Patient Photos, Marketing & HIPAA: Compliance Guidelines for Healthcare Marketing Teams
What HIPAA actually requires before a patient photo goes into a marketing campaign — written authorization elements, a real OCR settlement, and how to build a compliant photo workflow.
A "before and after" photo, a smiling patient testimonial on the homepage, a resident's birthday celebration shared on the clinic's Instagram — these are some of the most effective marketing assets a healthcare organisation has, and some of the easiest to get wrong under HIPAA. The rules here aren't obscure: a 2025 OCR settlement saw a Delaware nursing home pay $182,000 after posting photos of roughly 150 residents on social media without the required authorizations, plus a two-year corrective action plan. The failure wasn't malicious — it was a marketing team that didn't realise "the resident seemed happy to be in the photo" isn't the same thing as a valid HIPAA authorization.
Why a patient photo is protected health information
A photograph that shows a patient's face, combined with the fact that they're a patient at your facility, is itself protected health information (PHI) under HIPAA — even with no name attached and no clinical detail visible. That combination of visual identification and the fact of receiving care is enough to trigger HIPAA's protections, which is why marketing use requires a different standard of consent than most people assume.
Treatment photos vs. marketing photos: two different rules
HIPAA already permits photography for treatment, payment, and healthcare operations without separate authorization — a wound-care photo in a patient's chart, for example, needs no special consent because it's part of clinical documentation. Marketing is a different category entirely. Any photo intended for external promotional use — a website testimonial, a social media post, a brochure, a before-and-after gallery — requires the patient's written authorization, obtained specifically for that purpose, before it's used or shared.
What a valid marketing authorization actually needs
A valid authorization isn't a verbal "sure, go ahead" or an implied consent from someone posing for the camera. Under HIPAA's authorization standard, it needs to include, in writing:
- A clear description of the information being disclosed — specifically that a photo or video showing the patient's identity will be used.
- The specific purpose of the disclosure — not a blanket "for marketing" but the actual intended use (website, specific social platforms, print materials).
- An expiration date or event after which the authorization is no longer valid — an authorization signed once, five years ago, for a campaign that no longer exists isn't a standing licence to keep using the image.
- The patient's signature, dated, and kept on file — not a note in someone's inbox that they seemed fine with it.
Informal agreement, a nod during a photo shoot, or the patient's own enthusiasm about being included is not sufficient on its own — the OCR settlement above turned on exactly this gap between "the resident seemed happy" and a documented, purpose-specific authorization. The same rigour that underpins informed consent training for clinical procedures applies here: consent has to be specific, informed, and documented, not assumed.
The social media trap: authorization isn't the whole story
Even with a properly signed authorization, social media raises an additional risk that a printed brochure doesn't: once a photo is posted publicly, it can be screenshotted, shared, and redistributed in ways the organisation can no longer control, regardless of what the authorization said or whether it's later withdrawn. That's a real limitation marketing teams should factor into the decision to post at all, not just a box to tick on the consent form. This overlaps with, but is distinct from, the risk covered in Learnsignal's healthcare social media and patient privacy training, which focuses on individual staff posting habits rather than the organisation's official marketing use of patient images — both need their own training, because the failure modes and the people responsible for each are different.
Building a compliant marketing photo workflow
- Use a dedicated marketing authorization form, separate from general treatment consent paperwork, so marketing staff and clinical staff aren't relying on the same document for two different legal purposes.
- Track expiration dates centrally. A spreadsheet or simple database of who's authorised, for what use, and until when prevents a genuinely consented photo from quietly becoming an unauthorised one after the authorization lapses.
- Get marketing and compliance talking to each other early. The OCR settlement pattern repeats across the industry precisely because marketing teams often don't loop in compliance until after a campaign is already live.
- Honour withdrawal requests promptly. A patient can revoke authorization; the organisation needs a clear, fast process for pulling an image down when they do, even knowing a public post can't be fully un-shared.
Frequently asked questions
Does blurring a patient's face remove the need for authorization?
If the image can no longer identify the patient in any way (face, identifying tattoos, name tags, room numbers visible in the background), it generally falls outside HIPAA's definition of PHI. A blurred face with other identifying context still visible may not be enough on its own.
Can a patient's general willingness to be photographed substitute for written authorization?
No. HIPAA's marketing authorization requirements are specific and written; verbal willingness or a friendly photo op doesn't meet the standard, as the 2025 OCR settlement made clear.
Who should own the authorization process â marketing or compliance?
Both, working together. Marketing typically originates the request and collects the signature, but compliance should own the form template, the retention process, and periodic audits of what's currently in use against what's currently authorised.
Getting this right protects patients and protects the organisation from a costly, avoidable settlement. Learnsignal's CPD training library covers HIPAA and data protection training across clinical and non-clinical roles alike, including marketing and communications staff who handle patient images.
This page was last updated:
Learnsignal Education Team
Expert Tutor at Learnsignal
Qualified professional with years of experience in teaching and helping students achieve their accounting qualifications.
View all posts by Learnsignal Education Team


