New Mexico Privacy Laws for Wound Care Pressure Injury Photos in Measurement Apps

Product Pricing
Ready to get started? Book a demo with our team
Talk to an expert

New Mexico Privacy Laws for Wound Care Pressure Injury Photos in Measurement Apps

Kevin Henry

Data Privacy

September 02, 2026

7 minutes read
Share this article
New Mexico Privacy Laws for Wound Care Pressure Injury Photos in Measurement Apps

Capturing and analyzing wound care pressure injury photos in measurement apps implicates overlapping New Mexico statutes and federal HIPAA rules. This guide explains how state medical-records confidentiality, HIPAA’s Protected Health Information standards, image‑sharing limits, breach notice timelines, patient monitoring rules, and digital privacy proposals apply when you store, process, and share these sensitive clinical images.

Medical Records Confidentiality in New Mexico

How state confidentiality applies to wound photos

Under the Public Health Act, records held by health authorities are confidential, and New Mexico separately defines “Individually Identifiable Health Information” (IIHI) and governs its permitted use and disclosure. Wound images tied to a patient—directly or through metadata—qualify as IIHI and must be safeguarded accordingly. Health care insurers and facilities also have rules requiring that medical records be kept confidential and released only as permitted by state or federal law. ([law.justia.com](https://law.justia.com/codes/new-mexico/chapter-24/article-1/section-24-1-20/?utm_source=openai))

For recipients not otherwise authorized by law, New Mexico hospital regulations require written patient consent before releasing medical information. Your workflows for exporting or sharing pressure injury photos with external parties (for example, non‑covered consultants) should therefore incorporate documented consent paths in addition to any HIPAA authorization that may be required. ([regulations.vlex.com](https://regulations.vlex.com/vid/n-m-code-r-955537754?utm_source=openai))

Protected Health Information under HIPAA

When wound photos are PHI

A wound photo becomes Protected Health Information (PHI) when a HIPAA covered entity or its business associate creates, receives, maintains, or transmits the image and it can be linked to an individual. The HIPAA Privacy, Security, and Breach Notification Rules govern such handling. “Full‑face photographs and comparable images” are explicit identifiers, and de‑identification requires removing them (or using expert determination). ([hhs.gov](https://www.hhs.gov/hipaa/for-professionals/privacy/laws-regulations/index.html?utm_source=openai))

Apps inside vs. outside HIPAA

If your measurement app is provided on behalf of a covered entity (or its vendor) and processes PHI, you are a business associate and must execute a BAA and comply with the HIPAA Security Rule. Consumer apps used solely by patients for personal purposes are typically outside HIPAA, even if data originated from a provider portal. Clarify this boundary and structure data flows accordingly. ([hhs.gov](https://www.hhs.gov/hipaa/for-professionals/privacy/guidance/business-associates/index.html?utm_source=openai))

Minimum necessary and operational safeguards

Limit access to the minimum necessary for care, payment, or operations, and align access controls, role design, and audit logging with HIPAA’s administrative, physical, and technical safeguards. A documented risk analysis and ongoing risk management are foundational requirements for apps storing ePHI. ([hhs.gov](https://www.hhs.gov/hipaa/for-professionals/privacy/guidance/minimum-necessary-requirement/index.html?utm_source=openai))

Unauthorized Distribution of Sensitive Images

How New Mexico’s law can reach clinical images

New Mexico criminalizes the “unauthorized distribution of sensitive images” when a person shares images of another without consent and with harmful intent (e.g., to harass or intimidate), with escalating penalties for repeat offenses. If wound photos reveal intimate areas (common with sacral or buttock pressure injuries), non‑clinical sharing outside authorized treatment contexts may trigger this statute in addition to HIPAA and employment policies. ([codes.findlaw.com](https://codes.findlaw.com/nm/chapter-30-criminal-offenses/nm-st-sect-30-37a-1/?utm_source=openai))

Sensitive Image Distribution Penalties

A first offense is a misdemeanor; subsequent convictions are fourth‑degree felonies. App policies should include explicit Unauthorized Disclosure Prohibition language, workforce training, and fast escalation paths for investigating suspected image misuse. ([codes.findlaw.com](https://codes.findlaw.com/nm/chapter-30-criminal-offenses/nm-st-sect-30-37a-1/?utm_source=openai))

Data Breach Notification Requirements

New Mexico’s Data Breach Notification Act

If computerized personal identifying information of New Mexico residents is breached, notify affected residents “in the most expedient time possible,” but no later than 45 calendar days after discovery (subject to limited law‑enforcement or remediation delays). If more than 1,000 residents are affected, you must also notify the Attorney General and consumer reporting agencies and provide the AG a copy of the consumer notice within the same 45‑day window. ([law.justia.com](https://law.justia.com/codes/new-mexico/chapter-57/article-12c/section-57-12c-6/))

HIPAA Breach Notification Rule

For breaches of unsecured PHI, notify individuals without unreasonable delay; notify HHS (and, for incidents involving 500+ individuals in a state/jurisdiction, the media). Encryption consistent with HHS guidance provides a safe harbor because encrypted ePHI is not “unsecured PHI” under the Rule. Align your breach playbooks and encryption standards accordingly. ([hhs.gov](https://www.hhs.gov/hipaa/for-professionals/breach-notification/index.html?utm_source=openai))

Ready to simplify HIPAA compliance?

Join thousands of organizations that trust Accountable to manage their compliance needs.

Patient Care Monitoring Act Provisions

Electronic monitoring in long‑term care settings

New Mexico’s Patient Care Monitoring Act authorizes residents (or surrogates) in certain facilities to install monitoring devices, sets consent and notice requirements, and provides immunity for compliant use. Rules require facilities to provide notice and forms explaining the Act and to accommodate lawful monitoring. Tampering with authorized monitoring devices can be a criminal act. If your app captures wound images in these settings, align your consent and signage practices with these provisions. ([law.justia.com](https://law.justia.com/codes/new-mexico/chapter-24/article-26/))

Digital Privacy Regulations and CHISPA

Current digital privacy landscape

Beyond HIPAA, New Mexico has sectoral rules that signal strong privacy expectations. For example, the Nondisclosure of Sensitive Personal Information Act (effective July 1, 2025) restricts state agencies from disclosing certain sensitive personal data, including medical conditions—context your organization should consider when partnering with public programs. In 2023, SB 13 established protections around reproductive and gender‑affirming health care, reflecting increasing attention to health‑related privacy. ([spo.state.nm.us](https://www.spo.state.nm.us/2025/07/03/general-memorandum-2025-007/?utm_source=openai))

CHISPA’s status and implications

The Community and Health Information Safety and Privacy Act (CHISPA) was introduced as SB 53 in 2026 to tighten controls on data brokers and sensitive community and health information but was postponed indefinitely that session and is not enacted as of September 14, 2026. Monitor future sessions, as passage could add obligations for apps handling quasi‑health or location‑linked clinic visit data outside HIPAA. ([nmlegis.gov](https://www.nmlegis.gov/Sessions/26%20Regular/bills/senate/SB0053.PDF?utm_source=openai))

Security Requirements for Health Information Storage

Foundational safeguards for wound image repositories

  • Conduct and document a HIPAA risk analysis; implement role‑based access, strong authentication, audit logging, and device/endpoint controls for clinicians capturing bedside photos.
  • Encrypt images in transit and at rest to qualify for breach safe harbor; manage keys securely; and segment storage for production, analytics, and training uses. ([hhs.gov](https://www.hhs.gov/hipaa/for-professionals/security/laws-regulations/index.html?utm_source=openai))

De‑identification and minimization

When building datasets (e.g., training measurement algorithms), follow Safe Harbor or expert determination standards; remove full‑face photographs and comparable images and strip metadata that can re‑identify patients. New Mexico Medicaid regulations mirror these identifiers (including full‑face photos) for de‑identification. ([hhs.gov](https://www.hhs.gov/hipaa/for-professionals/special-topics/de-identification/index.html?utm_source=openai))

Retention and destruction

Maintain medical records in line with facility policies and New Mexico rules, and keep destruction logs when records are purged. In apps, pair retention schedules with patient‑centric deletion pathways and documented legal holds. ([law.cornell.edu](https://www.law.cornell.edu/regulations/new-mexico/N-M-Admin-Code-SS-13.10.23.10?utm_source=openai))

FAQs.

Within HIPAA‑covered care, you may use and disclose PHI (including wound images) for treatment, payment, and operations without a patient’s written authorization, applying the minimum‑necessary standard outside treatment. For any other sharing—such as marketing, external training materials, or non‑TPO purposes—obtain a HIPAA‑compliant written authorization. New Mexico hospital rules also require written consent to release medical information to persons not otherwise authorized by law. ([hhs.gov](https://www.hhs.gov/hipaa/for-professionals/privacy/laws-regulations/index.html?utm_source=openai))

How does HIPAA apply to wound care pressure injury images in measurement apps?

If the app is offered on behalf of a provider or health plan and handles identifiable images, it is a business associate subject to HIPAA (with a BAA and Security Rule safeguards). If a patient independently uses a consumer app for personal purposes, HIPAA typically does not apply to that app—even if the patient imported images from a provider portal—so you should disclose privacy practices clearly and avoid mixing PHI flows. ([hhs.gov](https://www.hhs.gov/hipaa/for-professionals/privacy/guidance/business-associates/index.html?utm_source=openai))

What penalties exist for unauthorized distribution of sensitive medical images?

New Mexico’s “unauthorized distribution of sensitive images” statute makes non‑consensual sharing a misdemeanor, and a fourth‑degree felony upon subsequent conviction. If clinical photos depict intimate areas and are shared outside permitted care contexts with harmful intent, the law may apply in addition to HIPAA and employment sanctions. ([codes.findlaw.com](https://codes.findlaw.com/nm/chapter-30-criminal-offenses/nm-st-sect-30-37a-1/?utm_source=openai))

Are there specific data breach notification laws for health information in New Mexico?

Yes. Under New Mexico’s Data Breach Notification Act, notify affected residents within 45 calendar days of discovering a breach of computerized personal identifying information; if 1,000+ residents are affected, you must also notify the Attorney General and consumer reporting agencies and provide the AG a copy of the notice. For breaches of unsecured PHI, HIPAA’s Breach Notification Rule requires notice to individuals (and, in some cases, HHS and the media). Encryption that meets HHS guidance provides safe harbor. ([law.justia.com](https://law.justia.com/codes/new-mexico/chapter-57/article-12c/section-57-12c-6/))

Share this article

Ready to simplify HIPAA compliance?

Join thousands of organizations that trust Accountable to manage their compliance needs.

Related Articles