HIPAA Compliance for Imaging Centers: Where the Studies Live

Practical guidance for healthcare teams and business associates

An imaging center is a strange kind of covered entity. Most patients spend twenty minutes in the building, never meet the radiologist, and leave with nothing but a bruise from the contrast line. The center keeps the rest: thousands of studies, each one a stack of image files with the patient's name, birth date, and medical record number written into the file itself.

OCR (the HHS Office for Civil Rights) has noticed. Its settlement list includes a $3,000,000 settlement with a Tennessee diagnostic medical imaging services company over a breach exposing over 300,000 patients' protected health information (May 6, 2019), a Security Rule settlement with Northeast Radiology (April 4, 2025), a cybersecurity settlement with Vision Upright MRI (May 15, 2025), and a resolution agreement with Assured Imaging (December 5, 2025). Four imaging entities in roughly six years is a pattern, not a coincidence.

This guide covers why HIPAA applies to an imaging center, where P.H.I. (Protected Health Information) hides in a radiology workflow, the violations that recur in this setting, how to build the program, which vendors need a B.A.A. (Business Associate Agreement), and what the proposed Security Rule update would add.

HIPAA Compliance for Imaging Centers: Why the Rules Apply

45 CFR 160.103 defines a covered entity to include "a health care provider who transmits any health information in electronic form in connection with a transaction covered by this subchapter." The same section lists "health care claims or equivalent encounter information," "health care claim status," and "eligibility for a health plan" among those transactions. An imaging center that submits claims to a payer electronically, checks eligibility online, or receives electronic prior authorizations meets the test. Size is irrelevant. A single-scanner MRI suite that bills electronically is as covered as a hospital radiology department. The covered entity guide walks through the test in more detail.

One wrinkle is specific to imaging. 45 CFR 164.501 defines an indirect treatment relationship as one in which the provider "delivers health care to the individual based on the orders of another health care provider" and "typically provides services or products, or reports the diagnosis or results associated with the health care, directly to another health care provider." A freestanding center that registers the patient, performs the scan, and hands over a CD has a direct treatment relationship and must follow the notice rules for direct providers in 164.520(c)(2): provide the Notice of Privacy Practices "no later than the date of the first service delivery" and make a good faith effort to get a written acknowledgment. A teleradiology reading group that never meets the patient has an indirect relationship and different notice timing. Know which one describes each service line, because the front desk workflow depends on it.

What PHI Looks Like in an Imaging Center

Radiology PHI is unusually dense and unusually portable. The main places it lives:

  • DICOM image files. The header of each image carries patient name, date of birth, patient ID, accession number, referring physician, and study description. The image itself can carry burned-in text, common on ultrasound stills and older CT scout views. Sending the image sends the identifiers, whether or not anyone meant to.
  • PACS and RIS. The picture archiving system and the radiology information system hold the studies, the orders, the schedules, and the reports. Between them they are the designated record set.
  • Modality worklists. Each scanner pulls the day's schedule from the RIS. The console in the control room is a workstation under 164.310(b) and (c), and the scanner's own hard drive stores studies until they are purged.
  • Dictation and reports. Voice files, draft reports, addenda, and critical-results call logs.
  • Outbound media. CDs, USB drives, and image-sharing links given to patients and referring offices.
  • Inbound comparisons. Prior studies requested from other facilities, often arriving by fax cover sheet, portable media, or an outside portal.
  • Screening forms. MRI safety questionnaires, contrast allergy screens, pregnancy status, and implant cards. All PHI, all paper, all in the changing area.
  • Mobile units. A trailer-mounted MRI or CT that rotates between sites carries ePHI (electronic P.H.I.) across facility lines every week.

Common HIPAA Violations in Imaging Centers

Image servers reachable from the internet. The imaging breach pattern is one server, one configuration error, every study on it. That is why imaging breaches produce patient counts in the hundreds of thousands rather than the dozens. The Security Rule answer is the risk analysis required by 164.308(a)(1)(ii)(A), which must be "accurate and thorough" and cover every system holding ePHI, including the PACS, the web viewer, the VPN for the reading group, and the modality vendors' remote-service connections. The vulnerability scanning guide explains how to find the exposed ones.

The wrong CD, the wrong fax. A patient handed another patient's disc, or a report faxed to the wrong referring office, is a disclosure not permitted by the Privacy Rule and is presumed to be a breach under 164.402 unless a documented four-factor risk assessment shows a low probability of compromise. Two-identifier verification at handoff, and confirmed fax numbers stored in the RIS, are the cheap fixes.

Retired equipment that still remembers. Scanners, CD burners, and workstations get traded in or hauled away with studies still on their drives. 164.310(d)(2)(i) requires disposal procedures for "the hardware or electronic media on which it is stored," and 164.310(d)(2)(ii) requires ePHI to be removed "before the media are made available for re-use." Write the trade-in wipe into the purchase contract.

Shared console logins. A technologist account named after the room, used by everyone on the shift, defeats the unique user identification specification in 164.312(a)(2)(i), which is Required, and makes the audit controls standard in 164.312(b) meaningless because the log cannot say who looked.

Mobile units without device controls. 164.310(d)(1) requires policies governing "the receipt and removal of hardware and electronic media that contain electronic protected health information into and out of a facility." A mobile MRI trailer is exactly that. Track it, encrypt it, and purge it between sites.

Building the Program

Name the officials. 164.308(a)(2) requires a security official; 164.530(a)(1) requires a privacy official. In a small center one person holds both titles. Write the designation down.

Inventory first, then assess. The risk analysis is only as good as the asset list under it. List every modality, the PACS and RIS servers, the web viewer, the CD burner, the dictation system, the reading-room workstations, the mobile units, and every vendor with a remote connection. Then assess each for confidentiality, integrity, and availability risk, and treat the findings under 164.308(a)(1)(ii)(B). The risk assessment guide walks through the method.

Plan for the day PACS is down. 164.308(a)(7) requires a contingency plan with a data backup plan, a disaster recovery plan, and an emergency mode operation plan, all three Required. For an imaging center, emergency mode means reading from the modality console, printing or burning studies for the surgeon who is waiting, and keeping a paper log of every study performed so the RIS can be reconciled later. The contingency plan guide covers all five components.

Turn on the audit trail and read it. 164.312(b) requires mechanisms that "record and examine activity in information systems," and 164.308(a)(1)(ii)(D) requires regular review of those records. Reviewing PACS access logs monthly for after-hours lookups and self-lookups is the imaging version of that requirement.

Handle access requests correctly. Images are part of the medical record and therefore part of the designated record set. Under 164.524(b)(2), a request must be acted on within 30 days, with one extension of up to 30 days. Patients may ask for their images in the electronic form they request if it is readily producible. The right of access guide covers fees and denials.

Train for the workflow. Technologists, schedulers, and film library staff need training on the actual handoffs: CD verification, fax confirmation, screening-form storage, and what to say when a referring office calls asking for "everything on Mrs. Ortiz." 164.530(b)(1) requires training for "all members of its workforce," and the documentation of that training is what OCR asks to see.

Vendor BAA Checklist for Imaging Centers

45 CFR 160.103 defines a business associate as a person who "creates, receives, maintains, or transmits protected health information" on behalf of a covered entity, and 164.308(b) requires written satisfactory assurances before any of them touch ePHI. The same definition excludes "a health care provider, with respect to disclosures by a covered entity to the health care provider concerning the treatment of the individual," which matters for reading groups.

VendorBAA required?Note
PACS, RIS, and web viewer vendorYesHosted or on-premises with remote support, either way they reach ePHI
Modality service (field engineers with remote access)YesService logins reach studies stored on the scanner
Teleradiology reading groupUsually no for the reading itselfInterpretation is treatment. If the group also hosts or stores your studies, that hosting piece needs a BAA. Have counsel read the contract
Dictation and transcription serviceYesVoice files and draft reports are ePHI
Image-sharing portal or CD and USB media serviceYesThey transmit studies on your behalf
Billing company or clearinghouseYesBilling is named in the BA definition
IT managed service provider and cloud backupYesAdministrative access is access
Offsite film storage and shreddingYesThey maintain and destroy PHI for you
Answering serviceYesMessages about scheduled studies are PHI
Contrast and supply vendorsNoNo PHI changes hands

Keep the signed agreements in one register with dates, and review them annually. The BAA guide lists the terms 164.504(e)(2) requires.

The Proposed Security Rule Update

In January 2025 HHS published a proposed rule that would rewrite much of the Security Rule. It has not been finalized, OCR is not enforcing it, and nothing in it is required today. If adopted as proposed, it would require a written technology asset inventory and network map, encryption of ePHI at rest and in transit, multifactor authentication, automated vulnerability scans at least every six months, and penetration testing at least every 12 months. For an imaging center the asset inventory and network map would be the heavy lift, because the modality network is usually the least documented part of the building. Building that inventory now, as part of the current risk analysis, costs nothing extra, satisfies the rule in force today, and prepares the center for the proposed one. The Security Rule delay article tracks the timeline.

---

FAQ

Is an imaging center a covered entity under HIPAA?

Yes, if it transmits any health information electronically in connection with a standard transaction such as a claim, an eligibility check, or a prior authorization. 45 CFR 160.103 sets that test, and it has no size threshold.

Do DICOM images count as protected health information?

Yes. The DICOM header carries the patient's name, date of birth, patient ID, and accession number, and some images carry burned-in identifiers. A study is PHI in every format it takes: on the scanner, in PACS, on a CD, or in an email attachment.

Does a teleradiology reading group need a business associate agreement?

Usually not for the interpretation itself, because the business associate definition in 160.103 excludes disclosures to a health care provider for treatment. If the same group hosts, stores, or transmits your studies as a service, that function needs a BAA. Have counsel read the contract.

Can patients demand their images, not just the report?

Yes. Images are part of the designated record set. Under 164.524 the center must act on the request within 30 days, with one extension of up to 30 days, and provide the copy in the electronic form requested if it is readily producible.

Is encrypting the PACS required?

Under the current Security Rule, encryption is an Addressable specification at 164.312(a)(2)(iv), which means it must be implemented if reasonable and appropriate, or the decision not to must be documented with an equivalent alternative. The proposed 2025 update would make encryption required, but that rule is not final.

Conclusion

An imaging center's HIPAA program is mostly an inventory problem: every modality, server, and vendor with a path to a study, written down and risk-assessed. One Guy Consulting's Full-Scope plan covers the risk analysis, the policies, the vendor and B.A.A. register, and workforce training, with consulting time to walk the reading room and the mobile unit. Start with a free 30-minute compliance review. No obligation, no pressure.

Sources


Related Reading