Learn how Fax.xyz protects PHI during fax transmission with encryption, secure storage, delivery tracking, and digital security features.

A few lines on a fax cover sheet can make a big difference in how confidential patient information is handled. A HIPAA fax disclaimer helps set clear expectations for the recipient and provides instructions for what to do if the information reaches the wrong person.
So, what should those few lines say? Here, we'll break down the essentials of a HIPAA fax disclaimer, explain what HIPAA does and doesn't require, and share free, copy-and-paste examples you can adapt to your organization.
A HIPAA fax disclaimer is a confidentiality notice that usually appears on a fax cover sheet when a transmission contains or may contain protected health information (PHI). It tells the recipient that the information is private and provides instructions for handling it appropriately.
A well-written disclaimer typically:
The disclaimer is usually placed on the fax cover sheet, where it can be seen before the recipient reviews the attached documents. It can appear near the bottom of the cover sheet or in a clearly labeled confidentiality notice.
No. HIPAA does not require a specific disclaimer on every fax, nor does it provide a mandatory template or exact wording.
Instead, HIPAA requires covered entities to use appropriate safeguards to protect the privacy of PHI. A confidentiality notice on a fax cover sheet can be part of those safeguards, particularly when it helps prevent an unintended recipient from using or disclosing the information.
Even though there isn't a federally required disclaimer, a confidentiality notice can serve several practical purposes:
Possibly. An organization's internal policies, state privacy laws, contracts, or other applicable requirements may call for additional safeguards or procedures when handling healthcare information.
That's why it's important to look at the disclaimer as just one part of the overall faxing process.
Remember: A HIPAA fax disclaimer can support a secure faxing workflow, but a disclaimer alone does not make a faxing process HIPAA compliant. Organizations still need appropriate safeguards for sending, receiving, storing, and accessing PHI.
There’s no required formula for writing a HIPAA fax disclaimer, but a good one should give the recipient enough information to understand the fax's confidential nature and know what to do if it was sent to them by mistake.
Here are the key elements to include:
Start by clearly stating that the fax is confidential. If the transmission contains protected health information, you can also mention PHI directly.
This immediately signals to the recipient that the contents should be handled with care.
Specify who the information is intended for. This helps distinguish the authorized recipient from anyone who may have received the fax accidentally.
The disclaimer should tell an unintended recipient what not to do with the information. Common instructions include not reading, copying, distributing, disclosing, or using the contents.
Keep this language clear and straightforward. The goal is to give the recipient an understandable instruction, not overwhelm the cover sheet with legal language.
Tell the recipient what to do if the fax was sent to them by mistake. This typically includes notifying the sender and securely destroying, deleting, or returning the information according to your organization's procedures.
If your organization has a specific procedure for misdirected faxes, the disclaimer can direct the recipient to follow it.
Finally, give the recipient a practical way to reach the sender. Include a phone number or other appropriate contact method so an accidental recipient can report the misdirected fax promptly.
You don't have to write your HIPAA fax disclaimer from scratch. Below are several free examples you can use as a starting point, with options for different levels of detail and common healthcare scenarios.
Feel free to replace the bracketed placeholders with your organization's information. Before using one as an official notice, make sure the wording fits your organization's privacy policies and procedures.
If you want to keep your cover sheet brief, this version covers the essentials without taking up much space:
CONFIDENTIALITY NOTICE: This fax may contain confidential information, including protected health information (PHI), intended only for the recipient named above. If you are not the intended recipient, please do not read, copy, distribute, disclose, or use this information. Please notify [Organization Name] at [Phone Number] immediately and securely destroy or return this fax.
For a more comprehensive cover sheet, this version provides additional context and clearer instructions for an unintended recipient:
CONFIDENTIALITY NOTICE: This fax transmission and any attachments may contain confidential information, including protected health information (PHI), intended solely for the recipient identified above and authorized individuals. If you are not the intended recipient, please do not read, copy, distribute, disclose, or otherwise use this information. If you received this fax in error, please notify [Organization Name] at [Phone Number] immediately, do not further disclose the information, and securely destroy or return the fax and any copies according to our procedures.
Use this version when sending medical records, referrals, lab results, imaging reports, or other patient documentation:
CONFIDENTIAL MEDICAL INFORMATION: This fax may contain protected health information (PHI) and other confidential patient information intended only for [Recipient Name/Organization Name] and authorized personnel. If you are not an intended recipient, please do not review, copy, distribute, disclose, or use this information. If you received this fax in error, please notify [Organization Name] at [Phone Number] immediately and securely destroy or return the fax and any copies in accordance with our procedures.
For physician practices and medical offices, a straightforward and approachable notice may work best:
CONFIDENTIALITY NOTICE: This fax is intended only for [Recipient Name/Practice Name] and may contain confidential patient information or protected health information (PHI). If you are not the intended recipient, please do not read, copy, share, disclose, or use the contents. If you received this fax in error, please contact [Doctor's Office Name] at [Phone Number] as soon as possible and securely destroy or return the fax. Thank you for helping us protect patient privacy.
Larger healthcare organizations may prefer more formal language:
CONFIDENTIALITY NOTICE: This fax transmission and any accompanying documents may contain confidential information, including protected health information (PHI), intended solely for the designated recipient and authorized individuals. Unauthorized review, copying, use, distribution, or disclosure of this information is prohibited. If you are not the intended recipient, please notify [Hospital/Organization Name] immediately at [Phone Number]. Please do not further disclose, copy, or use the information, and securely destroy or return the transmission and any copies in accordance with [Organization Name]'s procedures.
This version can be used when you specifically want to provide clear instructions to someone who receives a fax by mistake:
CONFIDENTIALITY NOTICE: You have received this fax in error. The transmission may contain confidential information, including protected health information (PHI), intended for another recipient. Please do not read, copy, distribute, disclose, or otherwise use the information. Contact [Sender Name/Organization Name] at [Phone Number] immediately to report the misdirected fax. Please securely destroy or return the fax and any copies according to the sender's instructions.
A clear HIPAA fax disclaimer can help set expectations and guide recipients when handling confidential information, but it's only one piece of the puzzle. Choosing the right online fax service also plays an important role in how your organization protects PHI throughout the faxing process.
Instead of treating the disclaimer as a box to check, look at the bigger picture: How is PHI transmitted, who can access it, and what safeguards does your faxing workflow have in place?
That's where Fax.xyz can help. With an online fax solution built for modern healthcare workflows, you can move away from relying on traditional fax machines and build a more streamlined approach to sending and receiving sensitive information.
Your fax cover sheet is a good place to start. Your choice of faxing platform matters, too.
From sending documents to receiving important healthcare information, Fax.xyz helps make online faxing straightforward for your team.
Explore the future of faxing and secure document sharing. Find practical guides, helpful tips, and expert resources to streamline your workflow.
