HIPAA Surveillance Cameras: Rules and Best Practices for Healthcare Facilities
Learn when surveillance footage becomes PHI, where cameras can go, and what safeguards healthcare facilities must implement to stay HIPAA compliant.
Surveillance cameras are standard in healthcare facilities, but they create HIPAA compliance risk the moment footage captures both an identifiable person and their care context. A single lens covering a nurse's station, for example, can pick up a patient's face alongside a computer screen displaying test results. When that happens, the footage becomes Protected Health Information (PHI) and must be handled in accordance with HIPAA's privacy and security requirements.
To stay compliant, healthcare facilities must treat surveillance not as a standalone security tool but as a governed system that protects patients and staff while supporting the organization's broader compliance posture.
Key Takeaways
- Surveillance footage becomes protected health information when it identifies a person and relates to care, treatment, or payment.
- Camera placement should avoid spaces where patients reasonably expect privacy and should limit incidental capture in operational areas.
- Video systems that store or transmit protected health information need documented access controls and audit logs, plus documented encryption decisions.
- Retention and notice should be set in written policies before deployment, along with any state-law duties.
When Surveillance Video Becomes Protected Health Information
The obligation flows from the definition of Protected Health Information at 45 CFR § 160.103, which covers individually identifiable health information in any form or medium. The provision's explicit exclusions cover FERPA education records, records described at 20 U.S.C. 1232g(a)(4)(B)(iv), employer-held employment records, and records of deceased persons over 50 years.
Identifiable Subjects and Care Context
Video crosses into PHI when the subject is identifiable, such as through a visible face or a wristband, and the footage relates to health care or payment. A camera that captures a patient's face alongside a monitor displaying test results has recorded PHI. For a covered entity, onward sharing of footage that contains identifiable health information can create disclosure risk under HIPAA.
Facilities must classify footage by whether it may combine patient identifiers with care context. In a healthcare environment, facilities should assume footage that may combine patient identifiers with care context needs Security Rule safeguards, unless the risk analysis supports a narrower treatment.
What the HIPAA Rules Require Once Video Is PHI
The HIPAA Privacy Rule governs footage that qualifies as PHI. It controls permissible uses and disclosures and imposes the minimum necessary standard. The HIPAA Security Rule requires administrative, physical, and technical safeguards for electronic PHI.
Risk Analysis Before Deployment
When a video system will store or transmit ePHI, HIPAA requires a risk analysis. 45 CFR § 164.308 requires an accurate, thorough assessment of the risks and vulnerabilities to the confidentiality, integrity, and availability of electronic protected health information. Facilities should complete that analysis before deployment so placement and safeguards are documented in advance. The analysis identifies where footage is likely to capture patient identifiers and health context, then drives placement and safeguard decisions.
Deployment and governance determine HIPAA compliance more than camera hardware. A facility's compliance posture depends first on placement and access control. Retention policy and oversight complete the governance picture.
Where Cameras Can and Cannot Go
Camera placement is primarily governed by state privacy and surveillance statutes that turn on reasonable expectations of privacy in the space, and in healthcare settings is also constrained by HIPAA’s physical safeguard standards when footage constitutes PHI. Placement decisions follow whether a patient reasonably expects privacy in a given space.
Lower-Risk Areas Commonly Monitored
Public and circulation spaces are generally lower-risk surveillance locations. In practice, these include building entrances and exits, lobbies and waiting rooms, hallways and corridors, parking structures and exteriors, supply and storage rooms, administrative areas without patient access, elevators, stairwells, and loading docks.
Pharmacies and medication rooms may be monitored for diversion control, with secure transmission, limited access, and regular audits. Emergency department access points and ambulance bays can be covered when the camera angle avoids clinical monitors and screens.
High-Privacy Areas Generally Avoided
Clinical and personal spaces create high privacy risk. Routine surveillance in those areas is generally inappropriate. Facilities generally avoid cameras in patient rooms and exam or treatment rooms. Restrooms and other changing or locker areas should be treated as off-limits unless state-specific legal review indicates otherwise.
Consultation rooms and staff break rooms should be treated as higher-privacy spaces, with surveillance considered only after review. Behavioral health and substance use treatment spaces carry heightened privacy concerns and should receive especially careful legal review before surveillance is considered.
Areas Requiring Operational Caution
Several spaces sit between lower-risk and high-privacy locations and demand careful field-of-view discipline:
- Hallways near exam rooms, where a camera can see into the room each time the door opens.
- Nursing stations, where the lens must avoid computer screens and other displays showing patient data, such as whiteboards or charts.
- Registration and check-in desks, where general activity is fine but screens, forms, and audible conversations should stay out of range.
- ICU and recovery areas, where coverage should focus on entrances and keep beds or active treatment outside the field of view.
Operating rooms and emergency departments should be evaluated case by case, with documented safety or operational justification and tightly controlled fields of view.
For incidental capture of PHI, compliance risk turns on whether access, use, and disclosure fit Privacy Rule permissions and whether ePHI safeguards are applied. Footage captured incidentally still requires Security Rule protection when stored or transmitted digitally.
Facilities should consider documented consent or authorization wherever surveillance reaches sensitive areas, and consent or authorization becomes especially important for intentional recording.

The Security Rule Safeguards That Apply to Video Systems
Once footage is stored or transmitted digitally, the full Security Rule attaches. The current federal implementation reference is NIST SP 800-66 Rev. 2, published in February 2024. The safeguards map onto how a video management system operates across administrative, physical, and technical controls.
Administrative Safeguards
Beyond the mandatory risk analysis, administrative requirements at § 164.308 include risk management to reduce identified risks to a reasonable level and information access management to authorize who may reach the VMS and its footage. These required safeguards are not optional.
Physical Safeguards
Physical controls at § 164.310 protect the hardware. Facility access controls govern the physical security of camera placement at entry points, server rooms, and pharmacies. Workstation security covers NVR and DVR consoles and VMS workstations. Device and media controls govern the disposal and reuse of storage media.
When retention ends, facilities must sanitize or destroy media. Sanitization should use clearing, purging, or physical destruction consistent with media sanitization standards. A third-party IT asset disposal vendor handling surveillance media must operate under a business associate agreement.
Technical Safeguards
Video systems most often fall short on the technical controls at § 164.312. Required specifications include unique user identification for each VMS operator, an emergency access procedure, audit controls that log access, person and entity authentication, and transmission security for camera-to-NVR and NVR-to-cloud streams. Addressable specifications include automatic logoff after inactivity, encryption/decryption of ePHI, transmission integrity controls to detect improper modification, and transmission encryption over electronic communications networks such as Wi-Fi, Bluetooth, or the internet.
Addressable implementation specifications still require a documented decision. Covered entities should decide whether and how to use encryption based on their risk analysis, then implement it or document a reasonable equivalent. Integrity and audit controls should prevent improper alteration of footage or logs, and each user requiring access should hold unique login credentials. Shared accounts undermine that control.
Who Can View Footage and What Contracts Are Required
A covered entity may not use or disclose PHI except as the Privacy Rule permits or as the patient authorizes in writing. When footage identifies a patient and no Privacy Rule permission applies, written authorization is required.
Physical access to monitoring stations should follow the same logic: surveillance monitors belong in a restricted area, authorized personnel should view footage in a private location, and workstations should log off automatically after inactivity.
The minimum necessary standard at §§ 164.502(b) and 164.514(d) requires reasonable efforts to use, disclose, and request only the minimum PHI needed for the purpose. In the surveillance context, that principle is upheld by limiting footage review to the purpose, using role-based permissions, and applying privacy masking that obscures areas likely to contain PHI.
Business Associate Agreements for VMS and Monitoring Vendors
The Privacy Rule at § 164.502(e) permits a covered entity to disclose PHI to a business associate only after obtaining satisfactory assurances that the associate will safeguard the information. When a vendor creates, receives, maintains, or transmits ePHI, the covered entity must execute a BAA before sharing data. Cloud VMS and managed storage create this issue; remote monitoring creates the same contract issue when the vendor touches ePHI.
A conforming BAA specifies the permissible uses and disclosures, prohibits further disclosure outside the contract, requires appropriate safeguards, obligates the associate to sign BAAs with any subcontractor that touches the ePHI, and requires reporting of security incidents and breaches. Sample BAA provisions reflect these contract elements. If the agreement is invalid or absent, the covered entity is not permitted to disclose PHI to the vendor, and doing so creates HIPAA compliance risk.
What HIPAA Enforcement Reveals About Video Risk
OCR matters involving video show enforcement scrutiny tied to access controls and disclosure governance. Those matters focused on access controls and disclosure governance.
Access Governance
A recent OCR case relevant to physical security operators is the BayCare Health System settlement, which resulted in a substantial penalty. A former non-clinical staff member's credentials were used to access a patient record, and the patient was later contacted by someone holding photographs of her printed records and a video of someone scrolling through those records on a computer screen.
The settlement pointed to failures in access authorization, risk reduction, and review of information system activity. Access governance carried the same weight as any placement decision. That distinction should not be read as a surveillance loophole; surveillance video obligations derive from the same rules applied to all ePHI.
How Long Footage Must Be Retained
HIPAA's documentation rule sets retention requirements for written policies, procedures, and records. The six-year rule at § 164.316(b)(2)(i) applies to written policies, procedures, and records. That six-year obligation covers risk analyses, Business Associate Agreements, audit logs, breach records, training records, and the written camera retention policy itself.
Because HIPAA sets no footage-specific window, actual footage retention should be set through applicable state law, accreditation standards, and documented policy.
Signage, Notice, and Consent Obligations
Notice and Signage
HIPAA's Notice of Privacy Practices provisions lack a camera-specific signage rule. The Notice of Privacy Practices must reflect how PHI is captured and used, so if video surveillance is a meaningful part of that picture, the NPP should say so and be updated under § 164.520 when a material change affects patient rights.
Signage remains best practice regardless. Posting visible signage for active surveillance helps document notice and manage expectation-of-privacy risk. State or facility-specific policy can convert best practice into mandate. Michigan DHHS policy APF 140 requires visible signage in all surveilled areas and written notice to patients and guardians on admission. Staff must document that notice in the patient record. The policy also prohibits cameras in patient rooms and restrooms.
Sensitive Recording and Audio
Consent obligations sharpen when recording moves from ambient security to deliberate capture of a patient. Intentional audio-visual recording for care delivery, telehealth, or surgical documentation calls for informing the patient and documenting agreement. Any external use, including marketing or teaching for outside audiences, requires a HIPAA-compliant authorization specifying purpose, information disclosed, expiration, and other required terms.
Audio deserves separate and stricter handling because it can capture private conversations. Cameras with audio capture should face heightened scrutiny and state-specific legal review before deployment.
How AI Video Systems Change the Compliance Picture
Biometrics and Identifiers
AI-powered video systems create added risk when they actively process the exact data HIPAA treats as most sensitive. Full-face images are identifiers, and biometric characteristics such as face, iris, and gait—as well as identifying marks such as tattoos and scars—are relevant to de-identification. Biometric identification on healthcare footage intentionally processes PHI.
Security directors evaluating AI video systems should document how the AI interacts with ePHI. A risk analysis at § 164.308 requires a concrete understanding of how the AI actually receives, processes, stores, transmits, and exposes PHI.
Vendors and Minimum Necessary Use
HIPAA applies to AI. For AI services, any vendor that creates, receives, maintains, or transmits PHI on behalf of a covered entity needs a BAA. That requirement includes subcontractors and hosting providers that touch the PHI.
The minimum necessary standard applies to machine processing as much as human access. Systems must access only the PHI their purpose requires, prevent re-identification of de-identified data, and keep strict access controls and audit trails; facilities should not place PHI into public AI tools or general-purpose model training unless that use is separately authorized and governed under HIPAA.
Where State Law Overrides the Federal Floor
More Stringent State Rules
HIPAA sets the federal baseline. The preemption rule at 45 CFR § 160.203 preempts contrary state law, but it carves out a decisive exception: state laws more stringent than the Privacy Rule survive. A more stringent law increases provider duties or patient rights, including through stronger disclosure limits or broader access rights. Where such a law exists, covered entities must satisfy both standards.
Several categories of state law bear directly on surveillance. General privacy statutes can impose additional limits on recording in high-privacy spaces where people normally disrobe. Bathrooms and similar areas fall into that category. Behavioral health and substance use settings should be reviewed for any privacy requirements beyond HIPAA.
For a multi-site health system operating across state lines, this layering can create a complex compliance matrix. Multi-site health systems should build a jurisdiction-specific compliance matrix for surveillance operations with legal counsel. The matrix should cover surveillance-specific privacy and audio-consent rules, along with specialized care settings such as nursing home and behavioral health statutes for every state where the organization operates.
Building a System That Holds Up Under Scrutiny
Placement discipline prevents the capture problem. Access governance is what enforcement punishes when it fails. A defensible program pairs disciplined placement with auditable access and protected storage. Vendor contracts and documented downstream assurances show how the organization governs footage before anyone touches it.
Frequently Asked Questions
What specific camera angles or technical configurations can healthcare facilities use at nursing stations to avoid capturing PHI on computer screens while still maintaining effective security coverage?
Position cameras above or beside workstations at angles framing personnel movement without monitor sightlines. Privacy screens, angled displays away from camera fields, and elevated mounting with downward tilt isolate activity monitoring from screen content capture.
Do healthcare facilities need a Business Associate Agreement with their on-premises video management system vendor, or does the BAA requirement only apply to cloud-based and remote monitoring vendors?
The requirement turns on whether the vendor creates, receives, maintains, or transmits ePHI, not deployment location. An on-premises VMS vendor needs a BAA if they access the system during maintenance, support, or configuration when footage containing PHI exists.
How should a healthcare facility handle a situation where surveillance footage that contains PHI is subpoenaed by law enforcement — does HIPAA permit disclosure without patient authorization?
HIPAA permits disclosure to law enforcement without patient authorization under 45 CFR § 164.512(f) for court orders, warrants, subpoenas with assurances, and administrative requests. Facilities must verify legal process meets HIPAA requirements and document disclosures.