
HIPAA doesn't ban faxing. It asks you to protect patient information when you fax it. This guide explains the requirements in plain English, how to meet them with an online fax service, and what changes in your account when HIPAA mode is on.
HIPAA (the Health Insurance Portability and Accountability Act) doesn't ban faxing patient information. The HIPAA Privacy Rule allows it, as long as you have reasonable administrative, technical, and physical safeguards in place to protect that information. For an online fax service, that typically means encryption, controlled access, a record of who did what, and a signed Business Associate Agreement with your provider.
If you mainly want to know what changes in your account when HIPAA mode is on, jump to the comparison table below.
Yes. The U.S. Department of Health and Human Services (HHS) confirms that a provider can fax protected health information to another provider for treatment. Protected health information (PHI) is any health information that can identify a patient, from a diagnosis to a date of birth.
What HIPAA asks for is care, not a specific technology. HHS points to 45 CFR 164.530(c), the Privacy Rule's safeguards requirement, and gives simple examples: confirm the fax number before you send, and keep the fax machine somewhere unauthorized people can't reach it.
HIPAA describes safeguards in three groups. Here's what each one means for faxing.
Administrative safeguards. Policies and people. Decide who is allowed to send and receive PHI by fax, train them, and confirm recipient numbers before sending. Send only the information the recipient needs.
Physical safeguards. Where documents end up. A paper fax sitting in a shared tray is the classic risk. With online fax, the equivalent is making sure faxes land in a protected inbox instead of on a machine or in a shared mailbox.
Technical safeguards. How the data is protected in systems. That covers encryption, unique user access, and audit records that show who sent, received, or viewed a fax.
Many organizations also use a cover sheet with a confidentiality notice. HIPAA doesn't specifically require one, but it's a common practice. Fax.Plus offers a free HIPAA fax cover sheet template.
When a vendor stores or transmits PHI for you, it becomes your business associate. HIPAA then requires a Business Associate Agreement (BAA): a contract in which the vendor commits to protecting the PHI it handles for you. Without a BAA, sending PHI through the service isn't compliant, however secure the service is.
You also want the technical safeguards built in. On the Fax.Plus Enterprise plan, that includes:
There is no official HIPAA certification, for fax or anything else. When a vendor says it is "HIPAA compliant," what matters is that it signs a BAA and implements the required safeguards.
HIPAA-compliant faxing on Fax.Plus is available on the Enterprise plan. Setup takes three steps:
HIPAA mode is set at the account level, not per user or per department. Everyone in the Enterprise account works inside the same protected setup, which removes the risk of one team member faxing PHI from an unprotected corner of the account.
Teams usually want this answered before they switch, so here is the full picture.
| Feature | Standard account | With HIPAA mode on |
|---|---|---|
| Email and Slack notifications | Can include the fax as an attachment | Notification only, no attachment |
| Received faxes by email | Delivered as an attachment (PDF or TIFF) | Notification without the attachment; the fax stays in your encrypted inbox |
| Email to fax | Send from your verified account email to number@fax.plus | Send to number@tls.fax.plus, with TLS enforced; only users provisioned in the account can send |
| Zapier | Available on Enterprise | Turned off |
| REST API and webhooks | Available on Enterprise | Keep working, including Fax.Plus AI |
| Web and mobile apps | Available | Keep working |
| User management and number assignment | Available | Keep working |
Two details are worth knowing. If someone on a HIPAA account emails the standard @fax.plus address by mistake, Fax.Plus redirects the message into the TLS-enforced pipeline automatically. And because Zapier is off, the API is the route for connecting fax to your other systems in a HIPAA workflow. See the HIPAA fax API for details.
Only Enterprise. The plan brings together what HIPAA faxing needs: the BAA, Advanced Security Controls, audit logging, role-based access, and data residency options. Lower plans don't include these, so they aren't eligible for PHI.
For the full list of controls, see HIPAA-compliant fax. For a primer on the law itself, see what is HIPAA.
Before your team faxes PHI, confirm each of these:
Use a fax service that signs a BAA and protects faxes with encryption and access controls. On Fax.Plus, that means an Enterprise account with Advanced Security Controls on and a signed BAA. Then confirm the recipient's number, send only the information they need, and use a cover sheet with a confidentiality notice.
A fax number on its own isn't health information. But fax numbers are on HIPAA's list of identifiers, so a fax number linked to a patient's health information is part of that patient's PHI and needs the same protection.
No specific rule requires one. Many organizations use a cover sheet with a confidentiality notice as part of their safeguards. You can start from the free HIPAA fax cover sheet template and check what to include on a HIPAA cover sheet.
There is no formal HIPAA certification program. Fax.Plus, on the Enterprise plan, implements HIPAA's technical safeguards and signs BAAs with covered entities and business associates.
No. On Fax.Plus, HIPAA mode applies to the whole Enterprise account. One BAA covers the account, and every member works inside the protected setup.
Yes. HIPAA accounts send email-to-fax through a dedicated address, number@tls.fax.plus, with TLS encryption enforced. Only users provisioned in your account can send this way.
No. HIPAA-compliant faxing requires the Enterprise plan with Advanced Security Controls and a signed BAA.
