Topical Steroids for Lichen Planus: Referral Records
At 4:40 on a Friday, a dermatology office calls your front desk and asks you to send the intraoral photographs, the biopsy report, and the last two progress notes for a patient your dentist referred out. Your receptionist puts them on hold and asks you whether she needs a signed release. The answer determines whether that patient gets seen Monday or three weeks from Monday. This post walks through the records and privacy workflow behind a referral like this one — the kind that ends with a prescription for topical steroids for lichen planus — including which disclosures are permitted without authorization, who owns each step, and which vendors in the chain need a Business Associate Agreement.
This is an administrative article. It contains no clinical guidance and takes no position on how anything should be treated. The clinical context matters only because it explains the traffic pattern: lichen planus frequently involves more than one organization — a general dentist or primary care office that notices something, an oral medicine or dermatology practice that evaluates it, sometimes a pathology lab, and a pharmacy. Every one of those handoffs is a disclosure of protected health information, and every one of them has a paper trail your practice is responsible for.
Can You Send Records for Topical Steroids for Lichen Planus Without an Authorization?
Yes. Under 45 CFR 164.506(c)(2), a covered entity may disclose protected health information to another covered entity for that entity's treatment activities without patient authorization. A referring dentist sending photos, notes, and a pathology report to a dermatology practice so it can evaluate the patient and decide on therapy — including whether to prescribe topical steroids for lichen planus — is a textbook treatment disclosure. No signature required. No authorization form. HHS says this plainly in its guidance on permitted uses and disclosures.
Two things people get wrong. First, the minimum necessary standard does not apply to disclosures to a provider for treatment purposes — you may send the full relevant record, and you should not force the receiving clinician to guess what you withheld. HHS addresses this directly in its minimum necessary guidance. Second, the absence of an authorization requirement does not mean the absence of a verification requirement. You still have to confirm the requester is who they say they are.
What you still have to do
- Verify the identity and authority of the requesting practice (164.514(h)). A callback to a published office number beats trusting a caller ID.
- Transmit securely. Permitted does not mean unencrypted.
- Honor any active restriction the patient has requested and you have agreed to (164.522).
- Apply state law where it is more stringent — including any specific consent rules your state imposes on dental records, minors, or sensitive categories.
The Three-Organization Handoff, Mapped by Role
Write this down as a workflow and assign a name to each step. "The front desk handles it" is not a role assignment; it is how records end up in the wrong fax queue.
Step 1 — Originating practice sends the referral packet
Owner: the referral coordinator, or whoever your practice designates. The packet typically includes the referral letter, relevant chart notes, imaging or clinical photographs, medication list, allergy list, and pathology if a biopsy was performed. Log the send with date, recipient organization, transmission method, and the name of the staff member who released it. You are not required to include treatment disclosures in an accounting of disclosures under 164.528, but you need an internal record for your own investigations.
Step 2 — Receiving specialist requests the gaps
Owner: the specialist's intake staff. This is where the Friday-afternoon phone call happens. Your policy should say exactly what your staff does when an outside practice calls for records: verify, document, transmit through an approved channel, log. If your answer to "which channel" is "whatever's fastest," you have a gap.
Step 3 — Consult note returns to the referrer
Owner: the specialist. This is the step that quietly fails most often. A patient is evaluated, a plan is set, and the referring office learns about it six weeks later from the patient. Build a tickler: if a consult note has not come back within your defined window — 14 business days is a common internal standard — the referral coordinator chases it. The return of that note is itself a permitted treatment disclosure. Nobody needs to sign anything for it to happen.
Step 4 — Prescription transmission
Owner: the prescriber. Sending a prescription to a pharmacy is a treatment disclosure to another covered entity. Your administrative concern is the e-prescribing pathway itself: who your intermediary is, whether the connection is authenticated, and whether prescription records are captured in your EHR audit log.
Clinical Photographs Are PHI, and They Are Where Practices Slip
Lichen planus referrals are image-heavy. Intraoral photos, lesion photos, sequential images over time. Every one of those files is protected health information the moment it is associated with a patient, and often before — a photograph of an identifiable body region is identifying on its own.
Three failure modes we see repeatedly:
- Personal-device capture. A clinician photographs a lesion on a personal phone, texts it to a colleague, and the image lands in a consumer cloud backup outside your control. Your BYOD policy either prohibits this or governs it. Silence is not a policy.
- Untracked exports. Photos exported to a desktop folder to attach to a referral, then never deleted. Six months later that folder holds 300 identifiable images and no one owns it.
- Wrong-patient attachment. Image files named IMG_4471.jpg get attached to the wrong referral. This is a disclosure of PHI to an unauthorized recipient and triggers a breach risk assessment under the four-factor test in 164.402.
Fix it with a written image-handling procedure: capture only on practice-controlled devices, name and file images inside the record within one business day, purge local copies on a set schedule, and require a second-person check before any image leaves the practice. That last control costs about eight seconds and prevents the most common wrong-recipient incident in a referral workflow.
Every Vendor That Touches the Referral Packet Needs a BAA
Trace the actual path of a referral packet through your practice and count the third parties. Most administrators find more than they expected:
- Your EHR or practice management vendor
- Your electronic fax or cloud fax provider
- Your secure messaging or encrypted email service
- Your health information exchange or e-referral platform
- Your release-of-information contractor, if you use one
- Your transcription service
- Your document scanning or storage vendor
- Your IT managed service provider, who has access to all of it
Each of these is a business associate. Each needs a signed agreement that predates the first disclosure — not one you scramble to paper after an incident. If you are missing agreements or working from a template someone modified in 2019, a signature-ready Business Associate Agreement generator will get you a defensible document faster than a redline cycle with counsel.
The vendor inventory is also the backbone of your Security Rule risk analysis. If your last risk analysis does not name these systems specifically and describe how PHI moves between them, it will not survive scrutiny. Practices that need to close that gap without a three-month consulting engagement can generate a complete HIPAA risk analysis and policy set built around their actual systems and use it as the working document their referral procedures point back to.
When the Patient Asks for the Same Records
Different rule, different clock. When the patient requests their own record — including the consult note that documents a plan involving topical steroids for lichen planus — you are operating under the right of access at 164.524, not the treatment-disclosure provision. You have 30 days, with one 30-day extension available if you notify the patient in writing of the reason and the new date.
You must provide the record in the form and format requested if you can readily produce it, including electronically. Fees are limited to a reasonable, cost-based amount for labor in copying, supplies, and postage — search and retrieval time is not billable. HHS maintains detailed right of access guidance, and access failures have driven a long run of OCR enforcement. Practices routinely underestimate this: a records request routed to a busy clinical inbox in July gets answered in October.
The one-page desk rule
Post this at the front desk: Provider asking for records to treat the patient = send it, verify first, log it, no form needed. Patient asking for their own records = right of access request, date-stamp it today, 30-day clock, route to the privacy officer. Two sentences prevent most of the confusion that produces complaints.
A Worked Fourteen-Day Timeline
Day 0: Dentist identifies a finding, initiates referral. Referral coordinator assembles the packet, verifies the recipient's secure fax or direct address against a maintained vendor contact list, transmits, and logs the send.
Day 1: Specialist intake confirms receipt. Missing pathology report noted; intake calls the originating office. Originating office verifies the caller via callback, releases the report, logs the disclosure.
Day 5: Patient seen. Clinical photographs captured on a practice-owned device, uploaded to the record, local copies purged per procedure.
Day 6: Prescription transmitted electronically. Consult note dictated through a transcription vendor with a current BAA on file.
Day 8: Consult note signed and returned to the referring dentist through the same verified channel. Referring office files it and closes the referral loop in the tracking log.
Day 14: Referral coordinator's exception report shows zero open referrals past the 14-day threshold. Nothing to escalate.
Nothing in that sequence required a patient authorization. All of it required documentation, verification, and vendor agreements that were already in place.
Where This Goes Wrong Badly Enough to Report
Misdirected disclosures — wrong fax number, wrong patient's images, wrong email recipient — are among the most common incident types small practices report. Scroll the HHS breach portal and you will see how ordinary the causes are. A referral workflow that moves images and notes between three organizations several times a week is exactly the kind of process where a single stale fax number in a contact list becomes a reportable event.
Controls that actually reduce this: an annually verified recipient directory, a required second field confirming the recipient organization name before send, encryption on every outbound channel, and a documented five-minute incident intake so staff report near-misses instead of hiding them.
Your Next Step
Pull your last twenty outbound referrals. Check three things: was the transmission channel on your approved list, was the disclosure logged with a named releaser, and did a consult note come back. If any of those three is a no, your written procedures and your actual practice have drifted apart. Start by building the risk analysis and policy documentation that names your real systems and workflows, then rewrite the referral procedure to match what your staff will genuinely do on a Friday at 4:40.