Skip to main content
Patient Protect circular logo mark in purple and white used for site navigationPatient Protect

HIPAA Compliance for Dermatology Practices

The HIPAA compliance and security operating system for dermatology practices. Clinical photography is the highest-volume ePHI in the practice and the least governed — capture, camera roll, cloud sync, EHR, pathology, portal, marketing. Patient Protect runs the risk analysis across that lifecycle, separates treatment use from marketing authorization, and keeps the proof together.

What HIPAA actually looks like for dermatology practices.

The regulatory framework, the enforcement patterns OCR has historically cited, the non-HIPAA standards that apply, the gaps audits routinely surface, and the record-retention overlay — HIPAA’s six-year rule for compliance documentation, and the separate state law that governs how long clinical records must be kept.

Regulatory framework

Dermatology practices operate under HIPAA as covered entities through standard electronic transactions — claims, eligibility, e-prescribing for topical and systemic dermatology medications. State dermatology board rules govern practice standards. State pathology rules apply to in-office laboratory testing under CLIA. The FDA cosmetic-vs-medical-device line affects practices performing aesthetic procedures alongside medical dermatology — the line determines whether records and procedures fall under HIPAA's medical framework or a different consumer-product regulatory frame.

OCR enforcement patterns

OCR's dermatology enforcement record has historically focused on clinical photo storage sitting outside the practice's control — personal cloud accounts and staff camera rolls with no agreement, no configuration, and no audit trail — alongside dermatopathology lab BAA gaps and teledermatology transmission errors. Photo storage is the single highest-frequency exposure in this segment because dermatology's clinical photography volume far exceeds what an unmanaged personal account can support. The problem is the unmanaged account, not the vendor's name: the same provider's business tier under a BAA, properly configured, is a different question.

Standards beyond HIPAA

DICOM for clinical photography and dermatoscopy. CLIA for in-office laboratory testing. State pathology rules for biopsy specimens and dermatopathology workflow. The FDA cosmetic-vs-medical-device distinction governing aesthetic procedures. State dermatology board rules on cosmetic procedures performed by non-physician staff. State Medicaid and Medicare rules for medically-necessary versus cosmetic procedure billing.

Common compliance gaps

Dermatology practice compliance gaps cluster around clinical photography: photos taken on staff personal devices, photos stored on consumer cloud platforms without BAAs, before/after marketing photos used without explicit photography-specific consent, mole-mapping photo retention not aligned with state retention rules, and dermatopathology lab BAAs assumed but not signed. Mohs surgery practices have additional compliance complexity around multi-stage photo and pathology integration.

Compliance documentation, then state record law.

HIPAA's six-year rule governs compliance documentation, not clinical records (§164.530(j)). State dermatology and medical practice record laws govern patient record retention — typically seven to ten years. Photographs as part of the medical record are subject to the same retention as the chart. Biopsy specimens are retained per CLIA requirements (typically seven years for surgical pathology slides, ten years for blocks). Dermatopathology slides and reports are subject to separate state-specific retention rules. Cosmetic procedure records may have their own retention framework distinct from medical dermatology records.

Reference summary, not legal advice. This page summarizes how HIPAA and adjacent regulatory frameworks apply to dermatology practices based on Patient Protect’s reading of the relevant CFR provisions, OCR enforcement record, and state statutes. Operators with specific compliance questions should consult a qualified HIPAA attorney. Patient Protect is a HIPAA compliance platform; we are not a law firm and do not provide legal advice.

Where dermatology practices are most exposed.

Clinical photography creates high-risk ePHI

Before-and-after photos, dermoscopy images, and wound documentation are ePHI the moment they include identifying features. Storage on personal phones, unencrypted cloud folders, or shared drives without access controls is a breach waiting to happen.

Teledermatology platforms need BAAs and encryption

Virtual consultations, store-and-forward imaging, and asynchronous dermatology platforms all transmit ePHI. Each platform requires a signed BAA, end-to-end encryption, and documented security configurations.

Pathology and lab integrations introduce vendor risk

Biopsy reports, lab results, and pathology consultations flow between your practice and external labs. Each exchange point requires a BAA and encrypted transmission. Most practices don't audit these data flows.

Marketing use of patient images requires documented authorization

Using patient photos for social media, websites, or marketing materials requires specific written authorization separate from the general consent for treatment. HIPAA authorization for marketing use has strict requirements that generic consent forms rarely satisfy.

Built for dermatology practices, not hospital systems.

Clinical photography risk assessment

SRA wizard evaluates image capture devices, storage locations, transmission methods, and access controls — specific to dermatology workflows.

Vendor BAA tracking for labs and platforms

Full BAA lifecycle management for pathology labs, teledermatology platforms, and imaging services — with renewal alerts and status tracking.

Policy generation for image handling

Auto-generated policies covering clinical photography, marketing authorization, image retention, and device management — customized to your practice.

Staff training on image privacy

Training modules covering clinical photography compliance, marketing authorization requirements, and secure image handling workflows.

Clinical photo storage compliance with BAA-covered infrastructure

Dermatology practices generate massive clinical photo volumes — mole mapping, before/after, biopsy site documentation, treatment progression. Photos linked to patient identity are PHI. The platform handles BAA-covered photo storage with the access logging and retention controls clinical photos require.

Pathology lab BAA tracking and Mohs surgery records

Dermatopathology labs receiving biopsy specimens with patient identifiers are business associates. Mohs surgery records — multi-stage, photo-heavy, often involving on-site pathology — create additional storage and BAA surfaces. The platform tracks the dermatology-specific lab and pathology vendor ecosystem rather than treating it as generic medical-practice infrastructure.

State-specific HIPAA rules for dermatology practices.

HIPAA is federal — but your state layers additional breach notification deadlines, AG reporting requirements, and privacy laws on top. Select your state to see what applies to your practice.

District of Columbia compliance requirements for dermatology practices

In addition to federal HIPAA requirements, dermatology practices operating in District of Columbia must comply with the following state-specific obligations.

Breach notification deadline

In the most expedient time possible and without unreasonable delay, subject to the needs of law enforcement and any measures necessary to determine the scope of the breach and restore the reasonable integrity of the data system.

The statute does not fix a numeric outer bound. Unreasonable delay is itself a violation and may result in state enforcement action, so treat the operative timeframe as the shortest window your incident circumstances reasonably support.

Attorney General notification

Required for all breaches

Your practice must notify the state AG in addition to affected patients and HHS.

District of Columbia-specific laws & requirements

DC uses the New-York pattern: HIPAA covers individual notice, but AG notice is independent

For HIPAA-regulated entities operating in DC, satisfying HIPAA breach-notification obligations to individuals is deemed to satisfy the § 28-3852 individual-notice requirement under subsection (g). But the separate DC Attorney General notification obligation under § 28-3852(b-1) is triggered independently once a breach affects 50 or more DC residents, and HIPAA compliance does not substitute for that AG notice. Practices notifying HHS under HIPAA still owe a separate written AG notice to DC.

Source: D.C. Code § 28-3852(a)

Verified against primary state authority as of August 2026. General reference — consult legal counsel for your specific obligations.

Primary sources: code.dccouncil.gov · oag.dc.gov

What happens after the paperwork is done.

Every major compliance platform covers risk assessments and policy templates. This is the part that differs.

What to ask

Patient Protect

01

Risk assessment that satisfies §164.308(a)(1)

A readiness quiz is not a risk analysis.

Full SRA wizard mapped to NIST CSF with live scoring

02

Auto-generated policies with workforce acknowledgment

HIPAA requires documented proof your staff reviewed them.

48 policies from your risk profile, versioned acknowledgment

03

Staff training with delivery tracking

§164.308(a)(5) — sending a PDF is not sufficient.

HIPAA Foundations — 19 modules, 95 assessment questions, verifiable certificates

04

Full BAA lifecycle management

Expired BAAs are a top enforcement target.

E-signature, renewal alerts, Vendor Risk Scanner

Yes on all 10. Now run the checklist on the rest.

From $39/mo · No long-term contracts.

Enterprise-grade compliance. Independent-practice pricing.

No contracts · No setup fees · Cancel anytime

Basic

$39/mo

Risk assessments, policies, BAA management, training, and compliance scoring.

Recommended

Pro

$99/mo

Everything in Basic plus secure messaging, breach intelligence, live diagnostics, and AI compliance assistant.

See full feature comparison →

Common questions about HIPAA compliance for dermatology practices.

Are clinical photos considered PHI under HIPAA?

Yes. Clinical photographs that include identifying features — face, distinctive marks, tattoos, or any feature that could identify the patient — are protected health information under HIPAA. Even cropped or de-identified images may still qualify if they can be linked back to the patient through metadata or context.

Can I store dermatology photos on my phone?

Only with proper safeguards — full-disk encryption, passcode lock, documented BYOD policy, and no personal cloud backup of clinical images. Many practices use dedicated clinical photography apps that encrypt and upload directly to a secured EHR. Patient Protect's risk assessment evaluates your actual image handling workflow.

What does HIPAA compliance cost for a dermatology practice?

Patient Protect starts at $39/month with no contracts — covering risk assessments, policy generation, BAA tracking for labs and platforms, staff training, and continuous compliance monitoring. Whether you use it alongside your existing compliance partner or as a standalone solution.

Are clinical photos in dermatology PHI even when faces aren't visible?

Yes when linked to patient identity in the medical record. A close-up photograph of a lesion that's stored as part of the patient's chart is PHI regardless of whether the patient's face is visible — it's identifiable through the link to the patient record, not through facial recognition. Photos require BAA-covered storage, encryption, access controls, and audit trails like any other ePHI.

Do dermatopathology labs need a BAA?

Yes. Dermatopathology labs receive biopsy specimens accompanied by patient-identifying information for slide preparation, interpretation, and reporting. Each is a business associate under §160.103 and requires a written BAA before specimens flow. Practices using multiple dermatopathology partners need separate BAAs with each.

How are teledermatology consultations handled under HIPAA?

Teledermatology — both store-and-forward (asynchronous) and live video — is HIPAA-regulated when it involves PHI. Asynchronous consults transmit clinical photos and patient information to a remote dermatologist; the platform mediating the transmission is a business associate. Live video uses standard telehealth compliance frameworks. Both require BAAs with the platform vendor and audit trails of consult transmissions.

Does a dermatology practice have to complete a HIPAA Security Risk Analysis?

Yes, and photography is the part that most often falls outside it. Every covered practice must conduct and document an accurate, thorough assessment of the risks affecting all its ePHI. For dermatology that means the EHR and practice-management system alongside every device used to capture clinical images, camera rolls and automatic cloud synchronization, image upload and EHR attachment, the teledermatology platform, dermatopathology and biopsy workflows, portal and results delivery, and every vendor that can store, process, edit, or access identifiable clinical images. A practice whose SRA covers the EHR but not the phone in a clinician's pocket has not covered its highest-volume ePHI source.

Which of our dermatology vendors need Business Associate Agreements?

Any organization handling PHI on the practice's behalf: the EHR, practice-management and portal vendors, teledermatology platform, image storage and photo-management systems, any marketing or web vendor that receives identifiable images, transcription, billing service, claims clearinghouse, cloud backup, and IT support. Dermatopathology laboratories require classification rather than assumption — a laboratory receiving a specimen and rendering a diagnosis is generally a treating provider, which HHS does not treat as a business associate relationship, while a lab performing a service on the practice's behalf is. Get that determination documented rather than defaulting either direction.

Can we use before-and-after photos in marketing if the patient already consented to treatment?

No. Consent to be photographed for the medical record and authorization to use that image in marketing are different instruments, and the treatment consent does not carry over. Marketing use requires a specific, written HIPAA authorization that identifies the use, and the patient can revoke it. Two practical consequences follow. First, the authorization has to be obtained separately and stored where it can be produced later — not assumed from an intake packet. Second, cropping out a face does not necessarily de-identify an image: a tattoo, scar, birthmark, or distinctive lesion can still identify a patient, and metadata inside the file often names them outright.

Is the government's Security Risk Assessment Tool mandatory?

No. The government's SRA Tool is one method designed to help small and medium-sized organizations perform the required analysis. HIPAA requires the underlying risk analysis — not the use of one particular tool. Patient Protect provides its own guided SRA and connects the findings directly to remediation, policies, tasks, and documentation.

Does our EHR make the practice HIPAA compliant?

No. An EHR may provide important safeguards for the records it maintains, but it does not conduct the practice's complete SRA, remediate every identified risk, train the workforce, manage all policies, identify every Business Associate, prepare the practice for incidents, or preserve the full body of compliance evidence.

How much does Patient Protect cost for a dermatology practice?

Patient Protect Basic costs $39 per office per month and includes up to 25 personnel. It includes the guided Security Risk Analysis, risk management, policies, workforce training, workforce and vendor management, BAA tracking, compliance scoring, and centralized documentation needed to operate the practice's core HIPAA compliance program.

Patient Protect is intuitive, proactive, and affordable — exactly what small clinics like ours need to keep patient data safe and stay on the right side of HIPAA.
Dr. Thomas E Murray, D.D.S.Patient Protect Member Since 2017

Your dermatology practice handles some of the most sensitive visual data in healthcare.

See your real exposure in five minutes. Free risk assessment — no login required.

Or explore the full HIPAA compliance software comparison or all HIPAA compliance solutions