HIPAA-Compliant Policy for Patient Access to OB Ultrasound Images and Results via the Patient Portal

Product Pricing
Ready to get started? Book a demo with our team
Talk to an expert

HIPAA-Compliant Policy for Patient Access to OB Ultrasound Images and Results via the Patient Portal

Kevin Henry

HIPAA

July 09, 2026

7 minutes read
Share this article
HIPAA-Compliant Policy for Patient Access to OB Ultrasound Images and Results via the Patient Portal

This policy explains how you can view, download, and share OB ultrasound images and results through the patient portal while maintaining HIPAA compliance. It details your access rights, required security safeguards for electronic protected health information (ePHI), secure delivery options, provider duties, release of information (ROI) procedures, allowable fees, and how the 21st Century Cures Act and state privacy regulations apply.

Patient Access Rights to OB Ultrasound Records

Scope of records you may obtain

  • Ultrasound images (e.g., DICOM files) and associated reports are part of your designated record set and qualify as ePHI.
  • You may request images and reports for prenatal screening, anatomy scans, growth assessments, biophysical profiles, and Doppler studies, along with final interpretations.

Timeliness and format

  • Requests must be fulfilled within HIPAA-required timelines (generally within 30 days, with a single permissible extension when necessary and communicated to you).
  • Records should be provided in the form and format you request if readily producible (e.g., DICOM, JPEG, PDF, or a readable viewer file). If not, a mutually agreeable, readily accessible format will be used.

Access through representatives

  • You may authorize a personal representative to access your OB ultrasound records, subject to identity verification and applicable state privacy regulations.
  • For pregnant minors, access and sharing rules may differ by state; the organization will apply the most protective applicable law.

HIPAA-Compliant Patient Portal Safeguards

Encryption standards and transmission security

  • Encrypt ePHI at rest and in transit using current encryption standards (e.g., AES-256 for storage; TLS 1.2+ for transmission). Where feasible, use FIPS-validated cryptographic modules.
  • Use re-authentication before sensitive actions (e.g., large image downloads or external sharing) and session timeouts to reduce unattended access risk.

Access control protocols

Audit trail requirements and integrity controls

  • Maintain audit logs that capture viewing, downloading, exporting, printing, and sharing of images and results.
  • Protect logs from alteration, review them regularly for anomalies, and retain them per documentation retention requirements.
  • Use checksums or digital signatures to detect tampering with images or reports.

Device and application safeguards

  • Enforce device encryption on mobile applications, disable untrusted storage, and block copy/paste of PHI where practical.
  • Use secure coding practices and regular vulnerability testing for the portal and image viewers.

Secure Methods for Imaging Access

Portal-based viewing

  • Provide a zero-footprint web viewer to see OB ultrasound images without requiring local installation.
  • Offer accessible report views with plain-language summaries alongside full radiology/sonography reports.

Download options

  • Allow download of DICOM studies with an embedded or bundled viewer when feasible; support alternatives (e.g., JPEG/PDF) for general use.
  • Use expiring, tokenized links for large-file delivery and require MFA or re-login before release.

Electronic sharing with third parties

  • Enable patient-directed sharing to clinicians or apps via secure APIs (e.g., SMART on FHIR, OAuth 2.0) or Direct secure messaging.
  • If you ask for unencrypted email, inform you of risks and document your preference before sending.

Physical media (disc/USB) as a fallback

  • Discouraged due to security and compatibility risks; if used, protect with strong encryption and share the password via a separate channel.

Provider Obligations for Image Sharing

Right of access without undue burden

  • Your access cannot be conditioned on portal sign-up; alternative delivery must be available upon request.
  • Provide clear instructions for obtaining images, including expected timelines and contact information for assistance.

Operational duties

  • Maintain business associate agreements with portal and imaging vendors handling ePHI.
  • Train staff on ROI workflows, identity verification, and how to process urgent requests and complaints.
  • Make reasonable accommodations for language and disability access when communicating results.

Managing sensitive findings

  • Release results promptly while complying with the 21st Century Cures Act; if a permitted exception applies, document the rationale and duration.

Authorization and Release Form Procedures

When authorization is not required

  • You do not need a HIPAA authorization to access your own OB ultrasound images or results via the portal; standard authentication is sufficient.

When ROI authorization is required

  • Written authorization (or a valid patient-directed request) is required to send images to a third party. Electronic signatures are acceptable when identity and intent are verifiable.
  • Your request should specify the recipient, records to be shared, delivery method, and format.

Standard ROI workflow

  • Intake and verify identity (including personal representatives as allowed by law).
  • Confirm scope, format, and destination; provide a fee estimate if any applies.
  • Fulfill within required timelines; log disclosures to meet audit trail requirements.
  • For limited, reviewable denials (e.g., risk of harm), provide written notice and a review process.

Fees and Cost Limitations for Record Copies

  • Viewing or downloading OB ultrasound records within the portal is typically free.
  • If you request copies through other means, only reasonable, cost-based fees for labor, supplies, postage, and any agreed-upon summaries may be charged.
  • No fees may be charged for record retrieval, maintenance, or verification.
  • Use documented, consistent fee methods (actual cost or a reasonable flat fee that approximates allowable costs) and provide an estimate in advance.

Compliance with 21st Century Cures Act and State Laws

Information blocking and timely access

  • OB ultrasound images and reports constitute electronic health information (EHI). You are entitled to timely electronic access without unnecessary delays.
  • Permitted exceptions include preventing harm, privacy, security, infeasibility, and content-and-manner constraints. Any use of an exception must be narrowly tailored and documented.

Alignment with state privacy regulations

  • When state privacy regulations are more protective than HIPAA (e.g., reproductive health or minor consent rules), the stricter standard applies.
  • Honor requests for confidential communications (e.g., alternate contact methods) and segment sensitive data where required.

In sum, this HIPAA-compliant policy ensures you can readily access OB ultrasound images and results through the patient portal, protected by strong encryption standards, access control protocols, and robust audit trail requirements, while providers meet clear obligations for secure, timely, and appropriately authorized sharing.

Ready to simplify HIPAA compliance?

Join thousands of organizations that trust Accountable to manage their compliance needs.

FAQs.

What are patients' rights to access OB ultrasound images under HIPAA?

You have the right to inspect, view, and obtain copies of your OB ultrasound images and reports maintained by your provider. Records must be provided within HIPAA timelines, in the form and format you request if readily producible, or in an agreed alternative. You may also direct your provider to send the records to a third party of your choosing.

How must patient portals protect OB ultrasound data?

Portals must safeguard ePHI with strong encryption standards, MFA, and role-based access control protocols; maintain detailed audit trail requirements for viewing and sharing; and enforce transmission security, session timeouts, and re-authentication before sensitive downloads. Logs are reviewed and retained per policy to detect and deter unauthorized use.

Are fees allowed for providing copies of ultrasound reports?

Viewing or downloading within the portal is generally free. If you request copies through other channels, only reasonable, cost-based fees for labor, supplies, postage, and any requested summaries may be charged. Retrieval or verification fees are not permitted, and you should receive an estimate before fulfillment.

What authorization is required for accessing ultrasound images electronically?

No HIPAA authorization is required to access your own records through the portal—your secure login suffices. Authorization (or a valid patient-directed request) is required only when sending your OB ultrasound records to a third party, and electronic signatures are acceptable when identity and intent are verifiable.

Share this article

Ready to simplify HIPAA compliance?

Join thousands of organizations that trust Accountable to manage their compliance needs.

Related Articles