It is 8:40 on a Tuesday and your portal inbox has nineteen unread messages. Three of them are from patients who had a cyst removal last week. Two include photographs of the site. One asks a question your medical assistant is not licensed to answer, and one is from a spouse logged in under the patient's credentials. Everything in that inbox is protected health information, and the way your front desk handles it in the next twenty minutes is a privacy workflow, a records workflow, and a vendor workflow at the same time.

This article is for the person who owns that inbox policy — practice administrator, privacy officer, or office manager. It covers what to do with post-procedure portal traffic, not what to tell a patient about their wound. No clinical guidance appears here, and none should be inferred.

Why Cyst Removal Generates More Portal Traffic Than You Budgeted For

Minor skin procedures share an administrative profile: short encounter, a specimen that may go to an outside pathology lab, a follow-up window measured in days, and a patient who leaves with instructions and then thinks of four questions in the parking lot. That combination produces a predictable burst of inbound messages between day two and day ten.

The records side matters just as much. A single cyst removal encounter can touch a referring primary care office, a dermatology or surgical practice, an outside pathology lab, and sometimes a hospital outpatient department. Each handoff is a disclosure your accounting and your release-of-information workflow have to survive. When the patient later asks "send me everything," your staff needs to know that "everything" includes portal messages and any images attached to them.

Practices under-resource this because the procedure itself is small. The message volume is not.

Can Front-Desk Staff Answer Portal Messages About Cyst Removal Follow-Up?

No — not the clinical content. Non-clinical staff may acknowledge, route, schedule, and document. They may not interpret symptoms, assess whether something looks normal, or advise a patient to wait.

What non-clinical staff can do in the portal:

  • Confirm receipt and state the expected response window
  • Route the message to the correct clinical queue and note the routing in the chart
  • Schedule, reschedule, or cancel an appointment
  • Answer billing, forms, and logistics questions
  • Escalate anything urgent-sounding to a licensed staff member immediately, by a defined path, without waiting for the queue

What they cannot do:

  • Answer any question about the site, healing, activity, or medications
  • Tell a patient a photo "looks fine" or "looks concerning"
  • Relay a clinician's verbal answer without documenting who said it and when
  • Release pathology results before your results-release policy allows it

Put this on a laminated card at every workstation. Scope violations in portal messaging are rarely malicious; they are the product of a helpful person under time pressure with an open text box.

Photo Uploads Are Records, Not Attachments

The moment a patient uploads an image of a surgical site, you own a piece of PHI that behaves differently from text. It is identifiable in ways a message body is not, it is easy to forward, and it frequently ends up somewhere other than the chart.

Decide where images live before patients send them

Write the answer down: does an uploaded image become part of the designated record set, and if so, at what point? If your portal stores images in a message thread that is not part of the legal medical record, you have created a shadow file. That file is still discoverable, still subject to the right of access, and still your breach exposure.

Most practices should adopt one rule: every clinically relevant image a patient sends is imported to the chart with a date, source, and the name of the staff member who imported it. Everything else gets a documented decline.

Ban the personal-device workaround

The failure mode is a patient texting a photo to a staff member's cell phone because the portal upload is clumsy. Now PHI sits on an unmanaged device, outside your audit log, backed up to a consumer cloud account you have no agreement with. Test your own upload flow on a phone. If it takes more than three taps, your staff will route around it and your policy will lose.

Set a retention answer for images specifically

State retention in your policy alongside the rest of the record. If your portal vendor purges message threads on a schedule that differs from your record retention schedule, you need to know that number and reconcile it, not discover it during a records request.

Identity Proofing and Proxy Access at Enrollment

Portal enrollment is usually handled at the front desk in under ninety seconds, which is exactly why it is a weak point. Two controls matter more than the rest.

Identity verification at activation. Define what your staff checks before issuing a portal invitation — government ID, a verified email on file, a knowledge-based check inside the portal product. Document the method in the chart. A portal account issued to the wrong email address is a disclosure, and it is one you will not detect unless someone complains.

Proxy access with an expiration date. Adult patients who want a spouse, adult child, or caregiver to see follow-up messages after a procedure should get a proper proxy account, not a shared password. Shared credentials destroy your audit trail: when the log says the patient viewed a result, you cannot prove who actually did. Require a signed proxy authorization, tie it to a named individual, and set a review date. For minors, your policy needs a defined age at which proxy access changes or terminates under your state law.

Assign one person to run a quarterly report of active proxy relationships. Stale proxies are the quiet, boring source of complaints that turn into OCR inquiries.

Texting, Email, and the Patient-Request Carve-Out

Patients ask for text reminders and emailed instructions constantly after a minor procedure. The rule is more permissive than most front desks believe, and more documented than most front desks practice.

OCR's guidance on the individual right of access confirms that a patient may request their information through an unsecure channel, and a covered entity may honor that request after warning the patient of the risk. The obligations are: the request comes from the patient, the warning is given, and both are documented. See HHS's individual right of access guidance for the framing.

Add a discrete field in your intake or portal enrollment step that captures: preferred channel, the risk warning delivered, date, and staff initials. If the consent lives only on a paper form in a scanned PDF, your staff will not check it before sending, and the field is the only thing that makes the policy enforceable.

Keep unsecure channels thin

Even with consent, limit what goes out by SMS or plain email: appointment reminders, "a new message is waiting in your portal," billing balances. Keep procedure specifics, images, and pathology results inside the authenticated portal. HHS maintains a plain-language overview of remote communication expectations on its telehealth and HIPAA pages that is worth circulating to clinical leadership.

The Vendor Chain Behind a Single Follow-Up Message

Trace one post-cyst removal message from patient to clinician and count the companies that touch it. The portal itself. The messaging module, which is sometimes a different company. The SMS notification gateway. The image storage layer. The translation service if you use one. The AI-assisted triage or summarization tool someone enabled last quarter. The archiving product your IT contractor set up.

Every one of those is a business associate if it creates, receives, maintains, or transmits PHI on your behalf. Every one needs a signed agreement on file, and every one needs to appear on a list you can produce in under ten minutes.

Most practices discover a gap here, not because they were careless, but because messaging features get bolted on between contract renewals. When you find one — and you will — you need a clean agreement quickly. A six-step wizard that produces a signature-ready Business Associate Agreement with PDF and DOCX export handles that in one sitting, as a one-time purchase rather than another subscription line item. Get it signed before the vendor processes another message, not after.

Ask vendors three questions in writing

  1. Where are portal messages and uploaded images stored, and for how long by default?
  2. What does the audit log capture — view, download, forward, delete — and can we export it ourselves?
  3. Which subcontractors touch this data, and do you hold agreements with each of them?

Keep the answers with the executed agreement. NIST's SP 800-66 Revision 2 is a useful crosswalk when you are mapping these controls to Security Rule standards without hiring a consultant to translate.

Misdirected Messages and the Wrong-Chart Problem

The most common portal incident in a small practice is not a hack. It is a staff member with two charts open who replies to the wrong one, or attaches the wrong image, or sends a post-procedure instruction sheet to a patient with a similar name.

Three controls reduce it measurably:

  • Single-chart discipline. Policy: one chart open at a time when composing a message. Some systems can enforce it; if yours cannot, make it a training and audit point.
  • Name-and-DOB confirmation in the compose step. Require staff to state the verification in the message log, or use a system prompt that displays DOB in the compose header.
  • A no-blame reporting path. Staff who fear discipline hide misdirected messages, and a hidden one becomes an unassessed breach. You cannot run a four-factor risk assessment on an incident you never hear about.

Every misdirected message gets a documented risk assessment, even when you conclude notification is not required. Write the conclusion down. The public HHS breach portal is a reminder of how routine the underlying causes usually are.

Two Clocks Your Staff Confuse

Your message-response service level is an internal commitment. The right of access is a legal deadline. They are not the same clock, and front-desk staff routinely treat both as "we'll get to it."

Clock one: your published portal response window. Pick a number — one business day is common — post it in the portal, and staff it. After a cyst removal, patients messaging about the site expect faster. If you cannot meet the number during high-volume weeks, publish a longer one rather than missing it.

Clock two: a request for a copy of the record triggers a 30-day response obligation, with one 30-day extension available if you notify the patient in writing of the reason and the new date. A portal message that says "can you send me my records" starts that clock. Train staff to recognize the phrasing and log the request date the day it arrives — not the day someone gets around to processing it.

Related: withholding information from the portal that patients are entitled to receive can raise information blocking questions under the Cures Act rules. If your results-release policy imposes a delay, have your compliance lead confirm it fits a recognized exception. HealthIT.gov is the starting point for that analysis.

A One-Week Audit You Can Actually Run

  1. Monday: Pull every portal message from the last 30 days tied to a minor procedure encounter. Count how many were answered by non-clinical staff and read what they said.
  2. Tuesday: Export the list of active proxy accounts. Flag any without a signed authorization on file.
  3. Wednesday: Inventory every product that touches a portal message. Match each to a signed business associate agreement. Note the gaps.
  4. Thursday: Test the patient-side image upload on a phone. Time it. Fix it if it takes more than three taps.
  5. Friday: Confirm your portal message retention setting matches your record retention schedule, in writing, from the vendor.

Assign a name to each day. Unassigned audits do not happen.

Close the Vendor Gaps First

Scripts and training fix behavior over weeks. A missing business associate agreement is a paperwork problem you can close today, and it is the first thing an investigator asks for. Produce a signature-ready BAA for each messaging, imaging, and notification vendor on your list, then work through the risk analysis and policy set that supports it — automated HIPAA risk analysis and policy generation shortens that from a quarter-long project to an afternoon. Start with the vendors that already have your patients' post-procedure photos.