How Lymphedema Clinics Can Photograph Limb Measurements and Store Them on a Shared Drive: HIPAA Compliance Guide

Product Pricing
Ready to get started? Book a demo with our team
Talk to an expert

How Lymphedema Clinics Can Photograph Limb Measurements and Store Them on a Shared Drive: HIPAA Compliance Guide

Kevin Henry

HIPAA

September 09, 2026

8 minutes read
Share this article
How Lymphedema Clinics Can Photograph Limb Measurements and Store Them on a Shared Drive: HIPAA Compliance Guide

This HIPAA Compliance Guide shows you how to standardize limb-measurement photography and store images on a shared drive without exposing protected health information (PHI). You’ll align everyday workflows with the HIPAA Security Rule using practical controls such as encryption standards, role-based access control, audit trails, patient authorization, secure data transmission, and clear breach notification requirements.

Standardize Limb Measurement Photography

Define a repeatable capture protocol

  • Set clinical objectives: document baseline size, track edema trends, and verify treatment response at consistent intervals.
  • Pick fixed anatomical landmarks (for example, wrist crease or patella) and measure at standard offsets so every session is comparable.
  • Use a neutral, nonreflective background and diffuse lighting to avoid shadows that distort limb contours and measurement markings.
  • Stabilize the camera with a tripod; keep lens perpendicular to the limb to prevent parallax that misreads tape measurements.
  • Include a physical scale (tape, ruler, or calibration card) in each frame so measurements are verifiable across visits.

Positioning and framing

  • Mark floor spots for the patient’s feet and the tripod so distance, height, and angle remain constant across sessions.
  • Capture standard views (anterior, lateral, posterior) and close-ups of key measurement levels where the tape is visible and flat.
  • Ask patients to relax muscles and keep weight balanced; small posture shifts can change circumference readings.

Capture the measurement

  • Place the tape snugly, level with the skin, without compression; confirm units (centimeters recommended for precision).
  • Shoot wide and then a detail shot where the tape and graduated markings are clearly legible.
  • Use burst mode to reduce motion blur; select the sharpest frame and discard the rest to minimize redundant PHI.

File naming, metadata, and documentation

  • Adopt a PHI-safe naming scheme: ClinicCode_PatientCode_YYYYMMDD_hhmm_BodyPart_Laterality_View.jpg (avoid names, DOB, or full MRNs).
  • Disable geotagging; strip EXIF metadata during ingest so location and device identifiers are not retained.
  • Record contextual data in the chart (landmarks, tape position, patient posture) rather than the filename.
  • Use a brief checklist for quality control before saving: focus, glare, scale visible, no incidental identifiers.

Secure Storage on Shared Drives

Meet baseline requirements under the HIPAA Security Rule

  • Store images only on an enterprise-managed shared drive or cloud file service with a signed business associate agreement.
  • Enforce encryption standards: full-disk or server-side encryption at rest and TLS-protected, secure data transmission in transit.
  • Use role-based access control to restrict folders to the minimum necessary workforce members.
  • Enable audit trails that capture create, view, modify, move, delete, and download events.

Harden the shared drive

  • Require multi-factor authentication for remote or offsite access; disallow personal email or consumer sync tools.
  • Segment storage: an intake “drop” folder with write-only rights, a review folder for clinicians, and a read-only archive for finalized images.
  • Block public links and anonymous sharing; confine access to authenticated users on managed devices.

Design the data lifecycle

  • Define retention and disposition rules consistent with medical record policy; automate archival and verified deletion.
  • Prevent “shadow copies” on local desktops; use streaming or on-demand access with short-lived caches.
  • Document the system of record so staff know exactly where images live and how they relate to the patient chart.
  • For treatment documentation, HIPAA generally permits photography without a special authorization; many clinics still obtain explicit consent for clarity and state-law alignment.
  • For non-treatment uses (education outside the care team, marketing, research), obtain a HIPAA-compliant patient authorization describing purpose, scope, and expiration.
  • State why images are taken, where they are stored (shared drive/EHR), who may access them, and how long they are kept.
  • Explain patient rights, including the ability to revoke future use, and how to request restrictions.
  • Address minors and surrogate decision-makers; ensure signatures and dates are captured and stored with the record.

Protect identity at the point of capture

  • Exclude the face and other unique identifiers (name badges, wristbands, tattoos) unless clinically necessary.
  • Use draping and neutral backdrops; avoid mirrors or reflective surfaces that can reintroduce identifiers.
  • Label with a patient code or visit ID, not names; never write PHI on placards visible in the image.
  • Disable automatic cloud backups on capture devices and remove location services for the camera app.

Implement Access Controls and Auditing

Role-based access control (RBAC)

  • Create groups for intake, treating clinicians, and supervisors; deny by default and grant time-bound access as needed.
  • Use “break-glass” procedures for emergencies that require a documented reason and enhanced logging.
  • Review group membership monthly and upon job changes; remove access promptly when roles end.

Identity, device, and session security

  • Assign unique user IDs; require strong passwords and MFA; enable automatic screen locks and short session timeouts.
  • Manage devices with full-disk encryption, remote-wipe capability, and blocked removable media for PHI folders.

Audit trails and monitoring

  • Log access attempts, successful reads, downloads, and deletions; alert on unusual patterns like mass exports.
  • Retain logs per policy (often six years to align with HIPAA documentation retention) and review them on a set cadence.
  • Document all privacy and security incidents, outcomes, and corrective actions.

Establish Data Backup and Recovery Procedures

Design a resilient backup strategy

  • Follow the 3-2-1 rule: three copies, two different media, one offsite/immutable; encrypt all backups.
  • Define recovery time and recovery point objectives with clinical leadership so downtime risks are explicit.
  • Store backup encryption keys securely, separate from data, with dual control and documented access.

Test and validate recovery

  • Run routine restore drills to a sandbox and verify file integrity and folder permissions.
  • Document each test, results, and improvements; update the runbook after system or workflow changes.
  • Ensure backups also capture audit logs so investigations remain possible after an incident.

Provide Privacy and Security Training

Deliver role-tailored training

  • Teach how to capture, label, and upload images without PHI leakage, including de-identification practices.
  • Cover secure data transmission, password hygiene, phishing awareness, lost-device reporting, and clean-desk rules.
  • Explain the HIPAA Security Rule in practical terms so staff understand why controls matter for patient trust.

Verify and reinforce

  • Onboard before access; refresh at least annually and when policies or systems change.
  • Use short scenario-based assessments; track acknowledgments and completion dates.
  • Conduct spot checks of images and folder permissions; share lessons learned from incidents.

Utilize HIPAA-Compliant Technology Tools

Capture and upload

  • Use managed devices or secure camera apps that bypass the personal photo gallery and upload directly to the protected share.
  • Enforce mobile device management with encryption, biometrics, and remote wipe; block third-party cloud backups.

Storage and management

  • Choose file platforms that offer encryption standards at rest, granular role-based access control, and built-in audit trails.
  • Automate metadata scrubbing and file renaming during ingest to remove geolocation and device identifiers.

Transmission safeguards

  • Transfer over VPN using SMB encryption or via SFTP/HTTPS with TLS 1.2+; never use unsecured Wi‑Fi for PHI.
  • Disable ad hoc Bluetooth or peer-to-peer transfers; prefer wired imports when feasible.

Automation and monitoring

  • Use data loss prevention to flag bulk downloads or attempted external sharing.
  • Set alerts for permission changes, access from unusual locations, and repeated failed logins.

Conclusion

By standardizing capture, protecting identity at the source, and enforcing security on your shared drive, you create reliable clinical photos without compromising privacy. Aligning with the HIPAA Security Rule through encryption, role-based access controls, audit trails, and tested backups reduces risk. Consistent training and HIPAA-compliant tools keep the process simple, secure, and sustainable.

Ready to simplify HIPAA compliance?

Join thousands of organizations that trust Accountable to manage their compliance needs.

FAQs.

Explain the clinical purpose and storage location during intake, and include photography in your treatment consent. Use a dedicated form when images may be shared beyond the care team. For non-treatment uses such as marketing, external education, or research, obtain a HIPAA-compliant patient authorization that specifies purpose, recipients, expiration, and the right to revoke.

What security measures are required for storing photos on shared drives?

Use enterprise-managed storage with a BAA, encryption at rest, and secure data transmission in transit. Restrict access with role-based access control, require MFA, and enable detailed audit trails. Segment folders by function, disable public links, and enforce retention and verified deletion to meet HIPAA Security Rule expectations.

How can clinics limit access to sensitive patient images?

Apply least-privilege RBAC, group-based permissions, and time-limited access. Use “break-glass” procedures for exceptions with reason logging. Block copying to removable media, disable external sharing, and monitor audit trails for unusual activity. Review memberships and access rights regularly and remove access promptly when roles change.

What steps should be taken if a data breach occurs?

Contain and investigate immediately: isolate affected systems, preserve logs, and assess the scope and risk to PHI. Follow breach notification requirements by notifying affected individuals without unreasonable delay and no later than 60 days after discovery, and notify regulators and media when thresholds apply. Document actions taken, provide mitigation support as needed, and update safeguards and training to prevent recurrence.

Share this article

Ready to simplify HIPAA compliance?

Join thousands of organizations that trust Accountable to manage their compliance needs.

Related Articles