Faxing Protected Health Information (PHI)
Despite the rapid adoption of electronic health records (EHRs) and secure messaging platforms, fax remains a common method for transferring patient data between hospitals, clinics, labs, and insurance companies. Many legacy systems only accept faxed documents, and some providers rely on the familiarity and perceived simplicity of the technology.
Because PHI is highly sensitive, every fax transmission must comply with the privacy and security rules of the Health Insurance Portability and Accountability Act (HIPAA) and any applicable state regulations.
HIPAA Privacy Rule: Requires covered entities and business associates to safeguard PHI during any transmission, including fax. The rule does not forbid faxing, but it mandates reasonable safeguards.
HIPAA Security Rule: Applies to electronic PHI (ePHI) and includes technical, physical, and administrative safeguards. Faxing is considered an electronic transmission, so the Security Rules requirements apply.
HITECH Act: Strengthens enforcement and expands breach notification requirements, meaning a faxrelated breach can trigger costly reporting obligations.
State Laws: Some states impose stricter privacy protections. Always verify local regulations before establishing a fax workflow.
Maintain an uptodate directory of authorized fax numbers. Use a doublecheck process: confirm the number verbally or through a secure portal before sending.
Consider a cloudbased or onpremises fax server that offers:
Before scanning or printing, redact any data not essential to the recipients purpose. Use redaction tools that permanently remove information.
If using a traditional analog fax machine:
Conduct quarterly training covering:
Review fax logs monthly for unusual activity, such as:
Investigate any anomalies promptly.
Mitigation: Implement a verification step in the workflow and use fax cover sheets that clearly label the intended recipient and content.
Mitigation: Transition to internetbased fax services that encrypt data over the network. If analog fax must be used, limit exposure by keeping the line dedicated to trusted parties only.
Mitigation: Store incoming faxes in a locked, accesscontrolled inboxeither a physical tray with restricted access or a secure electronic repository.
Mitigation: Use fax solutions that automatically retain logs for at least six years (the standard HIPAA retention period) and back them up securely.
Simple to use but lack encryption and detailed auditing. Suitable only when a secure, dedicated line is available and strict administrative controls are enforced.
Convert analog fax to digital packets that travel over the internet. When paired with TLS, they provide strong encryption and can integrate with EHRs for automated routing.
Examples include eFax Corporate, SRFax, and FaxLogic. Benefits:
Combine a physical fax machine for legacy needs with a secure fax server that captures each transmission digitally for archiving and audit purposes.
In the event a fax containing PHI is sent to an unauthorized party, follow these steps:
-------------------------------------------------------------- CONFIDENTIAL PROTECTED HEALTH INFORMATION--------------------------------------------------------------To: __________________________ Fax #: ______________________From: ________________________ Department: __________________Date: _________________________ Confidentiality Notice:Subject: ______________________ This fax contains PHI and is intended solely for the use of the individual(s) named above. If you are not the intended recipient, please destroy this fax and notify the sender immediately.--------------------------------------------------------------
Using a standard cover sheet reinforces the privacy notice and helps the recipient handle the fax correctly.
2026 Healthcare Compliance Resources. All rights reserved.
