Setting Up a Med Spa Ad Account the Right Way
Set up a med spa ad account under a verified business manager tied to your real legal entity, with separate ad accounts for testing and scaling, a verified domain, pixel plus Conversions API, and a written compliance checklist enforced before every launch. Getting this right at setup is what prevents the month-two restriction that kills most med spa accounts.
most med spa ad accounts are set up in twenty minutes by whoever happened to be free, and then inherit that decision for years. the setup determines your enforcement exposure, your attribution quality, and whether a single policy hit takes down one campaign or the whole business. spend an afternoon on it. here's the order.
operational guidance, not legal advice. anything touching prescription services, medical claims, or patient data needs review by your attorney and your medical director — HIPAA in particular changes how you're allowed to handle customer lists and pixel data.
step one: business manager and verification
- 1.create a business manager under your real legal entity name — the one on your formation documents, not your brand name if they differ.
- 2.complete business verification immediately, before you need it. you'll need formation documents, an EIN letter, a utility bill or bank statement at the business address, and a phone number that can receive a verification call.
- 3.add at least two admins with two-factor authentication enabled. a single-admin business manager is one lost phone away from being unrecoverable.
- 4.never build on a personal profile's ad account. everything of value lives inside the business manager.
- 5.if you work with an agency, grant partner access through business manager rather than adding them as admins on your assets. you keep ownership and you can revoke instantly.
verification is the difference between a support ticket that gets reviewed and one that doesn't. unverified businesses in health-adjacent categories get very little benefit of the doubt.
step two: account architecture
the structure is about containment. build it so a compliance event is survivable.
- —ad account 1 — scale. your proven creative and your main budget. nothing experimental ever runs here.
- —ad account 2 — testing. new hooks, new angles, new formats, small fixed budgets. this is where you absorb the disapprovals.
- —ad account 3 — reserve. created, verified, funded with a separate payment method, warmed with occasional small clean spend, and otherwise idle. this is your continuity plan.
- —one page per brand. if the clinic and the online product line are different brands, they get different pages, different domains, and ideally different ad accounts.
- —verify every domain you advertise in business manager. domain verification also unlocks aggregated event measurement configuration.
- —distinct payment methods per account where possible. shared payment instruments link risk across accounts.
that account ran 294 ads live at peak with top creatives between 6.79 and 14.96 ROAS. none of that is possible on a structure where one disapproval can freeze everything.
step three: tracking
attribution is worse than it used to be and med spa purchase cycles are long. server-side tracking is not optional.
- 1.install the meta pixel on every page, then implement the Conversions API — through your platform's native integration if it has one, or server-side via a tag manager server container.
- 2.deduplicate events between pixel and CAPI using consistent event IDs, or you'll double-count and misjudge every campaign.
- 3.configure aggregated event measurement with your eight events prioritized correctly. purchase first, then the events that precede it.
- 4.define your standard events properly: view content, add to cart, initiate checkout, purchase for ecommerce; lead and schedule for clinic booking.
- 5.upload offline conversions — appointments that actually showed and paid — so optimization targets real customers rather than form fills.
- 6.be careful with customer list uploads and pixel data if you handle protected health information. HIPAA obligations do not disappear because a platform makes uploading easy. get this reviewed.
margin sets this up as part of taking med spas from zero to selling peptides online — entity, compliance, processor, tracking, funnels, then ads. if you're starting with the ads, you're starting at step six.
step four: compliance guardrails at setup
write these down as a document your team actually uses. it's the highest-ROI hour in the whole setup.
- —the copy rule: the product, service, or practice is always the grammatical subject. the reader's body is never referenced. run a second-person check on every headline and primary text.
- —the creative rule: no before/after, no side-by-side composition, no body close-ups, no scale or measurement imagery, no on-screen result claims. review frame by frame including captions.
- —the Rx rule: no prescription compound names in copy or on the advertised destination without the relevant meta certification and licensure.
- —the destination rule: the landing page carries no claims the ad avoided, no result testimonials, no dosing content, and real policy pages with real contact information.
- —the disclaimer rule: research-use-only statements where the classification applies; FDA structure-function disclaimer where supplements apply.
- —the review rule: every ad passes the checklist before it's queued, not after it's rejected.
step five: warming and first campaigns
- 1.start with clean brand-level creative at a low budget — $30–50/day — for about a week. no aggressive testing, no policy-adjacent angles.
- 2.watch for clean delivery and zero disapprovals. that history is what makes later launches easier.
- 3.then introduce your first real prospecting campaign, broad targeting within your service radius, optimizing for the deepest event you have volume for.
- 4.add retargeting once you have meaningful site traffic — typically two to three weeks in.
- 5.only then open the testing account for aggressive creative exploration.
- 6.check account quality weekly from day one. make it a calendar item.
an afternoon on setup buys you years of not thinking about enforcement. skipping it buys you a month-two restriction and a rebuild.
the things people skip and regret
- —business verification — skipped because it's tedious, then desperately needed during a restriction.
- —domain verification — skipped, then aggregated event measurement is misconfigured and attribution is wrong for months.
- —the reserve account — skipped, then a restriction means two weeks of zero revenue.
- —conversions API — skipped, then campaigns optimize on 40% of the actual signal.
- —the written compliance checklist — skipped, then every new hire reintroduces the same violations.
- —second admin with 2FA — skipped, then one person leaves and the business manager is stranded.
if you're rebuilding after an enforcement event
rebuild for a real, properly owned business — not as a replacement identity for banned assets. fix the site and the claims first, appeal the existing assets properly, and only build new structure where it's legitimate to do so. creating new entities or using other people's identities to escape enforcement is circumvention, it takes down everything connected to you when detected, and it forecloses the recovery path you still have. the compliant rebuild is slower and it's the only one that lasts.
frequently asked questions
do i need a business manager or can i just use a personal ad account?
business manager, always. personal ad accounts can't be verified, can't hold structured partner access, are far harder to recover, and don't support the multi-account containment structure that protects a med spa from a single policy hit.
how many ad accounts should a med spa have?
three: one for scaled spend, one for creative testing, and one verified reserve kept warm and idle. the separation means a disapproval in testing never touches revenue, and a restriction never means zero.
what do i need for meta business verification?
formation documents in the legal entity name, an EIN confirmation letter, proof of address such as a utility bill or bank statement, and a business phone number that can receive a verification call. do it before you need it.
is the pixel enough or do i need the Conversions API?
you need both. browser-side tracking loses a substantial share of events to privacy restrictions, and med spa purchase cycles are long enough that the loss compounds. run pixel plus CAPI with proper event deduplication.
can i upload my patient list as a custom audience?
be very careful. patient information may be protected health information, and uploading it can create HIPAA exposure regardless of what the platform allows technically. this needs review by your attorney and your compliance officer before you do it.
how long should i warm a new med spa ad account?
about a week of clean brand-level creative at $30–50/day with no disapprovals, before introducing real prospecting budgets or any aggressive testing. rushing this is the single most common cause of early restriction.
want us to build this for you?
we take high-end med spas from zero to selling peptides — compliant, in-store, and online, in under two weeks.