HomeArticlesPatient Care
← Back to Articles

HIPAA and Patient Privacy in Radiography: A Rad Tech's Guide

Why HIPAA Matters for Radiologic Technologists

The Health Insurance Portability and Accountability Act (HIPAA) is not just a compliance checkbox that your hospital's privacy officer worries about — it is a daily, real-world responsibility for every radiologic technologist. Every time you call a patient's name in the waiting room, pull up a patient's imaging history, discuss a case with a colleague, or send an image to the PACS, you are handling Protected Health Information (PHI). One slip — a wrong button click, a conversation overheard in an elevator, a misdirected fax — can lead to a data breach, fines up to $1.5 million per violation year, and, most importantly, a loss of patient trust that takes years to rebuild.

On the ARRT exam, HIPAA and patient privacy questions appear in the Patient Care domain, and they are among the most commonly missed questions because students often assume they "already know" the rules. This guide covers everything you need — from the basics of PHI to real-world scenarios that will test your ethical judgment.

ARRT Exam Tip

The ARRT exam frequently presents scenarios where a rad tech must decide whether an action constitutes a HIPAA violation. The correct answer is almost always the option that protects patient privacy — even if it means inconveniencing a colleague or delaying a process. Remember: when in doubt, protect the patient's information first and verify the policy second.

What Is Protected Health Information (PHI) in Radiography?

Under HIPAA, Protected Health Information (PHI) is any individually identifiable health information — including demographic data — that relates to a patient's past, present, or future physical or mental health, the provision of healthcare, or payment for healthcare. In the imaging department, PHI takes many forms:

A common pitfall for rad techs is forgetting that the patient's mere presence in the radiology department is PHI. If a colleague asks you, "Is Mrs. Jones here for her barium enema?" and you answer in a hallway where others can hear, that disclosure alone may violate HIPAA's privacy rule.

Clinical Reality Check

The "name + anything" rule: Any piece of health information — even just "she's in Room 3" — becomes PHI the moment it is linked to a patient's name or other identifier. Even de-identified exam numbers, if they can be traced back to a specific patient, are PHI. If you wouldn't want your own health information shared in that context, don't share it.

The Minimum Necessary Rule: Access Only What You Need

The minimum necessary standard (45 CFR § 164.502(b) and § 164.514(d)) requires that all healthcare workforce members limit the PHI they access, use, or disclose to the minimum amount necessary to accomplish their intended purpose. For rad techs, this principle governs nearly every action you take:

ARRT Exam Scenario

Sample question: "A rad tech notices that their neighbor is listed on the daily schedule for an MRI. The tech has no role in that patient's care. May the tech open the patient's scheduling information to see what exam is ordered?"

Answer: No. Accessing PHI without a direct need related to patient care or job function violates HIPAA's minimum necessary rule, even if the tech does not share the information with anyone else.

Patient Privacy in the Imaging Department: Physical Environment

Privacy in radiography extends beyond computer screens and file cabinets. The physical layout of an imaging department creates unique privacy challenges that every rad tech must navigate daily.

Waiting Rooms and Registration Desks

Calling patients from the waiting room is a daily privacy test. Avoid calling out the patient's full name along with the exam type (e.g., "John Smith for his barium enema"). Instead, use a first-name-only approach or a number-based system when possible. Registration desks should be positioned so that conversations cannot be overheard by other patients in the queue.

Hallways, Elevators, and Cafeterias

Discussion of patient information in public areas is one of the most common HIPAA violations — and the easiest to prevent. Never discuss patient cases in an elevator, hallway, hospital cafeteria, or any location where unauthorized individuals could overhear. If a colleague stops you in the hallway to ask about a patient, step into a private space such as a control room, consult room, or behind a closed door.

Control Rooms and Workstations

Computer monitors displaying patient information should be positioned so they are not visible to patients, visitors, or unauthorized staff walking by. Use privacy screens and auto-lock features (screen savers that lock after 2–5 minutes of inactivity). Never leave a workstation logged in and unattended — even for "just a second" to grab a cassette or set up a room.

Quick Tip: The "Shoulder Surfing" Check

Before you start working on a patient's images or records, glance over your shoulder. Is anyone — a patient, a visitor, or staff who does not need to know — in a position to see your screen? If yes, angle the monitor, close the door, or wait until you have privacy. This simple habit prevents countless incidental privacy breaches.

Voice, Data, and Digital Security for Rad Techs

Modern radiography runs on digital systems — PACS, RIS, voice dictation, and mobile communication tools. Each of these presents unique privacy and security obligations.

PACS and RIS Security

Every time you query a patient in the RIS or PACS, an audit trail is generated. These audit logs are regularly reviewed by compliance officers. If you access a patient's records without a legitimate clinical reason — even a family member or a celebrity whose images you are "just curious" about — the access will show up in the logs, and you will face disciplinary action, termination, and potentially federal penalties.

Texting and Mobile Communication

Texting patient information (including images) to personal phones is generally not HIPAA-compliant unless the messages are sent through a secure, encrypted platform approved by the facility. Standard SMS is not encrypted in transit and is stored unencrypted on the device. Many departments now use secure messaging apps (e.g., TigerText, Imprivata, or HIPAA-compliant modules within the EMR) for clinical communication. Know your facility's policy and never use personal messaging apps for work-related patient information.

Email and Fax

Unencrypted email containing PHI is a HIPAA violation. If you must email patient information, use a secure portal or encrypted email system. Fax machines remain common in radiology, but they come with their own risks: misdialed numbers, faxes left sitting on the machine, and thermal paper records that are not securely stored. Always double-check the fax number, use a cover sheet that does not contain PHI, and retrieve faxes immediately.

Social Media

Posting patient images, videos, or identifying information on social media — even in "de-identified" form — is an absolute HIPAA violation. This includes sharing interesting cases in private Facebook groups, posting X-ray images for teaching purposes without proper authorization, or even mentioning a notable patient encounter without explicit, written consent. The ARRT has revoked certifications for social media violations.

The "Playground" Rule

A good rule of thumb: if you would not post it on a public billboard with the patient's name attached, do not share it anywhere — including in group chats, departmental emails, or social media. The only acceptable place to discuss a specific patient case is within the context of authorized patient care or a properly de-identified, IRB-approved educational presentation.

Breach Reporting: What to Do When Something Goes Wrong

Despite our best efforts, mistakes happen. A misdirected fax, a patient's chart left in the exam room, or an image sent to the wrong PACS folder — each of these is a potential breach. The key is not the mistake itself, but how you respond to it.

What Constitutes a Breach?

A breach is any unauthorized acquisition, access, use, or disclosure of PHI that compromises the privacy or security of the information. Not every incident is a reportable breach — there is a risk assessment process that evaluates the probability that PHI was actually compromised. However, as a rad tech, you should never self-assess that what happened is "not a big deal." Always report potential breaches through your facility's established incident reporting system.

Immediate Steps After a Potential Breach

  1. Stop and contain: If you realize you have sent information to the wrong recipient, try to retrieve it if possible (e.g., call the misdialed fax recipient and ask them to shred or delete the document)
  2. Notify immediately: Report the incident to your lead technologist, supervisor, or privacy officer — do not wait, do not try to "fix it yourself," and never attempt to cover it up
  3. Document everything: Write down exactly what happened, what information was involved, who was affected, what time it occurred, and what steps you took
  4. Cooperate with the investigation: The facility's privacy office will conduct a risk assessment to determine whether the incident is a reportable breach under HIPAA's Breach Notification Rule

The 60-Day Notification Rule

Under HIPAA, covered entities must notify affected individuals of a breach without unreasonable delay and within 60 days of discovery. If the breach involves more than 500 individuals, the Department of Health and Human Services (HHS) must also be notified, and the incident may be posted on the HHS "Wall of Shame" — a public list of breaches that has cost healthcare organizations hundreds of millions in fines since its inception.

Common HIPAA Violations in Radiography — and How to Avoid Them

Below is a comparison table of the most common HIPAA violations radiologic technologists encounter in clinical practice, along with best-practice prevention strategies.

ViolationExamplePreventionSeverity
Unauthorized access (snooping)Looking up a coworker's imaging results out of curiosityAccess only patients assigned to your care; audit logs are monitoredHigh — termination + fines up to $50,000
Public conversationDiscussing a trauma patient's injuries in the elevatorMove to a private area; use lowered voices when unavoidableModerate — disciplinary action common
Improper disposalThrowing printed patient schedules in the trash without shreddingUse locked shredding bins for all documents with PHIHigh — OCR fines + reputational damage
Misdirected communicationFaxing a report to the wrong number or emailing PHI to wrong recipientDouble-check recipients; use auto-complete cautiously; confirm fax numbersModerate to high — depends on data exposed
Leaving workstation unlockedStep away from a logged-in terminal; stranger views patient dataEnable auto-lock (2–5 min); lock screen manually before walking awayModerate — common cause of breaches
Social media postingPosting an interesting X-ray on Instagram or in a private Facebook groupNever post patient images; obtain IRB approval for educational useHigh — certification revocation possible
Talking to family/visitorsGiving an update on an exam to a family member without patient authorizationRefer family to the radiologist or ordering physician; verify release formsModerate — violation of privacy rule

Real-World Scenarios: Applying HIPAA in the Imaging Department

The best way to prepare for both the ARRT exam and clinical practice is to work through realistic scenarios. Here are situations you may encounter as a rad tech — try to decide the correct course of action before reading the resolution.

Scenario 1: The Curious Colleague

A fellow rad tech asks you to look up a patient's prior MRI report "just to see what the findings showed" because the tech is interested in the case. The tech is not assigned to that patient's care. What do you do?

Resolution: Politely decline and remind your colleague that accessing PHI without a legitimate treatment, payment, or operations (TPO) reason violates HIPAA. If the tech insists, escalate the concern to your supervisor. Both you and the requesting tech could face disciplinary action if you proceed with the unauthorized access.

Scenario 2: The Concerned Family Member

A patient's adult daughter approaches you in the waiting room after her mother's chest X-ray and asks, "Did the X-ray show pneumonia?" How do you respond?

Resolution: You must explain that you are not authorized to interpret images or share results. A polite and HIPAA-compliant response: "I'm sorry, but I'm not able to discuss results. The images will be reviewed by the radiologist, and the report will be sent to your mother's doctor. Please speak with her physician for the results." If the patient has signed a HIPAA release authorizing the daughter to receive information, the radiologist will handle the disclosure.

Scenario 3: The Accidental PACS Error

While processing a portable chest X-ray, you realize the images were sent to the wrong patient's folder in PACS — Patient A's images are now in Patient B's file. What do you do?

Resolution: This is a potential breach. Immediately stop what you are doing, notify your lead technologist or PACS administrator, and do not attempt to delete or move the images yourself (this can corrupt the audit trail). Document the incident, participate in the corrective action, and follow your facility's breach assessment protocol. The key is transparency — covering up the error would be far worse than the original mistake.

Key Takeaways for ARRT Exam Success

1

PHI Is Broad

Any identifier linked to health information — including the patient's name, MRN, exam date, or even their presence in the department — is PHI. Treat every piece of information as protected.

2

Minimum Necessary

Access only what you need for your specific job function. Curiosity does not justify access. Audit logs are regularly reviewed.

3

Public = Prohibited

Never discuss patient cases in hallways, elevators, cafeterias, or waiting rooms. Use private spaces for any conversation involving PHI.

4

Report, Don't Hide

If a breach occurs, report it immediately. Covering up errors leads to far more severe consequences than the original mistake.

5

No Social Media

Patient images and information never belong on social media — even in private groups. The ARRT can revoke your certification for such violations.

About the author: This guide was prepared by the Radiography 101 Clinical Team, referencing the HIPAA Privacy Rule (45 CFR § 160 and § 164), ARRT Standards of Ethics, and current CMS/HHS guidance on patient privacy in imaging. Content is reviewed for clinical and regulatory accuracy.
📝 ARRT Practice Questions

Test Your Knowledge

Try these ARRT-style multiple choice questions based on this article. Click an option to check your answer — correct answers turn green, wrong ones turn red.

1. A radiologic technologist is asked by a colleague to look up a friend's CT scan results "out of curiosity." The colleague is not involved in the friend's care. Which HIPAA principle is the colleague asking the technologist to violate?
✅ Correct!
The minimum necessary standard (45 CFR § 164.502(b)) requires that access to PHI be limited to the minimum necessary to accomplish the intended purpose. Browsing a patient's records "out of curiosity" — even without sharing the information — violates this principle. Audit logs in PACS and RIS systems routinely catch such unauthorized access.
2. While walking to the control room, another technologist stops you in a busy hospital hallway to ask about a patient's previous imaging findings. What is the most appropriate action?
✅ Correct!
Discussing PHI in hallways where unauthorized individuals may overhear is a common HIPAA violation. The correct action is to continue the conversation only in a private, non-public space. Lowering your voice does not eliminate the risk, and writing PHI on paper that could be lost or seen by others is equally problematic.
3. A rad tech accidentally sends a portable chest X-ray to the wrong patient's PACS folder. Which of the following is the correct first step?
✅ Correct!
The correct first step is to notify a supervisor or PACS administrator and document the incident. Attempting to delete or move images yourself can corrupt the audit trail and may be viewed as attempting to conceal a breach. The facility's privacy office will assess whether notification obligations apply under HIPAA's Breach Notification Rule. Transparency and prompt reporting are essential.