HIPAA does not ban faxing protected health information and never has; fax between covered entities has always been a permitted transmission, which is why healthcare still faxes. What the rules require is that the safeguards around the fax are reasonable: the service that stores and sends it on your behalf signs a business associate agreement, the recipient's number is verified so the record does not land on a stranger's machine, the cover carries a confidentiality notice, and the transmission is logged so it can be shown. The Fax Line Index records which vendors' pricing pages state HIPAA compliance with a BAA on the plan priced, and what those plans cost.
The business associate agreement
An online fax service that handles protected health information for a covered entity is a business associate and must sign a BAA binding it to safeguard the data. The vendor's willingness to sign one for the plan you are buying is the first requirement, and the pricing pages differ on it: WestFax prints a signed BAA on every plan including Solo at $14.99 a month; eFax prints HIPAA compliance with a Business Associate Agreement on its Business plan card; Documo prints HIPAA compliance as included on Solo at $25 a month billed annually and on Business. Six other vendors in the catalog do not state it on the pricing page, which is not a finding that they will not sign one, but a plan bought without the agreement in hand is a plan bought on a promise.
The sender's own safeguards
The BAA covers the provider. The covered entity's own policies cover the rest, and the usual ones are: verify the recipient's fax number before sending, and keep a list of confirmed numbers for regular recipients; put a confidentiality notice on the cover sheet stating that the fax is intended for the named recipient and that anyone else must notify the sender and destroy it; and keep the transmission report, which online services store with the sent fax. The cover sheet guide on this site sets out the fields; the notice's wording is your compliance officer's, not the vendor's.
What compliant does not mean
It does not mean the fax is protected once it prints at the other end: a fax to a paper machine in a busy office is that office's problem, and a call to confirm receipt is the usual answer. It does not mean the vendor has audited your workflow. And it does not mean a free service: none of the free or per-fax options in the catalog states HIPAA, and FaxZero, which sends free up to three pages, provides no agreement and no number. The requirements are met by the service's BAA plus your own three safeguards, and the price index shows what the services that state the first one charge.
Questions people ask about hipaa fax requirements
Is faxing HIPAA compliant?
Faxing protected health information is permitted under HIPAA when reasonable safeguards are in place: a BAA with any service that handles the fax, a verified recipient number, a confidentiality notice on the cover and a kept transmission log.
Do I need a BAA with my fax service?
Yes, if the service stores or sends protected health information on your behalf. WestFax, eFax (Business) and Documo state one on their pricing pages; confirm it covers the plan you buy.
Does HIPAA require a fax cover sheet?
HIPAA does not prescribe the wording, but a covered entity's policies almost always require a confidentiality notice on the cover and a check of the recipient's number.