By David Thompson · Published November 3, 2024 · Updated June 8, 2026 · 8 min read
Your fax is encrypted. Your staff is trained. Your cover sheets have the right disclaimer. But if your fax provider has never signed a Business Associate Agreement (BAA) with you, none of that matters — you are violating HIPAA right now.
A BAA is the legal foundation of any compliant relationship between a healthcare organization and a vendor that handles patient data. Without it, every fax containing Protected Health Information (PHI) is a violation, regardless of how secure the transmission itself was.
No BAA = No Compliance
Encryption and secure infrastructure do not substitute for a signed BAA. The Office for Civil Rights (OCR) has issued fines exceeding $5 million to organizations that transmitted PHI to vendors without an executed Business Associate Agreement.
This guide explains exactly what a BAA is, why your fax provider qualifies as a Business Associate, what the agreement must contain under 45 CFR 164.504(e), and how to get one before you send another patient record.
What Is a Business Associate Agreement?
A Business Associate Agreement is a legally binding contract required by HIPAA between a covered entity and a business associate. It defines how the business associate may use or disclose PHI, what safeguards they must implement, and what happens if a breach occurs.
Covered entities include:
- Healthcare providers (hospitals, clinics, physician practices, dentists)
- Health plans and insurance companies
- Healthcare clearinghouses
Business associates are third parties that create, receive, maintain, or transmit PHI on behalf of a covered entity. This includes cloud storage vendors, billing services, EHR platforms — and yes, online fax services.
The BAA does not transfer HIPAA liability from you to the vendor. It establishes a shared responsibility model: the provider secures their infrastructure, you control your access and policies, and both parties are accountable for their slice of the compliance picture.
Why Your Online Fax Service Is a Business Associate
Traditional analog fax machines transmit data point-to-point over phone lines without storing it on a third-party server. Online fax services work differently.
When you send a fax through an online service:
- Your document is uploaded to the provider's servers
- The provider converts and transmits the fax on your behalf
- Inbound faxes are stored on the provider's infrastructure until you retrieve them
- Delivery receipts and logs are retained by the provider
Because the provider creates, receives, and maintains PHI on your behalf, they are unambiguously a Business Associate under 45 CFR 160.103. The moment you use their service to transmit a patient record without a signed BAA, you have committed a HIPAA violation.
Analog vs. Online Fax
A traditional fax machine connected directly to a phone line does not route PHI through a third-party server, so no BAA is required for the machine itself. However, if the machine connects to a cloud platform for storage, conversion, or routing — a BAA is required for that cloud component. For a full breakdown, see our guide on HIPAA fax requirements.
The 10 Required Elements of a HIPAA BAA
Under 45 CFR 164.504(e), a BAA with a fax provider must include all of the following:
The contract must specify exactly what the fax provider is allowed to do with your PHI — transmit, store, audit — and nothing more.
The provider may not use PHI for its own purposes, sell it, or share it with unauthorized parties.
The provider must implement administrative, physical, and technical safeguards consistent with the HIPAA Security Rule, including encryption in transit (TLS 1.2+) and at rest (AES-256).
The provider must notify you of any breach or unauthorized disclosure of unsecured PHI within 60 days of discovery (though best practice is 24–72 hours).
If the provider uses subcontractors who touch your PHI (e.g., a third-party cloud hosting provider), those subcontractors must have their own BAA with the provider that is at least as stringent.
The provider must support your obligations to give patients access to their PHI, the right to request amendments, and an accounting of disclosures.
The provider must make its internal practices, books, and records available to the Department of Health and Human Services for audits.
You must have the right to terminate the contract if the provider violates a material term of the BAA.
When the contract ends, the provider must either return all PHI to you or destroy it — no residual copies may be retained.
The provider may not use PHI in a way that would violate HIPAA if the covered entity did the same thing.
Any BAA missing one of these elements is legally deficient — and a deficient BAA does not protect you from OCR enforcement.
The Real Cost of Operating Without a BAA
HIPAA violations are tiered by culpability. Fines for missing BAAs fall on a spectrum:
| Tier | Situation | Penalty per Violation |
|---|---|---|
| Tier 1 | No knowledge of the violation | $141 – $71,162 |
| Tier 2 | Reasonable cause (not willful neglect) | $1,424 – $71,162 |
| Tier 3 | Willful neglect, corrected | $14,232 – $71,162 |
| Tier 4 | Willful neglect, not corrected | $71,162 – $2,134,831 |
Maximum annual cap per violation category: $2,134,831 (adjusted for inflation)
Real-world examples illustrate the stakes:
- North Memorial Health Care paid $1.55 million to settle OCR charges for transmitting PHI to a business associate without a BAA.
- Advocate Health Care was fined $5.55 million partly because a vendor accessed PHI without a proper BAA in place.
- St. Elizabeth's Medical Center paid $218,400 for sharing patient data with a vendor that had no BAA.
One Fax Can Trigger a Violation
A single fax containing PHI sent through a service without a signed BAA constitutes a violation. If the same pattern repeats across a year of faxing, each transmission is counted separately — penalties compound quickly.
The Subcontractor Chain: It Goes Deeper Than You Think
HIPAA's BAA requirement does not stop at your direct vendor. If your fax provider uses a subcontractor (for example, AWS to host the fax servers, or a carrier to deliver the transmission), that subcontractor must also have a BAA with the fax provider.
This is the subcontractor chain — and you bear indirect responsibility for ensuring it exists.
When evaluating a fax provider, ask:
- Who hosts your infrastructure? Do you have BAAs with them?
- Do any third-party telecom carriers handle my transmissions?
- How do you ensure subcontractor compliance?
A reputable provider will answer these questions transparently and make their vendor compliance documentation available on request.
How to Get a BAA from Your Fax Provider
The process is straightforward. Most compliance-ready fax services offer a BAA at no additional cost on their business or enterprise plans.
Confirm BAA availability before signing up
Before committing to a fax provider, explicitly ask whether they offer a BAA. If they hesitate or say it is unavailable, that is a disqualifying answer. Do not transmit PHI until this is confirmed.
Request the BAA in writing
Contact the provider's sales or compliance team and request the BAA document. Many providers have it available in their compliance portal or can email it within 24 hours.
Have legal review the document
Verify all 10 required elements are present (see above). Your HIPAA Privacy Officer or healthcare attorney should review the BAA before signing, especially the breach notification timelines and data destruction provisions.
Execute the agreement before transmitting PHI
Both parties must sign the BAA. Once executed, file a copy in your compliance records. Do not transmit any PHI until the signed document is in hand.
Review annually and update when scope changes
HHS recommends reviewing your BAAs annually. If you add new services, expand fax volume, or the provider updates their infrastructure, the BAA may need to be amended or re-executed.
What to Look for in a Fax Provider's BAA
Not all BAAs are equal. Beyond the 10 required elements, look for these quality indicators:
- Breach notification in 24–72 hours (not just the legal 60-day minimum)
- Encryption specifics named — TLS 1.2+ in transit, AES-256 at rest
- Audit log retention period — 6 years minimum under HIPAA
- Geographic data residency — PHI stored in US data centers
- Subcontractor list available — transparency about who handles your data
- Compliance attestation — annual security assessments or third-party audits referenced
A provider that goes beyond minimum compliance language is signaling that HIPAA is built into their operations, not bolted on.
BAA Pre-Transmission Checklist
Before sending your first fax containing PHI through any online service, verify each of the following:
- ✓BAA signed and filed: Executed copy stored in your compliance records.
- ✓All 10 required elements present: Confirm against the 45 CFR 164.504(e) checklist above.
- ✓Breach notification timeline confirmed: Know exactly how and when the provider will notify you.
- ✓Subcontractor chain verified: Provider has BAAs with any infrastructure subcontractors.
- ✓Encryption confirmed: TLS in transit, AES-256 at rest — get this in writing or in the BAA itself.
- ✓Data retention policy understood: Know how long faxes are stored and how to request deletion.
- ✓Annual review scheduled: Calendar reminder set to re-evaluate the BAA in 12 months.
mFax Business: BAA-Ready HIPAA Fax
mFax Business is designed for healthcare organizations that cannot afford compliance gaps. Every Business plan includes:
- A signed Business Associate Agreement ready to execute before your first fax
- TLS 1.2+ encryption in transit and AES-256 at rest
- Comprehensive audit logs retained for HIPAA's required 6-year period
- Virtual fax numbers to eliminate paper trays and physical access risks
- Team accounts with role-based access controls
Plans start at about $9/mo (billed annually) — and because pricing is usage-based ($3/seat + $4 per 100 pages), you build your own plan around the exact seats and pages your practice needs, no rigid tiers. A fraction of the cost of a single OCR fine.
For a comparison of HIPAA-compliant fax services with BAA support, see our best HIPAA compliant fax services guide. To understand the full compliance picture beyond the BAA, read our complete HIPAA fax guide and our guide to faxing PHI securely.
Conclusion
A Business Associate Agreement is not paperwork formality — it is the legal prerequisite for any HIPAA-compliant fax operation. Encryption, cover sheets, and access controls are all necessary, but they are built on top of the BAA, not substitutes for it.
The steps are simple: confirm your provider offers a BAA, review the document against the 10 required elements, sign it before transmitting PHI, and revisit it annually. The only wrong move is waiting.
Get a BAA with mFax Business — HIPAA-ready faxing with a signed agreement before your first transmission.