Common HIPAA Violations Radiologists Should Know—and How to Avoid Them

Product Pricing
Ready to get started? Book a demo with our team
Talk to an expert

Common HIPAA Violations Radiologists Should Know—and How to Avoid Them

Kevin Henry

HIPAA

June 17, 2026

7 minutes read
Share this article
Common HIPAA Violations Radiologists Should Know—and How to Avoid Them

Unauthorized Access to Patient Records

In radiology, “curiosity viewing” is one of the most common HIPAA missteps—opening a study in PACS without a job-related reason. Accessing a family member’s CT, browsing a celebrity’s MRI, or leaving a shared workstation unlocked can all be unauthorized access events that expose electronic Protected Health Information (ePHI).

Red flags to watch for

  • Viewing images outside your assignment, such as cases from other services or locations “just to learn.”
  • Using shared or generic logins that hide who actually opened a study.
  • Pulling prior exams “just in case,” exceeding the minimum necessary standard.

Practical safeguards

  • Implement role-based access control (RBAC) to limit which worklists, studies, and reports each role can see.
  • Enable audit logs and real-time alerts for unusual access patterns; investigate and document findings.
  • Use automatic workstation lock and session timeout in reading rooms, procedure suites, and clinics.
  • Adopt “break-the-glass” workflows with justification and post-access review for sensitive records.
  • Reinforce sanctions and just-in-time privacy reminders during sign-on or before opening restricted studies.

Conducting Comprehensive Risk Analysis

A risk analysis is the backbone of HIPAA compliance. It helps you identify where ePHI lives across your imaging ecosystem—from modalities and workstations to RIS/PACS, speech recognition, and cloud archives—and how threats could compromise confidentiality, integrity, or availability.

A radiology-focused approach

  • Inventory assets: PACS/RIS, modality consoles (CT, MR, US), dictation servers, image sharing portals, mobile viewers, VPNs, backup systems, and offsite storage.
  • Map data flows: DICOM, HL7, APIs, and exports to teaching files or research databases.
  • Identify vulnerabilities: outdated modality OS, weak remote access, unencrypted media, excessive local caching, or misconfigured routing nodes.
  • Assess likelihood and impact: consider downtime risks that delay patient care, ransomware exposure, and reputational harm.
  • Mitigate and document: choose administrative, physical, and technical safeguards, assign owners, and set target dates.

Revisit the analysis at least annually and whenever you add a cloud archive, deploy AI tools, change teleradiology workflows, or sunset equipment. Align controls with the minimum necessary standard to reduce exposure surface area.

Establishing Business Associate Agreements

Business Associate Agreements (BAAs) are mandatory with vendors that create, receive, maintain, or transmit PHI for your practice. In radiology, this commonly includes teleradiology providers, PACS/RIS and cloud archive vendors, speech recognition platforms, image exchange networks, billing companies, IT MSPs, and AI solution providers.

What your BAA should cover

  • Permitted uses and disclosures of PHI and alignment with the minimum necessary standard.
  • Administrative, physical, and technical safeguards the vendor must maintain for ePHI.
  • Breach reporting duties, timing, cooperation on investigation, and mitigation procedures.
  • Downstream obligations ensuring subcontractors follow the same protections.
  • Data return or destruction at termination, plus assistance with secure transition.

Operational tips

  • Perform vendor due diligence: security questionnaires, references, and proof of safeguards.
  • Limit data scope shared with each vendor—configure interfaces to transmit only what’s needed.
  • Track BAA versions, renewal dates, and responsible owners; centralize documentation.
  • Test incident response with vendors so both sides can act quickly if ePHI is at risk.

Implementing Access Controls

Strong access controls ensure only the right people reach the right data at the right time. Build defenses around identity, authorization, and verification across all systems that store or transport ePHI.

Key controls to enforce

  • Role-based access control to segment reading, technologist, transcription, clerical, and trainee access.
  • Multi-factor authentication for remote access, privileged accounts, and any system exposed to the internet.
  • Unique user IDs, no shared accounts, and rapid provisioning/deprovisioning tied to HR events.
  • Contextual limits, such as restricting batch downloads or disabling export on kiosk or shared viewers.
  • Automatic logoff and screen privacy filters in high-traffic work areas.

Design workflows so users naturally comply with the minimum necessary standard: focused worklists, targeted prior retrieval, and “break-the-glass” for exceptional cases with justification.

Ready to simplify HIPAA compliance?

Join thousands of organizations that trust Accountable to manage their compliance needs.

Preventing Impermissible Use or Disclosure of PHI

Impermissible disclosures often happen during routine tasks: sending images to the wrong recipient, including identifiers in teaching slides, or discussing cases in public zones. In radiology, DICOM headers, voice dictation files, and image annotations can all carry PHI.

Keep disclosures appropriate and secure

  • Verify recipient identity and destination before transmitting reports, images, or CDs; use secure messaging whenever possible.
  • Apply the minimum necessary standard when sharing for operations, QA, teaching, or research.
  • De-identify images and reports for education; scrub DICOM headers and overlays before publication.
  • Avoid unapproved apps or personal email for PHI; use systems covered by BAAs and controlled by your organization.
  • Train staff to recognize social engineering and to escalate suspected misdirected disclosures immediately.

Applying Adequate Safeguards for PHI

Balanced administrative, physical, and technical safeguards protect PHI across your practice. Treat them as mutually reinforcing layers that reduce risk and support reliable patient care.

Administrative safeguards

  • Written policies for privacy, security, sanctions, device/media control, and contingency planning.
  • Role-based training and periodic drills covering PACS etiquette, secure image sharing, and incident reporting.
  • Vendor management: BAAs, risk assessments, and security addenda for integrations.
  • Change control and patching processes for modalities, workstations, and servers.

Physical safeguards

  • Controlled access to reading rooms, server closets, and archives; visitor logs where appropriate.
  • Workstation protections: privacy screens, cable locks, and secure placement away from public view.
  • Media controls: locked storage for films and portable media; documented chain of custody.

Technical safeguards

  • Encryption in transit and at rest for PACS, archives, backups, and image exchange.
  • Granular RBAC, audit logging, integrity checks, and anomaly detection.
  • Multi-factor authentication for external access and privileged administration.
  • Automated log retention and review procedures to spot policy violations early.

Ensuring Proper PHI Disposal

Improper disposal—like tossing image CDs in regular trash or reselling modality drives without sanitization—can trigger reportable breaches. Create clear procedures for every medium that may store PHI.

Disposal practices that work

  • Purge and cryptographically wipe or physically destroy drives in modalities, workstations, and retired PACS servers; keep certificates of destruction.
  • Shred paper worksheets, fax confirmations, and labels; never discard in open bins.
  • Use approved destruction for CDs/DVDs/USBs; consider disintegrators or contracted shredding with documented chain of custody.
  • Sanitize DICOM files used for teaching by removing identifiers from headers and overlays.
  • Define retention schedules and hold procedures so backups with ePHI are not discarded prematurely.

Summary and next steps

Focus on the basics: control access, share only what’s necessary, harden systems, manage vendors with BAAs, and dispose of PHI securely. Pair your risk analysis with layered administrative, physical, and technical safeguards, and you will reduce the most common HIPAA exposures in radiology while protecting patients and your practice.

FAQs.

What are the most common HIPAA violations radiologists face?

Typical violations include snooping in PACS without a job-related need, misdirected reports or image transfers, leaving unlocked workstations in shared spaces, sharing identifiers in teaching slides, and improper disposal of PHI on paper or media. Weak access controls and missing BAAs with vendors also frequently lead to reportable incidents.

How can radiologists protect ePHI from unauthorized access?

Use role-based access control to limit who can view studies, enforce multi-factor authentication for remote and privileged access, and apply the minimum necessary standard to worklists and prior retrieval. Combine these with automatic logoff, comprehensive audit logging, and prompt user provisioning and deprovisioning to keep ePHI exposure small and traceable.

What steps should be taken to properly dispose of PHI?

Establish written procedures that require shredding of paper, certified destruction of CDs/USBs, and cryptographic wiping or physical destruction of drives from modalities and workstations. Maintain chain-of-custody records, obtain certificates of destruction from vendors, and ensure teaching files are de-identified before public or educational use.

How important are Business Associate Agreements in radiology practices?

BAAs are essential whenever a vendor handles PHI. They legally bind partners to protect data, notify you of incidents, and flow down safeguards to subcontractors. In radiology—where cloud archives, teleradiology, speech recognition, and image exchange are common—robust BAAs, paired with due diligence, reduce vendor risk and close critical compliance gaps.

Share this article

Ready to simplify HIPAA compliance?

Join thousands of organizations that trust Accountable to manage their compliance needs.

Related Articles