Session recordings in the wrong cloud

Video of a child's session is the most sensitive thing your clinic produces. Where it actually lives, why the personal Drive folder is a violation nobody committed on purpose, and how to build a lawful path from camera to storage.

Last verified: 2026-07-12

Recording is good clinical practice. A BCBA reviews a session she did not attend. A team calibrates on what the behavior actually looked like. A parent sees the strategy work. Fidelity checks, supervision hours, training a new RBT: video does things a data sheet cannot.

And then the video needs to go somewhere, and that is where clinics quietly break. Because the tool that captured it was a phone, and the place it went was wherever that phone syncs.

What a recording is, legally

It is PHI (45 CFR 160.103), which is not the interesting part. The interesting part is that it is PHI you cannot strip down.

The safe harbor for de-identification requires removing eighteen categories of identifier, and two of them are sitting in every frame: full-face photographic images and comparable images, and biometric identifiers, which include voice prints (45 CFR 164.514(b)(2)). A session video is a face and a voice, usually with a name spoken aloud in the first minute and a family’s living room in the background. There is no practical way to de-identify it. It stays PHI, in the most identifiable form your clinic ever handles.

Say the quiet part: a video of a child in a hard moment is not a data point. It is the most exposing artifact your clinic will ever produce, and it usually lives in the worst place.

Where it actually goes

The camera roll, again. An RBT records on a phone. The phone’s photo library syncs to a personal cloud account within seconds, automatically, because that is what phones do. Nobody chose this. The camera roll is the leak in every one of these articles, and video is the payload that makes it worst.

“A video of a child in a hard moment is not a data point. It is the most exposing artifact your clinic will ever produce, and it usually lives in the worst place.”

The personal Drive or Dropbox folder. A supervisor collects clips for review and puts them somewhere convenient. That cloud provider now maintains PHI on your behalf, which makes it a business associate (45 CFR 160.103) that must be under a signed BAA before the data arrives (45 CFR 164.502(e)). A personal consumer account has no BAA and cannot have one. The disclosure was impermissible the moment the file finished uploading, and no one in the building did anything they thought was wrong.

The messaging thread. A clip texted or WhatsApped to a BCBA for a quick opinion is a transmission of ePHI over a channel with no agreement behind it (45 CFR 164.312(e)), and it now rests on two phones, two backups, and a vendor’s servers.

The laptop desktop, forever. Clips downloaded for a training that happened in 2023, never deleted, on a machine that may or may not be encrypted, that will someday be reassigned or sold. That is the disposal and media re-use problem (45 CFR 164.310(d)(2)), and it is the one that surfaces years later.

The pattern is the same every time: the capture device and the storage decision were never designed to be connected, so the default settings connected them for you.

Build one lawful path, and make it the easy one

The fix is not a rule telling people not to do the convenient thing. It is making the compliant thing the convenient thing.

Capture inside the system, not on the camera. If your practice management or data platform supports recording, that is your capture tool, and it stores to a BAA-covered system directly. If capture must happen on a device, it happens inside an app that writes to that system and never to the device’s photo library. No exceptions, because the exception is the whole failure.

One storage destination, under a BAA. Whatever it is, it is one place, it is covered by a signed agreement, it is access-controlled by role (the RBT sees her own clients, not the caseload), and it is encrypted at rest. If you must use general-purpose cloud storage, it is the business tier of a provider that signs a BAA, configured as a clinic account, never a personal one.

Delete on a schedule you actually run. A recording is useful for a defined window: the fidelity check, the supervision cycle, the training. HIPAA does not require you to keep clinical video forever, and the safest video is the one that no longer exists. Set a retention period, write it down, and enforce it, because every clip you keep past its usefulness is exposure with no upside. Note the distinction that trips people: the six-year rule at 45 CFR 164.316(b) governs your compliance documentation, not your clinical media, and it is not a reason to hoard video.

Kill the shadow copies. The clip on the laptop, the export in the download folder, the version in the messaging thread. One path means one copy in one place; every extra copy is a device-and-media problem waiting for its own bad day.

Treatment documentation may fall under your permitted uses, but recording a child in a family’s home reaches past HIPAA into state recording-consent law, which varies by state and this page will not guess yours. What holds up everywhere is written parental consent that is specific rather than ceremonial: what is recorded, why, where it is stored, who can view it, how long it is kept, and how consent can be withdrawn.

And when the recording is for anything beyond treatment, payment, and operations, a training video for new staff, a conference presentation, a marketing clip, that is a different legal act and it requires an authorization (45 CFR 164.508), not the intake consent. The distinction matters and clinics routinely miss it: the clip that was fine for supervision is not automatically fine for the website, and the parent who agreed to one did not agree to the other.

The test

Ask the question you can answer today, without a lawyer: if a parent asked right now to see every recording of their child and be told exactly where each copy is stored, could you answer?

If the honest answer involves a pause, a personal Google account, and a hope that someone deleted a text thread, that is the finding. Not a scandal, not negligence, just the default settings of the tools your clinicians hold, doing what they were designed to do, with the most sensitive material in your clinic.

The short version

  • Session video is PHI, and it is PHI with a face and a voice attached: the safe-harbor de-identification list treats both as identifiers, so recordings cannot be meaningfully de-identified.
  • The cloud that stores it is a business associate and needs a BAA; a personal Drive, iCloud, or consumer Dropbox account has none.
  • The camera roll is the leak: a phone recording syncs to a personal cloud within seconds, with no decision made by anyone.
  • Build one lawful path from capture to storage, make it easier than the shortcut, and delete on a retention schedule you actually enforce.
  • State recording-consent law sits on top of HIPAA and varies; get written parental consent that says what is recorded, why, where it is stored, who sees it, and how long it is kept.

This article is educational information about the HIPAA regulations, not legal advice. It describes what the rules say; it does not tell you what to do about your specific situation, and reading it does not create an attorney-client or consultant-client relationship. Regulations change, and enforcement positions change with them. For advice on your clinic, talk to a qualified professional.

Sources

One path from camera to storage.

Recordings are the artifact with the least margin for error. WiseUpHIPAA holds the vendors, the consents, and the retention decisions behind them, and shows you honestly where the recordings actually live.