If you fax protected health information, US law requires an agreement between your practice and us before you send the first page.
If you are a covered entity under HIPAA — a healthcare provider, health plan or clearinghouse — or a business associate of one, and you transmit protected health information through FaxProof, then FaxProof is your business associate and a written agreement is required.
In practice: if you fax patient records, referrals, prior authorizations, lab results or intake forms, you need one.
It's included with the Business plan at no extra cost. Request it in the app at Settings → Request a BAA, or contact us with your organization name and the email of the person who will sign.
We countersign within two business days and send the executed PDF back. You can see the current status in Settings at any time.
Protected health information you transmit or store in FaxProof Business, our use of Telnyx as a subcontractor (Telnyx signs a BAA), encryption in transit (TLS 1.2+) and at rest (AES-256 on Supabase), audit logging, and the no-retention option.
It doesn't make your organization HIPAA-compliant on its own, and it doesn't cover how your staff handle documents once they leave the app. It covers our part of the chain.
We will notify the covered entity without unreasonable delay and no later than 60 days after discovery of a breach of unsecured PHI, consistent with 45 CFR § 164.410.
Questions about scope: get in touch.