HIPAA Training for Burn Unit Nurses: How to Photograph Graft Sites for Remote Plastic Surgery Consults Safely
HIPAA Regulations on Patient Photographs
Why wound photographs are Protected Health Information
Any image that can identify a patient—alone or when combined with other data—is Protected Health Information (PHI). In practice, graft-site photos become PHI the moment they include full-face views, distinctive features, labels, dates, or are linked to the patient’s chart, encounter, or room number. Treat every clinical photo as PHI unless it has been rigorously de-identified.
Treatment vs. other uses
Images taken to support diagnosis or treatment—such as remote plastic surgery consults—fall under treatment activities and may be used and shared within your covered entity and its Business Associates under Telehealth HIPAA Compliance. Still, apply the minimum necessary principle, store them in the Electronic Medical Record (EMR), and restrict access to those who need to know. For teaching, marketing, or publication, obtain Patient Authorization before any use or disclosure.
Two HIPAA pathways for de-identification
HIPAA recognizes two methods: Safe Harbor De-identification (removal of specific identifiers, including full-face images) and Expert Determination (a qualified expert certifies that re-identification risk is very small). Use Safe Harbor for routine workflows; involve privacy/compliance for cases requiring Expert Determination.
Identifiable Features in Medical Images
Common identifiers that sneak into graft-site photos
- Full-face or profile views; visible eyes.
- Unique tattoos, jewelry, piercings, birthmarks, or scars unrelated to the graft.
- Bed tags, wristbands, room boards, prescription labels, monitors with names or MRNs.
- Backgrounds showing family members, visitors, or personal items.
- Date/time stamps, screen overlays, or device reflections.
Framing graft sites to avoid identification
Before shooting, remove jewelry, cover tattoos near the field with a plain drape, and position a neutral background. Crop tightly to the graft and a small rim of surrounding skin. Exclude the face, distinctive features, and bedside labels. If the head or other unique features are unavoidably close, mask them before saving to the record.
Quality without compromising privacy
Use consistent lighting, perpendicular angles, and a measurement scale for size reference. Capture a wide shot (anatomical context) and a close-up (detail) without drifting into identifiable zones. Avoid writing names or MRNs on the skin or drape; use a random study code placed outside the frame instead.
Methods for De-identification
Applying Safe Harbor De-identification to photos
Under Safe Harbor, remove direct identifiers such as names, full-face images, detailed geolocation, dates tied to the individual (beyond year), contact numbers, account numbers, device serials, URLs/IPs, and any unique codes. For photography, this means excluding full-face or comparable views, cropping out labels, and omitting dates in overlays. Store dates in the EMR metadata rather than burned into the image.
When to use Expert Determination
If an image must show a distinctive feature (e.g., a unique tattoo adjacent to a graft) and Safe Harbor cannot be met, escalate to privacy for Expert Determination. The expert will assess re-identification risk and may require masking, noise addition, or controlled-access storage to keep risk very small.
Practical de-identification workflow
- Capture on a secure clinical camera app that saves to an encrypted container.
- Crop/mask identifiers immediately; verify no faces, tattoos, or labels remain.
- Use a random study code in the image note; keep the patient-to-code mapping only in the EMR.
- Document who captured the image, purpose (remote plastic surgery consult), and body location in the EMR note—not on the photo.
Secure Storage and Transmission of Images
Capture and device controls
Use organization-managed devices with mobile device management, strong authentication, and remote wipe. Disable auto-backups to personal clouds and block camera roll storage when possible. Avoid personal smartphones unless your institution provides a HIPAA-compliant capture app and policy allowing their use.
Storage in the Electronic Medical Record
Store images within the EMR or a sanctioned clinical media repository with encryption at rest, access controls, and audit logging. Apply retention rules that mirror the medical record. Never store PHI on local galleries, unsecured shared drives, or personal messaging threads.
Transmission for remote consults
Transmit only through HIPAA-compliant channels (secure EMR messaging, secure image portals, or telehealth platforms under a Business Associate Agreement). Use encryption in transit, verify the recipient, and include only the minimum necessary images. Do not send photos via standard SMS, personal email, or consumer apps.
Ready to simplify HIPAA compliance?
Join thousands of organizations that trust Accountable to manage their compliance needs.
Obtaining Patient Authorization
When you do—and do not—need authorization
For treatment purposes within your covered entity and its Business Associates, separate Patient Authorization is typically not required, but consent to treatment and institutional policy still apply. If images will be used for education, marketing, external publication, or shared with third parties without a BAA, obtain written authorization first.
Elements of a valid HIPAA authorization
A compliant authorization specifies what will be disclosed (photographs), who may disclose and receive them, the purpose, expiration (date or event), the right to revoke, and whether refusal affects care. It must be signed and dated by the patient or an appropriate personal representative, with documentation of that authority when applicable.
Special situations
For minors or incapacitated patients, obtain authorization from the legal guardian or personal representative per state law and facility policy. In emergencies, document the clinical necessity for treatment images and complete any required consents as soon as feasible.
Metadata Removal Procedures
Understand the hidden data
Photos often carry metadata such as EXIF geotags, device IDs, timestamps, and creator fields. Some clinical systems also attach DICOM-style attributes. These can re-identify a patient even when the visible image is de-identified.
Metadata stripping and verification
- Use capture apps that perform automatic Metadata Stripping at save or export.
- Disable camera geolocation before imaging and avoid overlays that stamp dates or patient details.
- On export, select options that remove location and device data; verify by inspecting file properties.
- Adopt file-naming rules with random study codes—never names, DOBs, MRNs, or visit numbers.
Document the process
Record in the note that metadata was stripped and that the final images were saved to the EMR. Maintain an audit trail of who captured, edited, and uploaded each file for accountability.
Compliance in Telehealth Consultations
Pre-consult safety checklist
- Confirm the telehealth platform and image workflow are covered by a current BAA.
- Verify the remote plastic surgeon’s identity and access permissions.
- Limit images to the minimum necessary views; avoid identifiers and remove metadata.
- Log transmission details in the EMR, including purpose and recipients.
Working with patients and families
If patients or caregivers will send images, provide written instructions: neutral background, no faces, no personal items, and no visible labels. Route submissions through a HIPAA-compliant portal rather than personal messaging apps to maintain Telehealth HIPAA Compliance.
Bringing it all together
Your safest workflow is consistent: de-identify at capture, store only in the EMR, transmit via approved channels, and document each step. By following Safe Harbor De-identification where possible—and escalating for Expert Determination when needed—you protect privacy while giving surgeons the clear, high-quality graft-site images they need.
FAQs
What are the HIPAA requirements for photographing graft sites?
Treat every clinical photo as PHI. Exclude full-face and other identifiers, capture on a secure app, remove metadata, store in the EMR, restrict access, and transmit only through HIPAA-compliant channels. Use Safe Harbor De-identification when feasible; otherwise consult privacy for Expert Determination.
How can nurses de-identify patient photographs effectively?
Frame tightly on the graft, remove or cover tattoos and labels, avoid faces and backgrounds with personal items, crop or mask residual identifiers, and strip EXIF/DICOM metadata. Name files with random study codes and keep the patient linkage only inside the EMR.
What constitutes patient authorization for image use?
For treatment within your covered entity and its Business Associates, separate authorization is generally not required. For education, marketing, publication, or sharing outside approved partners, obtain a signed authorization specifying what is disclosed, to whom, for what purpose, expiration, and the right to revoke.
How should images be securely stored and transmitted?
Store images only in the EMR or an approved clinical media repository with encryption and audit logs. Transmit through secure EMR messaging or a HIPAA-compliant telehealth platform under a BAA, verify recipients, and send only the minimum necessary images—never via standard SMS, personal email, or consumer apps.
Ready to simplify HIPAA compliance?
Join thousands of organizations that trust Accountable to manage their compliance needs.