Tread Carefully With Patient Images and Personal Devices
Question: A provider takes a clinical photo of a patient’s forearm rash on a personal smartphone to document its progression. The image does not show the patient’s face, but a tattoo is visible. Later, the physician wants to use the photo in a staff presentation. Would the use of the image in an in-office presentation require authorization from the patient California Subscriber Answer: The image should be treated as protected health information (PHI) if it relates to the patient’s care and could identify the patient. How the image would be used determines whether authorization is required. First of all, a forearm may seem anonymous, but a full-face image is not required for identifiability. According to HIPAA’s de-identification standard, “full-face photographic images and any comparable images,” as well as “any other unique identifying number, characteristic, or code,” must be removed to de-identify the image. A tattoo, especially if it’s distinctive, can be considered an identifying characteristic. If the photo is taken and used for clinical documentation, the use may be permissible for treatment or healthcare operations without separate patient authorization, but you should check your specific situation, considering all the facts, against the Department of Health & Human Services’ (HHS’) guidance on treatment, payment, and health care operations. Generally, if a provider wants to use an image that hasn’t been properly de-identified in a context outside of permitted treatment, payment, or operations, or in any situation not covered by HIPAA’s permitted uses of PHI, then the patient’s authorization is required. Additionally, the provider’s use of their personal smartphone creates its own privacy and security compliance risks. A compliance best practice would be requiring providers to use organization-approved devices or secure applications, with rules about prompt uploading of the image/file to the designated medical record, restricted access of the content, and making sure the photo isn’t saved to the physician’s personal photo library. If those policies don’t already exist for your organization, consider establishing personal device policies that reflect device usage. Rachel Dorrell, MA, MS, CPC-A, CPPM, Production Editor, AAPC
