HIPAA Training Checklist for Tumor Board Coordinators Before Circulating Identifiable Imaging

Product Pricing
Ready to get started? Book a demo with our team
Talk to an expert

HIPAA Training Checklist for Tumor Board Coordinators Before Circulating Identifiable Imaging

Kevin Henry

HIPAA

August 19, 2026

7 minutes read
Share this article
HIPAA Training Checklist for Tumor Board Coordinators Before Circulating Identifiable Imaging

Circulating patient imaging for multidisciplinary review is essential to high-quality cancer care—but it must be done in strict alignment with HIPAA. Use this practical checklist to confirm that protected health information (PHI) and electronic PHI (ePHI) are handled lawfully and securely before you distribute any identifiable studies for a tumor board.

HIPAA Training Requirements

Core topics you must master

  • PHI and ePHI fundamentals: what counts as PHI in imaging (DICOM tags, overlays, burned‑in text) and how ePHI travels across systems.
  • Privacy Rule essentials: treatment vs. operations, the minimum necessary standard (note: not required for treatment, but still share only what’s relevant), and patient rights.
  • Security Rule safeguards: administrative, physical, and technical controls; encryption in transit and at rest; secure device handling; and secure disposal.
  • Breach Notification Rule: how to recognize an incident vs. a breach, perform risk assessments, and meet breach notification requirements and timelines.
  • Organization-specific policies: sanction policy, incident reporting, bring‑your‑own‑device limits, remote meeting etiquette, and data retention.

Training artifacts to keep on file

  • Current HIPAA training completion (including imaging workflows), competency verification, and annual refresher records.
  • Signed confidentiality acknowledgments and attestation that you understand sanction and incident response procedures.
  • Role-based access authorization confirming your coordinator duties for the tumor board.

Pre-circulation training check

  • Verify your training is current per organizational policy and covers identifiable imaging handling and remote presentation.
  • Confirm you know where to find policies, who the Privacy/Security Officers are, and the exact steps to report incidents.

Identifiable Imaging Protections

Decide whether imaging must be identifiable

  • First, consider de-identification (remove overlays and patient tags) if clinical decision-making will not be impaired.
  • If identity is required for continuity of care, restrict what you circulate to the sequences and series needed for the case.

Prepare studies before circulation

  • Review DICOM headers for patient name, medical record number, DOB, accession, and site—confirm necessity or mask when allowed.
  • Remove or hide burned‑in identifiers in the viewport; avoid cropping out clinically relevant anatomy.
  • Add a confidentiality banner in the viewer when supported to remind participants that PHI is present.

Secure transmission and storage

  • Use enterprise PACS/VNA, secure image sharing portals, or SFTP governed by your risk management plan—never personal email or consumer file services.
  • Require encryption in transit and at rest, link expiration, multi-factor authentication, and recipient verification.
  • Block local downloads when possible; otherwise ensure encrypted, managed devices and prompt deletion after the session.

Meeting hygiene for virtual and hybrid boards

  • Enable waiting rooms, lock meetings after start, restrict screen sharing, and disable recordings unless expressly approved and stored in authorized repositories.
  • Remind attendees: no screenshots, photos, or side-channel sharing; chat content must follow the same confidentiality rules as spoken content.

Risk Analysis and Management

Perform a focused Security Risk Analysis (SRA)

  • Map the data flow: where ePHI originates (PACS), how it’s exported, shared, displayed, and archived for the tumor board.
  • Identify assets (workstations, viewers, conferencing tools), threats (misaddressed invites, unauthorized recording), and vulnerabilities (weak access controls).
  • Rate likelihood and impact; document compensating controls; record residual risk and obtain sign-off.

Maintain and act on your risk management plan

  • Define required controls (MFA, restricted export, link expiration, watermarking) and responsible owners with due dates.
  • Escalate high-risk scenarios (e.g., cross-institution sharing without agreements) to Privacy/Security for approval before you circulate imaging.
  • Reassess after workflow or technology changes and after any incident.

Business Associate Agreements

Know when business associate agreements apply

  • BAAs are required with vendors that create, receive, maintain, or transmit PHI on your behalf (e.g., image portals, cloud storage, conferencing platforms).
  • Sharing for treatment between covered entities generally doesn’t require a BAA; using a vendor platform to enable that sharing usually does.

What to confirm before using a vendor

  • An executed BAA that covers the exact services you use, subcontractors, security incident reporting, and breach obligations.
  • Vendor capabilities: robust encryption, access control mechanisms, role-based permissions, and comprehensive audit trail documentation.
  • Termination terms for returning or destroying PHI and support for eDiscovery/record requests.

Access Controls and Audit Logs

Apply least privilege via strong access control mechanisms

  • Use role-based access tied to your tumor board roster; grant time-bound access to outside participants when necessary.
  • Require unique user IDs, MFA, and session timeouts; limit export, print, and forwarding rights.
  • Verify participants’ identities before granting access or admitting them from the virtual waiting room.

Enable complete audit trail documentation

  • Log who accessed which studies, when, from where, and what actions they took (view, export, download, share).
  • Retain audit logs and related policy documentation consistent with HIPAA’s six‑year record retention requirements.
  • Test your ability to retrieve and furnish logs quickly for investigations, quality reviews, or patient requests.

Incident Response and Breach Notification

Immediate actions if something goes wrong

  • Contain: revoke links, lock accounts, recall messages where possible, and isolate affected devices or repositories.
  • Preserve evidence: save logs, timestamps, and copies of messages; avoid altering affected systems until instructed by Security.
  • Notify your Privacy/Security Officer immediately and document the event, actions taken, and people involved.

Assess and coordinate notifications

  • Perform a four‑factor risk assessment (data type/sensitivity, unauthorized person, whether data was actually acquired/viewed, and mitigation achieved).
  • If a breach is determined, follow breach notification requirements: notify affected individuals without unreasonable delay and no later than 60 calendar days from discovery.
  • Report to HHS; for 500 or more individuals, notify HHS and, when required, the media; for fewer than 500, report to HHS no later than 60 days after the end of the calendar year.

After-action improvements

  • Update your risk management plan, close control gaps, and provide targeted retraining.
  • Review vendor performance under BAAs and strengthen access or logging as needed.

Confidentiality Policies and Procedures

Pre-meeting safeguards

  • Confirm the tumor board’s purpose (treatment/operations), verify attendee roles, and ensure required agreements are in place.
  • Prepare a PHI-minimized slide deck, omit unnecessary identifiers, and include a confidentiality reminder on introductory slides.
  • Arrange a private setting: no public areas, clear sightlines, and headsets for virtual participation.

During the meeting

  • Re-confirm attendees, restate no-recording/no-screenshot rules, and limit discussions to what’s clinically necessary.
  • Keep chat de-identified; avoid stating full names or MRNs aloud unless essential for patient safety.
  • Collect questions that require additional PHI for secure follow-up after the session rather than in open discussion.

Post-meeting wrap-up

  • Securely archive approved materials; delete local copies and temporary work files; confirm any recordings are stored in authorized systems.
  • Document attendance, cases discussed, decisions made, and where source imaging is retained.
  • Review access and audit logs to ensure only authorized viewing occurred.

Conclusion

By verifying training, hardening workflows, documenting a living risk management plan, enforcing BAAs, tightening access control mechanisms, and preparing for rapid incident response, you create a defensible, patient‑centric process for sharing identifiable imaging at tumor boards while safeguarding PHI and ePHI.

Ready to simplify HIPAA compliance?

Join thousands of organizations that trust Accountable to manage their compliance needs.

FAQs.

What are the HIPAA training requirements for tumor board coordinators?

You should complete organization-approved HIPAA training that specifically covers imaging workflows, PHI/ePHI handling, virtual meeting safeguards, incident reporting, and sanction policies. Maintain proof of completion and annual refreshers, plus signed confidentiality acknowledgments. Ensure you know where to find policies, how to escalate issues, and that your role-based access for coordination duties is documented.

How should identifiable imaging be protected under HIPAA?

Limit what you circulate to what’s clinically necessary, review and manage DICOM identifiers and overlays, and use encrypted, enterprise-approved systems for sharing and display. Require MFA, link expiration, and recipient verification; restrict downloads; disable recording unless authorized; and keep comprehensive audit trail documentation. When feasible, de-identify—but if identifiers are essential for care, apply strict access controls and logging.

What steps should be taken after a security breach involving imaging data?

Act immediately to contain the issue (revoke access, lock accounts), preserve evidence and logs, and notify your Privacy/Security Officer. Perform a risk assessment to determine if PHI was compromised; if a breach is confirmed, follow breach notification requirements for individuals and HHS within mandated timeframes. Afterward, update your risk management plan, strengthen controls, and provide targeted retraining.

Share this article

Ready to simplify HIPAA compliance?

Join thousands of organizations that trust Accountable to manage their compliance needs.

Related Articles