← All guides

Guide

Is email-to-fax HIPAA compliant?

It depends entirely on how the email leg is handled. Email-to-fax means the document travels through email before it becomes a fax — so that email path is now part of your PHI handling and part of your risk analysis. It can be done within HIPAA, but it introduces a channel that the Security Rule expects you to have assessed and secured.

Guide

What email-to-fax actually does

In an email-to-fax workflow you attach a document to an email and send it to an address like [email protected]. The provider converts it and transmits it as a fax. Convenient — and it means the PHI passed through your email system, your provider's mail servers, and any intermediaries along the way, before the fax was ever sent.

Guide

The questions your risk analysis has to answer

The Security Rule asks you to assess risks to ePHI. For an email-to-fax workflow, that means:

  • Is your email encrypted in transit? TLS between mail servers is common but not guaranteed end to end.
  • Who else can read that mailbox? Shared inboxes, assistants with delegated access, and archived mail all count.
  • Where does the copy live afterward? The sent item stays in the mailbox, often for years, and gets backed up.
  • Does your BAA cover it? The BAA with your fax provider covers the fax service. Your email provider is a separate relationship.
  • What about the reverse direction? If incoming faxes arrive as PDF attachments in email, the same questions apply to every fax you receive.
Guide

The inbound side is where most PHI leaks

Many services email you a copy of every incoming fax. That is convenient, and it is also the single most common way PHI drifts out of a controlled system and into ordinary mailboxes. Two safer patterns exist:

  • Notification only — the email says a fax arrived and links to a secure portal, carrying no PHI itself. LuzardoFax uses this pattern by design.
  • Portal-only access — no email notification at all; staff check the secure inbox.
Guide

A reasonable position

Email-to-fax is not automatically non-compliant, and plenty of practices use it. But if you do, the email path belongs in your documented risk analysis, and you should be able to explain what protects it. If that assessment is uncomfortable, sending from a secure portal instead removes the question entirely.

Sources

Primary sources.

We link to the original rule and guidance so you can verify anything here yourself.

← Back to all guides

Legal disclaimer

This content is provided for general informational and educational purposes only and does not constitute legal, regulatory, compliance, or professional advice. HIPAA compliance depends on the specific facts, systems, policies, and practices of each organization. Organizations should consult qualified legal or compliance professionals regarding their specific obligations.

Last reviewed: 2026-07-19. Product features, pricing, and compliance offerings may change. Verify current terms directly with each provider before making a compliance or purchasing decision.

Frequently asked

Questions worth asking.

It is possible within HIPAA, but the email leg becomes part of your ePHI handling and must be covered by your risk analysis and safeguards. Sending from a secure portal avoids introducing the email channel at all.

They can be. If the notification attaches the fax document, PHI now sits in ordinary mailboxes and backups. Notifications that carry only a secure link, with no PHI, avoid that.

No. A BAA covers the relationship with that specific vendor. Your email provider is a separate relationship with its own considerations.

Transport encryption between mail servers is common but not universal or guaranteed end to end. Do not assume a message is protected in transit unless you have verified how your systems are configured.

Try it before you decide.

14 days free. No credit card. The BAA is signed in-app before you send a single page — and it stays included at every plan, forever.