Printers, Copiers and eFax: The Overlooked Data Leaks

When facilities review security, they think about servers, computers and email. The multifunction copier in the hallway rarely makes the list, yet it scans, stores, prints and sometimes emails resident records all day. Fax, still a standard method for exchanging orders, referrals and lab results in healthcare, adds another channel that is often overlooked.

These devices are essentially computers with network connections, storage and software. Treat them accordingly.

What can go wrong

Default passwords left unchanged on the printer's administration page.

Stored documents. Many copiers keep images of scanned and copied pages on an internal drive.

Unpatched firmware with known vulnerabilities.

Open network access. A printer on the same network as everything else can be a stepping stone for an attacker.

Printed pages left in output trays where visitors or other staff can see them.

Misdirected faxes sent to the wrong number.

Scan-to-email abuse, where a poorly configured device is used to send unauthorized mail.

Devices returned at lease end with data still on the hard drive.

Secure the device itself

Change default credentials on every printer and copier, and use unique, strong passwords stored in your password manager.

Update firmware on a schedule. Include printers in your patching program.

Disable unused features, such as unneeded network protocols, guest scanning and remote services.

Restrict network access. Place printers on their own network segment with rules that allow only the necessary traffic from user computers.

Enable encryption for stored data and for network communication, where supported.

Turn on logging and review it for unusual activity.

Control what stays on the device

Enable automatic overwriting of temporary job data, if the copier offers it.

Disable storage of scanned documents on the device or limit retention.

Use secure print release, so that jobs print only when the user taps a badge or enters a PIN at the machine.

Place printers in staff-only areas and not at public counters.

Handle scanning carefully

Scan-to-folder and scan-to-email are convenient but risky.

Limit scan destinations to approved folders with appropriate permissions.

Require authentication to use scanning.

Restrict scan-to-email to internal addresses or your own domain, where practical.

Use secure email and avoid sending resident information through unprotected channels.

Fax: still essential, still risky

Traditional fax over a phone line has some inherent privacy advantages, since it does not travel across the open internet, but it brings human error risk. Many organizations have moved to cloud-based eFax services that deliver documents to secure mailboxes or portals. If you use one:

Choose a provider that will sign a business associate agreement.

Require multi-factor authentication for access.

Control who can see each inbox and review permissions regularly.

Confirm that documents are encrypted in transit and at rest.

Set retention rules so old faxes do not accumulate indefinitely.

For all fax use, put reasonable practices in place:

Use cover sheets with a confidentiality statement.

Verify numbers before sending and save frequently used numbers as pre-programmed entries.

Call to confirm receipt for highly sensitive documents.

Have a process for reporting and retrieving misdirected faxes, and assess whether they are reportable under HIPAA.

Retire devices responsibly

Before returning a leased copier, selling a printer or recycling equipment:

Ask the vendor to securely erase or remove the hard drive.

Obtain a written certificate of data destruction.

Record the disposal in your asset inventory.

The HIPAA Security Rule requires policies for the disposal and reuse of electronic media, and copiers are covered.

Make it part of your inventory

Include printers, copiers and fax devices in your asset list and risk analysis. Note their location, model, firmware status and who manages them. If a vendor supports them, make sure their remote access is controlled and covered by an agreement.

Quick audit checklist

Are default passwords changed?

Is firmware current?

Are stored images overwritten or disabled?

Is secure print release enabled?

Are fax inboxes restricted?

Is there a plan for end-of-lease disposal?

How UnityCare IT can help

UnityCare IT includes printers, copiers and eFax services in security reviews and can help configure and manage them for healthcare and senior living clients. We can walk through your devices and identify quick fixes.

More Articles

Contact UnityCare Technologies

Call or text: 405-285-3845

New customers: start@unitycareit.com

Existing customers: support@unitycareit.com

Address: UnityCare Technologies, 2524 N Broadway Ste 554, PMB 947974, Edmond, Oklahoma 73034-4172