Cybersecurity: 24/7/365

Healthcare is the last industry where the fax machine is load-bearing. Referrals arrive by fax. Prior authorizations go out by fax. The lab sends results by fax, and the specialist down the road will not accept anything else.
So the machine sits in the corridor, printing protected health information onto a paper tray that anyone walking past can read. It jams. Nobody knows whether last Tuesday's referral actually went through, because the confirmation slip is somewhere in a stack.
Online fax fixes the security problem and most of the workflow problem at once. The catch is that the service has to be the right kind, and the cheap ones are not.
It can be, and that surprises people. HIPAA never banned fax. A physical fax machine transmitting over an analogue phone line is a permitted way to send health information.
The problem is everything around the machine. A fax machine in a shared corridor prints sensitive information into an open tray. Misdialled numbers send records to a stranger, and misdirected faxes are one of the most common breach reports in healthcare. There is no audit trail beyond a paper log nobody keeps, and the machine's internal drive stores images of everything it processed — which becomes a disposal problem when the lease ends.
So the honest position is that a fax machine can meet the letter of the rule while failing every practical safeguard you would want. That is why the question is not "is fax allowed" but "why are we still doing it this way."
Almost every fax-related enforcement story starts the same way: a digit typed wrong, and medical records arriving at a business that has no reason to hold them.
A misdirected fax containing protected health information is a potential reportable breach. You have to assess it, document the assessment, and notify if the risk threshold is met. That is real work, and it happens most often when a number is keyed manually under time pressure.
Four habits prevent most of it:
Write the response procedure down before you need it: who is told, how the risk assessment is documented, and who decides on notification. HIPAA compliance is judged partly on how you handle the incident, not only on whether one occurred.
No fax solution is HIPAA compliant as a product. The service becomes part of a compliant setup when four things are true.
Ask for the BAA before you sign anything. A vendor that will not put one in front of you is answering the question.
Effectively no, and the reason is structural rather than technical.
Free tiers do not come with a business associate agreement. Providers offering a free plan are not willing to accept business-associate liability for an account generating no revenue, and many free services fund themselves in ways — advertising, data analysis — that are incompatible with handling health records.
The same trap catches the consumer tier of services that do offer compliant plans. The eFax question comes up constantly for this reason: the consumer product and the business product share a brand, and only the business tier is sold with a BAA. Check which plan the agreement attaches to, in writing, before you send a single page.
Expect roughly $10 to $60 per month for a small practice, depending on the number of fax numbers, page volume, and how many users need their own login. Services like iFax, SRFax, Updox, and the business tiers of the large fax brands all sit somewhere in that band.
Two things move the price. Page allowances are the first: plans bundle a monthly page count and charge overage beyond it, and a practice receiving lab results all day burns through pages faster than expected. The second is integration — connecting fax into your EHR usually costs more than a standalone inbox.
Compare it against what the machine already costs you. A dedicated analogue line runs $30 to $50 a month on its own, before toner, paper, maintenance, and the staff time spent walking to the corridor.
This is where online fax stops being a security upgrade and starts saving real time.
In a paper workflow, an inbound referral is printed, carried, scanned back in, indexed to the chart, and shredded. That is four handling steps for a document that arrived electronically and ended up electronic again.
Integrated fax removes the round trip. Inbound documents land in a work queue, get tagged to a patient, and file into the chart directly. Outbound faxes go from the chart without printing anything. Most healthcare providers who make this change report the referral backlog as the first thing that improves.
The ability to send and receive from inside the chart is the whole point. Integration depth varies, though. A basic setup gives you a shared inbox and manual filing. A deeper one uses your EHR's interface capabilities so documents route automatically — the same interface work we cover in our healthcare API integration guide. Ask a prospective vendor which EHRs they have live integrations with, and ask for a reference running your exact version.
Once the four compliance requirements are met, the differences that matter are practical.
Do it in stages. Sign the BAA, port the number, and run both systems in parallel for two weeks so nothing in flight gets lost. Tell your referring offices and labs nothing is changing, because from their side nothing is — same number, same process.
Train staff on the inbox before you unplug the machine, and decide who owns the queue. An electronic fax inbox with no named owner becomes the same unattended stack of paper, just on a screen.
Then deal with the machine itself. Its internal storage holds images of everything it ever processed, so wipe or remove that drive before it leaves the building. Faxes stored on it are health records like any other.
Fax is not disappearing from healthcare on any timeline you can plan around. Your specialists, labs, and payers will keep using it.
What you can change is whether your side of that exchange is encrypted, logged, and filed automatically — or printing sensitive information into a tray in the corridor. For under $50 a month, that is an easy trade.
Ready to take the next step? Explore our healthcare IT services, book a free consultation, or compare our plans.