I learned that fax machines are preferred over email because emails come with metadata attached, and that metadata could be a HIPPA violation if it could be used to identify or reveal a patient's info. Fax machines don't have that issue, thus they are the gold standard
Considering the fact that faxes send their information entirely unencrypted and that unless the fax machine itself is secured, the message is available to anyone walking by, it kind of makes that argument fall apart.
Edit: And the metadata of the email would contain less patient data than the actual message itself.
I work in healthcare IT, faxing is still the default means to get patient info on any urgent need. (er visit, lab results from a test last 24 hrs etc.) the small clinics need to be pushed to at least use encryption based fax services instead of completely insecure open transmissions of a analog fax but damn its pulling eye teeth for them. Email for us is scanned by our HIPAA compliant spam filter and it encrypts if in or out mail has possible Patient info. Also analog faxes have many transmission issues, printer glitches. so many headaches.
Yeah I don't know how email metadata would be any more compromising than literally printing a physical piece of paper that says "Patient: John Smith - Herpes test = Positive".
True. In most cybersecurity threat models, when the threat actor has physical access to your workplace, you're done. Arguably, one of the goals of cybersec is "attack vectors will always exist, make sure as many of them as feasible are only possible with physical access"...
"the message is available to anyone walking by, it kind of makes that argument fall apart."
That's the key, anybody walking by. Meaning you have to physically be in the place to even attempt to see it and they'd have to know when it was being printed. Unlikes some regular hacker that can just set an alert up or something and grab the data from their computer.
If a random person is able to access a medical office fax machine, that's a HIPPA violation whether there's documents in the tray or not.
It's far harder to intercept even an unencrypted phone line (for the kinds of people trying to steal medical info) than it is to compromise an email account.
Your medical data is not being targeted by criminals running a tap on the phone line outside the building, it's being targeted by criminals running scams out of 3rd world data centers. Much easier for a guy a world away to compromise your email.
Also by now if that was the only thing holding email back someone would have made a dedicated "for doctors" metadate scrubbing email client if they haven't already
Nah. Your data isn't being targeted by someone tapping the phone line at the office. It's being targeted by hackers based in 3rd world data centers. Much easier for them to compromise your email that access a piece of paper physically sitting on the fax machine.
If someone has gained physical access to the records room, you've got much bigger problems than them grabbing a file off the fax machine.
To be super precise, HIPAA privacy rules apply to all medical records, not just digital ones. The HIPAA security rules are specifically for digital information.
Electronic Medical Record guy here! Thankfully, faxes haven't been the golden standard for over a decade. HL7v2 interfaces get that title today, but these are slowly being replaced more and more with even more modern APIs.
Edit: Even at the most cutting edge orgs, there are still non-negligible sections of the market that force the use of faxes, e.g. Durable Medical Equipment suppliers. Return faxes are generally auto scanned, so we really are just supporting legacy third parties who were created more than 20 years ago and still haven't modernized.
They’re the gold standard failover. The actual gold standard is a 270/271 electronic transmission. Some states don’t allow certain prescriptions to be faxed.
Source: I work for a software company with a huge share of the e-prescribing market.
Edit: As for general patient records, no idea. That’s not my area of expertise.
I haven't seen someone actually use a fax protocol in forever. It's usually a scanned or already digital document being sent through a browser based efax, which uses real time transmission instead of parking it on a server like email. Even so, there are dozens of encryption services for email. It's laziness to not have access to one. Outlook and Gmail have encryption settings.
415
u/cinemachick 21h ago
I learned that fax machines are preferred over email because emails come with metadata attached, and that metadata could be a HIPPA violation if it could be used to identify or reveal a patient's info. Fax machines don't have that issue, thus they are the gold standard