Medcurity Get Compliance Help

Is Faxing HIPAA Compliant? Fax Security Requirements Explained

Quick Answer: Yes, faxing is HIPAA compliant when proper security controls are implemented. This includes using HIPAA-compliant fax machines (with encryption), verifying recipient fax numbers before transmission, maintaining fax logs, and securely storing/disposing of faxed documents. However, many healthcare organizations are moving away from fax due to security risks.

Can You Fax Protected Health Information (PHI)?

HIPAA doesn't prohibit faxing PHI, but it requires that faxing be done securely. The Privacy Rule mandates that covered entities implement "appropriate safeguards" for PHI transmission. When fax is used, you must ensure:

Core HIPAA Fax Requirements

Why Fax Remains a Compliance Challenge

Despite HIPAA-compliant implementations, fax poses inherent risks:

HIPAA Fax Compliance Checklist

Technical Requirements

  • Use modern fax machines with T.38 encryption or equivalent
  • Implement fax over IP (VoIP) with encryption protocols
  • Use secure fax services that encrypt in transit and at rest
  • Ensure fax machines have password protection to access sent/received files
  • Disable or secure memory storage on fax machines
  • Configure faxes to overwrite internal storage securely

Administrative Controls

  • Establish a written fax transmission policy
  • Require verification of recipient fax number (call ahead)
  • Maintain fax transmission logs (transmitter, date, time, recipient, content)
  • Implement fax cover sheets with confidentiality warnings
  • Train staff on proper fax procedures and misfax protocols
  • Limit fax use to necessary clinical communications

Physical & Operational Controls

  • Place fax machines in restricted, secure areas (not waiting rooms)
  • Limit access to fax machines to authorized personnel only
  • Implement regular fax machine audits
  • Require immediate pickup of received faxes (don't leave in tray)
  • Use shredding services or on-site shredders for fax disposal
  • Document all fax disposals with dates and responsible parties

Incident Response

  • Establish misfax notification procedures
  • Document all misfax incidents with details
  • Request return/destruction of misfaxed documents
  • Assess if misfax constitutes a reportable breach
  • Notify OCR if breach threshold is met (more than minimal risk)

Common Fax Compliance Mistakes

1. Not Verifying Fax Numbers

Misfaxing is the #1 cause of fax-related HIPAA breaches. Always call the recipient before sending to confirm the correct fax number. A single digit error can expose PHI to unauthorized parties.

2. Using Outdated Fax Machines

Older analog fax machines lack encryption. If you're still using 1990s-era equipment, you're not HIPAA compliant. Upgrade to modern fax systems with T.38 or cloud-based secure fax services.

3. Leaving Faxes in Open Trays

Received faxes left in the machine tray are accessible to anyone in the office. Implement "pull on demand" policies where staff retrieve their faxes immediately.

4. Not Maintaining Fax Logs

Auditors expect to see fax transmission logs. These should include sender, recipient number, date/time, and content summary. This is often overlooked but critical for compliance.

5. Improper Fax Disposal

Throwing faxes in regular trash violates HIPAA. Implement a secure document destruction program using cross-cut shredders or certified disposal services.

Important: The HHS Office for Civil Rights (OCR) has issued specific guidance on fax security. Many recent HIPAA settlements involved fax-related breaches, with penalties ranging from $10,000 to over $1 million for egregious cases.

Frequently Asked Questions

What's the difference between secure fax and regular fax?

Regular Fax (Analog/Older Digital): Transmits over standard phone lines without encryption. Vulnerable to interception.

Secure Fax (HIPAA-Compliant): Uses encrypted transmission (T.38 over VoIP), requires authentication, maintains audit logs, and often uses cloud-based delivery with secure portals. Examples include secure fax services like eFax Corporate, Citrix ShareFile, or hospital-grade fax systems.

Is email more secure than fax for HIPAA?

Not necessarily. Both require security measures:

  • Email: Requires end-to-end encryption (PGP, S/MIME) or secure portals. Standard email is NOT HIPAA compliant.
  • Fax: Requires encrypted fax services (T.38) or secure fax delivery platforms.

Many organizations are replacing fax with secure email or patient portals, which offer better audit trails and accessibility. However, secure fax remains acceptable if properly implemented.

What should I do if we misfax PHI to the wrong number?

Immediate steps:

  • Call the number immediately and inform them a fax was sent in error
  • Request they return or destroy the document
  • Document the incident: date, time, recipient, content, and actions taken
  • Assess if it's a reportable breach (generally low risk if recipient is healthcare-related)
  • If breach reporting required, notify affected patient within 60 days
  • Report to OCR if 500+ residents affected (check state AG requirements)

The key is immediate action and proper documentation. A single misfax, if handled appropriately, may not constitute a breach.

Can patients request fax instead of secure email?

Yes, patients can request their preferred method of delivery. However, you must ensure it's secure:

  • If patient requests fax, verify the fax number and implement safeguards
  • If patient requests email, you must use encrypted email or a secure patient portal
  • Document the patient's preference in the medical record
  • Still apply all security controls regardless of patient preference

Patient preference does not exempt you from HIPAA security requirements.

Are cloud-based secure fax services HIPAA compliant?

Yes, if they meet specific criteria:

  • Must have a signed Business Associate Agreement (BAA)
  • Must encrypt transmission (in transit and at rest)
  • Must provide audit logs and activity reports
  • Must comply with HIPAA's Security Rule (encryption, access controls, backups)
  • Examples: eFax Corporate, Citrix ShareFile, Kiteworks, Tresorit

Always verify the vendor has a HIPAA compliance statement and signed BAA before use.

Unsure If Your Fax Process Is HIPAA Compliant?

Medcurity conducts fax security audits and helps organizations transition from risky fax to secure modern alternatives. We'll review your fax policies, machines, and procedures to ensure compliance.

Schedule a Fax Security Audit