BAA for Fax: Why Every Healthcare Fax User Needs One

If your organization faxes Protected Health Information without a signed Business Associate Agreement, you are violating HIPAA — even if the fax is encrypted. Learn what a BAA is, what it must include, and how to get one from your fax provider before you send another patient record.

BAA for Fax: Why Every Healthcare Fax User Needs One

By David Thompson · Published November 3, 2024 · Updated June 8, 2026 · 8 min read

Your fax is encrypted. Your staff is trained. Your cover sheets have the right disclaimer. But if your fax provider has never signed a Business Associate Agreement (BAA) with you, none of that matters — you are violating HIPAA right now.

A BAA is the legal foundation of any compliant relationship between a healthcare organization and a vendor that handles patient data. Without it, every fax containing Protected Health Information (PHI) is a violation, regardless of how secure the transmission itself was.

No BAA = No Compliance

Encryption and secure infrastructure do not substitute for a signed BAA. The Office for Civil Rights (OCR) has issued fines exceeding $5 million to organizations that transmitted PHI to vendors without an executed Business Associate Agreement.

This guide explains exactly what a BAA is, why your fax provider qualifies as a Business Associate, what the agreement must contain under 45 CFR 164.504(e), and how to get one before you send another patient record.

What Is a Business Associate Agreement?

A Business Associate Agreement is a legally binding contract required by HIPAA between a covered entity and a business associate. It defines how the business associate may use or disclose PHI, what safeguards they must implement, and what happens if a breach occurs.

Covered entities include:

  • Healthcare providers (hospitals, clinics, physician practices, dentists)
  • Health plans and insurance companies
  • Healthcare clearinghouses

Business associates are third parties that create, receive, maintain, or transmit PHI on behalf of a covered entity. This includes cloud storage vendors, billing services, EHR platforms — and yes, online fax services.

The BAA does not transfer HIPAA liability from you to the vendor. It establishes a shared responsibility model: the provider secures their infrastructure, you control your access and policies, and both parties are accountable for their slice of the compliance picture.

Why Your Online Fax Service Is a Business Associate

Traditional analog fax machines transmit data point-to-point over phone lines without storing it on a third-party server. Online fax services work differently.

When you send a fax through an online service:

  1. Your document is uploaded to the provider's servers
  2. The provider converts and transmits the fax on your behalf
  3. Inbound faxes are stored on the provider's infrastructure until you retrieve them
  4. Delivery receipts and logs are retained by the provider

Because the provider creates, receives, and maintains PHI on your behalf, they are unambiguously a Business Associate under 45 CFR 160.103. The moment you use their service to transmit a patient record without a signed BAA, you have committed a HIPAA violation.

Analog vs. Online Fax

A traditional fax machine connected directly to a phone line does not route PHI through a third-party server, so no BAA is required for the machine itself. However, if the machine connects to a cloud platform for storage, conversion, or routing — a BAA is required for that cloud component. For a full breakdown, see our guide on HIPAA fax requirements.

The 10 Required Elements of a HIPAA BAA

Under 45 CFR 164.504(e), a BAA with a fax provider must include all of the following:

1
Permitted uses and disclosures of PHI

The contract must specify exactly what the fax provider is allowed to do with your PHI — transmit, store, audit — and nothing more.

2
Prohibition on unauthorized use or disclosure

The provider may not use PHI for its own purposes, sell it, or share it with unauthorized parties.

3
Appropriate safeguards

The provider must implement administrative, physical, and technical safeguards consistent with the HIPAA Security Rule, including encryption in transit (TLS 1.2+) and at rest (AES-256).

4
Breach notification

The provider must notify you of any breach or unauthorized disclosure of unsecured PHI within 60 days of discovery (though best practice is 24–72 hours).

5
Subcontractor BAA chain

If the provider uses subcontractors who touch your PHI (e.g., a third-party cloud hosting provider), those subcontractors must have their own BAA with the provider that is at least as stringent.

6
Individual rights support

The provider must support your obligations to give patients access to their PHI, the right to request amendments, and an accounting of disclosures.

7
HHS inspection rights

The provider must make its internal practices, books, and records available to the Department of Health and Human Services for audits.

8
Covered entity termination rights

You must have the right to terminate the contract if the provider violates a material term of the BAA.

9
PHI return or destruction at termination

When the contract ends, the provider must either return all PHI to you or destroy it — no residual copies may be retained.

10
No use beyond contract scope

The provider may not use PHI in a way that would violate HIPAA if the covered entity did the same thing.

Any BAA missing one of these elements is legally deficient — and a deficient BAA does not protect you from OCR enforcement.

The Real Cost of Operating Without a BAA

HIPAA violations are tiered by culpability. Fines for missing BAAs fall on a spectrum:

TierSituationPenalty per Violation
Tier 1No knowledge of the violation$141 – $71,162
Tier 2Reasonable cause (not willful neglect)$1,424 – $71,162
Tier 3Willful neglect, corrected$14,232 – $71,162
Tier 4Willful neglect, not corrected$71,162 – $2,134,831

Maximum annual cap per violation category: $2,134,831 (adjusted for inflation)

Real-world examples illustrate the stakes:

  • North Memorial Health Care paid $1.55 million to settle OCR charges for transmitting PHI to a business associate without a BAA.
  • Advocate Health Care was fined $5.55 million partly because a vendor accessed PHI without a proper BAA in place.
  • St. Elizabeth's Medical Center paid $218,400 for sharing patient data with a vendor that had no BAA.

One Fax Can Trigger a Violation

A single fax containing PHI sent through a service without a signed BAA constitutes a violation. If the same pattern repeats across a year of faxing, each transmission is counted separately — penalties compound quickly.

The Subcontractor Chain: It Goes Deeper Than You Think

HIPAA's BAA requirement does not stop at your direct vendor. If your fax provider uses a subcontractor (for example, AWS to host the fax servers, or a carrier to deliver the transmission), that subcontractor must also have a BAA with the fax provider.

This is the subcontractor chain — and you bear indirect responsibility for ensuring it exists.

When evaluating a fax provider, ask:

  • Who hosts your infrastructure? Do you have BAAs with them?
  • Do any third-party telecom carriers handle my transmissions?
  • How do you ensure subcontractor compliance?

A reputable provider will answer these questions transparently and make their vendor compliance documentation available on request.

How to Get a BAA from Your Fax Provider

The process is straightforward. Most compliance-ready fax services offer a BAA at no additional cost on their business or enterprise plans.

1

Confirm BAA availability before signing up

Before committing to a fax provider, explicitly ask whether they offer a BAA. If they hesitate or say it is unavailable, that is a disqualifying answer. Do not transmit PHI until this is confirmed.

2

Request the BAA in writing

Contact the provider's sales or compliance team and request the BAA document. Many providers have it available in their compliance portal or can email it within 24 hours.

3

Have legal review the document

Verify all 10 required elements are present (see above). Your HIPAA Privacy Officer or healthcare attorney should review the BAA before signing, especially the breach notification timelines and data destruction provisions.

4

Execute the agreement before transmitting PHI

Both parties must sign the BAA. Once executed, file a copy in your compliance records. Do not transmit any PHI until the signed document is in hand.

5

Review annually and update when scope changes

HHS recommends reviewing your BAAs annually. If you add new services, expand fax volume, or the provider updates their infrastructure, the BAA may need to be amended or re-executed.

What to Look for in a Fax Provider's BAA

Not all BAAs are equal. Beyond the 10 required elements, look for these quality indicators:

  • Breach notification in 24–72 hours (not just the legal 60-day minimum)
  • Encryption specifics named — TLS 1.2+ in transit, AES-256 at rest
  • Audit log retention period — 6 years minimum under HIPAA
  • Geographic data residency — PHI stored in US data centers
  • Subcontractor list available — transparency about who handles your data
  • Compliance attestation — annual security assessments or third-party audits referenced

A provider that goes beyond minimum compliance language is signaling that HIPAA is built into their operations, not bolted on.

BAA Pre-Transmission Checklist

Before sending your first fax containing PHI through any online service, verify each of the following:

  • ✓BAA signed and filed: Executed copy stored in your compliance records.
  • ✓All 10 required elements present: Confirm against the 45 CFR 164.504(e) checklist above.
  • ✓Breach notification timeline confirmed: Know exactly how and when the provider will notify you.
  • ✓Subcontractor chain verified: Provider has BAAs with any infrastructure subcontractors.
  • ✓Encryption confirmed: TLS in transit, AES-256 at rest — get this in writing or in the BAA itself.
  • ✓Data retention policy understood: Know how long faxes are stored and how to request deletion.
  • ✓Annual review scheduled: Calendar reminder set to re-evaluate the BAA in 12 months.

mFax Business: BAA-Ready HIPAA Fax

mFax Business is designed for healthcare organizations that cannot afford compliance gaps. Every Business plan includes:

  • A signed Business Associate Agreement ready to execute before your first fax
  • TLS 1.2+ encryption in transit and AES-256 at rest
  • Comprehensive audit logs retained for HIPAA's required 6-year period
  • Virtual fax numbers to eliminate paper trays and physical access risks
  • Team accounts with role-based access controls

Plans start at about $9/mo (billed annually) — and because pricing is usage-based ($3/seat + $4 per 100 pages), you build your own plan around the exact seats and pages your practice needs, no rigid tiers. A fraction of the cost of a single OCR fine.

For a comparison of HIPAA-compliant fax services with BAA support, see our best HIPAA compliant fax services guide. To understand the full compliance picture beyond the BAA, read our complete HIPAA fax guide and our guide to faxing PHI securely.

Conclusion

A Business Associate Agreement is not paperwork formality — it is the legal prerequisite for any HIPAA-compliant fax operation. Encryption, cover sheets, and access controls are all necessary, but they are built on top of the BAA, not substitutes for it.

The steps are simple: confirm your provider offers a BAA, review the document against the 10 required elements, sign it before transmitting PHI, and revisit it annually. The only wrong move is waiting.

Get a BAA with mFax Business — HIPAA-ready faxing with a signed agreement before your first transmission.

Frequently Asked Questions

What is a Business Associate Agreement (BAA) for fax?
A BAA is a legally required HIPAA contract between a covered entity (such as a healthcare provider) and any vendor that creates, receives, maintains, or transmits Protected Health Information (PHI) on their behalf. If your fax provider touches PHI, they are a Business Associate and a signed BAA is mandatory before you send a single patient record.
Do I need a BAA with my online fax service?
Yes. Any online fax service that transmits or stores PHI is considered a Business Associate under HIPAA. You must execute a signed BAA with them before using the service for patient data. Sending PHI without a BAA is a HIPAA violation regardless of encryption or other safeguards in place.
What happens if I fax PHI without a BAA?
Operating without a BAA is a HIPAA violation that can result in fines ranging from $141 to over $2.1 million per violation depending on culpability. The Office for Civil Rights (OCR) has levied multi-million dollar fines against healthcare organizations for exactly this failure.
What must a BAA include to satisfy HIPAA?
Under 45 CFR 164.504(e), a BAA must establish permitted uses and disclosures of PHI, require the business associate to implement appropriate safeguards, mandate breach notification within 60 days, require subcontractor BAA chains, grant the covered entity termination rights, and specify PHI return or destruction at contract end.
Does mFax Business offer a BAA?
Yes. mFax Business includes a signed Business Associate Agreement as part of its healthcare and enterprise plans. You can request it at [mFax.to/business](https://mfax.to/business/) before transmitting any PHI.
Home Business Pricing Fax API Blog Document Converter Company
Terms of Service Privacy Policy