Ask a dermatology practice manager whether the practice's photos are backed up and the answer is almost always yes. Ask where the photos are, and the answer gets less certain.
That gap is where we find most of the risk in dermatology IT. The EHR is usually fine. The images that live around it often aren't.
Where photos actually live
In a typical practice, clinical images pass through several places before they end up where they belong:
- The camera or phone that took the picture, until someone clears the card
- The imaging workstation where photos are imported, cropped and renamed
- A separate imaging or total-body photography system, with its own storage and its own database
- A network share where someone saved a batch "for now" three years ago
- The EHR, if the import step was completed
- A staff member's phone or email, because it was faster that day
Only the last one, the EHR, is reliably covered by most backups. The rest depend on whether someone set them up on purpose.
Why "we have a backup" isn't enough
We see the same three problems again and again:
- The backup covers the server, not the imaging PC. Thousands of photos sit on one workstation's local drive. When that drive fails, they're gone.
- The backup has never been restored. It reports success every night. Nobody has tried to get a photo back out of it, so nobody knows whether it works.
- The backup can be encrypted by ransomware. If the backup drive is plugged into the same network with the same logins, an attack that encrypts the practice's files will encrypt the backup too.
Any one of these can cost a practice years of before-and-after history, which is hard to explain to a cosmetic patient and harder to explain to an auditor.
A setup that actually protects images
You don't need anything exotic. You need every image to end up in one known place, and that place to be backed up properly.
1. One path from camera to storage. Photos go from the device into the EHR or the imaging system automatically or the same day, with a documented step. Camera cards are cleared on a schedule. Nothing stays on a personal phone.
2. Image storage sized for growth. Total-body photography and dermoscopy create large files. Storage that's 90% full is a problem waiting to happen; plan for at least two years of growth.
3. Three copies, two kinds of storage, one off-site. A local copy for fast restores, and an off-site copy that's encrypted and kept by a provider who signs a Business Associate Agreement.
4. Immutable backups. At least one copy that can't be changed or deleted for a set number of days, even by an administrator. That's what survives ransomware.
5. Restore tests on a schedule. Pick a random patient and a random date each month and restore their images. Write down how long it took. That's the only proof a backup works.
6. Monitoring. Someone gets alerted when a backup fails or an imaging workstation's disk starts going bad, rather than finding out the day it dies.
Questions to ask your IT provider this week
- Which machines in our practice hold patient images today?
- Is every one of them in the backup?
- When did we last restore a photo from backup, and how long did it take?
- Could ransomware on our network delete or encrypt our backups?
- Who has signed a BAA for our off-site backup?
If the answers are vague, that's your answer.
How we handle it
We support more than ten dermatology and aesthetic practices across Southwest Florida. Every one has its clinical images in a tested, encrypted, immutable backup, separate from general file backup, and we confirm restores on a schedule instead of assuming they work. See how we support dermatology practices, or book a 15-minute call and we'll tell you where your photos really are.




