Quick answer
Quick answer
HHS permits covered healthcare providers to share patient information by fax for treatment when reasonable safeguards are used. That does not make every fax service or every send automatically HIPAA compliant. A covered entity should assess the complete workflow, confirm whether a Business Associate Agreement is required, verify the recipient, control access, document retention, and maintain an incident-response process.
What to get right
- HIPAA does not ban fax; HHS specifically recognizes fax for treatment communications with reasonable safeguards.
- A vendor's encryption or deletion claim is not a substitute for a risk analysis or a required Business Associate Agreement.
- Patients sending their own records and covered healthcare organizations do not have the same compliance obligations.
- A delivered event shows transmission to the receiving fax system, not staff review, correct chart filing, or legal compliance.
HIPAA permits faxing, but the workflow still matters
HHS says a physician may fax a medical record to another provider for treatment when reasonable safeguards protect the information from inappropriate use or disclosure. One example is confirming a fax number that is not regularly used before transmitting.
The permission to use fax is not a certification for a device, website, or process. Compliance depends on who is sending, why the information is disclosed, what vendors handle it, and which administrative, physical, and technical safeguards surround the send.
Separate a patient send from a covered-entity workflow
A patient sending a release form or a copy of personal records to a doctor is not automatically operating as a HIPAA covered entity. The provider receiving and using the records may have different obligations from the patient who initiated the fax.
A clinic, health plan, clearinghouse, or business associate should route PHI only through tools approved by its privacy and security program. Do not assume that a consumer-facing fax service is approved for workforce use simply because it uses HTTPS or mentions privacy.
Decide whether a Business Associate Agreement is required
HHS guidance says a covered entity or business associate that uses a cloud provider to create, receive, maintain, or transmit ePHI generally needs satisfactory assurances in a Business Associate Agreement. The agreement and risk analysis must match the actual service and data flow.
1Fax's public privacy policy describes HTTPS transmission to the service, private encrypted storage, document-content deletion within 30 minutes after delivery or final failure, and limited metadata retention. Those controls do not by themselves establish that a BAA exists or that the service is approved for a particular covered entity.
If your organization requires a BAA, confirm that a signed agreement covers the product, vendors, and intended use before uploading PHI. If it does not, use the system your compliance team has approved.
| Question | Evidence to obtain | Why it matters |
|---|---|---|
| Will the vendor handle ePHI for a covered entity? | Data-flow and vendor-role assessment | Determines whether business-associate obligations may apply. |
| Is a BAA required and available? | Signed agreement for the exact service | Marketing copy is not a contract. |
| Who can access files and status records? | Access-control and support-access documentation | Limits inappropriate internal access. |
| How long are content and metadata retained? | Written retention and deletion terms | The document and its metadata may have different lifecycles. |
| What happens after a misdirected fax? | Incident and breach-response process | Teams need a tested escalation path before an event occurs. |
Send when ready
Your final PDF can go straight from browser to fax.
No fax machine or monthly plan. Verify the number, review the page count, and keep the delivery status.
Use safeguards before, during, and after the send
Start with the recipient's official directory, referral sheet, or direct confirmation. Verify every digit and the attention line, especially for a number the organization does not use regularly. Send only the packet needed for the stated purpose and keep sensitive detail off the cover page unless routing requires it.
On a managed workstation, control who can open the source file, upload it, view the status link, and retain the confirmation. Printed pages, browser downloads, shared inboxes, and exported receipts all need policies too; the online fax tool is only one part of the path.
- Verify the destination through an official channel.
- Confirm the recipient, department, and attention line.
- Use the minimum routing detail needed on the cover page.
- Review every page for unrelated PHI and blank pages.
- Restrict access to the source file, status URL, and confirmation.
- Follow the organization's retention and disposal policy.
Interpret delivery evidence correctly
A delivered status is evidence that the receiving fax endpoint accepted the transmission. It does not prove that the intended person read it, that staff placed it in the right chart, or that every compliance requirement was satisfied.
Keep the fax ID, final status, timestamped event history, and the exact document version according to your policy. For time-sensitive clinical or administrative work, contact the recipient through its official channel to confirm routing without disclosing unnecessary information.
Prepare for misdirected or exposed faxes
A wrong number, unattended machine, exposed printout, or broadly shared status link can create an incident even when the transmission technology worked correctly. Your response plan should identify who receives the report, how the organization attempts mitigation, how the event is documented, and who decides whether notification is required.
Test the process before an incident. Staff should know how to stop further disclosure, preserve the relevant logs, contact privacy or legal leadership, and avoid making unsupported promises to the sender or patient.
- Maintain a current privacy and security contact list.
- Document the destination, content scope, time, and people involved.
- Preserve system events without spreading additional PHI.
- Follow the organization's breach-assessment procedure.
- Correct the number or workflow before attempting another send.
Research notes
Official sources used for this guide
Agency, healthcare, and provider instructions can change. Recheck the linked source and the document in front of you before transmitting.
- 01Treatment communications by fax under the HIPAA Privacy Rule (opens in a new tab)
U.S. Department of Health and Human Services
- 02Faxing patient information between physician offices (opens in a new tab)
U.S. Department of Health and Human Services
- 03HIPAA guidance for cloud services and Business Associate Agreements (opens in a new tab)
U.S. Department of Health and Human Services
- 04HIPAA business associate guidance (opens in a new tab)
U.S. Department of Health and Human Services
- 05
Common questions
Frequently asked questions
Is faxing medical information allowed under HIPAA?
Yes. HHS says covered providers may fax health information for treatment when reasonable safeguards are used. The complete workflow still has to meet the applicable privacy, security, and business-associate requirements.
Does using an online fax service make a fax HIPAA compliant?
No. Encryption, private storage, deletion, and event history can support a safeguard program, but no single feature makes a disclosure compliant. A covered entity must assess the vendor, legal role, BAA needs, access, purpose, recipient, retention, and incident process.
Does 1Fax sign a Business Associate Agreement?
Do not infer a BAA from this article or the public privacy policy. A covered entity that requires one should obtain written confirmation and a signed agreement for the exact service before transmitting PHI; otherwise it should use an approved alternative.
Does a delivered fax prove the doctor's office reviewed it?
No. Delivered means the receiving fax endpoint accepted the transmission. It does not prove staff review, chart filing, or action on the document.
In summary
Key takeaway
HIPAA-safe faxing is a systems problem: confirm the legal basis, vendor role, BAA needs, recipient, access, retention, and response plan before the document moves. Patients can use 1Fax for an occasional outbound fax to a verified doctor and benefit from short document retention and delivery status. Covered entities should use it for PHI only after their own privacy and security review confirms that the complete workflow and required agreements are in place.


