Guide

Cameras: lobby maybe, clinical space never

Summary

Security cameras are generally fine in a practice's lobby, waiting room, entrance, and parking area as a safety measure, but clinical space — anywhere a session actually happens — should stay camera- and microphone-free. A recording of treatment is more sensitive than a chart note, undermines informed consent, and turns a security measure into the exact kind of unauthorized capture HIPAA and basic clinical practice both exist to prevent.

By Gale Editorial · Updated 2026-07-27. Every figure cited to a dated source. How we write.

Where cameras are allowed, and where they aren't

Security cameras belong in the common spaces a practice already treats as public-facing — the parking lot, the entrance, the waiting room, the hallway — where their purpose is ordinary property and personal-safety monitoring, not clinical documentation. Once a practice clears the covered-entity test that determines whether HIPAA applies at all, camera placement stops being purely a safety question and becomes a privacy one too, and the line that matters most is simple: nowhere a session actually happens.

  • Parking lot, entrance, hallways — fine as a standard safety measure
  • Waiting room — fine, with attention to what's in frame (see below)
  • Reception desk — fine for security, but keep screens and schedules out of frame
  • Session, exam, or therapy rooms — never
  • Restrooms — never, for the same basic reasons as anywhere else

The test isn't whether a space is technically "clinical" on a floor plan — it's whether a patient reasonably expects privacy there, which a waiting room doesn't carry the same way a closed office door does.

A practice operating out of a shared suite or a building with landlord-installed cameras in common hallways should confirm what those cameras cover and who controls the footage. A landlord's own security system is a separate arrangement the practice doesn't control and generally isn't a business associate of the practice at all — it belongs to the building, not the tenant, and the practice's own camera policy only needs to cover what it installs itself.

Cameras as a Security Rule tool, not just a safety measure

The Security Rule requires physical safeguards controlling access to areas where PHI lives — the front-desk terminal, a server closet, any room holding paper charts — and a camera covering those entry points is one practical way a practice satisfies that requirement, not an unrelated safety purchase 1. Framed this way, camera placement belongs inside the same risk analysis the Security Rule already requires, rather than a decision made without reference to it.

The free risk-assessment tool built for small practices walks through physical-safeguard questions in the same pass as the rest of the security review, and camera coverage of any PHI-storage area is a natural line item to answer while completing it 2.

The front desk and waiting room: what a camera there can and can't capture

A reception-area camera that happens to catch a sign-in sheet or an overheard conversation sits closer to the incidental disclosures the Privacy Rule already tolerates in a busy front office than to a new privacy problem 3. The more avoidable failure is a camera angle that captures a computer screen displaying patient names or a schedule board visible from the waiting room — a foreseeable exposure a practice can simply reframe the camera to avoid, rather than an unfixable one.

Many practices list camera use in common areas among the standard disclosures folded into the npp, alongside the rest of how the practice handles personal information. It isn't the centerpiece of the notice, but naming it there — rather than leaving patients to notice the camera on their own — is a small, easy piece of the same disclosure the notice already exists to provide.

Why clinical and session space stays camera-free

A camera or a microphone in a room where treatment happens converts every session into a recording, and no security purpose justifies that: the space where a patient discloses the most sensitive material of the whole visit is exactly the space that needs the fewest new capture points, not more of them. Recording without the patient's own explicit, session-specific consent also undercuts informed consent for treatment itself — a patient agreeing to therapy did not agree to being filmed doing it.

HIPAA's own hierarchy backs the instinct: the right of access, a patient's ability to obtain their own records, specifically excludes psychotherapy notes from what has to be produced — the strongest protection HIPAA gives any single category of record 4. A continuous recording of the room would function like an unrequested, unprotected version of exactly that kind of material, without any of the legal shielding psychotherapy notes actually carry.

The same logic extends to telehealth: recording a video session requires its own separate, explicit consent, and the platform running the call has to be a HIPAA-compliant arrangement covered by its own agreement, not a personal video-calling app repurposed for clinical use 5.

Third-party monitoring vendors and the BAA question

A cloud-based camera or monitoring service that stores footage off-site is a business associate the moment that footage could reasonably identify who is receiving care at a specific location — simply arriving at a mental health or substance use practice is itself sensitive information, camera footage or not — and the vendor needs a signed BAA before the system goes live, the same as any other vendor touching PHI 6.

Worth confirming with the vendor directly: how long footage is retained, who at the vendor can access it, and whether it's encrypted in storage and in transit. A monitoring contract signed without asking those three questions is a gap that surfaces only when something has already gone wrong.

A consumer smart-home camera — a doorbell camera or an indoor unit bought for personal use — is a common shortcut for a home-based solo practice, and it's worth pausing on before installing one at the office entrance. These systems are built for personal use, sync footage to a personal cloud account by default, and rarely offer a business associate agreement at all. Using one at an entrance that also serves as a home entrance blurs a line that's cleaner to keep separate from the start, either with a dedicated business-grade system or a clearly configured, BAA-covered account kept distinct from any personal one.

When someone asks for the footage

If footage is ever requested — by the subpoena process, a police visit, or an immigration enforcement action at the door — the same disclosure rules that govern any other record apply: a court order authorizes exactly what it specifies and nothing more, while a subpoena without a court order requires satisfactory assurances of notice to the patient or a protective order before anything is handed over 7.

Treating a request for camera footage with the same pause as a request for a chart — confirming what kind of legal process is actually behind it before producing anything — protects the practice from disclosing more than the request actually authorizes.

Keeping a simple log of who has reviewed footage and why — even for routine reasons, like confirming a delivery arrived — builds the same kind of audit trail HIPAA already expects for access to any other protected record. It's a small habit, and it's the difference between a clear answer and a shrug if the footage is ever the subject of a real request.

Common questions

Yes. A waiting room is a common area, not a treatment space, and a camera there for ordinary safety purposes is standard practice. Just keep the frame away from computer screens, schedule boards, or anything else that could display a patient's name or personal information.

Only with the patient's own explicit, session-specific consent, and only on a HIPAA-compliant platform covered by its own business associate agreement — not a personal video app. Supervision recording follows the same rule as any other recording of treatment: consent first, compliant platform always.

Yes, if its cameras or storage could reasonably identify who is receiving care at the practice's location. That's true of most off-site monitoring services covering a health care office, so confirm the BAA is in place before the system goes live, not after.

Confirm what's actually being presented — a warrant, a court order, or a subpoena without one — before producing anything, since each carries different disclosure limits. A court order authorizes only what it specifies; a subpoena without one generally requires notice to the patient or a protective order first.

Generally not, as long as it only captures who walks the hallway and not what's visible or audible inside a session room itself. The concern is capturing treatment, not the fact that a hallway exists — a camera angled to avoid session-room doorways and windows stays on the safe side of that line.

Run your practice on Gale

The software is free. Gale earns one flat 3.5% all-in per paid transaction — only on transactions that actually pay. No subscription, no setup fee, no network cut.

Start or manage a practice →

References

  1. 1.HHS Office for Civil Rights (2026). Summary of the HIPAA Security Rule. U.S. Department of Health and Human Services. linkThat the Security Rule requires physical safeguards controlling facility access to areas holding ePHI, supporting cameras as one tool satisfying that requirement.
  2. 2.Office of the National Coordinator / ASTP (2026). Security Risk Assessment Tool. HealthIT.gov. linkThat ONC/OCR's free risk-assessment tool walks through physical-safeguard questions, supporting camera coverage as a line item within that existing process.
  3. 3.HHS Office for Civil Rights (2026). Summary of the HIPAA Privacy Rule. U.S. Department of Health and Human Services. linkThat the Privacy Rule tolerates certain incidental disclosures in ordinary office operations, supporting the contrast between an incidental camera capture and an avoidable one.
  4. 4.HHS Office for Civil Rights (2026). Individuals' Right under HIPAA to Access their Health Information. U.S. Department of Health and Human Services. linkThat psychotherapy notes are excluded from the patient right of access, supporting the claim that HIPAA treats session content as its most protected category of record.
  5. 5.HHS Office for Civil Rights (2026). HIPAA and Telehealth. U.S. Department of Health and Human Services. linkThat telehealth must run on HIPAA-compliant, BAA-covered arrangements, supporting the claim that recording a telehealth session requires the same compliant-platform standard as any other PHI handling.
  6. 6.HHS Office for Civil Rights (2026). Business Associates. U.S. Department of Health and Human Services. linkThat a vendor storing or handling PHI on the practice's behalf is a business associate requiring a signed BAA, applied to a third-party camera or monitoring service.
  7. 7.HHS Office for Civil Rights (2026). Court Orders and Subpoenas. U.S. Department of Health and Human Services. linkThat HIPAA distinguishes a court order from a subpoena without one, requiring different assurances before disclosure, applied to a request for camera footage.

https://www.gale.care/for-providers/spc-cameras-in-practice · 7 sources. Competitor details are cited to dated public sources and maintained as they change; figures are estimates, not commitments. Synthetic demonstration.

Findability, by specialty

How practices like yours get found in local search and AI answers — the honest playbook, per specialty.

SEO for private practices · SEO for AI search / answer engines (all verticals)