Skip to content
HIPAA checklist · Free BAA, signed online

How to fax medical records.

Faxing is permitted under HIPAA when you apply reasonable safeguards: confirm the number, use a confidentiality cover sheet, send the minimum necessary, and have a signed Business Associate Agreement with your fax provider. HelpMeFax signs a BAA online at no charge.

Sending is $2.99 for 1–5 pages, $4.99 for 6–10 and $8.99 for 11–25, with no subscription. Upload the record in your browser, send it, and keep the delivery receipt with your disclosure log. There is no email-to-fax address and no machine to buy.

The short answer

Is faxing medical records HIPAA compliant?

Yes — faxing protected health information is permitted, provided you apply reasonable safeguards and have a Business Associate Agreement with whoever transmits or stores the records for you.

The part that trips people up: no fax service is "HIPAA compliant" on its own. Compliance is a property of your organization and the disclosure you are making, not a certificate a vendor holds. What a provider can do is give you the technical pieces — encryption, access control, an audit trail, a retention rule — and sign the agreement at 45 CFR 164.502(e) that makes it lawful for them to handle the records at all. Everything after that is your own procedure: verifying the destination, limiting what you send, and writing down that you sent it.

What HelpMeFax provides

  • A Business Associate Agreement, signed online at no charge, countersigned by HelpMeFax LLC.
  • Documents encrypted with AES-256 at rest and TLS 1.2+ in transit, on servers in the United States.
  • A delivery receipt by email on every fax, and a transmission record in your account history.
  • Automatic deletion of stored documents after 365 days. A received fax can also be deleted from your inbox at any time.

What stays your responsibility

  • Verifying the destination fax number before anything is sent.
  • Applying the minimum necessary standard to what you pull — 45 CFR 164.502(b).
  • Your workforce training (45 CFR 164.530(b)), your access policies, and the safeguards standard at 45 CFR 164.530(c).
  • Your own disclosure log and your own medical-record retention schedule.

More on the technical side in HIPAA-compliant online fax, and on day-to-day clinical use in fax for healthcare practices.

The checklist

How do I fax medical records step by step?

Seven steps: verify the number, send the minimum necessary, attach a confidentiality cover sheet, confirm the BAA is executed, send from your browser, file the delivery receipt, and follow up if it fails.

  1. 1

    Verify the fax number against a known-good source

    Read the number off the recipient's own release form, their records-request letter, or their published provider directory — not off a sticky note or an old fax header. Read it back to the recipient by phone when the records are sensitive. A mistyped digit is the single most common way faxed records go where they should not.

  2. 2

    Send only the minimum necessary

    Send the records that were actually requested and no more: the date range, the episode of care, the specific report. Pulling the whole chart because it is easier to export is exactly what the minimum necessary standard at 45 CFR 164.502(b) is written against. Treatment requests are the well-known exception — a treating clinician can ask for the full record.

  3. 3

    Attach a confidentiality cover sheet

    Put a cover page in front of every transmission with a confidentiality notice and an instruction for whoever receives it in error. HelpMeFax has an optional cover page built into the send form; fill it in and it is prepended as the first page of the fax.

  4. 4

    Confirm the BAA is executed before any PHI is sent

    If your fax provider transmits or stores protected health information for you, 45 CFR 164.502(e) requires a Business Associate Agreement in place first — not afterward. HelpMeFax signs one online at no charge; do it before the first patient record goes out, not after.

  5. 5

    Send from the browser and check the page count

    Upload the PDF or scan, enter the verified number, and confirm the page count and the price on screen before you pay. Domestic faxes take up to 500 pages, and files can be PDF, JPG, PNG or GIF up to 25 MB. There is no email-to-fax address — the whole send happens in the browser.

  6. 6

    Keep the delivery receipt with your disclosure log

    HelpMeFax emails a delivery receipt on every fax, and the transmission record stays in your account history with the date, the destination number, the page count and the result. That is the evidence that the disclosure happened, when, and to whom — keep it with whatever disclosure log your practice already maintains.

  7. 7

    Follow up if it fails

    A fax that does not connect is retried automatically — up to 30 attempts over about 24 hours on domestic numbers — and you get an email if it ultimately fails. Re-verify the number before resending, because a persistent failure usually means the number is wrong, disconnected, or not a fax line at all.

Fax medical records interface illustration showing document upload, fax destination, and medical fax preparation steps.

Faxes you send go out from shared HelpMeFax sending numbers, never from your own line, so put the number you want a response on in the cover page and in the body of your request. Records are accepted as PDF, JPG, PNG or GIF up to 25 MB — save a Word document as a PDF first, and export a camera-roll photo as JPEG or PDF rather than HEIC, which is not accepted.

Cover sheet

What goes on a HIPAA fax cover sheet?

Seven things: who it is from, who it is for, both fax numbers, the date, the page count, a confidentiality notice, and an instruction for whoever gets it by mistake — plus a callback number a person answers.

A cover sheet is not a legal requirement by itself; it is one of the reasonable safeguards you are expected to apply under 45 CFR 164.530(c), and it is the thing that turns a misdirected fax from a silent problem into a phone call. HelpMeFax has an optional cover page built into the send form — fill it in and it is prepended as the first page of the fax, so there is nothing to format in Word.

Sender

Your name, your practice or organization, and the fax number the transmission is coming from.

Recipient

The individual or department the records are for, their organization, and the fax number you verified.

Date and time

The date of the transmission, so the cover sheet matches the delivery receipt and your disclosure log.

Page count

Total pages including the cover sheet, so a missing page is obvious on the receiving end.

Confidentiality notice

A plain statement that the fax contains confidential health information intended only for the named recipient, and that any other use or disclosure is prohibited.

Misdirected-fax instruction

What to do if it reached the wrong desk: call this number immediately, do not read or copy it, and destroy or return the pages. Give a number, not just an instruction.

Keep protected health information off the cover sheet itself. The patient name, the diagnosis and the date of service belong behind it, not on the page that sits face-up in a shared output tray.

Business Associate Agreement

Do I need a BAA to fax PHI?

Yes, if the provider stores or transmits protected health information on your behalf. That is what 45 CFR 164.502(e) requires, and an online fax service plainly does both.

HelpMeFax LLC signs one with covered entities and business associates at no charge. You request it, read the full agreement on screen, and sign electronically; a person at HelpMeFax countersigns it and you get the executed PDF. The BAA page walks through the request, the signing and the countersignature step.

Request a BAA
  • Get it executed first. The agreement has to be in place before protected health information is sent, not reconstructed afterward. Sign it the day you open the account.
  • It costs nothing. There is no HIPAA tier and no upcharge for the agreement; the fax prices are the same either way.
  • It is signed online, not by email tag. Request, read the whole agreement on screen, sign, and a person at HelpMeFax countersigns — no sales call and no printing.
  • It is retained for six years. The executed agreement is kept for the six-year period HIPAA sets for required documentation at 45 CFR 164.316(b)(2), and your signed copy is in your account.
  • A BAA is not a compliance certificate. It allocates responsibility between you and HelpMeFax. Your safeguards, training and disclosure practices are still yours.
When it goes wrong

What if a fax goes to the wrong number?

Treat it as a potential impermissible disclosure, run it through your own breach-assessment process, and use the transmission record to establish exactly what left and where it went.

A misdirected fax is a safeguards problem before it is a breach problem. It is why step one is verifying the number against a known-good source and why the cover sheet carries an instruction for whoever receives it in error — those two habits are what keep a fat-fingered digit from becoming a reportable event. No fax service can prevent a wrong number; what it can do is make the aftermath provable.

The delivery receipt

An email on every fax telling you whether it was delivered and when. It is the first thing to pull when you need to know what actually happened.

The transmission record

Your account history keeps the date and time, the destination number, the page count and the outcome of every attempt. That is what you attach to your incident write-up.

The follow-up

Call the number that received it, ask for confirmation the pages were destroyed, document the call, and correct the bad number wherever it came from so nobody repeats it.

Whether a misdirected fax is reportable depends on your own risk assessment under the breach notification rule, and that judgment is yours to make — usually with your privacy officer or counsel. HelpMeFax gives you the transmission evidence; it does not make the determination for you.

Retention

How long are faxed records kept?

365 days, encrypted, on every plan — then deleted automatically. An executed Business Associate Agreement is kept for six years.

365 days

Documents you send and faxes you receive are stored encrypted for 365 days on every plan, then deleted automatically. There is no longer-retention tier and no shorter one.

Received faxes, deleted on demand

A fax that arrives on a dedicated number can be deleted from your inbox whenever you want, before the 365 days run out. A document you have sent is deleted on the 365-day schedule; there is no delete-on-demand control for sent faxes today, so do not write one into your own policy.

Six years for the BAA

The executed agreement is retained for six years, matching the HIPAA documentation-retention period at 45 CFR 164.316(b)(2). It is a contract, not a patient record, and it outlives the fax.

Do not mistake the 365-day window for your record-retention schedule. Your obligation to keep the underlying medical record, and the log of who you disclosed it to, lives in your own system and is usually measured in years — state law, not HIPAA, normally sets the number.

A limitation, stated plainly

Can my whole practice share one account?

Not in a way we would recommend. HelpMeFax accounts are single-user: one login, one audit trail. Separate logins per staff member are not available today.

We would rather say that here than let you find out after signing the BAA. An audit trail exists to answer "who sent this", and a login shared around a front desk cannot answer it — every disclosure traces back to the same account no matter who was at the keyboard. Sharing a password is also squarely against the access-control expectations your own policies almost certainly set.

If your practice needs per-user attribution, contact us before you sign the BAA and we will tell you honestly where that stands. A solo practitioner, a single billing coordinator, or one records custodian who owns the account and its log is the setup HelpMeFax fits today.

Related reading

FAQ

Faxing medical records: common questions.

Yes, faxing is a permitted way to disclose protected health information when you apply reasonable safeguards: verify the destination number, send the minimum necessary, use a confidentiality cover sheet, and have a signed Business Associate Agreement with any provider that transmits or stores the records for you. No fax service is "HIPAA compliant" by itself — the agreement plus your own procedures are what make the disclosure permissible.
Verify the recipient's fax number against a known-good source, pull only the records that were requested, attach a confidentiality cover sheet, confirm your BAA is executed, upload the PDF and send it from your browser, then keep the delivery receipt with your disclosure log. If the fax fails, re-verify the number before resending. HelpMeFax charges $2.99 for 1–5 pages, $4.99 for 6–10, $8.99 for 11–25, $14.99 for 26–50 and $24.99 for 51–100, with no subscription.
Sender name, organization and fax number; recipient name, organization and fax number; the date; the total page count including the cover sheet; a confidentiality notice; an instruction telling anyone who receives it in error to call you and destroy it; and a callback number a person actually answers. HelpMeFax includes an optional cover page in the send form, prepended as the first page of the fax.
Yes, if the provider transmits or stores protected health information on your behalf — that is the requirement at 45 CFR 164.502(e). HelpMeFax LLC signs a BAA with covered entities and business associates at no charge; you request, read and sign it online, and a person at HelpMeFax reviews and countersigns it, usually within one business day. Get it executed before the first record is sent.
Treat it as a potential impermissible disclosure and run it through your own breach-assessment process. Practically: pull the transmission record for the date, destination number and page count, call the number that received it and ask for confirmation it was destroyed, document what you did, and correct the number in whatever list sent you there. This is exactly why the number is verified beforehand and why the cover sheet carries a misdirection instruction.
Documents are stored encrypted for 365 days on every plan and then deleted automatically. A fax you receive can be deleted from your inbox whenever you want; a document you have sent is deleted on the 365-day schedule and cannot be removed sooner today. An executed Business Associate Agreement is retained for six years, matching the HIPAA document-retention period at 45 CFR 164.316(b)(2). Your own medical-record retention obligations are separate and usually longer — keep the record of the disclosure in your own system.
Not in a way we would recommend. HelpMeFax accounts are single-user today: one login, one audit trail. Separate logins per staff member are not available, and sharing one login destroys the per-user attribution an audit trail is for. If your practice needs individual accountability, contact us before you sign the BAA so we can tell you where that stands.
No. There is no email-to-fax address. You upload the file in your browser and send from there, which is deliberate: an emailed record would sit unencrypted in two mailboxes before it ever reached a fax line. Received faxes work the same way — you get an email alert with a secure link, and the document stays in your HelpMeFax inbox rather than travelling as an email attachment.

This page is practical guidance for people who fax patient records, not legal advice. Your privacy officer or counsel makes the call on your own policies and on any breach determination.

Sign the BAA, then send the records.

$2.99 for 1–5 pages, no subscription. Creating an account is free; you pay per fax, by card. The Business Associate Agreement is signed online at no charge, and records are encrypted for 365 days before they are deleted automatically.