CRM nobody sells?

Zay Custom builds start at $12,500. The HIPAA tier (signed BAA, dedicated VPC, audit logs) starts at $25,000 setup, $1,500/month hosting. We build it, you own it.