What does HIPAA require for faxing patient information?
Faxing protected health information (PHI) is permitted under HIPAA. What matters is how you do it. If you use an online fax service, that vendor is handling PHI on your behalf, which generally makes them a business associate — and that relationship normally requires a signed Business Associate Agreement (BAA). Beyond the BAA, the HIPAA Security Rule requires administrative, physical and technical safeguards for electronic PHI, including access controls and audit controls.
Faxing PHI is allowed
HIPAA does not ban fax. The Privacy Rule permits covered entities to disclose PHI for treatment, payment and health care operations, and fax remains a common channel in healthcare. The question is not whether you may fax patient information — it is whether your setup meets the Security Rule when that fax is electronic.
What the Security Rule asks for
The HIPAA Security Rule sets out safeguards for electronic PHI. In practical terms, for an online fax service these are the ones that come up most often:
- Access control — assign a unique name or number for identifying and tracking user identity (45 CFR 164.312(a)(2)(i)). In practice: if several staff members handle PHI, each person needs their own login. A shared account does not satisfy unique user identification.
- Audit controls — implement mechanisms to record and examine activity in systems that contain ePHI (45 CFR 164.312(b)).
- Transmission security — guard against unauthorized access to ePHI transmitted over a network (45 CFR 164.312(e)).
- Encryption — addressable specification for protecting ePHI at rest and in transit.
- Administrative safeguards — risk analysis, workforce training, sanction policy and incident procedures (45 CFR 164.308).
The BAA is not optional
An online fax provider that creates, receives, maintains or transmits PHI on your behalf is generally a business associate, and HHS states that covered entities must have contracts in place with their business associates. If a fax provider will not sign a BAA, that provider should not carry your PHI — no matter how the service is marketed.
- Ask for the BAA before sending the first fax, not after.
- Check whether the BAA is included in the plan you are buying or only in a higher tier.
- Keep a copy. Compliance documentation under the Security Rule must be retained for six years (45 CFR 164.316(b)(2)(i)). Note this applies to the documentation, not to the fax content itself.
What is on you, not on the vendor
This is the part vendors rarely say out loud: no fax service can make an organization compliant on its own. HHS requires each organization to conduct its own risk analysis and to implement policies appropriate to its size and circumstances. A compliant vendor is a necessary piece, not the whole picture.
- Your own risk analysis and documented policies.
- Workforce training and sanctions for violations.
- Verifying fax numbers before sending, and procedures for misdirected faxes.
- Physical safeguards where faxes are printed or stored.
- Deciding who on your team may access PHI, and reviewing that periodically.
A practical checklist for evaluating a fax service
When comparing providers, these are the questions that separate marketing from substance:
- Will you sign a BAA, and is it included in the plan I am quoted?
- Does each of my staff get an individual login, or do we share one account?
- Are audit logs available to me, and can I export them?
- Is PHI encrypted at rest and in transit?
- Which subprocessors touch my PHI, and do you have BAAs with them?
- What happens to my data if I cancel?
Primary sources.
We link to the original rule and guidance so you can verify anything here yourself.
This content is provided for general informational and educational purposes only and does not constitute legal, regulatory, compliance, or professional advice. HIPAA compliance depends on the specific facts, systems, policies, and practices of each organization. Organizations should consult qualified legal or compliance professionals regarding their specific obligations.
Last reviewed: 2026-07-19. Product features, pricing, and compliance offerings may change. Verify current terms directly with each provider before making a compliance or purchasing decision.
Questions worth asking.
Faxing PHI is permitted under HIPAA. Whether a specific setup meets HIPAA depends on the safeguards around it — a signed BAA with the service provider, access controls including unique user identification, audit controls, and your own policies and risk analysis.
If the provider creates, receives, maintains or transmits PHI on your behalf, it is generally a business associate, and HHS states that covered entities must have contracts in place with business associates. Ask for the BAA before sending PHI.
The Security Rule requires assigning a unique name or number for identifying and tracking user identity (45 CFR 164.312(a)(2)(i)). If multiple staff members access ePHI, a shared login does not satisfy that requirement. Each person handling PHI should have their own credentials.
HIPAA's six-year retention requirement (45 CFR 164.316(b)(2)(i)) applies to required Security Rule documentation such as policies and procedures. Retention of medical records themselves is generally governed by state law and other requirements, not by that provision.
Try it before you decide.
14 days free. No credit card. The BAA is signed in-app before you send a single page — and it stays included at every plan, forever.