Administrative safeguards
Governance turns security from a product setting into a repeatable operating practice.
- Risk analysis and risk management
- Workforce authorization and training
- Security incident procedures
- Contingency planning and evaluation
Quantum secure · GDPR & ISO 27001 focused
My MX Data gives healthcare organizations and their partners a controlled route for exchanging sensitive health files. Named-recipient access, permissions, multi-factor authentication, protected storage and detailed activity records can support the technical and operational safeguards around ePHI.
No credit card required. Up to 5 users.
Technology can support a HIPAA program, but no file-sharing product makes an organization compliant by itself. Coverage, permitted uses, minimum-necessary decisions, policies, risk analysis, contracts and breach obligations remain with the regulated organization.
SENDER VERIFIEDAuthorized user submitted the approved patient-data package.
POLICY APPLIEDRecipient, permissions and file protection controls confirmed.
ACCESS RECORDEDNamed recipient completed verification and accessed the exchange.
HIPAA is not a single encryption requirement. Covered entities and business associates need to consider privacy, security, permitted disclosures, contracts, incident response and the evidence that shows how safeguards operate in practice.
The HIPAA Privacy Rule establishes standards for protected health information, while the Security Rule focuses on administrative, physical and technical safeguards for ePHI.
When sensitive files move outside the source system, the handoff should still reflect the organization’s policies: an approved purpose, the correct data set, the right recipient, suitable access controls and a record that can support oversight.
Sets standards for uses and disclosures of PHI and gives individuals rights over their information.
purpose and disclosureRequires reasonable and appropriate safeguards for the confidentiality, integrity and availability of ePHI.
administrative • physical • technicalCreates notification duties following breaches of unsecured PHI, with different responsibilities for covered entities and business associates.
detect • assess • notifyContracts and direct regulatory duties matter when another organization creates, receives, maintains or transmits PHI on a covered entity’s behalf.
contract and accountabilityA file-sharing control is most effective when it supports the policies, workforce practices, physical environment and technical architecture around it.
Governance turns security from a product setting into a repeatable operating practice.
Facilities, workstations and devices still affect who can reach systems and health information.
System controls help manage access, integrity, authentication and transmission security.
My MX Data primarily supports the controlled-exchange and evidence layer. It does not replace the risk analysis, policy, training, device, facility or broader system controls required across the organization.
A secure platform can make the handoff clearer, but the organization still needs a repeatable approval process before the file is released.
Identify the permitted use, disclosure or operational basis for sharing the information.
Prepare the information reasonably needed for the purpose and exclude unnecessary content.
Confirm the person, organization and authority behind the destination account.
Set permissions, authentication and file-protection controls for the exchange.
Keep the activity history with the wider approval, contract and compliance evidence.
The file route can enforce recipient and access settings, while the covered entity or business associate remains responsible for deciding whether the disclosure is permitted, appropriately limited and correctly documented.
A controlled exchange can help translate internal access decisions into a more precise external handoff. The legal standard and any exceptions must still be assessed by the organization.
Prepare a purpose-specific package rather than exporting a complete record by default.
Use named accounts and recipient verification instead of open or reusable public links.
Escalate unusual, urgent or broad disclosures through the appropriate privacy and security process.
Illustrative only. Actual permissions depend on the purpose, relationship, applicable HIPAA provision, organizational policy and any other legal restriction.
Where a vendor or partner performs functions involving PHI on behalf of a covered entity, the parties need to determine their roles and put the required written assurances in place.
HHS explains that covered entities generally need written satisfactory assurances from business associates that PHI will be appropriately safeguarded. Confirm whether a BAA is required and what contractual arrangements are available during procurement; a secure product interface is not a substitute for the contract.
When a disclosure or access event is questioned, teams need facts: which file moved, who initiated it, which recipient was named, what controls were applied and what activity followed.
Those facts can support the security-incident and breach-assessment process, but they do not decide whether an event meets the legal definition of a breach or who must be notified.
Authorized workforce member selected a referral package for external delivery.
Named account, permissions and authentication requirements attached to the exchange.
Destination user completed the required sign-in and verification step.
Access event recorded for review alongside the organization’s wider logs and evidence.
Exchange history exported to the incident file for legal and security assessment.
Use technology to make approved exchanges more deliberate, more restricted and easier to reconstruct.
Direct sensitive files to identified accounts rather than broadly reusable links or unmanaged attachments.
Explore the featuresConfigure how approved recipients interact with a file and keep the exchange within a defined route.
View platform controlsAdd an extra verification step before the recipient can access protected information.
See encrypted file sharingUse My MX Data’s patented anonymize, shard and restore methodology within the protected exchange.
Understand the protection modelRetain a clearer account of sender, recipient and file events for oversight and incident review.
Read about audit trailsGive designated administrators a clearer way to manage users, exchanges and operational policy.
View the product walkthroughDifferent teams can use the same controlled-exchange principles while applying their own approval, minimum-necessary and retention rules.
Deliver referral records, imaging or supporting documents to the identified receiving team without relying on ordinary attachment chains.
named destination • documented handoffProvide an approved access-response package through a restricted route after identity, scope and redaction work is complete.
verified recipient • protected deliveryExchange approved files with billing, legal, analytics or operational partners under the applicable contract and access policy.
role clarity • permission controlsShare logs, investigation records or compliance evidence with authorized reviewers through a controlled channel.
evidence integrity • activity historyMy MX Data can support secure file handoffs and the activity evidence around them. Compliance still depends on how the organization scopes, configures, contracts for and operates the service within its wider environment.
Important: My MX Data should not be described as certified, approved or endorsed by HHS or OCR, or as making a customer HIPAA compliant automatically. Any HIPAA role, contractual requirement and permitted use must be determined from the actual service arrangement.
Named accounts, permissions, MFA, protected storage and activity records can reduce uncertainty around an approved exchange.
Privacy, clinical, legal and security teams determine the purpose, recipient, information set and applicable exception.
The assessment must consider all ePHI created, received, maintained or transmitted across the regulated environment.
Required written assurances, allocation of duties and incident-notification terms must be handled through the appropriate agreement.
HHS has proposed significant Security Rule changes. Organizations should monitor the rulemaking while continuing to comply with requirements currently in force.
These answers explain the operational role of controlled file exchange. They are general information and not legal advice.
Visit all FAQsHIPAA is a federal framework that includes privacy, security, breach-notification and enforcement requirements for protected health information. The core regulated groups are covered entities, including health plans, health care clearinghouses and certain health care providers that conduct covered electronic transactions, together with their business associates.
Business associates are organizations or people that perform particular functions or services involving PHI on behalf of a covered entity. Some subcontractors of business associates can also fall within the regulated chain. The label depends on the actual function and data relationship, not simply whether an organization works somewhere in healthcare.
The official HHS covered entities and business associates guidance is the appropriate starting point for role analysis.
No single product makes an organization HIPAA compliant. My MX Data can support selected technical and operational controls around the transfer of sensitive files, but HIPAA compliance extends across governance, risk analysis, policies, workforce behavior, facilities, devices, systems, contracts and incident response.
The platform can make an approved handoff more controlled through named-recipient access, configurable permissions, multi-factor authentication, file protection and detailed activity records. Those capabilities may reduce risks associated with ordinary attachments, uncontrolled public links and unclear recipient access.
My MX Data should therefore be described as supporting a HIPAA-aligned secure file-exchange workflow, not as replacing the wider compliance program.
The HIPAA Security Rule uses a framework of required and addressable implementation specifications. Encryption is an important safeguard, but an addressable specification is not the same as an optional control that can simply be ignored. A regulated entity must assess whether the safeguard is reasonable and appropriate and, if it is not implemented, document the reasoning and any equivalent alternative where appropriate.
That analysis should be based on the organization’s risk analysis, environment and the way ePHI is created, received, maintained or transmitted. For external file exchange, encryption alone also leaves other questions unanswered:
A controlled exchange combines file protection with identity, permissions and activity evidence rather than treating encryption as the entire compliance answer.
A covered entity generally needs written satisfactory assurances when a business associate creates, receives, maintains or transmits PHI on its behalf. These assurances are normally documented in a contract or other arrangement commonly called a business associate agreement or BAA.
The agreement addresses how PHI may be used and disclosed, the safeguards that must be applied, incident and breach reporting, subcontractors and what happens to PHI when the relationship ends. The required terms depend on HIPAA and the actual services, while state law and ordinary commercial provisions may add further requirements.
HHS publishes sample business associate agreement provisions, but organizations should obtain legal review for their own arrangement.
The minimum-necessary standard generally asks regulated entities to make reasonable efforts to limit certain uses, disclosures and requests for PHI to what is needed for the intended purpose. It does not apply identically in every situation, and there are important exceptions, so the privacy team must determine the correct legal treatment.
A secure exchange can support the operational side of that decision by creating a purpose-specific package and directing it to a defined recipient rather than distributing a broad export to an open group.
The platform cannot decide what is legally necessary. It helps enforce the delivery decision after the organization has made and documented it.
No. An activity log is evidence, not a legal conclusion. It may show when a file was submitted, which account was named, what access event occurred and which settings were applied. Those facts can materially improve the investigation, but the organization must assess the full circumstances under the applicable breach framework.
A breach analysis may consider the nature and extent of the PHI, the unauthorized person, whether the information was actually acquired or viewed and the extent to which risk was mitigated. Evidence may also be needed from identity systems, endpoints, email, applications, interviews and third parties.
The HHS Breach Notification Rule guidance explains the federal notification framework.
Risk analysis is foundational to the Security Rule. HHS describes it as the first step in identifying risks and vulnerabilities affecting the confidentiality, integrity and availability of ePHI. The scope must cover all ePHI the regulated entity creates, receives, maintains or transmits, rather than only the files held in one transfer product.
For a file-exchange service, the assessment may examine user provisioning, authentication, recipient errors, configuration, device access, integrations, retention, incident response, subcontractors and the way exports are prepared before upload.
Use the current HHS risk-analysis guidance and NIST SP 800-66 Revision 2 as authoritative implementation resources.
HHS published a notice of proposed rulemaking in December 2024 that would significantly strengthen and make more specific a range of Security Rule requirements. A proposal is not the same as a final rule. Organizations should distinguish the requirements currently in force from measures that may become mandatory after rulemaking is completed.
The proposal includes subjects such as more specific risk-analysis documentation, technology asset inventories, network maps, stronger authentication and encryption expectations, testing, incident planning and enhanced business-associate duties. These themes can still be useful indicators of regulatory direction, but they should not be presented as final legal requirements unless and until HHS finalizes them.
Check the official HIPAA Security Rule NPRM page for current information rather than relying on an undated summary.
Bring healthcare, privacy, security and external partners into a more accountable exchange, with clearer controls around recipient access and a more useful activity history.
No credit card required. Up to 5 users.
Free for 7 days · up to 5 users
Trusted for 150K+ exchanges weekly
No credit card required. Set up in minutes.
Check your inbox, your MX trial details are on their way. Welcome to properly secure file sharing.