How the Definition of Secure Communication Has Changed and Where Fax Fits




Compliance officer comparing modern fax encryption standards against legacy email security

The definition of secure communication has changed substantially over the past three decades, and the platforms that were considered secure in earlier eras may not meet the standards that current regulatory frameworks and threat environments require. Understanding how those standards have evolved, and where fax fits in the current landscape, is relevant for any organization making decisions about how it transmits sensitive documents.

The evolution cuts in both directions. Some assumptions about fax security that were valid in a PSTN-only world no longer apply to modern enterprise fax platforms. And some assumptions about the security of email and newer messaging channels overstate what those channels actually provide in cross-organizational communication contexts.

What Secure Communication Meant in the Early Era of Digital Business

In the early era of digital business communication, security was primarily a concern about physical access and basic authentication. A secure document was one that went to the right person, was not intercepted in transit on a shared physical line, and was not accessible to unauthorized parties in storage. The threat environment was primarily physical and organizational rather than technical and adversarial.

Fax in that era provided reasonable security for its context. The PSTN line was circuit-switched and dedicated for the duration of the transmission, which made interception require physical access to the line. Documents in a fax machine output tray were accessible to anyone near the machine, which was a recognized risk that organizations managed through procedural controls.

Email in that era was largely cleartext. Messages traveled over SMTP without encryption, were stored on mail servers without access controls that met modern standards, and were visible to system administrators and anyone who could access the mail server. The security of early email was, in important respects, weaker than the security of fax.

What Secure Communication Requires Now

Current regulatory frameworks and security standards have substantially higher requirements. HIPAA’s Security Rule requires encryption of electronic PHI in transit and at rest, audit controls that log and examine access to PHI, access controls that limit who can view PHI, and integrity controls that protect PHI from improper alteration or destruction. The NIST Cybersecurity Framework and standards like ISO 27001 and HITRUST define security management requirements that go beyond individual transmission controls to encompass the full lifecycle of information security governance.

For document transmission, those requirements translate to specific technical standards. Encryption in transit using current TLS versions with modern cipher suites. Access controls that authenticate and authorize users before they can send or receive sensitive documents. Audit logging that creates a complete and tamper-evident record of transmission activity. Data handling practices that limit retention of PHI after transmission is complete.

Where Modern Fax Platforms Stand Against Those Standards

Modern enterprise fax platforms, when properly implemented, meet or exceed those standards in ways that earlier fax infrastructure did not and that many commonly used email implementations still do not.

Lane’s Fax 2.0 transmits over the etherFAX network using TLS encryption, which satisfies the in-transit encryption requirement. Fax content is destroyed after delivery using FIPS 140-2 compliant deletion, which addresses the data retention risk that cloud storage creates. The etherFAX network is HITRUST certified and operates in PCI Level 1 certified data centers. Passport’s access controls authenticate and authorize users at the platform level. The Enterprise Status Manager provides the audit logging that HIPAA’s audit control requirement calls for.

That architecture represents a significant evolution from analog PSTN fax. The shared-machine-in-a-hallway model of fax security is a historical artifact, not a description of what modern enterprise fax platforms provide.

Where Email Still Has Gaps

Email has also evolved, but its evolution has been uneven in ways that matter for cross-organizational communication with sensitive documents. Organizations that have implemented S/MIME or PGP encryption, deployed a secure email gateway, or use a HIPAA-compliant secure messaging platform have addressed many of the security gaps of early email.

The challenge is that those implementations are not universal. When a healthcare organization sends an encrypted email to a community physician practice, the security of the transmission on the receiving end depends on what that practice has implemented. If the practice is on standard Gmail or a basic hosted Exchange environment without additional encryption configuration, the security of the receiving environment may not meet the same standard as the sending environment.

Fax encrypted at the platform level by a sender using Passport does not carry that uncertainty. The encryption is applied by the sending platform and does not depend on the receiving party’s email security posture. The post on why fax is more reliable than email for critical document transmission covers that comparison in detail.

The Standard That Matters for Regulated Industries

For organizations in regulated industries, the relevant standard is not what communication technology was considered secure in the past. It is what current regulatory frameworks require, what current threat environments demand, and what can be demonstrated to a regulator or auditor when the documentation of transmission security is requested.

Modern enterprise fax platforms meet that standard. Legacy analog fax machines do not. Consumer cloud fax services may not. The gap between what the regulatory framework requires and what an organization’s actual fax infrastructure provides is the compliance risk that fax modernization addresses.

Schedule a strategy call with the Lane team to discuss how Passport’s security architecture maps to your organization’s current compliance requirements.

Scroll to Top

Altera Digital Health (formerly known as Allscripts) has a proven track record of developing cutting-edge technology for healthcare systems. Lane’s Passport product is leveraged as a solution for hospitals within Altera’s ecosystem to provide faxing of lab results. With this partnership, hospitals benefit from the latest in healthcare technology, delivered by a team with years of experience in providing innovative solutions.

Lane has been an authorized partner with Clinisys (previously Sunquest) for decades. Since 1979, Clinisys has been providing diagnostic informatic solutions to laboratories and healthcare organizations. They develop, design and support a comprehensive clinical information suite for over 1200 hospitals. Clinisys is constantly evolving and pushing the boundaries of diagnostic care for pathology laboratories worldwide.