HIPAA Fax Requirements: How to Fax PHI Legally and Securely

Online Faxing

What are the HIPAA requirements for faxing PHI online? Under HIPAA, you can send protected health information (PHI) through an online fax service, but you need to take appropriate steps to keep that information secure. This guide breaks down the key HIPAA requirements for online faxing, including recipient verification, data security, access controls, and vendor considerations.

How Do HIPAA Privacy and Security Rules Apply to Faxing?

HIPAA doesn't treat faxing as a special category of communication. Instead, online faxing falls under the broader HIPAA rules governing the use, disclosure, and protection of PHI. Two rules are particularly important: the Privacy Rule and the Security Rule.

HIPAA Privacy Rule

The Privacy Rule determines when you can use or disclose PHI. For example, a provider can generally send relevant PHI to another healthcare provider for treatment without first obtaining patient authorization. Other permitted disclosures may include certain uses for payment and healthcare operations.

If the disclosure isn't permitted under HIPAA, written authorization from the patient may be necessary. In other words, before considering how to fax PHI, you first need to determine whether you're allowed to share it.

HIPAA Security Rule

The Security Rule addresses how electronic PHI should be protected. It requires appropriate safeguards to protect ePHI from risks such as unauthorized access, use, or disclosure.

When PHI is sent through an online fax platform, the electronic transmission falls within the scope of these security requirements. The safeguards needed can vary depending on an organization's systems, practices, and risk assessment.

Together, the two rules address both sides of online faxing: whether you can share the PHI and how you protect it when you do.

What Are the HIPAA Requirements for Online Faxing?

Online faxing can simplify the way healthcare organizations exchange patient information, but it also raises important HIPAA compliance considerations. Organizations that fax PHI need to put appropriate safeguards in place to protect it from unauthorized access or disclosure.

The following are the key HIPAA requirements to keep in mind when faxing PHI online.

Verify the recipient

Before sending PHI, verify the recipient's identity and fax number. An incorrect fax number can result in PHI being disclosed to an unauthorized person, even if the mistake is accidental.

For frequently used recipients, keep a verified list of fax numbers and review it regularly. When sending PHI to a new recipient, confirm the fax details before transmitting the information.

Protect PHI during transmission

Online faxing involves transmitting PHI electronically, so appropriate safeguards should be in place to protect the information during transmission. When evaluating an online fax service, look for security features such as encryption and secure connections.

Keep in mind that using an online fax service does not automatically make your faxing HIPAA compliant. Your organization is still responsible for implementing appropriate safeguards around how PHI is sent and handled.

Control access to faxes

Only authorized users should be able to send, receive, or access PHI through your online fax system. Use appropriate access controls and authentication measures to prevent unauthorized users from viewing sensitive information.

Organizations should also establish clear user permissions based on employees' roles and responsibilities. Regularly reviewing access can help identify and remove unnecessary permissions.

Send only the PHI that's needed

When the HIPAA minimum necessary standard applies, limit the PHI you send to what is needed for the intended purpose. For example, if a recipient only needs a patient's lab results, there may be no reason to send the patient's complete medical record.

Review the documents and information included in each fax before sending them to make sure you're not unnecessarily exposing additional PHI.

Secure received and stored faxes

HIPAA safeguards don't stop once a fax has been transmitted. PHI received through an online fax service should be protected from unauthorized access, whether it remains in an online inbox, is downloaded to a computer, or is printed.

Use secure storage, restrict access to authorized personnel, and establish procedures for the appropriate retention and disposal of PHI.

Choose your fax provider carefully

If an online fax provider handles PHI on your organization's behalf, determine whether it is a HIPAA business associate and whether a Business Associate Agreement (BAA) is required.

Before choosing a provider, review its security practices, access controls, data storage, and policies for handling PHI. Don't rely solely on a provider's claim that its service is "HIPAA compliant." Your organization should also configure and use the service appropriately.

Frequently Asked Questions

Is online faxing HIPAA compliant?

Yes. Under HIPAA, you can send PHI through an online fax service when appropriate safeguards are in place. Compliance depends on both the fax provider and how your organization uses the service.

Do I need a BAA with my online fax provider?

If the online fax provider is a business associate that handles PHI on your behalf, you may need a Business Associate Agreement (BAA). Before choosing a provider, determine whether it will access, store, or transmit PHI on your organization's behalf.

Is a HIPAA fax cover sheet required?

No. HIPAA does not require a specific fax cover sheet. However, your organization may use one as an additional safeguard when sending PHI, such as by including a confidentiality notice and limiting the information shown on the cover sheet.

Can I fax PHI to another healthcare provider?

Yes. Under HIPAA, you can generally send PHI to another healthcare provider for treatment without obtaining the patient's authorization. The disclosure should still be handled using appropriate safeguards.

Does HIPAA require online faxing to be encrypted?

HIPAA does not prescribe one specific technology for faxing PHI. However, organizations must implement appropriate safeguards to protect ePHI based on their circumstances and risks. Encryption can be an important security measure when using an online fax service.

Meeting HIPAA Requirements for Online Faxing

Online faxing can be a secure and practical way to send PHI when the right safeguards are in place. Under HIPAA, organizations need to consider both when PHI can be disclosed and how ePHI is protected throughout the faxing process.

By verifying recipients, limiting access, protecting data during transmission, and choosing an appropriate online fax provider, healthcare organizations can reduce the risk of unauthorized disclosures and maintain a more secure HIPAA-compliant faxing process.

Your Complete Resource Hub for Online Faxing

Explore the future of faxing and secure document sharing. Find practical guides, helpful tips, and expert resources to streamline your workflow.