Is Height HIPAA Compliant for Fertility Embryo Photo Project Databases?

Product Pricing
Ready to get started? Book a demo with our team
Talk to an expert

Is Height HIPAA Compliant for Fertility Embryo Photo Project Databases?

Kevin Henry

HIPAA

June 23, 2026

7 minutes read
Share this article
Is Height HIPAA Compliant for Fertility Embryo Photo Project Databases?

HIPAA Requirements for Fertility Data

Whether you can store embryo photos on Height depends on whether the platform and your configuration satisfy HIPAA’s Privacy, Security, and Breach Notification Rules. For fertility clinics and embryology labs, images associated with treatment, billing, or operations are protected health information and must be handled accordingly.

Covered entity compliance requires a signed Business Associate Agreement (BAA) with any vendor that stores or processes PHI, a documented risk analysis, and policies enforcing the minimum-necessary standard. Embryo photos linked to embryology lab records or patient identifiers fall squarely within this scope.

To use a project database like Height with PHI, you need administrative, physical, and technical safeguards that are provable and auditable. The goal is to ensure confidentiality, integrity, and availability while enabling clinical workflows without unnecessary exposure.

  • Signed BAA that covers storage, processing, backups, subcontractors, and breach notification.
  • Role-based or attribute-based access, multi-factor authentication, and least-privilege permissions.
  • Encryption in transit and at rest aligned to modern data encryption standards.
  • Comprehensive HIPAA audit controls capturing view, download, share, delete, and admin actions.
  • Documented training, incident response, and change management for workforce and vendors.

If a vendor will not sign a BAA or cannot meet these controls, treat the system as non-HIPAA and keep PHI out—use only de-identified training images.

Role of Protected Health Information in Photography

Embryo photos rarely identify a person by themselves, but they become PHI when they are linked to a patient or included in the designated record set. File names, timestamps, dish or straw IDs mapped to embryology lab records, and embedded EXIF data commonly create that linkage.

When images support care or billing, they belong in the clinical record and must be secured accordingly. For marketing or public sharing, obtain written patient authorization; for research or teaching, use de-identification or an appropriate approval pathway.

Practical safeguards for embryo photography

  • Use neutral file names and scrub EXIF; never include names, MRNs, or dates of birth.
  • Keep any mapping table that links images to patients inside a secured system with strict access.
  • Apply secure sharing protocols: patient portal delivery, expiring links, viewer-only modes, and watermarking.
  • If images are associated with PGT/PGT-A results, elevate genetic data security by restricting access and auditing usage.

Secure Data Storage Solutions

Photo databases typically pair object storage for images with a database for metadata. For HIPAA workloads, insist on encryption at rest, strong tenant isolation, and tested backup and disaster recovery that do not weaken confidentiality.

In a SaaS like Height, verify where data and backups reside, how tenants and projects are logically separated, and whether per-tenant keys protect both images and metadata. Segregate PHI projects from non-PHI workspaces to reduce accidental exposure.

Ready to assess your HIPAA security risks?

Join thousands of organizations that use Accountable to identify and fix their security gaps.

Take the Free Risk Assessment
  • AES-256 encryption at rest and TLS 1.2/1.3 in transit that align with data encryption standards.
  • Key management via HSM/KMS with rotation, separation of duties, and restricted key use.
  • Versioning and immutable, encrypted backups with documented RTO/RPO and restore testing.
  • Granular RBAC/ABAC, SSO, MFA, session timeouts, and IP allowlisting.
  • Endpoint controls (e.g., MDM) to prevent local caching of embryo images on unmanaged devices.
  • Secure sharing protocols for internal and patient-facing flows, plus SFTP or secure APIs for bulk ingest.

Encryption and Data Security Protocols

Encrypt data in transit and at rest as a baseline. Prefer modern TLS with forward secrecy and AES‑256 storage encryption, using envelope encryption so keys for images differ from keys for metadata and thumbnails.

Manage keys centrally in validated modules, rotate them on a defined schedule, and log every key operation. Treat key access as highly privileged, and monitor for anomalous patterns as part of HIPAA audit controls.

Preserve integrity with cryptographic hashes and object checksums; make changes traceable and reversible through versioning. Enforce SSO, MFA, least privilege, short sessions, and device posture checks to mitigate account takeover risk.

Harden operations with patching, vulnerability scanning, penetration testing, and a secure SDLC. Prepare for incidents with clear detection, containment, forensics, and breach notification processes that activate without delay.

Compliance Verification for Photo Databases

Compliance is verified, not assumed. Ask for a signed BAA, the vendor’s risk analysis, and evidence of administrative, physical, and technical safeguards. Confirm how subcontractors are managed and whether obligations flow down contractually.

Attestations such as SOC 2 Type II or HITRUST can support your review but are not a substitute for HIPAA. Your configuration must still enforce encryption, access control, and monitoring aligned to clinic policy.

Test controls in your environment. Attempt role misuse, export large image sets, and review reports to ensure you can reconstruct who viewed, shared, edited, or deleted any embryo image or associated note.

Due-diligence checklist when evaluating Height or any photo database

  • BAA with permitted uses, subcontractor flow-downs, breach notification timelines, and data return/deletion.
  • Documented encryption architecture and data encryption standards for storage, transit, and backups.
  • HIPAA audit controls: immutable logs, query/report capabilities, and retention aligned to policy.
  • Access model: RBAC/ABAC, SSO, MFA, session control, and conditional access.
  • Secure sharing protocols: portal-based delivery, expiring links, disabled public links, and watermarking.
  • Data lifecycle: retention schedules, legal hold, and verifiable secure deletion.
  • Disaster recovery: tested restores with defined RTO/RPO and evidence of success.
  • Support for de-identification and hard separation of PHI vs non‑PHI projects and environments.

If any of these are missing, treat the platform as unsuitable for PHI and limit it to de-identified embryo images.

Regulatory Considerations for Embryo Images

When embryo photos inform selection, grading, or documentation in the lab, they are part of the designated record set. Patients have rights to access copies, and your workflows should support timely, secure fulfillment.

For research or education, prefer de‑identification and minimize linkage to individuals. If risk of re‑identification persists, obtain appropriate authorization or approvals and document the analysis that supports your decision.

Align retention and deletion with clinic policy and applicable state requirements. Maintain compliance documentation and keep logs long enough to answer access, disclosure, and integrity questions over time.

Linking images with genetic test outcomes heightens sensitivity; apply stricter genetic data security, tighter access, and more frequent audit review. Limit export and ensure downstream systems can protect PHI to the same standard.

Control image capture devices in the lab: disable consumer cloud sync, remove cached copies after ingest, and place capture stations on segmented networks to reduce lateral movement risk.

Conclusion

To determine whether Height is HIPAA compliant for fertility embryo photo project databases, confirm a signed BAA, strong encryption and key management, enforceable access controls, comprehensive HIPAA audit controls, resilient backups and deletion, and secure sharing protocols. If those elements are not present, do not store protected health information in the system; use only de‑identified images.

FAQs.

What criteria determine if a photo database is HIPAA compliant?

A compliant system offers a signed BAA, documented risk analysis, encryption in transit and at rest, robust access controls with MFA, HIPAA audit controls for all user and admin actions, breach notification processes, and clear data lifecycle management. It must also support secure sharing protocols and align with your covered entity compliance policies.

How does HIPAA apply to embryo images?

Embryo images are PHI when they are linked to a patient or used in care alongside embryology lab records, file names, timestamps, or mapping tables. If fully de‑identified and used outside treatment, they may fall outside HIPAA, but you should still minimize re‑identification risk and control distribution.

What security measures are required for fertility data storage?

Use AES‑256 at rest, TLS 1.2/1.3 in transit, centralized key management, SSO and MFA with least‑privilege RBAC/ABAC, immutable logging and reporting, encrypted and tested backups, defined retention and secure deletion, and network segmentation. Enforce secure sharing protocols, watermarking, and device controls to protect sensitive genetic data and images end to end.

Share this article

Ready to assess your HIPAA security risks?

Join thousands of organizations that use Accountable to identify and fix their security gaps.

Take the Free Risk Assessment

Related Articles