HIPAA Compliance for Mohs Dermatology Clinics: A Practical Guide to Photographing Surgical Margins for Pathology Review
Accurate photographs of surgical margins can speed pathology interpretation, improve map-to-specimen correlation, and document each Mohs stage. Because these images often contain identifiers or can be linked to a patient record, you must handle them under HIPAA with the same rigor as any other ePHI.
This practical guide explains how covered dermatology practices can capture, store, and share margin photos compliantly—without slowing clinical workflow. It is informational and not legal advice; confirm requirements with counsel and your compliance officer.
HIPAA Applicability to Dermatology
Mohs practices as a Covered Entity
If your clinic transmits health information electronically in connection with standard transactions (for example, claims), it is a Covered Entity under HIPAA. That status extends HIPAA obligations to clinical photography tied to patient care, including surgical margin documentation for pathology review.
Treatment, payment, operations, and the “minimum necessary” nuance
Using and disclosing images for treatment—such as sharing margin photos with a dermatopathologist—does not require patient authorization under HIPAA. The “minimum necessary” standard does not apply to disclosures for treatment, but you should still limit photos and accompanying data to what the consultant needs.
Business Associates and downstream vendors
Any vendor that creates, receives, maintains, or transmits images or related PHI on your behalf (for example, secure camera apps, cloud storage, or messaging tools) must sign a Business Associate Agreement. Disclosures to another Covered Entity for treatment (such as a pathology lab) do not require a BAA, but you must still ensure secure transmission and proper handling.
Clinical Photography as Protected Health Information
When a photo becomes PHI
Clinical photos are Protected Health Information when they directly identify a patient or can reasonably be linked to a patient record. Identifiers can appear in the frame (face, tattoos, name bands) or be attached through context (chart overlays, room whiteboards) and metadata (timestamps, device IDs, GPS).
Mohs-specific capture that respects privacy
- Photograph the lesion, inking patterns, and specimen orientation (for example, a clock-face marker) without including the patient’s face or extraneous background.
- Use a ruler or scale for size and a consistent orientation marker so the pathologist can align maps and blocks.
- Avoid displaying screens, labels, or forms that show names, MRNs, or dates of birth.
- Keep identifiable body features outside the frame unless clinically necessary for pathology correlation.
Consent and Authorization Requirements
Informed Consent versus HIPAA Authorization for Use and Disclosure
Informed Consent is a clinical and ethical process that explains why you are photographing and how images support care. A HIPAA Authorization for Use and Disclosure is a separate, formal permission required for non-treatment purposes (for example, marketing, external teaching, or publication).
Ready to simplify HIPAA compliance?
Join thousands of organizations that trust Accountable to manage their compliance needs.
When consent or authorization is required
- Treatment: You may capture and share photos for patient care without a HIPAA authorization. Still, obtain informed consent to photograph, and follow any state laws or payer/credentialing rules that require written consent.
- Non-treatment: Obtain a signed Authorization for Use and Disclosure before using images for marketing, external presentations, or research outside routine operations. Store the authorization with the record and honor revocations prospectively.
- Special cases: For minors or surrogate decision-makers, document who provided consent and, when applicable, re-consent at majority.
Workflow tips that hold up under audit
- Include clinical photography in your consent-to-treat packet and document patient discussions in the EHR.
- Use standardized phrases (for example, “clinical photography for surgical margin documentation and pathology review”).
- Record any limits a patient sets (for example, “internal use only”).
Secure Storage and Sharing of Images
Capture controls at the point of care
- Use secure, enterprise camera apps that save directly to the EHR or a controlled repository; do not allow images to persist in the personal camera roll.
- Disable automatic cloud backups and geotagging on capture devices used for PHI.
- Enforce mobile device management with strong authentication, encryption, auto-lock, and remote wipe.
Storage that meets HIPAA’s Security Rule
- Store images where encryption at rest, role-based access, and audit logging are standard.
- Adopt neutral file naming (no names, DOBs, or full MRNs). Use an internal identifier mapped within the EHR.
- Limit staff access to those with a treatment-related need and review access logs regularly.
Sharing with pathology and within the care team
- Prefer EHR-to-lab interfaces, secure portals, or SFTP. If using email, ensure encryption in transit and verify recipient addresses.
- Do not use SMS, MMS, or consumer chat apps for PHI. Use only tools with executed BAAs.
- Confirm receipt when images affect immediate patient management and document the disclosure.
De-Identification and Metadata Considerations
Safe Harbor De-Identification
Under Safe Harbor De-Identification, you must remove specified identifiers so the remaining information cannot identify an individual. For photography, that includes removing full-face or comparable images, precise geolocation, dates more granular than year, contact numbers, device IDs, and any textual labels that reveal identity.
Expert Determination Method
Alternatively, a qualified expert can determine that the risk of re-identification is very small and document the methods and results. This Expert Determination Method is useful when you need richer image detail for teaching or analytics yet want to release data outside HIPAA controls.
Practical metadata hygiene
- Strip EXIF/IPTC metadata (GPS, device serials, timestamps) before external use or when de-identifying.
- Turn off location services on capture devices used for clinical photography.
- Keep any linkage file (image ID to patient ID) inside the EHR or a secure system, not alongside exported images.
Teledermatology and Secure Image Transmission
Store-and-forward and live telehealth
Whether you send still images asynchronously or use live video for intraoperative consultation, the same HIPAA safeguards apply. Treat the platform as part of your ePHI ecosystem and validate its security posture before go-live.
Transmission security and patient communications
- Use platforms that provide strong encryption in transit, multifactor authentication, and access controls.
- Avoid unencrypted channels. If a patient insists on receiving images via unencrypted email or text, document that preference and counsel on risks.
- Configure retention and auto-deletion so transient messages don’t linger on unmanaged devices.
Security Risk Analysis and Record Retention Policies
Security Risk Analysis for imaging workflows
- Inventory where images are captured, stored, and transmitted (cameras, phones, EHR, portals, lab interfaces).
- Identify threats and vulnerabilities (lost devices, misaddressed email, metadata leaks) and rate their likelihood and impact.
- Implement controls: technical (encryption, MDM, audit logs), administrative (policies, training, sanctions), and physical (device locks, restricted areas).
- Document findings, a risk management plan, and periodic evaluations—repeat after major changes or incidents.
Record retention and patient rights
- Retain HIPAA-required documentation (policies, procedures, BAAs, authorizations, and Security Risk Analysis records) for at least six years from creation or last effective date.
- Treat clinical photos that form part of the designated record set as part of the medical record and retain them per your state’s medical record laws and payer or accreditor requirements.
- Define how long transient copies may exist on devices and ensure secure deletion. Use media sanitization procedures when retiring hardware.
- Maintain processes to fulfill patient right-of-access requests for images in a timely, secure manner.
Conclusion
For Mohs clinics, compliant margin photography rests on three pillars: clear consent practices, secure-by-default technology, and disciplined governance. If you capture only what pathology needs, keep images inside managed systems, and document your Security Risk Analysis and retention rules, you will support excellent care while meeting HIPAA obligations.
FAQs.
What constitutes PHI in clinical photography?
Any photo that identifies a patient or can reasonably be linked to a patient record is PHI. That includes visible features (face, tattoos), contextual clues (charts on the wall, labeled specimen jars), and metadata (GPS, timestamps, device IDs). Even a close-up of a margin can be PHI if it’s stored with identifiers or tied to the chart.
How should Mohs clinics obtain consent for surgical margin photos?
Incorporate clinical photography into your informed consent-to-treat process and document it in the EHR. For routine treatment and pathology review, a HIPAA authorization isn’t required, but written consent is best practice and may be required by state law. Obtain a separate Authorization for Use and Disclosure for any non-treatment use such as marketing or external education.
What are secure methods for storing and sharing clinical images?
Capture with secure apps that save directly to your EHR or a protected repository, enforce encryption, role-based access, and audit logs, and disable personal cloud backups. Share via EHR interfaces, secure portals, or encrypted email; avoid SMS or consumer chat. Use only vendors with executed BAAs and verify recipient details before sending.
How can metadata affect HIPAA compliance in dermatology photography?
Image metadata can expose identifiers like GPS location, device serials, and precise timestamps that enable re-identification. Disable geotagging on capture devices, strip EXIF/IPTC data before external use, avoid putting names or MRNs in filenames, and store any mapping between image IDs and patient IDs inside the EHR or a secure system.
Table of Contents
- HIPAA Applicability to Dermatology
- Clinical Photography as Protected Health Information
- Consent and Authorization Requirements
- Secure Storage and Sharing of Images
- De-Identification and Metadata Considerations
- Teledermatology and Secure Image Transmission
- Security Risk Analysis and Record Retention Policies
- FAQs.
Ready to simplify HIPAA compliance?
Join thousands of organizations that trust Accountable to manage their compliance needs.