A patient walks in Tuesday at 9:15 with an itchy patch on the forearm. The visit lasts twelve minutes. The chart closes by 9:40. By Friday, protected health information from that single encounter for a fungal infection on skin has moved through your practice management system, an outside coder, a clearinghouse, a payer, possibly a reference lab, an image repository, and a statement-printing vendor. That is seven or eight organizations from one twelve-minute visit.

This article is for the person who signs those vendor contracts and answers the records request when it arrives ninety days later. It is not clinical guidance. It is a map of where the PHI goes, who is a business associate, and what your documentation has to survive.

The Trail: Who Touches One Dermatology Claim

Write this out for your own practice. Most administrators discover a vendor they forgot about.

  1. Front desk — captures demographics, insurance card image, reason for visit. That last field is often free text and often ends up in the appointment reminder queue.
  2. Medical assistant — rooming note, sometimes a photograph.
  3. Clinician — the note, the diagnosis, the order.
  4. In-house or contracted coder — reads the full note to assign codes.
  5. Billing staff or outsourced RCM vendor — builds the claim.
  6. Clearinghouse — scrubs and routes the 837P.
  7. Payer — adjudicates, sometimes requests the note.
  8. Reference or mycology lab — if a specimen left the building.
  9. Statement vendor — prints and mails the balance.
  10. Collections agency — if the balance ages past your threshold.
  11. Dermatology practice — if the case is referred out.

Eleven stops. Two of them (the payer and the treating dermatologist) are covered entities in their own right and do not need a business associate agreement with you. The rest almost certainly do. If you cannot immediately say which bucket each vendor falls into, that is the gap.

What Gets Coded on a Fungal Infection on Skin Claim

Superficial dermatophyte diagnoses live in the B35 family of ICD-10-CM — tinea of the body, the foot, the nails, the scalp, each with its own code. Candidal skin involvement sits in B37. The clinical distinctions are the clinician's job. The administrative point is that these codes are site-specific, and site specificity is where denials come from.

A note that says "rash, treated" does not support a site-specific code. Your coder then either queries the clinician, guesses, or picks an unspecified code that triggers a payer request for records. Every one of those three outcomes creates another PHI disclosure. The cleanest privacy control in a billing workflow is documentation good enough that nobody has to ask twice.

The lab line

If a specimen is collected — a scraping, a clipping, a biopsy — the claim gets more complicated fast. Either you bill the collection and the outside lab bills the analysis, or you bill globally under an arrangement with the lab. Those two models have different PHI implications.

When the outside lab bills the patient directly, the lab is acting as a health care provider and a covered entity. Your disclosure of PHI to that lab is a treatment disclosure. It does not require a business associate agreement, though many practices sign one anyway out of habit. When the lab performs work you then bill under your own NPI, look closely at the arrangement — you may have created a business associate relationship or something more complicated. Get that answer from counsel, not from the lab's sales rep.

The E/M level and the note that supports it

Office visit levels for these encounters are usually low-to-mid. That does not make them audit-proof. Payers pull charts on high-volume, low-complexity code combinations precisely because the volume is where the money is. Assume any fungal infection on skin encounter you bill could be one of fifty charts a payer requests in a post-payment review, and build your release workflow accordingly. CMS maintains the current ICD-10-CM files and coding guidance at cms.gov; make sure whoever updates your code tables each October is a named person, not "the EHR."

Clinical Photographs Are the Sloppiest PHI in Your Building

Dermatologic encounters generate images. Images are the single most commonly mishandled category of PHI in a small practice, and it is not close.

The failure pattern is consistent: a medical assistant photographs a lesion with a personal phone because the tablet is charging, texts it to the clinician, and intends to delete it later. The image lands in a cloud photo backup owned by a consumer vendor with no BAA. It syncs to a personal laptop. It appears in a shared family album. Three years later the MA has left and nobody knows the image exists.

Two rules to write down and enforce:

  • Images are captured only on practice-controlled devices, into a system covered by a BAA. No exceptions for "just this once."
  • Images of a body region are still PHI when they travel with a name, an MRN, a date, or an accession number — which they always do. The de-identification safe harbor removes full-face and comparable images, but that does not mean a cropped forearm photo in a named chart is de-identified. It is not.

If your practice uses store-and-forward teledermatology to get a specialist opinion, the platform is a business associate. So is the image archive. So is the vendor that compresses and transmits them.

Which of These Vendors Needs a Business Associate Agreement?

Short answer: any outside party that creates, receives, maintains, or transmits PHI on your behalf needs a signed BAA. For a typical dermatology claim, that means your billing or RCM company, your coding contractor, your clearinghouse, your EHR and practice management host, your image storage or teledermatology platform, your transcription service, your IT managed service provider, your statement and mailing vendor, your shredding company, and your collections agency.

It does not include: the health plan you bill (a covered entity receiving a permitted payment disclosure), the dermatologist you refer to (a covered entity receiving a permitted treatment disclosure), the patient, or a courier that only moves sealed containers without accessing contents. HHS publishes sample business associate agreement provisions that establish the required elements.

The sample provisions are a starting point, not a finished contract — they leave the breach notification window, subcontractor flow-down, termination terms, and record return obligations for you to specify. If you are staring at a spreadsheet with eleven vendors and four signed agreements, a guided BAA generator that walks you through the six decisions that actually matter will close that gap faster than emailing each vendor and hoping they send something usable. It exports signature-ready PDF and DOCX, one-time purchase.

Minimum Necessary When the Payer Asks for the Note

A payer requests records to support a claim. Your biller pulls the chart and sends the whole thing — five years of history, an unrelated behavioral health note, a family history section.

That is a minimum necessary failure. Disclosures for payment purposes are subject to the minimum necessary standard, and HHS is explicit that covered entities must limit payment-related disclosures to what is reasonably needed. Treatment disclosures are the exception — you may send the full record to the treating dermatologist. Payment disclosures are not exempt. Review the HHS minimum necessary guidance and then check what your billing staff actually sends.

Build a standard payment-response packet

Define, in writing, what goes to a payer for a routine dermatologic claim review: the encounter note for the date of service, the order, the lab result if billed, and the relevant image if the payer specifically requested it. Nothing else without privacy officer sign-off. Log every release with date, recipient, and what was sent.

Yes, payment disclosures are excluded from the accounting of disclosures a patient can request. Log them anyway. When a patient calls asking why their employer's plan seems to know about a skin condition, you will want a record.

The 30-Day Clock After the Visit Is Over

Patients with a chronic or recurring fungal infection on skin often accumulate records across multiple visits and multiple organizations — primary care, dermatology, a lab, sometimes a podiatrist for nail involvement. When that patient decides to consolidate, your practice gets an access request.

You have 30 days, with one 30-day extension available if you notify the patient in writing of the reason and the new date. The record must go in the form and format the patient requests if you can readily produce it, including to a third party the patient designates. Fees are limited to a reasonable, cost-based amount, and the flat-fee option HHS describes remains available. The HHS right of access guidance is the controlling reference, and OCR's enforcement record on access requests over the past several years is the reason to take the clock seriously.

Images count

The designated record set includes the photographs. If a patient asks for their complete dermatology record and your images live in a system your release-of-information workflow does not touch, you will produce an incomplete record and not know it. Test this. Pull one chart end to end and see whether the images come with it.

The superbill is not a records release

Out-of-network patients frequently ask for a superbill to submit themselves. That document contains diagnosis codes. Handing it to the patient is fine — it is their information. Emailing it unencrypted because the patient asked you to is also permissible if the patient was warned of the risk and still requested it. Document that warning in the chart. "Patient requested unencrypted email; risk explained" is a one-line entry that resolves a future dispute.

A Two-Hour Audit You Can Run This Month

Pick one closed claim from a dermatologic encounter in the last quarter. Then:

  1. List every system and every organization that held any part of that encounter's PHI. Include the reminder text vendor and the survey tool.
  2. For each external organization, find the signed BAA. Note the signature date and whether the signatory still works there.
  3. Check whether any BAA has a breach notification window longer than what your own 60-day obligation can absorb. Ten days from your vendor is workable. "Promptly" is not.
  4. Ask whether any image from that encounter ever existed on a personal device. Ask the MA directly, without blame.
  5. Confirm the subcontractor flow-down clause exists. Your clearinghouse has subcontractors. Your RCM vendor has offshore staff. Both are your exposure.

Whatever you find, the fix is documentation: an updated vendor inventory, a signed agreement, and a risk analysis that reflects the systems you actually use rather than the ones you used in 2021. If your risk analysis and policy set have drifted from reality, automated risk analysis and policy generation will get you to a current baseline without a consulting engagement.

Start with the vendor list. Pull one claim, trace it, and count the organizations that touched it. Then generate the BAAs you are missing before the next records request forces you to find out the hard way.