The Health Insurance Portability and Accountability Act (HIPAA) is not just a compliance checkbox that your hospital's privacy officer worries about — it is a daily, real-world responsibility for every radiologic technologist. Every time you call a patient's name in the waiting room, pull up a patient's imaging history, discuss a case with a colleague, or send an image to the PACS, you are handling Protected Health Information (PHI). One slip — a wrong button click, a conversation overheard in an elevator, a misdirected fax — can lead to a data breach, fines up to $1.5 million per violation year, and, most importantly, a loss of patient trust that takes years to rebuild.
On the ARRT exam, HIPAA and patient privacy questions appear in the Patient Care domain, and they are among the most commonly missed questions because students often assume they "already know" the rules. This guide covers everything you need — from the basics of PHI to real-world scenarios that will test your ethical judgment.
The ARRT exam frequently presents scenarios where a rad tech must decide whether an action constitutes a HIPAA violation. The correct answer is almost always the option that protects patient privacy — even if it means inconveniencing a colleague or delaying a process. Remember: when in doubt, protect the patient's information first and verify the policy second.
Under HIPAA, Protected Health Information (PHI) is any individually identifiable health information — including demographic data — that relates to a patient's past, present, or future physical or mental health, the provision of healthcare, or payment for healthcare. In the imaging department, PHI takes many forms:
A common pitfall for rad techs is forgetting that the patient's mere presence in the radiology department is PHI. If a colleague asks you, "Is Mrs. Jones here for her barium enema?" and you answer in a hallway where others can hear, that disclosure alone may violate HIPAA's privacy rule.
The "name + anything" rule: Any piece of health information — even just "she's in Room 3" — becomes PHI the moment it is linked to a patient's name or other identifier. Even de-identified exam numbers, if they can be traced back to a specific patient, are PHI. If you wouldn't want your own health information shared in that context, don't share it.
The minimum necessary standard (45 CFR § 164.502(b) and § 164.514(d)) requires that all healthcare workforce members limit the PHI they access, use, or disclose to the minimum amount necessary to accomplish their intended purpose. For rad techs, this principle governs nearly every action you take:
Sample question: "A rad tech notices that their neighbor is listed on the daily schedule for an MRI. The tech has no role in that patient's care. May the tech open the patient's scheduling information to see what exam is ordered?"
Answer: No. Accessing PHI without a direct need related to patient care or job function violates HIPAA's minimum necessary rule, even if the tech does not share the information with anyone else.
Privacy in radiography extends beyond computer screens and file cabinets. The physical layout of an imaging department creates unique privacy challenges that every rad tech must navigate daily.
Calling patients from the waiting room is a daily privacy test. Avoid calling out the patient's full name along with the exam type (e.g., "John Smith for his barium enema"). Instead, use a first-name-only approach or a number-based system when possible. Registration desks should be positioned so that conversations cannot be overheard by other patients in the queue.
Discussion of patient information in public areas is one of the most common HIPAA violations — and the easiest to prevent. Never discuss patient cases in an elevator, hallway, hospital cafeteria, or any location where unauthorized individuals could overhear. If a colleague stops you in the hallway to ask about a patient, step into a private space such as a control room, consult room, or behind a closed door.
Computer monitors displaying patient information should be positioned so they are not visible to patients, visitors, or unauthorized staff walking by. Use privacy screens and auto-lock features (screen savers that lock after 2–5 minutes of inactivity). Never leave a workstation logged in and unattended — even for "just a second" to grab a cassette or set up a room.
Before you start working on a patient's images or records, glance over your shoulder. Is anyone — a patient, a visitor, or staff who does not need to know — in a position to see your screen? If yes, angle the monitor, close the door, or wait until you have privacy. This simple habit prevents countless incidental privacy breaches.
Modern radiography runs on digital systems — PACS, RIS, voice dictation, and mobile communication tools. Each of these presents unique privacy and security obligations.
Every time you query a patient in the RIS or PACS, an audit trail is generated. These audit logs are regularly reviewed by compliance officers. If you access a patient's records without a legitimate clinical reason — even a family member or a celebrity whose images you are "just curious" about — the access will show up in the logs, and you will face disciplinary action, termination, and potentially federal penalties.
Texting patient information (including images) to personal phones is generally not HIPAA-compliant unless the messages are sent through a secure, encrypted platform approved by the facility. Standard SMS is not encrypted in transit and is stored unencrypted on the device. Many departments now use secure messaging apps (e.g., TigerText, Imprivata, or HIPAA-compliant modules within the EMR) for clinical communication. Know your facility's policy and never use personal messaging apps for work-related patient information.
Unencrypted email containing PHI is a HIPAA violation. If you must email patient information, use a secure portal or encrypted email system. Fax machines remain common in radiology, but they come with their own risks: misdialed numbers, faxes left sitting on the machine, and thermal paper records that are not securely stored. Always double-check the fax number, use a cover sheet that does not contain PHI, and retrieve faxes immediately.
Posting patient images, videos, or identifying information on social media — even in "de-identified" form — is an absolute HIPAA violation. This includes sharing interesting cases in private Facebook groups, posting X-ray images for teaching purposes without proper authorization, or even mentioning a notable patient encounter without explicit, written consent. The ARRT has revoked certifications for social media violations.
A good rule of thumb: if you would not post it on a public billboard with the patient's name attached, do not share it anywhere — including in group chats, departmental emails, or social media. The only acceptable place to discuss a specific patient case is within the context of authorized patient care or a properly de-identified, IRB-approved educational presentation.
Despite our best efforts, mistakes happen. A misdirected fax, a patient's chart left in the exam room, or an image sent to the wrong PACS folder — each of these is a potential breach. The key is not the mistake itself, but how you respond to it.
A breach is any unauthorized acquisition, access, use, or disclosure of PHI that compromises the privacy or security of the information. Not every incident is a reportable breach — there is a risk assessment process that evaluates the probability that PHI was actually compromised. However, as a rad tech, you should never self-assess that what happened is "not a big deal." Always report potential breaches through your facility's established incident reporting system.
Under HIPAA, covered entities must notify affected individuals of a breach without unreasonable delay and within 60 days of discovery. If the breach involves more than 500 individuals, the Department of Health and Human Services (HHS) must also be notified, and the incident may be posted on the HHS "Wall of Shame" — a public list of breaches that has cost healthcare organizations hundreds of millions in fines since its inception.
Below is a comparison table of the most common HIPAA violations radiologic technologists encounter in clinical practice, along with best-practice prevention strategies.
| Violation | Example | Prevention | Severity |
|---|---|---|---|
| Unauthorized access (snooping) | Looking up a coworker's imaging results out of curiosity | Access only patients assigned to your care; audit logs are monitored | High — termination + fines up to $50,000 |
| Public conversation | Discussing a trauma patient's injuries in the elevator | Move to a private area; use lowered voices when unavoidable | Moderate — disciplinary action common |
| Improper disposal | Throwing printed patient schedules in the trash without shredding | Use locked shredding bins for all documents with PHI | High — OCR fines + reputational damage |
| Misdirected communication | Faxing a report to the wrong number or emailing PHI to wrong recipient | Double-check recipients; use auto-complete cautiously; confirm fax numbers | Moderate to high — depends on data exposed |
| Leaving workstation unlocked | Step away from a logged-in terminal; stranger views patient data | Enable auto-lock (2–5 min); lock screen manually before walking away | Moderate — common cause of breaches |
| Social media posting | Posting an interesting X-ray on Instagram or in a private Facebook group | Never post patient images; obtain IRB approval for educational use | High — certification revocation possible |
| Talking to family/visitors | Giving an update on an exam to a family member without patient authorization | Refer family to the radiologist or ordering physician; verify release forms | Moderate — violation of privacy rule |
The best way to prepare for both the ARRT exam and clinical practice is to work through realistic scenarios. Here are situations you may encounter as a rad tech — try to decide the correct course of action before reading the resolution.
A fellow rad tech asks you to look up a patient's prior MRI report "just to see what the findings showed" because the tech is interested in the case. The tech is not assigned to that patient's care. What do you do?
Resolution: Politely decline and remind your colleague that accessing PHI without a legitimate treatment, payment, or operations (TPO) reason violates HIPAA. If the tech insists, escalate the concern to your supervisor. Both you and the requesting tech could face disciplinary action if you proceed with the unauthorized access.
A patient's adult daughter approaches you in the waiting room after her mother's chest X-ray and asks, "Did the X-ray show pneumonia?" How do you respond?
Resolution: You must explain that you are not authorized to interpret images or share results. A polite and HIPAA-compliant response: "I'm sorry, but I'm not able to discuss results. The images will be reviewed by the radiologist, and the report will be sent to your mother's doctor. Please speak with her physician for the results." If the patient has signed a HIPAA release authorizing the daughter to receive information, the radiologist will handle the disclosure.
While processing a portable chest X-ray, you realize the images were sent to the wrong patient's folder in PACS — Patient A's images are now in Patient B's file. What do you do?
Resolution: This is a potential breach. Immediately stop what you are doing, notify your lead technologist or PACS administrator, and do not attempt to delete or move the images yourself (this can corrupt the audit trail). Document the incident, participate in the corrective action, and follow your facility's breach assessment protocol. The key is transparency — covering up the error would be far worse than the original mistake.
Any identifier linked to health information — including the patient's name, MRN, exam date, or even their presence in the department — is PHI. Treat every piece of information as protected.
Access only what you need for your specific job function. Curiosity does not justify access. Audit logs are regularly reviewed.
Never discuss patient cases in hallways, elevators, cafeterias, or waiting rooms. Use private spaces for any conversation involving PHI.
If a breach occurs, report it immediately. Covering up errors leads to far more severe consequences than the original mistake.
Patient images and information never belong on social media — even in private groups. The ARRT can revoke your certification for such violations.
Try these ARRT-style multiple choice questions based on this article. Click an option to check your answer — correct answers turn green, wrong ones turn red.