Healthcare & Interoperability
Migrating to the Cloud: Closing the Hidden PHI Security Gaps in Outdated Federal Fax Workflows

Federal agencies continue to rely on fax as a trusted method for transmitting sensitive information, especially protected health information (PHI). In federal health agencies and programs, fax remains deeply embedded in workflows, and the assumption has long been that fax is inherently secure.
However, that assumption doesn’t reflect how fax is used today. Transmissions may be secure, but everything that happens before and after documents are sent can create significant risk. These “hidden workflow gaps” are creating exposure points that undermine compliance and put PHI at risk for exposure.
Why Fax Remains Critical in Federal Agencies
Many federal agencies still rely on fax for transmitting patient records, coordinating care between providers and supporting regulatory workflows. It remains one of the few communication methods that can bridge gaps between disconnected systems, and interoperability is still a serious concern across providers.
Despite decades of modernization, 24% of hospitals are still unable to meet standards for the four domains of interoperability (sending, receiving, finding, and integrating data, as defined by the Centers for Medicare and Medicaid Services), and that number is even higher in post-acute care facilities. Such gaps aren’t just limited to healthcare. Nearly a quarter of federal IT recommendations made by the Government Accountability Office (GAO) remain unimplemented, and that backlog is even more pronounced when it comes to replacing legacy systems. Nearly 73% of the federal government’s most critical legacy IT systems lack complete, documented modernization plans, and that deficiency is even higher among agencies managing essential infrastructure.
Fax works across these fragmented environments.
Where Traditional Fax Workflows Break Down
Traditional fax workflows rely heavily on manual steps. Documents are printed, handled, scanned, and re-scanned as they move through departments. Each of these touchpoints introduces the potential for error, particularly when documents must be routed quickly across teams or external partners. And, human error is responsible for 68% of data breaches. About half of those errors are due to misdelivery. When PHI is transmitted, even one misdirected document can create a serious compliance issue.
These structural vulnerabilities are exactly why the Centers for Medicare & Medicaid Services (CMS) finalized the CMS-0053-F rule. Championed as a core component of CMS’s broader initiative to “ax the fax” and eliminate snail mail, this administrative simplification rule mandates the first-ever national standards for the secure, electronic exchange of health care claims attachments—such as medical records, clinical notes, and diagnostic results.
Lack of Visibility and Auditability
Many legacy systems lack centralized tracking, making it difficult to confirm whether documents were delivered, accessed, or stored properly. Without consistent audit trails, proving compliance becomes more complex and time-consuming.
The CMS-0053-F rule directly addresses this structural visibility gap by outlawing fragmented manual workarounds in favor of a strictly regulated digital ledger. Under this final rule, covered entities must replace arbitrary fax logs with standardized, bidirectional electronic data interchange (EDI) transactions. These strict compliance requirements include adopting the HL7 Consolidated Clinical Document Architecture (C-CDA) for complete traceability and enforcing verified electronic signatures.
Fragmented Systems and Siloed Workflows
Fax infrastructure is often spread across departments, with different processes and standards in place. This fragmentation leads to inconsistent handling of sensitive information and limits an agency’s ability to enforce uniform security policies.
As documents move between systems and teams, the lack of coordination increases the likelihood of exposure.
Physical Infrastructure Creates Exposure Points
Traditional faxing still depends on physical devices and paper-based processes. Documents may be printed and left on shared machines, stored locally, or handled by multiple people before reaching its intended destination. How secure is it if someone leaves a fax sitting on a fax machine where any number of people have access?
But in today’s hybrid cloud landscape, the physical paper tray isn’t the only exposure point agencies need to worry about. Many agencies attempting to modernize mistake Infrastructure as a Service (IaaS) or transport middleware for a complete cloud solution. In doing so, they simply swap physical security vulnerabilities for digital ones:
- The virtual paper tray liability: Because hybrid IaaS providers exclude the user-facing application layer from their FedRAMP security boundary, unmanaged local caches and unmonitored viewer apps become the digital equivalent of an unattended fax machine tray.
- The vulnerability of integration modules: Hybrid architectures frequently require agencies to install and maintain local software connectors or virtual appliances to bridge their internal network to the cloud, creating highly attractive entry points for cybercriminals.
- Unclear chains of custody: Tracking who viewed, copied, or modified a document becomes nearly impossible to centralize when the software application used to access patient records sits outside the vendor’s authorized security boundary.
The Compliance Risk: How Workflow Gaps Put PHI at Risk
While Protected Health Information (PHI) does not carry the high-level national security classifications of intelligence data restricted to the Secret Internet Protocol Router Network (SIPR), managing it on the Non-classified Internet Protocol Router Network (NIPR) still carries strict regulatory mandates. Under frameworks like HIPAA and the new CMS-0053-F standards, federal agencies must maintain absolute control over the entire lifecycle of this data, and not just its final transmission.
As modern federal initiatives push for interoperability, sensitive information must move efficiently between organizations without relying on outdated, paper-bound processes. Traditional faxing creates exposure risks at multiple stages, including intake, routing, storage, and access. Even when standard network encryption is active, the manual handling of paper documents introduces vulnerabilities.
Besides the operational disruption itself, recovering from a breach within the federal ecosystem is exceptionally costly. Public sector and government data breaches average a baseline cost of $2.86 million per incident. HHS continues to enforce rigorous financial penalties on covered entities that fail to secure the technical checkpoints of PHI lifecycle data.
Incremental Fixes Are Not Enough
Many agencies attempt to address these risks through incremental improvements, such as adding encryption or digitizing specific steps in the process. While this can reduce certain vulnerabilities, they do not resolve the underlying issue of fragmented workflows.
In many cases, legacy infrastructure just isn’t able to handle today’s demands. Here’s how pervasive the issue is. A recent GAO review took a look at legacy systems across several federal agencies. Of the 11 systems they deemed most critical, eight used outdated language, four had unsupported hardware or software, and seven were operating with known cybersecurity vulnerabilities.
As long as agencies rely on outdated systems and manual processes, risk remains embedded in the workflow itself.
Closing the Workflow Gap with ECFax®
ECFax® (powered by eFax® for government) offers government agencies a consolidated, secure, cloud-based fax service that simplifies faxing processes and eliminates the need for a costly, inefficient, legacy fax infrastructure. ECFax® was developed specifically for government use and eliminates paper-based fax processes, providing:
- FedRAMP® Class D (High) Certified Status
- MFIPS 140-2, NIST Rev 4, and HIPAA compliant
- End-to-end encryption and secure document handling
- Centralized access controls to limit exposure
- Full audit trails to support compliance and accountability
By reducing manual touchpoints and consolidating workflows, agencies can significantly lower the risk of misdelivery, unauthorized access, and data loss. ECFax® is currently being implemented across the U.S. Department of Veterans Affairs enterprise.
Learn more about ECFax® or request a demo today.





