PicaJet

Reference Glossary

HIPAA compliance (imaging)

Storing and managing medical photos, clinical images, or scans in a DAM only under a signed Business Associate Agreement, with the safeguards HIPAA's Security Rule requires for Protected Health Information.

Why it matters in a DAM

A patient photo counts as Protected Health Information the moment it's identifiable — a visible face, a distinctive tattoo or scar, a wristband or room number in frame — and is tied to health or payment context, so a before/after clinical photo or wound-care image stored in an ordinary DAM plan is a HIPAA violation regardless of how well the vendor encrypts its infrastructure. The BAA is the legal instrument that makes storage lawful, not a technical feature: an entity that merely maintains ePHI on a covered entity's behalf is a business associate under HIPAA even if it never actually views the images, which means the DAM vendor itself has to sign one before any clinical photo can legally sit on its platform.

A worked example

PHI trigger Identifiable face, tattoo, scar, wristband, or room number visible in a clinical photo, tied to health/payment context
Legal requirement Signed Business Associate Agreement with the DAM vendor before storing any such image, regardless of vendor encryption claims
Non-compliant pattern Consumer-grade tools — personal smartphone camera roll, standard iCloud, free Google Drive — used for patient photos

Common mistake

Storing patient before/after or wound-care photos in a general marketing DAM plan, personal cloud photo library, or messaging app "just for internal reference," without confirming the vendor will sign a BAA — treating clinical images as ordinary marketing content instead of regulated PHI.

HIPAA imaging compliance in a DAM context starts from a fact healthcare marketing and clinical teams sometimes miss: a photograph is Protected Health Information the moment it identifies an individual and relates to their health care or payment for it. Identification doesn’t require a clearly visible face — a distinctive tattoo, a scar, a wristband, a visible room number, or other context in the frame can be enough to make a photo PHI even when it’s cropped to avoid showing someone’s face directly.

Once an image is PHI, storing it anywhere requires a Business Associate Agreement between the covered entity (the clinic, hospital, or medical device company) and the DAM vendor. This is a legal contract, not a technical certification: it defines permitted uses and disclosures of the images, requires the vendor to meet HIPAA Security Rule safeguards, sets breach notification obligations, and binds any subcontractor the vendor uses. Critically, an entity that merely maintains ePHI on a covered entity’s behalf is a business associate under HIPAA even if it never actually accesses the content — so a DAM vendor storing encrypted clinical photos it can’t itself view still needs a signed BAA before those images can legally live on its platform.

The practical failure mode is using tools that were never built for this: personal smartphone camera rolls, standard consumer iCloud accounts, free Google Drive, or personal Dropbox are explicitly non-compliant for storing patient photos, because none of those vendors will sign a BAA. For a DAM specifically, that means healthcare and medical-device customers need a plan or tier that offers a BAA outright, with encryption in transit and at rest as a baseline expectation layered on top of — not a substitute for — that contractual coverage.

Frequently asked

When does a patient photo become Protected Health Information?

The moment it's identifiable — a visible face, a distinctive tattoo or scar, a wristband or room number in frame — and tied to health or payment context.

What legal document makes it lawful for a DAM to store clinical images?

A signed Business Associate Agreement (BAA) between the covered entity and the DAM vendor, not just the vendor's technical security features.

Does a DAM vendor need a BAA even if it never views the images?

Yes — an entity that merely maintains ePHI on a covered entity's behalf is a business associate under HIPAA even if it never actually accesses the content.

What tools are explicitly non-compliant for storing patient photos?

Consumer-grade tools like a personal smartphone camera roll, standard iCloud, or free Google Drive — none of which will sign a BAA.

What's the most common mistake with clinical images in a DAM?

Storing patient before/after or wound-care photos in a general marketing DAM plan or personal cloud library "for internal reference" without confirming the vendor will sign a BAA.

What should healthcare DAM buyers look for beyond a BAA?

Encryption in transit and at rest as a baseline expectation layered on top of, not a substitute for, the contractual BAA coverage.

Sources

  • A patient photograph is PHI when it identifies an individual — including via less obvious cues such as tattoos, scars, wristbands, or room numbers — and relates to health care or payment; consumer tools like personal iCloud or free Google Drive are not HIPAA-compliant storage for patient photos. checked 2026-08-07HIPAA Journal — HIPAA Photography Rules, 2026 update
  • An entity that maintains ePHI on behalf of a covered entity is a business associate under HIPAA, even if it cannot actually view the ePHI, and must sign a Business Associate Agreement. checked 2026-08-07U.S. Department of Health and Human Services — Business Associates