HIPAA compliant faxing in practice: HIPAA faxing rules, HIPAA and faxing for a small office, and the HIPAA compliant fax to email path (HIPAA fax to email) that keeps them

HIPAA compliant faxing is something a practice does, not something it buys. The rules ask that protected health information go only to the intended recipient, that the practice can show who sent what and when, and that any vendor holding a copy along the way has accepted business associate obligations in writing. This page turns that into the handful of habits a small office needs, explains where HIPAA and faxing meet in the fax to email step that most services use, and points at the vendors in the Fax Line Index whose pages state a BAA.

The four habits of HIPAA faxing

Verify the number before the first send to a new recipient, with a test page or a phone call, and keep a list of verified numbers so nobody types one from memory. Use a cover sheet that names the recipient, carries a confidentiality statement and tells a wrong recipient what to do. Keep the transmission record, whether it is a paper report from a machine or the sent log in an online account, for as long as the practice's policy says. And send only what is needed: the referral, not the whole chart. None of this requires a particular product. It requires that the procedure be written down and followed, which is what an auditor will look for after a misdirected fax is reported.

Where HIPAA and faxing collide: fax to email

Most online services deliver an inbound fax as a notification to a mailbox, and many attach the PDF. The attachment is the problem. Once it leaves the vendor's account it is an email, stored by whatever mail provider the practice uses, forwarded by whoever receives it, and outside the vendor's BAA. HIPAA compliant fax to email therefore means one of two things: the notification carries a link into the vendor's secure account rather than the pages themselves, or the practice's mail system is itself covered by a BAA and encrypted. HIPAA fax to email with a plain attachment to a free mailbox is the configuration that turns a compliant service into a breach, and every vendor in the HIPAA class offers a way to avoid it.

The vendors whose pages state a BAA

The index reads each vendor's pricing page for the statement and records it beside the price. WestFax prints a signed BAA on every plan, including Solo at $14.99 a month billed monthly with 500 pages and a 3¢ overage. eFax's Business plan card prints HIPAA compliance with a Business Associate Agreement, with the offer starting at $14.99 for 500 pages a month and $0.07 per page beyond. The rest of the HIPAA class, Fax.Plus at $6.99, CocoFax at $9.99, iFax at $12.49 and Documo at $25 a month billed annually, state HIPAA compliance on their sites; the practice should ask each for the BAA that covers the entry plan and keep the signed copy with its policies.

Questions people ask about hipaa compliant faxing

Is faxing allowed under HIPAA at all?

Yes. Fax is a permitted way to transmit protected health information provided the practice applies reasonable safeguards: verified numbers, cover sheets, records, and a BAA for any vendor that stores copies.

What do I do after a misdirected fax?

Call the recipient, ask them to destroy or return it, document the call, and assess whether it is a reportable breach under the practice's policy. The cover sheet's instructions make the first step likelier.

Does a BAA make fax to email safe?

The vendor's BAA covers the vendor's storage. A PDF attached to an ordinary email is outside it. Use the secure-link delivery the vendor offers or an encrypted mailbox.

Sources

Related answers

Which fax plan fits?Compare fax prices