How to Build a Fax Compliance Program From Scratch




IT compliance officer reviewing a fax compliance program checklist covering encryption, vendors, and audit trail

Most organizations have some version of fax compliance: a policy that references HIPAA, a BAA somewhere in a vendor file, a general expectation that staff use fax appropriately. What most organizations do not have is a fax compliance program in the structured sense, meaning a defined set of controls, documented procedures, assigned ownership, and a testing cycle that gives the organization confidence that its fax-related risks are actually being managed rather than assumed.

Building that program from scratch is not a large project if approached systematically. It has five components, each of which is manageable independently and mutually reinforcing when assembled together.

Component 1: Transmission Security Assessment

The first step is understanding what your organization’s fax transmissions look like technically. Every fax channel in use needs to be identified and assessed against a simple question: does this channel encrypt PHI in transit in a way that satisfies HIPAA’s technical safeguard requirements?

The channels to assess include every shared fax machine, every fax server, and every cloud fax service the organization uses. For each one, document whether transmissions are encrypted, what encryption standard is applied, and whether the channel has been formally assessed against HIPAA or remained in use by default.

The most common finding in this assessment is that analog machines and legacy servers are transmitting PHI without encryption. HIPAA’s Security Rule requires that ePHI transmitted over a public network be appropriately protected. An analog fax signal over a PSTN line does not meet that requirement. Documenting that gap is the first step toward addressing it.

Modern enterprise platforms like Passport and Fax 2.0 address this at the platform level through TLS encryption over the etherFAX network. Platforms that cannot demonstrate current encryption standards are gaps that the program needs to remediate.

Component 2: Vendor Management and BAA Inventory

Every vendor that transmits, processes, or stores PHI on behalf of the organization is a business associate and requires a signed Business Associate Agreement. Building a fax compliance program means building a complete inventory of every vendor in the fax infrastructure chain and confirming BAA status for each.

This inventory typically reveals gaps. Consumer cloud fax services used by individual departments that never executed a BAA. A legacy fax server vendor whose software is still being used but whose BAA expired and was never renewed. A managed service provider with access to fax servers that was never identified as a business associate.

Each gap requires one of two resolutions: execute the BAA, or replace the vendor with one that will sign a BAA. Lane enters into BAAs with healthcare customers as a standard part of implementation. Consumer fax services that decline to sign BAAs are not viable for PHI workflows regardless of their other capabilities.

The post on what a HIPAA BAA is and when fax requires one covers the regulatory framework in detail.

Component 3: Audit Trail Documentation

HIPAA’s Security Rule requires covered entities to implement audit controls that record and examine activity in systems that contain or use ePHI. For fax infrastructure, that means maintaining a log of every transmission that includes the timestamp, sender, recipient, and delivery status.

A fax compliance program needs to define where that log lives, how long it is retained, who has access to it, and how it can be produced for a regulatory review or legal proceeding. For organizations running Passport, the Enterprise Status Manager provides that log automatically for every transmission. The program documentation needs to specify that the log exists, where it is, and how to retrieve it.

For organizations still running shared fax machines or legacy servers with incomplete logging, the compliance program cannot fully satisfy this requirement until the infrastructure is updated. Documenting the gap and including infrastructure modernization in the remediation plan is the appropriate interim response.

Component 4: Policy and Staff Training

A fax compliance program requires documented policies that govern how fax is used to transmit PHI, and evidence that staff have been trained on those policies. The policies need to cover at minimum: which fax channels are approved for PHI transmission, the minimum necessary standard for what information may be included in a fax, procedures for verifying that a fax number is correct before transmitting PHI, what to do when a fax is sent to the wrong recipient, and how to report a potential fax-related breach.

Staff training documentation does not need to be elaborate. It needs to be demonstrable: a training completion record, a signed acknowledgment of the policy, or a log of a training session. The specific format matters less than the ability to show an auditor that staff were trained and when.

For organizations that have never formally documented fax policies, the policy development step is where starting from scratch is most visible. The output does not need to be long. A clear, current, accessible policy document that addresses the core requirements is sufficient.

Component 5: Risk Management Integration

HIPAA’s Security Rule requires covered entities to conduct a risk analysis that identifies potential vulnerabilities to ePHI and implement security measures sufficient to reduce those risks to a reasonable and appropriate level. Fax infrastructure needs to be included in that risk analysis rather than treated as a telecommunications utility outside the scope of IT security governance.

The risk analysis for fax covers the encryption gap on unencrypted channels, the access control risk on shared machines, the audit trail completeness gap on legacy systems, and the vendor management gap from missing BAAs. Each identified risk gets a risk rating, a remediation plan, and an owner.

Integrating fax into the existing risk management process is typically straightforward once the transmission security assessment and vendor inventory are complete, because those components produce the inputs that the risk analysis needs.

Maintaining the Program

A fax compliance program is not a one-time documentation exercise. It requires an annual review that updates the transmission security assessment as infrastructure changes, verifies that BAAs are current for all active vendors, confirms that audit trail retention practices are functioning, and updates staff training documentation.

The post on how to conduct a fax security audit at your organization provides a useful framework for the annual review cycle. The program exists to give the organization confidence that fax-related risks are being managed continuously rather than assumed.

Schedule a strategy call with the Lane team to discuss how Passport supports each component of a fax compliance program at your organization.

Scroll to Top

Altera Digital Health (formerly known as Allscripts) has a proven track record of developing cutting-edge technology for healthcare systems. Lane’s Passport product is leveraged as a solution for hospitals within Altera’s ecosystem to provide faxing of lab results. With this partnership, hospitals benefit from the latest in healthcare technology, delivered by a team with years of experience in providing innovative solutions.

Lane has been an authorized partner with Clinisys (previously Sunquest) for decades. Since 1979, Clinisys has been providing diagnostic informatic solutions to laboratories and healthcare organizations. They develop, design and support a comprehensive clinical information suite for over 1200 hospitals. Clinisys is constantly evolving and pushing the boundaries of diagnostic care for pathology laboratories worldwide.