HIPAA-ready fax & email

HIPAA-Ready Fax and Email Software for Healthcare Communications

CopiaFacts includes technical controls that can support a covered entity's or business associate's HIPAA compliance program when transmitting protected health information (PHI) by fax or email. These include TLS and S/MIME email encryption, encrypted T.38 fax, signed and encrypted PDF delivery, and a complete audit trail.

HIPAA compliance remains the responsibility of the covered entity or business associate using the software. Copia is not a Covered Entity and cannot assert HIPAA compliance on a customer's behalf. The controls below are available to support an organization's own compliance program.

TLS & S/MIMEEncrypted, signed and verified email.
Encrypted T.38SIP signaling and media protection for fax.
Signed & encrypted PDFReceived faxes delivered securely by email.
Complete audit trailEvery transmission attempt is logged.
HIPAA-ready features

Technical controls built into the platform.

This is not an exhaustive list. If a compliance requirement involves fax or email, ask us about it.

TLS

E-Mail Security

TLS is supported on outbound and inbound e-mail connections, and can be configured to be required for all e-mail traffic.

✓

S/MIME E-Mail

Outgoing e-mail can be signed and encrypted; incoming signed mail can be verified and encrypted mail decrypted.

T.38

Encrypted T.38 Fax

Where the PBX or ITSP supports it, fax signaling and media can be protected with TLS and SRTP encryption.

PDF

Signed & Encrypted PDF

Received-fax-as-email PDF attachments can be signed and encrypted, with an open password limited to the authorized recipient.

•••

Password Management

Security pass-phrases are stored securely, avoiding clear-text passwords in configuration files.

≡

File Lifetime & Logging

Transactions and documents can auto-delete immediately after successful transmission. Every attempt remains logged for audit.

Audit, retention & storage

Controls beyond transmission encryption.

HIPAA-sensitive workflows also need records of system activity, controlled storage and appropriate retention settings.

  • Comprehensive audit trail. A system log records inbound and outbound activity daily, with per-transaction control files exportable for review.
  • Encrypted storage. CopiaFacts can run on OS-level encrypted volumes, with credentials restricting access to the fax data share.
  • Configurable retention. Transactions and transmitted documents can be set to delete automatically right after successful transmission.
  • Diagnostic trace control. Sites using TE Systems XCAPI can disable saving fax content in diagnostic trace files.
Where the responsibility sits

How the controls fit into a compliance program.

HIPAA compliance is a formal requirement for covered entities and their business associates. It includes physical and procedural safeguards as well as technology and requires ongoing management.

Compliance note

Copia is not a Covered Entity.

CopiaFacts provides encryption, signing, access management and audit controls that a covered entity or business associate can use as part of its HIPAA compliance program. Copia does not warrant that use of its products constitutes HIPAA compliance and cannot assert compliance on a customer's behalf. Full HIPAA compliance also requires physical and procedural safeguards and periodic review. Organizations subject to HIPAA should seek appropriate legal and authoritative guidance.

HIPAA-ready FAQ

Questions about fax, email and HIPAA.

Can fax be HIPAA compliant?

Yes, fax can be used within a HIPAA-compliant workflow, but no fax product by itself makes an organization compliant. FaxFacts provides technical controls such as encryption where supported, access management and audit logs; the covered entity or business associate remains responsible for its full compliance program.

Is CopiaFacts HIPAA compliant?

No software product can be "HIPAA compliant" on its own. Compliance is a program run by a covered entity or business associate and includes physical and procedural safeguards as well as technology. Copia is not a Covered Entity. CopiaFacts provides HIPAA-ready technical controls such as encryption, signing, access management and a complete audit trail for use within an organization's compliance program.

What encryption does CopiaFacts support for email?

TLS on outbound and inbound e-mail connections, which can be configured as required for all traffic, plus S/MIME signing and encryption of outgoing mail and verification or decryption of incoming signed or encrypted mail.

Can faxes be encrypted, not just email?

Yes, where the PBX or ITSP supports it. CopiaFacts supports encrypted T.38 fax, combining TLS for SIP signaling with SRTP encryption for the media stream.

Are received faxes delivered by email secured?

PDF attachments for received-fax-as-email delivery can be signed and encrypted, with an open password limited to the authorized recipient.

Is there an audit trail?

Yes. CopiaFacts keeps a comprehensive system log of inbound and outbound activity, including a record of each transmission attempt, with per-transaction control files that can be exported for review.

Can transactions and documents be deleted automatically?

Yes. File retention can be configured so transactions and transmitted documents delete immediately after successful transmission.

Will Copia sign a Business Associate Agreement (BAA)?

Copia can put a Business Associate Agreement in place for a covered entity that is unable to de-identify PHI and needs technical support assistance from Copia.

Discuss your compliance requirements

Tell us about your PHI fax and email workflow.

Share how protected health information moves through your organization today. Copia can help determine which HIPAA-ready controls fit your workflow.

Talk to Copia

Send a quick question about HIPAA-ready fax.

Add a few details and a Copia fax specialist will follow up.

For existing-product technical support, use the Support Center. See our Privacy Policy.