A shave biopsy leaves your office Tuesday afternoon in a courier bag. Nine days later the dermatopathology report comes back, the patient is referred to a Mohs surgeon two towns over, and a reconstruction consult follows. By the time that episode closes, the documentation behind one course of basal cell carcinoma treatment lives in at least four organizations' systems — and your practice is still the custodian of the part that started it.

This is for the administrator, privacy officer, or practice manager who has to make that trail defensible: what to capture, where it goes, who may receive it without an authorization, how long you hold it, and which vendors touching it need a signed Business Associate Agreement. No clinical guidance here. Treatment decisions belong to your clinicians. The records workflow around them belongs to you, and it is where the complaints, the audits, and the breaches actually land.

One Lesion, Six Record Custodians

Skin cancer encounters are administratively unusual because they fragment fast. A single episode routinely involves a primary care referral, a dermatology visit, an outside pathology lab, a surgical specialist, sometimes a reconstruction or radiation consult, and a billing entity behind each of them.

That fragmentation is the entire reason your workflow has to be tight. Every handoff is a disclosure. Every disclosure has a legal basis — treatment, payment, health care operations, patient authorization, or a specific permitted-use exception — and your staff needs to know which one they are relying on before the fax goes out.

The common failure is not malice. It is a front-desk staffer who releases an entire chart to a caller who says "I'm from the surgeon's office" without confirming who they are, or a medical assistant who emails photographs to a personal address because the portal was slow that morning.

What Records Must a Practice Keep for a Basal Cell Carcinoma Treatment Encounter?

Your designated record set for this kind of episode generally includes every item used to make decisions about the patient. In practice, that means:

  • The encounter note documenting the visit, the lesion location and laterality, and the plan discussed.
  • Consent and procedure documentation, including the signed consent form for any biopsy or excision.
  • Clinical photographs taken before, during, or after the procedure, plus any body-map or lesion-tracking diagram.
  • The pathology requisition and the returned pathology report, filed against the correct patient and the correct anatomic site.
  • Referral correspondence — the outbound referral, the receiving specialist's acknowledgment, and the consult note that returns.
  • Follow-up and surveillance scheduling records, including no-show and recall attempts.
  • Billing and coding records, including the claim, the remittance, and any prior authorization correspondence.

Separately, and often forgotten: the compliance documentation that proves the workflow existed — your authorization forms, disclosure logs, Notice of Privacy Practices version history, and the Business Associate Agreements covering every vendor in the chain.

Clinical Photography Is the Record Most Practices Mishandle

Dermatology and dermatologic surgery run on images, and images are the single messiest category of protected health information in the average practice. A photo of a lesion with a patient's face, a wristband, or a tattoo in frame is identifiable PHI whether or not a name is attached.

Three questions to answer in writing

What device captures the image? If the answer is "whatever phone the MA has," you have an unmanaged endpoint holding PHI. Decide whether photography happens on practice-owned devices only, and document the decision. If personal devices are permitted, your BYOD policy has to address encryption, screen lock, camera roll segregation, and what happens the day that employee resigns.

Where does the image land? Photos that auto-sync to a consumer cloud account are a disclosure to a vendor you never contracted with. This is the most common way a dermatology practice creates an unreported breach without noticing.

Who can delete it, and is that logged? If a photo is part of the designated record set, deleting it is a records-integrity problem, not a housekeeping task. Your image storage needs the same audit trail as your chart.

Marketing and education uses need their own paperwork

Before-and-after images used on a website, a social account, or a conference slide require a written HIPAA authorization that is specific to that use — not the general consent-to-treat signature. Keep a separate log of which patients authorized marketing use, with the authorization's expiration date and a documented process for honoring revocation. When a patient revokes, someone has to actually pull the image down, and that someone needs a name in your policy.

Which Vendors in a Basal Cell Carcinoma Treatment Workflow Need a BAA

Staff routinely get this backwards in both directions. The clean rule: a Business Associate Agreement is required when an outside entity creates, receives, maintains, or transmits PHI on your behalf. It is not required when you disclose PHI to another covered entity for that entity's own treatment, payment, or operations purposes.

Usually not business associates

  • The dermatopathology lab reading the specimen. It is a covered health care provider acting in its own right, and your requisition is a treatment disclosure.
  • The Mohs surgeon or reconstructive specialist you refer to. Same logic — provider-to-provider treatment disclosure, no authorization and no BAA needed.
  • The health plan receiving your claim, which is receiving PHI for its own payment activity.
  • Pure transmission conduits. The conduit exception is narrow — it covers entities that only transport, like the postal service and its electronic equivalents. Do not stretch it. A specimen courier that stores, sorts, or holds materials, or a records-handling service that does anything beyond transport, is not a conduit.

Almost always business associates

  • Your EHR host and any practice-management platform
  • Cloud image storage or a dermatology photo application
  • Transcription and AI scribe services
  • Release-of-information and records-retrieval vendors
  • Billing companies, coding contractors, and claims clearinghouses
  • Patient reminder, recall, and secure-messaging platforms
  • Your IT managed service provider and any remote-support tool
  • Document shredding and media destruction vendors
  • After-hours answering services

Run that list against your actual contract file this quarter. Most practices discover two or three vendors that were onboarded by a clinician or an office manager without anyone routing an agreement through the privacy officer — the photo app and the shredding company are the usual culprits. HHS publishes sample Business Associate Agreement provisions that show the required elements, though sample text alone is not a finished contract.

When you find a gap, close it the same week rather than adding it to a project list. You can generate a signature-ready Business Associate Agreement through a six-step wizard and export it as PDF or DOCX — one-time purchase, no subscription — which is faster than waiting on a vendor's legal team to send you something you will end up redlining anyway.

The 30-Day Clock and the Three Requests Your Front Desk Confuses

Every request that arrives at your window is one of three things, and the correct handling differs sharply. Train to the distinction.

1. A treatment request from another provider

The surgeon's office calls for the biopsy report before a scheduled procedure. Release it. Verify the requester's identity and authority using your documented verification procedure, then send. No patient authorization required, and the minimum necessary standard does not apply to disclosures for treatment. Turnaround should be measured in hours, not days.

2. A patient exercising their right of access

The patient wants their own chart, or wants it sent to a third party they designate in writing. You have 30 calendar days from the request, with one 30-day extension available if you give the patient written notice of the delay and the reason. Provide the record in the form and format requested if you can readily produce it that way. Fees must be reasonable and cost-based — copying labor, supplies, and postage — and you may not charge for search and retrieval time. HHS maintains detailed guidance on the individual right of access, and access failures have been one of the most consistently enforced provisions in the Privacy Rule.

The specific trap in these encounters: patients ask for "my pathology results" and staff sends a one-page summary. If the patient asked for the record, send the record.

3. A third-party request requiring authorization

An attorney, a disability carrier, a life insurance underwriter, or an employer wants the chart. This requires a valid written authorization signed by the patient, containing all required elements — specific description of the information, named recipient, purpose, expiration, and the signature. Check for expiration and revocation before releasing. A stale authorization from an unrelated matter two years ago is not a permission slip.

Log every disclosure in this category. Under the accounting-of-disclosures requirement, patients may request a list of certain disclosures going back six years, and treatment, payment, and operations disclosures are excluded — meaning the ones you must log are precisely these outliers.

Retention: Two Clocks, Not One

Practices frequently collapse these into a single rule and get it wrong.

The HIPAA clock governs your compliance documentation — policies, procedures, authorizations, Notice of Privacy Practices, risk analyses, and Business Associate Agreements. Six years from creation or from the date last in effect, whichever is later. That means a BAA signed in 2019 and terminated in 2025 is retained until 2031.

The medical record clock is set by state law and payer contract, not by HIPAA. HIPAA has no medical record retention period at all. Your state's requirement, your malpractice carrier's advice, and specific payer program requirements may each impose different minimums, and minors' records commonly run to a defined period past the age of majority. Write your governing period into a retention schedule, cite the source for each category, and review it annually.

The practical consequence for skin cancer episodes: surveillance often continues for years, and the original photographs and pathology reports remain clinically relevant long after the encounter closes. Purging on a generic schedule can destroy records your clinicians still need.

When the Pathology Report Is Wrong

A patient reviews their chart and says the report lists the wrong anatomic site. Your reflex may be to fix it. Do not silently edit an outside lab's report.

Under the amendment provisions, you must act on the request within 60 days, with one 30-day extension available on written notice. If your practice did not originate the record and the originator remains available to act on the request, you may deny the amendment on that basis — with a written denial that explains the reason, tells the patient how to submit a statement of disagreement, and explains how to complain. In practice, the right move is to deny in writing and route the issue to the lab so the source record actually gets corrected. Then document that you did.

If a corrected report arrives, both versions stay in the chart. Amendment means appending and flagging, not overwriting.

A Workable Assignment Sheet

Ambiguity about ownership is what breaks these workflows. Assign by role, in writing:

  1. Clinical staff — capture images on approved devices only, confirm site and laterality on the requisition before the specimen leaves the room.
  2. Front desk — triage every incoming request into treatment / patient access / third-party authorization, and escalate anything ambiguous rather than guessing.
  3. Records coordinator — owns the 30-day access clock, tracks extensions in a log with dates, applies the fee schedule consistently.
  4. Privacy officer — owns the vendor inventory, the BAA file, the accounting-of-disclosures log, and the annual retention schedule review.
  5. Practice administrator — reviews the outstanding-request log weekly. A request sitting at day 26 is a problem you want to find on day 12.

Pull three closed encounters at random each quarter and trace them end to end. Was the referral logged? Is the pathology report filed to the right site? Are the photos in the sanctioned storage location? Does every vendor that touched the episode have a current agreement on file? Twenty minutes of self-audit surfaces more than any policy binder. The HHS breach portal is a useful reality check on where small practices actually get hurt, and HealthIT.gov's privacy and security resources are worth circulating to clinical staff who think this is only a front-office concern.

Start With the Contract File

If you do one thing after reading this, list every outside party that touched your last ten skin cancer episodes and check each against your signed agreements. Where a business associate relationship exists without a current agreement, produce and execute a BAA before the next referral goes out. If your underlying risk analysis and policy set are also overdue, automating the full compliance document set is a faster path than rebuilding it from templates. Neither step is a certification — HHS does not certify or endorse compliance products — but both are documentation you will be glad exists the day someone asks.