Are Food Logs and Meal Photos PHI? A HIPAA Guide for Dietitians


Short answer: food logs and meal photos can be protected health information when they are identifiable and are handled by a HIPAA-covered practice or its business associate as part of care or payment. The same information in a consumer’s private notebook or independently chosen app is not automatically PHI under HIPAA. The data, the holder, the relationship, and the purpose all matter.
This article is educational information for US nutrition practices, not legal advice. HIPAA coverage and state-law duties depend on the practice, transaction, contract, location, and workflow. Have qualified counsel or a compliance professional review decisions for your organization.
Do not classify the file by its format. A photo, spreadsheet, chat message, paper diary, and app entry can all carry the same protected information.
Ask four questions:
The HHS summary of the HIPAA Privacy Rule explains that PHI is individually identifiable health information held or transmitted by a covered entity or its business associate in any medium. A diet history, symptom-linked meal record, prescribed nutrition plan, or photograph sent for clinical review can readily fit the health-information part of that definition.
The remaining questions determine whether HIPAA protects it in that specific flow.
| Scenario | Likely HIPAA position | The decisive question |
|---|---|---|
| A person keeps a paper food diary at home and never shares it | Not PHI in a provider’s hands because the provider does not hold it | Has it entered a covered care workflow? |
| A person independently uses a consumer calorie app | Often outside HIPAA for the app, though still sensitive health data | Is the app acting only for the consumer, or for a covered provider? |
| A patient sends an identifiable log or meal photo to a HIPAA-covered dietitian for care | It can be PHI once the covered practice receives or maintains it | Is the practice covered, and is the record identifiable? |
| A covered practice provides or requires an app that processes logs on its behalf | The vendor may be a business associate handling ePHI | Does the vendor create, receive, maintain, or transmit PHI for the practice? |
These are starting points, not legal conclusions. A cash-pay practice is not automatically outside HIPAA, and holding a health credential does not automatically make every service HIPAA-covered. HHS identifies covered providers by both their role and whether they conduct specified electronic transactions. Use the HHS covered-entity guidance to evaluate the practice itself.
A plate of food may look anonymous when viewed alone. Clinical systems rarely store it alone.
The photo may be attached to:
That surrounding context can connect an ordinary-looking image to an identifiable person’s health care. The correct question is not “Can I see a face?” It is “Could this image or its associated information identify the person?”
HHS’s de-identification guidance lists full-face photographs and comparable images among the identifiers removed under the Safe Harbor method. That does not mean every image without a face is automatically de-identified. Safe Harbor addresses a full list of identifiers and also requires no actual knowledge that the remaining information could identify the individual.
HIPAA provides two routes for de-identification:
A practice should not call a dataset “de-identified” merely because staff replaced the client’s name with initials or an internal number. Dates, geographic details, account numbers, device identifiers, full-face images, unique characteristics, and combinations of facts can still identify someone.
For everyday operations, the safer pattern is often not to create an extra copy at all. Keep the original record inside the approved care system and give each team member only the access needed for their role.
HHS says a business associate is a person or organization performing certain functions or services for a covered entity that involve access to PHI. Its business-associate guidance includes data processing, practice management, and other services that can resemble a connected nutrition platform.
A vendor may be acting as a business associate when it stores identifiable food logs for the practice, delivers them to practitioners, analyzes them for the practice, backs them up, or otherwise maintains or transmits them on the practice’s behalf.
If the vendor is a business associate, a Business Associate Agreement is an important requirement—but it is not a compliance certificate.
A BAA does not answer whether:
HHS’s cloud-computing guidance makes the same point: a covered organization must understand the service, conduct its own risk analysis, use the appropriate agreement, and manage the environment in which ePHI is handled.
The relationship can change the answer.
HHS’s health-app and API guidance distinguishes between:
When an individual directs a covered entity to send information to an independent app that is neither a covered entity nor business associate, HIPAA generally does not govern the app’s later use of the received data. When the app is provided by or acts for the covered practice, a business-associate relationship may exist.
This is why “our clients downloaded it themselves” is not a complete analysis. If the practice selected the app, requires it for the service, receives the entries inside a practitioner dashboard, or contracts with the developer, document the actual relationship instead of relying on the app-store category.
Data can fall outside HIPAA and still carry legal duties.
The FTC’s updated Health Breach Notification Rule guidance explains that many health apps and similar products not covered by HIPAA may have notification duties after certain unauthorized disclosures or breaches of identifiable health information. The FTC Act can also apply when a company makes misleading privacy or security promises.
State law may be broader. Washington’s Attorney General describes the My Health My Data Act as protecting consumer health data outside HIPAA and notes that health inferences can be covered. Other states have their own privacy, medical-record, breach, biometric, or consumer-protection rules.
Therefore:
“Not PHI under HIPAA” does not mean “unregulated,” “safe to advertise with,” or “ordinary data.”
Before a practice asks clients to record food or upload images, get written answers to these questions.
Do not accept “HIPAA compliant” as the complete answer. Ask for the architecture, contract, responsibility split, and operational controls behind the phrase. Our broader HIPAA-compliant meal-planning software guide explains how those safeguards fit the rest of a nutrition workflow.
If the care decision only needs meal timing and symptoms, do not require exact calories, a kitchen panorama, or unrelated device data. Collecting less reduces burden and exposure.
Avoid scattering the same meal photo across personal text messages, email, downloads, presentation decks, and staff phones. A connected dietitian client portal can keep the log, message, plan, and practitioner review in one access-controlled workflow.
Tell clients:
The approved app does not protect a screenshot copied into an unapproved chat. Policies should cover downloading, printing, teaching examples, marketing, research, AI tools, and disposal—not just the original system.
Adding image recognition, automated summaries, a new analytics vendor, or a consumer-device integration changes the data flow. HHS treats risk analysis as an ongoing foundation for selecting safeguards, not a one-time purchasing form.
Keep a concise data-flow record showing:
That record is more useful than a folder containing a vendor’s marketing page and an unsigned security checklist.
Food logs can be PHI when they identify a person and are created, received, maintained, or transmitted by a HIPAA covered entity or business associate in connection with health care or payment. A private food diary that stays with a consumer is not automatically PHI under HIPAA.
They can be. A meal photo may be linked to a named patient record, appointment, message, diagnosis, timestamp, location, or other identifying context. Removing a visible face does not by itself establish that a photo or the surrounding record is de-identified.
If a HIPAA covered practice engages the app vendor to create, receive, maintain, or transmit electronic PHI on the practice’s behalf, the vendor may be a business associate and a Business Associate Agreement may be required. The exact relationship and data flow matter.
A consumer app is not automatically subject to HIPAA. If a person independently chooses an app for personal use, HIPAA often does not govern the app’s later handling of the data. FTC rules, state consumer-health laws, privacy promises, and other obligations may still apply.
Not necessarily. HIPAA de-identification requires either a qualified expert’s determination or the Safe Harbor method, including removal of specified identifiers and no actual knowledge that the remaining information could identify the person.
A practical 10-minute food-log review checklist for dietitians: verify the record, scan safety, find patterns, identify barriers, and prepare the next question.
Read →Foodzilla vs NutriAdmin in 2026: compare meal planning, client portals, food logging, practice tools, HIPAA options, and current pricing.
Read →A transparent five-level framework for dietitians to prioritize follow-ups using urgency, care-plan timing, observable changes, barriers, and practitioner review.
Read →See how MealCircle connects plans, patient activity, and follow-up without adding another disconnected tool.