Do online faxes need to be HIPAA compliant? Learn how healthcare providers can use online faxing securely while protecting PHI and meeting HIPAA requirements.

Having HIPAA policies in place is a good start. But compliance is about more than having the right documents; it’s about making sure those policies translate into consistent practices across your organization. A HIPAA assessment helps you take a closer look at how PHI is handled, how systems and devices are protected, how employees and vendors access information, and what happens when something goes wrong.
HIPAA compliance is an ongoing process, not a one-time task. As your technology, workforce, vendors, and workflows change, your risks can change too. In this checklist, we'll walk through the key areas to review—from risk analysis and Privacy Rule requirements to security safeguards, vendor relationships, incident response, and the documentation that demonstrates your controls are working.
If your organization is covered by HIPAA, a regular assessment can help you understand whether your privacy and security practices are keeping up with your current operations.
This includes:
A covered entity generally provides or administers healthcare-related services, while a business associate is an organization that performs certain services for a covered entity and handles PHI as part of those services. Both have responsibilities under HIPAA, although the specific requirements can differ.
Before getting into the details, it helps to see what a HIPAA assessment covers as a whole. The checklist below provides a quick starting point. You can use it to see which areas are already covered and where you may need a closer review.
Start your HIPAA assessment checklist by reviewing the risks to ePHI. Identify where ePHI is created, received, stored, maintained, and transmitted, then evaluate potential threats and vulnerabilities.
Check whether you have:
These two terms are closely related but serve different purposes. Risk analysis is about understanding the risks your organization faces. Risk management is about deciding how to address those risks and putting appropriate measures in place.
The Privacy Rule focuses on how your organization uses and discloses PHI and gives individuals certain rights over their health information. As part of your assessment, review whether your policies are clear, up to date, and reflected in everyday practices.
Ask:
Your assessment should also look at whether employees understand their responsibilities when handling PHI.
The goal isn't simply to confirm that a privacy policy exists. Look for evidence that employees understand the policy and that the organization follows its procedures consistently.
Administrative safeguards focus on the people, policies, and processes your organization uses to protect ePHI. They help establish who is responsible for security, how access is managed, and how your organization prepares for and responds to security issues.
As part of your assessment, review whether you have:
Don't just check whether these processes exist. Look for evidence that they're being used. For example, you might review access records for recently hired or departed employees, training records, incident documentation, or the results of a recent security evaluation.
Technical safeguards are the technology-based controls used to protect ePHI. They cover how users access systems, how activity is monitored, how information is protected from improper changes, and how ePHI is secured when it is transmitted.
Review whether access to ePHI is limited to authorized users based on their roles and responsibilities. Check for:
Access should be reviewed when employees change roles or leave the organization.
Check whether systems record relevant activity involving ePHI and whether those records are reviewed.
Review safeguards that protect ePHI from unauthorized alteration or destruction. Check whether important data and system changes can be detected and monitored.
Confirm that users are properly verified before accessing systems containing ePHI. Authentication methods should be appropriate to the organization's risks.
Review how ePHI is protected when transmitted between systems or locations. Confirm that secure communication methods are used and that electronic transmissions are appropriately protected.
Your HIPAA assessment shouldn't stop at the systems and processes you control directly. If outside vendors handle PHI on your organization's behalf, their access and security practices should also be part of your review.
Review whether:
A BAA alone isn't enough. Also consider what PHI the vendor can access, why it needs that access, and how the information is protected.
Your HIPAA assessment should check not only whether training is provided, but whether employees understand their responsibilities.
Review whether:
Training should reflect employees' roles and the PHI they handle.
Your HIPAA assessment should confirm that your organization can identify, contain, investigate, and document incidents.
Review whether you have:
Not every security incident is a reportable breach. Your process should help determine what happened, what PHI was involved, and what action is required. Under the Breach Notification Rule, breaches of unsecured PHI generally require notification, subject to applicable requirements and exceptions.
Review whether your organization can protect and restore access to ePHI during disruptions.
Check that:
Don't just confirm that backups exist—test whether you can actually restore from them.
A HIPAA assessment shouldn't end with a list of controls that are supposedly in place. You should also be able to show how those controls work and demonstrate that your organization follows them.
As part of your review, gather and check documentation such as:
For each control you review, try to connect the requirement to evidence. For example, instead of simply marking “employee training: implemented,” record what training was provided, when it occurred, who completed it, and where the records are maintained.
This makes the assessment more useful because it creates a record of what was reviewed, what was found, and what actions were taken.
HHS generally requires organizations to retain required Security Rule documentation for six years from its creation or the date when it last was in effect, whichever is later.
A HIPAA assessment is more useful when findings are supported by clear evidence. Depending on the area you're reviewing, this may include:
For each control, record what you reviewed, what you found, and whether any follow-up is needed.
Once you've identified gaps, turn them into a simple action plan. For each finding, note:
Prioritize findings based on their potential impact and track open items until they're addressed.
A HIPAA assessment doesn't have to be complicated. By reviewing your risks, privacy practices, security safeguards, vendors, workforce, incident response, and documentation, you can get a clearer picture of how your organization protects PHI and where improvements may be needed.
Use the checklist as a practical starting point, document what you find, address priority gaps, and revisit your assessment as your organization changes.
Keep your fax workflows simple while protecting sensitive information. With Fax.xyz, you can send and receive PHI using a HIPAA-compliant faxing solution.
Explore the future of faxing and secure document sharing. Find practical guides, helpful tips, and expert resources to streamline your workflow.
