September 3, 2026

Zac Degraide

A patient photo is protected health information the moment it can identify the patient, and treatment consent does not cover marketing use. Those two facts decide almost everything else. Marketing a before and after image legally requires a separate, written, specific authorization that names the uses you intend, and it requires a way to honor a patient who later changes their mind. This guide covers what makes a photo PHI, why clinical consent and marketing consent are different documents, what a compliant authorization has to contain, how social media changes the calculation, and what to do when consent is revoked after a photo is already public.
Yes, whenever the image can reasonably identify the patient, and that threshold is lower than most practices assume.
A face is the obvious case. It is not the only one. A tattoo, a birthmark, a distinctive piece of jewelry, a scar, or a hand with recognizable features can all identify someone. So can the context around the image: a caption naming the procedure and the month, a location tag, or a post that appears hours after a known patient's visit. Identifiability is judged on whether a reasonable person could connect the image to an individual, not on whether you cropped the eyes out.
This is why the common cropping habit gives less protection than it appears to. An image cropped to the treatment area, published alongside a procedure name and a date, in a practice with a small local patient base, can still be identifying. The safer position is to treat every patient image as PHI by default and to rely on authorization rather than on de-identification, because authorization is a document you can produce and de-identification is a judgment call you would have to defend.
The practical consequence is straightforward. If an image is PHI, it is covered by the same rules as the rest of the chart, and using it for marketing requires the patient's specific written permission.
No. They are two different permissions and they usually need to be two different documents.
Treatment consent covers taking and keeping clinical photographs as part of the medical record: documenting a baseline, tracking a result, supporting continuity of care between providers. That is a use directly connected to the patient's own treatment, and it belongs in the intake and treatment paperwork.
Marketing use is different in kind. It means publishing the image to an audience that has nothing to do with that patient's care, to promote the practice. Under HIPAA, marketing uses of PHI require a separate authorization, and that authorization has to be specific rather than general. A line in the intake form saying the practice may use photographs for promotional purposes is the version that most often fails, because it does not tell the patient what they are actually agreeing to.
The failure this creates is quiet and common. A practice photographs a patient under treatment consent, the result is excellent, and the image goes into an ad six months later. Nobody acted in bad faith and the paperwork exists. It just does not authorize the use it is being asked to cover.
It has to be specific enough that the patient knows exactly what they are agreeing to, and it has to be in writing.
At minimum, a marketing authorization should name the following:
Two operational points matter as much as the wording. Keep the signed authorization with the images it covers, not filed separately, so that anyone about to publish can find the permission in the same place as the asset. And re-consent when the use changes materially. An authorization for the website gallery does not automatically extend to a paid campaign with a new audience.
You need one for every patient whose image you publish. You do not need one to take or keep a clinical photograph, which treatment consent already covers.
Splitting it that way keeps the workflow sane. Clinical photography runs on the treatment consent already in the intake paperwork, so documentation is never blocked. The marketing authorization is then a separate, deliberate step taken only for the images you actually want to use.
Practices that get this right tend to ask at the point where the answer is easiest. A patient who is delighted at their follow-up visit is the most willing they will ever be. That is the natural moment to ask whether they would be comfortable with the practice sharing the photos. Practices that ask months later, by email, when the patient has moved on, get far fewer yes answers and sometimes an uncomfortable conversation.
One caution worth naming: a patient who verbally agrees at the counter has not authorized anything. Enthusiasm is not documentation. The signature is what you would need to produce later, and the moment of enthusiasm is exactly when it is easiest to obtain.
Social media adds three problems that a website gallery does not have, and each needs its own answer.
The image leaves your control. Once a post is public it can be screenshotted, saved, reshared, and reposted by accounts you have no relationship with. Deleting your post does not retrieve those copies. This is the single strongest argument for making sure the patient understands social publication specifically, rather than agreeing to a general marketing line.
The context is identifying even when the image is not. A location-tagged post, a caption naming the treatment, a story published the same afternoon as a known appointment, or a comment thread where a friend recognizes the person, can all connect an image to a patient the crop was meant to protect. Practices also tag patients, or reshare patient-posted content, both of which reveal identity in ways the original authorization may never have contemplated.
Engagement invites disclosure. Comments asking who did this, or what it cost, or whether it hurt, pull the practice toward answering in public. Responding to a comment in a way that confirms someone is a patient is a disclosure, whoever raised the subject first. The rule your team needs is simple: never confirm or deny that a named individual is a patient in a public thread, and move the conversation to a direct channel.
Patient-generated content deserves its own note. A patient posting their own result and tagging you has authorized nothing on your behalf. They control their own disclosure. Resharing it to your account is your practice publishing PHI, and it needs the same written authorization as any other image.
They can revoke at any time, in writing, and you have to act on it. Revocation is not retroactive, so uses already made in good faith before you received it are not violations, but everything from that point forward is.
Acting on it means having a process that actually reaches every copy. That means all of the following, and it is worth rehearsing before you need it:
The reason to write this down in advance is that the hard part is knowing where every copy went. Willingness is rarely the problem. A practice that has run the same before and after image across a website gallery, three social platforms, a paid campaign, and a printed brochure often cannot answer that question quickly, and the delay is what turns a routine request into a complaint.
This is where the underlying system matters more than the policy. If patient images live in a shared folder, on staff phones, and in an ad account, with no record of which images are authorized and where each has been used, a revocation request is a search. If they live in one place with the authorization attached and the usage tracked, it is a task.
HIPAA is the floor, not the ceiling. Several states impose additional requirements on the use of a patient likeness, on advertising by medical practices, and on the retention and disposal of medical records including images. Some states have specific rules for before and after imagery in aesthetic advertising, including disclosure requirements about whether results are typical or whether an image has been altered.
Two rules follow from that. Do not retouch a before and after image in any way that changes the apparent result, including lighting and color adjustments that flatter the after; several state advertising rules treat that as deceptive, and the edit is what the complaint will be about. And have local counsel review your authorization form once, because it is a single document you will use for years.
The practices that never have a problem here have usually built the same four habits.
Clinical photography runs on treatment consent and happens for every patient, so documentation is complete. Marketing authorization is a separate signed document, obtained at the follow-up visit when the patient is happiest, and stored with the images it covers. Every image carries its own permission status, so anyone about to publish can check in seconds rather than asking around. And photos live in one controlled system rather than spread across staff phones, a shared drive, and a marketing folder, which is what makes both auditing and revocation possible.
None of that is legal work. It is workflow, and the part a practice can actually fix.
RxPhoto is the clinical photography system in the PatientNow family, built for practices that both document and market their results.
Photos are captured and stored in a HIPAA-compliant environment rather than on staff phones, which is the gap most practices are trying to close. Consent status travels with the image, so the question of whether a specific photo is cleared for marketing is answered where the photo lives instead of in someone's memory. Standardized capture keeps angles, distance, and framing consistent across staff and across visits, which is what makes a set usable for marketing in the first place. And because access is controlled and logged, a revocation request becomes a defined task rather than a hunt through folders.
The legal requirements above are the same for every practice. The difference is whether your system can answer, for any given image, who consented to what and where it has been used.
It can be. Identifiability is not limited to faces. Tattoos, birthmarks, scars, jewelry, and distinctive features can identify a patient, and so can context such as a procedure name, a date, or a location tag. Cropping reduces risk without eliminating it. The reliable protection is a signed marketing authorization, not the crop.
Only if their marketing authorization is still valid and has not been revoked. Ending the treatment relationship does not end the authorization, and it does not create one either. If the original consent was for treatment documentation only, you still need marketing permission, and reaching a former patient to obtain it is harder than asking at the last visit.
No. The patient controls their own disclosure, and choosing to post their result is not permission for the practice to publish it. Resharing to your account is your practice publishing PHI, and it needs the same written authorization as any other image. Ask, and keep the answer in writing.
Be careful. Care cannot be conditioned on agreeing to marketing use, and an incentive can blur that line, particularly if it is offered before or during treatment. Some state rules also treat compensated testimonials and imagery as advertising that requires disclosure. If you want to use an incentive, get local counsel to look at how it is structured and disclosed first.
Clinical photographs are part of the medical record and follow your state's medical record retention rules, which commonly run several years and longer for minors. Marketing authorizations should be kept for as long as you use the image and for a period afterwards, so you can evidence the permission if it is ever questioned. Retention is a reason to store images in a controlled system rather than on devices that leave the practice.
If the new use falls outside what the original authorization named, yes. An authorization for the website gallery does not cover paid social with a new audience. This is the strongest practical argument for listing channels specifically in the form: a well-drafted authorization covers the uses you can foresee, so you are not going back to patients every time the marketing plan changes.
If you want to see how consent status and usage tracking work when they live with the images themselves, book a walkthrough of RxPhoto.
This guide is general information about how consent and HIPAA apply to patient imagery. It is not legal advice. State requirements vary, and your authorization form should be reviewed by counsel licensed in your state.

Capture consistent photos, streamline documentation, and deliver clearer consultations with tools designed specifically for aesthetic practices.
Walk through how RxPhoto fits into your current workflow.