HIPAA Policy for Mohs Clinics: Photographing Surgical Margins on Personal Devices

Product Pricing
Ready to get started? Book a demo with our team
Talk to an expert

HIPAA Policy for Mohs Clinics: Photographing Surgical Margins on Personal Devices

Kevin Henry

HIPAA

September 08, 2026

7 minutes read
Share this article
HIPAA Policy for Mohs Clinics: Photographing Surgical Margins on Personal Devices

This policy outlines how Mohs clinics should capture and manage images of surgical margins while protecting Protected Health Information (PHI). It explains when Patient Consent is required, how the HIPAA Security Rule applies, and the safeguards that prevent Unauthorized Disclosure when personal devices are involved.

HIPAA Policy Overview

Clinical images are PHI when they contain identifiers (for example, name, medical record number, facial features, distinctive tattoos) or can reasonably be linked to a patient when combined with clinic-held data. Photographing surgical margins is permissible for treatment purposes, but you must limit identifiers, secure the images, and store them within the designated medical record.

The HIPAA Security Rule requires administrative, physical, and technical safeguards for electronic PHI. For images, this means strong Access Controls, Data Encryption, auditability, and policies that govern how photos are captured, transmitted, stored, and deleted. Apply the minimum necessary standard, and ensure workforce members are trained and sanctioned for violations.

Use and disclosure for treatment do not typically require written authorization; however, you must obtain documented Patient Consent for photography policies at intake and explicit written authorization if images will be used beyond treatment and operations (for example, education outside the care team or marketing).

Photographing Surgical Margins

Before you capture

  • Confirm the imaging purpose (treatment documentation, margin mapping, pathology correlation) and whether identifiers are needed.
  • Verify patient identity using two identifiers and document Patient Consent per clinic policy.
  • Prepare a secure capture workflow (authorized app, correct patient record selected) to avoid storing to the device camera roll.

While capturing

  • Frame images to minimize identifiers (exclude full face and unique features when not clinically essential).
  • Use orientation markers, a scale, and consistent lighting to clearly depict margins and specimen inking without adding unnecessary PHI.
  • Avoid including printed labels with full identifiers in-frame; instead, link the photo to the patient within the secure app or via barcode scanning.

After capture

  • Immediately upload to the EHR or approved imaging system over a secure connection; verify receipt in the correct chart.
  • Delete any temporary local copies after successful upload and confirmation, including items in “recently deleted.”
  • Document the image in the operative note, including orientation and any margin status annotations needed for Mohs mapping.

Use of Personal Devices

Personal devices (BYOD) pose heightened risk. By default, prohibit their use for clinical photography unless the device is enrolled in the clinic’s mobile device management (MDM) program and uses an approved secure camera application that never stores images in the native photo library.

Ready to simplify HIPAA compliance?

Join thousands of organizations that trust Accountable to manage their compliance needs.

  • Require a signed BYOD agreement acknowledging HIPAA obligations, Incident Reporting duties, and clinic monitoring of managed containers.
  • Permit capture only through an approved app with containerized storage, Access Controls, and automatic upload to the clinic system.
  • Forbid SMS/MMS, consumer messaging apps, and personal email for transmitting images.
  • Disable cloud backups and photo sync for clinical images; prevent cross-device synchronization (for example, to smartwatches or home computers).
  • Mandate immediate transfer and verified deletion from the device after upload; no long-term local storage.

Security Requirements

Administrative safeguards

  • Designate a Privacy Officer and Security Officer to oversee imaging workflows and Incident Reporting.
  • Maintain written procedures for capture, labeling, upload, storage, retention, and deletion of images.
  • Provide onboarding and annual training covering PHI, Patient Consent, Unauthorized Disclosure, and breach response.

Technical safeguards

  • Data Encryption: Full-disk encryption on devices and encryption in transit to clinic systems; disable unencrypted transports.
  • Access Controls: Unique user IDs, strong passcodes/biometrics, automatic lock, and role-based permissions; enable multi-factor authentication on apps.
  • Audit controls: Log access, capture, edits, and deletions; review logs regularly for anomalies.
  • Data minimization: Strip geolocation/EXIF when not necessary; block location services for the secure camera app.

Physical safeguards

  • Keep devices on your person or in secured areas; never leave them unattended in procedure rooms.
  • Enable remote lock and remote wipe; report loss or theft immediately.
  • Use privacy screens if viewing images in shared spaces.

Network and transmission

  • Use only secure clinic Wi‑Fi or VPN; block public or open networks for uploads.
  • Prohibit Bluetooth or AirDrop-style sharing for PHI unless managed and encrypted within the approved app.

Data lifecycle

  • Retention: Store images as part of the medical record per clinic policy and applicable state retention laws.
  • Deletion: Ensure verified deletion from devices and temporary caches after upload; include “recently deleted” folders.
  • Disposal: Wipe and deprovision devices before reassignment or repair.

Breach Consequences

An Unauthorized Disclosure occurs when PHI is accessed, acquired, used, or disclosed in a way not permitted by HIPAA. Photos on personal devices—especially if synced to personal clouds or sent via unsecure messaging—are common breach sources.

Incident Reporting and response

  • Immediately report suspected incidents to the Privacy or Security Officer; do not delete or alter evidence.
  • IT will isolate affected devices, assess exposure, and preserve logs; conduct a risk assessment and mitigation.
  • Follow breach notification obligations, including patient notification and required regulatory reports, within required timelines.

Sanctions and liabilities

  • Workforce sanctions may include retraining, suspension, or termination per policy.
  • Regulatory exposure includes civil monetary penalties and corrective action plans; criminal penalties may apply for willful misconduct.
  • Operational impacts include reputational harm, patient distrust, and costs related to remediation and monitoring.

Clinic-specific Policies

Roles and governance

  • Appoint a Privacy Officer and Security Officer to approve imaging tools and oversee compliance.
  • Maintain a current risk analysis covering mobile capture, storage, and transmission of clinical images.

Approved tools and workflows

  • Use a secure camera app integrated with the EHR or image archive to associate photos with the correct patient without in-frame identifiers.
  • Standardize a Mohs imaging checklist: verify consent, confirm patient, frame margins, upload, verify receipt, delete local copy.
  • Adopt naming and documentation conventions that support mapping of surgical margins and pathology correlation.

Training, auditing, and improvement

  • Provide scenario-based training on PHI, Patient Consent, and Incident Reporting.
  • Run periodic audits for orphaned local images, improper transmissions, and incomplete uploads.
  • Review this policy at least annually or after any incident; update device and app requirements as needed.

Conclusion

Mohs clinics can safely document surgical margins by treating every image as PHI, requiring secure capture workflows, enforcing Access Controls and Data Encryption, and responding swiftly to incidents. Clear procedures and consistent training minimize risk while preserving clinical quality and efficiency.

FAQs.

What are the HIPAA requirements for photographing surgical margins?

HIPAA permits photography for treatment when you protect PHI with administrative, physical, and technical safeguards. Limit identifiers, capture within an approved secure app, encrypt data in transit and at rest, store images in the medical record, and audit access. Obtain documented Patient Consent at intake and written authorization for any non-treatment use.

Can personal devices be used to photograph patient information?

Only if clinic policy allows it under strict BYOD controls: MDM enrollment, strong Access Controls, an approved secure camera app that bypasses the device camera roll, blocked cloud backups, encrypted transmission to the clinic system, and verified post-upload deletion. Unmanaged personal devices and consumer messaging apps must not be used.

What security measures are required for storing clinical images?

Store images in an approved system with Data Encryption at rest, role-based Access Controls, audit logging, and reliable backup. Disable location metadata unless clinically necessary, ensure retention aligns with policy, and restrict viewing to authorized personnel. Never rely on the personal device as the system of record.

What are the consequences of a HIPAA breach involving personal device photos?

Consequences can include patient notification, regulatory reporting, corrective action plans, civil monetary penalties, workforce sanctions up to termination, and reputational damage. Prompt Incident Reporting, containment, and documented remediation are critical to reducing risk and meeting breach notification obligations.

Share this article

Ready to simplify HIPAA compliance?

Join thousands of organizations that trust Accountable to manage their compliance needs.

Related Articles