Learn how Fax.xyz protects PHI during fax transmission with encryption, secure storage, delivery tracking, and digital security features.

Is faxing a medical referral HIPAA compliant? It can be, provided the organization uses appropriate safeguards to protect the patient's Protected Health Information (PHI). HIPAA allows the faxing of PHI but requires covered entities to protect it from unauthorized use or disclosure.
This guide explains how to build a secure referral faxing process, including recipient verification, minimum-necessary handling of PHI, approved faxing technology, transmission confirmation, and secure record management.
A medical referral fax is a faxed request from one healthcare provider to another asking for a patient to receive a consultation, evaluation, treatment, testing, or other medical service. The referral typically includes the information the receiving provider needs to understand the patient's needs and provide appropriate care.
Depending on the type of referral and the receiving provider's requirements, a referral fax may include:
Much of this information can constitute Protected Health Information (PHI) under HIPAA because it can identify a patient and relates to their health, healthcare, or payment for healthcare. That means referral documents should be handled with appropriate privacy and security safeguards throughout the faxing process.
Sending a medical referral securely comes down to controlling who receives the information, what information is shared, and how the records are handled before and after transmission.
Start by confirming that you're working with the correct patient record. Use the patient identifiers required by your organization's procedures and check that the referral contains everything the receiving provider needs.
Before sending, ask, Does the recipient need all of this information? Remove unnecessary PHI when permitted by your organization's minimum-necessary policies.
A fax sent to the wrong number can expose PHI to an unintended recipient. Verify the fax number against a trusted, current source before transmitting.
For a new recipient, consider independently confirming the number with the receiving organization. Avoid using an unverified number copied from an email, text, or other message.
Make sure the referral packet contains the right documents and nothing unnecessary.
Check that:
Follow your organization's procedures for preparing and handling PHI.
Send the referral through an approved fax machine or fax service. Confirm the destination number one final time before transmission.
Use the required login, authentication, and access controls. Don't use an unauthorized personal or consumer fax service to send PHI.
Check the fax system's transmission report or delivery status.
If the transmission fails, verify the recipient information before trying again. If the referral is urgent, don't assume that a successful fax report means the provider has seen it—follow up through an approved communication channel when necessary.
After transmission, handle the referral and transmission records in accordance with your organization's retention and security policies.
Don't leave printed PHI sitting at a shared fax machine. Store records securely and use approved methods to destroy documents that are no longer needed.
Report suspected misdirected faxes and other potential incidents according to your organization's procedures.
Yes. Faxing medical referrals is permitted under HIPAA. HIPAA does not prohibit covered entities from sending PHI by fax. Instead, organizations must use appropriate safeguards to protect that information from unauthorized access, use, or disclosure.
Those safeguards apply to the entire faxing process, not just the fax service itself. Organizations should have procedures for verifying recipients, limiting the PHI included in a referral, controlling access to fax systems, protecting printed documents, and handling transmission errors or misdirected faxes.
When using a third-party fax provider, organizations should also determine whether the provider is a Business Associate and whether a Business Associate Agreement (BAA) is required. A vendor's claim that its service is "HIPAA compliant" does not, by itself, make an organization's faxing process compliant.
Medical referrals need to reach the right provider quickly and securely. Using the right safeguards and a reliable faxing workflow can help healthcare teams protect PHI while keeping referrals moving without unnecessary delays.
Fax.xyz makes this easier with online faxing that lets teams send and manage documents without a physical fax machine. Features such as secure online transmission, delivery confirmations, and easy document management can support a more organized referral process and make it easier to keep track of important medical faxes.
With the right process and tools in place, faxing can remain a practical way to share medical referrals while keeping patient information protected.
Protect sensitive information while keeping your referral workflow moving. With Fax.xyz, healthcare teams can send and manage faxes online with features designed for secure document transmission.
Explore the future of faxing and secure document sharing. Find practical guides, helpful tips, and expert resources to streamline your workflow.
