FAQ Friday: Does Lane Support HIPAA Business Associate Agreements?




healthcare compliance officer reviewing a signed HIPAA Business Associate Agreement with a fax vendor

Yes. Lane enters into HIPAA Business Associate Agreements with healthcare customers as a standard part of the Passport and Fax 2.0 implementation process. A BAA is not an optional add-on or a premium tier requirement. It is a baseline component of how Lane works with covered entities and their business associates.

Why This Matters

Any vendor that transmits, processes, or stores protected health information on behalf of a covered entity is a business associate under HIPAA and must have a signed BAA with that covered entity before handling PHI. A fax platform vendor that transmits PHI through its infrastructure is unambiguously a business associate. Operating without a BAA is a HIPAA Privacy and Security Rule violation that creates liability for the covered entity regardless of whether a breach has occurred.

This matters practically because a significant number of healthcare organizations are using fax services, including popular consumer cloud fax tools, that do not offer BAAs. Their terms of service may explicitly disclaim responsibility for HIPAA-covered use. Using those services to transmit PHI is a compliance gap that no organizational policy or training program can remediate, because the gap is contractual rather than operational.

What Lane’s BAA Covers

Lane’s BAA establishes Lane’s obligations with respect to PHI that passes through the Passport and Fax 2.0 infrastructure. It documents the security measures Lane applies to PHI in transit, the content destruction practices that apply after delivery, the breach notification requirements Lane is obligated to meet, and the permitted uses and disclosures of PHI within the service.

One aspect of Lane’s compliance architecture that is particularly relevant to BAA terms is content destruction after delivery. Fax content transmitted through Fax 2.0 and the etherFAX network is destroyed after delivery using FIPS 140-2 compliant deletion. The content does not persist in Lane’s infrastructure after transmission is complete. For healthcare organizations concerned about PHI storage risk at third-party vendors, that architectural commitment is reflected in the BAA language and in etherFAX’s HITRUST certification.

How to Execute the BAA

For organizations implementing Passport or Fax 2.0, BAA execution is part of the standard implementation process. If your organization is evaluating Lane and wants to review the BAA before making a platform decision, Lane’s team can provide the BAA for legal review during the evaluation process.

If your organization is currently using a fax service without a BAA in place and wants to understand what a transition to a BAA-compliant platform would involve, schedule a strategy call with the Lane team. The post on what a HIPAA BAA is and when fax requires one provides additional context on the BAA requirement for fax platforms.

Scroll to Top

Altera Digital Health (formerly known as Allscripts) has a proven track record of developing cutting-edge technology for healthcare systems. Lane’s Passport product is leveraged as a solution for hospitals within Altera’s ecosystem to provide faxing of lab results. With this partnership, hospitals benefit from the latest in healthcare technology, delivered by a team with years of experience in providing innovative solutions.

Lane has been an authorized partner with Clinisys (previously Sunquest) for decades. Since 1979, Clinisys has been providing diagnostic informatic solutions to laboratories and healthcare organizations. They develop, design and support a comprehensive clinical information suite for over 1200 hospitals. Clinisys is constantly evolving and pushing the boundaries of diagnostic care for pathology laboratories worldwide.