LetterAgent
Mail physical letters by just asking your AI assistant.
Yes, faxing can be HIPAA compliant, but there is no blanket exemption: HIPAA never says "fax is fine." A compliant fax follows the same Security Rule safeguards as any other transmission of health information: reasonable steps to get the number right, a cover sheet marking the fax confidential, and a business associate agreement with any fax service that handles the data for you.
This is general information, not legal advice.
No, and that is the source of most confusion. HIPAA's Security Rule covers electronic protected health information, and it lists safeguards, not approved technologies. A traditional fax over an analog phone line arguably falls outside the electronic rules entirely, which is where the folk belief "fax is HIPAA exempt" comes from. But here is the catch that matters in 2026: almost no fax today travels purely over phone lines. The moment your fax touches an email-to-fax server, a cloud fax provider, or a multifunction printer that stores it digitally, it is electronic health information again, and the full rulebook applies. Treat every fax as covered and you will never be caught by the distinction.
| Safeguard | What to do |
|---|---|
| Verify the destination | Confirm the fax number with the recipient by phone before the first send; program numbers instead of hand-dialing |
| Cover sheet | Mark the fax confidential, name the intended recipient, and include a callback number with instructions for misdirected faxes |
| Business associate agreement | Sign a BAA with any fax vendor that touches the data on your behalf; without one, you are exposed |
| Minimum necessary | Send only the pages the recipient needs, not the whole chart |
| Confirmation page | Keep the transmission report with the sent document as your record |
A business associate agreement (BAA) is a contract in which a vendor handling health information on your behalf promises to safeguard it. If you are a clinic, insurer, or anyone covered by HIPAA, and you use an online fax service, that service is your business associate and you need a signed BAA with them before you send patient data through it. This is not optional paperwork: it is the mechanism HIPAA uses to extend its rules to vendors. Note the direction, though. If you are a patient faxing your own records to your own doctor, HIPAA's vendor rules are not aimed at you; the covered entity on the receiving end carries the compliance burden.
Dialing the wrong number. Not hacking, not interception: a misdialed fax that delivers a patient's full record to a stranger's machine. It is the most reported kind of fax incident because there is no bounce-back and no recall. The fix is boring and it works: confirm the number by voice before the first fax to a new recipient, store it in the machine or service so nobody hand-dials it again, and put a cover sheet on every fax naming the intended recipient with instructions to call you if it arrived somewhere unexpected. Auditors look for exactly these habits when something goes wrong.
HIPAA treats encryption of health information in transit as an "addressable" safeguard, which means you must assess it and implement it where reasonable, not that every transmission must be encrypted or else. For fax, the practical reading most compliance officers use is: verify the number, use cover sheets, keep confirmation pages, sign BAAs with vendors, and prefer services that encrypt stored faxes. If you want the strongest posture, a secure portal or encrypted file transfer beats fax outright. But a careful fax with all the safeguards above is the posture thousands of compliant offices actually run every day.
Ready to fax it? Fax with LetterAgent: describe it to your AI assistant, approve the exact quoted price, and it is sent.
LetterAgent is a working name. Prices include print, postage, and our service fee. US prices in USD, Canadian prices in CAD (Canadian prices exclude applicable sales tax, added at checkout). Currently in private testing.
Need help? Ask your assistant: it can check a job's status any time. If it ever can't handle something: hello@getletteragent.com