Are Faxes HIPAA Compliant? Safeguards, BAAs, and Penalties

Yes, faxes can be HIPAA compliant. HHS has explicitly confirmed that a physician’s office may fax patient records to another provider for treatment purposes, provided reasonable safeguards are in place.1U.S. Department of Health and Human Services. Can a Physicians Office Fax Patient Medical Information to Another Physicians Office The compliance risk sits in how the machine is secured, how numbers are verified, how much information you send, and how any electronic fax service stores what passes through it. Get those wrong and a routine transmission becomes a reportable breach with penalties reaching into the millions.

Safeguards for Traditional Fax Machines

Analog fax machines send documents over telephone lines in a point-to-point connection, which makes interception during transmission relatively difficult compared to unencrypted email. The real risks are physical. A fax sitting uncollected in a shared hallway is an exposure, and dialing the wrong number is a disclosure to an unauthorized person.

HHS guidance names two baseline safeguards for fax machines: confirming that the fax number is correct before sending, and placing the machine in a secure location where unauthorized individuals cannot access incoming documents.1U.S. Department of Health and Human Services. Can a Physicians Office Fax Patient Medical Information to Another Physicians Office Practical steps that follow from those requirements:

  • Pre-program frequently used fax numbers into the machine’s directory so staff aren’t retyping digits, and audit those stored numbers periodically to confirm they’re still valid.
  • Check the recipient number on the machine’s display against the intended destination before pressing send. If the machine lacks a digital display, add a line to the cover sheet asking the recipient to confirm receipt by phone.
  • Use a confidentiality cover sheet that identifies the contents as confidential health information and tells anyone who receives it in error to destroy the pages and notify the sender.
  • Assign someone to collect incoming faxes promptly, especially when the machine sits in a shared or semi-public area.

Fax-related breaches keep appearing in enforcement actions not because the technology is inherently insecure, but because staff skip verification when they’re busy and organizations treat these safeguards as common sense rather than writing them into policy.

Electronic Fax Services and the Business Associate Agreement

Electronic fax services let you send and receive faxes through a web portal, email attachment, or mobile app. They can solve some traditional fax problems: no output tray, no shared hallway machine. But because the faxed documents are now electronic PHI stored on someone else’s servers, they create new obligations.

An eFax service that stores your documents, even temporarily in a cloud portal or email inbox, is a business associate under HIPAA. The regulation defines a business associate to include any entity that provides data transmission services involving routine access to PHI, and anyone who creates, receives, maintains, or transmits PHI on a covered entity’s behalf.2eCFR. 45 CFR 160.103 – Definitions

Before you use an eFax service for PHI, you need a signed Business Associate Agreement. HIPAA requires the agreement to be in writing, and the BAA must ensure the vendor will appropriately safeguard the information.3eCFR. 45 CFR 164.502 – Uses and Disclosures of Protected Health Information If the vendor won’t sign a BAA, you can’t use that service for PHI. Some general-purpose fax apps market convenience without mentioning HIPAA at all, and those are the ones most likely to create problems.

Some vendors argue they’re just a conduit for data transmission, similar to the postal service carrying sealed envelopes, and therefore don’t need a BAA. That argument fails for electronic fax. The conduit exception applies only to entities that transmit PHI without persistent access to it, like internet service providers. An eFax service stores faxes in your account, lets you view and download them, and often retains copies, which goes well beyond transient transmission.2eCFR. 45 CFR 160.103 – Definitions

On encryption: any reputable HIPAA-focused eFax vendor encrypts data in transit and at rest. Under the Security Rule’s technical safeguards, encryption for ePHI in transit is an “addressable” specification, which does not mean optional. It means the covered entity must implement encryption where reasonable, or adopt and document an equivalent alternative.4eCFR. 45 CFR 164.312 – Technical Safeguards

Send Only the Minimum Necessary

Even when the recipient is legitimate and every safeguard is in place, HIPAA limits how much PHI you can put on the fax. The minimum necessary standard requires covered entities to make reasonable efforts to limit disclosures to the smallest amount needed to accomplish the purpose.5eCFR. 45 CFR 164.514 – Other Requirements Relating to Uses and Disclosures of Protected Health Information

If a specialist requests a patient’s medication list and you fax the entire chart, you’ve likely violated the minimum necessary rule, even if the number was right and the machine was in a locked room. For routine, recurring disclosures, written policies should specify what categories of information go out for each type of request. For non-routine requests, staff should review each one and send only what’s relevant.5eCFR. 45 CFR 164.514 – Other Requirements Relating to Uses and Disclosures of Protected Health Information

One important exception: disclosures for treatment purposes between healthcare providers are exempt from the minimum necessary requirement, so a referring physician sending a patient’s full relevant history to a treating specialist doesn’t need to redact down to the bare minimum. Disclosures for payment, operations, or other purposes still fall under the rule.

What Happens When a Fax Goes to the Wrong Number

A misdirected fax is an impermissible disclosure. Any impermissible disclosure is presumed to be a breach unless the covered entity can demonstrate, through a risk assessment, that there’s a low probability the PHI was actually compromised.6U.S. Department of Health and Human Services. Breach Notification Rule The assessment must weigh at least four factors: the nature of the information involved, who received it, whether it was actually viewed, and what steps were taken to mitigate the risk.

If you can’t show low probability of compromise, the notification clock starts. Affected individuals must be notified within 60 days of the breach being discovered. If 500 or more people in a single state or jurisdiction are affected, prominent local media outlets must also be notified within that same 60-day window. Regardless of size, all breaches must be reported to HHS: breaches affecting 500 or more require notification within 60 days, while smaller breaches can be reported annually.6U.S. Department of Health and Human Services. Breach Notification Rule

A written protocol for misdirected faxes matters here. Contact the unintended recipient immediately, request destruction of the pages, log the incident, and begin the breach risk assessment. Waiting to see if anyone complains is not a strategy. The 60-day clock runs from the date of discovery, not from the date you decide it matters.

Penalties for HIPAA Faxing Violations

HHS adjusts HIPAA civil monetary penalties for inflation each year. As of January 28, 2026, the tiers are:7Federal Register. Annual Civil Monetary Penalties Inflation Adjustment

  • Did not know: $145 to $73,011 per violation, with a calendar-year cap of $2,190,294.
  • Reasonable cause: $1,461 to $73,011 per violation, capped at $2,190,294 per year.
  • Willful neglect, corrected within 30 days: $14,602 to $73,011 per violation, capped at $2,190,294 per year.
  • Willful neglect, not corrected: $73,011 to $2,190,294 per violation, capped at $2,190,294 per year.

These figures are per violation, and a single compliance failure affecting multiple patients can be counted as multiple violations. In 2017, HHS settled with St. Luke’s-Roosevelt Hospital Center for $387,200 after staff faxed a patient’s PHI, including HIV status and mental health information, to the patient’s employer instead of the requested mailing address. A second misdirected fax had occurred nine months earlier at the same facility. The settlement included a three-year corrective action plan.8U.S. Department of Health and Human Services. Careless Handling of HIV Information Jeopardizes Patients Privacy

Criminal prosecution is reserved for individuals who knowingly obtain or disclose PHI in violation of HIPAA, with penalties that escalate based on intent:9GovInfo. 42 USC 1320d-6 – Wrongful Disclosure of Individually Identifiable Health Information

  • Knowing violation: up to $50,000 in fines and one year in prison.
  • Under false pretenses: up to $100,000 in fines and five years in prison.
  • Intent to sell, transfer, or use for personal gain or malicious harm: up to $250,000 in fines and ten years in prison.

Criminal cases are rare in the fax context but not theoretical. An employee who deliberately faxes a patient’s records outside the organization for personal reasons falls squarely within these provisions.

Tying the Safeguards Together

Organizations that draw enforcement attention typically don’t lack any single safeguard. They lack a written process that connects the safeguards. A workable fax workflow includes documented policies covering who is authorized to fax PHI, what verification steps are required, and how incoming faxes are handled; training for everyone who touches the equipment, refreshed annually; periodic risk review of machine locations, stored numbers, and vendor controls; and audit logs from your eFax service or confirmation sheets from your physical machine kept on file. Paper faxes containing PHI get shredded when no longer needed, and electronic fax retention should match what your BAA requires.