Monday in a dermatology practice: sixty patients, two Mohs cases, a dozen biopsies, total body photography for three high-risk patients, an isotretinoin follow-up, and a cosmetic afternoon of neurotoxin and filler. By lunch a medical assistant has photographed a lesion with a personal phone, the cosmetic coordinator has posted a before-and-after, and the front desk has replied to a one-star Google review. Each of those is a HIPAA event.
The HHS Office for Civil Rights (OCR) enforcement listing prices them. A dental practice paid $10,000 to settle social media disclosures of patients' protected health information (October 2019). A New Jersey provider reached an agreement after disclosing patient information in response to negative online reviews (June 2023). An allergy practice paid $125,000 over a doctor's disclosure of patient information to a reporter (November 2018). And OCR imposed a $1.19 million penalty against Gulf Coast Pain Consultants for Security Rule violations (December 2024), a reminder that a specialty practice is held to the full rule.
This guide covers why HIPAA applies to a dermatology practice including its cosmetic side, what protected health information looks like when the record is mostly images, the violations that cluster in this specialty, how to build a program around the photo workflow, and which vendors need a Business Associate Agreement.
HIPAA Compliance for Dermatology Practices: Photos, Pathology, and Cosmetic Add-Ons
Why HIPAA Applies to a Dermatology Practice
45 CFR 160.103 defines a covered entity to include "a health care provider who transmits any health information in electronic form in connection with a transaction covered by this subchapter," and the first listed transaction is "health care claims or equivalent encounter information." A dermatology practice bills medical visits, biopsies, and surgery to health plans electronically, so it is a covered entity. The definition is walked through in what is a covered entity under HIPAA.
The question dermatology practices actually ask is whether the cash-pay cosmetic side is covered. It is. HIPAA attaches to the entity, not the procedure. The filler chart, the laser consent, and the before-and-after photo are P.H.I. (Protected Health Information) held by a covered entity, protected exactly like the biopsy report. A practice cannot run a lighter privacy standard on the cosmetic hallway.
What P.H.I. Looks Like in Dermatology
Dermatology runs on images, and 45 CFR 164.514(b)(2)(i) lists "full face photographic images and any comparable images" among the identifiers that must be stripped for data to count as de-identified. The face is the identifier; the picture is the record. The full identifier list is in the 18 HIPAA identifiers.
- Total body photography and mole mapping. Serial whole-body image sets for high-risk patients, stored in imaging systems and compared visit to visit.
- Dermoscopy and lesion photos. Close-up images tied to a body-map location and a biopsy log entry.
- Biopsy logs and pathology requisitions. The specimen log, the requisition sent to the dermatopathology lab, and the report that comes back with a diagnosis.
- Mohs maps and surgical photos. Stage-by-stage maps, margin diagrams, and defect and closure photographs.
- Isotretinoin records. Prescribing documentation under the FDA-mandated iPLEDGE program, including pregnancy test results for patients who can become pregnant.
- Biologic prior authorizations. Specialty pharmacy paperwork, prior authorization packets, and enrollment forms for manufacturer patient-support programs.
- Phototherapy and procedure logs. Treatment dates, doses, and settings.
- Cosmetic treatment records. Neurotoxin units per site, filler product and lot numbers, laser parameters, and before-and-after photographs.
- Teledermatology images. Store-and-forward photos submitted through a portal or app for remote review.
Common Violations in Dermatology Practices
Clinical photos on personal phones. A lesion photographed on a staff member's phone syncs to a personal cloud account, a family photo stream, and whatever messaging app is installed. 45 CFR 164.310(d) requires policies governing hardware and media that hold ePHI (electronic P.H.I.), and 164.312(a)(2)(iv) makes encryption an addressable specification the practice must implement or justify skipping. Why the default photo backup is not an answer is in is iCloud HIPAA compliant.
Before-and-after photos used for marketing without a valid authorization. 164.508(a)(3) requires an authorization for "any use or disclosure of protected health information for marketing." The form has to meet 164.508(c): a specific description of the images, who may use them, the purpose, an expiration date or event, the right to revoke, plain language, and a copy to the patient. 164.508(b)(4) prohibits conditioning treatment on signing it. The practical elements are in HIPAA authorization requirements.
Replying to reviews with clinical details. The New Jersey agreement above is the price of confirming that a reviewer was a patient and what was done. The only safe reply is generic and moves the conversation offline.
Talking to the media. Skin cancer awareness stories are a staple of local news, and the allergy practice's $125,000 settlement over a disclosure to a reporter shows the cost of describing a real patient without a signed authorization. OCR's enforcement listing also shows multiple settlements totaling $999,000 over disclosures during ABC documentary filming (September 2018).
Pathology results to the wrong place. A report emailed unencrypted, faxed to the wrong number, or posted to the wrong portal account is a disclosure that has to be assessed under the breach rule at 164.402. Results workflows need a verification step, not just speed.
Slow response to record requests. Patients ask for their photos and pathology reports, and 164.524(b)(2) allows 30 days to act, with one 30-day extension on written notice. Images used to make decisions about the patient are part of the designated record set and are covered by the request. OCR's listing includes three right-of-access settlements with dental practices announced on one day (September 2022); specialty practices are not exempt. The deadlines and fee rules are in HIPAA right of access.
Building the Program
Risk analysis that includes the imaging stack. 164.308(a)(1)(ii)(A) requires "an accurate and thorough assessment of the potential risks and vulnerabilities to the confidentiality, integrity, and availability of electronic protected health information." For dermatology that means the EHR, the total body photography system, the dermoscopy camera and its software, the phones and tablets used for photos, the teledermatology platform, and the cosmetic coordinator's marketing folder.
A clinical photography policy. One page that states which devices may take clinical photos, where images are stored, how they are labeled, who may access them, how long they are kept, and the rule that marketing images live in a separate, authorization-backed folder. This single policy prevents most of the violations above.
Two consent workflows, kept apart. Treatment photography needs no authorization; it is part of treatment. Marketing use needs a 164.508 authorization for each patient, tracked with an expiration date and a revocation process.
Training that names the specialty's habits. 164.530(b)(1) requires training for the whole workforce. Cover the phone camera, the review reply, the media call, and the difference between a treatment photo and a marketing photo. Document it and keep the record for six years under 164.530(j)(2).
Notice of Privacy Practices, including online. 164.520(c)(2) requires the notice at first service delivery with a good-faith effort to obtain acknowledgment, and 164.520(c)(3)(i) requires a covered entity with a website describing its services to "prominently post its notice on the web site." Cosmetic landing pages count as the website.
Vendor B.A.A. Checklist for Dermatology
Under 160.103 a business associate is a person who, on the practice's behalf, "creates, receives, maintains, or transmits protected health information" for a regulated function. The same definition excludes "a health care provider, with respect to disclosures by a covered entity to the health care provider concerning the treatment of the individual," which is why the lab row below reads differently from the rest.
| Vendor category | Typical examples | B.A.A. required? |
|---|---|---|
| Dermatology EHR | ModMed EMA, Nextech, eClinicalWorks | Yes |
| Total body photography and imaging systems | Canfield VECTRA, FotoFinder, DermEngine | Yes, when images are stored with the vendor or the vendor has remote access |
| Teledermatology platform | Any store-and-forward or video platform | Yes |
| Patient communication and reminders | Klara, Solutionreach, Weave | Yes |
| Dermatopathology lab | The lab receiving specimens | No. The lab is a health care provider receiving P.H.I. for treatment and is a covered entity itself. Each side remains responsible for its own safeguards. |
| Specialty pharmacy | The pharmacy dispensing biologics or isotretinoin | No. A dispensing pharmacy is a provider for treatment disclosures. |
| Drug manufacturer patient-support programs | Copay and enrollment programs run by the manufacturer | No B.A.A.; the manufacturer is not acting on the practice's behalf. Check whether the disclosure fits payment or needs a patient authorization under 164.508, and when in doubt, get the authorization. |
| iPLEDGE (FDA isotretinoin program) | The federally mandated REMS system | No B.A.A. Disclosures into the program are a condition of prescribing; document the basis in policy and confirm it with counsel. |
| Billing company, IT managed services, cloud fax, shredding | Any of the standard back-office vendors | Yes |
| Marketing agency handling patient photos or lists | Any agency with access to images or patient data | Yes, and the authorizations must exist first |
The Proposed Security Rule Update (Proposed, Not Final)
HHS published a Notice of Proposed Rulemaking on January 6, 2025 that would make encryption and multifactor authentication required rather than addressable, require a written asset inventory and network map, and require vulnerability scans "at least once every six months." It is proposed, not final, and OCR is not enforcing it. The status is tracked in HIPAA Security Rule delayed to 2027. For a dermatology practice, the asset inventory would have to list every camera, phone, and imaging workstation that stores patient images. That list is already the backbone of a proper risk analysis under the current rule, so build it now.
---
FAQ
Are dermatology practices covered by HIPAA, including cosmetic services?
Yes. A dermatology practice that bills health plans electronically is a covered entity under 45 CFR 160.103, and HIPAA applies to the whole entity. Cash-pay cosmetic records, including before-and-after photos, are protected health information held by a covered entity.
Can a dermatology practice post before-and-after photos?
Only with a valid authorization from each patient under 164.508, because promotional use is marketing and a full-face image is an identifier. The authorization must contain the required elements, cannot be a condition of treatment, and can be revoked in writing.
Do clinical photos count as PHI?
Yes. An image tied to a patient, whether by face, name, chart number, or body-map location, is individually identifiable health information. 164.514(b)(2)(i) lists full face photographic images and any comparable images among the identifiers that must be removed for de-identification.
Does a dermatology practice need a BAA with its dermatopathology lab?
No. The lab is a health care provider receiving specimens for treatment, and 160.103 excludes disclosures to a provider concerning treatment from the business associate definition. The lab is a covered entity responsible for its own compliance.
Can staff take clinical photos on personal phones?
Only under a written policy that keeps the images out of personal cloud backups and messaging apps, encrypts the device, and routes photos into the practice's approved system. Most practices find it simpler to issue practice-owned devices or use the EHR's photo app.
Conclusion
A dermatology practice already has the hard part, the clinical discipline; what it usually lacks is a photography policy, an authorization form that works, and a vendor list with signed agreements. One Guy Consulting's Full-Scope plan supplies the risk analysis, the policy set including clinical photography, staff training, and B.A.A. tracking, with consulting time to fit it to a medical-plus-cosmetic practice. Start with a free 30-minute compliance review. No obligation, no pressure.
Sources
- 45 CFR 160.103 (definitions: covered entity, business associate, provider exclusion)
- 45 CFR 164.308 (administrative safeguards)
- 45 CFR 164.310 (physical safeguards)
- 45 CFR 164.312 (technical safeguards)
- 45 CFR 164.508 (authorizations, including marketing)
- 45 CFR 164.514 (de-identification and the identifier list)
- 45 CFR 164.520 (Notice of Privacy Practices)
- 45 CFR 164.524 (right of access)
- HHS OCR: Resolution Agreements and Civil Money Penalties
- Federal Register: HIPAA Security Rule NPRM (January 6, 2025)
Related Reading