Cameras: lobby maybe, clinical space never
Summary
Security cameras are generally fine in a practice's lobby, waiting room, entrance, and parking area as a safety measure, but clinical space — anywhere a session actually happens — should stay camera- and microphone-free. A recording of treatment is more sensitive than a chart note, undermines informed consent, and turns a security measure into the exact kind of unauthorized capture HIPAA and basic clinical practice both exist to prevent.
By Gale Editorial · Updated 2026-07-27. Every figure cited to a dated source. How we write.
Where cameras are allowed, and where they aren't
Security cameras belong in the common spaces a practice already treats as public-facing — the parking lot, the entrance, the waiting room, the hallway — where their purpose is ordinary property and personal-safety monitoring, not clinical documentation. Once a practice clears the covered-entity test that determines whether HIPAA applies at all, camera placement stops being purely a safety question and becomes a privacy one too, and the line that matters most is simple: nowhere a session actually happens.
- Parking lot, entrance, hallways — fine as a standard safety measure
- Waiting room — fine, with attention to what's in frame (see below)
- Reception desk — fine for security, but keep screens and schedules out of frame
- Session, exam, or therapy rooms — never
- Restrooms — never, for the same basic reasons as anywhere else
The test isn't whether a space is technically "clinical" on a floor plan — it's whether a patient reasonably expects privacy there, which a waiting room doesn't carry the same way a closed office door does.
A practice operating out of a shared suite or a building with landlord-installed cameras in common hallways should confirm what those cameras cover and who controls the footage. A landlord's own security system is a separate arrangement the practice doesn't control and generally isn't a business associate of the practice at all — it belongs to the building, not the tenant, and the practice's own camera policy only needs to cover what it installs itself.
Cameras as a Security Rule tool, not just a safety measure
The Security Rule requires physical safeguards controlling access to areas where PHI lives — the front-desk terminal, a server closet, any room holding paper charts — and a camera covering those entry points is one practical way a practice satisfies that requirement, not an unrelated safety purchase 1Ref 1HHS Office for Civil Rights (2026).Summary of the HIPAA Security Rule.That the Security Rule requires physical safeguards controlling facility access to areas holding ePHI, supporting cameras as one tool satisfying that requirement.. Framed this way, camera placement belongs inside the same risk analysis the Security Rule already requires, rather than a decision made without reference to it.
The free risk-assessment tool built for small practices walks through physical-safeguard questions in the same pass as the rest of the security review, and camera coverage of any PHI-storage area is a natural line item to answer while completing it 2Ref 2Office of the National Coordinator / ASTP (2026).Security Risk Assessment Tool.That ONC/OCR's free risk-assessment tool walks through physical-safeguard questions, supporting camera coverage as a line item within that existing process..
The front desk and waiting room: what a camera there can and can't capture
A reception-area camera that happens to catch a sign-in sheet or an overheard conversation sits closer to the incidental disclosures the Privacy Rule already tolerates in a busy front office than to a new privacy problem 3Ref 3HHS Office for Civil Rights (2026).Summary of the HIPAA Privacy Rule.That the Privacy Rule tolerates certain incidental disclosures in ordinary office operations, supporting the contrast between an incidental camera capture and an avoidable one.. The more avoidable failure is a camera angle that captures a computer screen displaying patient names or a schedule board visible from the waiting room — a foreseeable exposure a practice can simply reframe the camera to avoid, rather than an unfixable one.
Many practices list camera use in common areas among the standard disclosures folded into the npp, alongside the rest of how the practice handles personal information. It isn't the centerpiece of the notice, but naming it there — rather than leaving patients to notice the camera on their own — is a small, easy piece of the same disclosure the notice already exists to provide.
Why clinical and session space stays camera-free
A camera or a microphone in a room where treatment happens converts every session into a recording, and no security purpose justifies that: the space where a patient discloses the most sensitive material of the whole visit is exactly the space that needs the fewest new capture points, not more of them. Recording without the patient's own explicit, session-specific consent also undercuts informed consent for treatment itself — a patient agreeing to therapy did not agree to being filmed doing it.
HIPAA's own hierarchy backs the instinct: the right of access, a patient's ability to obtain their own records, specifically excludes psychotherapy notes from what has to be produced — the strongest protection HIPAA gives any single category of record 4Ref 4HHS Office for Civil Rights (2026).Individuals' Right under HIPAA to Access their Health Information.That psychotherapy notes are excluded from the patient right of access, supporting the claim that HIPAA treats session content as its most protected category of record.. A continuous recording of the room would function like an unrequested, unprotected version of exactly that kind of material, without any of the legal shielding psychotherapy notes actually carry.
The same logic extends to telehealth: recording a video session requires its own separate, explicit consent, and the platform running the call has to be a HIPAA-compliant arrangement covered by its own agreement, not a personal video-calling app repurposed for clinical use 5Ref 5HHS Office for Civil Rights (2026).HIPAA and Telehealth.That telehealth must run on HIPAA-compliant, BAA-covered arrangements, supporting the claim that recording a telehealth session requires the same compliant-platform standard as any other PHI handling..
Third-party monitoring vendors and the BAA question
A cloud-based camera or monitoring service that stores footage off-site is a business associate the moment that footage could reasonably identify who is receiving care at a specific location — simply arriving at a mental health or substance use practice is itself sensitive information, camera footage or not — and the vendor needs a signed BAA before the system goes live, the same as any other vendor touching PHI 6Ref 6HHS Office for Civil Rights (2026).Business Associates.That a vendor storing or handling PHI on the practice's behalf is a business associate requiring a signed BAA, applied to a third-party camera or monitoring service..
Worth confirming with the vendor directly: how long footage is retained, who at the vendor can access it, and whether it's encrypted in storage and in transit. A monitoring contract signed without asking those three questions is a gap that surfaces only when something has already gone wrong.
A consumer smart-home camera — a doorbell camera or an indoor unit bought for personal use — is a common shortcut for a home-based solo practice, and it's worth pausing on before installing one at the office entrance. These systems are built for personal use, sync footage to a personal cloud account by default, and rarely offer a business associate agreement at all. Using one at an entrance that also serves as a home entrance blurs a line that's cleaner to keep separate from the start, either with a dedicated business-grade system or a clearly configured, BAA-covered account kept distinct from any personal one.
When someone asks for the footage
If footage is ever requested — by the subpoena process, a police visit, or an immigration enforcement action at the door — the same disclosure rules that govern any other record apply: a court order authorizes exactly what it specifies and nothing more, while a subpoena without a court order requires satisfactory assurances of notice to the patient or a protective order before anything is handed over 7Ref 7HHS Office for Civil Rights (2026).Court Orders and Subpoenas.That HIPAA distinguishes a court order from a subpoena without one, requiring different assurances before disclosure, applied to a request for camera footage..
Treating a request for camera footage with the same pause as a request for a chart — confirming what kind of legal process is actually behind it before producing anything — protects the practice from disclosing more than the request actually authorizes.
Keeping a simple log of who has reviewed footage and why — even for routine reasons, like confirming a delivery arrived — builds the same kind of audit trail HIPAA already expects for access to any other protected record. It's a small habit, and it's the difference between a clear answer and a shrug if the footage is ever the subject of a real request.
Common questions
Run your practice on Gale
The software is free. Gale earns one flat 3.5% all-in per paid transaction — only on transactions that actually pay. No subscription, no setup fee, no network cut.
Start or manage a practice →References
- 1.HHS Office for Civil Rights (2026). Summary of the HIPAA Security Rule. U.S. Department of Health and Human Services. linkThat the Security Rule requires physical safeguards controlling facility access to areas holding ePHI, supporting cameras as one tool satisfying that requirement.
- 2.Office of the National Coordinator / ASTP (2026). Security Risk Assessment Tool. HealthIT.gov. link ✓That ONC/OCR's free risk-assessment tool walks through physical-safeguard questions, supporting camera coverage as a line item within that existing process.
- 3.HHS Office for Civil Rights (2026). Summary of the HIPAA Privacy Rule. U.S. Department of Health and Human Services. linkThat the Privacy Rule tolerates certain incidental disclosures in ordinary office operations, supporting the contrast between an incidental camera capture and an avoidable one.
- 4.HHS Office for Civil Rights (2026). Individuals' Right under HIPAA to Access their Health Information. U.S. Department of Health and Human Services. linkThat psychotherapy notes are excluded from the patient right of access, supporting the claim that HIPAA treats session content as its most protected category of record.
- 5.HHS Office for Civil Rights (2026). HIPAA and Telehealth. U.S. Department of Health and Human Services. linkThat telehealth must run on HIPAA-compliant, BAA-covered arrangements, supporting the claim that recording a telehealth session requires the same compliant-platform standard as any other PHI handling.
- 6.HHS Office for Civil Rights (2026). Business Associates. U.S. Department of Health and Human Services. linkThat a vendor storing or handling PHI on the practice's behalf is a business associate requiring a signed BAA, applied to a third-party camera or monitoring service.
- 7.HHS Office for Civil Rights (2026). Court Orders and Subpoenas. U.S. Department of Health and Human Services. linkThat HIPAA distinguishes a court order from a subpoena without one, requiring different assurances before disclosure, applied to a request for camera footage.
https://www.gale.care/for-providers/spc-cameras-in-practice · 7 sources. Competitor details are cited to dated public sources and maintained as they change; figures are estimates, not commitments. Synthetic demonstration.