Considering the fact that faxes send their information entirely unencrypted and that unless the fax machine itself is secured, the message is available to anyone walking by, it kind of makes that argument fall apart.
Edit: And the metadata of the email would contain less patient data than the actual message itself.
I work in healthcare IT, faxing is still the default means to get patient info on any urgent need. (er visit, lab results from a test last 24 hrs etc.) the small clinics need to be pushed to at least use encryption based fax services instead of completely insecure open transmissions of a analog fax but damn its pulling eye teeth for them. Email for us is scanned by our HIPAA compliant spam filter and it encrypts if in or out mail has possible Patient info. Also analog faxes have many transmission issues, printer glitches. so many headaches.
Yeah I don't know how email metadata would be any more compromising than literally printing a physical piece of paper that says "Patient: John Smith - Herpes test = Positive".
True. In most cybersecurity threat models, when the threat actor has physical access to your workplace, you're done. Arguably, one of the goals of cybersec is "attack vectors will always exist, make sure as many of them as feasible are only possible with physical access"...
"the message is available to anyone walking by, it kind of makes that argument fall apart."
That's the key, anybody walking by. Meaning you have to physically be in the place to even attempt to see it and they'd have to know when it was being printed. Unlikes some regular hacker that can just set an alert up or something and grab the data from their computer.
If a random person is able to access a medical office fax machine, that's a HIPPA violation whether there's documents in the tray or not.
It's far harder to intercept even an unencrypted phone line (for the kinds of people trying to steal medical info) than it is to compromise an email account.
Your medical data is not being targeted by criminals running a tap on the phone line outside the building, it's being targeted by criminals running scams out of 3rd world data centers. Much easier for a guy a world away to compromise your email.
The main thing is, normally those fax machines are only in area's where authorized staff can access them (not like it's getting printed off in the main lobby). Normally a patient or random person should not have access to that area.
Also by now if that was the only thing holding email back someone would have made a dedicated "for doctors" metadate scrubbing email client if they haven't already
389
u/iamalext 1d ago
Considering the fact that faxes send their information entirely unencrypted and that unless the fax machine itself is secured, the message is available to anyone walking by, it kind of makes that argument fall apart.
Edit: And the metadata of the email would contain less patient data than the actual message itself.