• Skip to main content
  • Skip to secondary menu
  • Skip to primary sidebar
  • Skip to secondary sidebar
  • Skip to footer

  • COVID-19
  • Opinion
  • Health IT
    • Behavioral Health
    • Care Coordination
    • EMR/EHR
    • Interoperability
    • Patient Engagement
    • Population Health Management
    • Revenue Cycle Management
    • Social Determinants of Health
  • Digital Health
    • Artificial Intelligence
    • Blockchain
    • Mobile Health
    • Precision Medicine
    • Telehealth
    • Wearables
  • Startups
  • M&A
  • Value-based Care
    • Accountable Care (ACOs)
    • Medicare Advantage
  • Life Sciences
  • Research

Best Practices to Ensure Telehealth Security and Protect Patient Data

by Paul Banco, CEO and co-founder of etherFAX 02/18/2021 Leave a Comment

How Fax Protects Patient Health Information
Paul Banco, CEO of etherFAX

To support the sudden increase in test results and medical records being transmitted during the pandemic, hospitals, laboratories, and pharmacies implemented additional devices and remote connections into their networks. After the Office for Civil Rights (OCR) lifted penalties around telehealth to expand care options amid the crisis, new platforms were adopted that were not previously allowed by the Health Insurance Portability and Accountability Act (HIPAA). 

This exercise of discretion applied to applications including FaceTime and Skype, regardless of whether the telehealth service administered while using the apps was directly related to the coronavirus. Unfortunately, this also increased security risks across thousands of healthcare organizations. Since many communications apps are not HIPAA compliant, the risk of a data breach occurring that compromises personally identifiable information (PII) is imminent. For example, though Apple is a HIPAA business associate, it is not willing to sign a BAA, and therefore, Apple services including FaceTime are not HIPAA compliant. 

In 2021, adopting new technology to ensure the health and safety of patients shouldn’t adversely affect security and privacy. Today, digital and direct fax solutions offer the flexibility to securely integrate with today’s popular mobile applications and third-party messaging platforms such as Slack, Teams, and Microsoft Fax while maintaining HIPAA, SOC 2, and PCI DSS compliance. 

To ensure that protected health information (PHI) remains secure at all times, organizations should utilize a hybrid-cloud fax network that leverages defense-in-depth strategies including end-to-end encryption and two-factor authentication. Unlike traditional PTSN-based networks, digital fax technology can also ensure that time-sensitive documents are delivered fast with high-resolution, near-diagnostic image quality. 

Here are the most important features your organization should look for to ensure telehealth security and protect patient data:

Direct Digital Fax

Many patients and organizations are unaware that a data exchange via email or text message will typically pass through multiple servers before it reaches the final point of delivery. This indirect transmission method can leave PHI and other unstructured data vulnerable to imminent threats of cyberattacks. 

Utilizing a hybrid-cloud network with direct digital faxing is the key to ensuring communications never traverse an external telephone network and that data is protected against unauthorized access. Black and White lists can also be leveraged to place further restrictions on the exchange of sensitive information. This allows patients to receive high-quality care at home or in person without compromising their personal information.

HITRUST CSF Certification 

The HITRUST CSF certification has become the gold standard for compliance framework in the healthcare industry as it addresses the requirements of existing standards and regulations including HIPAA, PCI, COBIT, NIST, ISO, FTC, and state laws. While the HITRUST CSF can be used by all organizations that create, access, store, or exchange sensitive and/or regulated data, it is ideal for healthcare organizations because of its prescriptive framework for managing the security requirements inherent in the Health Insurance Portability and Accountability Act. 

HITRUST offers providers a trusted benchmark from which they can measure and manage their own compliance while offering proven protection to their patients and partners. For guaranteed security, healthcare organizations should look for a fax provider that is HITRUST CSF certified in addition to SOC 2 and PCI DSS compliant. 

End-to-End Encryption 

Implementing a secure exchange network that leverages well-defined end-to-end encryption methods, such as those defined in the Elliptic Curve Integrated Encryption Scheme (ECIES), is crucial to fully protect the transfer of information between two endpoints. This hybrid encryption scheme uses Elliptic Curve Cryptography to generate a shared secret between peers to seed the encryption process with unique keying material while signing and authentication mechanisms assure the validity of the data in transit. Even if a third-party attempted to eavesdrop on the network communication, the information itself would be indecipherable thanks to end-to-end encryption. 

Two-factor authentication (2FA) should also be utilized on every device that sends and receives PHI. Two-factor authentication can prevent data breaches on applications and platforms by requesting a combination of credentials at access points that only the actual patient, doctor, billing operator, or pharmacist would know.

Overall, network security can have an adverse effect on patient care. To secure healthcare technology during the pandemic and beyond, organizations must extend legacy devices, remote connections, and telehealth services to a secure exchange network via the cloud. Hybrid-cloud fax technology can provide end-to-end encryption, two-factor authentication, and direct transmissions to protect the integrity of PHI while ensuring that business-critical communications are sent with ultra-fast transmission speeds. 

About Paul Banco

As CEO and co-founder of etherFAX, Paul Banco is responsible for the strategic direction of the company and leads technology development, including the patented etherFAX and etherFAX SEN intellectual property. In 2009, he identified the need to leverage the cloud for secure document delivery and co-founded etherFAX with fellow telecom industry veterans. As a cloud-based and virtual solution, etherFAX enables healthcare organizations to securely send and receive information from a broad range of applications and endpoint devices. 


Tagged With: apple, cloud, health insurance, healthcare technology, HIPAA, HITRUST, integrity, medical records, Microsoft, Partners, Patient Care, PHI, risk, telehealth, Telehealth Services, unstructured data

Get in-depth healthcare technology analysis and commentary delivered straight to your email weekly

Reader Interactions

Primary Sidebar

Subscribe to HIT Consultant

Latest insightful articles delivered straight to your inbox weekly.

Submit a Tip or Pitch

Most Popular

Survey: Clinician Burnout Is A Public Health Crisis Demanding Urgent Action

17 Execs Share How Health IT Can Address Clinician Burnout, Staffing, & Capacity

Q/A: Dr. Johnson Talks Racial Disparities in Breast Cancer Care

Q/A: Dr. Johnson Talks Racial Disparities in Breast Cancer Care

Northwell Health Extends Contract with Allscripts Sunrise Platform Through 2027

Northwell to Deploy Epic Enterprise EHR Platform Across System

Sanofi Cuts Price of Lantus Insulin by 78% & Caps Out of Pocket Costs at $35 for All Patients

Sanofi Cuts Price of Lantus Insulin by 78% & Caps Out of Pocket Costs at $35 for All Patients

Pfizer Acquires Seagen for $43B to Tackle Cancer

Pfizer Acquires Seagen for $43B to Tackle Cancer

5 Key Trends Driving Purchasing Decisions in Healthcare IT

5 Key Trends Driving Purchasing Decisions in Healthcare IT

Sanofi to Acquire Diabetes Therapy Maker Provention Bio for $2.9B

Sanofi to Acquire Diabetes Therapy Maker Provention Bio for $2.9B

Dr. Arti Masturzo

Q/A: Dr. Masturzo Talks Addressing Food Insecurity with Patients

Transcarent Acquires 98point6 AI-Powered Virtual Care Platform and Care Business

Transcarent Acquires 98point6 AI-Powered Virtual Care Platform and Care Business

Eli Lilly Cuts Insulin Prices by 70%, Caps Patient Costs at $35 Per Month

Eli Lilly Cuts Insulin Prices by 70%, Caps Patient Costs at $35 Per Month

Secondary Sidebar

Footer

Company

  • About Us
  • Advertise with Us
  • Reprints and Permissions
  • 2023 Editorial Calendar
  • Submit An Op-Ed
  • Contact
  • Subscribe

Editorial Coverage

  • Opinion
  • Health IT
    • Care Coordination
    • EMR/EHR
    • Interoperability
    • Population Health Management
    • Revenue Cycle Management
  • Digital Health
    • Artificial Intelligence
    • Blockchain Tech
    • Precision Medicine
    • Telehealth
    • Wearables
  • Startups
  • Value-Based Care
    • Accountable Care
    • Medicare Advantage

Connect

Subscribe to HIT Consultant Media

Latest insightful articles delivered straight to your inbox weekly

Copyright © 2023. HIT Consultant Media. All Rights Reserved. Privacy Policy |