HIPAA Policy for Mohs Surgery Photos: Retention Schedule Requirements and Best Practices

Product Pricing
Ready to get started? Book a demo with our team
Talk to an expert

HIPAA Policy for Mohs Surgery Photos: Retention Schedule Requirements and Best Practices

Kevin Henry

HIPAA

July 15, 2026

8 minutes read
Share this article
HIPAA Policy for Mohs Surgery Photos: Retention Schedule Requirements and Best Practices

HIPAA Record Retention Requirements

Mohs surgery photos are part of a patient’s Protected Health Information and, when they inform diagnosis, treatment mapping, or billing, they belong in the designated record set. Your HIPAA Policy for Mohs Surgery Photos should specify if and when images are treated as medical records and apply a uniform retention schedule to them alongside operative notes and pathology reports.

HIPAA’s Privacy Rule and Security Rule do not prescribe how long you must retain clinical images themselves. Instead, HIPAA requires you to retain HIPAA-related policies, procedures, and required documentation (for example, notices, risk analyses, and authorizations) for six years from their creation or last effective date. For the images, you follow state Medical Record Retention requirements and any stricter payer or accreditation obligations.

How to build a defensible retention schedule

  • Classify Mohs photos by purpose: treatment documentation (part of the medical record), internal quality improvement (health care operations), or external use (education, publication, or marketing).
  • Adopt the most stringent rule among state Medical Record Retention laws, payer contracts, and malpractice carrier guidance. Common practice is a floor of 7–10 years for adults and, for minors, until the age of majority plus several years.
  • Document the rule in policy, map it to workflows (capture, store, archive, destroy), and train staff. Keep your HIPAA policy documents and retention decisions for at least six years.

Minimum necessary and role-based access

Limit who can view or export Mohs photos to the minimum necessary for treatment, payment, and health care operations. Implement role-based access so surgeons, nurses, coders, and auditors see only what they need, and record each access in your Audit Trail Documentation.

State Medical Record Retention Laws

States set medical record retention periods that typically govern clinical images when those images are part of the medical record. These laws vary by state and sometimes by care setting. Many states require at least seven years from the last date of service for adult patients, with longer periods for minors (often until majority plus additional years). Some payers and programs (for example, certain Medicare Advantage and Medicaid arrangements) can require 6–10 years or more.

Operationalizing state rules in a Mohs practice

  • Create a state-by-state matrix listing minimum years for adults and minors, plus exceptions (for example, oncology, surgical images, or pending litigation).
  • Treat Mohs photos used to guide stages, margins, or closures as integral medical records and retain them for the same period as the operative note and pathology.
  • Honor legal holds. Suspend disposal if there is an investigation, audit, or potential claim until the hold is lifted.

Before imaging, explain why photos are needed, how they will be secured, and how long they will be kept. For treatment and health care operations, you may rely on general consent and the Privacy Rule; however, explicit written consent for clinical photography is a best practice and reduces disputes.

Core elements to document

  • Identity and authority: patient name and identifiers; if a minor, the legal representative; date and time.
  • Purpose and scope: treatment documentation for Mohs mapping; whether internal training is permitted; whether any external educational use is contemplated.
  • Authorization for non-TPO uses: separate HIPAA authorization for external education, publication, or marketing, with expiration, revocation rights, and a statement that refusal will not affect care.
  • Image specifics: anatomic site, laterality, stage (pre-op, intra-op, post-op), whether face or unique features are visible, photographer’s name, and device used.
  • Handling instructions: storage location, retention schedule, de-identification preferences, and restrictions on redisclosure.
  • Signatures: patient or representative and workforce member; provide a copy to the patient and archive in the EHR.

Special situations

  • Emergencies: capture images necessary for care and document the rationale; complete consent as soon as feasible.
  • Refusals: respect the decision; document refusal and offer alternative documentation methods (for example, detailed notes or diagrams).
  • Chaperones and modesty: note presence of a chaperone when appropriate and minimize exposure in images.

Secure Storage of Clinical Images

The Security Rule requires administrative, physical, and technical safeguards for ePHI. Apply these to Mohs images wherever they reside—EHR attachments, a dermatology PACS/VNA, or secure mobile capture applications integrated with your record system.

Ready to simplify HIPAA compliance?

Join thousands of organizations that trust Accountable to manage their compliance needs.

Access control and authentication

  • Use unique user IDs, role-based access controls, and the principle of least privilege.
  • Enforce strong authentication (for example, MFA) and automatic logoff on shared workstations and capture devices.

Encryption and transmission

  • Encrypt at rest (for example, AES-256) and in transit (for example, TLS 1.2+). Disable unencrypted local storage and consumer cloud backups on mobile devices.
  • Store images in systems that support versioning and immutability to preserve clinical integrity.

Device governance and vendor management

  • Enroll phones and tablets in MDM; restrict camera roll access; route captures directly into the EHR or PACS.
  • Execute Business Associate Agreements with any vendor handling PHI and verify Security Rule controls during onboarding and annually.

Data integrity, backups, and Contingency Planning

  • Adopt a 3-2-1 backup pattern with at least one offline or immutable copy; define recovery time and point objectives that protect ongoing surgical workflows.
  • Test restores quarterly; document results and remediate gaps. Include image systems in disaster recovery and emergency mode operations plans.

Documentation and Audit Trails

Implement audit controls that record who captured, viewed, annotated, exported, or deleted a Mohs image and when. Correlate each action with a patient, encounter, device, and user. Retain these logs for at least six years to align with HIPAA documentation retention and your risk posture.

What to log and review

  • Capture metadata: date/time, anatomic site, stage, device ID, and geotag status (disabled by default).
  • Access events: successful and failed logins, role changes, bulk views, and after-hours access.
  • Data lifecycle: edits, redactions, de-identification operations, archival, and disposal confirmations.
  • Monitoring: baseline normal access patterns; alert on anomalies; document investigations and corrective actions.

De-Identification for Educational Use

To use Mohs photos outside treatment and internal operations, de-identify them or obtain a HIPAA authorization. Under the Privacy Rule, you may de-identify by Safe Harbor (removing specified identifiers, including full-face photos and comparable images) or by Expert Determination that the re-identification risk is very small.

Practical de-identification steps for clinical images

  • Remove or obscure facial features, tattoos, scars, jewelry, and background objects that could identify a patient.
  • Strip EXIF and other metadata; rename files with non-identifiable IDs; avoid side-by-side “before/after” montages that reveal identity.
  • Keep a provenance record linking the de-identified copy to the source inside the secure environment; never publish that linkage.
  • When de-identification would compromise educational value, use a signed authorization narrowly tailored to the specific use.

Best Practices for PHI Disposal

Disposal must render PHI unreadable, indecipherable, and irretrievable. Align your procedures with NIST-grade media sanitization and document each step from request to verification.

Secure disposal checklist

  • Paper: cross-cut shred or pulp; log date, method, and witness.
  • Local drives and removable media: cryptographic erase or overwrite per policy; physically destroy when appropriate; record device serials.
  • Mobile devices: remote wipe, verify encryption was enabled, and remove from MDM inventory after attestation.
  • Cloud systems: submit ticketed deletion requests, validate purge from all replicas and backups at end-of-life, and retain vendor attestations.
  • Holds and exceptions: suspend destruction under legal or audit holds; resume only after documented release.

Conclusion

A sound HIPAA Policy for Mohs Surgery Photos integrates the Privacy Rule and Security Rule, Medical Record Retention requirements, Clinical Image De-Identification standards, robust Audit Trail Documentation, and tested Contingency Planning. By classifying uses, securing storage, documenting consent, and disposing of PHI correctly, you protect patients and your practice.

FAQs

What is the required retention period for Mohs surgery photos under HIPAA?

HIPAA does not set a retention period for clinical images themselves. Treat Mohs photos as part of the medical record when used for treatment, and retain them according to your state’s medical record laws and any stricter payer or accreditation requirements. Keep HIPAA-related policies and documentation for at least six years.

Use a written clinical photography consent that explains the purpose, scope, and handling of images, and record who captured them, when, where on the body, and with which device. For any external educational, publication, or marketing use, obtain a separate HIPAA authorization with required elements, including expiration and revocation rights, and store all documentation in the EHR.

What are the secure storage requirements for medical images in dermatology?

Apply Security Rule safeguards: role-based access with unique IDs and MFA; encryption at rest and in transit; MDM-controlled capture apps that bypass local camera rolls; centralized storage in your EHR or PACS/VNA; continuous audit logging; and tested backups with disaster recovery and emergency mode operations defined.

How should PHI images be disposed of to comply with HIPAA?

Make PHI unreadable and irretrievable. Shred paper; cryptographically erase or destroy drives and devices; remotely wipe mobile hardware; and require verifiable deletion from cloud systems, including replicas and backups at retention end. Document each step, respect legal holds, and maintain disposal logs for audit readiness.

Share this article

Ready to simplify HIPAA compliance?

Join thousands of organizations that trust Accountable to manage their compliance needs.

Related Articles