Security In A Virtual World

With so much information flying back and forth through cyberspace how do you know your information is secure?  This is an especially important question for those in the medical field that deal with patient information and fall under the Health Insurance Portability and Accountability Act of 1996 (HIPAA).  There are a few things that a consumer should look for when trying to decide on a virtual fax provider.

Administrative Procedures – A virtual fax provider should have documented, formal practices to protect data and limit access to files.  Most virtual fax providers will have policies that allow access to fax messages for the purpose of maintenance, customer service, repair, and backup, or in response to legal inquiries or warrants that legally force the disclosure of the messages or documents from courts or government agencies.

Physical Safeguards – A virtual fax provider should be able to protect data from fire, other natural and environmental hazards and intrusion.  A provider should have measures in place that include an industry standard fire safety system, off-site backups, and industry standard security systems to protect Personal Health Information from physical vulnerabilities.

Technical Security Services – a virtual fax provider should have measures in place to protect information and control individual access to information.   There are usually 3 ways to access documents in a virtual fax system and each one should have their own independent security measures.  

  • Access to a virtual fax system by phone should be restricted with PIN access.
  • Email delivery of virtual fax messages should be sent using encryption technology.  An added security feature is the ability to have the email delivery of fax documents configured for a ZIP format with password/encryption.
  • Virtual fax access over the internet should also be PIN protected as well as be secured by industry standard protocols and encryption algorithms.  An added security feature would be that the internet portal’s identity be verified by an SSL certificate. 

Technical Security Mechanisms – A virtual fax provider should be able to guard against unauthorized access or loss of data over the communications network.  Data storage systems should implement industry standard fault tolerant measures to prevent data loss due to storage media failure. Databases and storage systems should be protected by battery backup technology to protect against potential data loss due to power failures.  In addition, servers should use a measure comparable to FreeBSD UNIX to prevent unauthorized access and data security compromise.

It can sometimes seem impossible to make sure your, and your clients, information is secure.  However, there are security measures available to safeguard information sent through cyberspace.  You just need to make sure the provider you decide to do business with takes the steps to implement it.

Share it!



Got something to say?