Dental Photography in California: Consent, Storage, and Marketing Use

Dental Photography in California: Consent, Storage, and Marketing Use

Dental photos can be powerful tools for diagnosis, treatment planning, and patient education. In California, though, every image you capture is also a legal and privacy risk if you do not manage consent, storage, and marketing use correctly.

Any photo that can identify a patient is protected health information. That includes full‑face shots, smiles, and even intraoral photos if they are tied to a name, chart number, or other identifiers. HIPAA, California’s medical privacy laws, and general consent rules all apply.

For photography used in treatment and documentation only, you generally rely on your standard treatment consent and Notice of Privacy Practices. Still, it is smart to have a specific photography clause that explains why you take photos, how they will be stored, and who may access them. Patients should understand that images become part of their record and are protected like any other clinical information.

Marketing use is different. You need separate, explicit written authorization before using patient images in:

  • Website galleries or social media posts
  • Printed brochures, ads, or in‑office displays

That authorization should state that participation is voluntary, will not affect care, and can be revoked in writing, with the understanding that you cannot pull back materials already printed or widely published. Avoid bundling marketing photo consent into a long stack of clinical forms; keep it clear and easy to understand.

For minors, a parent or legal guardian must sign marketing authorization. Be cautious when a teen wants photos posted on social media; you still answer to the legal decision‑maker, and you still own the compliance risk. When in doubt, decline public posting.

Secure storage is just as important as consent. Clinical photos should be:

  • Stored in your practice management or imaging system, not personal phones
  • Encrypted when stored and transmitted
  • Backed up securely with business associate agreements in place for any cloud vendors

If staff capture images on mobile devices, those devices should be enrolled in your security program, with passwords, encryption, and the ability to remote‑wipe if lost. Avoid mixing personal and work photos on the same camera roll whenever possible.

Before posting any “before and after” images, confirm that:

  • You have current, signed marketing authorization for that patient and purpose
  • You have removed names, dates, and any background details that might reveal identity
  • Captions and comments do not disclose more information than the consent allows

Finally, train your team. A short, clear photography policy and a few extra seconds checking consent can prevent a complaint, a board inquiry, or a privacy incident you could have easily avoided.

*****

Looking for OSHA and HIPAA CE Training? MyDentalCE keeps CE courses easy and affordable. 

Back to blog