Faxing PHI: How to Send Protected Health Information Safely

Faxing protected health information (PHI) is legal under HIPAA — but only with the right safeguards. Learn the administrative, technical, and physical controls your practice needs, plus how to avoid costly misdirected-fax breaches.

Faxing PHI: How to Send Protected Health Information Safely

By David Thompson · Published May 18, 2025 · Updated June 8, 2026 · 8 min read

Quick Answer: Yes, you can fax PHI under HIPAA — but only with proper safeguards. Use a HIPAA-compliant fax service with encryption, a signed BAA, and a compliant cover sheet. mFax Business checks every box.


Faxing protected health information (PHI) remains one of the most common ways healthcare providers share patient data — referrals, lab results, prescriptions, and insurance claims all travel by fax every day. But a single misdirected fax or an unsecured transmission can trigger a HIPAA breach with penalties reaching $2 million per violation.

The good news: HIPAA doesn't ban faxing PHI. The Privacy Rule explicitly permits it for treatment, payment, and healthcare operations — as long as reasonable safeguards protect the information. This guide walks you through every safeguard your practice needs.

The Bottom Line

Faxing PHI without safeguards isn't just risky — it's illegal. St. Luke's-Roosevelt Hospital Center paid $387,200 to settle a case where staff repeatedly faxed PHI to a wrong number instead of using the patient's requested delivery method.

What Counts as PHI?

Protected Health Information is any individually identifiable health information held or transmitted by a covered entity. If a fax connects a person's identity to their health data, it's PHI.

PHI ExamplesNOT PHI
Patient name + diagnosisDe-identified statistical data
Medical record number + lab resultsAggregate hospital metrics
Social Security number on a claim formEmployee wellness tips (no names)
Insurance ID + treatment datesPublicly available health articles
Fax containing prescription detailsBlank fax cover sheet template

The minimum necessary standard applies: send only the PHI required for the specific purpose. Don't fax an entire patient chart when the recipient only needs one lab result.


The Three HIPAA Safeguard Categories

HIPAA requires three categories of safeguards whenever you transmit PHI — including by fax. Miss any one of them and your practice is exposed. For a deeper dive, see our HIPAA fax requirements checklist.

Administrative Safeguards

Administrative safeguards are the policies and training that govern how your staff handles PHI by fax.

  • ✓Written fax policy: Document who can send/receive PHI faxes, when, and to which recipients.
  • ✓Staff training: Train every employee who touches PHI on fax procedures — at onboarding and annually.
  • ✓Designated fax coordinator: Assign someone to monitor incoming faxes and distribute them promptly.
  • ✓Sanctions policy: Define consequences for employees who violate fax procedures.
  • ✓Incident response plan: Establish a step-by-step process for misdirected faxes (see below).

Technical Safeguards

Technical safeguards ensure the transmission itself is secure.

  • ✓Encryption in transit: Use TLS 1.2+ for online fax transmissions. Analog fax lines are point-to-point but lack encryption — an inherent risk.
  • ✓Encryption at rest: Stored faxes (digital copies, confirmations) must be encrypted with AES-256 or equivalent. See our fax encryption guide for details.
  • ✓Access controls: Restrict fax system access to authorized users only — no shared logins.
  • ✓Audit trails: Log every fax: sender, recipient, timestamp, page count, and delivery status.
  • ✓Business Associate Agreement: Sign a BAA with any third-party fax vendor before transmitting PHI.

Physical Safeguards

Physical safeguards protect the paper trail.

  • ✓Secure location: Place fax machines in restricted areas — not the front desk or a shared hallway.
  • ✓Immediate pickup: Collect received faxes promptly. PHI sitting in an open tray is an exposure.
  • ✓Secure disposal: Shred faxed documents containing PHI when no longer needed.
  • ✓Pre-programmed numbers: Save frequently used fax numbers to reduce dialing errors.

How to Fax PHI Safely: Step by Step

Whether you use a physical fax machine or an online service, follow this workflow every time you send PHI.

1

Verify the Recipient

Confirm the fax number belongs to the intended recipient. For new numbers, call ahead to verify. For saved numbers, double-check the contact entry. Read the number back digit by digit before pressing Send.

2

Apply the Minimum Necessary Standard

Include only the PHI required for the specific purpose. Sending a referral? Fax the referral form — not the patient's entire history. Redact unnecessary information before scanning.

3

Attach a HIPAA-Compliant Cover Sheet

Every PHI fax needs a cover sheet with a confidentiality disclaimer, sender/recipient details, and page count. Never put PHI on the cover sheet itself — it sits on top of the stack and is the first thing anyone sees. Use our HIPAA cover sheet template as a starting point.

4

Send and Confirm Delivery

Send the fax and wait for a delivery confirmation. If your machine or service provides a transmission report, save it. This is your audit trail proof that the fax reached the correct number.

5

Log the Transmission

Record the fax in your HIPAA disclosure log: date, time, sender, recipient, number of pages, and purpose. This is required for patient disclosure accounting under 45 CFR § 164.528.

Skip the Manual Steps

mFax Business handles steps 4 and 5 automatically — every fax gets a delivery confirmation and a searchable audit log. No paper trail to manage.


Traditional Fax Machine vs. Online Fax for PHI

Both methods are HIPAA-permissible, but they carry different risks.

FactorTraditional Fax MachineOnline Fax Service
EncryptionNone — analog signal on phone lineTLS 1.2+ in transit, AES-256 at rest
Interception riskLow (point-to-point) but not zeroVery low with proper encryption
Misdial riskHigh — manual number entryLower — saved contacts, auto-verification
Audit trailManual — paper confirmation slipsAutomatic — digital logs with timestamps
Physical exposureHigh — paper sits in open trayNone — faxes arrive in encrypted inbox
BAA required?No (you own the hardware)Yes — vendor handles PHI
CostHardware + phone line + maintenanceMonthly subscription

The Verdict

Traditional fax machines are legal for PHI but increasingly risky. Cloud-based fax services with encryption and audit trails are the modern standard — and the approach recommended by most compliance consultants. Learn more about whether online fax is secure.


What Happens If You Fax PHI to the Wrong Number?

A misdirected fax containing PHI is a presumed breach under the HIPAA Breach Notification Rule (45 CFR §§ 164.400–414). Here's what you must do:

  1. Contact the unintended recipient immediately. Ask them to confirm destruction of the fax — shredding, not just tossing in the trash.
  2. Document the incident. Record the date, time, wrong number, what PHI was exposed, and your remediation steps.
  3. Conduct a risk assessment. Evaluate: Was the PHI actually viewed? Was it identifiable? What's the probability of harm?
  4. Notify if required. If the risk assessment shows a significant probability of compromise, you must notify the affected patient within 60 days. Breaches affecting 500+ individuals require notification to HHS and local media.

HIPAA Penalty Tiers for Fax Violations

TierCulpabilityPenalty per Violation
1Lack of knowledge$141 – $71,162
2Reasonable cause$1,424 – $71,162
3Willful neglect, corrected ≤ 30 days$14,232 – $71,162
4Willful neglect, not corrected$71,162 – $2,134,831

Penalty amounts adjusted for inflation as of January 2026.

Real Enforcement Example

St. Luke's-Roosevelt Hospital Center paid $387,200 after staff faxed a patient's PHI to the wrong number — repeatedly. The OCR had flagged the issue nine months earlier, but the hospital failed to fix it. Misdirected faxes are one of the most common and most preventable HIPAA violations.


Fax vs. Email: Which Is Safer for PHI?

Healthcare providers often ask whether they should fax or email PHI. The short answer: both can be HIPAA-compliant, but fax is simpler to secure.

  • Traditional fax uses a dedicated phone line — the signal travels point-to-point without passing through email servers, making interception harder.
  • Email passes through multiple servers and is stored in cloud inboxes. Without end-to-end encryption (which most email providers lack by default), PHI is exposed at every hop.
  • Cloud fax combines the best of both: digital delivery with TLS encryption, no intermediate server exposure, and automatic audit trails.

That's why faxing remains the preferred method for PHI in healthcare — and why HIPAA doesn't require patient authorization for treatment-related fax transmissions.


Your HIPAA Fax Cover Sheet for PHI

Every fax containing PHI must include a cover sheet with these elements:

  • Sender information — name, organization, phone number, fax number
  • Recipient information — name, organization, fax number
  • Page count — including the cover sheet
  • Confidentiality disclaimer — a statement like: "This fax contains confidential information protected under HIPAA. If you are not the intended recipient, you are required to destroy all copies and notify the sender immediately."
  • No PHI on the cover sheet — patient names, diagnoses, or record numbers belong on inner pages only

✓DO Include on Cover Sheet

  • • Sender name, org, phone & fax

  • • Recipient name & fax number

  • • Total page count

  • • Confidentiality disclaimer

  • • Date and general subject line

✕DO NOT Include on Cover Sheet

  • • Patient names

  • • Diagnoses or conditions

  • • Medical record numbers

  • • Social Security numbers

  • • Insurance IDs or dates of birth

Generate a compliant cover sheet instantly with our free fax cover sheet generator, or download a ready-made HIPAA fax cover sheet template.


Common PHI Faxing Mistakes to Avoid

Even well-intentioned practices make these errors:

  1. Faxing entire patient charts instead of the specific pages needed — violates the minimum necessary standard.
  2. Leaving received faxes in an open tray where visitors or unauthorized staff can see them.
  3. Using a free online fax service that doesn't offer a BAA — your data isn't protected and you're liable.
  4. Not verifying new fax numbers before sending — one transposed digit creates a breach.
  5. Skipping the cover sheet — no confidentiality disclaimer means no legal protection if the fax is misdirected.
  6. Not training new hires — every staff member who touches PHI must understand fax procedures, not just clinicians.

Secure Your PHI Faxing with mFax Business

If your practice still relies on a physical fax machine for PHI, you're carrying unnecessary risk. mFax Business eliminates the most common failure points:

  • TLS encryption in transit and AES-256 at rest — every fax is protected end-to-end
  • Signed BAA included with every business plan
  • Automatic audit trails — every transmission is logged with sender, recipient, timestamp, and delivery status
  • Saved contact book — pre-verified fax numbers reduce misdial risk to near zero
  • No paper tray exposure — faxes arrive in a secure digital inbox, accessible only to authorized users

Plans start at about $9/mo (billed annually), and they're fully customizable — you build your own plan with a live calculator, picking the exact number of seats and pages your practice needs instead of paying for a rigid fixed tier. Visit mFax.to/business to get started — your compliance team will thank you.

Frequently Asked Questions

Is faxing PHI a HIPAA violation?
Faxing PHI is not automatically a violation. HIPAA permits faxing for treatment, payment, and healthcare operations as long as reasonable safeguards — encryption, verified recipients, cover sheets, and audit trails — are in place. See our [HIPAA fax requirements checklist](/blog/hipaa-fax-requirements/) for the full list.
Can you fax PHI without patient consent?
Yes, for treatment purposes. The HIPAA Privacy Rule allows covered entities to share PHI via fax for treatment, payment, and healthcare operations without written patient authorization. However, the minimum necessary standard applies — send only the information needed.
What happens if you fax PHI to the wrong number?
A misdirected fax containing PHI is a potential breach. You must document the incident, contact the unintended recipient to request destruction of the fax, and assess whether breach notification is required under the HIPAA Breach Notification Rule. Penalties range from $141 to over $2 million per violation.
Is faxing more secure than email for sending PHI?
Traditional fax is a point-to-point transmission that doesn't store data on intermediate servers, making it harder to intercept than unencrypted email. However, cloud-based fax services with TLS encryption offer the best of both worlds — digital convenience with end-to-end security. Learn more in our guide to [online fax security](/blog/is-online-fax-secure/).
Do you need a BAA to fax PHI through an online service?
Yes. Any third-party fax service that transmits, stores, or processes PHI on your behalf is a business associate under HIPAA. You must have a signed Business Associate Agreement (BAA) before sending your first fax.
Home Business Pricing Fax API Blog Document Converter Company
Terms of Service Privacy Policy