LitharySurgical knowledge, secured
← Blog

June 17, 2026 · Cayvon Morady

Where Surgeons Should Store Operative Photos

Most operative photos live on a personal phone, in a group text, or buried in a consumer notes app. None of those tools were built to hold patient images.

Operative photos should be stored in a system with a Business Associate Agreement, encryption, role-based access, full audit logging, and a way to remove patient identifiers before an image becomes searchable or shareable. A camera roll has none of that. The answer is not to stop capturing images. It is to capture them somewhere designed to support compliance from the first tap.

Where operative photos actually live today

Surgeons capture images for good reasons: teaching, follow-up comparison, morbidity and mortality review, and remembering how a difficult case was handled. The capture is easy. The storage is the problem.

In practice, those images end up in a personal camera roll, an AirDrop to a colleague, a group text, an email to self, or a consumer notes app. Each one is fast. None of them is governed. The moment a patient image lands in a personal photo library, it usually syncs to a personal cloud account that was never meant to hold protected health information.

Why the camera roll fails

A consumer phone and the apps on it were not designed for clinical images, and the gaps are specific:

  • No Business Associate Agreement. Personal cloud backups and messaging apps do not sign a BAA for your patient images.

  • No audit trail. There is no record of who viewed, copied, or forwarded an image.

  • No access controls. Anyone with the phone, or the thread, has the image.

  • Hidden identifiers. Wristbands, monitors, paperwork, and tattoos routinely sit in the frame, even when the face is out of view.

  • Uncontrolled copies. Once an image is texted or emailed, every recipient holds a permanent copy you cannot revoke.

This is a governance and exposure gap, not a moral failing. Surgeons reach for these tools because nothing better was built for them.

What secure operative photo storage should look like

A system that is safe to hold operative images should meet a short, non-negotiable list:

  • A BAA with any vendor that touches the images

  • Encryption in transit and at rest

  • Role-based access and full audit logging

  • A review step that flags or removes patient identifiers before images become searchable or shareable

  • Controlled sharing with verified colleagues rather than open links

  • Clear ownership that stays with the surgeon

If a tool cannot check those boxes, it should not hold patient photos.

How Lithary handles it

Lithary runs alongside the EHR, not inside it. The EHR remains the legal medical record. Lithary is the surgeon's private, searchable knowledge vault. The model is simple: one dictation, two destinations.

Images in Lithary are first-class knowledge, not loose attachments. When you add a photo, it lands in a governed staging layer that is PHI-capable, access-controlled, audit-logged, and time-bounded. On commit, an automated PHI scrub runs. High-confidence identifiers block the commit until they are resolved, and you confirm no visible identifiers remain. Only reviewed, de-identified content reaches the clean vault, and only clean vault content is searchable or shareable.

Sharing is controlled by design. Cases are shared inside Lithary with verified colleagues only. There are no anonymous public links, every view is logged, and the author can revoke access at any time. The result is a place to keep operative images that is built for healthcare-grade controls rather than retrofitted from a consumer app.

What this means for departments and institutions

When operative knowledge lives in personal camera rolls and text threads, the institution inherits the risk without any of the visibility. A governed vault changes that. Teaching libraries, residency review, and M&M material can be kept and shared without scattering patient images across personal devices, and the audit logging and access controls produce the documentation an institution actually needs.

The point is not to lock surgeons down. It is to give a department a single, governed home for the knowledge its surgeons are already capturing.

The takeaway

Operative knowledge is worth keeping. It should not cost you control of patient data to keep it. The camera roll was never the right place. A system designed to support compliance is.

Frequently asked questions

Is it a HIPAA violation to store operative photos on my phone?

Storing identifiable patient images on a personal device, without safeguards like a BAA, access controls, and audit logging, creates real exposure under HIPAA. Whether a specific situation counts as a violation depends on the facts and your institution's policies. The safer path is a system designed to support compliance. This is general information, not legal advice.

Can I just crop out the patient's face and reuse the photo?

Cropping a face helps, but identifiers hide in the background: wristbands, monitors displaying names or MRNs, paperwork, and distinctive tattoos. De-identification should be deliberate and reviewed, not eyeballed.

How is Lithary different from a cloud photo app?

A consumer photo app stores files. Lithary governs surgical knowledge: a PHI-aware staging layer, an automated PHI scrub on commit, a clean vault, controlled sharing with verified surgeons, and full audit logging. It is built for clinical images, not vacation photos.

Does Lithary replace my EHR?

No. The EHR remains the legal medical record. Lithary runs alongside it as a private, searchable surgical knowledge vault.