The short answer
Treatment consent is not automatically permission to publish patient photos. For HIPAA-regulated practices, marketing uses or disclosures of identifiable protected health information generally require a valid written authorization, subject to limited exceptions. Confirm the intended channels and applicable state requirements before publishing.
Separate clinical photography from advertising
HHS explains that most marketing uses of PHI need authorization. A photo used in the care record serves a different purpose from an Instagram post, website gallery or paid advertisement. Do not assume cropping a face removes all identifying information.
Maintain a permission review workflow
As an operational safeguard, record the approved images, purpose, channels, scope and authorization version. Check restrictions and any revocation before each new use. A generic checkbox or a signed treatment form may not satisfy the required authorization elements; have the actual form reviewed.
Your practical checklist
- Identify whether the image is PHI and which privacy rules apply.
- Separate treatment consent from marketing authorization.
- Verify the intended use falls within the valid authorization.
- Retain the authorization and recheck before reuse or a new campaign.
A worked example
A patient agrees to clinical photos during treatment. Months later, the marketing team wants to use them in a paid ad. The original clinical consent is not enough to assume advertising permission; review a valid authorization for that use.
Illustrative workflow example; not a patient case or individualized recommendation.
Mistakes to avoid
- Assuming a smile or verbal agreement is written authorization.
- Treating a face crop as guaranteed de-identification.
- Using photos outside the authorization’s scope.