If your organization is a HIPAA covered entity or a business associate, and you use a fax platform that transmits or stores protected health information, you are required to have a signed Business Associate Agreement with the fax vendor. This is not a best practice. It is a regulatory requirement, and operating without one is a HIPAA violation that creates liability for your organization regardless of whether a breach has occurred.
Despite that clarity, a significant number of healthcare organizations are using fax services without a BAA in place, often because they are using consumer cloud fax tools that do not offer BAAs or because the BAA requirement was not considered when the fax service was initially selected.
What a Business Associate Is
HIPAA defines a business associate as any person or entity that performs functions or activities on behalf of a covered entity that involve the use or disclosure of protected health information. A fax platform vendor that transmits or stores PHI as part of the service it provides is a business associate, and the covered entity is required to have a written agreement with that vendor that establishes the vendor’s obligations with respect to that PHI.
The BAA must specify what the business associate is permitted to do with PHI, require the business associate to implement appropriate safeguards to protect PHI, and require the business associate to notify the covered entity of any breach of unsecured PHI. A fax vendor that has not signed a BAA is operating outside the legal framework that HIPAA’s Privacy and Security Rules establish for PHI handling.
When Fax Requires a BAA
If your fax platform transmits PHI, stores PHI even temporarily during transmission, or provides services through which PHI passes, a BAA is required. This applies to cloud fax services, hosted fax platforms, and any software-as-a-service fax solution where the vendor’s infrastructure processes your fax transmissions.
It applies to fax-to-email services where the vendor’s servers receive inbound faxes and convert them to email attachments. It applies to cloud fax portals where users log in to view and send faxes through the vendor’s hosted environment. It applies to any fax platform where the vendor has technical access to the content of fax transmissions.
It does not apply to pure telecommunications carriers providing phone lines for on-premises fax servers, because those carriers are explicitly excluded from the business associate definition under a specific HIPAA conduit exception. But that exception applies narrowly and does not cover vendors that provide services beyond simple data transmission.
What to Look For in a Fax Vendor’s BAA
Not all BAAs provide equivalent protection. When reviewing a fax vendor’s BAA, key provisions to evaluate include how the vendor handles PHI after transmission, what security measures the vendor is contractually required to implement, what the breach notification timeline is, and what happens to PHI stored by the vendor if the relationship terminates.
Vendors whose BAA language is vague about post-transmission data handling may be retaining fax content in ways that create ongoing PHI storage risk. Lane’s compliance architecture includes content destruction after delivery using FIPS 140-2 compliant deletion, which means PHI does not persist in Lane’s infrastructure after the transmission is complete. That architectural commitment should be reflected in the BAA language.
Ask the vendor whether their BAA has been reviewed and updated to reflect the HITECH Act’s expanded business associate requirements and the 2013 Omnibus Rule changes. BAAs that predate those regulatory updates may not include all of the required provisions.
Consumer Fax Services and the BAA Gap
Consumer cloud fax services, including many well-known fax-to-email products marketed to small businesses, typically do not offer BAAs. Their terms of service may include language explicitly stating that the service is not intended for HIPAA-covered uses. Healthcare organizations that use those services to transmit PHI are using a product that the vendor has explicitly disclaimed responsibility for in a HIPAA context, with no BAA to establish the vendor’s obligations.
For healthcare organizations, the selection of a fax platform needs to include the BAA question as a threshold requirement before any other evaluation criteria are considered. A vendor that will not sign a BAA is not a viable option for transmitting PHI regardless of how their feature set compares to alternatives.
Lane enters into Business Associate Agreements with healthcare customers as a standard part of the Passport and Fax 2.0 implementation process. If your current fax vendor has not signed a BAA with your organization, contact the Lane team to discuss what a compliant alternative would look like.



