Our pick · Verified 18 August 2026
Fax.Plus — the cleanest BAA-backed online fax for study teams
Enterprise $79.99/mo (or $959.99/yr) — the only tier that includes HIPAA + BAA
Fax.Plus signs a Business Associate Agreement on its Enterprise plan, includes 4,000 pages a month, supports multiple numbers and users, and works from a browser, phone or API without a fax machine or a phone line anywhere in the chain. The honest caveat, which most comparison pages bury: the cheaper tiers are not HIPAA-covered. If you are transmitting PHI you need Enterprise, and you should budget for it rather than discovering it at contract review.
Try Fax.Plus free → Opens on the vendor’s site · CASRAI referral link
Not sending PHI? Start on the free tier → — Plenty of research faxing — IRB correspondence, non-identifiable admin, vendor paperwork — carries no PHI at all. Basic at $6.99/mo covers that comfortably.
Editorial disclosure: Some links on this page are CASRAI referral links. If you sign up through one, CASRAI may earn a commission at no extra cost to you — this helps fund our nonprofit mission. We only recommend tools our editorial team has independently researched. Read our full disclosure policy.
In summary
- A fax service is HIPAA-compliant only if the vendor will sign a Business Associate Agreement. Encryption alone does not make it compliant.
- On Fax.Plus, HIPAA compliance and the BAA are available on the Enterprise plan only — $79.99/month or $959.99/year. Verified 18 August 2026.
- Traditional analogue fax between two machines sits outside the BAA requirement, but almost nobody actually does that any more — if it touches a vendor’s servers, you need the BAA.
- Free and Basic tiers are fine for research faxing that carries no PHI, which is more of it than teams assume.
- Get the signed BAA before the first transmission, and file it where your monitor can find it — it is a document auditors ask for by name.
Fax.Plus plans, and which one you actually need
Verified against the vendor pricing page, 18 August 2026
| Dimension | Free | Basic | Premium | Business | Enterprise |
|---|---|---|---|---|---|
| Price / month | $0 | $6.99 | $13.99 | $27.99 | $79.99 |
| Price / year | — | $83.99 | $167.99 | $335.99 | $959.99 |
| Pages included | 10 total | 200/mo | 500/mo | 1,000/mo | 4,000/mo |
| Fax numbers | None | 1 | 1 | 2 free | 2 free |
| HIPAA + signed BAA | No | No | No | No | Yes |
| Suitable for PHI | No | No | No | No | Yes |
| Realistic use | Trying it out | Admin faxing, no PHI | Busier admin, no PHI | Multi-user admin, no PHI | Any study transmitting PHI |
Annual billing saves roughly 22% across the paid tiers (the vendor describes it as up to three months free). Page allowances are the published inclusions; overage is charged per page.
The BAA is the whole answer
There is no such thing as HIPAA certification for software. No government body certifies a fax service, and any vendor implying otherwise is describing their own marketing rather than a legal status. What HIPAA actually requires is straightforward: if a third party creates, receives, maintains or transmits protected health information on behalf of a covered entity, that third party is a business associate, and there must be a Business Associate Agreement in place.
So the only question that matters when evaluating a fax vendor is: will you sign a BAA, and on which plan? Everything else — TLS in transit, AES at rest, SOC 2, ISO 27001, data-centre location — is necessary supporting substance, and a vendor with none of it should not be signing a BAA in the first place. But encryption without a BAA does not make transmission of PHI lawful, and this is the single most common misunderstanding in the category. Vendors market “bank-grade encryption” loudly and mention the BAA in a footnote, because the encryption is on every tier and the BAA usually is not.
A second point that catches research teams: signing the BAA is the start of the obligation, not the end. Your side of it includes access controls, workforce training, keeping the account roster current when staff roll off the study, and treating received faxes as PHI once they land in an inbox. A compliant vendor with an account whose password is shared across a study team is not a compliant setup.
Why clinical research still faxes
It is worth being honest about why this page needs to exist in 2026. Fax persists in clinical research not because study teams like it but because the counterparties dictate it.
Referring physicians and community sites often have no secure email pathway that reaches you, and their practice-management systems treat fax as the default outbound channel for records requests.
Hospital medical records departments frequently accept release-of-information requests by fax and by nothing else, with a form that must arrive on their fax number to enter their queue at all.
Central labs, imaging vendors and IRBs maintain fax lines for requisitions, queries and safety reporting, and some sponsor safety desks still specify fax as an acceptable route for expedited reports.
Regulatory habit. A fax confirmation page is an artefact that has been accepted as transmission evidence for decades. Study teams keep them because monitors have historically asked for them.
The practical consequence is that a study team cannot unilaterally stop faxing. What it can do is stop faxing from a shared machine in a corridor, which is where the real risk lives.
The physical fax machine is usually the weakest link
Most HIPAA fax discussions focus on the transmission. In practice, the incidents that get reported involve paper.
A shared departmental machine produces an inbound fax containing a participant’s identifiable records, which then sits in an output tray in a corridor until someone collects it. A misdial sends a records request to a wrong number that belongs to a business with no obligation to protect it. A confirmation page carrying the participant’s name is left on the glass. A machine due for disposal goes out with an internal memory still holding scanned images.
Moving to a cloud fax service does not solve confidentiality by itself, but it does remove the paper step from both ends, replace an anonymous shared device with per-user accounts, and produce an actual access log. For a study team that needs to demonstrate who sent what and when, that log is more useful than a drawer of thermal confirmation slips.
The remaining discipline is yours: number verification before sending, a cover sheet with a misdirection notice, prompt removal of staff who leave the study, and a habit of not forwarding received faxes into personal email.
Work out whether your faxing actually carries PHI
Before committing to an Enterprise tier, it is worth separating your fax traffic, because a good deal of research faxing carries no protected health information at all.
Usually not PHI: IRB and ethics committee correspondence that references a protocol number rather than a participant; contract and budget paperwork with a site; vendor and supplier forms; regulatory binder administration; investigator CVs and financial disclosure forms; delegation logs identifying staff rather than participants.
Almost always PHI: anything with a participant’s name, date of birth, address, medical record number or contact details; source-document requests to a hospital records department; laboratory requisitions and results; imaging orders; adverse event narratives with identifiable detail; signed consent forms.
Two cautions on the “no PHI” column. First, a screening log that pairs a subject ID with anything re-identifiable is PHI in substance regardless of how it is labelled. Second, if a single account will be used for both categories — which is what happens in practice, because nobody maintains two fax habits — then treat the whole account as needing the BAA. Splitting by intention rather than by account is how breaches happen.
Where a team genuinely does only administrative faxing, the Basic plan at $6.99 a month is entirely adequate and there is no reason to pay for Enterprise.
Setting it up properly for a study
- Get the BAA signed before the first transmission. Not after go-live, not “in progress”. Store the executed copy in the regulatory binder or eTMF where a monitor can find it without asking you.
- Use named user accounts, never a shared login. The access log is only evidence if it identifies a person. A shared password destroys the main compliance advantage you just paid for.
- Put fax offboarding in your study close-out checklist. Staff roll off trials constantly, and a stale account with live access to inbound PHI is a finding waiting to happen.
- Verify numbers before sending, and use a cover sheet with a misdirection notice. Misdial remains the most common fax incident by a wide margin.
- Decide where received faxes live. Downloading PHI to a laptop desktop undoes the controls. Agree the destination — eTMF, secure shared drive, EDC upload — and write it into the study’s operations manual.
- Keep the confirmation records. They are your transmission evidence, and they are far easier to retrieve from a service than from a machine.
Start on the free tier, upgrade when the BAA is needed
You can test whether the service actually reaches your counterparties before committing to anything — the free tier includes 10 pages. Move to Enterprise when PHI is in scope and you need the signed BAA.
From $6.99/mo — HIPAA/BAA on Enterprise ($79.99/mo)
Send 10 free pages and test your counterparties → Opens on the vendor’s site · CASRAI referral link
Frequently asked questions
What makes a fax service HIPAA-compliant?
A signed Business Associate Agreement with the vendor. Encryption in transit and at rest, access controls and audit logging are all necessary supporting measures, but the BAA is the legal requirement — without one, transmitting PHI through a third-party service is not compliant no matter how well encrypted it is.
Is Fax.Plus HIPAA-compliant?
On the Enterprise plan, yes — Fax.Plus offers HIPAA compliance with a BAA on that tier, priced at $79.99 per month or $959.99 per year as verified on 18 August 2026. The Free, Basic, Premium and Business tiers do not include the BAA and should not be used for PHI.
What is the best HIPAA-compliant online fax service?
Judge it on one thing: which plan includes a signed Business Associate Agreement. Fax.Plus offers HIPAA compliance with a BAA on its Enterprise plan at $79.99 per month, including 4,000 pages and multiple users. Any service that will not sign a BAA on the plan you are actually buying is not an option for PHI, however good its encryption is.
Do I need a BAA for a traditional fax machine?
Transmission directly between two analogue machines over a phone line does not involve a business associate, so no BAA is required for the transmission itself. In practice almost nothing works that way any more — most modern fax paths route through a service provider at some point, and once a vendor handles the PHI, the BAA requirement applies.
Can I send patient records by email instead?
Only with appropriate safeguards, and often the receiving side is the obstacle rather than your own. Hospital records departments, referring practices and some central labs frequently accept requests by fax and by nothing else, which is the main reason research teams still need a fax route at all.
How much does a HIPAA-compliant fax service cost?
Expect to pay for a business or enterprise tier rather than an entry plan, because the BAA is almost always gated behind the higher tiers. Fax.Plus is $79.99 per month or $959.99 per year for its Enterprise plan, which includes 4,000 pages a month, verified 18 August 2026.
What should we do about faxes we receive?
Treat them as PHI from the moment they arrive. Decide in advance where a received fax is stored — eTMF, secure shared drive, or EDC upload — and write that into the study operations manual. The common failure is a coordinator downloading an inbound fax to a laptop desktop, which quietly removes every control the service provides.
Does a fax confirmation page prove the record was received securely?
It evidences that a transmission completed to a given number, which is useful and is what monitors have historically asked for. It does not evidence that the number was correct or that the recipient handled the document appropriately — which is why number verification before sending matters more than the confirmation after.







