Skip to main content
Patient Protect circular logo mark in purple and white used for site navigationPatient Protect

HIPAA Compliance for Dermatology Practices

The HIPAA compliance and security operating system for dermatology practices. Clinical photography is the highest-volume ePHI in the practice and the least governed — capture, camera roll, cloud sync, EHR, pathology, portal, marketing. Patient Protect runs the risk analysis across that lifecycle, separates treatment use from marketing authorization, and keeps the proof together.

Dermatology practices that electronically bill, check eligibility, request authorization, or conduct other adopted transactions are HIPAA covered entities. Once covered, the duties below apply to records, photographs, pathology, teledermatology, devices, people, and vendors — not just the EHR.

HIPAA compliance is not optional for a covered dermatology practice.

If your practice is a HIPAA covered entity, it is required to maintain an active, documented compliance program — and if it performs covered functions as a Business Associate, it must implement the Security Rule and every other duty attaching to that role. The responsibility does not transfer to your EHR, IT company, consultant, insurance carrier, or software provider. Those partners can support the work; your practice remains responsible for completing it.

Watching one training video is not a compliance program. Downloading a policy template is not a compliance program. Signing one BAA is not a compliance program. HIPAA requires your practice to implement, maintain, and document the complete operating system behind each of those activities.

Your practice is required to do all of the following

  1. 01Conduct and document a Security Risk Analysis

    Identify every place electronic protected health information enters, moves through, or leaves the practice. Assess the systems, devices, people, vendors, locations, workflows, threats, and vulnerabilities that could compromise that information.

    45 CFR §164.308(a)(1)(ii)(A)

  2. 02Manage the risks the analysis uncovers

    Turn identified risks into a documented remediation plan. Assign responsibility, prioritize the work, implement safeguards, and preserve evidence showing how the practice responded.

    45 CFR §164.308(a)(1)(ii)(B)

  3. 03Designate Privacy and Security Officials

    Assign and document who is responsible for developing, maintaining, and enforcing the practice's privacy and security program. In a small practice, one person may perform both roles — but the responsibilities must still be assigned and documented.

    45 CFR §164.530(a) · §164.308(a)(2)

  4. 04Maintain written policies and procedures

    Document how the practice protects patient information, controls access, handles permitted disclosures, responds to incidents, enforces workforce accountability, and maintains required privacy and security safeguards.

    45 CFR §164.316(a) · §164.530(i)

  5. 05Train the entire workforce

    Train workforce members on the privacy policies relevant to their roles and maintain an ongoing security-awareness program. Preserve records showing who was trained, what the training covered, and when it was completed.

    45 CFR §164.530(b) · §164.308(a)(5)

  6. 06Identify and govern every Business Associate

    Determine which vendors and service providers create, receive, maintain, or transmit protected health information on the practice's behalf. Execute the required Business Associate Agreement before protected information flows and maintain the agreement as part of the practice's compliance record.

    45 CFR §164.502(e) · §164.308(b) · §164.504(e)

  7. 07Implement administrative, physical, and technical safeguards

    Control who can access patient information, secure the systems and locations where it is maintained, review activity, authenticate users, protect data integrity, and safeguard electronic transmission.

    45 CFR §164.308 · §164.310 · §164.312

  8. 08Protect patient privacy rights

    Maintain the required notices, authorization processes, complaint procedures, and workflows for responding to patient requests involving access, amendments, confidential communications, restrictions, and applicable disclosure accounting.

    45 CFR §164.520 · §164.524 · §164.526 · §164.522 · §164.528

  9. 09Prepare for incidents, outages, and breaches

    Maintain security-incident procedures, data backup, disaster recovery, emergency operations, mitigation, and breach-notification processes before an event occurs.

    45 CFR §164.308(a)(6) · §164.308(a)(7) · Subpart D

  10. 10Preserve proof that the work was completed

    Retain the assessments, risk decisions, policies, training records, official designations, BAAs, acknowledgments, incident records, and other documentation needed to demonstrate what the practice actually did.

    45 CFR §164.316(b) · §164.530(j)

The Security Risk Analysis is where the work begins.

The Security Rule requires an accurate, thorough assessment of the risks and vulnerabilities affecting every form of electronic protected health information your practice creates, receives, maintains, or transmits. This is commonly called a Security Risk Analysis, or SRA.

The federal government publishes its own Security Risk Assessment Tool for small and medium-sized practices. You are not required to use that particular tool. You are required to perform and document the underlying analysis.

Patient Protect provides its own guided SRA. It walks the practice through the assessment in plain language, identifies what is missing, and carries those findings into risk management, remediation, policies, tasks, and documentation — so the assessment ends with the problem assigned and resolved, not merely named.

A five-minute readiness quiz is not an SRA. Reviewing only your EHR is not an SRA. Reusing an old checklist that no longer reflects your systems, vendors, workforce, or workflows is not an SRA.

That includes our own free tool. The Patient Protect Score is a free exposure scan and a starting point. It is not your completed Security Risk Analysis, and we will not tell you it is.

What a dermatology practice’s Security Risk Analysis must cover

Clinical photography makes dermatology unusually exposed. Images can contain a face, tattoo, body location, embedded metadata, patient identifier, or clinical context. The SRA must follow those images from capture through storage, treatment use, disclosure, marketing, retention, and deletion.

  • Every device used to capture clinical photographs, dermoscopy images, wound documentation, and treatment-progress images
  • Camera rolls, automatic cloud synchronization, local storage, image upload, EHR attachment, backup, and deletion
  • The EHR, practice-management system, portal, teledermatology platform, imaging tools, and photo-management systems
  • Dermatopathology, laboratory, biopsy, Mohs, referral, and specialist data flows
  • Email, text, e-fax, patient forms, scheduling, and delivery of images or results
  • Before-and-after photography used for treatment documentation, education, websites, advertising, or social media
  • Vendors that store, process, transmit, edit, or can access identifiable clinical images

What the dermatology compliance program must also address

  • A written clinical-photography policy covering approved devices, upload, storage, access, retention, and deletion
  • Separate authorization and governance for marketing use of patient images
  • Access controls that prevent clinical images from remaining in personal or broadly shared accounts
  • Business Associate management for technology and service vendors acting on the practice's behalf
  • Workforce training on photography, marketing authorization, pathology workflows, teledermatology, and minimum-necessary access

The photograph is part of the compliance surface from the moment it becomes identifiable patient information — not only after it reaches the EHR.

What HIPAA actually looks like for dermatology practices.

The regulatory framework, the enforcement patterns OCR has historically cited, the non-HIPAA standards that apply, the gaps audits routinely surface, and the record-retention overlay — HIPAA’s six-year rule for compliance documentation, and the separate state law that governs how long clinical records must be kept.

Regulatory framework

Dermatology practices operate under HIPAA as covered entities through standard electronic transactions — claims, eligibility, e-prescribing for topical and systemic dermatology medications. State dermatology board rules govern practice standards. State pathology rules apply to in-office laboratory testing under CLIA. The FDA cosmetic-vs-medical-device line affects practices performing aesthetic procedures alongside medical dermatology — the line determines whether records and procedures fall under HIPAA's medical framework or a different consumer-product regulatory frame.

OCR enforcement patterns

OCR's dermatology enforcement record has historically focused on clinical photo storage sitting outside the practice's control — personal cloud accounts and staff camera rolls with no agreement, no configuration, and no audit trail — alongside dermatopathology lab BAA gaps and teledermatology transmission errors. Photo storage is the single highest-frequency exposure in this segment because dermatology's clinical photography volume far exceeds what an unmanaged personal account can support. The problem is the unmanaged account, not the vendor's name: the same provider's business tier under a BAA, properly configured, is a different question.

Standards beyond HIPAA

DICOM for clinical photography and dermatoscopy. CLIA for in-office laboratory testing. State pathology rules for biopsy specimens and dermatopathology workflow. The FDA cosmetic-vs-medical-device distinction governing aesthetic procedures. State dermatology board rules on cosmetic procedures performed by non-physician staff. State Medicaid and Medicare rules for medically-necessary versus cosmetic procedure billing.

Common compliance gaps

Dermatology practice compliance gaps cluster around clinical photography: photos taken on staff personal devices, photos stored on consumer cloud platforms without BAAs, before/after marketing photos used without explicit photography-specific consent, mole-mapping photo retention not aligned with state retention rules, and dermatopathology lab BAAs assumed but not signed. Mohs surgery practices have additional compliance complexity around multi-stage photo and pathology integration.

Compliance documentation, then state record law.

HIPAA's six-year rule governs compliance documentation, not clinical records (§164.530(j)). State dermatology and medical practice record laws govern patient record retention — typically seven to ten years. Photographs as part of the medical record are subject to the same retention as the chart. Biopsy specimens are retained per CLIA requirements (typically seven years for surgical pathology slides, ten years for blocks). Dermatopathology slides and reports are subject to separate state-specific retention rules. Cosmetic procedure records may have their own retention framework distinct from medical dermatology records.

Reference summary, not legal advice. This page summarizes how HIPAA and adjacent regulatory frameworks apply to dermatology practices based on Patient Protect’s reading of the relevant CFR provisions, OCR enforcement record, and state statutes. Operators with specific compliance questions should consult a qualified HIPAA attorney. Patient Protect is a HIPAA compliance platform; we are not a law firm and do not provide legal advice.

Where dermatology practices are most exposed.

Clinical photography creates high-risk ePHI

Before-and-after photos, dermoscopy images, and wound documentation are ePHI the moment they include identifying features. Storage on personal phones, unencrypted cloud folders, or shared drives without access controls is a breach waiting to happen.

Teledermatology platforms need BAAs and encryption

Virtual consultations, store-and-forward imaging, and asynchronous dermatology platforms all transmit ePHI. Each platform requires a signed BAA, end-to-end encryption, and documented security configurations.

Pathology and lab integrations introduce vendor risk

Biopsy reports, lab results, and pathology consultations flow between your practice and external labs. Each exchange point requires a BAA and encrypted transmission. Most practices don't audit these data flows.

Marketing use of patient images requires documented authorization

Using patient photos for social media, websites, or marketing materials requires specific written authorization separate from the general consent for treatment. HIPAA authorization for marketing use has strict requirements that generic consent forms rarely satisfy.

Built for dermatology practices, not hospital systems.

Clinical photography risk assessment

SRA wizard evaluates image capture devices, storage locations, transmission methods, and access controls — specific to dermatology workflows.

Vendor BAA tracking for labs and platforms

Full BAA lifecycle management for pathology labs, teledermatology platforms, and imaging services — with renewal alerts and status tracking.

Policy generation for image handling

Auto-generated policies covering clinical photography, marketing authorization, image retention, and device management — customized to your practice.

Staff training on image privacy

Training modules covering clinical photography compliance, marketing authorization requirements, and secure image handling workflows.

Clinical photo storage compliance with BAA-covered infrastructure

Dermatology practices generate massive clinical photo volumes — mole mapping, before/after, biopsy site documentation, treatment progression. Photos linked to patient identity are PHI. The platform handles BAA-covered photo storage with the access logging and retention controls clinical photos require.

Pathology lab BAA tracking and Mohs surgery records

Dermatopathology labs receiving biopsy specimens with patient identifiers are business associates. Mohs surgery records — multi-stage, photo-heavy, often involving on-site pathology — create additional storage and BAA surfaces. The platform tracks the dermatology-specific lab and pathology vendor ecosystem rather than treating it as generic medical-practice infrastructure.

HIPAA already requires the work. Patient Protect starts at $39 a month.

For a covered practice, HIPAA does not ask whether the organization has the budget, internal expertise, or spare time to build a compliance program. The obligation already exists. The only real question is whether you run it through spreadsheets, generic templates, disconnected training and scattered agreements — or keep the whole program in one place.

  • Guided Security Risk Analysis
  • Risk-management and remediation workflows
  • 48 customizable policies and procedures
  • HIPAA Foundations workforce training
  • Completion tracking and verifiable training certificates
  • Workforce and vendor management
  • Business Associate Agreement tracking and documentation
  • Compliance scoring and centralized audit evidence
Start your 14-day free trial

$39 per office per month · Up to 25personnel · No long-term contract

State-specific HIPAA rules for dermatology practices.

HIPAA is federal. What a state adds on top of it varies more than most compliance guidance admits — some states impose their own notification deadline and regulator notice, and others exclude HIPAA covered entities from their breach statute entirely. Select your state to see which of those is true where you practice.

What happens after the paperwork is done.

Every major compliance platform covers risk assessments and policy templates. This is the part that differs.

What to ask

Patient Protect

01

Risk analysis structured to §164.308(a)(1)(ii)(A)

A readiness quiz is not a risk analysis.

Full SRA wizard mapped to NIST CSF with live scoring

02

Auto-generated policies with workforce acknowledgment

HIPAA requires documented proof your staff reviewed them.

48 policies from your risk profile, versioned acknowledgment

03

Staff training with delivery tracking

§164.308(a)(5) — sending a PDF is not sufficient.

HIPAA Foundations — 19 modules, 95 assessment questions, verifiable certificates

04

Full BAA lifecycle management

Expired BAAs are a top enforcement target.

E-signature, renewal alerts, Vendor Risk Scanner

Yes on all 9. Now run the checklist on the rest.

From $39/mo · No long-term contracts.

Enterprise-grade compliance. Independent-practice pricing.

No contracts · No setup fees · Cancel anytime

Basic

$39/mo

Risk assessments, policies, BAA management, training, compliance scoring, secure messaging, and standard PIPAA usage.

Recommended

Pro

$99/mo

Everything in Basic, plus the patient-facing workflows. Patient Management and Digital Forms, expanded PIPAA usage, and up to 50 personnel.

See full feature comparison →

Common questions about HIPAA compliance for dermatology practices.

Are clinical photos considered PHI under HIPAA?

Yes. Clinical photographs that include identifying features — face, distinctive marks, tattoos, or any feature that could identify the patient — are protected health information under HIPAA. Even cropped or de-identified images may still qualify if they can be linked back to the patient through metadata or context.

Can I store dermatology photos on my phone?

Only with proper safeguards — full-disk encryption, passcode lock, documented BYOD policy, and no personal cloud backup of clinical images. Many practices use dedicated clinical photography apps that encrypt and upload directly to a secured EHR. Patient Protect's risk assessment evaluates your actual image handling workflow.

What does HIPAA compliance cost for a dermatology practice?

Patient Protect starts at $39/month with no contracts — covering risk assessments, policy generation, BAA tracking for labs and platforms, staff training, and continuous compliance monitoring. Whether you use it alongside your existing compliance partner or as a standalone solution.

Are clinical photos in dermatology PHI even when faces aren't visible?

Yes when linked to patient identity in the medical record. A close-up photograph of a lesion that's stored as part of the patient's chart is PHI regardless of whether the patient's face is visible — it's identifiable through the link to the patient record, not through facial recognition. Photos require BAA-covered storage, encryption, access controls, and audit trails like any other ePHI.

Do dermatopathology labs need a BAA?

Yes. Dermatopathology labs receive biopsy specimens accompanied by patient-identifying information for slide preparation, interpretation, and reporting. Each is a business associate under §160.103 and requires a written BAA before specimens flow. Practices using multiple dermatopathology partners need separate BAAs with each.

How are teledermatology consultations handled under HIPAA?

Teledermatology — both store-and-forward (asynchronous) and live video — is HIPAA-regulated when it involves PHI. Asynchronous consults transmit clinical photos and patient information to a remote dermatologist; the platform mediating the transmission is a business associate. Live video uses standard telehealth compliance frameworks. Both require BAAs with the platform vendor and audit trails of consult transmissions.

Does a dermatology practice have to complete a HIPAA Security Risk Analysis?

Yes, and photography is the part that most often falls outside it. Every covered practice must conduct and document an accurate, thorough assessment of the risks affecting all its ePHI. For dermatology that means the EHR and practice-management system alongside every device used to capture clinical images, camera rolls and automatic cloud synchronization, image upload and EHR attachment, the teledermatology platform, dermatopathology and biopsy workflows, portal and results delivery, and every vendor that can store, process, edit, or access identifiable clinical images. A practice whose SRA covers the EHR but not the phone in a clinician's pocket has not covered its highest-volume ePHI source.

Which of our dermatology vendors need Business Associate Agreements?

Any organization handling PHI on the practice's behalf: the EHR, practice-management and portal vendors, teledermatology platform, image storage and photo-management systems, any marketing or web vendor that receives identifiable images, transcription, billing service, claims clearinghouse, cloud backup, and IT support. Dermatopathology laboratories require classification rather than assumption — a laboratory receiving a specimen and rendering a diagnosis is generally a treating provider, which HHS does not treat as a business associate relationship, while a lab performing a service on the practice's behalf is. Get that determination documented rather than defaulting either direction.

Can we use before-and-after photos in marketing if the patient already consented to treatment?

No. Consent to be photographed for the medical record and authorization to use that image in marketing are different instruments, and the treatment consent does not carry over. Marketing use requires a specific, written HIPAA authorization that identifies the use, and the patient can revoke it. Two practical consequences follow. First, the authorization has to be obtained separately and stored where it can be produced later — not assumed from an intake packet. Second, cropping out a face does not necessarily de-identify an image: a tattoo, scar, birthmark, or distinctive lesion can still identify a patient, and metadata inside the file often names them outright.

Is the government's Security Risk Assessment Tool mandatory?

No. The government's SRA Tool is one method designed to help small and medium-sized organizations perform the required analysis. HIPAA requires the underlying risk analysis — not the use of one particular tool. Patient Protect provides its own guided SRA and connects the findings directly to remediation, policies, tasks, and documentation.

Does our EHR make the practice HIPAA compliant?

No. An EHR may provide important safeguards for the records it maintains, but it does not conduct the practice's complete SRA, remediate every identified risk, train the workforce, manage all policies, identify every Business Associate, prepare the practice for incidents, or preserve the full body of compliance evidence.

How much does Patient Protect cost for a dermatology practice?

Patient Protect Basic costs $39 per office per month and includes up to 25 personnel. It includes the guided Security Risk Analysis, risk management, policies, workforce training, workforce and vendor management, BAA tracking, compliance scoring, and centralized documentation needed to operate the practice's core HIPAA compliance program.

Corrections & Updates

Healthcare security data changes as investigations progress, vendors update systems, and laws and guidance evolve. If you see something outdated, incomplete, or incorrect — or have newer source material — we’d appreciate hearing from you.

Submit a correction →

Patient Protect is intuitive, proactive, and affordable — exactly what small clinics like ours need to keep patient data safe and stay on the right side of HIPAA.
Dr. Thomas E Murray, D.D.S.Patient Protect Member Since 2017

Your dermatology practice handles some of the most sensitive visual data in healthcare.

See your real exposure in five minutes. Free risk assessment — no login required.

Or explore the full HIPAA compliance software comparison or all HIPAA compliance solutions