TL;DR

Patient images and videos become protected health information the moment they include identifiable details and relate to someone’s care. Protecting them requires written authorization for non-treatment uses, encryption at rest and in transit, Business Associate Agreements with every platform that touches the files, and ongoing staff training. Get it wrong, and you face fines up to $2.19 million per violation category, plus potential criminal charges.

Why This Glossary Exists

Healthcare data breaches more than doubled in 2025, with total breach volume surpassing the previous year by 112%. The average cost of a single healthcare breach now sits around $7 million. Meanwhile, a Los Angeles physical therapy clinic paid $25,000 just for posting patient testimonials with names and photos on its website, with a corrective action plan and annual compliance reporting on top of that.

If you’re a PT, OT, SLP, chiropractor, or clinic owner who records exercise demos, texts clinical photos, or posts patient progress on Instagram, this is the reference you need. Every term below is defined in plain language with a practical takeaway tied to real rehab workflows.

Explore HIPAA-compliant tools built for physical therapists.

Use the glossary alphabetically. Jump to any term, get the definition, and walk away knowing what it means for your clinic.


A–Z Glossary of Key Terms

Access Controls

Technical restrictions that limit who can view, edit, or share patient images within a system. Examples include role-based permissions (front desk sees scheduling, only clinicians see clinical photos), unique user IDs, and automatic logoff after inactivity.

In practice: If your clinic stores exercise videos on a shared tablet, every clinician should log in with their own credentials. A shared “clinic login” means you can’t track who accessed what, which is exactly what auditors look for.

Authorization (HIPAA)

A written, signed document from a patient granting permission to use their images or videos for purposes beyond treatment, payment, or healthcare operations. Authorization must specify what information will be used, who will receive it, the purpose, and an expiration date.

This is not the same as the general consent form patients sign at intake. A general treatment consent may not cover photography, so a specific form is required for image and video uses outside direct care.

Why it matters: Want to post a patient’s shoulder rehab progress on your clinic’s Instagram? You need a separate, signed authorization, not just a verbal “sure, go ahead.” Patients can also revoke authorization at any time, which is why posting to social media carries permanent risk: you can’t fully retract something the internet has already cached.

Breach Notification Rule

The HIPAA requirement that covered entities report unauthorized disclosures of unsecured PHI. If a staff member’s phone with unencrypted patient photos gets lost or stolen, this rule kicks in. Notifications must go to affected patients, HHS, and (for breaches affecting 500+ people) the media.

In practice: Practitioners on Reddit describe scenarios where a lost personal phone used for work holds patient photos and messages. If the data was unencrypted or accessible, the probability of compromise is high, triggering breach notification obligations.

Business Associate Agreement (BAA)

A legally required contract between a covered entity (your clinic) and any vendor that creates, receives, stores, or transmits ePHI on your behalf. Without a BAA in place, sharing PHI with a vendor is a HIPAA violation, regardless of how responsibly the vendor handles the data.

Why it matters: Many small clinics upload patient exercise videos to Google Drive, Dropbox, or Vimeo without a BAA. Even if the files are encrypted, the vendor has “persistent access” to the data, and that alone requires an agreement. Before you store a single patient image on any platform, confirm the vendor will sign a BAA. This applies to cloud storage, video hosting, messaging apps, and even your website host if patient testimonials live there.

Consent vs. Authorization

Two concepts that sound similar but carry very different legal weight. Consent is broad permission for treatment (the form patients sign at check-in). Authorization is specific, written permission for a defined use of PHI, such as posting a video on social media or using a photo in a conference presentation.

Most photo and video uses outside treatment, payment, and healthcare operations require authorization. Sending a patient their own exercise video through a HIPAA-secure messaging app for home practice generally falls under treatment. Reusing that same video in a marketing email does not.

Understanding the distinction matters for patient literacy too. If patients don’t understand what they’re signing, the authorization may not hold up under scrutiny.

Covered Entity

A healthcare provider, health plan, or healthcare clearinghouse that transmits any health information electronically. PT clinics, chiropractic offices, SLP practices, OT clinics, and solo mobile therapists who bill electronically all qualify.

In practice: If you’re a covered entity, every rule in this glossary applies to you. There is no small-practice exemption.

De-identification

The process of removing all 18 HIPAA identifiers from patient data so it no longer qualifies as PHI. One of those 18 identifiers is “full-face photographic images and any comparable images.” Others include names, dates, geographic data, and any unique identifying number, characteristic, or code.

Critical detail: Blurring a patient’s face in the background of a photo is not enough. If patients appear in even the distant background and haven’t signed a media release, you’ve technically violated HIPAA. Blurring still leaves them technically identifiable. The safe approach is to reshoot or crop them out entirely.

Designated Record Set

The group of records a covered entity uses to make decisions about patients. When clinical photos or exercise videos become part of this set (attached to a chart, referenced in treatment notes), they receive full HIPAA protections, including the patient’s right to access, amend, and request restrictions on their use.

In practice: If you record a patient performing a squat assessment and save it alongside their treatment plan, that video is part of the designated record set. It must be stored, secured, and retained according to HIPAA and state record-retention laws.

Encryption (At Rest and In Transit)

The process of rendering ePHI unreadable without a decryption key. “At rest” means stored data (on a server, phone, or hard drive). “In transit” means data being sent (over email, messaging, or file transfer). The standard benchmarks are AES-256 encryption for data at rest and TLS 1.2 or 1.3 for data in transit.

Currently, encryption is classified as “addressable” under the HIPAA Security Rule, but the word “addressable” does not mean optional. HHS has proposed removing the addressable distinction entirely in its 2026 Security Rule update, which would make encryption flatly mandatory with limited exceptions. If your clinic hasn’t encrypted stored patient images yet, now is the time, not after the rule change.

For clinics evaluating physical therapy technology, encryption capability should be the first checkbox, not an afterthought.

ePHI (Electronic Protected Health Information)

Any PHI created, received, maintained, or transmitted electronically. Patient exercise videos on a phone, clinical photos in cloud storage, DICOM files on an imaging server, and even the EXIF metadata embedded in a digital image all qualify as ePHI when they contain identifiable information tied to care.

In practice: The moment you record a patient on your smartphone, that file is ePHI. It doesn’t matter whether you intended it for the medical record or just wanted to show the patient their form. If it’s identifiable and relates to their health condition, it’s protected.

EXIF Data / Metadata

Information automatically embedded in digital image and video files by the device that captured them. This typically includes GPS coordinates, timestamps, device serial numbers, and sometimes the user’s name. EXIF data can turn an otherwise anonymous clinical photo into identifiable PHI, even if the patient’s face is cropped out.

Why it matters: Imagine you photograph a patient’s knee post-surgery, carefully framing to exclude their face. The photo’s metadata still records the exact GPS location (your clinic), the exact time, and your phone’s serial number. Cross-referenced with an appointment schedule, that photo identifies the patient. Before sharing any clinical image externally, strip the EXIF data. Most operating systems and free tools can do this in seconds.

Full-Face Photographic Image

One of HIPAA’s 18 identifiers under the Safe Harbor de-identification method. It includes any image where a patient’s face is recognizable, even partially visible in a frame’s background. Comparable images (like profile silhouettes or distinctive scars visible in a photo) also count.

In practice: If you record an exercise demo and another patient walks through the background, that clip now contains a full-face photographic image of someone who didn’t consent. Reshoot in a private area or review footage before sharing.

HIPAA Privacy Rule

The federal rule governing when and how PHI can be used and disclosed. It establishes patients’ rights to consent, access their records, revoke authorization, and request restrictions on how their information is shared. Under this rule, workforce members can take photos and videos of patients only for uses permitted by the Privacy Rule. Any other purpose requires written authorization.

HIPAA Security Rule

The federal rule requiring administrative, physical, and technical safeguards for all ePHI. It applies to every electronic patient image and video your clinic creates, receives, or stores. The proposed 2026 update, the first major rewrite since 2013, would make encryption, multi-factor authentication, annual penetration tests, network segmentation, and semiannual vulnerability scans all mandatory.

Between 2018 and 2023, large breaches reported to HHS grew 100%, and breaches from hacking grew 260%. The rule update is a direct response to that escalation.

Minimum Necessary Standard

The principle that only the least amount of PHI needed for a specific task should be used or disclosed. For clinical photography, this means capturing only what’s clinically essential, cropping identifiers out of the frame, and restricting who the image is shared with.

In practice: You’re documenting a patient’s gait pattern. You don’t need their face in the frame. Shoot from the waist down if that’s sufficient for the clinical purpose.

Multi-Factor Authentication (MFA)

A security measure requiring two or more verification methods (password plus a code sent to your phone, for example) to access systems containing ePHI. The proposed 2026 HIPAA Security Rule update would make MFA mandatory for all systems handling patient data.

In practice: If your cloud storage, HEP app, or EHR doesn’t support MFA, that’s a red flag. Enable it everywhere it’s available today.

Patient Media Release Form

A specific, written document authorizing external use of a patient’s image or video. It must clearly state what will be shared, on which platforms, for what purpose, and the patient’s right to revoke at any time. This is distinct from a general treatment consent and distinct from a HIPAA authorization (though they can be combined into one document if all required elements are present).

Why it matters: Patients should know they can refuse medical photography or withdraw consent at any time, and that their choice will not affect the quality of care they receive. Document this clearly on the form.

PHI (Protected Health Information)

Individually identifiable health information held or transmitted by a covered entity. Patient images become PHI when they include identifiable details AND relate to the patient’s past, present, or future health condition, the provision of care, or payment for care. A photo of a sunset taken on a clinic phone is not PHI. A photo of a patient’s surgical site taken on that same phone is.

Risk Assessment / Risk Analysis

A required HIPAA process to identify threats and vulnerabilities to ePHI, including patient images and videos. It is the single most cited deficiency in OCR enforcement actions. If you haven’t conducted a formal risk assessment that covers how your clinic captures, stores, shares, and disposes of patient images, you have a compliance gap.

In practice: Walk through every step of your image workflow. Where does the photo get taken? On whose device? Where is it stored? Who can access it? How is it transmitted? How is it deleted? Each step is a potential vulnerability.

Safe Harbor Method

One of two HIPAA-approved methods for de-identifying PHI. It requires removal of all 18 specified identifiers, including full-face photographs, dates more specific than year, geographic data smaller than a state, and any unique identifying number. For digital images, this also means stripping DICOM headers (PatientName, PatientID, DeviceSerialNumber, date-time elements) and checking that embedded thumbnails don’t expose identifiers even when the visible image is cropped.

Sanctions Policy

A covered entity’s internal policy defining consequences for workforce members who violate HIPAA, including rules around patient photography and video. HIPAA requires that this policy exist and that it be applied consistently.

In practice: If a staff member takes a selfie in the treatment area with a patient visible in the background and posts it to their personal social media, your sanctions policy dictates the response. Without one, you have no documented enforcement mechanism.

Secure Messaging

Communication through a platform that provides encryption, access controls, and audit trails meeting HIPAA requirements. Standard SMS, iMessage, WhatsApp, and Facebook Messenger do not qualify. It may seem easier to use regular SMS or an encrypted-but-not-HIPAA-compliant app, but as practitioners point out in online forums, it can invite data breaches, patient confusion, or compliance violations.

Learn how clinics are stopping PHI leaks through SMS and switching to compliant alternatives.

Social Media Policy (HIPAA)

A written organizational policy defining what workforce members can and cannot post online regarding patients, the clinic, and clinical environments. Privacy settings offer no protection. PHI shared in closed groups, private messages, or disappearing stories can all be captured and redistributed.

In practice: Your policy should explicitly prohibit posting patient photos or videos from clinical areas without signed authorization. It should also address personal devices, personal social accounts, and the use of clinic hashtags or location tags that could inadvertently link a patient to your facility.

TPO (Treatment, Payment, Healthcare Operations)

The three categories of PHI use that generally do not require separate patient authorization. Sending a patient their personalized exercise video through a secure app for home practice is a treatment use. Using that same video in a Facebook ad is marketing, which falls outside TPO and requires written authorization.

In practice: Most day-to-day exercise video workflows, like sharing videos with patients for home programs, fall under TPO. Problems arise when clinicians repurpose that content for social media, presentations, or website testimonials without going back to get authorization.

Telemedicine Recording

Audio or video captured during a virtual care session. These recordings can be used for TPO purposes without separate authorization. However, any use outside TPO (posting a clip as a case study, sharing in a webinar, using in marketing) requires the patient’s written authorization.

Why it matters: The growth of telehealth has created a massive volume of recorded sessions. Many clinicians don’t realize these recordings carry the same HIPAA protections as in-person clinical photos.

Workforce Training

HIPAA requires that all members of a covered entity’s workforce receive education on privacy and security policies, including rules around patient photography and video. Training must be documented and refreshed regularly. “Workforce” includes employees, volunteers, trainees, and anyone under the organization’s direct control.

In practice: Annual training should cover your clinic’s specific image policies: when photos can be taken, on which devices, where they’re stored, and what happens if someone violates the rules. New hires should receive training before they have access to patient areas.

Zero Trust

A security model that requires verification for every user and device attempting to access resources, regardless of whether they’re inside or outside the organization’s network. Instead of assuming that anything inside the clinic’s Wi-Fi is safe, zero trust assumes nothing is safe until proven otherwise.

Why it matters: Healthcare organizations are increasingly adopting zero trust because DICOM servers and other clinical imaging systems are routinely exposed due to basic security failures. For small clinics, zero trust principles translate to practical steps: require MFA, segment your networks, and never assume a device is secure just because it’s “yours.”


Quick-Reference Checklist: Protecting Patient Images and Videos

Pull this list and post it in your break room or pin it in your team Slack channel.

  1. Obtain written authorization before any non-TPO use of patient images (social media, website, presentations).
  2. Use only HIPAA-compliant platforms with signed BAAs for image and video storage, sharing, and messaging.
  3. Enable encryption at rest (AES-256) and in transit (TLS 1.2+) on every system touching patient media.
  4. Strip EXIF metadata from clinical images before sharing them outside your secure systems.
  5. Train every staff member annually on your photo, video, and social media policies.
  6. Conduct a risk assessment that specifically maps your image capture, storage, and sharing workflow.
  7. Implement access controls with unique logins and role-based permissions on all platforms storing patient content.
  8. Turn on multi-factor authentication for every system that supports it.
  9. Maintain a sanctions policy with documented consequences for photography and video violations.
  10. Review and re-sign BAAs when vendors update their terms or you change platforms.

What Happens When You Get It Wrong

HIPAA penalties are tiered based on the level of negligence, and the 2026 penalty amounts are steep:

Criminal penalties apply when someone knowingly obtains or discloses identifiable health information: up to $50,000 and one year in prison. If the offense involves false pretenses, that jumps to $100,000 and five years. Offenses committed with intent to sell or misuse PHI carry fines of $250,000 and up to ten years.

The Complete P.T. Pool & Land Physical Therapy case is especially instructive for rehab providers. This Los Angeles clinic paid $25,000 and agreed to a corrective action plan simply for posting patient testimonials, including full names and photos, on its website without proper authorization. The violation wasn’t a hack or a lost laptop. It was a marketing decision made without compliance awareness.

For clinics that want to see how others have handled compliance while still growing their practice, real-world case studies offer a useful reference point.


How HIPAA-Compliant Platforms Solve This

The common thread across every term in this glossary is that protecting patient images and videos online requires more than good intentions. It requires infrastructure. When evaluating a platform for storing and sharing patient content, look for:

  • A signed BAA (not just a privacy policy, an actual Business Associate Agreement)
  • Encryption at rest and in transit meeting AES-256 and TLS 1.2+ standards
  • Role-based access controls with unique user credentials
  • Audit trails showing who accessed what and when
  • Secure in-app messaging that keeps PHI out of SMS and consumer apps
  • Compliance with the proposed 2026 Security Rule requirements (MFA, network segmentation)

These aren’t nice-to-haves. They’re the baseline for any platform handling patient exercise videos, clinical photos, or care plan content.

See pricing for HIPAA-compliant plans or schedule a walkthrough with the team.


Frequently Asked Questions

When does a patient photo become PHI?

A photo becomes PHI when it is created or received by a covered entity, contains individually identifiable information (a face, tattoo, name, or even metadata like GPS coordinates), and relates to the patient’s health condition, treatment, or payment. A stock photo of a knee brace is not PHI. A photo of a specific patient’s knee in a brace, taken during their appointment, is.

Can I text a patient their exercise video?

Not through standard SMS. Regular text messages are unencrypted and leave no audit trail, which violates HIPAA’s technical safeguard requirements. You need a HIPAA-compliant secure messaging platform with encryption and a signed BAA. Practitioners in online forums consistently flag this as one of the most common, and most preventable, violations in small clinics.

Is blurring a patient’s face enough to de-identify a photo?

No. Under HIPAA’s Safe Harbor method, full-face photographic images are one of the 18 identifiers that must be removed. Blurring reduces recognizability but does not eliminate it, especially with modern image-enhancement technology. The compliant approach is to crop the patient out entirely or reshoot without them in the frame.

Do I need a BAA with my cloud storage provider?

Yes. Any vendor that creates, receives, stores, or transmits ePHI on your behalf needs a BAA. This includes cloud storage services like Google Drive, Dropbox, and video hosting platforms, even if the data is encrypted. Without a BAA, sharing patient files with that vendor is a violation regardless of how they handle it.

What’s the difference between consent and authorization for patient photos?

Consent is the general permission patients give for treatment at intake. Authorization is a separate, specific, written document permitting a defined use of their PHI, such as posting a before-and-after photo on social media. Most photo and video uses outside treatment, payment, and healthcare operations require authorization, not just consent.

What changes are coming in the 2026 HIPAA Security Rule update?

The proposed rule, published January 6, 2025, is the first major rewrite since 2013. It would eliminate the “addressable” category for security measures, making encryption, multi-factor authentication, annual penetration testing, network segmentation, and semiannual vulnerability scans all mandatory. Clinics should prepare now rather than waiting for final enforcement dates.

Can a patient revoke their authorization after I’ve posted their photo?

Yes. Patients have the right to revoke authorization at any time. This is why posting patient content to social media carries inherent risk: once something is online, it can be screenshotted, cached, or reshared, making full retraction practically impossible. Factor this into your marketing decisions.

What should my clinic’s social media policy cover?

At minimum, it should define which staff members can post on behalf of the clinic, prohibit sharing patient photos or videos without signed authorization, address personal social media use in clinical settings, and specify consequences for violations. Remember that privacy settings on platforms offer no real protection. Content shared in closed groups or via disappearing messages can still be captured and redistributed.


For more compliance and clinical resources, browse the resource center.

{ “@context”: “https://schema.org”, “@type”: “FAQPage”, “@id”: “#faq”, “mainEntity”: [ { “@type”: “Question”, “@id”: “#faq-question-1”, “name”: “When does a patient photo become PHI?”, “acceptedAnswer”: { “@type”: “Answer”, “text”: “A photo becomes PHI when it is created or received by a covered entity, contains individually identifiable information (a face, tattoo, name, or even metadata like GPS coordinates), and relates to the patient’s health condition, treatment, or payment. A stock photo of a knee brace is not PHI. A photo of a specific patient’s knee in a brace, taken during their appointment, is.” } }, { “@type”: “Question”, “@id”: “#faq-question-2”, “name”: “Can I text a patient their exercise video?”, “acceptedAnswer”: { “@type”: “Answer”, “text”: “Not through standard SMS. Regular text messages are unencrypted and leave no audit trail, which violates HIPAA’s technical safeguard requirements. You need a HIPAA-compliant secure messaging platform with encryption and a signed BAA. Practitioners in online forums consistently flag this as one of the most common, and most preventable, violations in small clinics.” } }, { “@type”: “Question”, “@id”: “#faq-question-3”, “name”: “Is blurring a patient’s face enough to de-identify a photo?”, “acceptedAnswer”: { “@type”: “Answer”, “text”: “No. Under HIPAA’s Safe Harbor method, full-face photographic images are one of the 18 identifiers that must be removed. Blurring reduces recognizability but does not eliminate it, especially with modern image-enhancement technology. The compliant approach is to crop the patient out entirely or reshoot without them in the frame.” } }, { “@type”: “Question”, “@id”: “#faq-question-4”, “name”: “Do I need a BAA with my cloud storage provider?”, “acceptedAnswer”: { “@type”: “Answer”, “text”: “Yes. Any vendor that creates, receives, stores, or transmits ePHI on your behalf needs a BAA. This includes cloud storage services like Google Drive, Dropbox, and video hosting platforms, even if the data is encrypted. Without a BAA, sharing patient files with that vendor is a violation regardless of how they handle it.” } }, { “@type”: “Question”, “@id”: “#faq-question-5”, “name”: “What’s the difference between consent and authorization for patient photos?”, “acceptedAnswer”: { “@type”: “Answer”, “text”: “Consent is the general permission patients give for treatment at intake. Authorization is a separate, specific, written document permitting a defined use of their PHI, such as posting a before-and-after photo on social media. Most photo and video uses outside treatment, payment, and healthcare operations require authorization, not just consent.” } }, { “@type”: “Question”, “@id”: “#faq-question-6”, “name”: “What changes are coming in the 2026 HIPAA Security Rule update?”, “acceptedAnswer”: { “@type”: “Answer”, “text”: “The proposed rule, published January 6, 2025, is the first major rewrite since 2013. It would eliminate the \”addressable\” category for security measures, making encryption, multi-factor authentication, annual penetration testing, network segmentation, and semiannual vulnerability scans all mandatory. Clinics should prepare now rather than waiting for final enforcement dates.” } }, { “@type”: “Question”, “@id”: “#faq-question-7”, “name”: “Can a patient revoke their authorization after I’ve posted their photo?”, “acceptedAnswer”: { “@type”: “Answer”, “text”: “Yes. Patients have the right to revoke authorization at any time. This is why posting patient content to social media carries inherent risk: once something is online, it can be screenshotted, cached, or reshared, making full retraction practically impossible. Factor this into your marketing decisions.” } }, { “@type”: “Question”, “@id”: “#faq-question-8”, “name”: “What should my clinic’s social media policy cover?”, “acceptedAnswer”: { “@type”: “Answer”, “text”: “At minimum, it should define which staff members can post on behalf of the clinic, prohibit sharing patient photos or videos without signed authorization, address personal social media use in clinical settings, and specify consequences for violations. Remember that privacy settings on platforms offer no real protection. Content shared in closed groups or via disappearing messages can still be captured and redistributed. — For more compliance and clinical resources, [browse the resource center](https://ac-health.com/resource-center/).” } } ] }