{"id":2551,"date":"2026-08-08T01:46:11","date_gmt":"2026-08-07T22:46:11","guid":{"rendered":"https:\/\/picajet.com\/articles\/glossary\/hipaa-compliance-imaging\/"},"modified":"2026-08-08T03:45:54","modified_gmt":"2026-08-08T00:45:54","slug":"hipaa-compliance-imaging","status":"publish","type":"glossary","link":"https:\/\/picajet.com\/articles\/glossary\/hipaa-compliance-imaging\/","title":{"rendered":"HIPAA compliance (imaging)"},"content":{"rendered":"<p class=\"wp-block-paragraph\">HIPAA imaging compliance in a DAM context starts from a fact healthcare marketing and clinical teams sometimes miss: a photograph is Protected Health Information the moment it identifies an individual and relates to their health care or payment for it. Identification doesn&#8217;t require a clearly visible face \u2014 a distinctive tattoo, a scar, a wristband, a visible room number, or other context in the frame can be enough to make a photo PHI even when it&#8217;s cropped to avoid showing someone&#8217;s face directly.<\/p>\n<p class=\"wp-block-paragraph\">Once an image is PHI, storing it anywhere requires a Business Associate Agreement between the covered entity (the clinic, hospital, or medical device company) and the DAM vendor. This is a legal contract, not a technical certification: it defines permitted uses and disclosures of the images, requires the vendor to meet HIPAA Security Rule safeguards, sets breach notification obligations, and binds any subcontractor the vendor uses. Critically, an entity that merely maintains ePHI on a covered entity&#8217;s behalf is a business associate under HIPAA even if it never actually accesses the content \u2014 so a DAM vendor storing encrypted clinical photos it can&#8217;t itself view still needs a signed BAA before those images can legally live on its platform.<\/p>\n<p class=\"wp-block-paragraph\">The practical failure mode is using tools that were never built for this: personal smartphone camera rolls, standard consumer iCloud accounts, free Google Drive, or personal Dropbox are explicitly non-compliant for storing patient photos, because none of those vendors will sign a BAA. For a DAM specifically, that means healthcare and medical-device customers need a plan or tier that offers a BAA outright, with encryption in transit and at rest as a baseline expectation layered on top of \u2014 not a substitute for \u2014 that contractual coverage.<\/p>","protected":false},"excerpt":{"rendered":"<p>Storing and managing medical photos, clinical images, or scans in a DAM only under a signed Business Associate Agreement, with the safeguards HIPAA&#8217;s Security Rule requires for Protected Health Information.<\/p>\n","protected":false},"author":0,"featured_media":0,"template":"","meta":{"footnotes":"","faq":[{"question":"When does a patient photo become Protected Health Information?","answer":"The moment it's identifiable \u2014 a visible face, a distinctive tattoo or scar, a wristband or room number in frame \u2014 and tied to health or payment context."},{"question":"What legal document makes it lawful for a DAM to store clinical images?","answer":"A signed Business Associate Agreement (BAA) between the covered entity and the DAM vendor, not just the vendor's technical security features."},{"question":"Does a DAM vendor need a BAA even if it never views the images?","answer":"Yes \u2014 an entity that merely maintains ePHI on a covered entity's behalf is a business associate under HIPAA even if it never actually accesses the content."},{"question":"What tools are explicitly non-compliant for storing patient photos?","answer":"Consumer-grade tools like a personal smartphone camera roll, standard iCloud, or free Google Drive \u2014 none of which will sign a BAA."},{"question":"What's the most common mistake with clinical images in a DAM?","answer":"Storing patient before\/after or wound-care photos in a general marketing DAM plan or personal cloud library \"for internal reference\" without confirming the vendor will sign a BAA."},{"question":"What should healthcare DAM buyers look for beyond a BAA?","answer":"Encryption in transit and at rest as a baseline expectation layered on top of, not a substitute for, the contractual BAA coverage."}],"checked_date":"2026-08-07","sources":[{"statement":"A patient photograph is PHI when it identifies an individual \u2014 including via less obvious cues such as tattoos, scars, wristbands, or room numbers \u2014 and relates to health care or payment; consumer tools like personal iCloud or free Google Drive are not HIPAA-compliant storage for patient photos.","source_name":"HIPAA Journal \u2014 HIPAA Photography Rules, 2026 update","url":"https:\/\/www.hipaajournal.com\/hipaa-photography-rules\/","checked":"2026-08-07"},{"statement":"An entity that maintains ePHI on behalf of a covered entity is a business associate under HIPAA, even if it cannot actually view the ePHI, and must sign a Business Associate Agreement.","source_name":"U.S. Department of Health and Human Services \u2014 Business Associates","url":"https:\/\/www.hhs.gov\/hipaa\/for-professionals\/privacy\/guidance\/business-associates\/index.html","checked":"2026-08-07"}],"kicker":"","fact_checker":0,"reading_time":0,"revisions":[],"seo_title":"","seo_description":"","noindex":false,"related":[2492,2585,2553,2491,2578,2550],"definition":"Storing and managing medical photos, clinical images, or scans in a DAM only under a signed Business Associate Agreement, with the safeguards HIPAA's Security Rule requires for Protected Health Information.","why":"A patient photo counts as Protected Health Information the moment it's identifiable \u2014 a visible face, a distinctive tattoo or scar, a wristband or room number in frame \u2014 and is tied to health or payment context, so a before\/after clinical photo or wound-care image stored in an ordinary DAM plan is a HIPAA violation regardless of how well the vendor encrypts its infrastructure. The BAA is the legal instrument that makes storage lawful, not a technical feature: an entity that merely maintains ePHI on a covered entity's behalf is a business associate under HIPAA even if it never actually views the images, which means the DAM vendor itself has to sign one before any clinical photo can legally sit on its platform.","example_rows":[{"field":"PHI trigger","values":"Identifiable face, tattoo, scar, wristband, or room number visible in a clinical photo, tied to health\/payment context"},{"field":"Legal requirement","values":"Signed Business Associate Agreement with the DAM vendor before storing any such image, regardless of vendor encryption claims"},{"field":"Non-compliant pattern","values":"Consumer-grade tools \u2014 personal smartphone camera roll, standard iCloud, free Google Drive \u2014 used for patient photos"}],"mistake":"Storing patient before\/after or wound-care photos in a general marketing DAM plan, personal cloud photo library, or messaging app \"just for internal reference,\" without confirming the vendor will sign a BAA \u2014 treating clinical images as ordinary marketing content instead of regulated PHI.","deep_link":""},"silo":[24],"class_list":["post-2551","glossary","type-glossary","status-publish","hentry","silo-glossary"],"_links":{"self":[{"href":"https:\/\/picajet.com\/articles\/wp-json\/wp\/v2\/glossary\/2551","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/picajet.com\/articles\/wp-json\/wp\/v2\/glossary"}],"about":[{"href":"https:\/\/picajet.com\/articles\/wp-json\/wp\/v2\/types\/glossary"}],"version-history":[{"count":3,"href":"https:\/\/picajet.com\/articles\/wp-json\/wp\/v2\/glossary\/2551\/revisions"}],"predecessor-version":[{"id":3536,"href":"https:\/\/picajet.com\/articles\/wp-json\/wp\/v2\/glossary\/2551\/revisions\/3536"}],"wp:attachment":[{"href":"https:\/\/picajet.com\/articles\/wp-json\/wp\/v2\/media?parent=2551"}],"wp:term":[{"taxonomy":"silo","embeddable":true,"href":"https:\/\/picajet.com\/articles\/wp-json\/wp\/v2\/silo?post=2551"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}