Faxing in 2026: e-fax with a BAA, and why fax persists
Summary
E-fax can be HIPAA compliant, but the fax service itself has to be — a signed business associate agreement, encrypted transmission and storage, and access controls on who can view an incoming fax, the same requirements as any other vendor touching PHI. A consumer fax app with no BAA option isn't compliant regardless of how it markets itself. Fax persists in 2026 because it remains the lowest common denominator between systems that still can't exchange records electronically.
By Gale Editorial · Updated 2026-07-27. Every figure cited to a dated source. How we write.
Is e-fax HIPAA compliant?
E-fax is HIPAA compliant when the service is covered by a signed business associate agreement, transmits and stores documents encrypted, and restricts who can view an incoming fax — it is not compliant simply because it replaced a physical machine with an app. Any vendor that creates, receives, maintains, or transmits PHI on a practice's behalf is a business associate requiring a BAA, and an e-fax provider fits that definition exactly 1Ref 1HHS Office for Civil Rights (2026).Business Associates.That any vendor creating, receiving, maintaining, or transmitting PHI on the practice's behalf — including an e-fax service — is a business associate requiring a signed BAA..
The short version for a solo clinician evaluating a service: ask for the BAA before asking about price or features. A provider unwilling to sign one, or that treats faxing as outside its BAA's scope, isn't a compliant option no matter how the product is marketed.
What actually makes a fax service compliant
A compliant e-fax setup rests on the same Security Rule safeguards as any other system touching ePHI: encryption of documents in transit and at rest, access controls limiting who can open an incoming fax, and an audit trail of who sent or received what and when — safeguards scaled to practice size, not a fixed brand-name checklist 2Ref 2HHS Office for Civil Rights (2026).Summary of the HIPAA Security Rule.That the Security Rule requires administrative, physical, and technical safeguards for ePHI, scalable to practice size, applying once a fax becomes a stored digital file.. A traditional analog fax line sent over the telephone network is generally treated as a permitted transmission method under the Security Rule's own analysis, but the moment a fax becomes a stored digital file — a PDF sitting in an inbox, an app, or a cloud folder — the same encryption-at-rest and BAA requirements apply as they would to any other stored ePHI.
That distinction is the actual compliance question, more than the word "fax" itself: a physical machine printing a paper fax into a locked room is a different risk profile than an app storing incoming faxes as unencrypted email attachments, even though both get called "fax."
Why fax persists in 2026
Fax survives because it remains the one document-exchange method every EHR, hospital system, and referring office can reliably send and receive, regardless of which platform is on the other end — a floor that electronic exchange initiatives are still working to replace rather than something already solved. TEFCA establishes a national framework for network-to-network health information exchange through Qualified Health Information Networks, but it connects participating networks to each other, not every fax machine and legacy system still in use across referring practices, labs, and hospitals 3Ref 3Office of the National Coordinator / ASTP (2026).TEFCA — Office of the National Coordinator for Health Information Technology.That TEFCA establishes a national floor for network-to-network health information exchange via QHINs, connecting participating networks rather than every legacy fax-dependent system..
Until that gap closes, a referral, a records request, or a prior-authorization packet often moves faster and more reliably by fax than by chasing down a portal login or a secure-email address the other office may not actually check. A solo clinician who drops fax entirely before every referral partner has a working electronic alternative risks losing referrals that simply can't reach the practice any other way.
Traditional fax line vs. e-fax: what actually changes
Switching from a physical fax machine to an e-fax service changes where the document lands — a digital inbox instead of a paper tray — and that shift is exactly what introduces the BAA and encryption requirements a paper fax line mostly avoids. A physical fax machine's main compliance exposure is the paper itself sitting in an open tray where anyone walking past can read it; an e-fax service's exposure is a stored digital file that needs the same device setup discipline as the rest of the practice's technology, including encryption and controlled access on whatever device the fax app runs on.
Many solo clinicians run their e-fax service through the same phone used for practice email and scheduling — and your phone is a HIPAA device the moment it holds an incoming fax containing PHI, needing the same passcode and encryption standard as any other device carrying patient information.
Setting up e-fax safely
A safe e-fax setup starts with the BAA, then adds a confirmation log for anything time-sensitive (a prior-authorization deadline, a records request with its own clock), automatic deletion or archiving of faxes after they're filed into the chart, and a cover sheet that states the fax may contain confidential health information without naming the patient on the cover page itself. Routing incoming faxes to auto-file into the EHR removes the step where a fax otherwise sits as a loose PDF in an inbox waiting to be filed, which is where most fax-related exposure actually happens.
A fax number, unlike a phone number, is fine to publish on referral materials and the practice website — the restriction on phone numbers in provider-facing content doesn't extend to a fax line, since a fax number isn't a route to a live conversation.
When fax isn't the right channel
Fax is well suited to document exchange with a referral partner but poorly suited to anything needing two-way interaction — a telehealth visit, a scheduling conversation, a benefits verification call — where a proper telehealth platform or a phone line does the job fax was never built for. Telehealth platforms carry their own BAA and configuration requirements distinct from a fax service, and treating the two as interchangeable "secure communication" tools is a common setup mistake for a solo clinician trying to consolidate vendors.
Worth keeping in mind for the practice's disaster planning too: fax is often the fallback channel that still works when an EHR or internet connection goes down, which is one reason it belongs in the contingency plan even for a practice that otherwise runs almost entirely digital.
Tying it to the risk analysis
Adding or changing a fax service — physical or e-fax — is exactly the kind of vendor change that belongs in the practice's documented risk analysis, since it changes where PHI is transmitted and stored and who has access to it. ONC and OCR publish a free Security Risk Assessment tool sized for a small practice specifically so this kind of review doesn't require hiring a consultant 4Ref 4Office of the National Coordinator / ASTP (2026).Security Risk Assessment Tool.That ONC/OCR publish a free Security Risk Assessment tool sized for small practices, usable when a new or changed fax vendor changes the practice's risk picture., and HHS's 405(d) program adds a small-practice cybersecurity baseline for deciding what a reasonable fax setup actually looks like at solo scale 5Ref 5HHS 405(d) Program (2026).HHS 405(d) — Aligning Health Care Industry Security Approaches.That HHS's 405(d) program publishes a small-practice-sized cybersecurity baseline for deciding what a reasonable fax setup looks like at solo scale..
A short annual check — confirm the BAA is still current, confirm the app or device it runs on is still encrypted and passcode-protected — keeps a fax setup that was compliant at setup from quietly drifting out of compliance a year or two later.
Common questions
Run your practice on Gale
The software is free. Gale earns one flat 3.5% all-in per paid transaction — only on transactions that actually pay. No subscription, no setup fee, no network cut.
Start or manage a practice →References
- 1.HHS Office for Civil Rights (2026). Business Associates. U.S. Department of Health and Human Services. linkThat any vendor creating, receiving, maintaining, or transmitting PHI on the practice's behalf — including an e-fax service — is a business associate requiring a signed BAA.
- 2.HHS Office for Civil Rights (2026). Summary of the HIPAA Security Rule. U.S. Department of Health and Human Services. linkThat the Security Rule requires administrative, physical, and technical safeguards for ePHI, scalable to practice size, applying once a fax becomes a stored digital file.
- 3.Office of the National Coordinator / ASTP (2026). TEFCA — Office of the National Coordinator for Health Information Technology. HealthIT.gov. link ✓That TEFCA establishes a national floor for network-to-network health information exchange via QHINs, connecting participating networks rather than every legacy fax-dependent system.
- 4.Office of the National Coordinator / ASTP (2026). Security Risk Assessment Tool. HealthIT.gov. link ✓That ONC/OCR publish a free Security Risk Assessment tool sized for small practices, usable when a new or changed fax vendor changes the practice's risk picture.
- 5.HHS 405(d) Program (2026). HHS 405(d) — Aligning Health Care Industry Security Approaches. U.S. Department of Health and Human Services. linkThat HHS's 405(d) program publishes a small-practice-sized cybersecurity baseline for deciding what a reasonable fax setup looks like at solo scale.
https://www.gale.care/for-providers/spc-efax-hipaa · 5 sources. Competitor details are cited to dated public sources and maintained as they change; figures are estimates, not commitments. Synthetic demonstration.