Resources 6 min read

Electronic Fax and HIPAA Compliance

The HIPAA Security Rule does not ban fax, and it does not require encryption in the way most vendors imply. It sets standards, marks some implementation specifications required and others addressable, and leaves the obligation with you.

Two women professionals collaborate at a desk; reviewing colorful data dashboards on a large monitor in a modern office.

Ask a fax vendor whether its service is HIPAA compliant and you will usually get a yes. The question is not quite the right one, and the yes is not quite an answer. HIPAA does not certify products. The Security Rule sets standards that a covered entity or business associate has to meet, and it leaves a good deal of the how to the organization meeting them. A fax service can make that easier or harder. It cannot do it for you.

What the Security Rule actually says about fax

Nothing, directly. There is no fax provision, no prohibition, and no approved list. Fax is simply one more way that electronic protected health information moves, and the same technical safeguards apply to it as to anything else.

Those safeguards live in 45 CFR 164.312. The standards are access control, audit controls, integrity, person or entity authentication, and transmission security. Read them and you will notice they describe outcomes rather than products: know who touched the record, be able to show it later, be able to tell whether it changed in transit, and protect it while it moves.

Required and addressable are not the same thing

This is the part most marketing gets wrong, and it is worth reading carefully because it changes what a vendor claim is worth.

Each standard in 164.312 carries implementation specifications, and each specification is marked either required or addressable. Unique user identification is required. Audit controls are a standard in their own right. But encryption and decryption is addressable, and so are integrity controls.

Addressable does not mean optional in the casual sense. It means you assess whether the specification is reasonable and appropriate in your environment, implement it if it is, and if it is not, document why and put an equivalent alternative in place. What it does mean is that a sentence like "HIPAA requires encryption, and our service encrypts, therefore our service makes you compliant" is three claims stacked on a false first one.

The reason for that structure is in 45 CFR 164.306, which sets out a flexibility of approach: a covered entity may use any security measures that reasonably and appropriately implement the standards, taking account of its size, complexity, capabilities and the cost of the measures. The same section frames the general requirement as protecting against reasonably anticipated threats or hazards to the security or integrity of such information. That is a judgment you are asked to make and to record. It is not a box a supplier can tick on your behalf.

What a fax service can genuinely provide

Quite a lot, and it is worth being precise about it, because these are the things that make your own assessment easier to complete and defend.

  • Transport protection between your systems and the service, and between the service and the network that carries the fax.
  • Named accounts, so that a transmission has a person or a system behind it rather than a machine in a corridor.
  • A retained record of what was sent, by whom, to which number, and what the far end reported back.
  • Retention and deletion behavior you can set, rather than a stack of paper in an output tray.
  • A written agreement covering how the provider handles the information, including a business associate agreement where one is appropriate.

That last item is doing real work. Where a provider handles protected health information on your behalf, the business associate agreement is the instrument that makes the relationship accountable. It is not a formality and it is not a substitute for the technical safeguards.

What remains yours

Everything about your own environment. Who has an account and who should not. What happens to a fax after it arrives, on whose device, in whose mailbox, and for how long. Whether the destination number was verified before a record went to it. Whether staff who leave keep access. Whether your risk analysis has been done at all, and whether it has been done since the fax workflow changed.

The documentation is part of the control

Where you decide an addressable specification is not reasonable and appropriate for your environment, the decision itself has to be written down along with what you did instead. That record is the thing an auditor reads. It is also, in practice, the thing organizations most often skip, because the technical work feels like the real work and the note explaining it feels like paperwork. A fax service can hand you the evidence of what it did; only you can write down why your arrangement is the right one for the records you handle.

A misdirected fax is still a disclosure, and it is one of the more common ones. No amount of encryption in transit helps if the number was wrong. That is a workflow control, not a product feature.

What to ask a provider

Replace "are you HIPAA compliant" with questions that have checkable answers.

  • Will you sign a business associate agreement, and what does it say about subcontractors?
  • What is encrypted, in transit and at rest, and where are the boundaries of that protection?
  • What audit record is kept, how long is it retained, and can we export it?
  • How is access controlled and how are accounts removed?
  • What is your process when a transmission fails, and what evidence do we get?
  • Which of your claims are attested by a third party, against which standard, in which version, and when was it last assessed?

What the resulting record should contain, and how long to keep it, is covered in electronic fax audit trails and records management.

If you want the criteria in a broader form, our checklist of what to look for in an electronic fax service covers the ground beyond compliance. The security and risk discussion sets out the threats these controls exist to answer.

Where to go next

If you are early in this, the guide to electronic fax is the wider picture, and our feature overview describes what the LABUSA service does. If you would rather talk it through against your own workflows, tell us what you are working with: which records travel by fax, who handles them at each end, and what your retention obligations look like.

Sources

About LABUSA

LABUSA is a managed service provider that enables organizations to build a robust digital business model. We provide managed services through an open hybrid cloud strategy integrating public, private, and on-premises computing systems with intelligent edge devices. The company is ISO 9001:2015 certified, and our solution enhances the efficiency, security, reliability, and cost-effectiveness of the information technology environment.

For more Information Contact LABUSA at

+1-281-393-8003