How to Write a HIPAA Fax Disclaimer?

HIPAA’s Privacy and Security Rules require “reasonable safeguards” to keep PHI private. A clear disclaimer is the frontline reminder for anyone who stumbles onto a misfaxed record. Sending a HIPAA-compliant fax with Fax.Plus is straightforward simply download the cover sheet and sign up for a HIPAA plan.

/  Overview

Why Every Fax Needs a HIPAA Disclaimer?

The Privacy Rule protects “individually identifiable health information,” while the Security Rule sets the technical and physical locks around it. Both expect you to warn unintended readers.

Recent breach penalties

  • $50 000 (2024) — Pediatric office mis-faxed immunization records.

  • $1.5 million (2023) — Hospital chain failed to act after repeated mis-routes. Each case noted that a missing or vague disclaimer made matters worse.

When is a disclaimer mandatory?

  • Mandatory whenever PHI leaves your office.

  • Strongly recommended for anything that might reference patient data (e.g., billing codes).

Step-by-Step HIPAA Disclaimer Writing Guide

Creating a HIPAA-compliant fax cover sheet doesn’t have to be complicated. Here are practical tips to keep in mind:

  • Open with confidentiality: Start the very first sentence with “This fax is confidential…”.

  • Name the intended recipient: Eg., “for Rachel Kim”

  • Reference the law: A quick “pursuant to HIPAA 164.306 and the HITECH Act” shows regulators you’re aligned.

  • Tell the wrong person what to do: Destroy, return, or call you—give a phone number.

  • Keep it under 120 words: Shorter text is more likely to be read and meets readability goals.

/  Templates

Fax Disclaimer Templates

Short-form (≤75 words)

This fax and any files attached are private and may contain protected health information (PHI). If you received this fax in error, please call 555 555 5555 and destroy this message. Sharing or keeping it violates federal law.

Long-form with state add-ons (≈110 words)

The information in this facsimile is confidential and intended solely for the individual or entity named above. It may include protected health information (PHI) governed by HIPAA 164.306 and the HITECH Act, and by California Civil Code 56 where applicable. If you are not the intended recipient, any review, disclosure, copying, distribution, or use of this fax is strictly prohibited. Please notify the sender at 555 555 5555, return the fax to the address below, and permanently delete or shred all pages.


Looking to send sensitive documents securely? Use one of our HIPAA-compliant cover sheets to help protect patient privacy and support your compliance efforts.

Start faxing now.

Create an account to save time and money by sending free faxes from a computer or mobile to anywhere in the world.

Partner with us!

Join our affiliate program and deliver exceptional online faxing solutions to your audience.
Become a Partner