Still Running on Fax: The Crumbling Security Infrastructure Exposing Your Medical Records
Photo by Photo by Stephen Andrews on Unsplash on Unsplash
In virtually every other industry, fax machines are a relic. In American healthcare, they remain the connective tissue of daily operations. Physician offices transmit referrals by fax. Pharmacies receive prescriptions by fax. Insurance companies request prior authorizations by fax. The American Medical Association estimated as recently as 2021 that 75 percent of all medical communication in the United States still travels over fax lines — a technology developed in the 1960s, running over telephone infrastructure that offers no native encryption, no delivery confirmation with identity verification, and no audit trail that would satisfy a modern security standard.
This is not an anomaly. It is a symptom of a healthcare sector that has been chronically under-resourced for technology investment, legally constrained by regulatory frameworks that have failed to keep pace with the threat landscape, and operationally resistant to the kind of rapid modernization that other industries have undergone. The consequences are borne almost entirely by patients.
The Breach Landscape in American Healthcare
The numbers are stark. According to the U.S. Department of Health and Human Services Office for Civil Rights — which maintains a public database of healthcare data breaches affecting 500 or more individuals — more than 133 million Americans had their health records exposed in 2023 alone, a record figure that represented a near doubling of the prior year's totals. The Identity Theft Resource Center has classified healthcare as the most frequently breached sector in the United States for over a decade running.
High-profile incidents illustrate the scale. The 2024 cyberattack on Change Healthcare, a subsidiary of UnitedHealth Group that processes roughly one-third of all US medical claims, disrupted billing and prescription fulfillment at thousands of facilities nationwide and exposed the protected health information of an estimated 100 million individuals — making it the largest healthcare data breach in American history. Investigators attributed the intrusion in part to the absence of multi-factor authentication on a critical remote access portal.
But large-scale ransomware events, while dramatic, represent only one vector. Quieter, structural vulnerabilities exist at every level of the healthcare ecosystem.
Where the Infrastructure Fails
Fax and unencrypted transmission. A standard fax transmission travels over the public switched telephone network without encryption. A misdirected fax — sent to a wrong number, received in an unsecured location, or intercepted through a compromised line — constitutes a breach under the Health Insurance Portability and Accountability Act (HIPAA). Yet the practice persists because HIPAA's technical safeguard requirements, last substantively updated in 2013, do not categorically prohibit fax use. Compliance is assessed against a "reasonable and appropriate" standard that has historically been interpreted permissively.
Legacy electronic health record (EHR) systems. Many regional hospitals and smaller clinical practices operate on EHR platforms built in the late 1990s or early 2000s. These systems frequently lack support for modern encryption protocols, do not receive security patches, and cannot integrate with contemporary identity verification frameworks. Replacing them is expensive and operationally disruptive — so they persist, often connected to modern networks in ways their architects never anticipated, creating hybrid environments that are notoriously difficult to secure.
Unencrypted email. Despite clear guidance from HIPAA's Security Rule requiring covered entities to protect electronic protected health information (ePHI) in transit, a significant volume of internal and external healthcare communication occurs over standard email without end-to-end encryption. A 2022 investigation by ProPublica found numerous medical providers transmitting patient lab results, diagnoses, and insurance information through unencrypted channels.
Third-party vendor exposure. Modern healthcare organizations rely on extensive networks of business associates — billing companies, transcription services, telehealth platforms, and medical device manufacturers. Each represents a potential breach vector. HIPAA requires covered entities to execute Business Associate Agreements (BAAs) with these vendors, but the depth of security due diligence applied to those relationships varies enormously.
What HIPAA Does — and Doesn't — Do
HIPAA is frequently misunderstood as a comprehensive data security law. It is more accurately described as a minimum-standard compliance framework with significant structural limitations.
The law's enforcement mechanism is complaint-driven and under-resourced. The HHS Office for Civil Rights, which investigates HIPAA violations, has a small investigative staff relative to the volume of complaints it receives. Civil monetary penalties, while occasionally substantial in high-profile cases, have historically been inconsistent. And HIPAA does not grant individual patients a private right of action — meaning you cannot personally sue a covered entity for a HIPAA violation, even if your records were exposed through demonstrable negligence.
Moreover, HIPAA applies only to "covered entities" — healthcare providers, health plans, and healthcare clearinghouses — and their designated business associates. A wide range of health-related applications, wellness platforms, and data brokers that handle sensitive health information fall entirely outside its scope.
How Criminals Exploit the Gap
Medical records are among the most valuable commodities on underground markets, commanding prices that routinely exceed those of financial credentials. A complete medical record can include a Social Security number, date of birth, insurance information, medication history, and diagnosis codes — enough to commit insurance fraud, prescription fraud, and identity theft simultaneously.
Phishing campaigns targeting healthcare workers are a primary initial access vector. Hospital staff, under significant operational pressure, represent attractive targets for credential-harvesting emails impersonating EHR vendors, insurance portals, or internal IT departments. Once a single employee account is compromised, lateral movement through poorly segmented legacy networks can be rapid.
Patients themselves are also directly targeted. Following a breach, affected individuals frequently receive fraudulent calls or emails purporting to be from their healthcare provider, insurer, or a government health agency — using confirmed personal information from the breach to establish false credibility before soliciting additional data or financial information.
Practical Steps Patients Can Take
While individual patients cannot remediate systemic infrastructure failures, several concrete actions can limit personal exposure.
Request your records and review them. Under HIPAA, you have the right to access your medical records. Request copies periodically and review them for unfamiliar diagnoses, procedures, or providers — indicators of medical identity theft. The Federal Trade Commission provides guidance on disputing inaccurate medical records.
Monitor your Explanation of Benefits (EOB). Review every EOB statement from your insurer. Charges for services you did not receive are a primary signal of medical fraud conducted in your name.
Be skeptical of post-breach outreach. If you receive notification that your healthcare data has been exposed, treat all subsequent communications claiming to be from that organization with heightened scrutiny. Verify contact information independently through the provider's official website before responding to any inquiry.
Limit data shared with health apps. Consumer wellness applications — fitness trackers, mental health platforms, nutrition apps — are generally not HIPAA-covered entities. Review their privacy policies carefully and avoid connecting them to your formal medical records unless there is a compelling clinical reason.
Ask your providers about their security practices. Patients have the right to ask how their information is transmitted and stored. A provider that cannot answer basic questions about data security is itself a signal worth weighing.
The healthcare system's security debt has been accumulating for decades. The criminals targeting it are not waiting for the industry to modernize. Until structural reform arrives — through regulatory update, litigation pressure, or federal investment — patients must treat their own medical data as an asset requiring active protection.