By Alexey Spasskiy · Published October 27, 2025 · Updated March 9, 2026 · 4 min read
Faxing remains the backbone of communication for healthcare, insurance, and government entities. Yet, the shift from clunky analog machines to cloud solutions has left many compliance officers asking: Is online faxing actually safe?
The answer is yes, but only if you choose the right partner and configure your workflow correctly.
Sending Protected Health Information (PHI) requires a chain of custody that satisfies HIPAA’s rigorous administrative, physical, and technical safeguards. Without a BAA, no fax solution is compliant.
This guide breaks down exactly how to achieve HIPAA compliance with modern cloud fax and how to implement a secure workflow using mFax Business, where a signed BAA comes with every plan.
The "Shared Responsibility" of HIPAA Compliance
It is important to clarify a common misconception: HIPAA does not "certify" software. There is no official seal of approval from the Department of Health and Human Services.
Instead, compliance is a state of operation achieved through safeguards. When using a cloud fax provider, you operate under a Shared Responsibility Model:
Provider's Responsibility
Secure the infrastructure (encryption, physical servers, network security) and sign a Business Associate Agreement (BAA).
Your Responsibility
Configure user access, enforce strong passwords, train staff on policies, and ensure you are sending to the correct numbers.
Technical Safeguards: The Digital Defense
To transmit PHI digitally, your environment must meet specific technical standards.
1. Encryption Everywhere
Data must be unreadable to unauthorized parties at all times.
- In Transit: All web sessions (HTTPS) and email-to-fax connections must utilize TLS 1.2 or higher.
- At Rest: Once the fax reaches the server, it must be stored using high-standard encryption (e.g., AES-256).
2. Access Control & Authentication
Stop sharing passwords. HIPAA requires unique user identification.
- Individual Accounts: Every staff member needs their own login.
- MFA/2FA: Enable Two-Factor Authentication.
- Least Privilege: Configure roles so staff can only access what they need (e.g., billing clerks shouldn't be able to delete records).
3. Comprehensive Audit Trails
You must be able to answer the question: "Who accessed this patient record and when?"
Regularly export your fax logs. Ensure your logs capture: Sender/Recipient details, Timestamps, IP addresses, and transmission status. mFax.to retains these logs indefinitely for your convenience.
The HIPAA Fax Cover Sheet
A HIPAA-compliant fax cover sheet is your first line of defense against accidental disclosure.
✓DO Include
• Sender Name, Org, Phone & Fax
• Recipient Name, Org & Fax Number
• Date and Total Pages
• Confidentiality Disclaimer
✕DO NOT Include
• Patient Names (Use initials or MRN if strictly necessary)
• Diagnosis codes
• Treatment details
• Any specific PHI in the "Subject" line
4 Secure Workflows supported by mFax.to
- Secure Email-to-Fax: Ensure your mail server enforces TLS. mFax.to allows you to whitelist specific sender domains.
- The Web Portal: The most secure method. Documents are uploaded directly via HTTPS, bypassing email entirely.
- API Integration: For developers. Use the REST API with secure credentials and webhooks for delivery confirmations.
- Inbound Routing: Replace physical machines with Virtual Numbers that route PDFs to secure folders, not public paper trays.
Step‑by‑Step: Sending Your First Compliant Fax
Ready to modernize your workflow? Here is the path to production with mFax.to:
Account Setup
Create your mFax.to account and immediately enable 2FA (Two-Factor Authentication) in the security settings.
Legal Housekeeping
Request and sign the BAA. Do not transmit any PHI until this document is executed and filed.
User Provisioning
Invite your staff using "Least Privilege" principles (assign "User" roles rather than "Admin" roles).
Prepare & Send
Upload your PDF (monochrome, 200+ DPI), attach a compliant cover sheet using the toggle, and enter the destination number.
Archive
Once the transmission receipt arrives, download it along with the audit log for your compliance records.
Quick Compliance Checklist
Before you go live, ensure you can check all these boxes:
- ✓BAA Signed: Contract executed with the provider.
- ✓Encryption Verified: TLS enforced for email and web traffic.
- ✓Access Controlled: No shared logins; MFA enabled.
- ✓Audit Logging: You know how to access and export logs.
- ✓Retention Set: Auto-delete policies configured (if applicable).
- ✓Staff Trained: Team knows never to put PHI on a cover sheet.
Conclusion
HIPAA‑compliant faxing is not just about avoiding fines; it's about protecting patient trust while maintaining the speed modern healthcare demands.
By moving to a cloud solution like mFax Business, you eliminate the physical risks of paper trays and gain the visibility of digital audit trails. For a comparison of the best HIPAA-compliant providers, see our best HIPAA compliant fax services guide. For step-by-step instructions, read how to fax medical records and learn how to fax from email with HIPAA compliance.