What is HIPAA?
The USA Health Insurance Portability and Accountability Act or HIPAA was passed 1996. It modernized the flow of healthcare information and specifically how personally identifiable information is maintained and transmitted.
Fax can be a secure method of transmission of medical documents, but it's important to note that correct handling of documents before and after transmission are key to ensuring HIPAA-Compliance
HIPAA Compliance
HIPAA compliance is a formal requirement for some data processors, and also includes compliance with the HITECH Act as well as state and local regulations. If as CopiaFacts user you are acting as a business associate with a HIPAA covered entity, it may also require signing a business associate agreement. HIPAA compliance is a complex moving target and anyone who needs to follow HIPAA regulations should seek legal and authoritative advice from the appropriate sources. Copia does not and cannot warrant that use of its products will constitute HIPAA compliance. Full HIPAA compliance requires both physical and procedural steps to protect access to patient health information. It’s an ongoing process that also requires periodic audits.
Copia suggests that companies seeking to become HIPAA compliant consult the HHS government web site for more information. The following link is a good starting point:
https://www.hhs.gov/hipaa/for-professionals/training/index.html
There is also the HIPAA Journal, which is a good source for news stories and informative articles concerning HIPAA.
This free article provides a good overview of HIPAA
https://pubmed.ncbi.nlm.nih.gov/31182664/
HIPAA compliance is a complex task and should not be undertaken without professional help because there can be legal and financial consequences for failure to adhere to the rules. However, keep in mind that many companies have already achieved a degree of compliance and anyone who is willing to put forth the effort can do so as well.
CopiaFacts HIPAA-Ready Features
CopiaFacts includes important security features which can contribute to making a process or service HIPAA-Compliant. Among the relevant features and options are:
| E-Mail Security | E-Mail, either sent by CopiaFacts to transmit received faxes or received by CopiaFacts to initiate outbound faxes, can be sent using Transport Layer Security (TLS) to ensure secure transmission. CopiaFacts can be configured to require TLS for all e-mail connections, in which case e-mail will not be sent to or received from a remote server unless TLS is supported and used. TLS security is a standard CopiaFacts feature. |
| S/MIME E-Mail | E-Mail content sent by CopiaFacts can optionally be signed using a sender private key encrypted using the recipient's public key. For incoming e-mail a sender's key can be verified, and e-mail encrypted using the CopiaFacts recipient account's public key can be decrypted on receipt. This process therefore requires the co-operation of the remote party to ensure that the e-mail content is transmitted securely. This is a CopiaFacts optional feature, and CopiaFacts can be configured to require S/MIME signing and/or encryption on all e-mail traffic. See Appendix N for more information. |
| Encrypted T.38 Fax | CopiaFacts supports XCAPI Encrypted T.38 fax when supported by the PBX or ITSP to which your CopiaFacts system is connected. This uses TLS encryption while establishing the FoIP SIP connection, and secure real-time protocol (SRTP) for the media connection (transmission or reception of document content). |
| Encrypted ITSP | CopiaFacts can support an encrypted fax service when provided by an Internet Telephony Service Provider. Currently the ITSP Cloudli CryptAgent is the only such provider supported. |
| Signed/Encrypted PDF | CopiaFacts optionally supports signing and encryption of PDF files when used for transmission of received faxes as e-mail attachments. It is also possible to maintain a PDF 'open password' for each authorized e-mail sender, which will be used to open incoming e-mail attachments for conversion to fax format for transmission by fax. |
| Password Management | CopiaFacts provides secure storage for a limited number of pass-phrases which can be used to access CopiaFacts security features. This avoids the need to include passwords in clear in CopiaFacts configuration files or transactions. Transactions which access restricted features contain an authentication key which detects and prevents the use of a modified file. |
| File Lifetime | CopiaFacts can be configured to automatically delete transactions and transmitted documents immediately after successful transmission, either by fax or by e-mail. |
| File System Security | CopiaFacts will run on a system for which the data files are all encrypted using an OS feature such as BitLocker. However this principally secures the physical media on which the data resides. Another method of keeping the active files and documents secure is to use Windows credentials to limit access to the COPIA share on which all transaction and document data resides. |
| File Documentation | Please see Appendix F for a summary of all the data types handled and processed by CopiaFacts, together with details of where the data is stored and how it is maintained. |
| XCAPI Trace files | Sites using TE-Systems XCAPI can disable the saving of fax content in XCT trace files, so that these files can be sent to Copia or to TE-Systems for diagnostic purposes. Note that if instead you use Wireshark to capture PCAP diagnostic logs of fax traffic without suitable filtering, there may be specialist forensic tools which can extract and view documents, although currently Wireshark has no built-in fax viewing capability. |