{"id":3755,"date":"2023-06-20T10:28:56","date_gmt":"2023-06-20T17:28:56","guid":{"rendered":"https:\/\/blog.sprucehealth.com\/?p=3755"},"modified":"2023-10-26T04:57:13","modified_gmt":"2023-10-26T11:57:13","slug":"the-dos-and-donts-of-hipaa-compliant-faxing","status":"publish","type":"post","link":"https:\/\/sprucehealth.com\/blog\/the-dos-and-donts-of-hipaa-compliant-faxing\/","title":{"rendered":"The Do&#8217;s and Don&#8217;ts of HIPAA-Compliant Faxing"},"content":{"rendered":"\r\n<p><strong>IN THIS ARTICLE<\/strong><\/p>\r\n<ul>\r\n<li><a href=\"#Usage-of-eFaxing\">The Usage of eFaxing in Telemedicine<\/a><\/li>\r\n<li><a href=\"#general-rules\">Some General Rules for HIPAA-Compliant Faxing<\/a><\/li>\r\n<li><a href=\"#what-to-avoid\">What to Avoid During Faxing to Prevent HIPAA Violations<\/a><\/li>\r\n<li><a href=\"#main-advantages\">The Main Advantages of Online Fax Services<\/a><\/li>\r\n<li><a href=\"#send-online-fax\">How to Send an Online Fax<\/a><\/li>\r\n<\/ul>\r\n<p><span style=\"font-weight: 400;\">It isn\u2019t news to anyone working in healthcare that the industry at large still heavily relies on faxing to send and receive confidential documents, despite the availability of more modern technologies. There are many reasons why faxing is still prevalent in this space and this article will reveal the criticality of understanding the relationship between HIPAA regulations and faxing. But the primary reason why fax is still heavily leveraged is because <\/span><span style=\"font-weight: 400;\">faxing is a familiar technology that has been used in the industry for decades, so while seemingly antiquated, it very much falls into the category of \u201cif it isn\u2019t broken, why fix it?\u201d Now, let\u2019s get into the nitty gritty.<\/span><span style=\"font-weight: 400;\"><br \/><\/span><\/p>\r\n<h2 id=\"Usage-of-eFaxing\">The Usage of eFaxing in Telemedicine<\/h2>\r\n<p><span style=\"font-weight: 400;\">Internet faxing (&#8220;eFaxing&#8221;) has become a reliable and secure way for medical professionals to exchange documents with patients and providers alike. Healthcare providers began the transition from traditional fax to eFax over the past couple of decades to both improve communication and remain current with the latest technology. HIPAA compliant faxing, like that offered by Spruce, has been designed to make it simple to adhere to basic security protocols. It takes the guesswork out of the equation and gets around more traditional necessities like the cover letter. The Spruce fax cover sheet will automatically display a &#8220;from&#8221; section that will contain your Practice Name, the name of the user who sent the message, the user&#8217;s default phone number, and the fax number the fax was sent from.<\/span><\/p>\r\n<p><span style=\"font-weight: 400;\">Net net, efaxing is simply a convenient way to share and receive chart notes, lab reports, documents, and other information that contains private health information and has proven to be an excellent replacement to a traditional fax machine because, among other things, it can work across different EHR platforms, digitally sharing documents and information with ease.<\/span><\/p>\r\n<h2 id=\"general-rules\">Some General Rules for HIPAA-Compliant Faxing<\/h2>\r\n<h3><b>Verify the Recipient&#8217;s Fax Number<\/b><\/h3>\r\n<p><span style=\"font-weight: 400;\">Check the destination fax number before transmission to avoid an unnecessary leak of personable identifiable information (PII), <\/span><span style=\"font-weight: 400;\">which can often also be protected health information (PHI) under HIPAA.<\/span><\/p>\r\n<h3><b>Use Cover Sheets<\/b><\/h3>\r\n<p><span style=\"font-weight: 400;\">Leverage a cover sheet that clearly identifies the sender and recipient and marks the document as confidential.<\/span><\/p>\r\n<h3><b>Ensure Recipient Availability<\/b><\/h3>\r\n<p><span style=\"font-weight: 400;\">If you are unsure as to whether your recipient is going to receive the fax as a physical printout, you can call them ahead of the transmission to let them know the document is coming through and to watch for it.<\/span><\/p>\r\n<h3><b>Minimum Necessary Standard<\/b><\/h3>\r\n<p><span style=\"font-weight: 400;\">Make sure you are following the <\/span><span style=\"font-weight: 400;\">&#8220;minimum necessary&#8221; guidelines for HIPAA compliance and general best practices; only send the minimum information that is needed to accomplish the task at hand.\u00a0<\/span><\/p>\r\n<h3><b>Documentation<\/b><\/h3>\r\n<p><span style=\"font-weight: 400;\">Make sure that the fax service you are using stores your fax contacts and transmission logs, as well as digital copies of all of your incoming and outgoing faxes. This will protect your fax documentation by the same technical, administrative, and physical safeguards that HIPAA demands. <\/span><span style=\"font-weight: 400;\">Such storage will make the fax provider your business associate under HIPAA, however, so you must have a business associate agreement (BAA) in place with them, and they must understand and live up to the requirements of HIPAA.<\/span><\/p>\r\n<p><span style=\"font-weight: 400;\">Using a HIPAA-compliant communication platform like Spruce ensures that the above considerations are accounted for. But, if you are not using a solution like Spruce, then you will have to ask yourself:\u00a0<\/span><\/p>\r\n<ol>\r\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Is your online fax service in compliance with the HIPAA Security Rule?<\/span><span style=\"font-weight: 400;\"><br \/><br \/><\/span><\/li>\r\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Are you keeping a record of the date and time of your fax transmission? How about the receiver&#8217;s complete name, fax number, and organization? Are you also documenting the sender&#8217;s complete name, fax number, and organization? Audit logs are key to HIPAA compliance.<\/span><span style=\"font-weight: 400;\"><br \/><br \/><\/span><\/li>\r\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Have you created audit logs to keep track of all activity in your network? Audit controls and access logs are important for all covered entities and business associates, meaning that healthcare providers, medical organizations, and all their vendors must keep them.<\/span><span style=\"font-weight: 400;\"><br \/><br \/><\/span><\/li>\r\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">When electronically storing or transmitting sensitive information, are you choosing an encryption method that renders the information &#8220;secure&#8221; under the HIPAA Breach Notification Rule?<\/span><span style=\"font-weight: 400;\"><br \/><\/span><\/li>\r\n<\/ol>\r\n<p><span style=\"font-weight: 400;\">Note that Spruce makes it simple to directly fax contacts from within the platform and as noted above, the Spruce fax cover sheet will automatically include the necessary security details. There is also the benefit of media attachment options, which a traditional fax can obviously not support. Within Spruce, you can attach:<\/span><\/p>\r\n<ul>\r\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\"><strong>Text<\/strong>: Any text typed into the message-compose bar while creating a fax will be included in a fax cover sheet.<\/span><span style=\"font-weight: 400;\"><br \/><\/span><\/li>\r\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\"><strong>PDF<\/strong>: Any attached PDF file will be converted to black and white and included as typical fax pages after the cover sheet.<\/span><span style=\"font-weight: 400;\"><br \/><\/span><\/li>\r\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\"><strong>Images<\/strong>: Attached images will be converted to black and white and included in the fax. This can be used to send photos of single-page documents, such as a signature page, as part of your fax. When you include image files, the fax will also include a QR code to download the full-resolution, color image.<\/span><span style=\"font-weight: 400;\"><br \/><\/span><\/li>\r\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\"><strong>Video<\/strong>: You can include a video in your fax! The recipient will get a single fax page that contains a QR code to download and view the video.<\/span><span style=\"font-weight: 400;\"><br \/><\/span><\/li>\r\n<\/ul>\r\n<h2 id=\"what-to-avoid\">What to Avoid During Faxing to Prevent HIPAA Violations<\/h2>\r\n<h3><b>Avoid Using Non-Secure Fax Machines<\/b><\/h3>\r\n<p><span style=\"font-weight: 400;\">If you are not using a secure eFax solution that supports the T.38 protocol (more on that below) and other essential controls, then you should assume you are using a non-secure fax solution. There are patient privacy concerns to consider if you are using a non-secure fax machine, many of which are areas of concern in the HIPAA regulations. For traditional fax, it\u2019s essential to verify the recipient&#8217;s fax number and ensure recipient availability, as mentioned above. Even if your practice is not covered by HIPAA, developing and implementing fax safeguards can help protect sensitive information and may help prevent liability under state data security law\u2014a whole other ball of wax. There\u2019s also human error to consider. Leaving behind copies on the fax machine, inadvertently sending to the wrong person, etc. are all hazards to keeping up fax hygiene.<\/span><\/p>\r\n<h3><b>Avoid Unconfirmed Transmission and Faxing to Unverified Recipients<\/b><\/h3>\r\n<p><span style=\"font-weight: 400;\">There are some easy ways to avoid unconfirmed fax transmission or inadvertently faxing to unverified recipients, sparing a whole host of complications:\u00a0<\/span><\/p>\r\n<ol>\r\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Check the destination fax number before transmission.<br \/><\/span><span style=\"font-weight: 400;\"><br \/><\/span><\/li>\r\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">If your faxes are failing to send or taking too long to send, they may be sent in parts to increase the likelihood of success. (Note that this isn&#8217;t necessary to do if you&#8217;re using Spruce for eFax.)<br \/><\/span><span style=\"font-weight: 400;\"><br \/><\/span><\/li>\r\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">If you receive a fax error message, contact the person receiving the fax to see if they are receiving or canceling the transmission on their end.<br \/><\/span><span style=\"font-weight: 400;\"><br \/><\/span><\/li>\r\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Check your fax machine&#8217;s features to see if it has any options to prevent sending faxes to unverified recipients. Or, leverage a secure contact book, like the one Spruce offers, to ensure you are only ever sending to the intended recipient.<\/span><\/li>\r\n<\/ol>\r\n<h3><b>Best Practices for Including Sensitive Information in Faxes\u00a0<\/b><\/h3>\r\n<p><span style=\"font-weight: 400;\">There are several ways to mitigate the risk of exposing sensitive information when faxing. Using a confidential fax cover sheet that states that the fax information may be confidential is a start. You can also request that the recipient of a misdirected fax destroy the information and notify you immediately.<br \/><br \/><\/span><span style=\"font-weight: 400;\">Another way to avoid mishandling sensitive information is to leverage a secure contact book in your eFax platform, like Spruce does. <\/span><span style=\"font-weight: 400;\">In this way you will not run the risk of accidentally entering an incorrect fax number or inadvertently faxing the wrong recipient.\u00a0<br \/><br \/><\/span><span style=\"font-weight: 400;\">All users of Spruce agree to our standard Terms of Service, which includes a HIPAA Business Associate Agreement (BAA). Importantly, Spruce stores fax contacts and transmission logs, as well as digital copies of all incoming and outgoing faxes, identically to how all other medical data is stored. This means that your fax information is protected by the same technical, administrative, and physical safeguards that HIPAA demands and that we use regularly throughout our entire system. For more detail on using Spruce fax while maintaining regulatory compliance, please see our white paper on <\/span><a href=\"https:\/\/spruce.docsend.com\/view\/nur46mb\"><span style=\"font-weight: 400;\">Using Spruce in a HIPAA-Compliant Way<\/span><\/a><span style=\"font-weight: 400;\">.<br \/><br \/><\/span><span style=\"font-weight: 400;\">Importantly, when electronically storing or transmitting sensitive information (e.g., via eFax), be sure to choose an encryption method that renders the information unreadable except by the receiving party, as Spruce does automatically when the recipient connection permits it. When possible, avoid using fax altogether to transmit personal information.<\/span><\/p>\r\n<h3><b>Avoid Leaving the Fax Unattended<\/b><\/h3>\r\n<p><span style=\"font-weight: 400;\">If you are using a traditional, physical fax machine that is sitting on a desk in your office, never leave your faxes unattended. Keep an eye on your documents\u2014even if you need to do a quick task while sending a fax\u2014because simply put, you cannot leave a patient record unattended. It can lead to a HIPAA violation. You also need to store these faxes in a secure location.<br \/><br \/><\/span><span style=\"font-weight: 400;\">If you work in a busy office and the team is constantly multitasking, the easy answer is to switch to an online fax service so that it becomes impossible to leave a fax unattended. Short of that, you can check your fax machine&#8217;s features to see if it has any options to prevent leaving the fax unattended. Some are built by design to require the sender to manually monitor the progress.<\/span><\/p>\r\n<h2 id=\"main-advantages\">The Main Advantages of Online Fax Services<\/h2>\r\n<p><span style=\"font-weight: 400;\">Online fax services offer several advantages over traditional fax machines.\u00a0<\/span><\/p>\r\n<h3><b>Convenience<\/b><\/h3>\r\n<p><span style=\"font-weight: 400;\">Online faxing services enable users to send and receive documents instantly, without having to wait for mail or courier services. This saves time and makes it easier to stay on top of important communications.<\/span><span style=\"font-weight: 400;\"><br \/><\/span><\/p>\r\n<h3><b>Speed<\/b><\/h3>\r\n<p><span style=\"font-weight: 400;\">Online faxing is much faster than traditional faxing, as it eliminates the downtime that you might spend waiting to send or receive a fax through a physical fax machine and landline. Plus, with online faxing, there are no busy signals. You can send and receive faxes simultaneously without burdening the system or having to wait for a dial tone. Online faxing can be done on any computer or mobile device that is connected to the internet, making it easy to send and receive faxes from anywhere, at any time.<\/span><span style=\"font-weight: 400;\"><br \/><\/span><\/p>\r\n<h3><b>Cost-efficiency<\/b><\/h3>\r\n<p><span style=\"font-weight: 400;\">Online faxing services are generally more cost-effective than traditional fax machines, as they eliminate the need for a dedicated phone line and the associated costs of paper, ink, and maintenance. Do you remember how much you used to pay to send a fax at Kinko&#8217;s? Gone are those days.<\/span><span style=\"font-weight: 400;\"><br \/><\/span><\/p>\r\n<h3><b>Organization<\/b><\/h3>\r\n<p><span style=\"font-weight: 400;\">Online faxing services keep all your documents organized and always available\u2014or at least they should, like Spruce does!\u2014making it easier to manage and store important documents.<\/span><span style=\"font-weight: 400;\"><br \/><\/span><\/p>\r\n<h3><b>Multi-user functionality<\/b><\/h3>\r\n<p><span style=\"font-weight: 400;\">Online faxing services offer new and improved features like multi-user functionality and document sharing, which lets several users receive the same fax simultaneously.<\/span><span style=\"font-weight: 400;\"><br \/><\/span><\/p>\r\n<h3><b>Security<\/b><\/h3>\r\n<p><span style=\"font-weight: 400;\">Online faxing services are generally more secure than traditional fax machines, as solutions like Spruce use encryption to protect sensitive information and prevent unauthorized access.<\/span><span style=\"font-weight: 400;\"><br \/><\/span><\/p>\r\n<h3><b>Environmentally friendly<\/b><\/h3>\r\n<p><span style=\"font-weight: 400;\">Online faxing services are more environmentally friendly than traditional fax machines, as they eliminate the need for paper and ink.<\/span><\/p>\r\n<h3><b>Underlying technology<\/b><\/h3>\r\n<p><span style=\"font-weight: 400;\">And finally, you should understand the underlying technology of your eFax provider. The basic fax protocol is T.30, but modern systems should use T.38, which enables faxes over the internet and allows for key technological benefits, such as encryption, which can be important for HIPAA. Learn more about the <\/span><a href=\"https:\/\/getvoip.com\/library\/t38-fax\/\"><span style=\"font-weight: 400;\">basics of this protocol<\/span><\/a><span style=\"font-weight: 400;\">. It&#8217;s critical to note that the suitability of T.38 or T.30 depends on the specific requirements of the fax transmission environment. In traditional telephony setups, T.30 may still be a reliable choice. However, in modern IP-based communication systems, T.38 is often preferred due to its compatibility, reliability, efficiency, and integration capabilities.<\/span><\/p>\r\n<h2 id=\"send-online-fax\">How to Send an Online Fax<\/h2>\r\n<h3><b>Choose a Secure Online Fax Service<\/b><\/h3>\r\n<p><span style=\"font-weight: 400;\">Sending an online fax isn\u2019t rocket science but finding the right provider may be challenging. Searching the internet for &#8220;free online fax&#8221; or &#8220;secure online fax&#8221; will often turn up options that are non-secure or free on a trial basis, but never a long-term solution for a thriving medical practice.\u00a0<\/span><\/p>\r\n<h3><b>Sign up and Set up Account<\/b><\/h3>\r\n<p><span style=\"font-weight: 400;\">From a prescriptive standpoint, the basic gist of getting set up online with a fax solution that adheres to today\u2019s guidelines for the health vertical hinges entirely on choosing a secure online fax service like Spruce (and avoiding supposedly free solutions, as mentioned above).\u00a0\u00a0<\/span><\/p>\r\n<h3><b>Prepare Documents You Want to Send<\/b><\/h3>\r\n<p><span style=\"font-weight: 400;\">Compile the documents that you want to transmit and attach a cover note.<\/span><\/p>\r\n<h3><b>Create a New Fax<\/b><\/h3>\r\n<p><span style=\"font-weight: 400;\">Creating a new fax just means that you are now positioned for transmission and all of the content\u2014text, images, even video\u2014are accounted for.\u00a0<\/span><\/p>\r\n<h3><b>Log into Your Account<\/b><\/h3>\r\n<p><span style=\"font-weight: 400;\">Make sure you are logged in as yourself so that if any questions come up later about the sender\/receiver\/transmission there won\u2019t be any mistaking the details.<\/span><\/p>\r\n<h3><b>Enter Recipient&#8217;s Fax Number<\/b><\/h3>\r\n<p><span style=\"font-weight: 400;\">Enter the destination fax number and check it twice. If you are using a solution like Spruce, this number will be attached to the contact in your secure contact book, eliminating any concerns around inadvertently sending to the wrong recipient.<\/span><\/p>\r\n<h3><b>Upload Document(s)<\/b><\/h3>\r\n<p><span style=\"font-weight: 400;\">Upload your documents and get them ready for transmission.<\/span><\/p>\r\n<h3><b>Provide Additional Message if Needed<\/b><\/h3>\r\n<p><span style=\"font-weight: 400;\">If you need to provide context or mark the document confidential, do so before you transmit so that the recipient has all of the information they need up front.<\/span><\/p>\r\n<h3><b>Send Fax<\/b><\/h3>\r\n<p><span style=\"font-weight: 400;\">Send your fax and you will receive confirmation that the transmission was successful.<\/span><\/p>\r\n<h2><b><br \/>Final Thoughts<\/b><\/h2>\r\n<p><span style=\"font-weight: 400;\">HIPAA compliance is a crucial consideration when it comes to faxing in the healthcare industry. Despite the rise of digital communication methods, faxing remains a popular and widely used method of transmitting sensitive healthcare information, and electronic faxing is the strongest option for HIPAA-compliant faxing, as we&#8217;ve discussed in this article.\u00a0<\/span><\/p>\r\n<p><span style=\"font-weight: 400;\">If you still have questions about faxing or compliance, please check out our <\/span><a href=\"http:\/\/help.sprucehealth.com\"><span style=\"font-weight: 400;\">help center<\/span><\/a><span style=\"font-weight: 400;\">, our <\/span><a href=\"https:\/\/sprucehealth.com\/blog-rc\"><span style=\"font-weight: 400;\">blog<\/span><\/a><span style=\"font-weight: 400;\">, or reach out to a member of our <\/span><a href=\"mailto:support@sprucehealth.com\"><span style=\"font-weight: 400;\">support team<\/span><\/a><span style=\"font-weight: 400;\">.\u00a0<\/span><\/p>\r\n","protected":false},"excerpt":{"rendered":"<p><\/p>\n","protected":false},"author":21,"featured_media":3778,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"slim_seo":{"title":"The Do's and Don'ts of HIPAA-Compliant Faxing - Spruce Blog","description":""},"footnotes":""},"categories":[14,24,39],"tags":[116,122,117,119,120,121,118,5,4],"different-template":[],"class_list":["post-3755","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-hipaa","category-telehealth","category-whats-new","tag-efaxing","tag-faxing-rules","tag-hipaa-compliant-faxing","tag-is-faxing-hipaa-compliant","tag-online-faxing","tag-secure-communication","tag-send-confidential-documents","tag-telehealth","tag-telemedicine"],"acf":[],"_links":{"self":[{"href":"https:\/\/sprucehealth.com\/blog\/wp-json\/wp\/v2\/posts\/3755","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/sprucehealth.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/sprucehealth.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/sprucehealth.com\/blog\/wp-json\/wp\/v2\/users\/21"}],"replies":[{"embeddable":true,"href":"https:\/\/sprucehealth.com\/blog\/wp-json\/wp\/v2\/comments?post=3755"}],"version-history":[{"count":0,"href":"https:\/\/sprucehealth.com\/blog\/wp-json\/wp\/v2\/posts\/3755\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/sprucehealth.com\/blog\/wp-json\/wp\/v2\/media\/3778"}],"wp:attachment":[{"href":"https:\/\/sprucehealth.com\/blog\/wp-json\/wp\/v2\/media?parent=3755"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/sprucehealth.com\/blog\/wp-json\/wp\/v2\/categories?post=3755"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/sprucehealth.com\/blog\/wp-json\/wp\/v2\/tags?post=3755"},{"taxonomy":"different-template","embeddable":true,"href":"https:\/\/sprucehealth.com\/blog\/wp-json\/wp\/v2\/different-template?post=3755"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}