Note: Your progress in watching these videos WILL NOT be tracked. These training videos are the same videos you will experience when you take the full ProHIPAA for Leaders program. You may begin the training for free at any time to start officially tracking your progress toward your certificate of completion.

Show full transcript for HIPAA & Social Media, Mobile Devices, Email and Faxes video

In this lesson, we'll cover how HIPAA applies to electronic Protected Health Information (ePHI) across modern communication channels, including social media, mobile devices, email platforms, and faxes.

HIPAA Law & Social Media

HIPAA covers all electronic Protected Health Information across all social media platforms, including Facebook, X, Snapchat, and Instagram. Never disclose a patient's name, treatment, or identifiable health details on any social media network under any circumstance.

Personal Liability & Social Media Disclosures

Disclosing PHI on social media platforms carries severe risks. Individuals can be held personally liable both financially and criminally for posting protected health information on social channels.

Mobile Devices & Encryption Requirements

Mobile devices include smartphones, tablets, and laptops. While mobile devices can be used to share PHI, strict technical safeguards must be in place first:

  • Encrypted Messaging Required: You must use a dedicated, encrypted texting or chatting platform to transmit PHI.
  • Standard SMS & Messaging Risks: Standard messaging platforms lack sufficient encryption, store data on unapproved third-party servers, and are not HIPAA-compliant.

Email Platforms & Business Associate Agreements

Free consumer email services should never be used to send or store PHI because consumer providers generally refuse to sign a Business Associate Agreement (BAA), which is legally required to handle protected data.

Organizations must use paid enterprise email platforms (such as Google Workspace or Microsoft 365) properly configured for HIPAA compliance and supported by a signed BAA.

Pro Tip: The Cost of Insecure Email: Unsecured email communications lead to major regulatory penalties. In 2019, Solara Medical Supplies agreed to a $3 million OCR settlement following an email breach that exposed over 114,000 patient records.

Fax Machine & eFax Compliance

Faxes remain an approved and compliant method for transmitting PHI, provided essential security protocols are followed:

  • Cover Sheets: Always use a HIPAA-compliant cover sheet before sending PHI through a physical fax machine or eFax service.
  • Erroneous Faxes Sent: If PHI is faxed in error, contact the recipient immediately and instruct them to destroy the transmitted information.
  • Erroneous Faxes Received: If you receive PHI in error, notify the sender right away and destroy the document immediately.

Guidelines for Properly Disposing of PHI

So what do you do if you do receive PHI in error or no longer need access to it?  Disposing of PHI is of the utmost importance, particularly in our modern digital world where deleted files and posts are rarely ever completely gone. Following these PHI disposal guidelines will help ensure you and your organization remain HIPAA compliant. Click each guideline to learn more about proper disposal protocols:

1. Shredding Hard Copies

Shred all hard copies containing Protected Health Information (PHI) when the copies are no longer needed.

2. Recycling Paper Records

Place hard copies designated for recycling into locked recycle bins whenever available.

3. Deleting Digital Files (Soft Copies)

Delete all soft copy files containing PHI from your workstation computer and local server once the information is no longer required within your record retention requirements.

4. Destroying Removable Media

Physically destroy all disks, CDs, and external media drives that contained PHI prior to disposal.

5. Sanitizing Reusable Media

Do not reuse disks, CDs, or storage drives that previously contained PHI without thoroughly sanitizing them first.

6. Equipment Transfer & IT Protocol

Contact your IT department before transporting or transferring hardware. IT must follow proper procedures to move equipment and sanitize hard drives and storage media.

7. Contractual Returns

Return PHI directly to the original sender if this requirement is stipulated in any contractual agreements.