Medcurity Get Compliant Now

HIPAA for Optometrists: Eye Care Compliance Guide

Last updated: March 2026 | 10 min read

Quick Answer

Optometrists are covered entities under HIPAA if they bill insurance, Medicare, Medicaid, or use electronic health records. Most optometry practices bill vision insurance, making HIPAA compliance mandatory. Key requirements include Notice of Privacy Practices, secure EHR systems, patient prescriptions rights, secure storage of digital eye images, written policies, Business Associate Agreements with vendors, and breach notification procedures.

HIPAA Coverage for Optometric Practices

When HIPAA Applies to Optometrists

HIPAA requirements apply to optometric practices if they:

• Bill vision insurance (most common)
• Bill medical insurance for eye conditions
• Bill Medicare or Medicaid
• Maintain electronic health records (EHR software)
• Transmit patient information electronically
• Maintain any digital patient records

Solo Optometrist Practices

Solo optometrists are covered entities under HIPAA if they meet any of the criteria above. Even a solo practice with one employee must comply with full HIPAA requirements including designated Privacy Officer responsibilities.

Retail and Corporate Optometry

Optometrists employed by retail chains or optical companies:

• Must ensure the employer maintains HIPAA compliance
• Must understand their role in patient privacy
• Should verify that Business Associate Agreements are in place

Cash-Only Optometry Practices

Even optometry practices operating on a cash-only basis are likely subject to HIPAA because:

• Using any electronic records triggers HIPAA
• Many patients submit to insurance themselves (creating disclosure)
• Most optometrists will eventually bill some insurance

Protected Health Information in Optometry

What Information Must Be Protected

All of the following patient information must be protected under HIPAA:

• Refraction results (sphere, cylinder, axis, add)
• Visual acuity measurements
• Glasses and contact lens prescriptions
• Eye pressure readings and glaucoma testing
• Fundus photographs and images
• OCT (optical coherence tomography) scans
• Visual field testing results
• Corneal topography data
• A-scan measurements for intraocular lens calculations
• Contact lens fitting information
• Medical history related to eye health
• Insurance information and billing records
• Names, addresses, phone numbers, and email addresses

Patient Right to Prescriptions

Patients have an absolute right to their prescriptions. Under HIPAA and state laws:

• You must provide prescriptions at the conclusion of the eye exam
• You cannot withhold prescriptions or use them as leverage
• Charges for prescription copies must be reasonable (typically $5-10)
• You cannot charge for the initial prescription given at visit
• You cannot require prescriptions be filled at your optical shop
• Patients can use prescriptions at any optical retailer

Contact Lens-Specific Information

Contact lens information is particularly sensitive:

• Patients must receive the CL prescription at the conclusion of a successful fit
• Cannot require patients to buy contact lenses from your practice
• Must disclose base curve, diameter, brand, and power
• Fitting data and follow-up notes are PHI and must be protected

Digital Imaging and OCT Scan Protection

Storing Digital Eye Images

Fundus photographs, OCT scans, and other digital images must be:

• Stored on encrypted servers or drives
• Accessible only to authorized optometrists and staff
• Backed up regularly with encryption
• Deleted securely after retention periods
• Subject to audit logs tracking access

Transferring Images to Other Providers

When optometrists refer to ophthalmologists or other providers:

• Obtain written patient authorization before transferring
• Use secure methods (encrypted email, secure portal, hand delivery)
• Do not transfer via unencrypted email or unsecured file sharing
• Document who received the images, when, and via what method
• Can restrict use (e.g., "for diagnosis only")

Patient Request for Images

Patients have the right to copies of their images:

• Provide within 30 calendar days of request
• Provide in requested format (digital, printed, etc.)
• Can charge reasonable copying costs
• Include all images from the requested date range

Privacy and Security for Optometric Practices

Notice of Privacy Practices

Optometrists must provide written Notice of Privacy Practices explaining:

• How patient eye care information is used and disclosed
• Patient rights (access to records, amendments, accounting of disclosures)
• Practice contact information for privacy questions
• How patients can file complaints
• Right to receive prescriptions

Permitted Disclosures Without Consent

Patient information can be disclosed without authorization for:

• Treatment (referrals to ophthalmologists, opticians, etc.)
• Payment (billing insurance, collections)
• Healthcare operations (scheduling, staff training, quality improvement)

Disclosures Requiring Written Authorization

Must obtain written consent before disclosing to:

• Employers or workplace wellness programs
• Law enforcement (unless legally required)
• Attorneys or insurance companies for claims
• Family members
• Other unrelated third parties

Workplace Vision Screenings

If conducting workplace vision screenings or occupational assessments:

• Obtain written authorization from the employee
• Maintain separate records from occupational health records
• Clarify what information will be disclosed to the employer
• Only disclose information authorized by the employee

Business Associates in Optometry

Common Business Associates

Business Associate Agreements must be in place with:

• EHR software vendors
• Practice management software providers
• Insurance billing companies
• Cloud storage and backup providers
• IT support and managed service providers
• Answering services and appointment schedulers
• Vision insurance clearinghouses

Retail Optical Shop Considerations

If your practice has an affiliated optical shop:

• Execute a BAA if the shop accesses EHR records
• Maintain separate access controls for optical staff
• Train optical staff on HIPAA confidentiality
• Limit optical staff access to necessary prescriptions only

Frequently Asked Questions

Can I send eye exam results via email?

Only via encrypted email. Never send refraction results, visual acuity, images, or any eye exam information via unencrypted email. Use secure patient portals, encrypted email services, or have patients call for results. If a patient requests email delivery, use encrypted methods and confirm they understand the security limitations.

What if a patient loses their glasses/contacts and claims they left them at my office?

You can only discuss their specific order/records with them directly. Do not discuss patient orders or prescriptions with anyone else without authorization. If someone claims a patient sent them, request written authorization from the patient before discussing anything. Keep records of all transactions.

How long should I keep patient records and eye images?

Recommended minimum is 5 years from last visit for adults. For minors, retain until age of majority plus 5-7 years. Check your state's optometry board regulations. Some practices maintain records longer to defend against malpractice claims. Digital images require secure deletion after retention period (not just file deletion).

Can I use patient photos in my marketing?

No, without written authorization. Even if the patient consents verbally, get it in writing. The authorization should specify how the image will be used (website, social media, etc.). Never use patient eye images (fundus photos, OCT) for marketing without explicit written consent and HIPAA compliance.

Secure Your Optometry Practice with HIPAA Compliance

Optometry practices handle sensitive visual health information and must manage prescriptions, digital images, and insurance billing securely. Medcurity helps optometrists implement compliant EHR systems, secure image storage, and proper procedures for prescription management and patient records access.

Get Your Practice Compliant Now