
By Sezgin Tekin · October 10, 2026
Fax Privacy Laws: 3 Safeguards for Healthcare
Yes, HIPAA permits faxing protected health information, but only when reasonable safeguards are in place. For treatment, payment, and operations, the Privacy Rule allows faxing PHI without separate patient authorization, provided staff verify the recipient and apply appropriate controls. Any cloud or online fax vendor touching ePHI must sign a Business Associate Agreement, and some jurisdictions outside the United States restrict fax use when secure electronic alternatives exist.
TL;DR:
- Digital fax systems need encryption in transit and at rest, access controls, audit logs, and a signed BAA that covers the service.
- Verify each recipient through an authoritative source, test a new number with a blank page and phone call, and keep clinical details off cover sheets.
- NHS contractors must use an available secure electronic channel instead of faxing; Canadian guidance favors encrypted alternatives, and GDPR requires security measures matched to risk.
- If a fax goes to the wrong number, stop further transmission, request destruction, assess whether PHI was viewed or disclosed, and document actions and required reporting.
How HIPAA frames faxing of PHI
The Privacy Rule treats fax as a legitimate channel for sharing PHI, not a legacy workaround. HHS guidance confirms that covered health care providers can share patient information by fax for treatment purposes without a signed authorization, as long as reasonable safeguards match the sensitivity of the information and the mode of transmission.
The Security Rule enters the picture the moment a fax becomes electronic rather than purely analog. A standalone phone-line fax machine sits mostly outside the Security Rule’s technical requirements, but a fax server, fax-over-IP (FoIP) system, or cloud-based eFax service creates and stores ePHI, which brings encryption, access controls, and audit logging into scope.
That distinction matters for liability too:
- A traditional analog machine is generally treated as a conduit, with minimal Security Rule exposure.
- A digital or cloud fax platform that stores, converts, or routes ePHI functions as a business associate.
- Any vendor acting as a business associate needs a signed BAA before it touches real patient data.
Reasonable safeguards: technical, administrative, and physical controls
Regulators do not prescribe a single checklist, but the safeguards expected under HIPAA fall into three familiar buckets.
- Technical controls: use TLS or HTTPS for any web-based fax submission, apply AES encryption to stored faxes, enable hold-and-release printing so documents do not sit exposed on a tray, and disable outdated or unencrypted transmission protocols.
- Administrative controls: apply the minimum-necessary standard, require a verification step before sending sensitive faxes, train staff on fax-specific risks, document procedures, and maintain audit logs of what was sent and when.
- Physical controls: keep fax machines and servers in supervised areas, lock output trays, and shred or securely dispose of printed PHI once it is no longer needed.
Pro Tip: Before sending a new recipient’s first fax containing PHI, send a blank or non-PHI test page and confirm receipt by phone, then send the real document.
Fax cover sheets: what to include and sample language
A cover sheet does real work: it tells the recipient what arrived, confirms the page count, and gives a path to flag a misdirected fax before anyone reads further. Keep it generic enough that a glance at the cover sheet alone reveals nothing clinical.
- Sender name, department, and direct callback number
- Recipient name and department (never a diagnosis or specific service line)
- Date and total page count, including the cover sheet
- A short confidentiality notice instructing accidental recipients to destroy the fax and call to report it
- No patient diagnoses, medication names, or other clinical identifiers anywhere on the cover page
Several institutions publish ready reference templates, including the UAMS HIPAA Office’s cover sheet examples, and we maintain our own HIPAA fax cover sheet template along with ready-to-use confidentiality statements that teams can adapt directly.
Cloud/online fax and Business Associate Agreements
Once a fax moves through a cloud or online service rather than a dedicated phone line, the vendor is handling ePHI on the organization’s behalf. HHS guidance on cloud services makes clear that this relationship requires a signed Business Associate Agreement, and the vendor can be held directly liable under the HIPAA Rules regardless of whether staff ever view the stored data.
Before signing with any fax vendor, procurement teams should confirm:
- A BAA is available and covers the specific service being purchased, not just a general terms-of-service page
- Transmissions are encrypted in transit and documents are encrypted at rest
- The vendor maintains audit trails showing who sent or received each fax and when
- The vendor has a documented breach notification process with defined timelines
- Data retention and deletion practices match the organization’s own record-keeping policy
Vendor due diligence does not end at contract signature. Periodic review of these same points, especially audit log access and encryption configuration, keeps the relationship defensible if a regulator ever asks.
International rules that change practice
Fax rules are not uniform once an organization operates, refers patients, or exchanges records across borders.
- The National Health Service (Electronic Communications) Regulations 2020 bar NHS contractors from using facsimile transmission to send information to NHS bodies when a secure, direct electronic channel is available, with narrow exceptions for private clinical services.
- GDPR requires controllers to apply security appropriate to the risk when transmitting personal data, which in practice means evaluating threats like unauthorized disclosure and applying safeguards such as encryption before a fax carrying personal data leaves the building.
- The Office of the Privacy Commissioner of Canada recommends phasing out analog fax machines for personal health information in favor of encrypted email or secure portals, while offering mitigation tips for organizations that still rely on fax.
For clinics weighing a broader shift away from fax entirely, our partner at NFD’s guidance on secure messaging for clinics walks through migration paths worth comparing against current workflows.
Practical step-by-step checklist for staff
A short, printable process reduces the most common fax errors, which are almost always human rather than technical.
- Verify the recipient’s fax number against an authoritative source, such as a main directory line, rather than a handwritten note, and document the verification.
- Apply the minimum-necessary standard, redacting or omitting information that is not required for the specific purpose.
- Attach a compliant cover sheet with the confidentiality notice and callback instructions, never clinical details.
- Use hold-and-release printing or a secure-receive setting on the recipient end whenever the document is clinically sensitive.
- Request delivery confirmation for anything time-sensitive or high-risk, and log the transmission metadata (date, time, recipient, page count).
Pro Tip: Post this checklist directly above shared fax machines and multifunction printers, since most misdirected faxes trace back to a skipped verification step, not a technology failure.
Breach response if PHI is misdirected or exposed via fax
A misdirected fax is a common, manageable incident when the response is fast and documented.
- Stop any further transmission to the wrong number immediately and attempt to reach the unintended recipient to request destruction of the fax.
- Conduct a risk assessment that weighs the nature and extent of the PHI involved, who received it, whether it was actually viewed, and the likelihood the information was further disclosed.
- If the risk assessment indicates a reportable breach, follow the Breach Notification Rule’s required timelines and documentation steps, and keep a written record of every action taken, from discovery to resolution.
Treating each incident this way, rather than informally, is what makes a fax error defensible later rather than a compliance gap.
Encryption standards for fax transmissions and their legal requirements
HIPAA does not mandate one specific encryption algorithm for faxing, but it does require that any electronic handling of PHI, including fax servers and cloud fax platforms, apply safeguards appropriate to the risk. In practice, that means transmissions should run over TLS or an equivalent encrypted channel rather than an unsecured internet connection, and any stored copies, whether on a fax server or in a vendor’s cloud environment, should use strong encryption such as AES at rest.
A standalone analog fax machine connected directly to a phone line operates differently: because the signal travels over the traditional telephone network rather than the internet, it falls largely outside the Security Rule’s encryption requirements in the way a digital system does. That does not make analog fax inherently safer. It simply shifts the risk toward physical exposure, misdialed numbers, and unattended output trays rather than network interception.

For any system that does route faxes digitally, whether an on-premises FoIP setup or a cloud-based service, the organization should confirm encryption in transit, encryption at rest, and a documented explanation from the vendor of which standards are in use. This is also where the Business Associate Agreement becomes relevant again: the BAA should specify that the vendor maintains encryption and security controls consistent with the Security Rule, not just a general promise of safe handling. Our overview of online fax security walks through how encryption and audit trails typically work on cloud fax platforms.
Secure storage and disposal of faxed PHI received or sent
A compliant fax program does not end when the transmission completes. Received faxes containing PHI need the same storage controls as any other medical record: locked file cabinets or access-controlled digital folders, limited to staff with a legitimate need to view the document, and a retention schedule consistent with the organization’s broader medical records policy.
Digital fax systems and multifunction printers often retain images in internal memory even after a document has been printed or forwarded. Treat every shared fax machine or server as a workstation that could hold PHI, and include it in decommissioning and disposal procedures. Before retiring or returning a leased device, confirm that internal storage has been sanitized according to a documented process, not just reset to factory settings.
For printed faxes, shredding remains the standard disposal method once a document is no longer needed, and the shredding or secure destruction should be logged the same way other PHI disposal is logged. Organizations that document both storage and disposal practices in writing are in a far stronger position if a regulator or auditor asks how faxed PHI was handled after delivery.
Guidance on faxing PHI across state or international borders
Faxing across state lines within the United States does not change the HIPAA analysis much: the Privacy Rule and Security Rule apply based on the sender’s and receiver’s status as covered entities or business associates, not based on which state line the fax crosses. The safeguards already discussed, verification, encryption where applicable, and minimum-necessary disclosure, apply the same way whether the recipient is down the hall or across the country.
Crossing an international border is where the analysis changes. A fax sent to a UK NHS contractor may run into the restriction on facsimile transmission when a secure electronic channel is available, under the National Health Service (Electronic Communications) Regulations 2020. A fax carrying personal data into or within the European Union triggers GDPR’s requirement for security appropriate to risk, regardless of whether HIPAA also applies to the sender. And a fax involving Canadian patient data runs into the Privacy Commissioner of Canada’s explicit recommendation to move away from analog fax for health information.
The practical takeaway: before faxing PHI internationally, confirm which jurisdiction’s rules govern the recipient, not just the sender, since the destination country’s restrictions can be stricter than HIPAA’s own baseline.

Operational perspective: balancing legacy fax use with a migration path
Fax persists in healthcare because referral networks, pharmacies, and payers still depend on it, not because it is anyone’s preferred technology. The realistic goal is not eliminating fax overnight. It is making every fax defensible: verified recipients, encrypted transmission where digital, signed BAAs for every vendor, and a periodic review that treats fax safeguards as seriously as any other PHI channel while a longer migration to secure digital alternatives moves forward.
— Engin
How PerPageFax supports compliant fax workflows
We built PerPageFax around the safeguards this guide covers rather than around a subscription you have to manage. Every fax we send uses encrypted transmission, automatic retries if a line is busy, and delivery confirmation so you have a record of what went out and when, all at a flat $0.50 per page with no account or subscription required.

If your organization needs ePHI handled under a Business Associate Agreement, ask us about that directly before sending patient records. For the cover sheet itself, our HIPAA fax cover sheet template is ready to download and pair with your next transmission, and you can send your fax online whenever you’re ready.
This article is general information, not a substitute for advice from a qualified doctor. Consult a qualified healthcare professional about your own circumstances before acting on anything here.
FAQ
Is fax HIPAA compliant?
Fax can be HIPAA compliant when covered providers apply reasonable safeguards and share PHI for treatment, payment, or operations, as HHS guidance confirms. Compliance depends on the safeguards used and, for digital or cloud fax services, on having a signed Business Associate Agreement with the vendor.
What privacy guidelines apply to electronic documentation?
Electronic PHI falls under HIPAA’s Security Rule, which requires technical, administrative, and physical safeguards such as encryption, access controls, and audit logging. Outside the United States, frameworks like GDPR add their own requirement to apply security measures appropriate to the risk of the data being handled.
Are fax cover sheets necessary?
Cover sheets are not explicitly mandated by HIPAA, but they are a widely recommended safeguard that gives accidental recipients clear instructions to destroy a misdirected fax and contact the sender. A good cover sheet confirms the page count and callback information while keeping clinical details off the page entirely.
Do people still use fax today?
Yes, fax remains common in healthcare because referral networks, pharmacies, and insurers continue to rely on it alongside newer digital channels. Some jurisdictions, including the UK’s NHS regulations, are actively limiting fax use where secure electronic alternatives already exist, which signals a gradual shift away from it.
Sources
- FAQ 482 — Does the HIPAA Privacy Rule permit sharing patient information by fax, e‑mail, or phone? — HHS
- Legislation
- Consider the risks: Faxing personal information — Office of the Privacy Commissioner of Canada
- Regulation (EU) 2016/679 (GDPR) — EUR-Lex
Recommended
Ready to send a fax?
Send your fax online in minutes for $0.50/page — no account needed.
Send a fax now