Question: Our office wants to use electronic faxing for medical records, and we want to know what precautions are needed to protect private patient information – can you help? South Carolina Subscriber Answer: Once a fax becomes electronic, it is considered electronic personal health information (ePHI), so you must develop proper access controls so that only authorized users can see that document. Best practice: Store faxes on a central server where users have the ability to know that the intended fax recipient actually received the information. Ensure that the server is well secured and protected. If you’re using an outside vendor, make sure the vendor is compliant with the Health Insurance Portability and Accountability Act (HIPAA): “The covered entity must have a written business associate contract or other arrangement with the business associate that establishes specifically what the business associate has been engaged to do and requires the business associate to comply with the Rules’ requirements to protect the privacy and security of protected health information. In addition to these contractual obligations, business associates are directly liable for compliance with certain provisions of the HIPAA Rules,” U.S. Department of Health and Human Services Office for Civil Rights says. Don’t forget that you’re responsible for protecting outbound faxes as well. Establish a validation procedure so that if a patient asks you to fax her something, you can determine that it is an authentic request. Bottom line: Make sure that you have procedures in place to ensure that you send faxes to the right place. And when you receive an e-fax, be sure it has the same protections as the rest of your ePHI.