Clinical photography is a valuable tool for physicians. Smartphones, as well as other devices supporting network connectivity, offer a convenient, efficient method to take and share images. However, due to the private nature of the information contained in clinical photographs there are concerns as to the appropriate storage, dissemination, and documentation of clinical images. Confidentiality of image data must be considered and the dissemination of these images onto servers must respect the privacy and rights of the patient. Importantly, patient information should be considered as any information deriving from a patient, and the concepts outlined therefore apply to any media that can be collected on, or transmitted with, a smart-device.
Clinical photography can aid in documenting form and function, in tracking conditions and wound healing, in planning surgical operations, and in clinical decision-making. Additionally, clinical photographs can provide physicians with a valuable tool for patient communication and education. Due to the convenience of this type of technology it is not appropriate to expect physicians to forego their use in providing their patients with the best care available.
The technology and software required for secure transfer, communication, and storage of clinical media is presently available, but many devices have non-secure storage/dissemination options enabled and lack user-control for permanently deleting digital files. In addition, data uploaded onto server systems commonly cross legal jurisdictions. Many physicians are not comfortable with the practice, citing security, privacy, and confidentiality concerns as well as uncertainty in regards to regional regulations governing this practice.1 Due to concern for patient privacy and confidentiality it is therefore incredibly important to limit the unsecure or undocumented acquisition or dissemination of clinical photographs.
To assess the current state of this topic, Heyns et al. have reviewed the accessibility and completeness of provincial and territorial medical regulatory college guidelines.2 Categories identified as vital and explored in this review included: Consent; Storage; Retention; Audit; Transmission; and Breach. While each regulatory body has addressed limited aspects of the overall issue, the authors found a general lack of available information and call for a unified document outlining pertinent instructions for conducting clinical photography using a smartphone and the electronic transmission of patient information.2
The discussion of this topic will need to be ongoing and it is important that physicians are aware of applicable regulations, both at the federal and provincial levels, and how these regulations may impact the use of personal devices. The best practices supported here aim to provide physicians and healthcare providers with an understanding of the scope and gravity of the current environment, as well as the information needed to ensure patient privacy and confidentiality is assessed and protected while physicians utilize accessible clinical photography to advance patient care. Importantly, this document only focusses on medical use (clinical, academic, and educational) of clinical photography and, while discussing many core concepts of patient privacy and confidentiality of information, should not be perceived as a complete or binding framework. Additionally, it is recommended that physicians understand the core competencies of clinical photography, which are not described here.
The Canadian Medical Association (CMA) suggests that the following recommendations be implemented, as thoroughly as possible, to best align with the CMA policy on the Principles for the Protection of Patient Privacy (CMA Policy PD2018-02). These key recommendations represent a non-exhaustive set of best practices - physicians should seek additional information as needed to gain a thorough understanding and to stay current in this rapidly changing field.
* Informed consent must be obtained, preferably prior, to photography with a mobile device. This applies for each and any such encounter and the purpose made clear (i.e. clinical, research, education, publication, etc.). Patients should also be made aware that they may request a copy of a picture or for a picture to be deleted.
* A patient's consent to use electronic transmission does not relieve a physician of their duty to protect the confidentiality of patient information. Also, a patient's consent cannot override other jurisdictionally mandated security requirements.
* All patient consents (including verbal) should be documented. The acquisition and recording of patient consent for medical photography/dissemination may be held to a high standard of accountability due to the patient privacy and confidentiality issues inherent in the use of this technology. Written and signed consent is encouraged.
* Consent should be considered as necessary for any and all photography involving a patient, whether or not that patient can be directly recognized, due to the possibility of linked information and the potential for breach of privacy. The definition of non-identifiable photos must be carefully considered. Current technologies such as face recognition and pattern matching (e.g. skin markers, physical structure, etc.), especially in combination with identifying information, have the potential to create a privacy breach.
* Unsecure text and email messaging requires explicit patient consent and should not be used unless the current gold standards of security are not accessible. For a patient-initiated unsecure transmission, consent should be clarified and not assumed.
* Transmission of photos and patient information should be encrypted as per current-day gold standards (presently, end-to-end encryption (E2EE)) and use only secure servers that are subject to Canadian laws. Explicit, informed consent is required otherwise due to privacy concerns or standards for servers in other jurisdictions. Generally, free internet-based communication services and public internet access are unsecure technologies and often operate on servers outside of Canadian jurisdiction.
* Efforts should be made to use the most secure transmission method possible. For data security purposes, identifying information should never be included in the image, any frame of a video, the file name, or linked messages.
* The sender should always ensure that each recipient is intended and appropriate and, if possible, receipt of transmission should be confirmed by the recipient.
* Storing images and data on a smart-device should be limited as much as possible for data protection purposes.
* Clinical photos, as well as messages or other patient-related information, should be completely segregated from the device's personal storage. This can be accomplished by using an app that creates a secure, password-protected folder on the device.
* All information stored (on internal memory or cloud) must be strongly encrypted and password protected. The security measures must be more substantial than the general password unlock feature on mobile devices.
* Efforts should be made to dissociate identifying information from images when images are exported from a secure server. Media should not be uploaded to platforms without an option for securely deleting information without consent from the patient, and only if there are no better options. Automatic back-up of photos to unsecure cloud servers should be deactivated. Further, other back-up or syncing options that could lead to unsecure server involvement should be ascertained and the risks mitigated.
4. Cloud storage should be on a Canadian and SOCII certified server. Explicit, informed consent is required otherwise due to privacy concerns for servers in other jurisdictions.
5. AUDIT & RETENTION
* It is important to create an audit trail for the purposes of transparency and medical best practice. Key information includes patient and health information, consent type and details, pertinent information regarding the photography (date, circumstance, photographer), and any other important facts such as access granted/deletion requests.
* Access to the stored information must be by the authorized physician or health care provider and for the intended purpose, as per the consent given. Records should be stored such that it is possible to print/transfer as necessary.
* Original photos should be retained and not overwritten.
* All photos and associated messages may be considered part of the patient's clinical records and should be maintained for at least 10 years or 10 years after the age of majority, whichever is longer. When possible, patient information (including photos and message histories between health professionals) should be retained and amalgamated with a patient's medical record. Provincial regulations regarding retention of clinical records may vary and other regulations may apply to other entities - e.g. 90 years from date of birth applies to records at the federal level.
* It may not be allowable to erase a picture if it is integral to a clinical decision or provincial, federal, or other applicable regulations require their retention.
* Any breach should be taken seriously and should be reviewed. All reasonable efforts must be made to prevent a breach before one occurs. A breach occurs when personal information, communication, or photos of patients are stolen, lost, or mistakenly disclosed. This includes loss or theft of one's mobile device, texting to the wrong number or emailing/messaging to the wrong person(s), or accidentally showing a clinical photo that exists in the phone's personal photo album.
* It should be noted that non-identifying information, when combined with other available information (e.g. a text message with identifiers or another image with identifiers), can lead to highly accurate re-identification.
* At present, apps downloaded to a smart-device for personal use may be capable of collecting and sharing information - the rapidly changing nature of this technology and the inherent privacy concerns requires regular attention. Use of specialized apps designed for health-information sharing that help safeguard patient information in this context is worth careful consideration.
* Having remote wipe (i.e. device reformatting) capabilities is an asset and can help contain a breach. However, inappropriate access may take place before reformatting occurs.
* If a smartphone is strongly encrypted and has no clinical photos stored locally then its loss may not be considered a breach.
* In the event of a breach any patient potentially involved must be notified as soon as possible. The CMPA, the organization/hospital, and the Provincial licensing College should also be contacted immediately. Provincial regulations regarding notification of breach may vary.
Approved by the CMA Board of Directors March 2018
i Heyns M†, Steve A‡, Dumestre DO‡, Fraulin FO‡, Yeung JK‡
† University of Calgary, Canada
‡ Section of Plastic Surgery, Department of Surgery, University of Calgary, Canada
1 Chan N, Charette J, Dumestre DO, Fraulin FO. Should 'smart phones' be used for patient photography? Plast Surg (Oakv). 2016;24(1):32-4.
2 Unpublished - Heyns M, Steve A, Dumestre DO, Fraulin FO, Yeung J. Canadian Guidelines on Smartphone Clinical Photography.
These Guidelines constitute an implementation tool of seven recommendations and are informed by Guidelines for CMA’s Activities and Relationships with Other Parties (aka CMA’s Corporate Relationships Policy) and CMA’s Advertising and Sponsorship Policy.
These Guidelines apply to the Canadian Medical Association (and not to its subsidiaries). As these are Guidelines, exceptions may be necessary from time to time wherein staff may use their discretion and judgment.
Endorsement is an umbrella term encompassing “policy endorsement”, “sponsorship1” and “branding”.
Policy endorsement includes:
(a) CMA considering upon request, non-pecuniary public approval, which may include the use of
CMA’s name and/or logo, of an organization’s written policy, on an issue that aligns with CMA policy, where there is no immediate expectation of return; or,
(b) CMA adopting the policy of another organization as our policy; or
(c) CMA asking another organization to publicly support our policy.
(a) Criteria: For policy endorsement requests from another organization to endorse their policy2 the following criteria shall be applied:
i) we have a policy on the subject-matter and
ii) we are actively working on advancing that policy position and
iii) the organization has a follow-up action plan associated with its request.
(b) Approval: Where policy exists, approval requires a policy staff member (with portfolio responsibility) and the VP of Medical Professionalism, or the policy staff member (with portfolio responsibility) and the Chief Policy Advisor. Where no policy exists, approval of the Board of Directors is required.
(c) Annual confirmation: Where CMA adopts the policy of another organization3, CMA staff shall confirm annually, or more frequently if circumstances dictate, that the policy has not been altered by the other organization.
(d) Requests: Pursuit of personal endorsement requests are not appropriate. Wherever possible, requests should come from an organization and not an individual.
(a) Where CMA adopts the policy of another organization, the adopted policy shall become CMA policy, and will include a notation on the document as being an adopted policy of [organization].
(b) All adopted policies will be housed in an accessible searchable database.
(c) All requests by organizations for CMA to endorse their policy will be tracked in a central location, along with any response.
1 Sponsorship means, to consider upon request, pecuniary public approval, which may include the use of CMA’s name and/or logo, of an organization’s event (eg., conference), on an issue that is supported by CMA policy or that promotes CMA brand awareness, where there is an immediate expectation of return.
2 That is, part (a) of the definition in Section 2.
3 That is, part (b) of the definition in Section 2.
Medical professionalism (Update 2005)
The environment in which medicine is practised in Canada is undergoing rapid and profound change. There are now continued opportunities for the medical profession to provide leadership for our patients, our communities and our colleagues through strengthened professionalism. The Canadian Medical Association (CMA) is strongly committed to medical professionalism and has developed this policy both to inform physicians and others about its meaning and value and to promote its preservation and enhancement. This document outlines the major features of medical professionalism, the opportunities which exist in this area and the challenges which lie before us.
Why Medical Professionalism?
The medical profession is characterized by a strong commitment to the well-being of patients, high standards of ethical conduct, mastery of an ever-expanding body of knowledge and skills, and a high level of clinical independence. As individuals, physicians' personal values may vary, but as members of the medical profession they are expected to share and uphold those values that characterize the practice of medicine and the care of patients.
Medical professionalism includes both the relationship between a physician and a patient and a social contract between physicians and society. Society grants the profession privileges, including exclusive or primary responsibility for the provision of certain services and a high degree of self-regulation. In return, the profession agrees to use these privileges primarily for the benefit of others and only secondarily for its own benefit. Three major features of medical professionalism - the ethic of care, clinical independence and self-regulation - benefit physicians, their patients and society:
Ethic of care: This is characterized by the values of compassion, beneficence, nonmaleficence, respect for persons and justice (CMA's Code of Ethics). Society benefits from the ethic of care whereby, in the provision of medical services, physicians put the interests of others ahead of their own. Dedication and commitment to the well-being of others is clearly in the interests of patients, who are the primary beneficiaries.
Clinical independence: Medicine is a highly complex art and science. Through lengthy training and experience, physicians become medical experts and healers. Whereas patients have the right to decide to a large extent which medical interventions they will undergo, they expect their physicians to be free to make clinically appropriate recommendations. Although physicians recognize that they are accountable to patients, funding agencies and their peers for their recommendations, unreasonable restraints on clinical autonomy imposed by governments and administrators, whether public or private, are not in the best interests of patients, not least because they can damage the trust that is an essential component of the patient-physician relationship. Conversely, physicians are not morally obliged to provide inappropriate medical services when requested by patients despite their respect for patient autonomy.
Self-regulation: Physicians have traditionally been granted this privilege by society. It includes the control of entrance into the profession by establishing educational standards and setting examinations, the licensing of physicians, and the establishment and ongoing review of standards of medical practice. In return for this privilege, physicians are expected to hold each other accountable for their behaviour and for the outcomes they achieve on behalf of their patients. Self-regulation is exercised by many different professional organizations, from medical practice partnerships to the statutory provincial/territorial licensing bodies. It has evolved into a partnership with the public. Self-regulation benefits society by taking the best advantage of the professional expertise needed to appropriately set and maintain standards of training and practice, while providing suitable accountability in matters of professional behaviour. The profession's commitment to the maintenance of those standards is demonstrated by its willingness to participate in outcomes review at many levels, from institutional quality assurance activities to formal prospective peer review, and to actively support their statutory and legislated licensing authorities.
Opportunities in Medical Professionalism
Over the past few years much has been written about the issue of medical professionalism in both the lay and scientific media. The practice of medicine has changed considerably, and with these changes have come challenges but also opportunities. The medical profession continues to be a greatly respected one, and it is still generally seen as being distinct from many others because of the unique nature of the physician-patient relationship. There exists now an opportunity to reinforce the professional values and priorities that have sustained medicine for so long, and to embrace new approaches which will serve it well in the years to come.
Medical professionals must recognize that patients have a wide variety of resources available for their health care needs, from traditional physician services to paramedical practitioners, to complementary medicine and to information obtained from the internet. While maintaining responsibility for care of the patient as a whole, physicians must be able to interact constructively with other health care providers within an interdisciplinary team setting, and must be able to interpret information for patients and direct them to appropriate and accurate resources.
The relationship of physicians with their colleagues must be strengthened and reinforced. Patient care benefits when all health care practitioners work together towards a common goal, in an atmosphere of support and collegiality.
Although there are some challenges to professionalism, as outlined below, the greatest opportunity before us may be to remind physicians of the reasons they chose a career in medicine to begin with - for many, it is a calling rather than a job. In spite of the numerous recent changes in the health care system and the practice of medicine, the primary reason most physicians entered the field remains the same - the sanctity of the fiduciary relationship between physicians and their patients. The renewal of medical professionalism must be led from within the profession itself, and the CMA and its members are in a unique position to take advantage of the many opportunities which exist and to respond to the challenges we face.
Challenges to Medical Professionalism
Medical professionalism is being challenged from within and without. These challenges arise from pressures that may serve to undermine the ethic of care, clinical independence and self-regulation and may result, for individual physicians and the medical profession, in diminished morale and changes in lifestyle and practice patterns. These changes may have a detrimental impact on the health of physicians, and also on the quality of patient care.
Resource restraints: The CMA has identified scarcity of resources, whether human or material, as undermining the ability of physicians to maintain excellence in clinical care, research and teaching. Although much attention has been paid recently to the insufficient number of physicians in Canada, and although recent developments indicate some limited cause for optimism, much work remains to be done. Issues of access to continuing professional development, workforce sustainability, inadequate numbers of training positions for new doctors, the integration of foreign-trained physicians into the workforce and the apparent inability of governments to resolve inadequacies in health care funding continue to frustrate physicians' attempts to achieve their professional goals and care for their patients. These factors all have the potential for contributing to the decline of professional morale.
Bureaucratic challenges: This refers to the introduction of layers of management and policy directives between the physician and the patient. It is a result of changes that have taken place in the organization and delivery of medical care, especially the involvement of governments in all aspects of health care. The traditional one-on-one relationship of physician and patient is now set within a context of government and corporate interests, in which the physician may sometimes assume the status of an employee, that pose considerable challenges to the exercise of the professional values of clinical autonomy and self-regulation. Moreover, while the responsibility for organizing the delivery of scarce resources has been increasingly transferred from physicians to managers, physicians are still ultimately responsible, both morally and legally, for providing quality care. Although the increasing complexity of health care delivery requires recourse to sophisticated management systems, there is a danger that as physicians become increasingly answerable to or constrained by third parties, their ability to fulfill their commitment to their individual patients can be seriously compromised.
Unprofessional conduct: Some physicians do not uphold the values of the profession. A few put their interests or the interests of third parties ahead of the interests of their patients. The profession needs to meet this challenge by demonstrating its ability to uphold its values and its commitment to doing so. Supporting strong and transparent self-regulatory systems will be a key component of this endeavor.
Commercialism: In recent years the market mentality has expanded its influence to many areas formerly outside its domain, including governments, universities and the professions. Health care has become a major industry, one in which physicians play a central role, and commercial interests, whether private or public, may pressure physicians to compromise their responsibilities to their patients, research subjects and society. The potential for physicians and medical associations to become drawn into conflict-of-interest situations is increasing. Commercialism may compromise both the ethic of care and clinical independence by its reinterpretation of medical care as a commodity and the patient-physician relationship as something less than a fiduciary relationship. There is an inherent opportunity for the profession to address the issue of conflict of interest and to re-affirm its primary obligation and dedication to the patients it cares for.
Consumerism: Physicians strongly support the right of patients to make informed decisions about their medical care. However, the CMA's Code of Ethics requires physicians to recommend only those diagnostic and therapeutic procedures that they consider to be beneficial to the patient or to others. There is a proliferation of health information and advertising in the popular media and on the Internet that may be inaccurate or poorly understood. Taken to its extreme, consumerism can be detrimental not just to professionalism but to the well-being of patients and the interests of society.
Industrialization: This refers to the increased division and specialization of labour in the delivery of health care, whereby the delivery of health care may become fragmented. There is increasing pressure within medicine to improve efficiency and optimize cost savings. While these may be important goals in the broader context of health care, we must ensure that they do not impact negatively on the doctor-patient relationship.
Realizing Opportunities and Dealing with Challenges
Individual physicians should protect, enhance and promote professionalism in medicine by reflecting the values of the medical profession in their practice and by contributing to the efforts of organized medicine to maintain and enhance the ethic of care, clinical autonomy and self-regulation. These efforts require action in 3 areas: policy, education and self-regulation.
Policy: All those involved in health care - physicians, patients, other health care providers, administrators, governments and the general public (as taxpayers, potential patients, relatives of patients, etc.) - should be informed about the values of the medical profession and where it stands on issue related to accountability, clinical autonomy and self-regulation. Policies of medical associations should reflect these values and should speak clearly on topics such as conflict of interest. Policies should be reviewed frequently and updated when necessary, in order to take account of the rapidly changing environment in which medicine is practiced. The topic of professionalism should be granted increasing importance in policy discussions. Policies should be developed and updated in related areas, such as conflict of interest and physician-industry interactions.
In order to be consistent and trustworthy, medical associations should adhere to the same high standards of behaviour that they require of individual physicians. The challenges posed by resource restraints, bureaucratization, unprofessional conduct, commercialism and consumerism are no less serious for associations than for individuals and require sound harmonized policies for both. The CMA has an opportunity for leadership in this regard.
Education: However professional values and policies are established, they must be transmitted to current and future members of the profession in order to have any effect.
Like most other aspects of medical education, the values of professionalism are both taught and modeled. Professionalism should be an essential component of the formal medical curriculum at the undergraduate and postgraduate training levels. Moreover, active demonstration of professionalism such as role modeling by physicians, and in the internal culture of the medical schools and hospitals where students receive their training, should be used to advantage and challenged when necessary. Likewise for physicians in practice, formal continuing professional development programs and role modeling by other physicians are important for the maintenance of professionalism.
Physicians need to communicate and test their understanding of their professional role with others involved in patient care at numerous levels. Such initiatives, which would engage patients, other professionals and policy-makers, require further development.
The CMA and other medical organizations have taken leadership roles in assisting patients and health care providers in making informed decisions by creating numerous continuing professional development opportunities and readily available clinical information for physicians, effective patient education materials, self-help books and validated Web sites, including www.cma.ca. These efforts need to continue and be strengthened.
Self-regulation: In order to maintain self-regulation in an environment that is increasingly suspicious of such privileges, the medical profession has to demonstrate that self regulation benefits society in general. This requires, among other things, that the medical profession continue to demonstrate its commitment to the tasks required by self-regulation, including setting and enforcing high standards of behaviour for both individual physicians and medical associations.
Physicians continue to value medical professionalism highly. They believe that it benefits patients greatly and that it should be preserved and enhanced. Professionalism will continue to be based on the relationship of trust between patients and physicians, and the primacy of the physician-patient relationship. It encompasses the values of compassion, beneficence, nonmaleficence, respect for persons and justice. As professionals, physicians will strive to maintain high standards of ethics, clinical practice and education and demonstrate a capacity for social responsibility through self-regulation and accountability (see CMA Policy Statement The Future of Medicine).
The CMA welcomes opportunities to engage in dialogue with others as to how professionalism in health care can be preserved and enhanced for the benefit of patients, physicians and society in general.