{
 "name": "Fax Line Index Fax Compliance Rules",
 "title": "Fax Compliance Rules",
 "url": "https://faxlineindex.com/datasets/fax-compliance-rules/",
 "csv": "https://faxlineindex.com/datasets/fax-compliance-rules.csv",
 "markdown": "https://faxlineindex.com/datasets/fax-compliance-rules/index.md",
 "computed_at": "2026-09-15",
 "license": "https://faxlineindex.com/terms",
 "headline": "The Fax Compliance Rules carries 2 published figures read from 2 sources' own pages, from 30 to 60 day, read 15 September 2026.",
 "quotes": [
  "The Fax Compliance Rules carries 2 published figures read from 2 sources' own pages, from 30 to 60 day, read 15 September 2026.",
  "2 of the 15 named sources read in full publish a figure; 13 publish none, read 15 September 2026."
 ],
 "citation": "\"Fax Line Index Fax Compliance Rules\", updated 2026-09-15, https://faxlineindex.com/datasets/fax-compliance-rules/.",
 "changed_since": null,
 "national": {
  "unit": "day",
  "n": 2,
  "median": 45,
  "min": 30,
  "max": 60,
  "p25": 22.5,
  "p75": 67.5,
  "mean": 45,
  "units": {
   "day": 2
  },
  "published_sources": 2,
  "named_sources": 15,
  "read_sources": 15,
  "not_published": 13,
  "published_share": 0.133
 },
 "by_axis": {},
 "rows": [
  {
   "source": "HHS: the Breach Notification Rule",
   "url": "https://www.hhs.gov/hipaa/for-professionals/breach-notification/index.html",
   "figure": "60 days",
   "value": 60,
   "unit": "day",
   "axis": {},
   "retrieved_at": "2026-09-12",
   "quote": "Like individual notice, this media notification must be provided without unreasonable delay and in no case later than 60 days following the discovery of a breach and must include the same information required for the individual notice.",
   "source_class": "primary-government",
   "text_sha256": "3eef4d61280cb31a61b5f3018dbc2758625b7c17c12307456b373ace1a12a7a4"
  },
  {
   "source": "HHS: the Breach Notification Rule",
   "url": "https://www.hhs.gov/hipaa/for-professionals/breach-notification/index.html",
   "figure": "60 days",
   "value": 60,
   "unit": "day",
   "axis": {},
   "retrieved_at": "2026-09-12",
   "quote": "If a breach affects 500 or more individuals, covered entities must notify the Secretary without unreasonable delay and in no case later than 60 days following a breach.",
   "source_class": "primary-government",
   "text_sha256": "3eef4d61280cb31a61b5f3018dbc2758625b7c17c12307456b373ace1a12a7a4"
  },
  {
   "source": "HHS: the Breach Notification Rule",
   "url": "https://www.hhs.gov/hipaa/for-professionals/breach-notification/index.html",
   "figure": "60 days",
   "value": 60,
   "unit": "day",
   "axis": {},
   "retrieved_at": "2026-09-12",
   "quote": "Reports of breaches affecting fewer than 500 individuals are due to the Secretary no later than 60 days after the end of the calendar year in which the breaches are discovered.",
   "source_class": "primary-government",
   "text_sha256": "3eef4d61280cb31a61b5f3018dbc2758625b7c17c12307456b373ace1a12a7a4"
  },
  {
   "source": "HHS: the Breach Notification Rule",
   "url": "https://www.hhs.gov/hipaa/for-professionals/breach-notification/index.html",
   "figure": "60 days",
   "value": 60,
   "unit": "day",
   "axis": {},
   "retrieved_at": "2026-09-12",
   "quote": "A business associate must provide notice to the covered entity without unreasonable delay and no later than 60 days from the discovery of the breach.",
   "source_class": "primary-government",
   "text_sha256": "3eef4d61280cb31a61b5f3018dbc2758625b7c17c12307456b373ace1a12a7a4"
  },
  {
   "source": "eCFR 47 CFR 64.1200 junk fax rules",
   "url": "https://www.ecfr.gov/current/title-47/chapter-I/subchapter-B/part-64/subpart-L/section-64.1200",
   "figure": "30 days",
   "value": 30,
   "unit": "day",
   "axis": {},
   "retrieved_at": "2026-09-12",
   "quote": "(B) The notice states that the recipient may make a request to the sender of the advertisement not to send any future advertisements to a telephone facsimile machine or machines and that failure to comply, within 30 days, with such a request meeting the requirements under paragraph (a)(4)(v) of this section is unlawful;",
   "source_class": "primary-government",
   "text_sha256": "5a5435725d1f27ef115f758f9a25f69c80dd09e41075023eb6dabcd5f9a60909"
  },
  {
   "source": "eCFR 47 CFR 64.1200 junk fax rules",
   "url": "https://www.ecfr.gov/current/title-47/chapter-I/subchapter-B/part-64/subpart-L/section-64.1200",
   "figure": "30 days",
   "value": 30,
   "unit": "day",
   "axis": {},
   "retrieved_at": "2026-09-12",
   "quote": "(3) When notified by the Commission through its Enforcement Bureau that a Final Determination Order has been issued finding that an upstream provider has failed to comply with paragraph (n)(2) of this section, block and cease accepting all traffic received directly from the upstream provider beginning 30 days after the release date of the Final Determination Order.",
   "source_class": "primary-government",
   "text_sha256": "5a5435725d1f27ef115f758f9a25f69c80dd09e41075023eb6dabcd5f9a60909"
  }
 ],
 "not_published": [
  {
   "source": "HHS: the HIPAA Security Rule",
   "url": "https://www.hhs.gov/hipaa/for-professionals/security/laws-regulations/index.html",
   "retrieved_at": "2026-09-11",
   "reason": "read in full and no accepted figure on the page"
  },
  {
   "source": "HHS: Security Rule guidance material",
   "url": "https://www.hhs.gov/hipaa/for-professionals/security/guidance/index.html",
   "retrieved_at": "2026-09-11",
   "reason": "every candidate on the page was refused"
  },
  {
   "source": "HHS: business associates",
   "url": "https://www.hhs.gov/hipaa/for-professionals/privacy/guidance/business-associates/index.html",
   "retrieved_at": "2026-09-12",
   "reason": "read in full and no accepted figure on the page"
  },
  {
   "source": "HHS: sample business associate agreement provisions",
   "url": "https://www.hhs.gov/hipaa/for-professionals/covered-entities/sample-business-associate-agreement-provisions/index.html",
   "retrieved_at": "2026-09-12",
   "reason": "read in full and no accepted figure on the page"
  },
  {
   "source": "HHS: the minimum necessary requirement",
   "url": "https://www.hhs.gov/hipaa/for-professionals/privacy/guidance/minimum-necessary-requirement/index.html",
   "retrieved_at": "2026-09-12",
   "reason": "read in full and no accepted figure on the page"
  },
  {
   "source": "eCFR 45 CFR 164.312 technical safeguards",
   "url": "https://www.ecfr.gov/current/title-45/subtitle-A/subchapter-C/part-164/subpart-C/section-164.312",
   "retrieved_at": "2026-09-12",
   "reason": "read in full and no accepted figure on the page"
  },
  {
   "source": "eCFR 45 CFR 164.502 uses and disclosures",
   "url": "https://www.ecfr.gov/current/title-45/subtitle-A/subchapter-C/part-164/subpart-E/section-164.502",
   "retrieved_at": "2026-09-12",
   "reason": "read in full and no accepted figure on the page"
  },
  {
   "source": "eCFR 45 CFR 164.504 organizational requirements",
   "url": "https://www.ecfr.gov/current/title-45/subtitle-A/subchapter-C/part-164/subpart-E/section-164.504",
   "retrieved_at": "2026-09-11",
   "reason": "read in full and no accepted figure on the page"
  },
  {
   "source": "eCFR 45 CFR 164.530 administrative requirements",
   "url": "https://www.ecfr.gov/current/title-45/subtitle-A/subchapter-C/part-164/subpart-E/section-164.530",
   "retrieved_at": "2026-09-12",
   "reason": "read in full and no accepted figure on the page"
  },
  {
   "source": "eCFR 45 CFR 164.402 breach defined",
   "url": "https://www.ecfr.gov/current/title-45/subtitle-A/subchapter-C/part-164/subpart-D/section-164.402",
   "retrieved_at": "2026-09-12",
   "reason": "read in full and no accepted figure on the page"
  },
  {
   "source": "NIST SP 800-66r2 implementing the HIPAA Security Rule",
   "url": "https://csrc.nist.gov/pubs/sp/800/66/r2/final",
   "retrieved_at": "2026-09-12",
   "reason": "read in full and no accepted figure on the page"
  },
  {
   "source": "NHS England: removal of fax machines from general practice",
   "url": "https://www.england.nhs.uk/publication/practice-guidance-removal-of-facsimile-fax-machines-from-general-practice/",
   "retrieved_at": "2026-09-12",
   "reason": "read in full and no accepted figure on the page"
  },
  {
   "source": "hhs.gov",
   "url": "https://www.hhs.gov/hipaa/for-professionals/security/laws-regulations/index.html",
   "retrieved_at": "2026-09-11",
   "reason": "read in full and no accepted figure on the page"
  }
 ],
 "sources": [
  {
   "url": "https://www.hhs.gov/hipaa/for-professionals/security/laws-regulations/index.html",
   "label": "HHS: the HIPAA Security Rule",
   "license": "the publisher's own terms; quoted for reporting and comment"
  },
  {
   "url": "https://www.hhs.gov/hipaa/for-professionals/security/guidance/index.html",
   "label": "HHS: Security Rule guidance material",
   "license": "the publisher's own terms; quoted for reporting and comment"
  },
  {
   "url": "https://www.hhs.gov/hipaa/for-professionals/privacy/guidance/business-associates/index.html",
   "label": "HHS: business associates",
   "license": "the publisher's own terms; quoted for reporting and comment"
  },
  {
   "url": "https://www.hhs.gov/hipaa/for-professionals/covered-entities/sample-business-associate-agreement-provisions/index.html",
   "label": "HHS: sample business associate agreement provisions",
   "license": "the publisher's own terms; quoted for reporting and comment"
  },
  {
   "url": "https://www.hhs.gov/hipaa/for-professionals/privacy/guidance/minimum-necessary-requirement/index.html",
   "label": "HHS: the minimum necessary requirement",
   "license": "the publisher's own terms; quoted for reporting and comment"
  },
  {
   "url": "https://www.hhs.gov/hipaa/for-professionals/breach-notification/index.html",
   "label": "HHS: the Breach Notification Rule",
   "license": "the publisher's own terms; quoted for reporting and comment"
  },
  {
   "url": "https://www.ecfr.gov/current/title-45/subtitle-A/subchapter-C/part-164/subpart-C/section-164.312",
   "label": "eCFR 45 CFR 164.312 technical safeguards",
   "license": "the publisher's own terms; quoted for reporting and comment"
  },
  {
   "url": "https://www.ecfr.gov/current/title-45/subtitle-A/subchapter-C/part-164/subpart-E/section-164.502",
   "label": "eCFR 45 CFR 164.502 uses and disclosures",
   "license": "the publisher's own terms; quoted for reporting and comment"
  },
  {
   "url": "https://www.ecfr.gov/current/title-45/subtitle-A/subchapter-C/part-164/subpart-E/section-164.504",
   "label": "eCFR 45 CFR 164.504 organizational requirements",
   "license": "the publisher's own terms; quoted for reporting and comment"
  },
  {
   "url": "https://www.ecfr.gov/current/title-45/subtitle-A/subchapter-C/part-164/subpart-E/section-164.530",
   "label": "eCFR 45 CFR 164.530 administrative requirements",
   "license": "the publisher's own terms; quoted for reporting and comment"
  },
  {
   "url": "https://www.ecfr.gov/current/title-45/subtitle-A/subchapter-C/part-164/subpart-D/section-164.402",
   "label": "eCFR 45 CFR 164.402 breach defined",
   "license": "the publisher's own terms; quoted for reporting and comment"
  },
  {
   "url": "https://www.ecfr.gov/current/title-47/chapter-I/subchapter-B/part-64/subpart-L/section-64.1200",
   "label": "eCFR 47 CFR 64.1200 junk fax rules",
   "license": "the publisher's own terms; quoted for reporting and comment"
  },
  {
   "url": "https://csrc.nist.gov/pubs/sp/800/66/r2/final",
   "label": "NIST SP 800-66r2 implementing the HIPAA Security Rule",
   "license": "the publisher's own terms; quoted for reporting and comment"
  },
  {
   "url": "https://www.england.nhs.uk/publication/practice-guidance-removal-of-facsimile-fax-machines-from-general-practice/",
   "label": "NHS England: removal of fax machines from general practice",
   "license": "the publisher's own terms; quoted for reporting and comment"
  },
  {
   "url": "https://www.hhs.gov/hipaa/for-professionals/security/laws-regulations/index.html",
   "label": "hhs.gov",
   "license": "the publisher's own terms; quoted for reporting and comment"
  }
 ],
 "methodology": "Every row is a verbatim sentence read from the named source's own page through the estate's fetch service on the date shown, hash-pinned to the stored read (the sha of the page's visible text; the raw page is mirrored to R2). 2 of the 15 named sources that could be read published a usable figure; 13 published none and are recorded as not published, never filled in; 0 could not be read (blocked, dead or unreachable) and count nowhere. The headline figures (median, minimum, maximum, quartiles) are over ONE figure per source in day (a source's median where its page yielded several accepted sentences), so N counts sources, never sentences; 15 candidate sentence(s) were refused by a reviewer with the reason recorded. Derivation as chartered: one row per rule per regime, quoted verbatim from the authority with its citation and effective date (the Security Rule's transmission-security standard, the BAA provisions at 45 CFR 164.504(e), the six-year retention at 164.530(j), the breach test at 164.402, the opt-out notice at 47 CFR 64.1200), joined to a column that records, per vendor in the price index, whether the vendor's own page says it signs a BAA and at which plan - so the page answers 'is this service HIPAA compliant' with the rule and the vendor's own claim side by side, never with a badge",
 "embed": "<figure style=\"margin:0;padding:16px;border:1px solid #d9d9d9;border-radius:8px;background:#ffffff;color:#111111;font-family:system-ui,sans-serif;max-width:480px\"><p style=\"margin:0 0 8px;font-size:28px;font-weight:700;color:#111111;background:#ffffff\">30 to 60 day</p><p style=\"margin:0 0 8px;font-size:14px;color:#111111;background:#ffffff\">2 published figures, Fax Compliance Rules, across 2 sources, read 15 September 2026</p><figcaption style=\"font-size:12px;color:#444444;background:#ffffff\"><a href=\"https://faxlineindex.com/datasets/fax-compliance-rules/#median\" style=\"color:#1a4fd6;background:#ffffff\">Source: Fax Line Index Fax Compliance Rules</a></figcaption></figure>"
}
