By David Thompson · Published May 18, 2025 · Updated June 8, 2026 · 8 min read
Quick Answer: Yes, you can fax PHI under HIPAA — but only with proper safeguards. Use a HIPAA-compliant fax service with encryption, a signed BAA, and a compliant cover sheet. mFax Business checks every box.
Faxing protected health information (PHI) remains one of the most common ways healthcare providers share patient data — referrals, lab results, prescriptions, and insurance claims all travel by fax every day. But a single misdirected fax or an unsecured transmission can trigger a HIPAA breach with penalties reaching $2 million per violation.
The good news: HIPAA doesn't ban faxing PHI. The Privacy Rule explicitly permits it for treatment, payment, and healthcare operations — as long as reasonable safeguards protect the information. This guide walks you through every safeguard your practice needs.
The Bottom Line
Faxing PHI without safeguards isn't just risky — it's illegal. St. Luke's-Roosevelt Hospital Center paid $387,200 to settle a case where staff repeatedly faxed PHI to a wrong number instead of using the patient's requested delivery method.
What Counts as PHI?
Protected Health Information is any individually identifiable health information held or transmitted by a covered entity. If a fax connects a person's identity to their health data, it's PHI.
| PHI Examples | NOT PHI |
|---|---|
| Patient name + diagnosis | De-identified statistical data |
| Medical record number + lab results | Aggregate hospital metrics |
| Social Security number on a claim form | Employee wellness tips (no names) |
| Insurance ID + treatment dates | Publicly available health articles |
| Fax containing prescription details | Blank fax cover sheet template |
The minimum necessary standard applies: send only the PHI required for the specific purpose. Don't fax an entire patient chart when the recipient only needs one lab result.
The Three HIPAA Safeguard Categories
HIPAA requires three categories of safeguards whenever you transmit PHI — including by fax. Miss any one of them and your practice is exposed. For a deeper dive, see our HIPAA fax requirements checklist.
Administrative Safeguards
Administrative safeguards are the policies and training that govern how your staff handles PHI by fax.
- ✓Written fax policy: Document who can send/receive PHI faxes, when, and to which recipients.
- ✓Staff training: Train every employee who touches PHI on fax procedures — at onboarding and annually.
- ✓Designated fax coordinator: Assign someone to monitor incoming faxes and distribute them promptly.
- ✓Sanctions policy: Define consequences for employees who violate fax procedures.
- ✓Incident response plan: Establish a step-by-step process for misdirected faxes (see below).
Technical Safeguards
Technical safeguards ensure the transmission itself is secure.
- ✓Encryption in transit: Use TLS 1.2+ for online fax transmissions. Analog fax lines are point-to-point but lack encryption — an inherent risk.
- ✓Encryption at rest: Stored faxes (digital copies, confirmations) must be encrypted with AES-256 or equivalent. See our fax encryption guide for details.
- ✓Access controls: Restrict fax system access to authorized users only — no shared logins.
- ✓Audit trails: Log every fax: sender, recipient, timestamp, page count, and delivery status.
- ✓Business Associate Agreement: Sign a BAA with any third-party fax vendor before transmitting PHI.
Physical Safeguards
Physical safeguards protect the paper trail.
- ✓Secure location: Place fax machines in restricted areas — not the front desk or a shared hallway.
- ✓Immediate pickup: Collect received faxes promptly. PHI sitting in an open tray is an exposure.
- ✓Secure disposal: Shred faxed documents containing PHI when no longer needed.
- ✓Pre-programmed numbers: Save frequently used fax numbers to reduce dialing errors.
How to Fax PHI Safely: Step by Step
Whether you use a physical fax machine or an online service, follow this workflow every time you send PHI.
Verify the Recipient
Confirm the fax number belongs to the intended recipient. For new numbers, call ahead to verify. For saved numbers, double-check the contact entry. Read the number back digit by digit before pressing Send.
Apply the Minimum Necessary Standard
Include only the PHI required for the specific purpose. Sending a referral? Fax the referral form — not the patient's entire history. Redact unnecessary information before scanning.
Attach a HIPAA-Compliant Cover Sheet
Every PHI fax needs a cover sheet with a confidentiality disclaimer, sender/recipient details, and page count. Never put PHI on the cover sheet itself — it sits on top of the stack and is the first thing anyone sees. Use our HIPAA cover sheet template as a starting point.
Send and Confirm Delivery
Send the fax and wait for a delivery confirmation. If your machine or service provides a transmission report, save it. This is your audit trail proof that the fax reached the correct number.
Log the Transmission
Record the fax in your HIPAA disclosure log: date, time, sender, recipient, number of pages, and purpose. This is required for patient disclosure accounting under 45 CFR § 164.528.
Skip the Manual Steps
mFax Business handles steps 4 and 5 automatically — every fax gets a delivery confirmation and a searchable audit log. No paper trail to manage.
Traditional Fax Machine vs. Online Fax for PHI
Both methods are HIPAA-permissible, but they carry different risks.
| Factor | Traditional Fax Machine | Online Fax Service |
|---|---|---|
| Encryption | None — analog signal on phone line | TLS 1.2+ in transit, AES-256 at rest |
| Interception risk | Low (point-to-point) but not zero | Very low with proper encryption |
| Misdial risk | High — manual number entry | Lower — saved contacts, auto-verification |
| Audit trail | Manual — paper confirmation slips | Automatic — digital logs with timestamps |
| Physical exposure | High — paper sits in open tray | None — faxes arrive in encrypted inbox |
| BAA required? | No (you own the hardware) | Yes — vendor handles PHI |
| Cost | Hardware + phone line + maintenance | Monthly subscription |
The Verdict
Traditional fax machines are legal for PHI but increasingly risky. Cloud-based fax services with encryption and audit trails are the modern standard — and the approach recommended by most compliance consultants. Learn more about whether online fax is secure.
What Happens If You Fax PHI to the Wrong Number?
A misdirected fax containing PHI is a presumed breach under the HIPAA Breach Notification Rule (45 CFR §§ 164.400–414). Here's what you must do:
- Contact the unintended recipient immediately. Ask them to confirm destruction of the fax — shredding, not just tossing in the trash.
- Document the incident. Record the date, time, wrong number, what PHI was exposed, and your remediation steps.
- Conduct a risk assessment. Evaluate: Was the PHI actually viewed? Was it identifiable? What's the probability of harm?
- Notify if required. If the risk assessment shows a significant probability of compromise, you must notify the affected patient within 60 days. Breaches affecting 500+ individuals require notification to HHS and local media.
HIPAA Penalty Tiers for Fax Violations
| Tier | Culpability | Penalty per Violation |
|---|---|---|
| 1 | Lack of knowledge | $141 – $71,162 |
| 2 | Reasonable cause | $1,424 – $71,162 |
| 3 | Willful neglect, corrected ≤ 30 days | $14,232 – $71,162 |
| 4 | Willful neglect, not corrected | $71,162 – $2,134,831 |
Penalty amounts adjusted for inflation as of January 2026.
Real Enforcement Example
St. Luke's-Roosevelt Hospital Center paid $387,200 after staff faxed a patient's PHI to the wrong number — repeatedly. The OCR had flagged the issue nine months earlier, but the hospital failed to fix it. Misdirected faxes are one of the most common and most preventable HIPAA violations.
Fax vs. Email: Which Is Safer for PHI?
Healthcare providers often ask whether they should fax or email PHI. The short answer: both can be HIPAA-compliant, but fax is simpler to secure.
- Traditional fax uses a dedicated phone line — the signal travels point-to-point without passing through email servers, making interception harder.
- Email passes through multiple servers and is stored in cloud inboxes. Without end-to-end encryption (which most email providers lack by default), PHI is exposed at every hop.
- Cloud fax combines the best of both: digital delivery with TLS encryption, no intermediate server exposure, and automatic audit trails.
That's why faxing remains the preferred method for PHI in healthcare — and why HIPAA doesn't require patient authorization for treatment-related fax transmissions.
Your HIPAA Fax Cover Sheet for PHI
Every fax containing PHI must include a cover sheet with these elements:
- Sender information — name, organization, phone number, fax number
- Recipient information — name, organization, fax number
- Page count — including the cover sheet
- Confidentiality disclaimer — a statement like: "This fax contains confidential information protected under HIPAA. If you are not the intended recipient, you are required to destroy all copies and notify the sender immediately."
- No PHI on the cover sheet — patient names, diagnoses, or record numbers belong on inner pages only
✓DO Include on Cover Sheet
• Sender name, org, phone & fax
• Recipient name & fax number
• Total page count
• Confidentiality disclaimer
• Date and general subject line
✕DO NOT Include on Cover Sheet
• Patient names
• Diagnoses or conditions
• Medical record numbers
• Social Security numbers
• Insurance IDs or dates of birth
Generate a compliant cover sheet instantly with our free fax cover sheet generator, or download a ready-made HIPAA fax cover sheet template.
Common PHI Faxing Mistakes to Avoid
Even well-intentioned practices make these errors:
- Faxing entire patient charts instead of the specific pages needed — violates the minimum necessary standard.
- Leaving received faxes in an open tray where visitors or unauthorized staff can see them.
- Using a free online fax service that doesn't offer a BAA — your data isn't protected and you're liable.
- Not verifying new fax numbers before sending — one transposed digit creates a breach.
- Skipping the cover sheet — no confidentiality disclaimer means no legal protection if the fax is misdirected.
- Not training new hires — every staff member who touches PHI must understand fax procedures, not just clinicians.
Secure Your PHI Faxing with mFax Business
If your practice still relies on a physical fax machine for PHI, you're carrying unnecessary risk. mFax Business eliminates the most common failure points:
- TLS encryption in transit and AES-256 at rest — every fax is protected end-to-end
- Signed BAA included with every business plan
- Automatic audit trails — every transmission is logged with sender, recipient, timestamp, and delivery status
- Saved contact book — pre-verified fax numbers reduce misdial risk to near zero
- No paper tray exposure — faxes arrive in a secure digital inbox, accessible only to authorized users
Plans start at about $9/mo (billed annually), and they're fully customizable — you build your own plan with a live calculator, picking the exact number of seats and pages your practice needs instead of paying for a rigid fixed tier. Visit mFax.to/business to get started — your compliance team will thank you.