Quick answer

No fax service is "HIPAA compliant" on its own. HIPAA rules apply to health care providers, health plans, and their business associates, not to a product. HHS allows providers to fax health information with reasonable safeguards. A practice that uses an online fax service for patient data generally needs a business associate agreement with it.

You'll see "HIPAA compliant fax" on a lot of websites. This article explains what that phrase can and can't mean, using guidance from the U.S. Department of Health and Human Services (HHS), the agency that enforces HIPAA. It's general information, not legal advice.

Who does HIPAA actually apply to?

HIPAA's rules apply to two groups (HHS.gov):

  • Covered entities: health care providers (such as doctors, clinics, dentists, and pharmacies) that conduct certain transactions electronically, health plans, and health care clearinghouses.
  • Business associates: people or companies that create, receive, maintain, or transmit protected health information on behalf of a covered entity.

HHS states plainly: "If an entity does not meet the definition of a covered entity or business associate, it does not have to comply with the HIPAA Rules."

What does that mean for patients?

If you're a patient faxing your own records, a form, or a referral to your doctor, you're generally not a covered entity. HIPAA rules don't apply to you personally in that situation. That doesn't mean privacy doesn't matter, though. It's still your sensitive information, so you'll want to be careful (see the checklist below).

Does HIPAA allow faxing at all?

Yes. HHS says the HIPAA Privacy Rule permits a physician to share health information with another provider for treatment "by fax or by other means." Covered entities must have reasonable and appropriate safeguards in place. HHS gives examples such as confirming that the fax number is correct and keeping the fax machine in a secure location (HHS FAQ). So fax itself is allowed. The question is how it's done.

Why isn't any fax service "HIPAA certified"?

Because there's no official HIPAA certification for products. In its cloud computing guidance, HHS's Office for Civil Rights (OCR) says it "does not endorse, certify, or recommend specific technology or products" (HHS cloud guidance). When a company calls its service "HIPAA compliant," it usually means it offers features and contracts that help its customers meet their own HIPAA duties. Compliance depends on how the covered entity uses the service, plus its policies, training, and risk analysis.

Do medical practices need a business associate agreement for online fax?

Often, yes. According to HHS, when a covered entity uses a cloud service provider to create, receive, maintain, or transmit electronic protected health information on its behalf, that provider is a business associate. The two must sign a business associate agreement (BAA). HHS adds that a provider counts as a business associate even if it only stores encrypted data it can't read (HHS cloud guidance).

What is the "conduit exception"?

HHS describes a narrow exception for "transmission-only" services, like the postal service, that only store information temporarily as part of sending it. A service that stores data beyond that is a business associate, not a conduit (HHS cloud guidance). Whether a specific fax service falls under the exception depends on how it handles data, so practices should ask the vendor and their compliance advisor rather than assume.

What should I check before faxing health information?

Who you areWhat to check
Patient sending your own recordsIs there a patient portal instead? Is the fax number current and correct? Are you sending only what was requested?
Clinic, therapist, or small practiceDo you have a signed BAA with the fax provider? Does your risk analysis cover it? How long does the provider keep documents?
Business handling health data for a providerAre you a business associate yourself? What does your contract with the covered entity require?

A simple privacy checklist for any sensitive fax

  1. Ask about alternatives first. Many providers offer secure patient portals for uploads.
  2. Verify the number. Copy it from an official letter or website, or call to confirm. HHS lists this as a basic safeguard.
  3. Use a cover sheet with the recipient's name and a short confidentiality note.
  4. Send only what's needed. Don't include extra pages "just in case."
  5. Read the privacy policy of the fax service you choose.
  6. Confirm receipt for anything important. See How do I know my fax went through?

Can I use sendfaxfast.com for medical documents?

sendfaxfast.com is a simple online fax service for people who need to send a fax now and then. Single faxes need no account and no subscription. We don't make HIPAA compliance claims, and we don't want to oversell. Here's how to decide:

  • Patients faxing their own paperwork should check what their provider asks for, review our privacy policy, and decide whether they're comfortable.
  • Covered entities and business associates that need a BAA should check their requirements with their compliance officer before using any fax service, including ours.

How is health privacy handled in Canada, Australia, and New Zealand?

HIPAA is a US law. Other countries have their own rules:

  • Canada: The Personal Information Protection and Electronic Documents Act (PIPEDA) sets privacy rules for private-sector businesses. Which law applies can depend on your province and the type of organization, and the Office of the Privacy Commissioner offers a "Which privacy law applies?" tool (OPC).
  • Australia: According to the OAIC, "Australian privacy law has strict rules about how a health service provider can collect, use and disclose your health information" (OAIC).
  • New Zealand: The Health Information Privacy Code 2020 covers health information that health agencies collect, use, hold, and disclose (Privacy Commissioner NZ).

Wherever you are, the practical advice is the same: verify the number, send only what's needed, and follow the recipient's instructions.

Frequently asked questions

Is faxing medical records legal under HIPAA?

Yes. HHS says providers may share health information for treatment by fax, as long as they use reasonable safeguards, such as confirming the fax number.

Is there an official list of HIPAA-compliant fax services?

No. HHS's Office for Civil Rights does not endorse, certify, or recommend specific technology or products.

Do I need a BAA to fax my own medical records as a patient?

Generally, no. BAAs are contracts between covered entities (or business associates) and their service providers. As a patient sending your own records, you're usually not a covered entity.

Is fax more secure than email?

It depends on the setup on both ends. A fax sent to the wrong number, or left on a shared machine, can expose information too. Use the safeguards in the checklist above, whatever method you choose.

Is sendfaxfast.com HIPAA compliant?

We don't make HIPAA compliance claims. If you're a covered entity or business associate, check your requirements, including whether you need a BAA, before sending protected health information through any service.

This article is general information, not legal advice. For your specific situation, talk to a qualified compliance professional or attorney.