E-Mail Security
TLS is supported on outbound and inbound e-mail connections, and can be configured to be required for all e-mail traffic.
CopiaFacts includes technical controls that can support a covered entity's or business associate's HIPAA compliance program when transmitting protected health information (PHI) by fax or email. These include TLS and S/MIME email encryption, encrypted T.38 fax, signed and encrypted PDF delivery, and a complete audit trail.
HIPAA compliance remains the responsibility of the covered entity or business associate using the software. Copia is not a Covered Entity and cannot assert HIPAA compliance on a customer's behalf. The controls below are available to support an organization's own compliance program.
This is not an exhaustive list. If a compliance requirement involves fax or email, ask us about it.
TLS is supported on outbound and inbound e-mail connections, and can be configured to be required for all e-mail traffic.
Outgoing e-mail can be signed and encrypted; incoming signed mail can be verified and encrypted mail decrypted.
Where the PBX or ITSP supports it, fax signaling and media can be protected with TLS and SRTP encryption.
Received-fax-as-email PDF attachments can be signed and encrypted, with an open password limited to the authorized recipient.
Security pass-phrases are stored securely, avoiding clear-text passwords in configuration files.
Transactions and documents can auto-delete immediately after successful transmission. Every attempt remains logged for audit.
HIPAA-sensitive workflows also need records of system activity, controlled storage and appropriate retention settings.
HIPAA compliance is a formal requirement for covered entities and their business associates. It includes physical and procedural safeguards as well as technology and requires ongoing management.
CopiaFacts provides encryption, signing, access management and audit controls that a covered entity or business associate can use as part of its HIPAA compliance program. Copia does not warrant that use of its products constitutes HIPAA compliance and cannot assert compliance on a customer's behalf. Full HIPAA compliance also requires physical and procedural safeguards and periodic review. Organizations subject to HIPAA should seek appropriate legal and authoritative guidance.
Yes, fax can be used within a HIPAA-compliant workflow, but no fax product by itself makes an organization compliant. FaxFacts provides technical controls such as encryption where supported, access management and audit logs; the covered entity or business associate remains responsible for its full compliance program.
No software product can be "HIPAA compliant" on its own. Compliance is a program run by a covered entity or business associate and includes physical and procedural safeguards as well as technology. Copia is not a Covered Entity. CopiaFacts provides HIPAA-ready technical controls such as encryption, signing, access management and a complete audit trail for use within an organization's compliance program.
TLS on outbound and inbound e-mail connections, which can be configured as required for all traffic, plus S/MIME signing and encryption of outgoing mail and verification or decryption of incoming signed or encrypted mail.
Yes, where the PBX or ITSP supports it. CopiaFacts supports encrypted T.38 fax, combining TLS for SIP signaling with SRTP encryption for the media stream.
PDF attachments for received-fax-as-email delivery can be signed and encrypted, with an open password limited to the authorized recipient.
Yes. CopiaFacts keeps a comprehensive system log of inbound and outbound activity, including a record of each transmission attempt, with per-transaction control files that can be exported for review.
Yes. File retention can be configured so transactions and transmitted documents delete immediately after successful transmission.
Copia can put a Business Associate Agreement in place for a covered entity that is unable to de-identify PHI and needs technical support assistance from Copia.
Share how protected health information moves through your organization today. Copia can help determine which HIPAA-ready controls fit your workflow.
Add a few details and a Copia fax specialist will follow up.