A patient uploads four close-up photographs of her lower lip to your intake portal at 11:40 on a Sunday night, checks a consent box, and types a paragraph about sun exposure into a free-text field. By Monday morning that submission has touched your portal vendor, your image storage, your video platform, and — after the visit — a dermatology group across town. A telehealth visit for actinic cheilitis is administratively unremarkable and technically messy, and this article is about the mess: who signs what, where the photos land, what your consent actually covers, and which contracts have to exist before the first appointment is booked.

Nothing here is clinical guidance. The only clinical fact that matters for your purposes is a boring one: this is a lip condition usually evaluated by dermatology or oral surgery, which means records leave your building.

Why an Actinic Cheilitis Telehealth Visit Crosses Four Vendor Boundaries

Map the encounter before you map the policy. A typical remote intake for a lip lesion produces PHI in at least four systems, and most practices have contracts covering only two of them.

  • The intake portal or form builder — collects demographics, sun-exposure history, symptom narrative, and uploaded images.
  • The image pipeline — whatever moves a photograph from the patient's phone into your chart. Sometimes this is the portal. Frequently it is a second product nobody put on the vendor list.
  • The video platform — carries the live encounter and, in many configurations, retains session metadata, chat transcripts, or recordings.
  • The referral channel — direct messaging, a health information exchange, a fax gateway, or a shared drive that pushes the record to the specialist.

Each boundary is a place where a business associate agreement either exists or doesn't. When OCR asks — and after a complaint they do ask — the question is not whether you trusted the vendor. It is whether you can produce a signed agreement dated before the PHI moved.

HHS retired its COVID-era telehealth enforcement discretion in August 2023. Since then the standard is unremarkable and unforgiving: telehealth technology used for treatment is subject to the same Privacy, Security, and Breach Notification requirements as anything else. The department's telehealth guidance for covered entities is short, and it is worth having your practice manager read it once a year.

The Intake Form Is a Records Problem Before It Is a Clinical One

Front-desk staff think of intake as data collection. Treat it as designated record set creation, because that is what it is.

Free-text fields collect more than you asked for

Ask a patient why they scheduled and you will get employment history, family cancer history, insurance frustrations, and occasionally the name of another provider. All of it is PHI the moment it hits your system. All of it is subject to a right-of-access request, and all of it has to be producible within 30 days under the individual right of access standard.

Practical control: cap free-text fields at a length that discourages narrative dumping, and label them narrowly. "Describe the change you noticed and when" produces a cleaner record than "Tell us about your concern."

Decide, in writing, whether intake submissions from non-patients count

A person who submits an intake form and never books is still an individual about whom you hold identifiable health information. Your retention schedule needs a row for abandoned intakes. Most practices default to keeping them forever inside the form vendor's database, which is the worst of both options: retained long enough to be breachable, never reviewed, never indexed for an access request.

Set a disposal interval — 90 days is defensible for unconverted submissions — and confirm the vendor actually deletes rather than soft-flags. Ask for the deletion behavior in writing. "Archived" is not "deleted."

Name an owner for the intake queue

Assign one role, not a committee. The person who owns the intake queue is responsible for confirming, weekly, that submissions have been moved into the chart and purged from the staging system. Without that assignment, PHI accumulates in a portal admin panel that six people can access with shared credentials.

Photographs Are the Highest-Risk PHI in an Actinic Cheilitis Workflow

A lip photograph shows a face. Facial imagery is identifying on its own, which is why it appears in the HIPAA de-identification standard's list of identifiers under full-face photographic images and comparable images. You cannot strip a name off a lip photo and call it de-identified.

Where the image actually lives

Walk the path with your IT contact and write down every resting place:

  1. The patient's phone camera roll — outside your control, but relevant to what you tell patients about their own copies.
  2. The upload service's temporary storage bucket.
  3. The portal's attachment database.
  4. The chart itself.
  5. Any thumbnail cache, CDN edge node, or email notification that embedded a preview.
  6. The referral packet you generated for the specialist.

Item five is where practices get surprised. If your portal emails staff a notification containing an image preview, that image has now traveled through your mail system and possibly a spam filter operated by a vendor you never contracted with. Turn preview attachments off in notification settings. Notifications should say a submission arrived, nothing more.

Staff phones are not an image pipeline

The most common shortcut in remote skin and lip assessments is a staff member texting a patient "just send it to my cell." That creates PHI on a personal device, outside any retention schedule, backed up to a consumer cloud account. Prohibit it explicitly in your telehealth policy, name the sanction, and give staff a compliant alternative that takes fewer than three steps. Policies without a faster substitute do not survive a busy Tuesday.

Do You Need a BAA With Your Telehealth Platform?

Yes, if the platform creates, receives, maintains, or transmits PHI on your behalf. A video vendor that carries a live clinical encounter meets that test. So does a portal that stores intake photographs, a transcription service, a scheduling tool that holds visit reasons, and a cloud host that stores encrypted records — the conduit exception is narrow and covers transient transmission, not storage.

Practical rule for your vendor list: if the product could be subpoenaed and produce a patient's identifiable information, it needs an executed agreement before go-live. HHS publishes sample business associate agreement provisions, which are a starting point rather than a finished contract — they omit breach notification timelines, subcontractor flow-down specifics, and termination mechanics that you will want defined.

If you are staring at a vendor that has no paper on file and a visit scheduled Thursday, you can generate a signature-ready business associate agreement through a six-step wizard and export it as PDF or DOCX. It is a single purchase, not a subscription, which matters when the gap you are closing is one contract rather than a program.

Telehealth consent and HIPAA authorization are different documents doing different jobs, and practices routinely merge them into one checkbox. Separate them.

Modality limitations, the possibility that the remote encounter will be converted to an in-person visit, technology failure procedures, and — this is the piece administrators forget — the patient's acknowledgment that they are choosing a setting where household members may overhear. State law drives most of this. Several states require documented consent to telehealth specifically, separate from general treatment consent, and a handful require it verbally with a note in the chart. Confirm your state's rule with counsel and record the date and version of the consent the patient signed.

What the image authorization covers

If photographs might be used for anything beyond treatment, payment, or operations — teaching files, marketing, a conference deck, a website before-and-after — you need a separate, revocable authorization with a specific description of the use. Bundling that permission into intake is the failure mode that generates complaints. Give patients a genuine decline path that does not affect their appointment, and log the choice as a structured field, not a scanned signature nobody can search.

Store the exact text the patient saw, not a pointer to the current version. When your consent language changes in March 2027, you need to reconstruct what a January 2026 patient agreed to. Keep a dated archive of every consent revision and record the version identifier in the chart entry.

The Referral Handoff Is Where the Record Leaves Your Control

Because remote evaluation of a lip lesion frequently ends in a referral, the referral packet is a recurring, predictable disclosure. Predictable disclosures deserve a written procedure.

Decide in advance what goes in the packet. The temptation is to send the whole chart because it is one click. Minimum necessary applies to disclosures for treatment differently than to other purposes, but sending eleven years of unrelated records to a specialist evaluating a lip is sloppy practice and it expands the specialist's breach surface on your behalf.

Standardize a packet contents list: the intake narrative, the relevant images, current medication list, insurance information, and the referring note. Assign the packet to a named role. Log the disclosure — date, recipient, contents, transmission method — even for treatment disclosures that do not require accounting, because the log is what lets you answer a patient who asks where their photos went.

If the specialist's office asks you to email images to a general practice inbox, that is a conversation, not a compliance failure on their part alone. Offer the encrypted channel. Document the offer. If they insist on an unencrypted method and the patient has been informed and requests it, note that too — patients may request unencrypted communication, and you may honor it after warning them of the risk.

Assign These Five Roles Before Your Next Telehealth Visit

  • Intake queue owner — moves submissions to the chart, purges staging, weekly.
  • Vendor list custodian — maintains the inventory of every system touching PHI, with BAA status and execution date per row.
  • Consent version controller — archives every revision, maps version IDs to date ranges.
  • Referral packet reviewer — applies the contents standard, logs the disclosure.
  • Incident intake — the single named person staff call when a photo goes to the wrong address at 4:50 on a Friday.

Five names on one page, reviewed when anyone leaves. That page is worth more in an investigation than a hundred-page manual nobody opened.

The Annual Review That Takes Ninety Minutes

Once a year, sit down with the vendor list and do four things. Confirm every entry has an executed agreement and note which agreements predate a material change in what the vendor does. Review each vendor's subcontractors — your video platform's transcription add-on is a subcontractor, and its safeguards flow through to you. Check the OCR breach portal for any vendor on your list. And reread your own security risk analysis to see whether the telehealth workflow you built two years ago still matches the systems you actually use.

HHS proposed a substantial Security Rule update in January 2025, and its direction — asset inventories, stronger encryption expectations, and periodic verification that business associates are meeting their safeguard obligations — is a reasonable planning baseline regardless of where rulemaking stands when you read this. The technical background material at HealthIT.gov's privacy and security resources is useful for briefing non-technical partners.

Two practical notes. No vendor, including any compliance product, can grant you a government-recognized HIPAA certification; HHS does not certify or endorse compliance tools. And documentation is only useful if it reflects what your staff actually do — a risk analysis describing a workflow you abandoned in 2024 is worse than none, because it demonstrates you weren't looking.

Start With the Contract Gap

Pull your vendor list this week and mark every row without a signed agreement. For the gaps, you can build and export a business associate agreement in about ten minutes and get it into signature routing today. If the review surfaces a broader problem — no current risk analysis, policies written for an in-person-only practice — the automated risk analysis and policy document set is the next step after the contracts are closed. Contracts first. They are the fastest thing to fix and the first thing anyone asks for.