HIPAA Training for Mohs Clinic Medical Assistants: How to Photograph Surgical Margins Securely on Mobile Phones

Product Pricing
Ready to get started? Book a demo with our team
Talk to an expert

HIPAA Training for Mohs Clinic Medical Assistants: How to Photograph Surgical Margins Securely on Mobile Phones

Kevin Henry

HIPAA

September 16, 2026

8 minutes read
Share this article
HIPAA Training for Mohs Clinic Medical Assistants: How to Photograph Surgical Margins Securely on Mobile Phones

As a Mohs clinic medical assistant, you play a central role in documenting surgical margins accurately while protecting patient privacy. This guide translates HIPAA requirements into step-by-step practices you can apply when capturing clinical photos on mobile phones.

You will learn compliance essentials, a repeatable photography workflow, and how to secure devices, apps, and transfers. The goal is simple: produce high-quality, clinically useful images while meeting encryption standards, privacy safeguards, and audit expectations.

HIPAA Compliance Essentials for Medical Assistants

Understand how HIPAA applies to clinical photography

Photos of surgical margins are protected health information (PHI) when they can identify a patient directly or indirectly. HIPAA’s Privacy Rule limits use and disclosure to the minimum necessary, and the Security Rule requires administrative, physical, and technical safeguards for any electronic PHI you create, receive, store, or transmit.

Apply the minimum necessary standard

Only capture what is clinically required. Tight framing, neutral backdrops, and excluding faces, tattoos, and documents reduce identifiers. If an identifier must appear to ensure clinical utility, justify it in the note and restrict access accordingly.

Use approved systems and vendors

Only use applications and cloud services that your clinic has vetted and covered with a Business Associate Agreement. Approved systems must support secure image storage, strong authentication, and an audit trail of access and actions.

Protect data in transit and at rest

Follow HIPAA data transmission rules by sending images over encrypted channels (for example, TLS) and storing them using recognized encryption standards on devices and servers. Never send clinical photos via personal email, standard texting, or consumer messaging apps.

Best Practices for Photographing Surgical Margins

Prepare before you shoot

  • Confirm the order: pre-excision, intraoperative margins, and post-repair as required by the surgeon.
  • Sanitize hands and place the phone in a sterile or clean barrier sleeve; never break the sterile field.
  • Disable geotagging for the camera app to prevent automatic location metadata.
  • Gather a sterile ruler, orientation marker (e.g., “12 o’clock” arrow), and a neutral, nonreflective background.

Compose for clinical clarity

  • Include the entire lesion or margin edge with a ruler for scale; keep the ruler in the same plane as the tissue.
  • Use orientation markers so the surgeon and pathologist can correlate margins (e.g., superior, inferior, medial, lateral).
  • Ensure even lighting; avoid harsh flash glare on moist tissue by angling light or diffusing it.
  • Use the phone’s gridlines, tap-to-focus, and exposure controls; stabilize with two hands or a support.

Standardize every image set

  • Capture wide, medium, and close-up views for each stage; maintain consistent distance and angle across shots.
  • Use a white balance reference (e.g., color card) in the first frame to keep tissue color accurate.
  • Record margin inks, sutures, or notches that identify orientation; ensure these are crisp and legible.
  • Take a verification shot after closure if instructed, documenting repair type and final orientation.

Prevent identifiers and errors

  • Keep wristbands, faces, name labels, and charts out of frame; use coded chart identifiers instead of names.
  • Review each image immediately for focus, framing, and orientation; delete clinical misfires before upload.
  • Document in the note which images were captured and their purpose to support the minimum necessary standard.

Securing Mobile Devices for Medical Imaging

Harden the device

  • Enable a strong passcode plus biometric access controls; set auto-lock to the shortest practical time.
  • Enroll the device in mobile device management (MDM) for remote wipe, enforced updates, and configuration.
  • Turn off lock-screen previews and voice assistants that could reveal PHI.
  • Update the OS and security patches promptly to maintain platform protections.

Control storage to protect PHI

  • Use secure image storage in a managed “work container” isolated from the personal camera roll.
  • Disable automatic backups to personal clouds and consumer photo libraries.
  • Configure automatic in-app deletion after confirmed upload, leaving no residual PHI on the device.
  • Encrypt local storage according to your clinic’s encryption standards and MDM policy.

Secure the network path

  • Transmit over clinic-approved Wi‑Fi or a trusted cellular connection; avoid public networks.
  • Require TLS for all transfers and block SMS, MMS, AirDrop, and unmanaged Bluetooth sharing for PHI.
  • Use VPN if your clinic mandates it, and verify the app confirms successful, encrypted upload.

Reduce metadata risk

  • Disable camera geotagging and remove unnecessary EXIF data as your app allows.
  • Rely on the EHR for patient linkage rather than embedding identifiers in filenames.

Know when authorization is needed

Clinical photos taken for treatment or operations generally may be used within the care team, but your clinic may still require written patient consent forms. If images could be used for marketing, education, or external publication, obtain a specific written authorization before photographing.

Inform and respect patient preferences

Explain what you will photograph, why, and who will see it. Offer modesty drapes, limit visibility of noninvolved areas, and pause if the patient asks questions. Document any verbal discussions and store signed forms with the chart.

Ready to simplify HIPAA compliance?

Join thousands of organizations that trust Accountable to manage their compliance needs.

Minimize identifiers proactively

  • Frame out faces and unique features; cover tattoos and jewelry when feasible.
  • Use coded chart IDs, not names or dates of birth, in any on-screen notes or tags.
  • Keep consent details and clinical photography policies readily accessible to staff.

Implementing Clinic-Specific Photography Policies

Define roles, tools, and permissions

  • Specify who can capture, review, approve, and upload images.
  • List approved devices and apps; prohibit personal devices unless enrolled via MDM.
  • Require training and annual attestation to clinical photography policies.

Create a Mohs margin photo SOP

  • Step 1: Confirm consent status and the clinical indication for each image.
  • Step 2: Prepare the field, barrier the device, and disable geotagging.
  • Step 3: Capture standardized sequences (wide/medium/close) with ruler and orientation marks.
  • Step 4: Review in-app, delete errors, and add structured notes.
  • Step 5: Upload via secure workflow, verify receipt, and auto-purge local copies.
  • Step 6: Link images to the encounter; record who captured and who verified.

Set retention and purge schedules

Align image retention with medical record policies and state requirements. Automate deletion of device-resident copies after confirmed upload, and define how to handle duplicates or superseded images.

Using Approved Applications and Secure Data Transfer

Choose apps that meet clinical and security needs

  • BAA in place, role-based access, and multifactor authentication.
  • End-to-end encryption and adherence to HIPAA data transmission rules.
  • Metadata control, barcode/EHR patient matching, and audit trail management.
  • Offline capture with queued, encrypted upload and automatic local purge.

Follow a safe transfer workflow

  • Initiate capture from within the approved app to avoid the personal camera roll.
  • Confirm secure upload and EHR attachment before leaving the room.
  • Reconcile image counts with your note; if an upload fails, retry on a trusted network.
  • Never share via personal email, SMS, or consumer cloud links.

Handle edge cases correctly

  • If connectivity is poor, keep images encrypted in the app’s container until you can upload securely.
  • If a device is lost or stolen, trigger remote lock/wipe and report per your incident response plan.

Maintaining Documentation and Access Logs

Document the imaging event

  • Record who captured the images, the clinical purpose, and the number and type of views.
  • Link each image to the correct encounter and anatomical site; include orientation notes.

Manage audits proactively

  • Use audit trail management to track creation, viewing, editing, exporting, and deletion.
  • Run periodic access reviews to detect out-of-role viewing or bulk downloads.
  • Log staff training, exceptions, and corrective actions after any deviation.

Respond to incidents

  • Escalate suspected exposures immediately to compliance and IT.
  • Contain (remote wipe, password resets), investigate, and document risk assessment steps.
  • Notify affected parties as required by the HIPAA Breach Notification Rule and applicable state laws.

FAQs

What are the HIPAA requirements for photographing surgical margins?

Use the minimum necessary standard, avoid unnecessary identifiers, and store and transmit images using encryption standards that protect PHI at rest and in transit. Capture and transfer only within approved systems covered by a BAA, restrict access by role, and maintain an auditable record of who created, viewed, or shared images. Document consent status and clinical purpose in the chart.

How can medical assistants secure mobile phones used for clinical photos?

Enable a strong passcode with biometric access controls, auto-lock, and remote wipe via MDM. Keep the OS updated, disable camera geotagging, and block unmanaged sharing methods (SMS, AirDrop). Use secure image storage inside an approved app, verify encrypted upload, and ensure automatic deletion of local copies after transfer.

For treatment and internal operations, clinics may allow photography within HIPAA without a separate authorization; however, many require written patient consent forms as a best practice. For marketing, education, or external publication, obtain specific written authorization before capturing images. Always follow your clinic’s policy and any applicable state requirements.

What policies should clinics have for mobile device usage in medical imaging?

Establish clinical photography policies that define approved devices/apps, user roles, encryption and HIPAA data transmission rules, retention and purge schedules, consent procedures, and audit trail management. Include incident response steps for lost devices or misdirected images and require regular training and attestations from staff.

Share this article

Ready to simplify HIPAA compliance?

Join thousands of organizations that trust Accountable to manage their compliance needs.

Related Articles