Guide

Faxing in 2026: e-fax with a BAA, and why fax persists

Summary

E-fax can be HIPAA compliant, but the fax service itself has to be — a signed business associate agreement, encrypted transmission and storage, and access controls on who can view an incoming fax, the same requirements as any other vendor touching PHI. A consumer fax app with no BAA option isn't compliant regardless of how it markets itself. Fax persists in 2026 because it remains the lowest common denominator between systems that still can't exchange records electronically.

By Gale Editorial · Updated 2026-07-27. Every figure cited to a dated source. How we write.

Is e-fax HIPAA compliant?

E-fax is HIPAA compliant when the service is covered by a signed business associate agreement, transmits and stores documents encrypted, and restricts who can view an incoming fax — it is not compliant simply because it replaced a physical machine with an app. Any vendor that creates, receives, maintains, or transmits PHI on a practice's behalf is a business associate requiring a BAA, and an e-fax provider fits that definition exactly 1.

The short version for a solo clinician evaluating a service: ask for the BAA before asking about price or features. A provider unwilling to sign one, or that treats faxing as outside its BAA's scope, isn't a compliant option no matter how the product is marketed.

What actually makes a fax service compliant

A compliant e-fax setup rests on the same Security Rule safeguards as any other system touching ePHI: encryption of documents in transit and at rest, access controls limiting who can open an incoming fax, and an audit trail of who sent or received what and when — safeguards scaled to practice size, not a fixed brand-name checklist 2. A traditional analog fax line sent over the telephone network is generally treated as a permitted transmission method under the Security Rule's own analysis, but the moment a fax becomes a stored digital file — a PDF sitting in an inbox, an app, or a cloud folder — the same encryption-at-rest and BAA requirements apply as they would to any other stored ePHI.

That distinction is the actual compliance question, more than the word "fax" itself: a physical machine printing a paper fax into a locked room is a different risk profile than an app storing incoming faxes as unencrypted email attachments, even though both get called "fax."

Why fax persists in 2026

Fax survives because it remains the one document-exchange method every EHR, hospital system, and referring office can reliably send and receive, regardless of which platform is on the other end — a floor that electronic exchange initiatives are still working to replace rather than something already solved. TEFCA establishes a national framework for network-to-network health information exchange through Qualified Health Information Networks, but it connects participating networks to each other, not every fax machine and legacy system still in use across referring practices, labs, and hospitals 3.

Until that gap closes, a referral, a records request, or a prior-authorization packet often moves faster and more reliably by fax than by chasing down a portal login or a secure-email address the other office may not actually check. A solo clinician who drops fax entirely before every referral partner has a working electronic alternative risks losing referrals that simply can't reach the practice any other way.

Traditional fax line vs. e-fax: what actually changes

Switching from a physical fax machine to an e-fax service changes where the document lands — a digital inbox instead of a paper tray — and that shift is exactly what introduces the BAA and encryption requirements a paper fax line mostly avoids. A physical fax machine's main compliance exposure is the paper itself sitting in an open tray where anyone walking past can read it; an e-fax service's exposure is a stored digital file that needs the same device setup discipline as the rest of the practice's technology, including encryption and controlled access on whatever device the fax app runs on.

Many solo clinicians run their e-fax service through the same phone used for practice email and scheduling — and your phone is a HIPAA device the moment it holds an incoming fax containing PHI, needing the same passcode and encryption standard as any other device carrying patient information.

Setting up e-fax safely

A safe e-fax setup starts with the BAA, then adds a confirmation log for anything time-sensitive (a prior-authorization deadline, a records request with its own clock), automatic deletion or archiving of faxes after they're filed into the chart, and a cover sheet that states the fax may contain confidential health information without naming the patient on the cover page itself. Routing incoming faxes to auto-file into the EHR removes the step where a fax otherwise sits as a loose PDF in an inbox waiting to be filed, which is where most fax-related exposure actually happens.

A fax number, unlike a phone number, is fine to publish on referral materials and the practice website — the restriction on phone numbers in provider-facing content doesn't extend to a fax line, since a fax number isn't a route to a live conversation.

When fax isn't the right channel

Fax is well suited to document exchange with a referral partner but poorly suited to anything needing two-way interaction — a telehealth visit, a scheduling conversation, a benefits verification call — where a proper telehealth platform or a phone line does the job fax was never built for. Telehealth platforms carry their own BAA and configuration requirements distinct from a fax service, and treating the two as interchangeable "secure communication" tools is a common setup mistake for a solo clinician trying to consolidate vendors.

Worth keeping in mind for the practice's disaster planning too: fax is often the fallback channel that still works when an EHR or internet connection goes down, which is one reason it belongs in the contingency plan even for a practice that otherwise runs almost entirely digital.

Tying it to the risk analysis

Adding or changing a fax service — physical or e-fax — is exactly the kind of vendor change that belongs in the practice's documented risk analysis, since it changes where PHI is transmitted and stored and who has access to it. ONC and OCR publish a free Security Risk Assessment tool sized for a small practice specifically so this kind of review doesn't require hiring a consultant 4, and HHS's 405(d) program adds a small-practice cybersecurity baseline for deciding what a reasonable fax setup actually looks like at solo scale 5.

A short annual check — confirm the BAA is still current, confirm the app or device it runs on is still encrypted and passcode-protected — keeps a fax setup that was compliant at setup from quietly drifting out of compliance a year or two later.

Common questions

A standalone analog fax machine connected only to a phone line typically doesn't involve a third-party vendor handling the document digitally, so there's no BAA to sign for the transmission itself. The moment that fax is scanned, emailed, or routed through any digital service, that service becomes a business associate needing its own BAA.

Yes — a fax number doesn't connect to a live phone conversation the way a phone number does, so it doesn't carry the same lead-generation or direct-contact concern. Publishing a fax number for referral partners to send records or authorization requests is standard practice and doesn't require the same caution as publishing a direct phone line.

It can, and many practices use whichever the receiving office actually monitors reliably, since both require their own BAA and encryption when handling PHI. Neither is inherently more compliant than the other; the deciding factor is usually which channel the referral partner or requesting party actually checks.

A standard confidentiality notice stating the fax may contain protected health information intended only for the named recipient, without putting the patient's name or diagnosis on the cover page itself. This limits exposure if the fax is misdirected or sits visible in an open tray before someone retrieves it.

Electronic exchange frameworks connect participating networks to each other, but many referring offices, labs, and legacy systems still aren't on a connected network, leaving fax as the one method almost every party can reliably send and receive. That gap is closing gradually, not all at once, which is why fax remains part of a working referral setup even in an otherwise digital practice.

Run your practice on Gale

The software is free. Gale earns one flat 3.5% all-in per paid transaction — only on transactions that actually pay. No subscription, no setup fee, no network cut.

Start or manage a practice →

References

  1. 1.HHS Office for Civil Rights (2026). Business Associates. U.S. Department of Health and Human Services. linkThat any vendor creating, receiving, maintaining, or transmitting PHI on the practice's behalf — including an e-fax service — is a business associate requiring a signed BAA.
  2. 2.HHS Office for Civil Rights (2026). Summary of the HIPAA Security Rule. U.S. Department of Health and Human Services. linkThat the Security Rule requires administrative, physical, and technical safeguards for ePHI, scalable to practice size, applying once a fax becomes a stored digital file.
  3. 3.Office of the National Coordinator / ASTP (2026). TEFCA — Office of the National Coordinator for Health Information Technology. HealthIT.gov. linkThat TEFCA establishes a national floor for network-to-network health information exchange via QHINs, connecting participating networks rather than every legacy fax-dependent system.
  4. 4.Office of the National Coordinator / ASTP (2026). Security Risk Assessment Tool. HealthIT.gov. linkThat ONC/OCR publish a free Security Risk Assessment tool sized for small practices, usable when a new or changed fax vendor changes the practice's risk picture.
  5. 5.HHS 405(d) Program (2026). HHS 405(d) — Aligning Health Care Industry Security Approaches. U.S. Department of Health and Human Services. linkThat HHS's 405(d) program publishes a small-practice-sized cybersecurity baseline for deciding what a reasonable fax setup looks like at solo scale.

https://www.gale.care/for-providers/spc-efax-hipaa · 5 sources. Competitor details are cited to dated public sources and maintained as they change; figures are estimates, not commitments. Synthetic demonstration.

Findability, by specialty

How practices like yours get found in local search and AI answers — the honest playbook, per specialty.

SEO for private practices · SEO for AI search / answer engines (all verticals)