HIPAA Compliance & Data Protection

CM Relay is built with compliance in mind. Our Enterprise plan supports HIPAA-compliant email relay with Business Associate Agreement (BAA) documentation available upon request.

🔐 HIPAA-Compliant Infrastructure

Our Enterprise plan is designed to meet the technical safeguards required by HIPAA, including:

  • AES-256 encryption for all data at rest
  • TLS 1.2+ encryption for all data in transit
  • Encrypted OAuth token storage with per-tenant encryption keys
  • Role-based access controls and audit logging
  • Secure cloud infrastructure with regular security assessments

📄 Business Associate Agreement (BAA)

Organizations subject to HIPAA require a Business Associate Agreement with any vendor that handles Protected Health Information (PHI). CM Relay’s Enterprise plan includes:

  • Executed BAA documentation available on request
  • Clearly defined responsibilities and breach notification procedures
  • Annual review and renewal process
  • Compliance documentation for your records and auditors

The Scan-to-Email Compliance Risk Most Companies Miss

When organizations set up multifunction copiers and scanners with scan-to-email, they typically configure a shared mailbox or SMTP relay and consider the job done. But there’s a critical compliance risk that most companies overlook:

Without send-to restrictions, any employee can scan confidential documents to any email address in the world.

Think about what your copier can access. Employees scan payroll records, contracts, patient files, financial statements, legal documents, and personally identifiable information (PII). If your scan-to-email has no restrictions on where those emails can be sent, you have an unmonitored data exfiltration channel sitting in your office — accessible to anyone who walks up to the machine.

⚠️ The Risk

  • A departing employee scans proprietary client lists to their personal email
  • A contractor scans financial records to an external address
  • A temp worker scans HR documents with Social Security numbers to themselves
  • No logs, no alerts, no way to know it happened

✅ How CM Relay Solves This

  • Configure allowed recipient addresses or domains — block all others
  • Every send attempt (allowed or blocked) is logged with source IP, recipient, subject, and timestamp
  • Unauthorized sends are flagged in the mail log for immediate review
  • Full audit trail for compliance reporting and incident response

Send-To Restrictions

CM Relay’s send-to restriction feature gives you granular control over where your devices can send email. Configure allow-lists by individual address, domain, or pattern.

🌐 Domain-Level Controls

Restrict scan-to-email to your own company domain only. For example, allow @yourcompany.com and block everything else. Employees can still scan to internal colleagues, but cannot send documents to personal Gmail or Yahoo accounts.

📋 Full Audit Logging

Every email attempt — whether allowed or blocked — is recorded in the mail log with sender, recipient, subject line, timestamp, delivery status, and source IP address. If a current or former employee tries to scan a document to an unauthorized address, you’ll see it in the log immediately.