Written and maintained by CASRAI Editorial Board
Last updated
Short answer: eFax can be used for protected health information, but only on the products that come with a signed Business Associate Agreement (BAA). As of August 2026, eFax’s own HIPAA compliance page states that BAA coverage applies to eFax Business, eFax Corporate, eFax Unite and jSign. eFax Personal is not on that list, even though the same page’s plan table carries a “HIPAA Compliant” feature label against it. That gap is the entire answer to this question: the encryption and audit features are not what makes faxing PHI lawful — the executed BAA is. If your office is running a consumer or free-tier fax account, PHI should not move through it until you are on a BAA-covered product and have the countersigned agreement on file.
Tip: try code CASRAI at checkout for 15% off, if the offer is currently active for this program — codes vary by vendor and aren’t guaranteed.
This page is written for the person who has been handed an inherited eFax account and asked by a privacy office, IRB or compliance lead to prove it is compliant — a practice manager, a clinical research coordinator, a site start-up specialist. It answers the plan-and-BAA question directly, gives you the checklist your privacy office will actually ask for, and is honest about the cases where the right move is to stay on eFax and upgrade rather than bring in a second vendor.
Does eFax sign a business associate agreement, and on which plans?
Yes — on some products, not all. eFax’s published HIPAA compliance page (checked August 2026) names the products with BAA coverage explicitly: eFax Business, eFax Corporate, eFax Unite and jSign. Corporate is the quote-based tier aimed at organisations that need custom user counts, provisioning and volume terms; Business is the self-serve tier above Personal.
Two things follow from that, and they are the two things a privacy office will care about:
- eFax Personal is not a BAA-covered product. The plan table on that page shows Personal at $20/month (with a $4.99 promotional first month) and lists “HIPAA Compliant” among its features, but Personal does not appear in the enumerated list of products with BAA coverage. A feature badge is a marketing claim about the product’s controls. It is not a contract, and HIPAA’s business-associate obligation is a contractual one.
- Being on the right plan is necessary but not sufficient. eFax does not countersign a BAA automatically the moment you subscribe. You have to request it, execute it, and keep the executed copy — the signed PDF, with dates and both signatures — where your privacy office can retrieve it during an audit. “We’re on the Business plan” is not evidence. The executed BAA is.
Pricing note, stated carefully: the figures displayed on eFax’s compliance page in August 2026 were promotional first-month rates ($14.99 for Business; Personal at $20/month with a $4.99 first month), and Corporate was quote-only. Promotional and ongoing rates are not the same number, and eFax did not publish a standing Business rate on that page. Confirm the ongoing monthly rate, the included page allowance and the per-page overage directly with eFax before you build a budget line around it.
Why free and consumer eFax cannot be used for patient or participant data
This is where most of the real exposure sits, because consumer accounts are how fax quietly enters a clinical or research office. Someone signs up personally to send one referral, the number gets printed on a form, and two years later it is receiving lab results.
Under the HIPAA Privacy Rule, a vendor that creates, receives, maintains or transmits PHI on behalf of a covered entity is a business associate (45 CFR 160.103), and a covered entity may not disclose PHI to a business associate without satisfactory assurances in the form of a written contract — the BAA — under 45 CFR 164.502(e) and 164.308(b). There is a narrow “conduit” carve-out in HHS guidance for services that merely transmit and have only transient access to the data, of the kind that covers a telephone company or a courier. An internet fax service does not fit inside it: it stores your sent and received faxes in an account, indexes them, and makes them retrievable later. That is persistent access, which makes the provider a business associate rather than a conduit.
So a consumer eFax account carrying PHI is a disclosure to a business associate with no BAA in place. That is a Privacy Rule violation on its own terms, independent of whether anything was ever intercepted — and if the account is later found to have received PHI, you are also in the awkward position of having to assess it under the Breach Notification Rule (45 CFR Part 164, Subpart D, with its 60-day clock) without any contractual visibility into what the vendor did with the data.
The practical remediation, in order: stop routing PHI to the account today; move the number to a BAA-covered product or a compliant provider; execute the BAA before the first PHI-bearing fax; and document the gap period for your privacy office rather than hoping nobody asks about it.
Compare Fax.Plus HIPAA plans →
What actually makes any online fax service HIPAA compliant — the real checklist
“Is it HIPAA compliant?” is not a yes/no property of a product. It is a property of your configuration, your contract and your procedures together. When a privacy office reviews a fax vendor, this is roughly what it is looking for. Run it against eFax, against Fax.Plus, or against anything else you are shortlisting.
- An executed BAA. Countersigned, dated, retrievable. Confirm it covers the specific product SKU you bought, not a sibling product.
- Encryption in transit. TLS on the leg between you and the provider, and — this is the part people miss — a defined behaviour for the email-to-fax path, which is often plain SMTP by default.
- Encryption at rest. AES-256 on stored fax images and metadata in the provider’s storage.
- Unique per-user accounts and role-based access. 45 CFR 164.312(a)(1) requires access control with unique user identification. A single shared login for the whole clinic fails this, no matter how good the vendor’s encryption is.
- Audit logging. 45 CFR 164.312(b) requires audit controls — records of who sent what, to which number, when, and who opened an inbound fax.
- Retention and disposal. How long the provider keeps fax images, whether you can delete them, and what happens to stored PHI at contract termination.
- Misdirection controls and procedure. Confirmed-number lists, cover sheets with the correct disclaimer language, and a documented what-to-do-when-it-goes-to-the-wrong-number procedure. See our HIPAA-compliant fax cover sheet template for the required language.
- Notification obligations flowing back to you. The BAA should oblige the vendor to notify you of a security incident on a timeline that lets you meet your own 60-day obligation.
Only items 1 through 6 are things a vendor can sell you. Item 7 is the one that actually causes most fax-related breaches, and it is entirely yours.
Encryption in transit vs at rest: what the Security Rule actually requires
Worth being precise here, because vendors quote encryption specs as though they settle the question and they do not. The HIPAA Security Rule (45 CFR Part 164, Subpart C) classifies encryption as an addressable implementation specification — at 164.312(a)(2)(iv) for data at rest and 164.312(e)(2)(ii) for transmission — not a flatly required one. “Addressable” does not mean optional: it means you must assess whether it is reasonable and appropriate, implement it if it is, and document your reasoning if you implement an equivalent alternative instead. In practice, for a fax service handling PHI over the public internet, there is no defensible risk analysis that concludes encryption is unreasonable.
By contrast, access control (164.312(a)(1)), audit controls (164.312(b)) and integrity controls (164.312(c)(1)) are required specifications with no such flexibility — which is why per-user accounts and log retention matter more to an auditor than the difference between one vendor’s AES-256 and another’s.
One forward-looking caveat: HHS published a proposed rule in January 2025 that would tighten several of these addressable specifications, including encryption, into required ones. Confirm its current status before you cite it to your privacy office as settled law — it was still a proposal, not a final rule, at our last check, and a compliance memo that treats a proposed rule as final is worse than one that omits it.
Also worth knowing what encryption does not solve: it protects the leg between you and the provider. It does nothing about the fact that the last mile of a fax is often an actual analogue line into a machine in a corridor, and nothing at all about a transposed digit in the destination number. Misdirection is the dominant real-world fax breach mode, and no vendor sells a fix for it.
eFax vs Fax.Plus: BAA availability, seats and controls
This is the comparison most people land here for, so here is the straight version, including the part that does not favour our referral partner.
| Dimension | eFax (as of Aug 2026) | Fax.Plus (as of Aug 2026) |
|---|---|---|
| Lowest tier with a BAA | eFax Business (also Corporate, Unite, jSign) | Enterprise only |
| Consumer/entry tier | Personal — labelled “HIPAA Compliant” but not listed as BAA-covered | Free, Basic, Premium, Business — no BAA |
| Encryption in transit | 256-bit AES with TLS 1.2 | TLS (AES-128+) |
| Encryption at rest | 256-bit AES | AES-256 |
| Audit trails | Audit trail capabilities across the product suite | Full activity logging |
| Access controls | Role-based permissions, “minimum necessary” support | Role-based permissions, 2FA, SSO |
| Hardened HIPAA mode | Not described as a separate toggle | Advanced Security Controls (ASC), enabled with the BAA |
| Data residency choice | Not published on the compliance page | US (Los Angeles / Oregon), Zurich, Singapore, Sydney |
| Published certifications | HIPAA compliance page; suite-level controls | ISO 27001, SOC 2 badges |
On the single axis most readers care about — how far up the price list you have to climb to get a BAA — eFax wins. eFax puts BAA coverage on its self-serve Business tier. Fax.Plus does not: its own HIPAA page states plainly that Enterprise is the only plan that includes a BAA, and our separate write-up of whether Fax.Plus is HIPAA compliant recorded Enterprise list pricing starting around $79.99/month as of August 2026. If your requirement is “a BAA, cheaply, for a low volume of PHI faxes,” eFax Business is the more direct route and we are not going to pretend otherwise.
Where Fax.Plus is genuinely stronger is the configuration layer on top of the BAA. Its Advanced Security Controls mode, which is switched on alongside the BAA rather than left to the administrator to remember, forces email-to-fax through a TLS-only address (@tls.fax.plus), strips file attachments out of email and Slack notifications, and disables the Zapier integration while leaving API access intact. Those are exactly the three quiet leak paths that turn a technically-encrypted fax account into a PHI-in-your-inbox problem: an unencrypted email-to-fax submission, a notification email carrying the fax image itself, and an automation connector copying documents into a third-party workspace nobody put on the risk register. Being able to point at a vendor-enforced setting that closes all three is a real answer to a real audit question. So is choosing where the data sits — the Zurich and Singapore options matter if you are running a multi-site study with data-localisation commitments in the protocol.
See Fax.Plus security controls →
When you should stay on eFax and not switch
Several of these will apply to more readers than the vendor-comparison framing suggests.
- Your institution already holds an enterprise eFax contract with a countersigned BAA. Then the compliant answer is to confirm or upgrade the existing plan, not to add a second fax vendor and a second BAA to your third-party risk register. Every additional business associate is another vendor to assess, another agreement to renew, another notification path to test. Adding one to save a few dollars a month is a net loss in compliance overhead, and your privacy office will tell you so.
- You need a BAA at the lowest possible cost and your volume is small. eFax Business carries BAA coverage; Fax.Plus makes you buy Enterprise. Confirm eFax’s ongoing Business rate and page allowance, and if the numbers work, that is your answer.
- Your fax number is printed on referral forms, lab requisitions and IRB-approved participant materials. The switching cost here is not the porting itself — it is the paperwork downstream of it. See the porting section below before you commit.
When neither eFax nor Fax.Plus is the right answer
If you need inbound faxes routed into the chart — HL7 or FHIR delivery into an EHR, discrete-field extraction from a referral, work queues that assign an inbound document to a coordinator — you are not shopping for an online fax service at all. That is an enterprise clinical fax platform (the Consensus, Concord, Updox class of product), bought and integrated through IT, not something you provision on a card. Both eFax and Fax.Plus are standalone services with APIs; neither replaces a clinical fax integration layer, and forcing one into that role produces a manual re-keying step that is itself a data-integrity risk.
And the point that outranks every product decision on this page: no fax product makes you compliant by itself. The cover sheet, the confirmation-page review, the verified-number list and the misdirection procedure are where fax breaches actually originate. A correctly-configured vendor with sloppy desk procedure will still send PHI to a random dentist’s office.
Porting an existing fax number without losing referrals
If you do move providers, the number is the asset — it is printed on forms you do not control and stored in the address books of practices that refer to you. Port it; do not issue a new one and hope.
- Confirm portability before you cancel anything. Fax numbers are portable in principle, but portability depends on the number type and the rate centre. Get written confirmation from the gaining provider first.
- Never cancel the losing account before the port completes. Cancellation releases the number and the port fails. This is the single most common way an office loses a fax number permanently.
- Match the account details exactly. Ports are rejected for mismatched billing name, service address or account number far more often than for anything technical.
- Handle the BAA gap. The new BAA must be executed before the first PHI-bearing fax arrives on the new service — which, on a port, means before cutover, not after. Plan for a window where both are live and only one is receiving PHI.
- Test inbound and outbound after cutover, from an external line, before you tell referrers anything has changed.
What to document for your privacy office before you send the first fax
If you are the person who has to produce the file, this is the file. It is short, and having it assembled in advance is the difference between a ten-minute conversation and a finding.
- The executed BAA — countersigned PDF, with the effective date and the product it covers.
- The plan/SKU you are actually subscribed to, with evidence it is one of the BAA-covered products.
- A short vendor security summary: encryption in transit and at rest, audit logging, access controls, and any certifications (ISO 27001, SOC 2) the vendor publishes.
- Your user roster: who has an account, at what role, and how accounts are deprovisioned when someone leaves.
- The configuration decisions you made — email-to-fax on or off and how it is secured, notification content settings, integrations enabled, data residency if selectable.
- Retention: how long fax images persist in the account, and your deletion practice.
- Your misdirection and confirmation procedure, and the cover sheet in current use.
- A note recording when PHI first moved through the account, relative to the BAA effective date — and, if there is a gap, what you did about it.
Items 4 through 8 are yours regardless of vendor. If you are starting this file from scratch, our guide to what actually makes a fax service HIPAA compliant covers the vendor-evaluation side in more depth, and the HIPAA in clinical research entry covers the research-specific pathways (authorisation, waiver, limited data set, de-identification) that determine whether the document you are about to fax is PHI in the first place.
See Fax.Plus pricing and BAA terms →
Frequently asked questions
Is eFax HIPAA compliant?
Conditionally. eFax offers BAA coverage on eFax Business, eFax Corporate, eFax Unite and jSign as of August 2026. Using one of those products, with an executed BAA and appropriate configuration, supports compliant handling of PHI. Using eFax Personal, or any account without a BAA, does not — regardless of the encryption in place.
Is eFax Personal HIPAA compliant if the plan table says “HIPAA Compliant”?
No, not for PHI. The same compliance page that shows that feature label lists the BAA-covered products separately, and Personal is not among them. Treat the feature label as a description of the product’s technical controls, not as evidence of a business-associate relationship. Without a BAA, disclosing PHI to the service is a Privacy Rule problem on its own.
Is the free version of any online fax service safe for PHI?
No. Free tiers are not BAA-covered by any mainstream provider, and free-tier terms frequently permit uses of your data that are incompatible with a business-associate obligation. Free fax is fine for a signed lease. It is not fine for a consent form.
Does encryption alone make a fax service HIPAA compliant?
No. Encryption is an addressable implementation specification under the Security Rule (45 CFR 164.312(a)(2)(iv) and 164.312(e)(2)(ii)) and, on its own, satisfies none of the Privacy Rule’s contractual requirements. Access control and audit controls are required specifications; the BAA is a separate contractual obligation. A perfectly encrypted service with no BAA is still non-compliant use.
What is the cheapest way to get a BAA for online fax?
As of August 2026, among the two services compared here, eFax’s self-serve Business tier is the lower-priced route to BAA coverage — Fax.Plus requires Enterprise. Confirm current ongoing pricing with both vendors before deciding; published figures on vendor pages are frequently promotional first-month rates.
Do I need a BAA if I am faxing de-identified research data?
If the data has been properly de-identified under 45 CFR 164.514(a)-(b) — Safe Harbor or Expert Determination — it is no longer PHI and falls outside HIPAA’s scope, so the business-associate obligation does not attach. Two cautions: a limited data set is not de-identified data and does still require a data use agreement, and de-identification judgements should be made by whoever owns that determination at your institution, not by the person operating the fax machine.
Is a fax provider a “conduit” like the phone company?
Generally no. HHS’s conduit exception is narrow and covers services with only transient access to the data in transit. An internet fax service that stores your sent and received documents in a retrievable account has persistent access, which makes it a business associate.
What happens if a fax containing PHI goes to the wrong number?
It is an impermissible disclosure and must be assessed under the Breach Notification Rule (45 CFR Part 164, Subpart D), which presumes a breach unless a risk assessment demonstrates a low probability that the PHI was compromised. Individual notification runs on a 60-day clock from discovery. This is the failure mode that no vendor feature prevents, which is why the confirmation-review step belongs in your written procedure.
Related reading
- HIPAA-compliant fax for clinical research teams — the full vendor-evaluation guide.
- Is Fax.Plus HIPAA compliant? — the same question, answered for the other vendor on this page.
- Fax.Plus review — pricing, limits and real usage detail.
- HIPAA-compliant fax cover sheet — free template and required language.
- HIPAA, HIPAA Privacy Rule, PHI exemptions from the Privacy Rule.
- Clinical research administration — the wider cluster.
Vendor facts on this page were checked against eFax’s and Fax.Plus’s own published compliance pages in August 2026. Plan names, tier eligibility and pricing change; confirm current terms with the vendor before purchasing, and have your privacy office review the BAA before any PHI moves through a new service.








