Are clinical photos considered PHI under HIPAA?
Yes. Clinical photographs that include identifying features — face, distinctive marks, tattoos, or any feature that could identify the patient — are protected health information under HIPAA. Even cropped or de-identified images may still qualify if they can be linked back to the patient through metadata or context.
Can I store dermatology photos on my phone?
Only with proper safeguards — full-disk encryption, passcode lock, documented BYOD policy, and no personal cloud backup of clinical images. Many practices use dedicated clinical photography apps that encrypt and upload directly to a secured EHR. Patient Protect's risk assessment evaluates your actual image handling workflow.
What does HIPAA compliance cost for a dermatology practice?
Patient Protect starts at $39/month with no contracts — covering risk assessments, policy generation, BAA tracking for labs and platforms, staff training, and continuous compliance monitoring. Whether you use it alongside your existing compliance partner or as a standalone solution.
Are clinical photos in dermatology PHI even when faces aren't visible?
Yes when linked to patient identity in the medical record. A close-up photograph of a lesion that's stored as part of the patient's chart is PHI regardless of whether the patient's face is visible — it's identifiable through the link to the patient record, not through facial recognition. Photos require BAA-covered storage, encryption, access controls, and audit trails like any other ePHI.
Do dermatopathology labs need a BAA?
Yes. Dermatopathology labs receive biopsy specimens accompanied by patient-identifying information for slide preparation, interpretation, and reporting. Each is a business associate under §160.103 and requires a written BAA before specimens flow. Practices using multiple dermatopathology partners need separate BAAs with each.
How are teledermatology consultations handled under HIPAA?
Teledermatology — both store-and-forward (asynchronous) and live video — is HIPAA-regulated when it involves PHI. Asynchronous consults transmit clinical photos and patient information to a remote dermatologist; the platform mediating the transmission is a business associate. Live video uses standard telehealth compliance frameworks. Both require BAAs with the platform vendor and audit trails of consult transmissions.
Does a dermatology practice have to complete a HIPAA Security Risk Analysis?
Yes, and photography is the part that most often falls outside it. Every covered practice must conduct and document an accurate, thorough assessment of the risks affecting all its ePHI. For dermatology that means the EHR and practice-management system alongside every device used to capture clinical images, camera rolls and automatic cloud synchronization, image upload and EHR attachment, the teledermatology platform, dermatopathology and biopsy workflows, portal and results delivery, and every vendor that can store, process, edit, or access identifiable clinical images. A practice whose SRA covers the EHR but not the phone in a clinician's pocket has not covered its highest-volume ePHI source.
Which of our dermatology vendors need Business Associate Agreements?
Any organization handling PHI on the practice's behalf: the EHR, practice-management and portal vendors, teledermatology platform, image storage and photo-management systems, any marketing or web vendor that receives identifiable images, transcription, billing service, claims clearinghouse, cloud backup, and IT support. Dermatopathology laboratories require classification rather than assumption — a laboratory receiving a specimen and rendering a diagnosis is generally a treating provider, which HHS does not treat as a business associate relationship, while a lab performing a service on the practice's behalf is. Get that determination documented rather than defaulting either direction.
Can we use before-and-after photos in marketing if the patient already consented to treatment?
No. Consent to be photographed for the medical record and authorization to use that image in marketing are different instruments, and the treatment consent does not carry over. Marketing use requires a specific, written HIPAA authorization that identifies the use, and the patient can revoke it. Two practical consequences follow. First, the authorization has to be obtained separately and stored where it can be produced later — not assumed from an intake packet. Second, cropping out a face does not necessarily de-identify an image: a tattoo, scar, birthmark, or distinctive lesion can still identify a patient, and metadata inside the file often names them outright.
Is the government's Security Risk Assessment Tool mandatory?
No. The government's SRA Tool is one method designed to help small and medium-sized organizations perform the required analysis. HIPAA requires the underlying risk analysis — not the use of one particular tool. Patient Protect provides its own guided SRA and connects the findings directly to remediation, policies, tasks, and documentation.
Does our EHR make the practice HIPAA compliant?
No. An EHR may provide important safeguards for the records it maintains, but it does not conduct the practice's complete SRA, remediate every identified risk, train the workforce, manage all policies, identify every Business Associate, prepare the practice for incidents, or preserve the full body of compliance evidence.
How much does Patient Protect cost for a dermatology practice?
Patient Protect Basic costs $39 per office per month and includes up to 25 personnel. It includes the guided Security Risk Analysis, risk management, policies, workforce training, workforce and vendor management, BAA tracking, compliance scoring, and centralized documentation needed to operate the practice's core HIPAA compliance program.