Skip to content
  • About Us
    • Who We Serve
  • Solutions
    • HIPAA for Covered Entities
    • OSHA for Healthcare
    • HIPAA for Business Associates
    • SRA for Covered Entities
    • Abyde Incident Response Program
    • Abyde Reseller Program
  • Resources
  • News
  • Events
  • Partners
  • Contact Us
  • Login
    • HIPAA for Covered Entities
    • OSHA for Healthcare
    • HIPAA for Business Associates
    • SRA for Covered Entities
SIGN UP
BOOK A DEMO

OSHA in Dermatology: Best Practices to Achieve Compliance

June 12, 2025

 

While working in a dermatology office might have you focused on taking care of your patients’ skin, your health should be the first priority. 

It’s easy to incorrectly assume a dermatology office is a relatively “safe” healthcare environment. After all, we’re not typically dealing with the same acute emergencies as an ER. Dermatology presents many challenges when working with patients, such as lasers, sharp instruments, chemicals, potential exposure to bloodborne pathogens, and more. 

With these unique challenges, your practice must be aware of the safeguards the Occupational Safety and Health Administration (OSHA) requires.

 

More than Skin Deep: Facility Risk Assessment

An annual Facility Risk Assessment (FRA) is the foundation of your OSHA compliance program. The FRA is a thorough assessment of the healthcare hazards your practice might face. This assessment spans from your staff is trained, to unique equipment you might use, how situations are prevented, and even how management handles workplace safety.

Since this is an annual requirement, this assessment must be kept current. If your practice introduces anything new that might heighten risk, this needs to be documented. For instance, if your practice begins offering laser treatments, this must be mentioned in the FRA and also staff must be trained on how to use it safely. 

By reviewing and addressing potential vulnerabilities in your practice, you can mitigate risks and ultimately keep patients safe. 

 

Personal Protective Equipment (PPE) in Dermatology: Your First Line of Defense

While you advise patients on sun protection, remember that your staff’s skin needs protection, too. Always ensure that it remains covered with Personal Protective Equipment (PPE).

PPE, like gloves and masks, are essential barriers that keep your team safe. Your practice must supply this PPE and provide comprehensive training on how to use it correctly. 

For instance, when a staff member is with a patient, a new set of gloves is always required. From putting them on to how they must be disposed of, these are all critical ways to keep staff members safe. 

Depending on the treatment, your staff may also need eye protection. As a result, it’s essential to review all available forms of PPE with staff before they start working with patients. 

 

Dermatology Laser Safety

When it comes to lasers in your dermatology practice, preparation is paramount. 

It’s not enough to just have the equipment; you need to ensure every team member is properly trained and fully aware of the risks associated with these powerful devices. Once again, proper PPE is vital, such as eyewear and gloves. Additionally, the room where the laser is being used must adhere to safety guidelines, including not having any reflective surfaces for the laser to shine off. 

Your practice should designate a Laser Safety Officer to oversee and enforce compliance. This staff member is likely already your OSHA Safety Officer, or OSO. This Laser Safety Officer needs to ensure staff is routinely trained on lasers, especially if new equipment is being used. 

For staff safety, the laser device must be off when not in use. 

While laser treatments offer dermatologists innovative possibilities, proper staff training always remains crucial. 

 

Keeping Your Dermatology Practice Safe

Ensuring the safety of your dermatology practice is not just about compliance; it’s about fostering a secure environment for both your dedicated staff and your valued patients. 

Your practice can proactively address potential hazards by diligently conducting annual facility risk assessments, consistently utilizing appropriate personal protective equipment, and prioritizing comprehensive training. 

With the right solution, your practice can streamline these requirements. Smart software can utilize the answers from your FRA and provide thorough policies and procedures and recommended training. A safe practice is a successful practice. 

To see how you can streamline compliance for your practice, schedule a meeting with a compliance expert today.

RECENT POSTS

  • OSF Healthcare HIPAA Settlement
    What OSF Healthcare's Ransomware Fine Teaches Every Practice About SRAs
  • Spencer Gifts HIPAA Fine
    Spencer Gifts HIPAA Settlement: Ransomware, Risk Analysis, and What Comes Next
  • OCR Ransomware Settlements
    OCR Ransomware Settlements: 4 Massive HIPAA Fines from April 2026 & How to Avoid Them
PrevPreviousDermatology’s Hidden Layer: Unpacking HIPAA Compliance
NextOSHA’s Rapid Response: Why Every Practice Needs a Safety CultureNext

Related posts

OSHA 2026 GHS Deadlines
Abyde News, Legislation, OSHA

2026 OSHA HazCom Deadlines: How the GHS Update Impacts Your Practice

March 23, 2026 Penelope Schweitzer No comments yet

March 23, 2026   Quick Guide: 2026–2028 OSHA HazCom Deadlines (as of March 2026) May 19, 2026: Deadline for manufacturers to update labels for pure substances. Nov 20, 2026: Deadline for practices to update written HazCom programs and staff training for substances. May 19, 2028: Final deadline for practices to be fully compliant for all mixtures (disinfectants, resins, etc.). If you came here after hearing that a major OSHA deadline is coming up in May 2026, then you can exhale. You aren’t late (yet)… although if you are reading this closer to November, you can panic [a little]. The changes are actually not terribly complex for your practice, as we will explain in this blog, so you can be prepared.   What is GHS, and why does it exist? The Globally Harmonized System can be thought of as a standardized or universal language that is aligned with GHS Revision 7. Since chemical manufacturing occurs all over the globe, something made in one country might use different warning symbols and formats than something made here in the U.S., which can be confusing, if not problematic, for those who use them.  OSHA is updating its standards so that every chemical label and Safety Data Sheet (SDS) uses the same icons (called pictograms) and formatting worldwide, helping your team to easily identify what is what, no matter where the product came from.   Why are there so many deadlines? There are really two different audiences for the deadlines: manufacturers and consumers of the chemicals. There are also two waves of chemical classes with different priorities: Pure Substances and Mixtures. Wave 1 – Pure Substances (Deadline: Nov 20, 2026) This first wave covers “pure” chemicals, or products that have only one main ingredient. For many practices, this list tends to be short including (but not limited to) medical gas – like 100% Oxygen or Nitrous Oxide, bulk alcohol – like 99% Isopropyl Alcohol, etc. Wave 2 – Mixtures (Deadline: May 19, 2028) Most products are likely “mixtures” of several chemicals. Because these are more complex to re-label, OSHA has given everyone until 2028 to reach full compliance. This includes most surface disinfectants, cleaners, clinical materials, etc. What if we mix things ourselves? Most mixtures you do in-house are probably to dilute other “mixtures” (ie: secondary container labeling). But say, for instance, you still mix your own amalgam – you have a unique situation where you’re dealing with two different deadlines. Your mercury needs updated labels by Nov 2026, but the alloy you’re mixing with would fit the mixture deadline, as would the final product.   When will we see changes? You might have heard about a May 19, 2026, deadline. That is the deadline for the manufacturers to have their pure substance labels ready. Here is when you can expect to see the changes in your orders: May 2026 (Manufacturer Deadline) New labels for pure substances. Nov 2027 (Manufacturer Deadline) New labels for all mixtures.   Should I be doing anything now? Just be aware of the changes and try to notice them. You may already see some manufacturers have these changes live; others may happen by the deadline. The key is effective Safety Data Sheet (SDS) management. When a new version of an SDS arrives, simply swap it out in your library (whether that’s a physical binder or stored digitally). Replacing them as they come in is much easier than doing a mass update in November. If you haven’t received new sheets for your pure substances by this summer, you can reach out to your vendor to request the GHS-aligned version. The other change you’ll notice is products adding the GHS hazard pictograms where previously they had none or few. When you spot these, show them to your team during a morning meeting and explain what each icon means. It’s a simple way to keep staff informed and safe. Beyond that, start thinking about updates to your OSHA Hazard Communication training.   Need Help? We get it, you didn’t get into healthcare to become an OSHA expert… But we did. If you want to stay up to date on the deadlines and get the easy button covered for OSHA compliance, our platform and our compliance experts are here to help you do exactly that. If you’d like to learn more about Abyde and how we can help, check out our OSHA for Healthcare platform.

Basic HIPAA Requirements
Abyde News, Best Practices, HIPAA

HIPAA Basics You Can’t Skip (Even If You’ve ‘Always Done It This Way’)

January 15, 2026 Penelope Schweitzer No comments yet

January 15, 2026 As your practice shakes off the post-holiday haze, it’s time to go back to basics. Before picking up the pace, it’s worth slowing down to look at the foundations. While your practice might have routine procedures, it’s time to double-check if they’re even compliant.   The Training Refresh Staff must complete HIPAA training when joining your practice, but that’s not all. HIPAA requires annual training and updates after policy changes or breaches, and whenever staff review is needed. Long story short, your practice needs a lot of training. When in doubt, provide staff training to ensure they are comfortable and confident in handling Protected Health Information (PHI).   Titles Matter Even in a small practice, it’s required to assign a HIPAA Compliance Officer (HCO). We know that ‘wearing many hats’ is the reality of a small team, but designating a clear leader for compliance provides a vital anchor. It ensures your staff knows exactly who to turn to for guidance. If the OCR ever comes knocking, they require a single point of contact to streamline the investigation. Social Media Savviness We hate to break it to you, but your Gen Z receptionist could make your practice viral for all the wrong reasons. Social media can be beneficial for sharing your practice to a larger audience, but your staff needs to handle it very carefully. While it might be fun to partake in the latest TikTok trend, make sure that any PHI cannot be seen in the clips, and do not include a patient in any content unless there is explicit consent to do so. Having a media consent form is key in these situations. Keep it General Alongside social media, Google reviews can be a great way to show you’re listening, but HIPAA changes what you can say. Even if the review is favorable, you cannot identify whether the patient has been in your practice or not. Even if the review details a specific experience at your practice, it’s their choice to disclose this information, and your job, under HIPAA, is not to confirm it. For instance, a good public review would be: Thanks for the kind words! If you have additional feedback, please call us at xxx-xxx-xxxx. If you get a negative review, keep your response brief and offline. First, check for spam or rule violations and report if necessary. Otherwise, don’t clarify details or if they’re a patient. A good response: Thank you for your feedback. We’d like to learn more. Please contact us at xxx-xxx-xxxx. Practices can, and have been, fined for improper Google review responses, so your team must remain calm and neutral online. Lock it Down While it might feel easier for your practice to use a single, shared email to log in and access everything, it’s much safer (and wiser) for every team member to have their own login with role-based permissions. Individual accounts create accountability, keep information organized, and enable the implementation of role-based access. Not everyone in your practice needs access to the same information, and they shouldn’t have it. For example, your receptionist likely doesn’t need access to X-rays or clinical notes, but they do need access to scheduling software. When permissions align with the job, you reduce the risk of accidental exposure and keep sensitive data limited to those who genuinely need it. Individual logins make off-boarding easy. When someone leaves, remove their access immediately without disrupting the team or requiring a shared password change. This small shift greatly boosts compliance and protects patient information. Change Habits Today It’s easy to let compliance fall to the bottom of the to-do list when you’ve “always done it this way”. Thankfully, intelligent software can streamline these requirements for you. With the right platform, you can ensure training is handled correctly, that dynamic policies and procedures are properly formatted for your team, and that you have access to a team of compliance experts when navigating difficult compliance questions. Take the next step: schedule a compliance consultation with our team. We’ll show you exactly how to meet HIPAA requirements, simplify your processes, and protect your practice with confidence. Contact us today to get started.

End of Year HIPAA Checklist
Abyde News, Best Practices, HIPAA

End of Year HIPAA Checklist: 5 Things to Wrap Up Before 2026

December 30, 2025 Penelope Schweitzer No comments yet

December 30, 2025   You may be done wrapping gifts, but year-end is the perfect time to wrap up compliance loose ends and start the new year with everything tied up in a neat bow.  As your office returns to normal after a post-holiday haze, use the (hopefully) quiet time to get your compliance program in order. Here’s your practice’s end-of-year HIPAA checklist to help you confirm the essentials are handled and documented before 2026 begins.   Confirm HIPAA Training is Complete (and Documented) HIPAA training is required yearly and for all new staff members upon joining the team. As the year comes to a close, it’s strongly recommended to review all training documentation. This should include confirming that any new hires have received HIPAA onboarding training, verifying that all current staff completed training during the calendar year, and ensuring that your practice has the necessary documentation, such as training certificates, to prove it.  Maintaining records of your training is crucial. Not only does it keep your documentation organized, but the Office for Civil Rights (OCR) will require this proof if your practice is ever investigated.   Make sure your Right of Access Process is Crystal Clear to all Staff While patient record requests might seem simple, they’re one of the most common HIPAA violations. In fact, the latest HIPAA fine, exceeding $100,000, was issued due to one patient’s complaint after their records weren’t properly released.  Ensure your staff is aware of the process for releasing patient records and the strict timelines your practice must follow. On a federal level, records must be released within 30 days; however, depending on the state, they may be released even sooner.    Review your Business Associate Agreements (BAAs) This is one of the most common gaps across practices: vendors have access to PHI, but the paperwork isn’t complete or updated. The vendors, or Business Associates (BAs), with which your practice works must also follow HIPAA requirements. To protect your practice, ensure your practice has a Business Associate Agreement (BAA) in place with any vendors you work with. A BAA establishes legal liability if your BA experiences a breach. It also outlines the steps your vendor must take to maintain the security of Protected Health Information (PHI) and how to respond to a data breach.    Confirm your Security Risk Analysis (SRA) is Current The Security Risk Analysis (SRA) is at the foundation of a compliant practice. The SRA is a comprehensive review of all physical, technical, and administrative safeguards your practice has in place. For example, the SRA would review how your practice checks patients, as well as the operating system used on the computers in your practice.  Take this downtime to review your SRA. The OCR expects this to be an active, living document, not something that sits in a folder gathering dust. Ensure you have identified any new risks, such as new software implementations or changes in office layout, and have updated your SRA accordingly.    Update Your Policies and Procedures Operating on “outdated instructions” is a major liability. HIPAA requires that your written policies and procedures accurately reflect your practice’s current daily operations. If you’ve implemented new technology in your practice or changed any internal workflows, now is the time to ensure that the policies and procedures show that.  While policies and procedures might feel like just paperwork, alongside thorough training, they are the primary tools for ensuring your staff knows exactly how to handle and protect patient data.   Streamline Compliance in 2026 If this End of Year HIPAA checklist feels overwhelming to manage while running a busy practice, you’re not alone. The good news? You don’t have to do it manually. Smart compliance software is designed to eliminate the guesswork from the process. From dynamically generating your policies and procedures to automating employee training and guiding you through your SRA, turning hours of “paperwork” into a few simple clicks. Meet with a compliance expert today to see how you can streamline compliance in 2026.

  • Facebook
  • Instagram
  • LinkedIn
  • YouTube
Abyde Logo

1.800.594.0883 | info@abyde.com

Automated HIPAA and OSHA Compliance

Our Reviews

From Our Blog
  • Don’t Get Caught Off Guard: HIPAA Audits are Back!
  • Don’t Be a Statistic: Why OSHA Compliance Matters in Healthcare
  • What Money Doesn’t Cover: The True Price of HIPAA Non-Compliance
  • HIPAA: It’s Not Just a Training – Your Guide to Continuous Compliance
Solutions
  • HIPAA for Covered Entities
  • OSHA for Healthcare
  • HIPAA for Business Associates
  • SRA for Covered Entities
  • Abyde Incident Response Program
  • Abyde Reseller Program
Resources
  • News
  • Events
  • Partners
  • HIPAA Badges
  • OSHA Badges
  • Learning Center
  • Compliance FAQs
Company
  • About Us
  • Who We Serve
  • Pricing
  • Contact Us
  • Newsletter
  • Jobs
  • COPYRIGHT © 2026 ABYDE
  • |

  • TERMS & CONDITIONS
  • |

  • PRIVACY POLICY
  • |

  • SECURITY MEASURES
  • |

  • E-SIGNATURE TERMS