HIPAA compliance in medical faxing means sending protected health information (PHI) by fax only for permitted purposes, with reasonable safeguards: verifying the fax number, using a cover sheet, sending the minimum necessary information and protecting incoming faxes. Online fax providers that handle PHI must sign a business associate agreement (BAA). HIPAA allows faxing; it does not ban it.
Key Takeaways
- The HIPAA Privacy Rule permits providers to fax PHI for treatment without patient authorization, provided they use reasonable safeguards such as confirming the recipient’s fax number.
- An online fax service that stores or processes PHI is a business associate, so a signed business associate agreement (BAA) is required before using it.
- A fax sent to the wrong number is presumed to be a reportable breach unless a documented risk assessment shows a low probability that the PHI was compromised.
- As of January 28, 2026, HHS civil penalties range from $145 to $2,190,294 per violation, depending on culpability.
- The proposed HIPAA Security Rule overhaul (published January 6, 2025) was still not final as of September 2026; the current Security Rule remains in force.
Before any transmission of medical files or records is completed, the business or medical facility should check whether a signed authorization from the patient is needed: HIPAA allows records to be shared for treatment, payment and healthcare operations without one, but most other disclosures require it. Federal rules limit when and how patient records can be shared, and staff must follow them for every transmission.
If a breach occurs, the organization must be able to show what safeguards were in place and may have to notify the affected patients. Online fax services can be useful for healthcare organizations, but the protected health information (PHI) in each fax must be safeguarded every time a document is sent.

Safeguarding Medical Records Transmissions
The Health Insurance Portability and Accountability Act of 1996 requires covered entities, such as healthcare providers and health plans, and their business associates to safeguard medical record transmissions. Online faxing services are convenient for all organizations, but the owners and staff must manage healthcare data with the utmost care.
Faxes that contain medical data should carry a warning, usually on the cover sheet, telling anyone who receives the fax in error that it contains confidential health information. A cover sheet with a confidentiality notice is a widely used safeguard, although HIPAA does not prescribe specific wording. Companies can discuss these requirements for e-faxing with HIPAA compliance with service providers.
Ensuring the Correct Person Sees the Data
As a recommended safeguard (HIPAA does not prescribe a specific cover sheet), staff should use a cover letter that identifies the correct recipient, and HHS guidance suggests confirming an unfamiliar fax number with the recipient before sending. Businesses receive a large number of faxes each day, and in a busy office environment, anyone could receive the faxes.
Online fax services can reduce this risk, because incoming faxes can be delivered to an access-controlled inbox instead of a shared paper tray. Since the online business services offer email to fax options, the administrator can set up the services to send faxes to specific parties via email.
Preventing Data Corruption and Medical Errors
Cybercriminals attack medical data systems to capture data and use the information unethically. If the criminals get access, the perpetrators could change or alter information to do harm to the patients. When an online fax service is set up, access should be limited by role, so that only employees who need the medical data for their work can view, change or use it; the HIPAA Security Rule calls these access controls. Encryption and integrity controls protect the data and help prevent changes while the information is transmitted.
Establishing Secure Connections for Traveling Healthcare Workers
Nurses and doctors travel to provide care for patients in a variety of locations. During this care, medical data is collected and must be stored. When managing care for local individuals, the healthcare workers may need assistance from other medical professionals.
To get a consultation on the case, the healthcare workers must transmit the medical data to the other party. When online fax services are set up, the organization and its provider should give remote workers secure, authenticated connections, such as encrypted apps or a VPN, and apply the same safeguards used in the office.
The Ramifications of Violations
Any violation of HIPAA regulations could lead to serious penalties for the business or healthcare organization. Civil penalties are tiered according to how culpable the organization was (see the penalty table below). Under 42 U.S.C. 1320d-6, criminal penalties reach up to $50,000 and one year in prison for knowingly obtaining or disclosing health information in violation of HIPAA, up to $100,000 and five years if the offense involves false pretenses, and up to $250,000 and ten years where the intent is to sell or use the information for commercial advantage, personal gain or malicious harm.
If the victim incurred any financial losses or injuries because of the violation, the criminal laws may require the offender to pay restitution upon conviction. Online faxing services must prevent unauthorized access or patient injuries.
Healthcare records must be protected according to HIPAA regulations to prevent unauthorized viewing and use. The HIPAA Security Rule’s transmission security standard requires technical measures that guard against unauthorized access to electronic health information sent over a network.
A cover sheet that names the intended recipient and carries a confidentiality notice is good practice for every fax that contains health data. By reviewing details about the importance of HIPAA compliance, all organizations and medical facilities can safeguard patients and their data.
What Is HIPAA-Compliant Faxing?
HIPAA-compliant faxing is the transmission of protected health information by fax in a way that meets the requirements of the Health Insurance Portability and Accountability Act of 1996 (HIPAA, often misspelled HIPPA). HIPAA does not ban fax. The law requires covered entities and their business associates to limit who receives PHI, protect it in transit and at rest, and respond properly when something goes wrong.
The distinction between paper fax and electronic fax matters. Under the HIPAA definitions in 45 CFR 160.103, a paper fax is not treated as a transmission via electronic media if the information did not exist in electronic form immediately before it was sent. A fax sent from an electronic health record, a computer or an email-to-fax service, however, involves electronic PHI (ePHI), so the HIPAA Security Rule applies to it as well as the Privacy Rule.
Which HIPAA Rules Apply to Medical Faxing?
Three HIPAA rules shape how a practice, hospital, pharmacy or health plan should handle faxes.
| HIPAA rule | What it covers | What it means for faxing |
|---|---|---|
| Privacy Rule | When PHI may be used or disclosed, and the minimum necessary standard | Fax only for a permitted purpose (such as treatment or payment) or with the patient’s authorization, send only what the recipient needs, and use reasonable safeguards |
| Security Rule | Administrative, physical and technical safeguards for electronic PHI | Risk analysis, access controls, audit logs and transmission security for e-fax, fax servers and multifunction devices that store images |
| Breach Notification Rule | Notice after a breach of unsecured PHI | A misdirected fax may require notice to the patient, to HHS and, for large breaches, to the media |
Is Faxing Medical Records HIPAA Compliant?
Yes, faxing medical records is permitted under HIPAA when reasonable safeguards are used. According to an HHS frequently asked question on treatment communications, the Privacy Rule allows providers to share PHI for treatment by fax, email or phone. HHS gives examples such as a laboratory faxing test results to a physician and a hospital faxing care instructions to a nursing home that will receive the patient.
HHS also describes what reasonable safeguards look like for fax: confirming the fax number with the intended recipient when sending to a number that is not regularly used, and pre-programming frequently used numbers into the fax machine to avoid misdialing.
How to Send a HIPAA-Compliant Fax: Step by Step
- Confirm the purpose. Check that the disclosure is permitted (treatment, payment or health care operations) or that a signed patient authorization is on file.
- Apply the minimum necessary standard. For purposes other than treatment, send only the pages the recipient actually needs.
- Verify the number. Confirm an unfamiliar fax number by phone, and use saved, pre-programmed numbers for regular contacts.
- Use a cover sheet. Name the sender and intended recipient, give the page count and include a confidentiality notice asking anyone who receives it in error to notify the sender.
- Protect the receiving end. Ask the recipient to collect the fax promptly or use a secure digital inbox, rather than leaving pages on a shared machine.
- Confirm delivery and keep records. Keep the transmission report or the online service’s audit log, so the organization can show what was sent, when and to whom.
Choosing a HIPAA-Compliant Online Fax Service
An online fax service that stores or processes PHI is a HIPAA business associate and must sign a business associate agreement. HHS guidance on cloud computing states that a cloud service provider that creates, receives, maintains or transmits ePHI is a business associate, even if it stores only encrypted data and has no decryption key. The narrow “conduit” exception covers only transmission services with transient access to data, and HHS says it does not apply to providers that store ePHI.
Before choosing a provider, an organization should check that the service offers:
- A signed business associate agreement (BAA) covering fax storage and transmission
- Encryption of faxes in transit and at rest
- Unique user logins, role-based permissions and multi-factor authentication
- Audit logs showing who sent, viewed or downloaded each fax
- Configurable retention and secure deletion settings
- Integration with the practice’s electronic health record, where needed
The same questions apply to any vendor that hosts health data; the guide to selecting HIPAA compliant web hosting covers similar checks, and the overview of the risk of data breaches in the cloud explains why storage settings matter. Consumer shortcuts, such as sending a fax from Gmail or using a fax app on an iPhone, are convenient for everyday documents, but they should not be used for PHI unless the organization has a BAA with the provider and has configured the account to meet its Security Rule policies. When evaluating records systems, the checklist of must-have features in EHR software can help an organization decide whether faxing can be handled inside the EHR.
What Happens If a Fax Goes to the Wrong Number?
A misdirected fax containing PHI is presumed to be a breach under the HIPAA Breach Notification Rule unless the covered entity documents a risk assessment showing a low probability that the information was compromised. That assessment considers four factors: the nature and extent of the PHI, who received it, whether the PHI was actually viewed or acquired, and how far the risk has been mitigated, for example by obtaining the recipient’s written confirmation that the pages were destroyed.
If notice is required, the rule sets these deadlines:
- Affected individuals: without unreasonable delay and no later than 60 days after discovery of the breach.
- HHS, breaches of 500 or more people: within 60 days of discovery.
- HHS, breaches of fewer than 500 people: in an annual log submitted within 60 days of the end of the calendar year.
- Media: prominent media outlets must be notified when a breach affects more than 500 residents of a state or jurisdiction.
- Business associates: must notify the covered entity, which then handles the notices.
General incident-response habits, such as those in these strategies to protect a business from data breaches, help, but the HIPAA deadlines above are legal requirements, not best practices.
HIPAA Penalty Tiers and Current Amounts
HIPAA civil money penalties depend on the level of culpability and are adjusted for inflation every year. The amounts below come from the HHS annual civil monetary penalties inflation adjustment published in the Federal Register on January 28, 2026, and apply to violations on or after February 18, 2009.
| Tier | Culpability | Penalty per violation (as of January 2026) |
|---|---|---|
| 1 | Did not know and, with reasonable diligence, would not have known | $145 to $73,011 |
| 2 | Reasonable cause, not willful neglect | $1,461 to $73,011 |
| 3 | Willful neglect, corrected within 30 days | $14,602 to $73,011 |
| 4 | Willful neglect, not corrected within 30 days | $73,011 to $2,190,294 |
The regulation sets a calendar-year cap of $2,190,294 for identical violations in every tier. However, under a Notification of Enforcement Discretion published in April 2019, HHS applies lower annual caps to the first three tiers: before inflation adjustments, $25,000 for tier 1, $100,000 for tier 2, $250,000 for tier 3 and $1.5 million for tier 4. HHS’s Office for Civil Rights (OCR) enforces these civil penalties, while criminal cases are prosecuted by the Department of Justice.
Recent and Pending HIPAA Rule Changes
The proposed HIPAA Security Rule update is not yet law. HHS published a notice of proposed rulemaking on January 6, 2025, and the comment period closed on March 7, 2025. The proposal would require encryption of ePHI at rest and in transit and multi-factor authentication (each with limited exceptions), remove the distinction between “required” and “addressable” safeguards, require vulnerability scans at least every six months and penetration tests at least every 12 months, and set a 72-hour target for restoring certain systems after an incident.
As of September 2026, no final Security Rule had been published. The federal regulatory agenda moved the target for final action from May 2026 to July 2027, according to HIPAA compliance publications and law-firm alerts reporting on the 2026 agenda. The current Security Rule remains in effect, and because the target date has already slipped, organizations should check the Federal Register for the latest status.
Other recent changes relevant to health information:
- Privacy Rule update: a 2020 proposal would, among other things, shorten the time to respond to patient access requests from 30 days to 15 days. The 2026 regulatory agenda targeted final action for August 2026; its publication had not been confirmed when this article was updated, so the current 30-day rule should be followed until a final rule takes effect.
- Reproductive health privacy rule: the 2024 HIPAA rule on reproductive health care privacy was vacated nationwide by a federal court in Texas in June 2025.
- Part 2 alignment: the February 2024 final rule aligning federal substance use disorder record rules (42 CFR Part 2) more closely with HIPAA had a compliance date of February 16, 2026.
Common HIPAA Faxing Mistakes to Avoid
- Typing fax numbers manually for regular recipients instead of using verified, saved numbers
- Leaving received faxes on a shared machine in a public or busy area
- Using a free or consumer online fax account without a business associate agreement
- Sending a full medical record when the recipient needs only a few pages for a non-treatment purpose
- Ignoring stored images on multifunction printers and fax servers when devices are replaced or disposed of
- Failing to include fax systems in the organization’s Security Rule risk analysis
Frequently Asked Questions
Is it legal to fax medical records under HIPAA?
Faxing medical records is legal under HIPAA. HHS guidance confirms that the Privacy Rule lets providers share PHI for treatment by fax, as long as they use reasonable safeguards such as confirming the recipient’s fax number. Disclosures for purposes other than treatment, payment or health care operations generally need patient authorization.
Does HIPAA require a fax cover sheet?
HIPAA does not specifically require a fax cover sheet or prescribe its wording. A cover sheet naming the intended recipient and carrying a confidentiality notice is a widely used safeguard that helps meet the Privacy Rule’s requirement for reasonable safeguards.
Do online fax services need a business associate agreement?
An online fax service that stores or processes PHI needs a business associate agreement. HHS treats cloud providers that maintain ePHI as business associates even when the data is encrypted, and it says the conduit exception does not cover providers that store data.
What should a practice do if a fax is sent to the wrong number?
A practice should contact the recipient, ask for the pages to be destroyed and get written confirmation, then document a four-factor risk assessment. Unless that assessment shows a low probability of compromise, the Breach Notification Rule requires notice to the patient within 60 days of discovery and a report to HHS.
What are the penalties for a HIPAA violation?
As of January 28, 2026, HIPAA civil penalties range from $145 to $2,190,294 per violation, depending on culpability, with annual caps. Criminal penalties reach up to $250,000 and ten years in prison when health information is misused for commercial advantage, personal gain or malicious harm.
Is HIPAA spelled HIPPA?
The correct spelling is HIPAA, which stands for the Health Insurance Portability and Accountability Act. HIPPA is a common misspelling.