One Med Spa. Three Compliance Reviews. Three Very Different Answers.

2026-07-21 · CompliancePilotAI.io

In July 2026 we reviewed the public marketing of a real medical spa in the Cleveland area three different ways, each one looking deeper than the last. Identifying details have been removed. The scores have not.

Level 1: Keyword screening said 96/100 — "nearly clean"

An automated pass checked the practice's website against a library of known risky phrases — the way most "compliance checker" tools work. It found twelve housekeeping items, mostly testimonial pages missing a results-vary disclaimer. Nothing severe.

The problem: this practice never used the exact phrases the keywords look for. Nobody wrote "guaranteed results" or "cures disease" verbatim. The risky claims were all paraphrased — and paraphrased claims sail straight through keyword matching.

Level 2: AI deep analysis said 55/100 — "severe risk"

The same pages, the same day — but this time AI read them the way a regulator would: for meaning, not keywords. Eight additional findings surfaced, including:

The score didn't drop because the website changed. It dropped because the reviewer got smarter. Regulators don't run keyword searches — they read.

Level 3: A full multi-channel audit said Grade D — "significant exposure"

A professional audit then examined all four public channels: website, Facebook, Instagram, and TikTok. Sixteen consolidated findings, five requiring legal review — including an unapproved biologic listed in the practice's social media bios that never appears on the website at all.

A website-only review, at any depth, could not have seen it. Regulators and plaintiffs' attorneys read your social media too.

What this means for your practice

This practice would have passed a keyword checker with a 96. Its actual posture was enforcement-level risk across four channels. The difference between "looks fine" and "call your lawyer" was simply how hard anyone looked — and a regulator only ever looks hard.

Three practical takeaways:

  1. A clean automated scan is a starting point, not a verdict. If the tool only matches phrases, it can only catch the mistakes you already knew not to make.
  2. Your riskiest claims are probably paraphrased. "Effects similar to Botox" contains no forbidden words — and is precisely the kind of claim that draws an FDA objection.
  3. Audit every channel you publish on. Service lists in Instagram bios, TikTok captions, and Facebook posts are marketing claims with the same regulatory weight as your homepage.

Want to see where you stand? A free scan takes about a minute and shows your score with sample findings. Paid audits include the full AI deep analysis described above, and multi-channel professional audits are available through Garrett Medical Technologies.

This article is educational content about publicly available regulatory guidance. It is not legal advice; consult healthcare counsel for guidance specific to your practice.

Wondering if your website says any of this?

Run a free AI compliance scan — your score and sample findings in about a minute.

Analyze My Website — Free