The Practice Intelligence Layer is architected so that protected health information stays inside the practice management system — where it already lives, governed by HIPAA, behind your existing access controls. Sculptrix sees the operational gaps without seeing the people in them.
Every patient touchpoint that lives inside an aesthetic practice — names, contact details, treatment notes, photographs, billing records — is governed by HIPAA and stored inside the practice management system. Sculptrix is built so that data never has to leave that system to do its job.
When the layer surfaces an action — a rebooking nudge, a slot-fill match, a follow-up reminder — it does so by passing an anonymized event trigger to the PMS, which executes the patient-facing action through its own existing communication channels. Sculptrix sees the operational pattern. The PMS still owns the patient.
The pattern eliminates a long chain of legal exposure. The patient relationship stays one-to-one with the practice. The data stays where regulators expect it to stay. And the layer can do its work — finding the gaps, surfacing the moments, orchestrating between systems — without ever becoming a custodian of the information that makes those gaps personal.
The layer requests only the minimum signal it needs to identify a revenue gap. Anonymized internal IDs, treatment-cycle metadata, appointment timestamps. Never names, contact details, or clinical notes.
All patient-facing communication is sent by the practice management system, using the channels and credentials your practice already trusts. Sculptrix never owns a direct relationship with a patient.
Patient identifiers passed between Sculptrix and the PMS are opaque references — meaningful only to the PMS, useless if intercepted in isolation. The practice can rotate them at any time.
Every action the layer recommends is governed by approval thresholds the practice sets. No outbound message, no rebooking attempt, no data write — without owner-defined permission.
Aesthetic practices that perform medical procedures — injectables, lasers, hormone therapy — are covered entities under HIPAA. Patient data stored in a PMS is protected health information. Any vendor that handles PHI on their behalf becomes a Business Associate, with the contractual and operational burden that follows.
Sculptrix is intentionally architected to not be a Business Associate. Because the layer never receives PHI — only anonymized event triggers from the PMS — it operates as a workflow intelligence service rather than a PHI custodian. The PMS retains the BAA relationship with the practice. Sculptrix sits one level above.
"The Pattern 2 architecture eliminates the Business Associate Agreement requirement that would otherwise apply to a vendor reading raw practice data."
Practices may still choose to execute a confidentiality agreement covering the operational metadata Sculptrix processes. We provide a template. The legal lift is small. The HIPAA-grade BAA stack — the audit logs, the breach-notification clauses, the access-control attestations — is not invoked because the trigger model never requires it.
This is not a workaround. It's the architecture. The same property that makes the layer legally lighter to deploy is what makes it operationally honest: Sculptrix can only see what the PMS lets it see, and the PMS only lets it see what the practice has approved. The constraint is the moat.
Sculptrix is pre-SOC 2 today. We do not represent otherwise to prospects. The roadmap below is committed and dated to our revenue milestones — not to vague "soon" language.
If your practice is part of a private-equity-backed roll-up that requires a vendor-security review before the first contract, we'll meet you in that review with the architecture documentation, the trigger model spec, and a signed confidentiality agreement covering the operational metadata involved. The conversation moves quickly because there's less to argue about: the layer doesn't see the things a Business Associate would have to defend.
The certifications take time. The security practices do not. Here is what is in production today, independent of the roadmap above:
"Permanence is a design choice. One percent of every contract goes to the Snow Leopard Trust, every quarter, on a cadence we won't let drift."
For questions about this disclosure: hello@sculptrix.ai.
Email hello@sculptrix.ai →Sculptrix.ai
The Practice Intelligence Layer for aesthetic practices.
Built to be on top.
Newsreader for display and body. JetBrains Mono for interface and metadata.
Color: cream, ink, oxblood, sandstone, and navy — chosen to last beyond the quarter.
Briana O'Brien, founder & developer.
Padraic Doyle, chairman & co-founder.
Jennifer Doyle, co-founder & investor.
Filed from Belle Isle, Florida.