Skip to content
HexaTransfer
Back to blog
GDPR & Compliance

Healthcare File Sharing Rules: Compliance Essentials

Essential compliance rules for sharing healthcare files including patient data protection, authorized access, and secure transmission protocols.

Healthcare file sharing rules come down to one idea: Protected Health Information (PHI) only moves through channels that encrypt it, log it, and restrict it to authorized recipients. Under HIPAA's Security Rule, any tool sending a DICOM scan, a 45 MB EHR export, or a lab PDF needs AES-256 encryption, TLS 1.3 in transit, per-user access controls, and a signed Business Associate Agreement with the vendor. GDPR Article 9 adds consent and minimization requirements for EU patients. HITECH layers breach notification within 60 days, and 2026 rules in several states tighten that further.

What Counts as PHI in a File

PHI is any health information tied to one of 18 identifiers: name, email, medical record number, insurance ID, biometric data, face photo, and so on. A radiology image without a name still counts if the DICOM header preserves the patient ID. A staff schedule with no medical details probably isn't PHI, but add a note like "move Jordan's appointment after chemo" and it becomes PHI. This matters because the file transfer rules apply the moment anything on that list appears in your .pdf, .xlsx, or .zip. Clinics get this wrong by treating summary reports as "de-identified" when birth date and ZIP code combine to re-identify individuals under HIPAA's Safe Harbor test.

The BAA Is Non-Negotiable

HIPAA's Privacy Rule at 45 CFR 164.504(e) requires a Business Associate Agreement with any vendor handling PHI on behalf of a covered entity. That includes the file transfer service. The BAA names the vendor as a Business Associate, requires them to implement Security Rule safeguards, commits them to breach notification, and bars sharing PHI with sub-contractors who haven't signed their own agreements. Consumer file transfer products rarely offer a BAA on free tiers. Healthcare-specific services like Paubox, Kiteworks, and enterprise tiers of Dropbox do. Before a single patient file moves, the BAA needs to be countersigned and on file.

Minimum Technical Safeguards Under the Security Rule

The Security Rule at 45 CFR 164.312 is surprisingly concrete for a law from 2003. It mandates unique user identification, automatic logoff, encryption and decryption mechanisms, audit controls, and transmission security. In practice for file transfer that means: every recipient authenticates individually rather than sharing a link, idle sessions close after 15 minutes, files are encrypted end-to-end with AES-256-GCM, every access creates a log entry, and the transport layer uses TLS 1.3. The 2024 Notice of Proposed Rulemaking from HHS OCR pushes toward making these addressable specifications mandatory rather than "reasonable and appropriate."

Authorized Access and the Minimum Necessary Standard

Sharing a patient chart with a specialist is fine. Sharing the full EHR export when only three pages are relevant violates HIPAA's minimum necessary standard. File transfer tools can help by supporting recipient-specific access, expirable links tied to a named email, and download caps. A primary care clinic sending a 180 MB export to a cardiologist should instead send a 4 MB extract covering relevant labs and imaging. When that's impractical, redaction via tools like Adobe Acrobat's redaction feature or open-source libraries like PyMuPDF cuts down what leaves the facility.

Patient Consent and GDPR Article 9

European patients have stronger defaults than US patients. GDPR Article 9 categorizes health data as special category data, requiring explicit consent or another specific lawful basis. For a UK hospital sharing a scan with a German specialist, that consent has to be documented and withdrawable. Many EU health systems use standardized consent forms captured during registration. The file transfer tool doesn't manage consent itself, but the process around it matters: don't send the file before the consent is on record, and keep the consent artifact linked to the transfer log.

Breach Notification Timelines

If a laptop with unencrypted patient files gets stolen, or a misaddressed transfer link reaches the wrong recipient, HIPAA's Breach Notification Rule kicks in. Covered entities have 60 days to notify affected individuals, HHS, and sometimes media for breaches over 500 records. GDPR is tighter: 72 hours to the supervisory authority. Several US states now require faster notification, California's CMIA at 15 days for certain breaches. The fastest way to avoid the timeline is to use encryption that qualifies for safe harbor under HHS guidance. A stolen laptop with AES-256-encrypted files often doesn't trigger notification because the data is considered unusable.

Auditing and Retention

HIPAA requires six years of retention for policies, audit logs, and risk assessments. File transfer logs fit into that. A typical audit request from OCR after a complaint wants to see: who uploaded a specific patient's record, when, who downloaded it, from which IP, and whether the transfer was encrypted. The log format should be machine-readable and exportable. Tools that only keep logs for 90 days fail this requirement unless you ingest them into a SIEM. Health systems often route transfer logs into Splunk, Sumo Logic, or Microsoft Sentinel with six-year cold storage on S3 Glacier or Azure Archive.

Cross-Border Clinical Research Files

Pharmaceutical companies running trials across the US, EU, and Asia face overlapping rules. A 500 MB dataset moving from a Boston CRO to a Munich investigator crosses HIPAA and GDPR boundaries. The workable setup: encrypt the file locally with AES-256 before upload, use a transfer tool with EU residency, include a Data Transfer Agreement referencing the 2021 SCCs, and pseudonymize patient identifiers with a key held only at the origin. For DICOM imaging, tools like dcm4che's de-identification profiles strip PHI from headers before export.

HexaTransfer encrypts files in your browser with AES-256-GCM before upload, stores ciphertext in EU data centers, and deletes after 7 days. Try it at hexatransfer.com — free, no account, 10 GB max. For regulated production use, pair it with your organization's BAA review.

Healthcare file sharing works when the tool, the process, and the paperwork line up. Encryption keeps the data safe if something goes wrong. Access controls keep the right eyes on the file. Logs prove compliance when auditors come asking. Skip any one of those, and a single misrouted .pdf becomes a reportable breach.

Send large files securely with end-to-end encryption

Transfer files up to 10 GB for free with end-to-end encryption. No account required. Your files are encrypted in your browser before upload — no one else can read them.

Send a file