How to Stay HIPAA Compliant When Recording Jaw‑Tracking Videos (Patient Faces Visible) in a TMJ/Orofacial Pain Clinic

Product Pricing
Ready to get started? Book a demo with our team
Talk to an expert

How to Stay HIPAA Compliant When Recording Jaw‑Tracking Videos (Patient Faces Visible) in a TMJ/Orofacial Pain Clinic

Kevin Henry

HIPAA

September 16, 2026

7 minutes read
Share this article
How to Stay HIPAA Compliant When Recording Jaw‑Tracking Videos (Patient Faces Visible) in a TMJ/Orofacial Pain Clinic

HIPAA Applicability to Video Recordings

When a jaw-tracking video is PHI or ePHI

When a patient’s face is visible in a jaw-tracking video and the recording relates to diagnosis, treatment, or payment, it is Protected Health Information (PHI). If you capture, store, or transmit that video electronically, it becomes Electronic Protected Health Information (ePHI) and must meet HIPAA’s Privacy and Security Rules.

Designated record set and operational recordings

If you rely on a recording to make clinical decisions or it documents care, treat it as part of the designated record set. If you capture videos for quality improvement or staff training, define in policy how you segregate, retain, and protect those files. Your policy should also explain when an operational video becomes part of the medical record.

Minimum necessary and workforce access

Apply the minimum necessary standard for uses and disclosures other than treatment. Limit who can access videos to workforce members with a legitimate role, and document role-based permissions to reinforce video recording privacy.

Obtain a patient’s informed consent to be recorded. HIPAA authorization is separate and only required when you use or disclose recordings for purposes outside treatment, payment, and health care operations, or when state law demands it.

You may record for treatment and certain internal operations (such as internal training) with documented consent to be recorded and appropriate notices. Keep the recording within your workforce and business associates, and apply strict access controls.

When authorization is required

Secure a written Patient Authorization before using a video with a visible face for external education, marketing, public presentations, publications, or other non-TPO purposes. The authorization should specify purpose, recipients, expiration, the right to revoke, and what happens to videos after revocation.

Special situations

Use the legally authorized representative for minors or patients lacking capacity. If audio is captured, be mindful that names or other identifiers may be recorded; consider disabling audio unless clinically necessary.

Security Measures for Video Recordings

Administrative Safeguards

  • Conduct a risk analysis focused on video capture, storage, transmission, and disposal.
  • Adopt policies on who may record, where recordings reside, retention timeframes, and approved devices and apps.
  • Train staff on handling ePHI in multimedia, sanctions for violations, and incident reporting.
  • Document contingency and backup plans so videos remain available during outages.

Physical Safeguards

  • Secure recording areas to avoid capturing bystanders and unintended screens or charts.
  • Lock rooms and cabinets housing servers, cameras, and removable media.
  • Implement device and media controls for any camera, tablet, or storage device used to record or export videos.

Technical Safeguards

  • Use unique user IDs, strong authentication, and automatic logoff on recording and viewing systems.
  • Encrypt videos in transit and at rest; protect backups with the same controls.
  • Enable audit logs to track who accessed, copied, exported, or deleted a recording.
  • Segment networks, restrict external sharing, and use secure, managed applications—avoid personal devices and consumer clouds.
  • Adopt secure deletion for media disposal and routine lifecycle management.

Workflow tips

  • Disable auto-upload or sync to non-approved cloud services on capture devices.
  • Store videos directly to your EHR, PACS/VNA, or approved repository rather than local device memory.
  • Label videos with internal IDs instead of names and keep metadata minimal.

Patient Rights Over Recorded Videos

Access and copies

Patients may request access to recordings in your designated record set and receive a copy in the form and format requested if readily producible. Respond within required timelines and charge only a reasonable, cost-based fee where permitted.

Amendment and restrictions

Patients may request an amendment if a video informs clinical decisions. If you deny the amendment, maintain a written statement of disagreement. Patients may request restrictions on certain disclosures; document your determinations and apply them consistently.

Accounting of disclosures

Maintain an accounting for disclosures of videos outside treatment, payment, and operations for the applicable lookback period. Keep logs that capture what was disclosed, to whom, when, and why.

Retention and disposal

Follow your retention schedule and state requirements for medical records. When disposal is due, use secure deletion or physical destruction methods aligned with your risk analysis and policies.

Ready to simplify HIPAA compliance?

Join thousands of organizations that trust Accountable to manage their compliance needs.

Business Associate Agreements

Who counts as a business associate

Any vendor that creates, receives, maintains, or transmits jaw-tracking videos or related ePHI for your clinic—such as cloud storage, telehealth or capture platforms, analytics providers, IT support, or transcription—requires a Business Associate Agreement (BAA).

Key BAA elements

  • Permitted uses and disclosures and a prohibition on unauthorized re-disclosure.
  • Administrative, physical, and technical safeguards aligned with HIPAA’s Security Rule.
  • Timely breach notification, subcontractor flow-down obligations, and right to terminate and require return or destruction of ePHI.
  • Audit, logging, and cooperation terms for inspections and investigations.

Due diligence

Assess vendor security practices, encryption, access controls, resilience, and incident response. Verify their ability to support your retention, export, and deletion requirements before you record a single video.

De-Identification of Video Recordings

Safe Harbor vs. Expert Determination

Under Safe Harbor, you must remove direct identifiers, including full-face images and comparable visuals. If faces are visible, you must blur or crop them and strip other identifiers and metadata. Expert Determination allows a qualified expert to document that the re-identification risk is very small, enabling controlled use without identifiers.

Practical steps to reduce risk

  • Crop to the lower face or jawline when feasible; blur full faces and distinctive features like tattoos or scars.
  • Remove audio or scrub names and incidental identifiers captured during recording.
  • Strip timestamps, GPS, device IDs, and file metadata; replace names with coded IDs stored separately.
  • Validate de-identification with periodic re-identification risk testing before external use.

State and Local Laws

HIPAA sets a national floor, but state and local rules may be stricter. Some jurisdictions require explicit consent to record in clinical settings and additional disclosures when audio is captured. Incorporate these requirements into your consent workflow and signage.

Retention, minors, and special protections

States dictate medical record retention periods and often apply longer timelines for minors. Some laws add extra protections for images and videos captured in health care settings; confirm requirements before defining your retention schedule.

Biometric and image-specific laws

Certain states regulate collection and use of facial imagery and other biometric identifiers. These laws may require written notice, purpose limitation, dedicated retention and deletion schedules, and specific safeguards beyond HIPAA.

Conclusion

To stay compliant, treat jaw-tracking recordings with visible faces as PHI/ePHI, obtain appropriate consent and Patient Authorization when needed, and implement strong Administrative and Technical Safeguards. Use BAAs for any vendor handling videos, and de-identify carefully before external use.

Document your policies, train your staff, and align your workflows with both HIPAA and stricter state rules. These steps protect your patients and your clinic while preserving the clinical value of jaw-tracking videos.

FAQs.

What constitutes PHI in jaw-tracking videos?

Any recording that can reasonably identify a patient—such as a visible face—and that relates to diagnosis, treatment, or payment is PHI. If the file is created, stored, or transmitted electronically, it is ePHI and must meet HIPAA’s Privacy and Security Rules.

Consent to be recorded is typically sufficient when you record for treatment or strictly internal operations and keep access limited to your workforce and business associates. If you plan to use or disclose the video outside those purposes, obtain a written HIPAA-compliant Patient Authorization.

How should jaw-tracking videos be securely stored?

Store videos only on approved, encrypted systems with role-based access, unique user IDs, multi-factor authentication, audit logging, and secure backups. Avoid personal devices and disable auto-sync to consumer clouds; apply secure deletion at end of retention.

What are patient rights regarding recorded videos?

Patients may access and receive copies of recordings in the designated record set, request amendments, and seek an accounting of certain disclosures. They may also request restrictions and confidential communications, subject to policy and applicable law.

Share this article

Ready to simplify HIPAA compliance?

Join thousands of organizations that trust Accountable to manage their compliance needs.

Related Articles