Foot Heel Sore Follow-Ups: Portal and Messaging Policy
At 9:41 p.m. on a Thursday, a patient uploads three photographs of a foot heel sore to your patient portal and types, "Is this worse?" Nobody reads it until 8:05 a.m. Friday. By then the message has been replicated across your portal vendor's database, a cloud image store, an email notification relay, and — if your after-hours answering service is integrated — a fourth system you have never audited. This article is about who touches that message, where it lands in the record, and what your front desk is supposed to do at 8:06 a.m. It is a records and vendor problem, not a clinical one.
Wound follow-up encounters are administratively noisy for a reason. They tend to involve repeat visits, serial photographs, and referral traffic between primary care, podiatry, wound care, and sometimes home health. That means records move between organizations frequently, and each hop is a place your policy has to say something specific.
What Actually Enters the Record When a Patient Messages About a Foot Heel Sore
A portal message is not a courtesy note. If your clinicians use it to make or document decisions about care, it belongs to the designated record set, and so do the attachments. That single sentence drives most of the downstream obligations in this article.
Write down, in your portal policy, exactly which of the following your practice treats as part of the designated record set:
- The message body and clinician reply thread
- Patient-uploaded images and the metadata attached to them
- Automated system notifications (appointment reminders, refill status)
- Administrative-only threads (billing questions, form requests)
Most practices land on: clinical threads and attachments are in, pure scheduling and billing chatter is out but still protected health information. Whatever you decide, decide it once and put it in writing, because the answer determines what you produce on a records request and what your retention schedule has to cover.
The Image Problem
Patient-uploaded wound photos are the piece most portal policies ignore. Ask your portal vendor three questions in writing: where are attachments stored, are they encrypted at rest, and do they persist in the vendor's environment after they are imported into the chart? If the image is copied into the EHR but a duplicate remains in the portal vendor's object storage indefinitely, you now have PHI in two systems with two different retention clocks and two different breach exposure profiles.
Assign this to your privacy officer as a documented vendor question, with the answer stored alongside the contract. If the vendor cannot answer in a week, that itself is a finding.
Can Patients Text or Email Photos of a Foot Heel Sore to the Practice?
Short answer: Yes, a patient may request communication by unencrypted email or text, and HIPAA permits you to honor that request after you warn them of the risk and document both the warning and their choice. You may not require staff to initiate unencrypted clinical exchanges, and you remain responsible for securing the copy that lands in your systems. HHS addresses patient-requested communication channels in its right of access guidance.
The practical failure is not the legal analysis — it is that the warning and the patient's election never get recorded anywhere retrievable. Build a single structured field in the chart: preferred communication channel, risk warning delivered (date, staff initials), patient election. If your front desk cannot complete that in fifteen seconds, they will skip it.
The Staff-Phone Rule You Need in Writing
A patient who has your medical assistant's cell number will use it. Your policy should state plainly that clinical images and clinical questions do not travel to personal devices, that any that arrive must be forwarded into the record and deleted from the device the same business day, and that the forwarding is logged. Put a named person on the quarterly spot check. Without that, personal-device PHI is invisible until a phone is lost.
A Front-Desk Routing Decision Tree That Does Not Ask Staff to Practice Medicine
Your front desk should never be asked to evaluate whether a foot heel sore is getting worse. They should be asked to route on message characteristics, not medical content. Build the tree around observable triggers:
- Contains an image or the words "worse," "new," "drainage," "fever," or "can't walk" — route to the clinical inbox with a same-business-day flag. No staff interpretation, no reply beyond acknowledgment.
- Requests an appointment or referral status — front desk handles, documents in the scheduling module.
- Requests records, images, or a copy of the referral packet — route to the records queue and start the access clock that day.
- Sender is not the patient — stop. Verify the proxy relationship before any substantive reply.
- Anything unclear — route to the clinical inbox. Ambiguity escalates; it never gets resolved at the desk.
Two rules make this survive contact with reality. First, the acknowledgment script is fixed text: "Thank you — your message has been routed to the clinical team and will be reviewed today." Second, every routing action is logged in the portal, not on a sticky note.
Coverage and the Weekend Gap
Name the person who reads the clinical inbox on Saturday, or state clearly in your portal welcome text and your auto-reply that messages are reviewed on business days and give the after-hours instruction. Silence is what produces the 9:41 p.m. message that sits unread for eleven hours with nobody accountable. Post the coverage schedule where the desk can see it, and update it when staffing changes.
Every System Between the Patient and the Chart Needs a Signed Agreement
Map the message path for one wound follow-up and count the vendors. A typical mid-size practice finds five to eight: portal or engagement platform, EHR host, email notification relay, SMS gateway, cloud image storage, answering service, transcription, and the referral or direct-messaging network that carries the packet to the specialist. Each one that creates, receives, maintains, or transmits PHI on your behalf is a business associate.
The common gap is not the EHR — that contract is almost always in place. It is the appointment-reminder tool the office manager signed up for with a credit card, the answering service inherited from the prior owner, and the image-sharing link a clinician started using because it was convenient. Those are the ones that show up in a breach investigation without paperwork.
Run the inventory this month: list every system that has touched a portal message in the last ninety days, note the executed agreement date for each, and close the gaps. If you find vendors without one, you can generate a signature-ready Business Associate Agreement through a six-step wizard and export it as PDF or DOCX — a one-time purchase, no subscription, which matters when you are papering six small vendors at once rather than one enterprise contract.
What to Add for Messaging Vendors Specifically
Beyond the standard terms, get written answers on: breach notification timeline to you (push for something well inside the 60-day outer limit so you have room to notify), subcontractor list, data return or destruction at termination, and whether the vendor uses message content or metadata for product analytics. That last one has become the sharp edge in tracking-technology enforcement, and it belongs in your diligence file for anything that renders a page a patient sees.
Referral Handoffs: When the Foot Heel Sore Record Leaves Your Building
These follow-ups frequently involve a specialist, which means a records packet crosses an organizational boundary. Standardize what goes in it. A referral packet assembled ad hoc by whoever is free tends to include the entire chart, which is a minimum-necessary problem and an unnecessary breach surface.
Define the standard packet — demographics, insurance, the relevant encounter notes, imaging, and current medication list — and require a named approver for anything beyond it. Log the transmission: date, recipient organization, method, and who released it. When the specialist's office calls back three weeks later asking what you sent, that log is the answer.
Incoming records deserve the same discipline. Consult reports arriving by fax, portal, or direct message need a defined intake owner and a target for filing into the chart — same business day is realistic for most practices. Records that sit in an unmonitored inbound queue are simultaneously a care-coordination risk and an unaudited PHI store.
Information Blocking Sits Underneath All of This
Delaying or obstructing the electronic exchange of information without a defined exception is its own regulatory problem, separate from HIPAA. If your policy adds friction to legitimate requests — a mandatory in-person form, a routine multi-day hold — review it against the information blocking framework before it becomes a complaint.
Proxy Access, Caregivers, and the Shared Login You Will Find
Wound follow-ups often involve a spouse, adult child, or home health aide who takes the photos and sends the messages. That is normal and manageable — but only if the caregiver has their own credentialed proxy account with a documented scope, not the patient's password.
Build a one-page proxy request form: who is being granted access, the relationship, the scope (full clinical, appointments only, billing only), the authorization signature, and an expiration or review date. Then run a quarterly report of active proxies and terminate the stale ones. Practices that have never run this report are routinely surprised by how many active proxy accounts belong to people no longer involved in the patient's care.
Train the desk on the tell: a message signed with a different first name, or a caller who says "I'm logged in as her." The response is scripted and neutral — offer the proxy form, do not lecture, do not disclose anything in the interim.
The Access Request Hiding Inside a Portal Message
"Can you send me the pictures I uploaded and what the podiatrist wrote?" is a right-of-access request. The 30-day clock starts the day you receive it, and portal messages count as receipt. Your front desk needs to recognize that phrasing and move it into the records queue rather than replying "we'll ask the doctor."
Two operational details save you. First, log the receipt date in the same place every time, so you can prove the clock. Second, decide in advance how you deliver images — patients frequently want the photos back, and "our system can't export those" is not a satisfactory answer if the images are in the designated record set. Test the export once, document the steps, and keep them with the records procedure.
Quarterly Portal Audit: Six Things to Check
Put this on the calendar with a named owner. It takes about ninety minutes.
- Access review — every staff account with portal message access, matched against current roster and role
- Proxy report — active proxies, with terminations for anyone past their review date
- Unread and unrouted messages — anything older than two business days, with a root-cause note
- Vendor list reconciliation — systems in use versus agreements on file
- Audit log sampling — pull ten records and confirm the log shows who viewed what and when
- Communication-preference documentation — sample charts for the unencrypted-channel warning and election
NIST's SP 800-66r2 maps Security Rule requirements to concrete practices and is a reasonable backbone if you are building this review from scratch rather than inheriting one.
Where This Fits in Your Broader Documentation
Portal and messaging policy is one chapter. It sits on top of a risk analysis that identifies the systems, a set of policies that assign the roles, and workforce training records that prove the front desk was told. If those pieces are scattered across drives and email threads, pull them into one governed set — automated risk analysis and policy generation is a faster path there than rebuilding templates by hand.
Start narrow this week. Pick one recent foot heel sore follow-up, trace every system that touched the messages and images, and check each against your signed agreements. If you find a vendor without one, draft and export the agreement before the next message arrives at 9:41 p.m.