Privacy in the Room
Beyond HIPAA: what patients notice, what regulators enforce, and what good practice looks like.
8 min readUpdated May 2, 20262 topics
Layers of privacy
Patient privacy in the room is layered:
- Physical — curtains, doors, sightlines, sound isolation.
- Informational — who can see the chart, screen orientation, printer placement.
- Observational — cameras, microphones, wearables, and RTLS badges.
Programs that treat all three explicitly, with signage and consent, avoid most objections.
Consent in practice
The Fair Information Practice Principles (FIPPs) map cleanly onto in-room technology:
- Notice — clear signage at the door.
- Choice — a documented off-switch or hardware disable.
- Access — patients can ask what is recorded and for how long.
- Integrity — data retention windows, deletion on discharge as appropriate.
- Accountability — a named privacy officer with a public contact channel.
Standards
- HIPAA Privacy Rule (45 CFR Part 164 Subpart E).
- NIST Privacy Framework.
- FTC Fair Information Practice Principles.
- ISO/IEC 27701 — privacy information management.
- OCR guidance on audio and video recording of patients.
References & further reading
- 145 CFR Part 164 Subpart E — HIPAA Privacy Rule
- 2NIST Privacy Framework v1.0
- 3ISO/IEC 27701:2019 Privacy information management system
Help us improve
Spotted something wrong, outdated, or unclear? Let the editors know.
Continue reading