Two things are true about fax and HIPAA, and they point in different directions. Almost no fax incident starts with someone intercepting a transmission. It starts with a wrong number. And almost no enforcement action turns on the wrong number itself. It turns on the risk analysis nobody wrote.

The threat you prepared for is not the one that happens

Ask most teams how they secure fax and you’ll hear about encryption. TLS on the transport, AES at rest, a signed business associate agreement with whoever carries the traffic. Good answers, all of them, and we’ve written the full checklist in HIPAA-compliant fax in 2026.

Now look at what actually goes wrong. A records clerk fixes a referral for a patient waiting on the phone, types eleven digits, transposes two of them, and sends a discharge summary to a tyre shop. A cover sheet from last week gets reused with last week’s destination still on it. A directory entry lists a practice that moved offices in 2023 and the number now belongs to somebody’s mother.

None of those are attacks. All of them are breaches. And an encrypted transmission to the wrong recipient is encrypted right up to the moment it lands, in perfect condition, in the hands of a stranger.

That’s an uncomfortable thing to sit with if you’ve spent your budget on the transport layer. It’s also the most tractable problem in healthcare compliance, because unlike ransomware, the failure mode is predictable and happens in software you control.

The finding that shows up in settlement after settlement

Diagram comparing the cause of a fax breach, a wrong number in the send path, with the cause of the fine, a missing HIPAA risk analysis that never named the fax system

Here’s the second half, and it catches people who did nothing wrong on the day.

When the Office for Civil Rights investigates, the incident is the reason they showed up. It’s frequently not the reason for the penalty. Read a run of HIPAA settlements and the same finding appears with tedious regularity: the organisation had never conducted an accurate and thorough assessment of the risks to the electronic protected health information it holds. Not a missing firewall. Missing paperwork about what could go wrong and where.

OCR has been explicit that risk analysis is an enforcement priority, and the settlements bear it out across hospitals, business associates, software vendors and employer health plans of every size. The incident varies. The finding barely does.

Fax gets caught here more than it should, because risk analyses tend to cover the systems people think of as systems. The EHR, obviously. The mail server, usually. The fax path moves exactly the same records, sits on a server somebody configured in 2019, and appears in no document anywhere. So when the assessor asks where else ePHI lives, the honest answer is a shrug, and the shrug is what gets written down.

Five places to stop a wrong number

The fax send path from staff selecting a file to the delivery receipt, showing five control points: directory selection, destination confirmation, number rules, minimal cover pages, and receipt retention

Pick, don’t type. Every number typed by hand is a chance to get it wrong, and the fix is to make the typed path the exception rather than the default. Send to directory entries that have an owner and a review date. The value isn’t only accuracy. It’s that a directory can be audited and a keypad cannot.

Confirm against a name, not digits. This is the cheapest control on the list and the one most often skipped. Before the fax goes, show the practice name the number belongs to. People proof-read names automatically. Nobody proof-reads an eleven digit string at the end of a shift, and asking them to is a control that exists on paper only.

Put rules on the number itself. Block the ranges you have no business faxing, premium and international among them. Flag a destination that nobody in this department has ever sent to before, and let the sender confirm rather than blocking outright. First-time destinations are where transposition errors surface, because a wrong number that somebody faxes daily gets noticed within a day.

Send less on the front page. If the fax does go astray, the damage is set by what’s readable without opening anything. A cover page with a patient name and a diagnosis on it makes a misdial into a reportable disclosure of clinical detail. A cover page with a reference number and a callback line makes the same misdial into an embarrassment. Same error, different Monday.

Treat the receipt as a record. Delivery confirmation is not a courtesy feature. It’s how you establish that a document reached the machine you meant, and it’s what you’ll be asked for when somebody claims they never received a referral. Keep sender, destination, result, timestamps, retries, page count, and who opened the document afterwards, for longer than the employment of the person who sent it.

Those five controls are most of the risk analysis you owe

This is the part I find genuinely useful, and it’s why the two halves of this post belong together.

A risk analysis is not a mystical document. At its core it answers three questions for every place ePHI lives: what could go wrong here, how bad would it be, and what have you done about it. If you’ve implemented the five controls above, you’ve already answered the third question for the fax path. Writing it down is the cheap part.

Start by naming the places. In a fax path that’s more than most people expect: the spool directory where a document waits, the queue, the archive, the mail relay if you route inbound faxes to email, and the carrier holding the transmission in transit. Each one holds ePHI, each one has a different failure mode, and each one belongs in the document by name.

Then answer the question everyone gets wrong: who can read a finished fax today, and does that list still match the people who work here? Access lists rot faster than anything else in a fax deployment, because inbound routing tends to be set up once, by someone who has since left, using a group that made sense at the time. Our post on what actually makes a fax server HIPAA compliant goes deeper on the access side.

And if the only place any of this is recorded is the memory of whoever set the server up, you don’t have a risk analysis. You have a person, and people leave.

Why self-hosting makes this cheaper rather than harder

There’s a fair argument that cloud fax offloads compliance work, and for some organisations it does. I’d push back on one specific point though, which is evidence.

When the spool, the logs and the archive sit on hardware you control, answering “where does ePHI live and who touched it” is a query. When they sit with a vendor, it’s a support ticket, a wait, and whatever export format they decided to offer. That difference is invisible for years and then becomes the whole job for two weeks. Retention is the same story: your retention policy is a setting you own, rather than a tier you pay for.

The proposed tightening of the HIPAA Security Rule pushes in the same direction, with encryption, multi-factor authentication and regular vulnerability scanning moving from addressable to required. We covered what that means for fax in the proposed Security Rule post. Every one of those requirements is easier to demonstrate on a system whose configuration you can show somebody.

Where to start on Monday

If you do one thing, add the destination confirmation showing a name rather than digits. It takes an afternoon, it addresses the failure that actually happens, and staff stop resenting it within a week because it catches real mistakes.

If you do two things, open a document and list every place ePHI sits in your fax path. Not the polished assessment, just the list. Most teams discover a spool directory or an email relay they’d forgotten, and finding that on your own terms is considerably better than finding it during an investigation.

Frequently asked questions

Is a misdirected fax a reportable HIPAA breach?

Usually yes. Sending protected health information to someone not authorised to receive it is an impermissible disclosure, and it’s presumed to be a breach unless a risk assessment shows a low probability that the information was compromised. The content of the pages, and particularly what’s readable on the cover sheet, drives that assessment.

Does encryption protect us if the fax goes to the wrong number?

No. Encryption protects the transmission, not the addressing. A document encrypted in transit and at rest arrives perfectly intact at whatever destination you dialled, which is exactly the problem when the destination is wrong. Addressing controls and transport security solve different problems and you need both.

Why does the risk analysis matter more than the incident?

Because it’s the finding regulators can make regardless of how the incident went. An organisation that suffered a breach but can show a thorough, current assessment and the controls that followed from it is in a very different position from one that cannot produce the document at all. The second case is where the larger settlements cluster.

Does our risk analysis have to name the fax server specifically?

It has to cover every system that creates, receives, maintains or transmits ePHI, and a fax server does all four. Naming it, along with the spool, queue, archive and any mail relay in the path, is the straightforward way to show that coverage rather than arguing about it later.

How long should we keep fax transmission logs?

Long enough to answer a question about a transmission years after the person who sent it has left, which in practice means aligning fax log retention with your wider HIPAA documentation retention rather than with a mailbox quota. Keep the delivery result, not just the attempt.

Can fax server software prevent all wrong numbers?

No, and any vendor claiming otherwise is selling something. What it can do is remove the most common causes: hand-typed destinations, unreviewed directory entries, silent first-time sends, and cover pages carrying more clinical detail than they need. That turns a frequent incident into a rare one, and gives you the record to show what happened when it does.