RightFax Security & Compliance Highlights

RightFax protects sensitive information during fax transmission and storage. Key measures include encryption to safeguard data, secure delivery mechanisms to limit faxes to their intended recipients, Active Directory integration, and granular audit trails and access control.

RightFax supports compliance with industry standards such as HIPAA, PCI-DSS, and GDPR, and its infrastructure is regularly audited for standards like SAS70 and SOC2. As the industry standard in healthcare, it also offers HIPAA-compliant Business Associate Agreements (BAAs) and data sovereignty options.

Refer to the tables below for more details on specific RightFax security features as well as a comparison to traditional, paper-based faxing.

RightFax Security and Compliance Features

Encryption Prevents interception of data in transit or unauthorized access to data at rest.
Secure Delivery Ensures faxes reach the intended recipient securely. Reduces risk of misdelivery and unauthorized viewing.
User Authentication Uses systems like Active Directory so only authorized personnel can send/receive faxes.
Audit Trails Supports audits and compliance by logging all activity around every fax.
Access Controls Supports granular user permissions to minimize the risk of data breaches or unauthorized actions.
Regulatory Compliance Reduces the effort of complying with regulations like HIPAA, PCI-DSS, and GDPR.
Third-Party Audits Independent reviews verify compliance with SAS 70 and SOC 2.
Privacy Agreements Available BAAs help covered entities comply with HIPAA.
Data Sovereignty Control over data location facilitates compliance with local data protection laws.

Risk Comparison: RightFax vs. Paper-Based Faxing

Unintended Recipients No safeguards besides physical "lock-and-key" access control. Secure, private, personal delivery.
Routing Issues Delivery to wrong recipient is impossible to prevent and hard to detect. Routing rules, phonebook look-ups, and status reports ensure correct delivery.
Lost Pages Physical documents are easily jumbled or misplaced. Digital receipt and automatic routing make documents easy to track.
Delivery Promptness Prone to delays, which can be hard to identify. Timely delivery with near-real-time monitoring.
Misdialed Numbers Manual dialing is highly prone to error. Automated dialing ensures accuracy and allows for centralized contact management.
Compliance with Laws Paper document handling risks are hard to mitigate and difficult to audit. Built-in audit and control features facilitate compliance.
Audit Capabilities Little or no detail beyond transmission numbers and times. Comprehensive logging of transmissions, metadata, and even document content.
Vendor Infrastructure Compliance Not applicable. Supports compliance with standards like SAS 70, SOC 2, and PCI-DSS.
Privacy Agreements Not applicable. BAAs available for HIPAA compliance.
Data Sovereignty Not applicable. Allows control over data location.

