Founding cohort openLock in founding member pricing while spots are available.
Compliance · 11 min read

Are Food Logs and Meal Photos PHI? A HIPAA Guide for Dietitians

Are Food Logs and Meal Photos PHI? A HIPAA Guide for Dietitians article illustration

Short answer: food logs and meal photos can be protected health information when they are identifiable and are handled by a HIPAA-covered practice or its business associate as part of care or payment. The same information in a consumer’s private notebook or independently chosen app is not automatically PHI under HIPAA. The data, the holder, the relationship, and the purpose all matter.

This article is educational information for US nutrition practices, not legal advice. HIPAA coverage and state-law duties depend on the practice, transaction, contract, location, and workflow. Have qualified counsel or a compliance professional review decisions for your organization.

The four questions that determine whether a food log is PHI

Do not classify the file by its format. A photo, spreadsheet, chat message, paper diary, and app entry can all carry the same protected information.

Ask four questions:

  1. Is it health information? Does it relate to a person’s health, care, or payment for care?
  2. Is the person identifiable? Does the record identify them directly, or is there a reasonable basis to believe it could?
  3. Who holds or transmits it? Is that party a HIPAA covered entity or business associate?
  4. Why are they handling it? Are they acting for the person’s care, payment, or another covered function?

The HHS summary of the HIPAA Privacy Rule explains that PHI is individually identifiable health information held or transmitted by a covered entity or its business associate in any medium. A diet history, symptom-linked meal record, prescribed nutrition plan, or photograph sent for clinical review can readily fit the health-information part of that definition.

The remaining questions determine whether HIPAA protects it in that specific flow.

Four common food-logging scenarios

Scenario Likely HIPAA position The decisive question
A person keeps a paper food diary at home and never shares it Not PHI in a provider’s hands because the provider does not hold it Has it entered a covered care workflow?
A person independently uses a consumer calorie app Often outside HIPAA for the app, though still sensitive health data Is the app acting only for the consumer, or for a covered provider?
A patient sends an identifiable log or meal photo to a HIPAA-covered dietitian for care It can be PHI once the covered practice receives or maintains it Is the practice covered, and is the record identifiable?
A covered practice provides or requires an app that processes logs on its behalf The vendor may be a business associate handling ePHI Does the vendor create, receive, maintain, or transmit PHI for the practice?

These are starting points, not legal conclusions. A cash-pay practice is not automatically outside HIPAA, and holding a health credential does not automatically make every service HIPAA-covered. HHS identifies covered providers by both their role and whether they conduct specified electronic transactions. Use the HHS covered-entity guidance to evaluate the practice itself.

Why a meal photo can be PHI without showing a face

A plate of food may look anonymous when viewed alone. Clinical systems rarely store it alone.

The photo may be attached to:

  • a named patient profile;
  • a message thread with a practitioner;
  • a date, appointment, or meal-plan assignment;
  • symptoms, glucose readings, allergies, or diagnoses;
  • location or device information;
  • a recognizable home, workplace, prescription label, face, or document in the frame.

That surrounding context can connect an ordinary-looking image to an identifiable person’s health care. The correct question is not “Can I see a face?” It is “Could this image or its associated information identify the person?”

HHS’s de-identification guidance lists full-face photographs and comparable images among the identifiers removed under the Safe Harbor method. That does not mean every image without a face is automatically de-identified. Safe Harbor addresses a full list of identifiers and also requires no actual knowledge that the remaining information could identify the individual.

Removing the name is not enough

HIPAA provides two routes for de-identification:

  1. Expert Determination: a person with appropriate statistical and scientific expertise determines and documents that the identification risk is very small.
  2. Safe Harbor: specified identifiers are removed, and the covered entity has no actual knowledge that the remainder could identify the person.

A practice should not call a dataset “de-identified” merely because staff replaced the client’s name with initials or an internal number. Dates, geographic details, account numbers, device identifiers, full-face images, unique characteristics, and combinations of facts can still identify someone.

For everyday operations, the safer pattern is often not to create an extra copy at all. Keep the original record inside the approved care system and give each team member only the access needed for their role.

When a food-logging vendor may be a business associate

HHS says a business associate is a person or organization performing certain functions or services for a covered entity that involve access to PHI. Its business-associate guidance includes data processing, practice management, and other services that can resemble a connected nutrition platform.

A vendor may be acting as a business associate when it stores identifiable food logs for the practice, delivers them to practitioners, analyzes them for the practice, backs them up, or otherwise maintains or transmits them on the practice’s behalf.

If the vendor is a business associate, a Business Associate Agreement is an important requirement—but it is not a compliance certificate.

A BAA does not answer whether:

  • the practice configured access correctly;
  • staff use approved accounts and devices;
  • data are sent through unapproved email or chat;
  • exports remain on personal laptops;
  • the practice has completed its risk analysis;
  • retention and deletion match policy;
  • the vendor’s subcontractors and incident process are acceptable.

HHS’s cloud-computing guidance makes the same point: a covered organization must understand the service, conduct its own risk analysis, use the appropriate agreement, and manage the environment in which ePHI is handled.

What if the client chooses the app?

The relationship can change the answer.

HHS’s health-app and API guidance distinguishes between:

  • an app independently selected by the individual to receive their information; and
  • an app developed, provided, or used on behalf of a covered entity.

When an individual directs a covered entity to send information to an independent app that is neither a covered entity nor business associate, HIPAA generally does not govern the app’s later use of the received data. When the app is provided by or acts for the covered practice, a business-associate relationship may exist.

This is why “our clients downloaded it themselves” is not a complete analysis. If the practice selected the app, requires it for the service, receives the entries inside a practitioner dashboard, or contracts with the developer, document the actual relationship instead of relying on the app-store category.

HIPAA is not the only health-data law

Data can fall outside HIPAA and still carry legal duties.

The FTC’s updated Health Breach Notification Rule guidance explains that many health apps and similar products not covered by HIPAA may have notification duties after certain unauthorized disclosures or breaches of identifiable health information. The FTC Act can also apply when a company makes misleading privacy or security promises.

State law may be broader. Washington’s Attorney General describes the My Health My Data Act as protecting consumer health data outside HIPAA and notes that health inferences can be covered. Other states have their own privacy, medical-record, breach, biometric, or consumer-protection rules.

Therefore:

“Not PHI under HIPAA” does not mean “unregulated,” “safe to advertise with,” or “ordinary data.”

A procurement checklist for food-log and meal-photo software

Before a practice asks clients to record food or upload images, get written answers to these questions.

Relationship and contract

  1. Will the vendor act for the practice or only for the individual user?
  2. Will it sign an appropriate BAA when required?
  3. Which subprocessors can create, receive, maintain, or transmit the data?
  4. Do the contract and privacy notice match the product’s actual data flow?

Data use

  1. Is client content used to train, evaluate, or improve any model?
  2. Is it used for advertising, profiling, analytics, or unrelated product development?
  3. Can the practice turn optional uses off?
  4. Does the vendor collect metadata beyond what care requires?

Safeguards and access

  1. Is data encrypted in transit and at rest?
  2. Are practitioner and patient roles separated?
  3. Does the product support strong authentication and prompt account removal?
  4. Can the practice review an audit trail for access, export, and material changes?

Retention, portability, and incidents

  1. How can the practice export the complete record in a usable form?
  2. What is deleted after account closure, from which systems, and on what schedule?
  3. What backups remain and when do they expire?
  4. How and when will the vendor report a security or privacy incident?

Do not accept “HIPAA compliant” as the complete answer. Ask for the architecture, contract, responsibility split, and operational controls behind the phrase. Our broader HIPAA-compliant meal-planning software guide explains how those safeguards fit the rest of a nutrition workflow.

A safer workflow for dietitians

1. Define the purpose before collecting the data

If the care decision only needs meal timing and symptoms, do not require exact calories, a kitchen panorama, or unrelated device data. Collecting less reduces burden and exposure.

2. Keep the record in one approved system

Avoid scattering the same meal photo across personal text messages, email, downloads, presentation decks, and staff phones. A connected dietitian client portal can keep the log, message, plan, and practitioner review in one access-controlled workflow.

3. Explain the boundaries to clients

Tell clients:

  • what to record;
  • why the practice needs it;
  • who can see it;
  • how it will be used;
  • what not to include in the frame;
  • where urgent concerns should be directed;
  • how to request access, correction, or deletion where applicable.

4. Train staff on exports and secondary use

The approved app does not protect a screenshot copied into an unapproved chat. Policies should cover downloading, printing, teaching examples, marketing, research, AI tools, and disposal—not just the original system.

5. Reassess when the workflow changes

Adding image recognition, automated summaries, a new analytics vendor, or a consumer-device integration changes the data flow. HHS treats risk analysis as an ongoing foundation for selecting safeguards, not a one-time purchasing form.

What should a practice document?

Keep a concise data-flow record showing:

  • what clients submit;
  • where it enters the system;
  • which entities receive or store it;
  • the purpose and permitted uses;
  • the applicable agreements;
  • roles and access levels;
  • retention, backup, export, and deletion behavior;
  • incident contacts and escalation steps;
  • the date of the last review.

That record is more useful than a folder containing a vendor’s marketing page and an unsigned security checklist.

Frequently Asked Questions (FAQs)

Are food logs protected health information under HIPAA?

Food logs can be PHI when they identify a person and are created, received, maintained, or transmitted by a HIPAA covered entity or business associate in connection with health care or payment. A private food diary that stays with a consumer is not automatically PHI under HIPAA.

Are meal photos PHI even when they do not show a face?

They can be. A meal photo may be linked to a named patient record, appointment, message, diagnosis, timestamp, location, or other identifying context. Removing a visible face does not by itself establish that a photo or the surrounding record is de-identified.

Does a dietitian need a BAA with a food-logging app?

If a HIPAA covered practice engages the app vendor to create, receive, maintain, or transmit electronic PHI on the practice’s behalf, the vendor may be a business associate and a Business Associate Agreement may be required. The exact relationship and data flow matter.

Is a consumer calorie-tracking app HIPAA compliant?

A consumer app is not automatically subject to HIPAA. If a person independently chooses an app for personal use, HIPAA often does not govern the app’s later handling of the data. FTC rules, state consumer-health laws, privacy promises, and other obligations may still apply.

Does removing a client’s name make a food log de-identified?

Not necessarily. HIPAA de-identification requires either a qualified expert’s determination or the Safe Harbor method, including removal of specified identifiers and no actual knowledge that the remaining information could identify the person.

Sources reviewed

Related articles

Turn the idea into a calmer care workflow.

See how MealCircle connects plans, patient activity, and follow-up without adding another disconnected tool.

See who needs you today. Free to start · no card.Book a demoStart free