HIPAA Fax Requirements: Encryption, BAA & Audit Trail Checklist

HIPAA doesn't ban faxing — but it demands specific safeguards before you send PHI. Here's every encryption, BAA, and audit trail requirement your practice must meet in 2026.

HIPAA Fax Requirements: Encryption, BAA & Audit Trail Checklist

By Alexey Spasskiy · Published July 18, 2025 · Updated June 8, 2026 · 10 min read

Quick Answer: HIPAA allows faxing PHI — but only with proper encryption, a signed BAA from your fax vendor, and a documented audit trail. Use a HIPAA-ready service like mFax Business to meet all three requirements out of the box.


Faxing remains one of the most common ways healthcare providers share protected health information (PHI). Referrals, lab results, prescriptions, and insurance claims still move by fax every day. But HIPAA fax requirements go far beyond pressing "Send" — and the penalties for getting them wrong range from $141 to over $2.1 million per violation.

This guide breaks down every requirement your practice must meet: encryption standards, Business Associate Agreements, audit trail obligations, and the major changes coming with the 2026 HIPAA Security Rule update. Whether you use a traditional fax machine or an online fax service, you'll find an actionable checklist at the end.

2026 Security Rule Update

HHS has proposed the first major update to the HIPAA Security Rule since 2013. Encryption and multi-factor authentication become mandatory — no longer "addressable" safeguards. The final rule is expected by mid-2026.

What HIPAA Actually Requires for Faxing

HIPAA does not ban faxing. The HHS Privacy Rule explicitly permits covered entities to share PHI by fax for treatment, payment, and healthcare operations — without patient authorization — as long as "reasonable safeguards" are in place.

Those safeguards fall into three categories defined by the HIPAA Security Rule (45 CFR Part 164):

  1. Administrative safeguards — policies, training, and risk assessments
  2. Physical safeguards — device placement, access controls, disposal
  3. Technical safeguards — encryption, authentication, audit logs

The key phrase is reasonable safeguards. What counts as "reasonable" depends on the size and complexity of your organization — but the three pillars above apply universally. Let's break each one down.


Administrative Safeguards

Administrative safeguards are the policies and procedures that govern how your organization handles PHI by fax. These are often the most overlooked — and the most cited in breach investigations.

Written Fax Policies

Every covered entity needs a documented fax policy that covers:

  • Who is authorized to send and receive faxes containing PHI
  • When faxing is appropriate (treatment, payment, operations) vs. when it's not
  • Cover sheet requirements — what must appear on every fax
  • Misdirected fax procedures — what to do when PHI goes to the wrong number
  • Retention and disposal — how long faxes are kept, how they're destroyed

Staff Training

HIPAA requires that all workforce members receive training on your fax policies. This isn't a one-time event — training must be updated when policies change. Document who was trained, when, and on what.

Risk Assessment

You must conduct a formal risk assessment that includes faxing workflows. The assessment should identify where PHI enters and exits your organization by fax, what threats exist (misdirected faxes, unattended machines, intercepted transmissions), and what controls mitigate each risk.

Under the proposed 2026 rule, risk assessments must be documented and repeated every 12 months — with formal testing of all safeguards.

Designated Privacy Officer

A designated privacy officer (or security officer) must oversee fax compliance as part of their broader HIPAA responsibilities. This person is accountable for enforcing the fax policy and investigating any fax-related incidents.


Physical Safeguards

Physical safeguards protect the actual devices and documents involved in faxing.

Fax Machine Placement

If you use a physical fax machine, it must be in a secure, controlled-access area — not a shared hallway, open reception desk, or public-facing counter. Only authorized staff should be able to retrieve incoming faxes.

Document Handling

  • Never leave faxes unattended on the machine tray
  • Pick up incoming faxes immediately or designate someone to monitor the machine
  • Shred or securely destroy faxes containing PHI once no longer needed
  • Lock filing cabinets or storage areas where faxed documents are kept

Cover Sheets

Every fax containing PHI must include a cover sheet with:

  • Sender name, organization, phone number, and fax number
  • Recipient name and fax number
  • Date and time of transmission
  • Number of pages (including the cover sheet)
  • A confidentiality notice stating the fax is intended only for the named recipient and should be destroyed if received in error

Never Put PHI on the Cover Sheet

The cover sheet sits on top of the stack in the recipient's fax tray — visible to anyone walking by. Patient names, diagnoses, and other PHI belong on interior pages only, not the cover sheet.

Need a ready-to-use template? Download our free HIPAA medical fax cover sheet or confidential fax cover sheet.


Technical Safeguards

Technical safeguards are the encryption, authentication, and logging controls that protect PHI during and after transmission. This is where traditional fax machines and online fax services diverge sharply.

Encryption: In Transit

HIPAA requires that electronic PHI (ePHI) be encrypted during transmission. For online fax services, this means:

  • TLS 1.2 or higher for all connections between your browser/app and the fax server
  • TLS encryption on the fax transmission itself (T.38 over TLS or secure SIP)
  • No unencrypted fallback — the connection must fail rather than downgrade
StandardMinimum VersionStatus
TLS (in transit)TLS 1.2Required (1.3 recommended)
AES (at rest)AES-256Required under 2026 proposed rule
MFAAny NIST-approved methodRequired under 2026 proposed rule

How to verify: In your browser, click the padlock icon next to the URL of your fax service. Check that the connection uses TLS 1.2 or 1.3. If you see TLS 1.0 or 1.1, your provider does not meet the standard.

Encryption: At Rest

Any fax stored on a server — incoming faxes in your inbox, sent fax confirmations, archived documents — must be encrypted at rest. The industry standard is AES-256, and the proposed 2026 rule makes this a mandatory ("shall") requirement under 45 CFR § 164.312(a)(2)(ii).

Ask your fax vendor:

  1. How is stored ePHI encrypted? (AES-256 is the benchmark)
  2. Where are encryption keys stored? (Should be separate from the data)
  3. Who has access to decryption keys? (Should be limited to authorized personnel)

Authentication and Access Controls

HIPAA requires unique user identification and access controls for any system containing ePHI:

  • Unique logins — no shared "office" accounts
  • Role-based access — staff should only see the faxes they need (minimum necessary standard)
  • Automatic session timeout — idle sessions must lock
  • Multi-factor authentication (MFA) — required under the proposed 2026 rule for all systems accessing ePHI

For a deeper dive into encryption standards, see our guide on whether online fax is secure.


Business Associate Agreement (BAA)

A Business Associate Agreement is a legally binding contract between a covered entity (you) and any vendor that handles PHI on your behalf. Under HIPAA, any third-party fax service that transmits, stores, or has access to PHI is a business associate — and you cannot use them without a signed BAA.

Who Needs a BAA?

Vendor TypeBAA Required?
Cloud/online fax service (mFax, eFax, Fax.Plus)Yes
Fax-over-IP (FoIP) providerYes
Email-to-fax gatewayYes
Traditional phone company (PSTN line)No — conduit exception applies
IT company managing your fax serverYes

The key distinction: PSTN carriers (AT&T, Verizon) that merely transmit an analog signal qualify for the HIPAA conduit exception — they never store PHI in a persistent, accessible form. Online fax services store faxes on servers, which means they have persistent access and must sign a BAA.

What a BAA Must Include

A valid BAA must address:

  • Permitted uses and disclosures of PHI — limited to the services being provided
  • Safeguards the vendor will implement to protect ePHI
  • Breach notification obligations — how quickly the vendor will notify you of a security incident
  • Subcontractor requirements — the vendor must ensure its own subcontractors also comply
  • Return or destruction of PHI when the contract ends
  • Audit and compliance verification — under the 2026 proposed rule, vendors must provide annual written verification of their controls

BAA Red Flags

If a fax vendor says they "don't need a BAA" or "aren't a business associate," that's a disqualifying red flag. Walk away. Without a BAA, your organization bears full liability for any breach involving that vendor.

mFax Business provides a signed BAA as part of every plan, along with encryption, audit logging, and access controls built in.


Audit Trail Requirements

HIPAA's Security Rule requires covered entities and business associates to maintain audit trails that log activity involving ePHI. For faxing, this means:

What Your Audit Trail Must Capture

  • Who sent or received each fax (unique user ID)
  • When the fax was transmitted (date, time, time zone)
  • What was sent (page count, document identifiers — not the PHI content itself in the log)
  • Where it went (recipient fax number)
  • Delivery status — confirmed, failed, or pending
  • Access events — who viewed, downloaded, or printed a received fax

Retention Period

HIPAA requires that audit logs be retained for a minimum of 6 years from the date of creation or the date the policy was last in effect — whichever is later. Many organizations retain fax logs for the same period as their medical records (typically 7–10 years).

2026 Changes

The proposed Security Rule significantly strengthens audit requirements:

  • Comprehensive compliance audits must be conducted at least annually
  • All administrative, physical, and technical safeguards must be formally tested every 12 months
  • Vulnerability scans at least every 6 months; penetration testing annually
  • Business associates must notify covered entities within 24 hours of activating incident response procedures

Traditional Fax Machines vs. Online Fax

Not all fax methods carry the same HIPAA obligations. The distinction hinges on whether the fax is electronic (ePHI) or paper-to-paper (non-electronic).

RequirementTraditional Fax (PSTN)Online Fax Service
Administrative safeguardsRequiredRequired
Physical safeguardsRequiredLess applicable (no physical machine)
Technical safeguards (encryption, etc.)Not required for paper-to-paperRequired
BAA with vendorNo (conduit exception)Yes
Audit trailManual loggingAutomatic
Cover sheetRequiredRequired
Risk assessmentRequiredRequired

The catch: Most fax machines in 2026 are actually multifunction printers connected to VoIP lines — making them electronic transmissions subject to the full HIPAA Security Rule, including encryption. True analog fax over PSTN is increasingly rare.

Why Online Fax Is Often Easier to Secure

Online fax services like mFax Business handle encryption, audit logging, access controls, and BAA requirements automatically. With a physical fax machine, you're responsible for all of those manually — plus the physical security of the device and every printed document.

For a full comparison, see Is Faxing HIPAA Compliant? What Healthcare Providers Must Know.


Common HIPAA Fax Violations

Understanding what goes wrong helps you avoid it. These are the most frequently cited fax-related HIPAA violations:

1. Misdirected Faxes

Sending PHI to the wrong fax number is the single most common fax breach. Prevention:

  • Pre-program frequently used numbers — don't type them manually
  • Verify the number before every transmission by calling the recipient first
  • Use confirmation pages to verify delivery to the correct number
  • Notify the recipient in advance so they can retrieve the fax immediately

2. No BAA on File

Using an online fax service without a signed BAA is a violation — even if the service is technically secure. Always obtain the BAA before sending the first fax.

3. Unattended Fax Machines

Leaving incoming faxes on an unsecured tray in a public area is a physical safeguard failure. Secure the machine or switch to online fax where documents arrive in an encrypted inbox.

4. Missing Cover Sheets

Sending PHI without a confidentiality cover sheet is a safeguard failure. Every fax should include one. Use our free HIPAA cover sheet template.

5. No Audit Trail

If you can't prove who sent what, when, and to whom, you can't demonstrate compliance during an audit. Manual fax logs are acceptable but error-prone — automated audit trails from online fax services are far more reliable.

6. Failure to Train Staff

Untrained staff are the weakest link. A single employee who doesn't know the misdirected-fax procedure can cause a reportable breach.


HIPAA Fax Compliance Checklist

Use this checklist to verify your practice meets every requirement. Print it, share it with your compliance officer, and review it quarterly.

Administrative

  • ✓Written fax policy: Documented procedures for sending, receiving, and disposing of faxed PHI.
  • ✓Risk assessment: Annual assessment that includes faxing workflows and identified threats.
  • ✓Staff training: All workforce members trained on fax policies; training documented and updated annually.
  • ✓Privacy officer: Designated individual responsible for fax compliance oversight.
  • ✓Incident response plan: Documented procedure for handling misdirected faxes and fax-related breaches.

Physical

  • ✓Secure placement: Fax machine in a controlled-access area, not visible to unauthorized individuals.
  • ✓Document retrieval: Process for immediate pickup of incoming faxes; no unattended PHI.
  • ✓Cover sheets: Every fax includes a cover sheet with confidentiality notice (PHI on interior pages only).
  • ✓Secure disposal: Shredding or secure destruction of faxed PHI when no longer needed.

Technical

  • ✓Encryption in transit: TLS 1.2+ for all electronic fax transmissions.
  • ✓Encryption at rest: AES-256 (or equivalent) for stored faxes on servers.
  • ✓Unique user IDs: No shared logins; every user has their own account.
  • ✓Access controls: Role-based permissions; minimum necessary access to faxed PHI.
  • ✓MFA: Multi-factor authentication for all systems accessing ePHI (required under 2026 proposed rule).
  • ✓Audit trail: Automated logging of all fax send/receive/view events, retained for 6+ years.

Vendor

  • ✓BAA signed: Business Associate Agreement executed with every fax vendor before first use.
  • ✓Subcontractor compliance: Vendor confirms its subcontractors meet HIPAA requirements.
  • ✓Annual verification: Vendor provides written confirmation of safeguards annually.
  • ✓Breach notification: BAA includes vendor's obligation to report incidents within 24 hours.

How to Choose a HIPAA-Compliant Fax Service

If you're evaluating fax vendors, ask these questions before signing:

  1. Do you provide a signed BAA? — Non-negotiable. No BAA, no deal.
  2. What encryption do you use? — TLS 1.2+ in transit, AES-256 at rest.
  3. Do you support MFA? — Required under the 2026 proposed rule.
  4. What does your audit trail capture? — Must include user, timestamp, recipient, status.
  5. Where is data stored? — US-based data centers preferred for healthcare; ask about data residency.
  6. What's your breach notification timeline? — Should be 24 hours or less.
  7. How do you handle data retention and destruction? — Must comply with your retention policy.

For a side-by-side comparison of services, see our 10 best HIPAA-compliant fax services review.


Secure Your Faxing with mFax Business

Meeting HIPAA fax requirements doesn't have to mean manual checklists and spreadsheet audit logs. mFax Business handles the technical safeguards automatically:

  • TLS 1.3 encryption in transit and AES-256 at rest
  • Signed BAA included with every plan
  • Automatic audit trail with user, timestamp, recipient, and delivery status
  • Role-based access controls and MFA support
  • Virtual fax numbers — no physical machine to secure

Plans start at about $9/mo (billed annually) — and there are no fixed tiers, so you build your own plan from the exact seats and pages you need. Visit mFax.to/business to get started.

For personal HIPAA faxing needs — sending a single prescription or medical record — the mFax app lets you fax securely from your phone in under 2 minutes.

Frequently Asked Questions

Is faxing PHI allowed under HIPAA?
Yes. HIPAA permits faxing protected health information for treatment, payment, and healthcare operations — as long as you apply reasonable administrative, physical, and technical safeguards. See our [complete HIPAA fax guide](/blog/hipaa-compliant-fax/) for details.
Do I need a BAA with my fax service provider?
Yes. Any third-party fax vendor that stores, transmits, or has access to PHI is a business associate under HIPAA. You must execute a signed BAA before sending the first fax.
What encryption does HIPAA require for faxing?
HIPAA requires TLS 1.2 or higher for data in transit and AES-256 (or equivalent) for data at rest. The 2026 proposed Security Rule makes encryption mandatory — no longer an addressable safeguard.
Are traditional fax machines HIPAA compliant?
Analog fax machines transmit over PSTN phone lines and are not subject to the HIPAA Security Rule's electronic safeguard requirements. However, you still need physical and administrative safeguards — secure placement, cover sheets, and access controls.
What happens if I fax PHI to the wrong number?
A misdirected fax containing PHI is a potential HIPAA breach. You must report it to your privacy officer, document the incident, and follow your organization's breach notification procedures. Penalties range from $141 to $2,134,831 per violation depending on the level of negligence.
Home Business Pricing Fax API Blog Document Converter Company
Terms of Service Privacy Policy