How to Stay HIPAA-Compliant When Your Pediatric Dental Office Uses Behavior Guidance Videos

Product Pricing
Ready to get started? Book a demo with our team
Talk to an expert

How to Stay HIPAA-Compliant When Your Pediatric Dental Office Uses Behavior Guidance Videos

Kevin Henry

HIPAA

August 26, 2026

8 minutes read
Share this article
How to Stay HIPAA-Compliant When Your Pediatric Dental Office Uses Behavior Guidance Videos

Before recording any behavior guidance videos, obtain clinical informed consent from a parent or legal guardian and, when appropriate, the child’s assent. Informed consent covers the clinical decision to record and how recording supports the child’s care, which is distinct from a HIPAA Authorization for disclosure.

Use clear, plain language and explain:

  • Why the video is being recorded and how it supports behavior guidance and treatment.
  • Who will be allowed to view it for care and Healthcare Operations, and how long it will be kept.
  • Where and how it will be stored, security safeguards, and who to contact with questions.
  • That participation is voluntary, refusal will not affect treatment, and consent may be withdrawn prospectively.

Capture signatures and dates, and file the Informed Consent Documentation in the patient record. Note any limitations the family requests (for example, “care team only”). Keep a simple index so you can quickly locate, retrieve, and, if needed, delete specific recordings tied to a child’s Protected Health Information.

Obtain HIPAA Authorization for Video Use

When you want to use or disclose a video beyond treatment, payment, or Healthcare Operations—such as on your website, social media, public presentations, or external education—you must obtain a HIPAA Authorization from the parent or legal guardian. This is separate from clinical consent and specifically permits the use/disclosure of PHI in the video.

A valid HIPAA Authorization should include:

  • A specific description of the PHI (for example, “behavior guidance video recorded on [date]”).
  • Who may disclose and who may receive the video (named persons or organizations).
  • The purpose of the disclosure (for example, “marketing,” “community education”).
  • An expiration date or event (for example, “one year from signature” or “until withdrawn”).
  • Notice of the right to revoke in writing and that prior uses cannot be undone.
  • Disclosure risks, including the potential for re-disclosure by recipients not subject to HIPAA.
  • Signature and date of the parent/guardian (and patient if state law requires).

Limit any sharing to exactly what the Authorization describes. If a vendor will store, edit, or distribute the video, ensure a Business Associate Agreement is in place. Apply the Minimum Necessary Standard to planning and workflows so only the smallest necessary portion of the video is used.

Apply Exemptions for Treatment and Operations

HIPAA permits using and sharing PHI without Authorization for treatment and Healthcare Operations. You may record and use behavior guidance videos internally to coordinate care, consult within your care team, or coach staff on improving comfort and safety.

For Healthcare Operations (such as internal quality improvement or workforce training), apply the Minimum Necessary Standard: limit access to the smallest video segment needed, restrict viewers to those with a work-related need, and avoid unnecessary duplication. Remember, the Minimum Necessary Standard does not apply to treatment uses, but you should still practice prudent access control.

  • Allowed without Authorization: showing a clip to your clinical team to plan a future appointment (treatment), or using a short segment in an internal staff huddle (operations).
  • Requires Authorization or De-Identification: showing a video to other families in your waiting room, posting online, or presenting to audiences outside your workforce.

If a single recording could serve both treatment and external education, create two versions: an internal version for care and a separate copy that is either properly Authorized or fully de-identified.

Ensure Video De-Identification

Once a video is de-identified, it is no longer PHI and HIPAA no longer governs its use. You can de-identify by removing identifiers to Safe Harbor standards or by obtaining expert determination that the re-identification risk is very small.

Practical steps for behavior videos include:

  • Mask faces (child, family, staff), modulate voices, and remove spoken names.
  • Crop or blur backgrounds that show names, addresses, school logos, or appointment boards.
  • Delete on-screen or embedded metadata with dates, times, device IDs, or GPS coordinates.
  • Hide unique features that could identify the child (distinctive braces colors paired with dates, rare conditions, or visible birthmarks).
  • Remove any documents or screens in frame that reveal treatment plans or account details.

Document your De-Identification workflow and quality checks. If you must retain limited elements (for example, dates) for analysis, treat the file as a limited data set, use a data use agreement, and continue applying strong safeguards.

Ready to simplify HIPAA compliance?

Join thousands of organizations that trust Accountable to manage their compliance needs.

Maintain Detailed Documentation

Good records prove good compliance. Keep required documentation for at least six years from creation or last effective date. Maintain a clear map of where videos live, who can access them, and how they are protected.

  • Informed Consent Documentation and any HIPAA Authorizations, including revocations.
  • A video inventory noting patient, purpose (treatment vs. Healthcare Operations), storage location, and retention period.
  • Access and audit logs showing who viewed, edited, or exported each file.
  • Written policies for recording, Minimum Necessary Standard application, retention, and destruction.
  • Vendor due diligence records and Business Associate Agreements for any tools handling videos.
  • De-Identification records: methods used, reviewer sign-off, and date completed.
  • Incident and breach response notes, if applicable, with corrective actions.
  • Compliance Training Records for all workforce members.

Use consistent file naming and standardized forms so you can respond quickly to family requests, audits, or investigations.

Conduct HIPAA Compliance Training

Train every workforce member who can record, view, edit, or share videos. Make training role-based and repeat it at hire, annually, and whenever policies or technologies change.

  • What counts as Protected Health Information in video, and when Authorization is required.
  • How to apply the Minimum Necessary Standard in day-to-day tasks.
  • De-Identification techniques and when to use them.
  • Secure capture and storage practices, including device and screen hygiene.
  • How to handle family requests, revocations, and incident reporting.

Have staff attest to understanding and keep Compliance Training Records with dates, curricula, and attendance. Reinforce expectations with quick refreshers during huddles and technology updates.

Secure Video Storage and Access Controls

Behavior videos are PHI and must meet HIPAA Security Rule safeguards. Protect them with layered technical, administrative, and physical controls from capture to deletion.

  • Use encrypted storage at rest and in transit; enable device encryption and automatic locking.
  • Implement role-based access, unique user IDs, multi-factor authentication, and strong passwords.
  • Maintain audit controls to log viewing, editing, exporting, and deletion; review logs regularly.
  • Standardize capture devices and disable local camera rolls or auto-uploads to personal clouds.
  • Prohibit unmanaged messaging apps; use approved, secure platforms with BAAs.
  • Limit copies, set retention periods, and automate archival and destruction workflows.
  • Back up securely, test restores, and document your disaster recovery process.

By combining informed consent, precise HIPAA Authorizations, strict De-Identification, disciplined documentation, ongoing training, and strong security, you uphold HIPAA while using behavior guidance videos to improve pediatric dental care.

FAQs

Valid consent explains the purpose of recording, expected benefits and any risks, who may view the video for care or Healthcare Operations, how it will be secured and retained, and that participation is optional and can be withdrawn prospectively. It is documented with the parent or guardian’s signature (and child assent when appropriate), date, scope limits, and a contact for questions. Remember: informed consent covers clinical recording, while a HIPAA Authorization is required for uses beyond treatment and operations.

How can videos be de-identified to comply with HIPAA?

Apply Safe Harbor-style removal of identifiers or obtain expert determination that re-identification risk is very small. In practice, blur faces, crop backgrounds, remove names and on-screen documents, modulate or strip audio that reveals identity, and delete metadata like timestamps and GPS. Keep a De-Identification checklist and reviewer sign-off; if any identifying elements remain, treat the file as PHI or as a limited data set with appropriate agreements.

When is HIPAA authorization required for behavior video use?

You need Authorization when using or disclosing a video outside treatment, payment, or Healthcare Operations—for example, posting on your website or social media, presenting to external audiences, sharing with third parties without a BAA, or displaying to other patients in your waiting room. Internal care coordination and workforce training typically do not require Authorization, but you should still apply the Minimum Necessary Standard and access controls.

What documentation is necessary to maintain HIPAA compliance with behavior videos?

Maintain Informed Consent Documentation, HIPAA Authorizations and revocations, a video inventory, access and audit logs, written policies (recording, Minimum Necessary Standard, retention, destruction), vendor assessments and BAAs, De-Identification records, incident/breach notes, and Compliance Training Records. Retain required documentation for at least six years from creation or last effective date and ensure you can quickly retrieve specific items during audits or family requests.

Share this article

Ready to simplify HIPAA compliance?

Join thousands of organizations that trust Accountable to manage their compliance needs.

Related Articles