HIPAA Compliance Guide for Pelvic Floor Therapy Internal Exam Video Storage

Product Pricing
Ready to get started? Book a demo with our team
Talk to an expert

HIPAA Compliance Guide for Pelvic Floor Therapy Internal Exam Video Storage

Kevin Henry

HIPAA

August 17, 2026

8 minutes read
Share this article
HIPAA Compliance Guide for Pelvic Floor Therapy Internal Exam Video Storage

HIPAA Applicability to Video Recordings

HIPAA applies when a video is created or received by a covered entity or a business associate and contains individually identifiable health information related to a patient’s condition, treatment, or payment. An internal exam video captured during pelvic floor therapy typically meets this standard, making it Protected Health Information (PHI). When captured, stored, or transmitted electronically, it is electronic PHI (ePHI).

Apply the Minimum Necessary Rule from the HIPAA Privacy Rule to the entire lifecycle of video capture and use. Record only what is clinically necessary, restrict who can access it, and limit disclosures to the smallest scope needed for care, operations, or payment.

When a recording may not be PHI

If a video is fully de-identified using accepted methods (for example, removing all identifiers and any features that could reasonably identify a patient), it is no longer PHI. In practice, internal exam videos are difficult to de-identify reliably; treat them as PHI unless a qualified expert determines otherwise.

Definition of Protected Health Information

Protected Health Information (PHI) is any information that identifies a patient and relates to past, present, or future physical or mental health, the provision of care, or payment for care. Identifiers include obvious elements (name, face, voice) and less obvious ones (dates, medical record numbers, unique markings, or combinations of data that can reasonably identify a person). Internal exam videos often include unique anatomical features or synchronized metadata that can re-identify an individual, so you should handle them as PHI.

Is the recording part of the Designated Record Set?

The Designated Record Set (DRS) includes records used to make decisions about a patient. If the video informs diagnosis, treatment planning, progress tracking, or is referenced in clinical notes, it likely belongs in the DRS. When a video is in the DRS, patients have specific rights to access and obtain a copy, and your retention practices should align with your medical record policy and applicable law.

Security Safeguards for Video Recordings

Administrative Safeguards

  • Conduct and document a risk analysis focused on the capture, storage, transmission, and disclosure of internal exam videos; update it with any workflow or vendor change.
  • Adopt written policies that enforce the Minimum Necessary Rule, specify who may record and view videos, and define how long recordings are retained and how they are disposed of.
  • Train your workforce on sensitive-handling procedures for pelvic floor therapy recordings; include sanctions for violations.
  • Establish contingency plans: tested backups, disaster recovery, and emergency mode operations for video systems.
  • Vet vendors, execute a Business Associate Agreement (BAA), and verify their security controls before any data flows.

Physical Safeguards

  • Control the recording environment: restrict recording devices to clinical areas, prohibit personal/BYOD recording, and secure rooms and servers.
  • Implement device and media controls: inventory devices, restrict removable media, and apply secure media reuse and disposal procedures.
  • Protect workstations used for playback with privacy screens and location-based controls to reduce incidental exposure.

Technical Safeguards

  • Enforce unique user IDs, role-based access, and multi-factor authentication for systems that store or play ePHI.
  • Enable comprehensive audit logging: access time, user, action, device, and IP; review logs routinely and upon any incident.
  • Apply integrity controls: cryptographic checksums or object-locking to detect alteration.
  • Use strong Encryption of ePHI in transit (TLS 1.2+ or equivalent) and at rest (AES-256 or better with FIPS-validated modules).
  • Disable local downloads by default; prefer secure streaming with expiring, single-use links where operationally feasible.
  • Implement automated session timeouts, clipboard/download restrictions, and watermarking to deter misuse.

Operational controls specific to video

  • Standardize file naming that omits patient identifiers; store linkage in secure metadata, not filenames.
  • Segment storage (e.g., per-tenant buckets) and apply least-privilege access to minimize blast radius of an incident.
  • Document a breach response plan with defined roles, timelines, patient notification, and corrective actions.

Business Associate Agreements

Any vendor that creates, receives, maintains, or transmits exam videos containing PHI is a business associate. You must have a Business Associate Agreement (BAA) in place before onboarding the service. This typically includes cloud storage providers, video platforms, EHR modules handling video, backup vendors, and analytics or transcription services.

Ready to simplify HIPAA compliance?

Join thousands of organizations that trust Accountable to manage their compliance needs.

What your BAA should address

  • Permitted uses and disclosures, including clear limits on secondary use (e.g., analytics or training).
  • Security obligations: Encryption of ePHI at rest and in transit, access controls, audit logging, and vulnerability management.
  • Breach notification to you without unreasonable delay, and no later than the federal deadline; include reporting details and cooperation duties.
  • Downstream compliance: require subcontractors to sign equivalent BAAs and meet the same safeguards.
  • Data rights and exit: return or destroy PHI upon termination and provide attestations of destruction.
  • Support for patient rights requests when the video is in the Designated Record Set.

Patient Rights Over Recorded Video

Under the HIPAA Privacy Rule, patients have the right to access and obtain a copy of PHI contained in the Designated Record Set. If the video is in your DRS, you must provide access within 30 days (one 30-day extension permitted with written explanation). Provide it in the form and format requested if readily producible; otherwise, offer an agreed alternative.

  • Reasonable, cost-based fees are allowed for labor, media, and postage; avoid fees that deter access.
  • Verify identity before release and use secure transfer methods (e.g., encrypted portal or encrypted media with separate key exchange).
  • For amendments, do not overwrite the original video. Append an explanatory addendum or clinician note and link it to the recording.
  • Honor valid requests for restrictions and confidential communications to the extent required by HIPAA and applicable law.
  • Maintain an accounting of certain disclosures as required, especially those outside treatment, payment, and operations.

Encryption of Stored Recordings

Encryption is a critical safeguard and a strong risk reducer for internal exam videos. Encrypt data at rest with AES-256 (or stronger) using FIPS-validated cryptographic modules. Encrypt in transit with modern protocols (TLS 1.2+ or equivalent). Manage keys in a dedicated key management service (KMS) or hardware security module with strict separation of duties.

Practical encryption and key management tips

  • Rotate encryption keys on a defined schedule and upon role changes or suspected compromise; monitor and log all key use.
  • Segment keys per environment and sensitivity level; avoid shared master keys across tenants or systems.
  • Encrypt backups and replicas; verify you can restore encrypted data reliably during disaster recovery tests.
  • Protect endpoints: full-disk encryption, secure boot, remote wipe, and blocked removable media on devices used for capture or viewing.
  • When sharing, use expiring, single-use links and avoid embedding PHI in URLs, filenames, or email subjects.

Retention Period for Video Recordings

HIPAA does not prescribe a universal retention period for medical records or videos. It does require you to retain HIPAA-required documentation (such as policies, risk analyses, and BAAs) for six years. The appropriate retention period for internal exam videos depends on state medical record laws, payer requirements, and your policy—especially if the video is part of the Designated Record Set.

How to set a defensible retention policy

  • Classify videos as part of the medical record when they inform clinical decisions; align retention with your medical record schedule and state law.
  • Apply holds for litigation, audits, or investigations that require preservation beyond normal schedules.
  • Define secure deletion procedures consistent with recognized media sanitization practices; log destruction events and retain those logs.
  • Periodically review retention rules to reflect changes in care standards, technology, and legal requirements.

Key takeaways

  • Treat pelvic floor internal exam videos as PHI/ePHI by default and apply Administrative Safeguards, encryption, and least-privilege access.
  • Use BAAs with any vendor touching the recordings and verify their controls.
  • If a video is in the Designated Record Set, patients have access rights and your retention policy should match your medical record rules and applicable law.

FAQs

What are the HIPAA requirements for storing internal exam videos?

You must treat the videos as PHI/ePHI: conduct a risk analysis, implement Administrative Safeguards, restrict access under the Minimum Necessary Rule, use strong encryption in transit and at rest, maintain audit logs, and store them with vendors under a signed BAA. If the video is part of the Designated Record Set, support patient access, amendments via addendum, and proper retention and disposal.

How should pelvic floor therapy videos be encrypted for compliance?

Encrypt at rest with AES-256 (FIPS-validated) and in transit with TLS 1.2 or higher. Manage keys in a dedicated KMS or HSM, rotate keys regularly, encrypt backups, and prefer secure streaming with expiring links over downloads. Protect endpoints with full-disk encryption and remote wipe.

Is patient authorization always required to record internal exams?

HIPAA allows recording for treatment, payment, and healthcare operations without a separate HIPAA authorization, but you should still obtain informed consent due to the sensitivity of pelvic floor exams and to satisfy state consent and recording laws. When recording is for non-TPO purposes (e.g., external education or marketing), obtain written patient authorization that clearly states the intended use.

How long must internal exam videos be retained under HIPAA?

HIPAA does not set a universal retention period for videos. Retain HIPAA-required documentation for six years, and set video retention based on state medical record laws, payer rules, and your policy. If the video is part of the Designated Record Set, align its retention with your medical record schedule and preserve it during any legal or audit hold.

Share this article

Ready to simplify HIPAA compliance?

Join thousands of organizations that trust Accountable to manage their compliance needs.

Related Articles