Dentist photographing a patient's teeth for a medical record

Do Orthodontic Patient Photos Need to Be HIPAA Compliant?

Yes. If you're an orthodontist in Houston, or anywhere else in the country, patient photos that can be tied to an identifiable person count as protected health information under HIPAA, the same as x-rays or chart notes.

If you're an orthodontist in Houston specifically, there's a second layer to know about. Texas has its own law, HB 300, that adds requirements on top of federal HIPAA, including a shorter window for giving patients access to their own records. Designed specifically for orthodontic imaging, OrthoPhoto helps practices save time, capture better ortho photos, and streamline dental recordkeeping across all offices in one secure platform.

Why Patient Photos Count as Protected Health Information

HIPAA defines protected health information broadly: any health information that's linked to an identifiable patient, in any format. A braces photo filed under a patient's name meets that bar just as clearly as a written note.

That means the same expectations around storage, access, and sharing that apply to written records apply to photos too. The American Dental Association's guidance on patient recordstreats them as part of the same documentation that practices should be auditing regularly, not a separate category with looser rules.

It's a common misconception that photos are somehow lower-stakes than a written chart note, since they don't contain a name typed directly on the image. In practice, a photo filed under a specific patient's record is identifiable the moment it's connected to that file, which is exactly what happens in a normal clinical workflow.

What Federal HIPAA Requires for Orthodontic Photos

At the federal level, HIPAA expects patient photos to be encrypted, access-controlled, and limited to the staff who actually need to see them. Practices also need a signed Business Associate Agreement with any vendor, including a photo app, that touches that data.

None of this is unique to photography. It's the same baseline HIPAA sets for any protected health information, whether it's a scanned form or an image captured on a phone.

Where practices tend to run into trouble is the capture step itself, before a photo ever reaches a secure file. A photo sitting in a phone's camera roll, even briefly, is outside that protected environment, which is one reason manual workflows are harder to keep fully compliant than a dedicated capture tool.

Extra Rules for an Orthodontist in Houston or Elsewhere in Texas

Texas passed its own medical privacy law, HB 300, that goes further than federal HIPAA in a few specific ways. It applies to a broader range of organizations, not just traditional healthcare providers, and it shortens the timeline for giving patients access to their records.

The table below summarizes where Texas HB 300 adds to what federal HIPAA already requires.

RequirementFederal HIPAATexas HB 300
Patient record access Up to 30 days Up to 15 business days
Breach notification Required, no fixed state deadline Patients and the Texas Attorney General notified within 60 days
Staff training Required, general timeline Specific, role-based training timelines
Penalties Up to roughly $2.1 million per violation category, per year Up to an additional $1.5 million per year, enforced separately by the state

An orthodontist in Houston is subject to both columns at once. Where the two laws differ, the stricter rule applies.

That combination catches some practices off guard, particularly the faster records-access window. A process built only around HIPAA's 30-day standard can fall short of what Texas actually requires.

How OrthoPhoto Helps Meet Both Standards

OrthoPhoto's encryption, access controls, audit trails, and signed BAA are built to satisfy federal HIPAA by default. Texas practices get the added benefit of records that are already organized and quick to pull, which matters more once a 15-day clock is running instead of 30.

For a closer look at how that security works day to day, see OrthoPhoto's HIPAA compliance or how it handles dental recordkeeping more broadly.

Frequently Asked Questions

Do dental photos count as protected health information under HIPAA?

Yes, as long as they can be tied to an identifiable patient. HIPAA defines protected health information broadly, covering any format, so braces and orthodontic progress photos filed in a patient's chart meet that standard just as much as written notes or x-rays.

It's a common misconception that photos are lower-stakes simply because they don't have a name printed on the image itself. In practice, the moment a photo is filed under a specific patient's record, it becomes identifiable and falls under the same protections as the rest of that chart.

Does Texas require anything beyond federal HIPAA for patient photos?

Yes. Texas HB 300 applies a broader definition of covered entities than federal HIPAA, reaching organizations that might not otherwise be considered healthcare providers, and it shortens the patient record request window to 15 business days instead of the federal 30.

HB 300 also adds its own training requirements and a separate breach notification rule requiring the Texas Attorney General to be notified within 60 days. A practice that only builds its compliance program around federal HIPAA can still be out of step with what Texas specifically requires.

What happens if a practice doesn't comply with HB 300?

Texas can pursue its own penalties, entirely separate from federal HIPAA enforcement. Fines scale based on intent and financial gain, and can run alongside whatever the federal government pursues for the same underlying incident.

That dual-track enforcement is what catches some practices off guard. A compliance gap in Texas isn't just a federal HIPAA question anymore, it can also draw direct attention from the Texas Attorney General's office on top of any federal review.

Is OrthoPhoto compliant with both HIPAA and Texas HB 300?

OrthoPhoto's security features, encryption in transit and at rest, role-based access controls, automatic audit trails, and a signed BAA at onboarding, are built around federal HIPAA as the baseline every practice needs to meet.

Texas practices get an added benefit from that same setup. Because every photo is already organized and filed the moment it's captured, pulling a complete record takes far less scrambling once a 15-day request clock is running instead of the federal 30.

Sources

Documentation/Patient Records. American Dental Association. https://www.ada.org/resources/practice/practice-management/documentation-patient-records
Understanding Texas HB 300 and Its Impact on Dentists. HealthFirst. https://www.healthfirst.com/knowledge-base/articles/understanding-texas-hb-300-and-the-impact-on-dentists/
HIPAA Compliance in Texas: 2026 Guide for Hospitals, Clinics & CHCs. Medcurity. https://medcurity.com/hipaa-compliance-texas/