By Sarah Martinez · Published January 31, 2025 · Updated June 8, 2026 · 7 min read
Quick Answer: Faxing can be HIPAA compliant — but it is not automatic. Traditional fax machines fail the standard. A HIPAA-compliant online fax service with a signed BAA, TLS encryption, and audit logging is the only path that meets the regulation. mFax Business covers all five requirements out of the box.
Healthcare providers send Protected Health Information (PHI) by fax every day — referrals, lab results, discharge summaries, prior authorizations. For decades, the fax machine was considered "secure by default" because it used a dedicated phone line instead of the open internet.
That assumption is outdated. HIPAA's Security Rule demands specific technical safeguards that analog fax machines simply cannot provide. Understanding is faxing HIPAA compliant — and under what conditions — is no longer optional for any covered entity or business associate.
The Bottom Line Up Front
Traditional analog fax is not HIPAA compliant. Online fax can be compliant, but only if the provider signs a BAA and meets the five technical and administrative requirements below.
What HIPAA Actually Requires for Faxing
HIPAA's Security Rule (45 CFR § 164.312) mandates specific safeguards for any electronic transmission of PHI. When you fax a patient record, you are transmitting ePHI. That triggers five core requirements.
1. A Signed Business Associate Agreement (BAA)
Any third-party service that handles PHI on your behalf is a Business Associate under HIPAA. Your fax service provider is no exception. Without a signed BAA, using that service to transmit PHI is a violation — full stop.
Traditional fax machines transmit directly over the phone network with no intermediary service, so there's no BAA to sign. But there's also no encryption, no audit trail, and no access controls — which brings us to the other four requirements.
2. Encryption in Transit (TLS)
HIPAA requires that ePHI be protected from unauthorized interception during transmission. For fax, this means TLS (Transport Layer Security) must be enforced between your device and the fax provider's servers.
Standard analog phone lines carry unencrypted audio-frequency signals. Anyone with physical access to the line can intercept a transmission. Online fax services that enforce TLS 1.2 or higher meet this requirement; those that don't, don't.
3. Access Controls and Unique User IDs
The HIPAA Security Rule requires that each person accessing PHI uses a unique login — no shared passwords, no shared inboxes. Your fax system must be able to identify who sent or received each document.
A standalone fax machine with a shared paper tray fails this requirement entirely. Cloud fax platforms with individual user accounts, role-based permissions, and multi-factor authentication (MFA) satisfy it.
4. Audit Logs and Activity Tracking
HIPAA requires an audit trail: a log of who accessed, transmitted, or received PHI, and when. For faxing, that means transmission logs with timestamps, sender/recipient numbers, and delivery confirmation.
This is one of the clearest gaps with traditional fax. The machine prints a confirmation page, which is a paper artifact — not a searchable, tamper-evident audit record. Cloud fax platforms store digital logs that can be retrieved during an audit or breach investigation.
5. A HIPAA-Compliant Fax Cover Sheet
Every fax containing PHI must include a confidentiality notice on the cover sheet. The notice must warn that the fax contains protected health information, instruct unintended recipients to destroy it, and provide a return contact.
This is the one requirement that applies to both traditional and online fax. Our guide to HIPAA-compliant fax cover sheets includes a free template you can use immediately.
Why Traditional Fax Machines Fall Short
The assumption that "fax is secure because it's not email" was never quite right, and HIPAA makes it explicit. Here's what analog fax cannot provide:
| Requirement | Traditional Fax | Online Fax (HIPAA-ready) |
|---|---|---|
| BAA with provider | Not applicable | ✅ Provider signs BAA |
| Encryption in transit | ❌ Unencrypted phone signal | ✅ TLS 1.2/1.3 enforced |
| Unique user accounts | ❌ Shared machine | ✅ Individual logins + MFA |
| Digital audit logs | ❌ Paper confirmation only | ✅ Full transmission history |
| HIPAA cover sheet | ✅ Possible (manual) | ✅ Possible (templates built in) |
The risk isn't just regulatory. A misdirected fax — sent to the wrong number because someone mistyped a digit — lands on a shared paper tray that anyone in that office can read. Online fax with delivery confirmation and verified recipient logs dramatically reduces that exposure.
HIPAA Fines Are Real
OCR (Office for Civil Rights) has levied multi-million dollar fines for PHI disclosure via misdirected fax. In 2019, a New York provider paid $1.6M after patient records were repeatedly faxed to a patient's employer. A BAA and access controls would not have prevented the misdial, but they are required safeguards regardless.
The 5-Step HIPAA Fax Compliance Checklist
Before sending any PHI by fax, verify all five boxes are checked:
- ✓BAA Signed: Your fax service has executed a Business Associate Agreement with your organization.
- ✓Encryption Verified: TLS 1.2 or higher is enforced for all fax transmissions — confirm this in the provider's security documentation.
- ✓Access Controlled: Every staff member who sends or receives faxes has a unique login. Shared accounts are disabled. MFA is enabled.
- ✓Audit Logs Active: Your platform logs every transmission with sender, recipient, timestamp, and delivery status — and those logs are retained per your organization's policy.
- ✓Cover Sheet Ready: Every PHI fax is preceded by a HIPAA-compliant cover sheet with a confidentiality notice. See our free HIPAA cover sheet template.
Online Fax vs. Traditional Fax: The HIPAA Verdict
For any covered entity that must transmit PHI, the choice is clear. Online fax platforms designed for healthcare compliance offer everything HIPAA requires; analog fax machines do not.
But not every online fax service is HIPAA-ready. Many consumer services — including free tiers of popular apps — do not offer a BAA. Before sending a single patient record, confirm that your provider:
- Explicitly advertises HIPAA compliance
- Will sign a BAA (often requires a paid business tier)
- Documents their encryption standards
- Provides searchable audit logs
Our full comparison of the best HIPAA compliant fax services walks through which providers meet the standard and which to avoid.
How to Send a HIPAA-Compliant Fax with mFax Business
mFax Business is built for healthcare organizations that need compliant faxing without the complexity. Here's how it works:
Sign the BAA
mFax Business includes a BAA as part of the onboarding process for qualifying plans. No negotiation required — it ships with the account.
Set Up User Accounts
Each team member gets a unique login. Assign roles and permissions so only authorized staff can access PHI faxes. Enable MFA for all accounts.
Add a HIPAA Cover Sheet
Use the built-in template or upload your own. The cover sheet is attached automatically as the first page of every outbound fax.
Send from Any Device
Upload the document from your computer, phone, or tablet. mFax Business encrypts the transmission over TLS and delivers with a full audit trail.
Verify Delivery
Check the transmission log for delivery confirmation, timestamp, and recipient number. Every record is retained and exportable for compliance audits.
For a deeper walkthrough of sending medical records specifically, see our guide on how to fax medical records securely.
Frequently Asked Questions
Does HIPAA require fax encryption?
Yes. HIPAA's Security Rule requires that ePHI be protected during transmission (45 CFR § 164.312(e)(1)). For online fax, this means TLS encryption between your device and the fax provider. Traditional analog fax over the PSTN does not encrypt transmissions.
What happens if a fax containing PHI goes to the wrong number?
A misdirected fax containing PHI is a potential breach under HIPAA. You must assess the risk, document the incident, and — depending on the likelihood of compromise — notify the patient and potentially the HHS. Verified recipient numbers and delivery receipts help demonstrate due diligence but do not eliminate the breach obligation.
Is eFax HIPAA compliant?
eFax offers a HIPAA-compliant tier with a BAA for business customers. It is more expensive than alternatives like mFax Business, which provides the same compliance features at a lower starting price. See our comparison of HIPAA-compliant fax services for a side-by-side breakdown.
Do I need to encrypt faxes to other healthcare providers?
Yes, if the fax contains PHI. The HIPAA Security Rule applies to all transmissions of ePHI, regardless of whether the recipient is also a covered entity. Both parties to the transmission must handle PHI in compliance with the Security Rule.
Send HIPAA-Compliant Faxes Starting Today
Faxing is HIPAA compliant — but only with the right infrastructure. The checklist is straightforward: BAA, TLS encryption, unique user accounts, audit logs, and a proper cover sheet. Most traditional fax setups fail on four of the five.
mFax Business handles all five out of the box. Plans start at about $9/mo (billed annually) with HIPAA compliance features, a signed BAA, and full audit logging — everything your practice or organization needs to fax PHI confidently. Instead of locking you into rigid fixed tiers, mFax Business lets you build your own plan with a live calculator — choose the exact seats and pages you need and pay only for what you use.
For the complete picture on HIPAA faxing requirements, our HIPAA Compliant Fax guide covers every safeguard in detail, including encryption standards, BAA requirements, and staff training obligations.