Hipaa compliant fax: Fax Compliance Rules
The Fax Compliance Rules carries 2 published figures read from 2 sources' own pages, from 30 to 60 day, read 15 September 2026.
- Median of the published figures
- 45 day
- Range
- 30 to 60 day
- Sources with a figure
- 2
- Sources read that publish one
- 2 of 15
2 of the 15 named sources read in full publish a figure; 13 publish none, read 15 September 2026.
Every figure, with its source
One row per source: the figure the source's own page publishes, the page, and the day it was read. A figure that is not on a page we read is not on this one.
| Source | Figure | Read |
|---|---|---|
| HHS: the Breach Notification Rule | 60 day | 2026-09-12 |
| HHS: the Breach Notification Rule | 60 day | 2026-09-12 |
| HHS: the Breach Notification Rule | 60 day | 2026-09-12 |
| HHS: the Breach Notification Rule | 60 day | 2026-09-12 |
| eCFR 47 CFR 64.1200 junk fax rules | 30 day | 2026-09-12 |
| eCFR 47 CFR 64.1200 junk fax rules | 30 day | 2026-09-12 |
The sentence each figure was read from (6)
- HHS: the Breach Notification Rule, read 2026-09-12:
Like individual notice, this media notification must be provided without unreasonable delay and in no case later than 60 days following the discovery of a breach and must include the same information required for the individual notice.
- HHS: the Breach Notification Rule, read 2026-09-12:
If a breach affects 500 or more individuals, covered entities must notify the Secretary without unreasonable delay and in no case later than 60 days following a breach.
- HHS: the Breach Notification Rule, read 2026-09-12:
Reports of breaches affecting fewer than 500 individuals are due to the Secretary no later than 60 days after the end of the calendar year in which the breaches are discovered.
- HHS: the Breach Notification Rule, read 2026-09-12:
A business associate must provide notice to the covered entity without unreasonable delay and no later than 60 days from the discovery of the breach.
- eCFR 47 CFR 64.1200 junk fax rules, read 2026-09-12:
(B) The notice states that the recipient may make a request to the sender of the advertisement not to send any future advertisements to a telephone facsimile machine or machines and that failure to comply, within 30 days, with such a request meeting the requirements under paragraph (a)(4)(v) of this section is unlawful;
- eCFR 47 CFR 64.1200 junk fax rules, read 2026-09-12:
(3) When notified by the Commission through its Enforcement Bureau that a Final Determination Order has been issued finding that an upstream provider has failed to comply with paragraph (n)(2) of this section, block and cease accepting all traffic received directly from the upstream provider beginning 30 days after the release date of the Final Determination Order.
Read in full, publishes no figure
13 named sources were read in full on the dates shown and print no usable figure. They are counted, never filled in.
- HHS: the HIPAA Security Rule, read 2026-09-11: read in full and no accepted figure on the page
- HHS: Security Rule guidance material, read 2026-09-11: every candidate on the page was refused
- HHS: business associates, read 2026-09-12: read in full and no accepted figure on the page
- HHS: sample business associate agreement provisions, read 2026-09-12: read in full and no accepted figure on the page
- HHS: the minimum necessary requirement, read 2026-09-12: read in full and no accepted figure on the page
- eCFR 45 CFR 164.312 technical safeguards, read 2026-09-12: read in full and no accepted figure on the page
- eCFR 45 CFR 164.502 uses and disclosures, read 2026-09-12: read in full and no accepted figure on the page
- eCFR 45 CFR 164.504 organizational requirements, read 2026-09-11: read in full and no accepted figure on the page
- eCFR 45 CFR 164.530 administrative requirements, read 2026-09-12: read in full and no accepted figure on the page
- eCFR 45 CFR 164.402 breach defined, read 2026-09-12: read in full and no accepted figure on the page
- NIST SP 800-66r2 implementing the HIPAA Security Rule, read 2026-09-12: read in full and no accepted figure on the page
- NHS England: removal of fax machines from general practice, read 2026-09-12: read in full and no accepted figure on the page
- hhs.gov, read 2026-09-11: read in full and no accepted figure on the page
Methodology
Every row is a verbatim sentence read from the named source's own page through the estate's fetch service on the date shown, hash-pinned to the stored read (the sha of the page's visible text; the raw page is mirrored to R2).
2 of the 15 named sources that could be read published a usable figure; 13 published none and are recorded as not published, never filled in; 0 could not be read (blocked, dead or unreachable) and count nowhere.
The headline figures (median, minimum, maximum, quartiles) are over ONE figure per source in day (a source's median where its page yielded several accepted sentences), so N counts sources, never sentences; 15 candidate sentence(s) were refused by a reviewer with the reason recorded.
Derivation as chartered: one row per rule per regime, quoted verbatim from the authority with its citation and effective date (the Security Rule's transmission-security standard, the BAA provisions at 45 CFR 164.504(e), the six-year retention at 164.530(j), the breach test at 164.402, the opt-out notice at 47 CFR 64.1200), joined to a column that records, per vendor in the price index, whether the vendor's own page says it signs a BAA and at which plan - so the page answers 'is this service HIPAA compliant' with the rule and the vendor's own claim side by side, never with a badge
15 candidate sentences on these pages were refused by a reviewer; each refusal and its reason is recorded in the review ledger.
Sources (15)
- HHS: the HIPAA Security Rule (the publisher's own terms; quoted for reporting and comment)
- HHS: Security Rule guidance material (the publisher's own terms; quoted for reporting and comment)
- HHS: business associates (the publisher's own terms; quoted for reporting and comment)
- HHS: sample business associate agreement provisions (the publisher's own terms; quoted for reporting and comment)
- HHS: the minimum necessary requirement (the publisher's own terms; quoted for reporting and comment)
- HHS: the Breach Notification Rule (the publisher's own terms; quoted for reporting and comment)
- eCFR 45 CFR 164.312 technical safeguards (the publisher's own terms; quoted for reporting and comment)
- eCFR 45 CFR 164.502 uses and disclosures (the publisher's own terms; quoted for reporting and comment)
- eCFR 45 CFR 164.504 organizational requirements (the publisher's own terms; quoted for reporting and comment)
- eCFR 45 CFR 164.530 administrative requirements (the publisher's own terms; quoted for reporting and comment)
- eCFR 45 CFR 164.402 breach defined (the publisher's own terms; quoted for reporting and comment)
- eCFR 47 CFR 64.1200 junk fax rules (the publisher's own terms; quoted for reporting and comment)
- NIST SP 800-66r2 implementing the HIPAA Security Rule (the publisher's own terms; quoted for reporting and comment)
- NHS England: removal of fax machines from general practice (the publisher's own terms; quoted for reporting and comment)
- hhs.gov (the publisher's own terms; quoted for reporting and comment)
Cite or embed this figure
Cite or embed this figure
The Fax Compliance Rules carries 2 published figures read from 2 sources' own pages, from 30 to 60 day, read 15 September 2026.
2 of the 15 named sources read in full publish a figure; 13 publish none, read 15 September 2026.
Cite as: "Fax Line Index Fax Compliance Rules", updated 2026-09-15, https://faxlineindex.com/datasets/fax-compliance-rules/.
Download the CSV (6 rows, computed 2026-09-15)