Free Security Risk Analysis

HIPAA Compliance Checklist for Plastic Surgery

Protect patient privacy in cosmetic and reconstructive surgery with our comprehensive HIPAA checklist covering before/after photography, cosmetic vs reconstructive documentation, patient consent, and social media security.

Quick Answer
A HIPAA-compliant plastic surgery practice must encrypt before/after photos and imaging, obtain explicit documented consent for all photography, implement segregated storage systems, maintain strict social media policies, distinguish cosmetic vs reconstructive documentation, and implement audit logging for all photo access. Photos without patient consent cannot be used for any purpose.

Patient Photography & Documentation Security

Obtain explicit written consent for all patient photography
Document informed consent for before/after photos specifying intended use (clinical, marketing, research, education).
High Priority
Encrypt all before/after photos and imaging files
Store surgery photos with encryption at rest and in transit using AES-256. Restrict access to authorized personnel only.
High Priority
Implement segregated photo storage systems
Maintain separate encrypted databases for clinical photos vs marketing/social media photos with different access controls.
High Priority
Maintain audit logs for all photo access
Track all access to patient photos with timestamp, user ID, and intended use. Review logs monthly for unauthorized access.
High Priority
De-identify or obscure facial features in marketing photos
When using patient photos for marketing or social media, blur facial features or use identifying consent from patients. Ensure photos cannot identify patient.
High Priority
Distinguish cosmetic vs reconstructive surgery documentation
Clearly document whether procedures are cosmetic or reconstructive as this affects insurance coverage and documentation requirements.
High Priority
Implement secure social media policies
Document clear policies prohibiting staff from posting patient photos, information, or identifying comments on personal social media accounts.
High Priority
Secure before/after photography workflows
Ensure photography capture systems, storage devices, and transfer methods use encryption and secure protocols.
High Priority
Implement role-based access to surgical photography
Restrict access to before/after photos to treating surgeon, surgical staff, and authorized clinical personnel only.
High Priority
Manage consent revocation requests
Establish procedures for patients to revoke photo consent at any time. Remove all photos from marketing/social media upon revocation.
High Priority
Protect photos of minors with extra care
Require parental/guardian written consent for all photos of patients under 18. Store separately with enhanced access restrictions.
High Priority
Conduct HIPAA training on patient photography
Provide annual training on photography consent requirements, de-identification, social media policies, and secure photo handling.
High Priority
Implement secure backup and retention of photos
Regularly backup encrypted photo data and test restoration. Document retention period and secure deletion procedures.
High Priority
Monitor third-party use of practice photos
Verify that before/after photos used by vendors, medical spas, or partners have proper patient consent. Audit their security practices.
Medium Priority
Document cosmetic vs reconstructive classifications
Clearly document whether each procedure is cosmetic, reconstructive, or both in the medical record with supporting rationale.
Medium Priority

Common HIPAA Violations in Plastic Surgery

Frequently Asked Questions

Can we use before/after photos without patient consent? +
No. Before/after photos are considered PHI and cannot be used for any purpose without explicit written patient consent. Consent must be specific to each intended use (clinical record, marketing, social media, publications, etc.). Generic consent is insufficient. If a patient refuses consent, do not take or store photos.
How do we properly de-identify patient photos for marketing? +
To de-identify photos, blur or pixelate the face and any identifying marks, tattoos, or unique features. Remove identifying metadata from image files. Ensure the photo cannot reasonably be used to identify the individual. Even with de-identification, it's best practice to obtain consent. Keep a record of which original consent applies to which photo.
What should we do if a patient requests their photos be removed? +
Patients can revoke consent to use their photos at any time. You must remove the photos from your website, social media, marketing materials, and any other public use immediately. However, you may retain a copy in the clinical record for medical purposes. Document the date of the revocation request.
Are there different rules for cosmetic vs reconstructive surgery photos? +
HIPAA requirements are the same for both, but documentation and insurance coverage differ. Reconstructive surgery may be covered by insurance, while cosmetic is typically not. Some patients may be uncomfortable having cosmetic surgery photos used in marketing, so be especially careful about consent and de-identification for cosmetic cases.

Secure Your Plastic Surgery Practice

Medcurity helps plastic surgery practices ensure HIPAA compliance with patient photography, consent management, and secure data handling.

Get Your Free Security Analysis