Skip to content
Six Year Retention: Fax Archive Requirements

September 23, 2026

Six Year Retention: Fax Archive Requirements

Any fax that contains protected health information is treated as ePHI and must be archived, protected, and disposed of under HIPAA’s rules. That means access controls, audit trails, a signed Business Associate Agreement with any third-party fax vendor, and a documented retention and destruction policy. The sections below walk through timelines, storage integrity, and the operational checklist you need to defend these practices in an audit.


TL;DR:

  • Fax records containing protected health information must include transmission metadata such as sender and recipient numbers, timestamps, page counts, and delivery status to be compliant.
  • Proper storage requires high-quality, long-lasting digital formats like PDF/A, and thermal paper faxes must be digitized immediately to prevent fading and loss of record integrity.
  • Data security measures including access controls, audit logs, encryption, and secure destruction are mandatory for ePHI stored in fax archives, with vendor BAAs explicitly covering fax storage procedures.
  • Retention periods depend on federal six-year minimums for compliance documents and state laws for medical records, with the longer period requiring adherence and documentation.
  • A well-implemented compliance program should sequence policy creation, technical controls, and operational audits to prevent common failures like metadata loss, unsigned vendor agreements, and faded thermal originals.

What Counts as a Compliant Fax Record?

A fax is not a compliant record just because it arrived and got printed or saved. Auditors and regulators look for two things together: the document image itself and the transmission metadata that proves what happened to it. Strip out the metadata, and you have a document with no chain of custody, which is a serious problem if that fax ever becomes evidence in a dispute or a breach investigation.

A defensible fax record generally includes:

  • The document image, at full resolution and legible quality
  • Sender and recipient fax numbers, plus the named parties when known
  • Date and exact timestamp of transmission or receipt
  • Total page count, confirming nothing was dropped mid-transmission
  • Delivery status code (successful, failed, retried)

Once a fax carries PHI and gets stored, printed, or referenced in a patient’s record, it typically becomes a business record subject to your organization’s retention schedule, not just a transient communication. Federal records guidance treats fax transmissions the same way, pairing the image with metadata to preserve what NARA calls the evidentiary chain. Skip that pairing, and you cannot prove who sent what, to whom, or when. That gap alone can sink a compliance defense.

HIPAA Requirements for Storing and Protecting Fax Records

The HIPAA Security Rule requires specific technical safeguards for any stored fax containing ePHI: access controls tied to unique user IDs, automatic logoff on idle sessions, and audit controls that log every access, retrieval, and edit. 45 CFR §164.312 spells out these technical safeguards directly, and they apply whether the fax lives on a server in your building or with a hosted vendor.

Administrative safeguards matter just as much. You need workforce training, a documented risk analysis, and minimum-necessary access policies that limit who can even see a given fax archive.

Statistic in focus: Encryption is classified as an “addressable” specification under the Security Rule, according to NIST SP 800-66. That does not make it optional. If you skip encryption, you must document a risk analysis and an equivalent alternative control, or you have no defense during an audit.

When vetting a vendor’s Business Associate Agreement, demand:

  • A signed BAA that names fax archiving explicitly
  • Sample audit logs showing access and modification history
  • Written confirmation of encryption status, in transit and at rest

How Long Should You Retain Faxed Records?

HIPAA does not set a single retention clock for every fax. The federal baseline for HIPAA compliance documentation, such as policies, training records, and risk assessments, is six years under the Security Rule. Medical records themselves are a different matter entirely: those retention periods are set at the state level and vary widely, sometimes stretching well past a decade, especially for minors.

Building an auditable schedule means checking both clocks and applying whichever runs longer:

  • Confirm the federal six-year floor for compliance documentation
  • Check your state’s medical-record retention statute separately
  • Apply the longer period when the two conflict, and document why
  • Review the schedule annually, since state rules change

Guessing wrong in either direction, destroying too early or hoarding indefinitely, creates its own liability.

Storage Formats That Preserve Record Integrity

Format choice affects whether a fax record survives a legal challenge years later. Searchable, high-quality PDF or PDF/A is the practical standard, paired with an exportable transmission log that a system administrator can pull on demand. PDF/A specifically locks the file’s rendering, so it looks the same in an audit five years from now as it did the day it was captured.

Thermal paper fax originals are a different animal. The thermal imaging process fades within months under normal light exposure, which means a printed fax you plan to keep for six years could be blank paper by year two. NARA Bulletin 96-03 instructs copying thermal facsimiles to plain paper or digitizing them immediately on receipt, precisely because the fading is that predictable.

Thermal fax paper beside preservation copy

Once you have a verified digital copy, keep the original only until that verification is confirmed in your official record system, then destroy it on schedule.

Secure Destruction and Breach Response for Fax Records

Destruction needs the same rigor as retention. Paper originals go through cross-cut shredding with a documented chain of custody; digital files need secure deletion that actually removes the data rather than just unlinking it from an index. SSA’s POMS guidance on document retention makes this concrete: keep the source document until the electronic image is verified in the system, then destroy it under a documented process.

When something goes wrong, follow this sequence:

  1. Identify the misdirected fax and confirm what PHI it contained.
  2. Run a risk assessment. HHS guidance on breach notification confirms a misdirected fax can qualify as a reportable breach depending on the probability that PHI was compromised.
  3. Notify affected individuals and, where thresholds apply, HHS itself, within the required window.
  4. Preserve the incident timeline, risk assessment findings, and remediation steps for your audit file.

Document everything from step one. An incident with no paper trail looks worse to an auditor than the incident itself.

Building Your Fax Compliance Checklist

Most compliance gaps trace back to policies that exist on paper but were never operationalized. A working checklist needs three layers: policy, technical controls, and ongoing operations.

Policy elements to lock down:

  • A defined list of authorized senders and receivers
  • Standard cover sheet language limiting liability and directing misdirected faxes back to the sender
  • Written retention and disposal procedures tied to your six-year floor and state overlay

Technical controls to verify:

  • Audit logging turned on and reviewed on a set cadence
  • Access review scheduled at least quarterly
  • Encryption decisions documented, including any alternative controls if encryption is not used

Operational items that keep the system honest over time include recurring workforce training, periodic internal audits, and a scheduled review of every vendor BAA on file.

Pro Tip: Run a fax number validation check before any bulk send to referral partners or insurance offices. A single transposed digit is the single most common cause of a misdirected-fax breach, and it is entirely preventable with a confirmation step before transmission.

What to Look for When Vetting a Fax Archive Vendor

Procurement is where good policy either holds up or falls apart. Before signing with any vendor that will touch PHI, get proof, not promises. Ask for a signed BAA naming fax storage explicitly, a sample export of audit logs, and confirmation of encryption status both in transit and at rest.

Then test it. Request temporary access to a sandbox account, pull sample logs, and run a real export and deletion exercise. Vendors that hesitate on that request, or that only offer vague retention language, are telling you something. Hosted fax archive platforms vary significantly in retention configuration, and some auto-delete records after a set threshold whether you want that or not, so confirm the defaults before you rely on them.

Worth noting: PerPageFax operates as a pay-per-use sending service, with no account required, delivery confirmation on every transmission, and encryption applied during transfer. It sends faxes rather than archiving them long-term, so it fits into your workflow as the transmission layer feeding into whatever archive and retention system you already run.

What to Look for When Vetting a Fax Archive Vendor — overview diagram

Where Compliance Programs Usually Break Down

The failures I see repeated across fax compliance reviews are rarely exotic. They are the same three, over and over: metadata that got stripped somewhere between the fax machine and the file server, a vendor relationship running for years without a signed BAA, and thermal originals sitting in a filing cabinet slowly fading into blank paper.

None of that requires a technology overhaul to fix. It requires sequence. Stabilize your capture and logging first, because a broken audit trail undermines every other control you build on top of it. Write the retention schedule second, reconciling the federal six-year floor against your state’s medical-record statute rather than guessing. Train staff on cover sheet handling and number verification third. Run an internal audit last, once the first three are actually in place, not before. Skipping the sequence is how organizations end up with a beautiful policy document and no evidence they ever followed it.

— Engin

Sending Faxes Into a Compliant Archive With PerPageFax

PerPageFax gives you a straightforward way to test your archive controls without committing to a subscription first. There is no account to create, no recurring fee, and no contract. You pay $0.50 per page sent, with encryption applied during transmission and delivery confirmation on every job, so you can see exactly when a fax landed before you file it into your system of record.

PerPageFax

That flat, per-page pricing makes it a practical option for the procurement checks covered earlier: run a sample transmission, confirm the delivery confirmation lands cleanly in your log, and check that the encrypted transfer matches what your BAA requires from any vendor touching PHI. If you regularly send across borders, PerPageFax supports faxing to 35 countries at one flat rate, and its free PDF preparation tools let you get a document fax-ready before it ever leaves your system. Send your next fax and see how the confirmation and logging fit into your archive workflow at PerPageFax.

Sources

This guide draws on the HHS Security Rule, NIST SP 800-66, 45 CFR §164.312, and NARA Bulletin 96-03. For secure disposal documentation practices beyond fax records, see this IT disposal compliance guide.

This article is general information, not legal advice. Consult a qualified compliance or legal professional about your own circumstances before acting on anything here.

FAQ

Faxes containing PHI must be stored with access controls, audit trails, and a documented retention policy under the HIPAA Security Rule. Any third-party vendor handling that archive needs a signed Business Associate Agreement before it touches the data.

Is fax still used for protected health information in 2026?

Yes. Fax remains common in healthcare because many providers, pharmacies, and insurers still rely on it for referrals, prior authorizations, and records requests, and it stays subject to full HIPAA obligations whenever PHI is involved.

What are the HIPAA rules regarding faxing patient information?

Faxed PHI falls under both the Privacy Rule and Security Rule: minimum-necessary access applies, cover sheets should limit exposed information, and stored faxes need the same technical safeguards as any other ePHI. A misdirected fax can trigger breach notification obligations depending on the risk assessment outcome.

How long must fax records be retained under HIPAA?

HIPAA-related compliance documentation generally has a six-year federal retention floor, while actual medical-record retention periods are set by individual states and can run longer. Build your schedule around whichever period applies longest to a given document.

What are the main reasons for keeping a fax archive?

Organizations archive faxes to maintain a defensible chain of custody, satisfy state and federal retention statutes, and produce evidence during audits or legal disputes. A complete archive also protects the organization if a delivery or content dispute arises later, since the transmission metadata proves what was actually sent.

Ready to send a fax?

Send your fax online in minutes for $0.50/page — no account needed.

Send a fax now