Most organizations have undergone security audits of their EHR, their cloud storage, their email environment, and their network infrastructure. Fax infrastructure is included in those audits far less consistently, partly because it is often managed as a telecommunications utility rather than a system that handles protected health information, and partly because the failure modes of insecure fax are less visible than those of other systems.
A fax security audit surfaces the gaps between how your organization is currently transmitting faxes and what HIPAA’s Security Rule, your organization’s own security policies, and current enterprise security standards actually require. For most organizations, that audit produces findings that are addressable and that, once addressed, meaningfully improve both the compliance posture and the operational reliability of fax infrastructure.
What a Fax Security Audit Covers
A comprehensive fax security audit has six components: transmission security, access controls, audit trail completeness, vendor management, physical security, and policy and training documentation. Working through each one systematically produces a clear picture of where gaps exist and what remediation is required.
Component 1: Transmission Security
The first and most consequential question in a fax security audit is whether fax content is encrypted in transit. HIPAA’s Security Rule requires that electronic PHI transmitted over a public network be encrypted. Fax transmitted over PSTN analog lines does not satisfy that requirement because the transmission is an unencrypted analog signal. Fax transmitted through a modern enterprise platform like Passport or Fax 2.0 uses TLS encryption over the etherFAX network, which satisfies the requirement.
The audit question is specific: for each fax transmission channel currently in use at your organization, how is fax content encrypted in transit? Document the answer for every channel, including shared fax machines, on-premises fax servers, and any cloud fax services in use. Channels that cannot demonstrate encryption in transit are audit findings that require remediation.
Component 2: Access Controls
Access controls determine who can send and receive faxes containing PHI, and whether that access is appropriate, authenticated, and limited to the minimum necessary. The audit questions for access controls include: who has access to shared fax queues, how are user accounts authenticated in the fax platform, are individual user access levels configured appropriately, and how is access revoked when a staff member leaves or changes roles?
For organizations using shared fax machines or shared fax queues without individual user authentication, the access control question is effectively unanswerable because there is no record of who accessed specific documents. A modern platform with individual user authentication and role-based access controls provides the access documentation that the audit requires.
Component 3: Audit Trail Completeness
HIPAA’s Security Rule requires organizations to implement audit controls that record and examine activity in systems that contain or use electronic PHI. For fax infrastructure, that means maintaining a complete and searchable log of all fax activity: who sent what to whom, when, and with what result.
The audit question is whether your current fax infrastructure maintains that log in a form that is complete, persistent, and accessible for review. For shared fax machines, the answer is typically no. For on-premises fax servers, the answer depends on whether audit logging is enabled, how long logs are retained, and whether the logs are in a format that can be searched and produced for a compliance review. For Passport, the audit trail is comprehensive, persistent, and centrally accessible by design.
Component 4: Vendor Management
Any vendor that processes, transmits, or stores PHI as part of the fax service they provide is a business associate under HIPAA and must have a signed Business Associate Agreement with your organization. The audit question is whether a BAA is in place with every vendor involved in your fax infrastructure.
This includes cloud fax platform vendors, hosted fax service providers, and any managed service provider that has access to fax content. It does not include pure telecommunications carriers providing the underlying phone line, which are covered by HIPAA’s conduit exception. The post on what a HIPAA BAA is and when fax requires one covers the specific requirements in detail.
Document every vendor in your fax infrastructure chain and confirm BAA status for each. Missing BAAs are straightforward audit findings: execute the BAA or replace the vendor.
Component 5: Physical Security
For organizations using shared fax machines in clinical or administrative areas, physical security is a fax security consideration that does not exist for organizations running fully digital fax infrastructure. A document containing PHI sitting in a shared fax tray in a waiting area is a HIPAA exposure that no amount of transmission encryption can address.
The audit questions for physical security include: where are shared fax machines located, who has physical access to those locations, how quickly are received faxes removed from output trays, and is there a documented procedure for handling PHI received by fax? For organizations moving to a fully digital fax platform, physical security concerns associated with shared machines are eliminated.
Component 6: Policy and Training Documentation
A fax security audit is not complete without reviewing the policy and training documentation that governs how staff use fax to transmit PHI. HIPAA requires covered entities to implement policies and procedures for the safeguarding of PHI, which includes fax. The audit questions include: does a fax transmission policy exist, is it current and consistent with how fax is actually used, and can the organization demonstrate that staff have been trained on it?
Missing or outdated policies are audit findings. A fax policy that references equipment or procedures that no longer reflect current practice is a documentation gap that can complicate regulatory responses even when the actual security posture is sound.
Prioritizing Remediation
A fax security audit typically produces findings across multiple components. Prioritize remediation based on the risk and regulatory significance of each finding. Unencrypted transmission and missing BAAs are the highest-priority findings because they represent direct HIPAA Security and Privacy Rule violations. Access control gaps and audit trail deficiencies are high priority because they affect the organization’s ability to demonstrate compliance in a regulatory review. Policy and training gaps are addressable through documentation work rather than infrastructure change.
For organizations whose audit findings point toward the need for a modern fax platform, Lane addresses the transmission security, audit trail, BAA, and access control findings simultaneously as part of a Passport or Fax 2.0 implementation.
Schedule a strategy call with the Lane team to discuss how Passport addresses the findings a fax security audit is likely to surface at your organization.



