HIPAA’s requirements for transmitting protected health information are specific, but they are frequently misunderstood in ways that create both compliance gaps and unnecessary complexity for healthcare organizations. The most common misunderstandings are that HIPAA prohibits fax, that email is an acceptable alternative as long as it is encrypted, and that any encryption is sufficient to satisfy the Security Rule’s transmission safeguard requirements.
None of those assumptions are accurate, and understanding what the rules actually say is the foundation for making sound decisions about how your organization transmits PHI.
What the HIPAA Security Rule Says About Transmission
The HIPAA Security Rule requires covered entities and business associates to implement technical security measures that guard against unauthorized access to electronic PHI that is being transmitted over an electronic communications network. The specific standard requires encryption and decryption of ePHI as a mechanism to protect data in transit, though HIPAA designates this as an addressable implementation specification rather than a required one.
The addressable designation does not mean optional. It means that covered entities must assess whether the specification is reasonable and appropriate for their environment, and if they determine it is not, they must document that determination and implement an equivalent alternative measure. In practice, for any organization transmitting PHI externally over a public network, encryption of ePHI in transit is the expected and essentially universal implementation.
The Security Rule does not specify which transmission channel must be used. It specifies the safeguards that must be applied to whatever channel is used. Fax, email, and direct messaging are all permissible channels as long as the appropriate safeguards are in place.
What Fax Needs to Satisfy HIPAA
Fax transmitted through a compliant enterprise platform satisfies HIPAA’s transmission safeguard requirements when the platform provides encrypted transmission of fax content, delivery confirmation with a timestamped audit record, and access controls that limit who can send and receive faxes containing PHI.
Lane’s Passport platform and Fax 2.0 provide all of those elements. Transmissions route through the etherFAX network using Transport Layer Security encryption. Every transmission generates a delivery confirmation and an audit log entry. User access to the platform is controlled through Passport’s access management configuration. Fax content is destroyed after delivery using FIPS 140-2 compliant deletion, which means PHI does not persist in a third-party cloud environment after the transmission is complete.
A traditional fax machine transmitting over an analog PSTN line does not satisfy HIPAA’s transmission encryption requirement because the transmission is not encrypted. The document moves as an analog signal over a phone line with no encryption layer. Many healthcare organizations continue to operate analog fax machines under the assumption that fax is inherently HIPAA compliant, which is a compliance gap that creates real risk.
What Email Needs to Satisfy HIPAA
Email transmitting PHI over a standard SMTP connection does not satisfy HIPAA’s transmission safeguard requirements because standard email is not encrypted in transit in a way that protects against interception. To transmit PHI by email compliantly, the email must be encrypted using a method that protects the content in transit and at rest, and the recipient must be able to decrypt it.
In practice, this means using a secure email platform that applies encryption automatically, obtaining a business associate agreement with the email provider if it handles PHI, and having confidence that the recipient’s email environment does not introduce a gap in the encryption chain. For external communications with providers, payers, and other organizations whose email security posture you cannot control, that last requirement is difficult to satisfy consistently.
Fax through a compliant platform sidesteps the recipient-side security uncertainty because the encryption is applied at the transmission level by the sending platform, and the security of the transmission does not depend on the recipient’s infrastructure.
Business Associate Agreements
Any vendor that handles PHI on behalf of a covered entity or business associate is itself a business associate and must sign a Business Associate Agreement. This applies to fax platform vendors, email platform vendors, and any other technology provider that processes, transmits, or stores PHI as part of the services they provide.
Lane enters into BAAs with healthcare customers as a standard part of the implementation process. Organizations using consumer fax services or cloud fax platforms that do not offer BAAs are operating a HIPAA compliance gap that creates liability for the covered entity, not just the vendor.
The FAQ Friday post on what a HIPAA BAA is and when fax requires one covers the BAA requirement in more detail in the context of fax platform selection.
Schedule a strategy call with the Lane team to discuss how Passport’s compliance architecture addresses your organization’s HIPAA transmission requirements.



