HomeBlogCompliance

Is Faxing HIPAA Compliant? Fax and eFax Rules for Practices

Illustration of a robot in a bright medical office holding a tablet checklist, beside a shield and padlock icon and an open file drawer

Yes. HIPAA lets a practice fax patient information, including for treatment, as long as it uses reasonable safeguards, such as confirming a number before the first send and pre-programming numbers it uses often. A paper fax falls under the Privacy Rule. Once a fax passes through a computer or an online service, the Security Rule applies too.

This guide covers what HHS says, where the Security Rule starts, what to require of an eFax service and how to route faxes into Microsoft 365. Our HIPAA compliance services set up and document these safeguards for practices, and the same reasoning applies to email, covered in our guide to HIPAA rules for email. HHS's site blocked our automated requests, so we read the Internet Archive's July and October 2026 copies of the HHS pages cited. This is general information, not legal advice.

Is faxing HIPAA compliant?

Yes, with reasonable safeguards. HHS answers the question in its FAQ on sharing information by fax, email or phone: the Privacy Rule lets health care providers share protected health information (PHI) for treatment without the patient's authorization, by phone, fax, email or otherwise, as long as they use reasonable safeguards. Its examples include a laboratory faxing test results to a physician and a hospital faxing care instructions to a nursing home.

The safeguard duty comes from 45 CFR 164.530(c): a covered entity must have appropriate administrative, technical and physical safeguards, and must reasonably protect PHI from uses or disclosures the rules do not allow. For fax, HHS gives two examples: confirm a number you do not use regularly with the recipient before sending, and pre-program numbers you use often so staff do not misdial.

When does the HIPAA Security Rule apply to fax?

It depends on whether the information is electronic before it is sent. The Security Rule protects electronic protected health information (ePHI), and its definition of electronic media in 45 CFR 160.103 says a paper fax is not a transmission via electronic media if the information did not exist in electronic form immediately before it was sent. HHS has also said that ePHI kept in the memory of a fax machine or copier is subject to the Security Rule.

How the fax travelsRules that applyWhat to set up
Paper document on a standalone fax machinePrivacy Rule safeguardsVerified numbers, pre-programmed speed dials, a machine out of public view, a cleared output tray
Fax sent from an EHR or a computerPrivacy and Security RulesAccess controls, audit logs and encryption in transit
Fax received into email, a fax server or an online portalPrivacy and Security Rules, plus a BAA with any service that stores itA restricted inbox, MFA, a retention policy and audit logging
Fax machine or multifunction printer that stores imagesSecurity Rule for the stored copiesEncrypt or limit stored images, and wipe the storage before the device leaves (45 CFR 164.310(d))

Once a fax is electronic, the technical safeguards in 45 CFR 164.312 apply: access control, audit controls, integrity, person or entity authentication, and transmission security. Our HIPAA Security Rule glossary entry explains the rest of the rule.

What safeguards should a practice use for faxing?

  • Verify new numbers. Confirm the number with the recipient before the first fax, as HHS suggests, and recheck the numbers in your directory each year.
  • Pre-program frequent numbers into the machine or the fax service's address book, so staff pick them instead of typing them.
  • Send only what is needed. The minimum necessary standard applies to most disclosures. It does not apply to disclosures to a provider for treatment, but trimming pages still limits the harm of a misdial.
  • Use a cover sheet that names the sender, the recipient and the page count and asks a wrong recipient to call you and destroy the pages. No HIPAA provision requires one, and it cannot fix a misdirected fax, but it makes recovery faster.
  • Place machines out of public view and clear the output tray, because physical safeguards apply to paper too.
  • Train staff and write the procedure into your policies, including what to do when a fax goes astray.

What happens if a fax goes to the wrong number?

Treat it as a possible breach and assess it. Under 45 CFR 164.402, an impermissible disclosure is presumed to be a breach unless a documented risk assessment shows a low probability that the PHI was compromised, weighing four factors: the information involved, who received it, whether it was actually acquired or viewed, and how far the risk was mitigated. One exception covers a disclosure where you have a good faith belief that the recipient could not reasonably have kept the information.

  1. Ask the recipient to destroy or return the pages, and get that confirmed in writing.
  2. Log the date, the number dialed and the pages sent.
  3. Complete and keep the four-factor risk assessment, and follow the breach notification rules if you cannot show a low probability of compromise.
  4. Fix the cause, such as a wrong directory entry.

Does an eFax service need a BAA?

Almost always. A business associate is anyone who creates, receives, maintains or transmits PHI on your behalf (45 CFR 160.103), and you may let one handle PHI only with satisfactory assurances that it will safeguard the information (45 CFR 164.502(e)), which in practice means a business associate agreement. HHS's cloud computing guidance says a cloud service that maintains ePHI is a business associate even if it cannot view the data, and it reads the conduit exception narrowly: it covers transmission only, with no storage beyond what is temporary and incidental to the transmission.

An online fax service keeps copies in a portal, inbox or archive, so treat it as a business associate. Before you sign up, check for:

  • A signed BAA that covers the fax service itself, not just another product from the same vendor.
  • Encryption of faxes in transit and at rest.
  • A retention period you can set or shorten.
  • Individual portal logins protected by MFA.
  • Access and transmission logs you can export.
  • Breach notice to you, which 45 CFR 164.410 requires of a business associate.

Our business associate agreement guide covers what else the agreement should say.

How should eFax reach Microsoft 365?

When inbound faxes arrive as email, treat the mailbox as a system holding ePHI:

  • Deliver faxes to a shared mailbox that only the staff who process them can open, not to personal inboxes or a distribution list.
  • Require MFA for everyone with access, and block automatic forwarding to outside addresses.
  • Encrypt any fax you forward outside the organization. Our email encryption service sets up rules that do it automatically.
  • Apply a retention policy that matches your records policy, so faxes are neither deleted early nor kept forever.
  • Make sure audit logging covers the mailbox and someone reviews it, which supports the audit controls standard in 45 CFR 164.312(b).

Microsoft 365 needs its own BAA, which Microsoft provides through its Data Protection Addendum; our Microsoft 365 HIPAA guide covers the tenant settings. If faxes land in an EHR instead, the EHR vendor's BAA and access controls apply.

What does a HIPAA IT audit check for fax?

Our HIPAA compliance audit reviews transmission security for email, e-fax and patient messaging with the rest of the Security Rule. For fax, we look for:

  • A BAA on file for every fax and eFax vendor.
  • Fax workflows included in your risk analysis, the assessment 45 CFR 164.308(a)(1)(ii)(A) requires.
  • Where inbound faxes land, who can open them, and whether MFA protects that access.
  • Encryption in transit and at rest for electronic faxes, or a documented reason why an alternative is reasonable.
  • Audit logs that are switched on, kept and reviewed.
  • Fax machines and printers that store images, and how their storage is wiped at disposal.
  • A written procedure for misdirected faxes, and incident records showing it is used.

Is the HIPAA fax rule about to change?

Possibly. On January 6, 2025, HHS proposed rewriting the Security Rule (90 FR 898). The proposal would revise the definition of electronic media and drop its exception for fax and telephone transmissions, so fax equipment that transmits ePHI would need Security Rule safeguards, and it would require encryption of all ePHI at rest and in transit, with limited exceptions. When we checked the Federal Register on October 7, 2026, it listed only the proposed rule under its regulation number, with no final rule. Our post on HIPAA Security Rule changes tracks it.

Frequently asked questions

Is eFax HIPAA compliant?

It can be. An eFax service handles ePHI, so the Security Rule applies, and because it stores faxes it is a business associate that must sign a BAA. With a BAA, encryption, individual logins with MFA, sensible retention and audit logs, eFax can meet HIPAA. Without a BAA, keep PHI off it.

Does a fax cover sheet need a HIPAA confidentiality notice?

No HIPAA provision requires one. A notice that asks a wrong recipient to call you and destroy the pages is still good practice, because it speeds recovery. It does not make a misdirected fax acceptable; verified numbers do more than any disclaimer.

Is faxing safer than email under HIPAA?

Neither is safer by default. Fax risks misdialed numbers and pages left on shared machines; email risks wrong recipients and unencrypted delivery. HIPAA allows both with reasonable safeguards. Decide workflow by workflow in your risk analysis, and encrypt electronic transmissions where it is reasonable.

Do we need to keep fax logs?

HIPAA does not name a fax log, but the audit controls standard applies to systems that hold ePHI, so keep the transmission and access logs your eFax service and mailbox produce. Keep your fax policies and procedures for six years, as 45 CFR 164.316(b)(2) requires for Security Rule documentation.

Sources and further reading

HIPAA Compliance Services

Discuss hipaa compliance services for your business.

Tell us about your current systems, the result you need and your timeline. We will discuss the work, responsibilities and pricing before you decide on an engagement.

Explore HIPAA Compliance Services 845-203-3914