HIPAA Compliance for Dermatology Practices: Clinical Photos and Teledermatology

What sets dermatology apart from most specialties under HIPAA is the sheer volume of clinical photography. Dermatologists document lesions, rashes, moles, and surgical sites constantly, and those images are protected health information the moment they can be tied to a patient. Add the rise of teledermatology, where patients text or upload photos of their skin from home, and you have a specialty whose core workflow generates ePHI on phones, tablets, and personal devices, often outside any formal system. That is where dermatology compliance risk concentrates.

Clinical Photos Are PHI, Even on a Phone

A photo of a patient’s skin condition is PHI when it is linked to identifying information, and dermatologic images frequently include identifying features such as faces, tattoos, or distinctive markings. The common failure point is the camera roll: a clinician snaps a photo on a personal phone, it syncs to a consumer cloud backup, and now ePHI sits in an environment with no business associate agreement and no access controls. Compliant photography means capturing images directly into the EHR or a dedicated, encrypted clinical imaging app, never the device’s default camera, and ensuring images are not retained on personal devices or synced to unmanaged cloud accounts.

Teledermatology and Patient-Submitted Images

Store-and-forward teledermatology, where patients submit photos for later review, is convenient but raises specific issues. Patients texting images to a clinician’s personal phone, or emailing them unencrypted, creates ePHI in insecure channels. Practices should route patient-submitted images through a secure patient portal or a HIPAA-eligible telehealth platform covered by a business associate agreement, obtain appropriate consent, and train staff never to accept clinical photos over ordinary SMS or personal email. Live video teledermatology visits should run on platforms that offer a BAA and encryption.

Start With a Security Risk Analysis

Because dermatology ePHI scatters across cameras, phones, imaging apps, the EHR, and telehealth tools, a Security Risk Analysis is the only reliable way to see the full picture. The SRA, required of every covered entity under 45 CFR § 164.308(a)(1)(ii)(A), forces you to inventory every place clinical images are captured, transmitted, and stored, evaluate the threats to each, and document remediation. For a dermatology practice the analysis almost always surfaces unmanaged photo storage as a top risk. Pairing the SRA with a thorough HIPAA compliance checklist helps confirm nothing is missed.

The Proposed 2026 Security Rule Update

The Notice of Proposed Rulemaking that OCR published in December 2024 would tighten requirements that matter directly to image-heavy specialties. It proposes making encryption, multi-factor authentication, and mobile-device controls effectively mandatory rather than addressable, which would raise expectations for how clinical photos on phones and tablets are protected. The NPRM is a proposal, not final law, and organizations would have a 240-day compliance window once a final rule is published. Dermatology practices that lock down mobile imaging now will be well positioned. Our HIPAA risk assessment guide covers how to document these controls.

How Medcurity Helps

Medcurity guides dermatology practices through the Security Risk Analysis, helping you map where clinical images and other ePHI are captured and stored, identify gaps in mobile and cloud handling, and track remediation in an audit-ready format. Pricing is $499/year (about $42/month) for a single practice; larger or multi-location groups can request a quote.

Frequently Asked Questions

Are clinical photos of skin conditions considered PHI?

Yes, whenever the image can be linked to a patient. Dermatologic photos often include identifying features, so they should be treated as protected health information and stored in secured, access-controlled systems.

Can a dermatologist take patient photos on a personal phone?

Only if images are captured into a secure, encrypted clinical app and never stored in the device’s camera roll or synced to a personal cloud account. The safest practice is to capture directly into the EHR or a dedicated imaging tool covered by a business associate agreement.

How should patients send photos for teledermatology?

Through a secure patient portal or a HIPAA-eligible telehealth platform covered by a business associate agreement, not ordinary text message or personal email, which are not secure channels for ePHI.

Do we need a BAA for our teledermatology platform?

Yes. Any vendor that stores or transmits ePHI on your behalf, including a teledermatology or image-hosting platform, is a business associate and must sign a business associate agreement before you use it.