What makes an online fax service HIPAA compliant?
No fax service is "HIPAA certified" — there is no such certificate, and HHS does not certify products. What a service can do is support your compliance: sign a BAA, encrypt PHI in transit and at rest, give each user their own login, keep audit logs you can export, and be transparent about which subprocessors touch your data. Whether your organization is compliant also depends on your own policies, training and risk analysis.
There is no HIPAA certification
This is the first thing to understand, because a lot of marketing implies otherwise. HIPAA is a set of rules enforced by HHS Office for Civil Rights; it is not a certification program, and no government body certifies software as HIPAA compliant. A vendor claiming to be "HIPAA certified" is describing a private audit at best, not a government seal.
What a compliant-capable fax service provides
These are the concrete things to look for, in rough order of importance:
- A signed BAA — and clarity on whether it is included in your plan or gated behind a higher tier.
- Encryption — TLS for data in transit and encryption at rest for stored faxes.
- Individual user accounts — unique identification per person who touches PHI (45 CFR 164.312(a)(2)(i)).
- Audit logs — a record of who did what and when, exportable for your own compliance review.
- Access controls — roles and permissions, session timeouts, and two-factor authentication.
- Subprocessor transparency — the fax transport carrier and the hosting provider also touch PHI. Ask whether the vendor has BAAs with them.
- Data handling on exit — how you export your data and what happens to PHI when you cancel.
Where email notifications fit in
Many fax services email you a copy of the incoming fax. That is convenient and it is also where PHI most often leaks out of a controlled system. Some providers, including LuzardoFax, design notifications to carry no PHI — the email tells you a fax arrived and links to the secure portal, rather than attaching the document. If your provider attaches PHI to email, that email path becomes part of your risk analysis.
Questions that reveal the difference
If you only ask one thing, ask for the BAA. If you can ask five, ask these:
- Is the BAA included in the price you quoted me?
- Does every staff member get their own login on this plan?
- Can I export my audit log?
- Do your email notifications contain PHI?
- Which companies besides you can technically access my faxes?
What this still does not cover
Even with a vendor that does everything above, compliance is not finished. HHS requires each organization to perform its own risk analysis and to implement administrative safeguards appropriate to its operations. Choosing a capable vendor reduces your risk; it does not transfer your obligations.
Primary sources.
We link to the original rule and guidance so you can verify anything here yourself.
This content is provided for general informational and educational purposes only and does not constitute legal, regulatory, compliance, or professional advice. HIPAA compliance depends on the specific facts, systems, policies, and practices of each organization. Organizations should consult qualified legal or compliance professionals regarding their specific obligations.
Last reviewed: 2026-07-19. Product features, pricing, and compliance offerings may change. Verify current terms directly with each provider before making a compliance or purchasing decision.
Questions worth asking.
No. HIPAA is enforced by HHS Office for Civil Rights and there is no government certification for software. Vendors that advertise certification are usually referring to a private third-party audit, which is not the same thing.
No. Encryption is one technical safeguard among several. A signed BAA, unique user identification, audit controls and your own administrative safeguards are also part of the picture.
It is a risk decision. If the notification includes the fax itself, PHI travels through email and becomes part of your risk analysis. Some services send a link to a secure portal instead, keeping PHI out of email.
Typically the fax transport carrier and the hosting provider, at minimum. Ask your vendor for its list of subprocessors and whether it has BAAs with the ones that can access PHI.
Try it before you decide.
14 days free. No credit card. The BAA is signed in-app before you send a single page — and it stays included at every plan, forever.