Privacy >> TUSDM Policy on Fax Transmissions

TUSDM Policy on Fax Transmissions

I. Purpose and Scope: 
  1. There can be serious consequences when faxed materials are misdirected and the contents inappropriately disclosed. While faxing is an efficient business tool, it must be undertaken according to procedures that help reduce the risk of a breach of confidentiality. For example, fax numbers must be verified to ensure they are entered correctly; and stored numbers must be verified to ensure that they remain current and correct.
II. Policy Statement: 
  1. This policy describes the standards and rules to be followed for safe and appropriate faxing of Tufts University School of Dental Medicine (TUSDM) confidential information. This policy governs both paper faxing and computer-generated automatic faxes and “autofaxing.” It applies to all confidential and highly confidential TUSDM information. It applies to all Workforce Members faxing TUSDM information so classified.
III. Definitions: 
IV. General Rules: 
  1. Each fax will have a cover sheet clearly identifying the sender and sender’s contact information (name of organization, phone, and fax number), and carrying a standard TUSDM message such as:

    “This fax transmission is intended only for the addressee(s) named above. It may contain information that is confidential and prohibited from unauthorized use or disclosure. If you are not the intended recipient, you are hereby notified that any review, use, disclosure, copying, or dissemination of this transmission or the taking of any action in reliance on its contents is strictly prohibited.

    If you believe you have received this fax in error, and the fax contains patient information, please contact the TUSDM Compliance Office at 617-636-3746 or 617-636-0328. If this fax was sent to you in error but does not contain patient information, please contact the sender immediately so that arrangements can be made for its disposal. Thank you for your cooperation.”
     
  2. Prior to manual faxing, the following steps will be taken:
    1. Review the material to ensure the minimum necessary information is being faxed.
    2. Review the intended recipient to ensure the person is authorized to receive the information.
    3. Review the recipient’s fax number, whether entered or stored.
    4. After entering the fax number, visually check the fax number on the machine prior to sending the transmission.
    5. Whenever possible, confirm that the recipient has received the information.
  3. In the case of autofaxing, the process details will be verified a minimum of twice yearly. Verification will include:
    1. Review of all stored fax numbers to ensure they are correct.
    2. Review of autofaxed protected health information (PHI) to ensure the minimum necessary is being disclosed.
    3. Review of autofaxed PHI to ensure that recipients are authorized and disclosure is consistent with TUSDM policies and with the Health Insurance Portability and Accountability Act (HIPAA) and other applicable laws and regulations.
  4. Faxing material outside the TUSDM carries greater risk than internal faxing to an extension number. Whenever possible, external faxing should be done based on necessity rather than convenience. Mail service provides greater confidentiality protection. 
  5. Faxing confidential information outside the TUSDM may only be done in a medical or other emergency and by the Medical Records Office or other authorized department. Further, the recipient must stand by and promptly confirm receipt of the transmission.
  6. The faxing of PHI must be documented in the contact notes section of the patient’s electronic health record as a disclosure of PHI.
  7. Copies of any fax sent or received that contains PHI must be scanned and stored in the attachment manager module of the electronic health record.
  8. Fax machines used for receipt of confidential information should be in private offices or restricted areas. If they must be in open areas or exposed to third party cleaning and service staff, then they should have a locking, opaque cover which is locked when unattended or they should be replaced by electronic faxing.
  9. Fax machines used for receipt of confidential information (other than those with locked covers) should be cleared of incoming faxes before leaving the area unattended for more than a brief period.
  10. Misdirected faxes:
    1. If an incoming fax is received by the TUSDM in error, the recipient should promptly contact the sender by phone or return fax. Recipient also should notify the TUSDM Security & Privacy Officer who will comply with reasonable requests to return or destroy the misdirected fax.
    2. If an outbound fax from the TUSDM is misdirected and the error is noted, the sender will immediately send a follow-up fax to the incorrect number, noting the error; otherwise, it is expected that the recipient will voluntarily contact the sender.
    3. In either case, the TUSDM sender must immediately report this as a privacy/security incident. The TUSDM Security & Privacy Officer will follow up and seek written assurance that the misdirected fax will be destroyed (paper shredded and electronic file erased) following the TUSDM’s Incident Response Plan and breach determination procedure.
V. Policy Compliance Monitoring and Enforcement: 
  1. The TUSDM Security and Privacy Officer is responsible for the monitoring and enforcement of this policy. However, directors and managers are also responsible for monitoring compliance with procedures specific to their areas.The TUSDM Security & Privacy Officer is responsible for the monitoring and enforcement of this policy. However, directors and managers are also responsible for monitoring compliance with procedures specific to their areas.
VI. Potential Disciplinary Actions and Sanctions: 
  1. Failure to follow standard operating procedures may trigger review for potential disciplinary action under the TUSDM Policy on Sanctions for HIPAA and MGL Violations.
VIII. Approval and Review Cycle: 
  1. This policy shall be subject to periodic review, revision, and approval by the TUSDM Compliance Committee.