When a Nonprofit Video Shoot May Involve HIPAA: Questions to Ask Before Filming

This article is for informational and educational purposes only and does not constitute legal advice.

A compelling client or patient story can help supporters understand a nonprofit’s work. If filming involves healthcare services, a clinic, a therapy program, or identifiable health information, the planning process needs to begin before anyone brings in a camera.

The first point is simple: HIPAA is not a general privacy law for every nonprofit. A charitable mission, tax-exempt status, or work with vulnerable communities does not by itself make an organization subject to HIPAA. HIPAA applies to covered entities, including health plans, healthcare clearinghouses, and certain healthcare providers that conduct specified electronic transactions, as well as their business associates. A nonprofit clinic or health plan may be covered, while an unaffiliated charity may not be. Start by asking the organization’s privacy or compliance lead whether the program hosting the shoot is regulated by HIPAA. HHS explains covered entities and business associates.

Decide whether the shoot could expose PHI

Protected health information, or PHI, is individually identifiable information connected to a person’s health condition, healthcare, or payment for care. A recognizable face alone is not automatically PHI. The concern arises when an image, voice, or other identifier is tied to health-related information or a care context.

That connection can be obvious in an interview about treatment or diagnosis. It can also appear in the background: a patient-room sign, chart, computer screen, medication, appointment board, badge, clinical conversation, or the fact that an identifiable person is receiving services in a care setting. Under HIPAA’s Safe Harbor de-identification method, full-face photographs are among the identifiers that must be removed, along with other specified identifiers and the absence of actual knowledge that the remaining information could identify the person. HHS de-identification guidance provides useful context for understanding why a simple decision to omit a name may not solve the issue.

Make the location review part of pre-production

For regulated providers, HHS gives particularly direct guidance on filming. Providers generally may not invite or allow media personnel, including a film crew, into treatment areas or other areas where PHI will be available in written, electronic, visual, or audio form without prior written HIPAA-compliant authorization from every patient whose PHI will be accessible. HHS’s film and media guidance applies this principle to the practical realities of a shoot.

This is why a location walk-through matters. Before scheduling crew, identify what could be seen or heard in every planned shot. A waiting room, intake area, therapy space, clinic floor, or patient room may expose information about people who are not the featured participant. Plan a closed set, use a controlled non-treatment location when possible, clear screens and visible materials, and prevent clinical conversations from being recorded. If an unapproved person or identifiable care information enters the scene, pause filming.

Do not rely on post-production to repair an uncontrolled shoot. HHS specifically explains that blurring a face or changing a voice later does not cure the initial unauthorized access to PHI by media personnel. Limited incidental disclosures may be permitted only when they are secondary to an otherwise permitted disclosure and reasonable safeguards are in place. They are not permission to knowingly expose patient information during a communications shoot. HHS guidance on incidental disclosures explains that narrow standard.

Use the right authorization, before filming

A general appearance release may address permission to use someone’s likeness, but it is not necessarily a HIPAA authorization. When HIPAA authorization is required, a verbal agreement or a generic release is not enough unless it contains the required authorization elements.

A valid authorization must describe the PHI in a specific, meaningful way; identify who may disclose it and who may receive it; state the purpose; and include an expiration date or event. It must be signed and dated, explain the right to revoke in writing, address whether care or benefits can be conditioned on signing, warn about possible redisclosure by a recipient, use plain language, and be provided to the individual. The regulation generally prohibits conditioning treatment, payment, enrollment, or eligibility for benefits on signing an authorization, subject to limited exceptions. 45 CFR 164.508 sets out these requirements.

For a public-facing fundraising video, use the organization’s privacy-approved authorization process instead of improvising on shoot day. HIPAA has a limited fundraising provision for certain uses or disclosures of defined PHI by a covered entity for its own fundraising, with conditions including notice and an opportunity to opt out of future fundraising communications. That rule does not replace the separate analysis needed when a crew will access PHI or an organization plans to publish an identifiable patient story. 45 CFR 164.514 addresses fundraising and de-identification requirements.

Plan for the footage after the shoot

Raw footage can create its own questions. Ask who will receive, edit, store, transmit, and delete it. An outside editor, production participant, transcription provider, or storage service may create business-associate and security questions if that party creates, receives, maintains, or transmits PHI on the organization’s behalf. A videographer is not automatically a business associate; the answer depends on the services and access involved. Ask the privacy officer or counsel whether a business associate agreement is required. HHS business associate guidance explains the fact-specific standard.

Cloud storage deserves a separate check. HHS states that a cloud service maintaining electronic PHI on behalf of a covered entity or business associate is itself a business associate and requires a compliant business associate agreement. HHS cloud computing guidance addresses that relationship.

Flag special situations early

For minors, do not assume a parent can always sign. Whether a parent or another adult is the appropriate personal representative can depend on state and other applicable law, including circumstances in which a minor may consent to particular care. HHS guidance on minors and personal representatives outlines that limitation.

School-based organizations should also determine whether student records are governed by FERPA rather than HIPAA. Programs involving federally assisted substance-use-disorder treatment should assess the separate confidentiality requirements under 42 CFR Part 2 in addition to HIPAA. State privacy rules can be more protective than HIPAA, making state-specific review important for organizations working across jurisdictions. HHS FERPA and HIPAA guidance, HHS Part 2 information, and HHS guidance on more stringent state laws can help identify issues for internal review.

A careful pre-shoot review protects the people whose stories a nonprofit hopes to share. Confirm HIPAA status, map every possible exposure of PHI, obtain appropriate authorization before access occurs, and decide how footage will be handled before recording begins.

Sources / References

HHS: Covered Entities and Business Associates

HHS: Film and Media FAQ

eCFR: 45 CFR 164.508

eCFR: 45 CFR 164.514

HHS: Business Associates

HHS: Guidance on HIPAA and Cloud Computing