Skip to main content

Is Faxing Patient Records a HIPAA Violation? Your 2026 Guide to HIPAA Compliant Fax

Illustration of a fax machine printing a patient medical record with a green security check, asking if faxing patient records is a HIPAA violation.

Faxing is still everywhere in healthcare. Practices fax referrals, prescriptions, lab orders, and records dozens of times a day, often on equipment that has not changed in a decade. That routine raises a question every practice should be able to answer: is faxing patient records a HIPAA violation? The short answer: faxing protected health information (PHI) is allowed, but staying compliant depends entirely on how you fax and what safeguards surround it. Get it wrong and a single misdirected fax can become a reportable breach that one New York hospital settled for $387,200. Here is what a HIPAA compliant fax actually requires.

Is faxing patient records a HIPAA violation?

No, faxing itself is not a violation. The HIPAA Privacy Rule permits a provider to disclose PHI to another provider for treatment purposes, and it specifically allows this to happen by fax. The condition is in the same rule: you must have reasonable and appropriate administrative, technical, and physical safeguards in place to protect that information. HHS offers two plain examples, confirming that the receiving fax number is correct before you send, and placing the fax machine in a secure location where unauthorized people cannot read what comes through.

In other words, compliance is less about the machine and more about the process around it. A fax becomes a violation when safeguards fail, not because fax technology is banned.

Traditional fax vs. online fax: why the difference matters

How you fax changes which HIPAA rules apply. HHS has been clear that a classic paper-to-paper fax sent over a phone line is not considered electronic PHI, because the information did not exist in electronic form before or after the transmission. That kind of fax still falls under the Privacy Rule, but not the more technical Security Rule.

Modern faxing is different. Fax-to-email, cloud fax, and computer-based services create and store electronic PHI, so the HIPAA Security Rule applies in full. That is where many practices unknowingly fall out of compliance.

  • Traditional fax machine: Privacy Rule safeguards apply. Risk centers on wrong numbers, unattended machines, and paper left in trays.
  • Online or cloud fax: Privacy and Security Rules both apply. You now need encryption, access controls, and a signed agreement with your fax vendor.

What makes an online fax service HIPAA compliant

If your fax runs through email or the cloud, the vendor is handling PHI on your behalf, which makes them a business associate under HIPAA. That triggers a few non-negotiable requirements before you send a single patient record through a HIPAA compliant fax service.

  • A signed Business Associate Agreement (BAA): This is the single most important item. Without a BAA, the service is not compliant no matter how secure it claims to be. Free fax tiers almost never include one.
  • Encryption in transit and at rest: Compliant services encrypt data while it moves and while it is stored, so intercepted or stolen files stay unreadable.
  • Access controls and audit logs: Only authorized staff should reach inbound faxes, and the system should record who viewed or sent what.
  • Secure delivery: Faxes should land in a protected, monitored inbox, not a shared email account the whole office can open.

Popular services such as eFax can support HIPAA compliance, but only on the right paid plan, once you sign their BAA, and when the account is configured correctly. A default consumer setup is not enough.

The real risk is the misdirected fax

The most common fax breach is simple and preventable: the right document sent to the wrong number. In the St. Luke’s-Roosevelt Hospital case, a staff member faxed a patient’s highly sensitive records, including HIV status, to the patient’s employer instead of the requested address. The outcome was a $387,200 settlement with federal regulators and a corrective action plan.

A misdirected fax containing PHI can count as a breach and trigger notification obligations, so prevention beats cleanup. Practical safeguards include verifying numbers before sending, using saved contacts instead of hand-keyed digits, adding a confidentiality cover sheet, and training staff on what to do when a fax goes astray. The same discipline you apply to HIPAA compliant email and patient texting should extend to every fax you send. If you are unsure where your gaps are, a HIPAA risk assessment is the fastest way to find them.

How Atlantic Computer Systems helps

We help medical, dental, and behavioral health practices move from aging fax hardware to secure, documented workflows that hold up to an audit. As part of our managed IT services for healthcare and HIPAA compliance services, we set up compliant cloud fax with a signed BAA, restrict access to inbound documents, and make faxing one less worry.

Frequently asked questions

Is a regular fax machine HIPAA compliant?

It can be. A traditional fax machine falls under the HIPAA Privacy Rule, which allows faxing PHI as long as you use reasonable safeguards like confirming the number and keeping the machine in a secure spot. The risk comes from human error, not the device itself.

Do I need a BAA for an online fax service?

Yes. Any service that transmits or stores PHI on your behalf is a business associate, so you must have a signed Business Associate Agreement in place before you send patient information. Free fax tiers rarely offer one.

Is faxing medical records to the wrong number a HIPAA breach?

It can be. A misdirected fax containing PHI may qualify as a reportable breach and trigger notification requirements. That is why verifying numbers and keeping a written response plan are essential.

Is email or texting safer than faxing?

No channel is automatically safer. Each can be compliant with the right safeguards: encryption, access control, a BAA where a vendor is involved, and consistent staff training across email, texting, and fax.

Not sure whether your practice’s faxing, email, and messaging would survive an OCR review? Book a free IT and security consultation with Atlantic Computer Systems. We will review how your practice handles PHI and show you where to tighten up. Prefer to talk now? Call 1-650-300-7557.

Is your practice’s IT actually secure?

Book a free 30-minute IT & HIPAA security assessment with our team, no obligation, no jargon.

Book a Free Assessment

Related articles

Request a Quote

Fill out the form below and our team will get back to you within one business day.

Free IT & HIPAA security assessment