On a Monday in a mid-sized primary care office, the front desk phone shows four unread MMS messages. All four are photographs of hands. Two came from patients who were told at checkout "just text us a picture if it doesn't clear up." Nobody logged them, nobody knows which staff phone they landed on, and one of them is attached to a visit that will be referred out to dermatology this week.

That is the administrative shape of a tinea manuum telehealth encounter. This article is for the person who owns intake forms, consent language, vendor contracts, and records requests — not for the person making the diagnosis. It covers where protected health information actually travels during an image-driven virtual dermatology visit and what your workflow needs to catch.

Why a Tinea Manuum Visit Produces More Records Than a Cold

Skin complaints are visual. A virtual encounter for a hand rash typically involves patient-supplied photographs, sometimes a lab confirmation performed by an outside facility, and frequently a referral to a dermatology practice when the picture is ambiguous or the course is prolonged. That is three or more organizations touching one episode of care.

Compare that to a telephone follow-up on blood pressure, which usually lives entirely inside your EHR. The tinea manuum visit generates: an intake questionnaire, one to six images, a telehealth consent record, a platform session log, an e-prescription transaction, a referral packet, and possibly a lab requisition and result. Each of those is a separate retention decision and a separate potential disclosure.

Your job is not to evaluate the images. Your job is to make sure that when a patient asks for "everything you have," or when a regulator asks how images reached your staff, you can answer in one sitting.

The Photo Intake Channel Is Your Largest Uncontrolled Surface

Most practices have a sanctioned telehealth platform and an unsanctioned shadow channel that patients actually use: the front desk's cell phone, a personal email a nurse gave out, or a general info@ mailbox that forwards to three people.

Patient-initiated messages are not the same as practice-directed workflows

HHS has been consistent that a covered entity may communicate with a patient through the patient's chosen method after warning them of the risks, and that a patient's own unsecured email or text is their choice to make. What it does not permit is your practice building an intake process that routes clinical images through a channel you neither control nor can retrieve.

The distinction is who set the expectation. If your discharge instructions say "text photos to this number," you designed that workflow and you own it. Review the current HHS guidance on HIPAA and telehealth, and remember that the pandemic-era enforcement discretion for non-public-facing video tools ended in 2023. There is no remaining grace period for consumer video apps used without an agreement.

Write down where images are allowed to land

Pick one destination and make it the only one. A defensible pattern looks like this:

  • Sanctioned: patient portal secure upload, telehealth platform's in-session capture, or a dedicated store-and-forward module that writes directly into the chart.
  • Tolerated with documented patient request: patient-initiated email or text, logged into the chart by staff within one business day, then deleted from the receiving device.
  • Prohibited: personal staff devices, consumer messaging apps, shared inboxes with no access log, and any cloud photo library that syncs automatically.

That last item catches practices constantly. A staff member photographs a screen or downloads an image to a device with automatic backup enabled, and the image is now in a consumer cloud account with no agreement behind it. Your mobile device policy should address auto-sync explicitly, not just screen locks.

Does a Telehealth Platform Used for Tinea Manuum Visits Need a BAA?

Yes. If a vendor creates, receives, maintains, or transmits protected health information on your behalf, a business associate agreement is required before use. For a tinea manuum telehealth visit, that includes the video platform, the store-and-forward image tool, the transcription service, the e-fax provider carrying the dermatology referral, the cloud host storing image files, and the patient-communication vendor sending appointment links.

The narrow exception is a true conduit — an entity that only transports data without accessing it, like a telecommunications carrier. Most software vendors do not qualify, because they store the data even briefly. If the vendor can technically retrieve the image, get the agreement.

If you are onboarding a new imaging or telehealth vendor and the contract is stalled in legal, you can generate a signature-ready business associate agreement through a six-step wizard and export it as PDF or DOCX. One-time purchase, no subscription — useful when a single vendor is holding up a launch and you need executable paper this week rather than next quarter.

Your general Notice of Privacy Practices is not a telehealth consent, and your telehealth consent is probably not an image-use authorization. Three separate documents, three separate purposes.

Most states impose their own telehealth consent requirements, and several require it be documented before the first virtual encounter. The consent should name the modality (live video, store-and-forward, or both), state that images may be captured and retained in the medical record, describe the technology limitations, and confirm the patient's location at the time of service. Location matters for licensure, and licensure questions land on the administrator's desk, not the clinician's.

2. The communication-preference record

If a patient wants to send photos by unencrypted text, capture that request in writing, along with the fact that you warned them of the risk. One checkbox in the intake form with a timestamp is enough. Without it, you are defending a workflow choice instead of a patient choice.

3. The authorization for any secondary use

Clinical photographs of hands, nails, and skin are prime candidates for teaching decks, conference slides, marketing pages, and vendor case studies. Every one of those is a use outside treatment, payment, and operations, and requires a signed HIPAA authorization that is separate from the treatment consent. De-identification is harder than it looks: a hand photo can carry a tattoo, a ring, a scar, or a wristband with a visible account number. Crop and review before anyone assumes it is anonymous.

The Six-Vendor Map for One Tinea Manuum Encounter

Sit down with your vendor inventory and trace a single virtual tinea manuum visit end to end. A typical trace:

  1. Scheduling and reminder vendor — sends the visit link, holds name, phone, appointment reason.
  2. Telehealth platform — session video, in-session images, chat log, session metadata.
  3. EHR and its cloud host — chart note, attached images, problem list entry.
  4. E-prescribing network — transaction routed to the patient's pharmacy.
  5. Referral transport — e-fax, direct messaging, or an HIE connection carrying the packet to dermatology.
  6. Lab interface — if a specimen was collected in-office or at an outside draw site, the requisition and result cross another boundary.

Now check each row for three things: executed BAA on file, agreement date within your review cycle, and a named internal owner. In practices I have audited, the failure is almost never the EHR. It is the e-fax provider that was signed up on a corporate card in 2019, or the transcription tool a clinician started using independently.

NIST's SP 800-66 Revision 2 is the practical companion here — it maps Security Rule requirements to concrete safeguards and is a reasonable backbone for documenting how you evaluated each of those vendors.

Images Are Part of the Designated Record Set

When a patient requests their record after a tinea manuum telehealth visit, the photographs come too. Images used to make or support a clinical decision are part of the designated record set, and the 30-day response clock under the HIPAA right of access applies to them the same as to the note.

This breaks practices whose images live outside the EHR — in the telehealth vendor's separate media library, or in a folder on a shared drive. If your records clerk pulls from the EHR only, you have delivered an incomplete record and started a clock you did not know was running.

Two fixes, in order of preference: configure the platform to write images into the chart automatically, or assign a named person to reconcile the media library against the visit list weekly. Test it. Have someone submit a mock request and time the fulfillment.

The Referral Handoff and Minimum Necessary

Referrals for skin complaints move quickly, and staff tend to send the entire chart because it is one click. Treatment disclosures are not subject to the minimum necessary standard, so this is technically permissible — but it is still bad practice. Sending a full longitudinal record to a specialty office expands the blast radius of that office's next breach, and it is exactly the kind of habit that surfaces during an investigation.

Build a referral packet template: the visit note, the relevant images, current medication list, allergies, and any lab result tied to the episode. Nothing about the 2019 orthopedic surgery. If your referral coordinator does not have a template, they will improvise, and improvisation is what you will be explaining later.

Log what left the building

Treatment disclosures do not require accounting under the Privacy Rule, but you still want an internal log — sent date, recipient, transport method, and what was included. When a patient calls asking why their images ended up somewhere unexpected, an operational log answers in two minutes what a forensic reconstruction takes two weeks to answer.

Retention, Deletion, and Image Sprawl

Set retention on images to match your state's medical record retention period, not the vendor's default. Some platforms retain session media for 30 or 90 days and then purge; if the image was clinically relevant and never copied into the chart, that purge destroys part of the record.

Run this check quarterly:

  • Vendor-side media retention setting, documented with a screenshot and a date.
  • Staff device sweep: any clinical images on phones or laptops outside the sanctioned system?
  • Shared mailbox sweep: images sitting in a general inbox older than your defined transfer window.
  • Departed-employee check: were images stored in a personal drive that was deactivated without export?

If you use any patient-facing app that sits outside HIPAA — a wellness tool, a symptom tracker, an unaffiliated portal your marketing team promoted — note that the FTC's Health Breach Notification Rule reaches health apps and connected devices that HIPAA does not. Two regimes, two notification paths, and administrators are the ones who have to know which applies.

A 30-Minute Tabletop You Can Run This Month

Gather your privacy officer, front desk lead, referral coordinator, and one clinician. Walk one fictional tinea manuum telehealth visit through the entire pipeline out loud. Ask:

  1. Where did the first photo arrive, and who touched it?
  2. Which consent forms were signed, and where are they filed?
  3. Which vendors handled the data, and do we hold current agreements with all of them?
  4. If the patient requested the full record today, who pulls it, from how many systems, and how long does it take?
  5. If the dermatology office reports a breach next month, can we say exactly what we sent them?

Write down every answer that starts with "I think." Those are your gaps. Most practices find two or three in the first pass — usually an unpapered vendor and an image store nobody owns.

If your underlying risk analysis and policy set are older than your current telehealth stack, that is a bigger gap than the photos. You can automate the risk analysis and policy documentation so the paperwork reflects the systems you actually run today. And when the next imaging or telehealth vendor arrives without contract language, build the business associate agreement in one sitting rather than letting the deployment run ahead of the paper. Either way, close the gap before the records request arrives — not after.