Fax.Plus
>
HIPAA Fax Requirements

HIPAA Fax Requirements

HIPAA Fax Requirements

HIPAA doesn't ban faxing. It asks you to protect patient information when you fax it. This guide explains the requirements in plain English, how to meet them with an online fax service, and what changes in your account when HIPAA mode is on.

Published on
September 29, 2026
Last updated on
October 7, 2026
Share
  • HIPAA allows you to fax protected health information (PHI) if you have reasonable safeguards in place.
  • With an online fax service, those safeguards include encryption, access controls, audit trails, and a signed Business Associate Agreement (BAA).
  • On Fax.Plus, HIPAA-compliant faxing is available on the Enterprise plan with Advanced Security Controls and a signed BAA.
  • HIPAA mode applies to the whole account. Notifications stop carrying attachments, Zapier is turned off, and email-to-fax moves to a dedicated TLS-enforced address.
  • The API and the web and mobile apps keep working in HIPAA mode.

HIPAA (the Health Insurance Portability and Accountability Act) doesn't ban faxing patient information. The HIPAA Privacy Rule allows it, as long as you have reasonable administrative, technical, and physical safeguards in place to protect that information. For an online fax service, that typically means encryption, controlled access, a record of who did what, and a signed Business Associate Agreement with your provider.

If you mainly want to know what changes in your account when HIPAA mode is on, jump to the comparison table below.

Is faxing allowed under HIPAA?

Yes. The U.S. Department of Health and Human Services (HHS) confirms that a provider can fax protected health information to another provider for treatment. Protected health information (PHI) is any health information that can identify a patient, from a diagnosis to a date of birth.

What HIPAA asks for is care, not a specific technology. HHS points to 45 CFR 164.530(c), the Privacy Rule's safeguards requirement, and gives simple examples: confirm the fax number before you send, and keep the fax machine somewhere unauthorized people can't reach it.

What does HIPAA require when you fax?

HIPAA describes safeguards in three groups. Here's what each one means for faxing.

Administrative safeguards. Policies and people. Decide who is allowed to send and receive PHI by fax, train them, and confirm recipient numbers before sending. Send only the information the recipient needs.

Physical safeguards. Where documents end up. A paper fax sitting in a shared tray is the classic risk. With online fax, the equivalent is making sure faxes land in a protected inbox instead of on a machine or in a shared mailbox.

Technical safeguards. How the data is protected in systems. That covers encryption, unique user access, and audit records that show who sent, received, or viewed a fax.

Many organizations also use a cover sheet with a confidentiality notice. HIPAA doesn't specifically require one, but it's a common practice. Fax.Plus offers a free HIPAA fax cover sheet template.

What changes when you use an online fax service?

When a vendor stores or transmits PHI for you, it becomes your business associate. HIPAA then requires a Business Associate Agreement (BAA): a contract in which the vendor commits to protecting the PHI it handles for you. Without a BAA, sending PHI through the service isn't compliant, however secure the service is.

You also want the technical safeguards built in. On the Fax.Plus Enterprise plan, that includes:

  • AES-256 encryption for stored faxes and TLS encryption in transit
  • Role-based access, so members see only what their role allows
  • Two-factor authentication, which admins can enforce for the team
  • Audit trails of account and fax activity
  • A choice of where your fax data is stored, including the United States and Canada

There is no official HIPAA certification, for fax or anything else. When a vendor says it is "HIPAA compliant," what matters is that it signs a BAA and implements the required safeguards.

How do you set up HIPAA-compliant faxing on Fax.Plus?

HIPAA-compliant faxing on Fax.Plus is available on the Enterprise plan. Setup takes three steps:

  1. Be on the Enterprise plan. Free, Basic, Premium, and Business plans are not HIPAA-eligible and shouldn't be used for PHI.
  2. Turn on Advanced Security Controls. An account owner or admin activates them under Settings, Security. They apply to the whole team at once.
  3. Request and sign the BAA. Once the BAA is signed and the security controls are on, your team can send and receive PHI.

HIPAA mode is set at the account level, not per user or per department. Everyone in the Enterprise account works inside the same protected setup, which removes the risk of one team member faxing PHI from an unprotected corner of the account.

What changes when HIPAA mode is on?

Teams usually want this answered before they switch, so here is the full picture.

FeatureStandard accountWith HIPAA mode on
Email and Slack notificationsCan include the fax as an attachmentNotification only, no attachment
Received faxes by emailDelivered as an attachment (PDF or TIFF)Notification without the attachment; the fax stays in your encrypted inbox
Email to faxSend from your verified account email to number@fax.plusSend to number@tls.fax.plus, with TLS enforced; only users provisioned in the account can send
ZapierAvailable on EnterpriseTurned off
REST API and webhooksAvailable on EnterpriseKeep working, including Fax.Plus AI
Web and mobile appsAvailableKeep working
User management and number assignmentAvailableKeep working

Two details are worth knowing. If someone on a HIPAA account emails the standard @fax.plus address by mistake, Fax.Plus redirects the message into the TLS-enforced pipeline automatically. And because Zapier is off, the API is the route for connecting fax to your other systems in a HIPAA workflow. See the HIPAA fax API for details.

Which Fax.Plus plans can be used for PHI?

Only Enterprise. The plan brings together what HIPAA faxing needs: the BAA, Advanced Security Controls, audit logging, role-based access, and data residency options. Lower plans don't include these, so they aren't eligible for PHI.

For the full list of controls, see HIPAA-compliant fax. For a primer on the law itself, see what is HIPAA.

A HIPAA fax checklist

Before your team faxes PHI, confirm each of these:

  1. A BAA is signed with your fax provider.
  2. HIPAA mode (Advanced Security Controls on Fax.Plus) is on for the account.
  3. Only trained staff have access, with roles that match their job.
  4. Two-factor authentication is enforced.
  5. Recipient numbers are confirmed before sending, and saved as contacts when possible.
  6. Faxes are sent with only the information the recipient needs.
  7. Staff know where received faxes land, and that PHI shouldn't be forwarded to personal email or unapproved tools.

FAQs

How do you send a HIPAA-compliant fax?

Use a fax service that signs a BAA and protects faxes with encryption and access controls. On Fax.Plus, that means an Enterprise account with Advanced Security Controls on and a signed BAA. Then confirm the recipient's number, send only the information they need, and use a cover sheet with a confidentiality notice.

Is a fax number protected under HIPAA?

A fax number on its own isn't health information. But fax numbers are on HIPAA's list of identifiers, so a fax number linked to a patient's health information is part of that patient's PHI and needs the same protection.

Does HIPAA require a fax cover sheet?

No specific rule requires one. Many organizations use a cover sheet with a confidentiality notice as part of their safeguards. You can start from the free HIPAA fax cover sheet template and check what to include on a HIPAA cover sheet.

Is Fax.Plus HIPAA certified?

There is no formal HIPAA certification program. Fax.Plus, on the Enterprise plan, implements HIPAA's technical safeguards and signs BAAs with covered entities and business associates.

Can I turn on HIPAA mode for one department only?

No. On Fax.Plus, HIPAA mode applies to the whole Enterprise account. One BAA covers the account, and every member works inside the protected setup.

Can I still send faxes from email with HIPAA mode on?

Yes. HIPAA accounts send email-to-fax through a dedicated address, number@tls.fax.plus, with TLS encryption enforced. Only users provisioned in your account can send this way.

Can I use Fax.Plus for PHI on the Basic, Premium, or Business plan?

No. HIPAA-compliant faxing requires the Enterprise plan with Advanced Security Controls and a signed BAA.

Jump to section
H2 toc
Secure Online Fax Service
Fax.Plus