Establishing secure connection…Loading editor…Preparing document…

Healthcare Fax Agreement

This template is fully customizable. Edit the text, fill out the fields, and send it for signature. Give it a try!

HEALTHCARE FAX AGREEMENT

This Healthcare Fax Agreement ("Agreement") is entered into by and between the parties identified below for the limited purpose of transmitting Protected Health Information by facsimile. This Agreement establishes the parties' responsibilities, security procedures, permitted uses, and notification obligations with respect to fax transmissions containing Protected Health Information.

Parties and Effective Date

Provider Name:

Recipient Name:

Effective Date:    Expiration Date (if any):

Definitions

"Protected Health Information" or "PHI" means individually identifiable health information transmitted or maintained in any form, including but not limited to medical records, test results, imaging reports, treatment plans, and billing information, as defined under applicable state and federal law.

Scope and Permitted Transmissions

The parties agree that fax transmissions under this Agreement will be limited to the minimum necessary PHI required to accomplish the intended purpose. Permitted categories of information include:

Security Procedures and Operational Controls

The parties shall implement reasonable administrative, physical and technical safeguards to protect PHI transmitted by fax. The receiving party acknowledges that a facsimile transmission may expose PHI to the risk of misdirection and agrees to adopt the following controls:

Minimum required operational procedures include use of a HIPAA-compliant cover sheet; verification of recipient fax number before each transmission; prompt retrieval of received faxes from shared devices; restricted access to received PHI to authorized personnel only; and maintenance of fax transmission logs for audit purposes.

Patient Information (if transmission is patient-specific)

Authorization and Use Restrictions

The sender represents that it has obtained all necessary authorizations to disclose PHI where required by law. The recipient agrees:

  1. To use PHI transmitted by fax solely for the purpose expressly stated in the accompanying transmission cover sheet or as otherwise authorized in writing.
  2. Not to redisclose PHI except as permitted by law or with the express written consent of the patient or as otherwise required by law.
  3. To limit access to received PHI to employees or contractors with a legitimate need to know, and to require such persons to comply with confidentiality obligations at least as restrictive as those in this Agreement.

Notification of Misdirected or Unauthorized Disclosure

In the event of an actual or suspected misdirected fax or unauthorized disclosure of PHI, the receiving party shall:

  1. Notify the sender immediately upon discovery and provide a description of the incident, the PHI involved, and actions taken to mitigate harm.
  2. Cooperate with the sender regarding mitigation, investigation, and any required notifications to affected individuals or authorities.
  3. Conduct a root-cause analysis and, where practical, implement corrective measures to prevent recurrence.

Breach Notification and Compliance

Each party shall comply with applicable breach notification laws and shall notify the other party promptly and in any event no later than seventy-two (72) hours after discovery of a breach of unsecured PHI that affects transmitted records under this Agreement.

Indemnification and Limitation of Liability

Each party shall indemnify, defend and hold harmless the other party from and against any claims, liabilities, losses, expenses or damages arising from the indemnifying party's negligent or willful breach of this Agreement or applicable law with respect to fax transmissions of PHI. Neither party shall be liable for incidental, consequential or punitive damages except for liability arising from willful misconduct.

Termination

This Agreement may be terminated by either party upon thirty (30) days' written notice. Termination shall not relieve a party of liability for breaches occurring prior to termination. Upon termination, the parties shall cease fax transmissions of PHI except as necessary to wind down ongoing patient care, and shall return or destroy PHI in accordance with law and documented procedures.

Miscellaneous

This Agreement constitutes the entire understanding between the parties with respect to fax transmissions of PHI and supersedes all prior agreements. Any amendment must be in writing and signed by authorized representatives of both parties. This Agreement shall be governed by the laws of the state in which the sender's principal place of business is located, without regard to conflict of law principles.

Special Instructions / Additional Terms

Acknowledgment

By signing below, each party represents and warrants that it has the authority to enter into this Agreement, agrees to comply with the terms herein, and acknowledges that failure to comply may result in corrective action, including termination and potential legal remedies.

Healthcare Provider (Printed Name):

By (Signature):

Date:

Title / Relationship:

Fax Recipient (Printed Name):

By (Signature):

Date:

Title / Relationship:

Enter text✕

What a Healthcare Fax Agreement Covers

A Healthcare Fax Agreement documents the terms and procedures for sending protected health information (PHI) by fax between covered entities and business associates. It defines permitted uses, recipient verification, cover‑sheet requirements, logging and retention, responsibility for transmission errors, breach notification steps, and obligations to comply with HIPAA privacy and security standards.

Why a Formal Fax Agreement Matters for Healthcare

A written agreement reduces transmission errors and liability, sets security expectations for PHI, clarifies responsibilities when faxes are misdirected, and documents procedures needed for HIPAA compliance and incident response.

Why a Formal Fax Agreement Matters for Healthcare

Who typically signs a Healthcare Fax Agreement

Common parties include healthcare providers, health systems, third‑party vendors, and business associates that exchange PHI by fax.

  • Covered entities (hospitals, clinics) — set sender/receiver responsibilities and patient privacy safeguards.
  • Business associates (billing, transcription) — accept duties to protect PHI and report breaches promptly.
  • Health IT vendors and clearinghouses — document technical controls, audit logging, and transmission encryption expectations.

Identifying the correct contract signatories up front prevents ambiguity and supports compliance with HIPAA and vendor management requirements.

Stepwise process for executing and using a Healthcare Fax Agreement

Follow these steps to prepare, sign, and operationalize an agreement before exchanging PHI by fax.

  • 01
    Draft and Review: Customize terms for parties, include PHI handling and breach response clauses.
  • 02
    Obtain Signatures: Authorized representatives sign; record dates and retain executed copy.
  • 03
    Operationalize Procedures: Train staff on cover sheets, number verification, and logging transmissions.
  • 04
    Monitor and Audit: Periodically review logs and update procedures after incidents or regulatory changes.

How the fax exchange workflow operates under the agreement

The agreement frames technical and operational steps for each transmission, from sender preparation to confirmation and audit logging.

  • Prepare Document: Attach required cover sheet and minimum PHI; redact nonessential data.
  • Verify Recipient: Confirm fax number by phone or secure directory before sending.
  • Secure Transmission: Use secure fax gateways or encrypted lines where available; retain delivery receipts.
  • Confirm and Log: Record sender, recipient, timestamp, and transmission result in an audit log.

Configuring digital workflows for faxed PHI

Map specific system settings to the agreement requirements so operational teams can implement consistent controls.

Field Configuration
Retention Retain logs for 6 years (HIPAA)
Access Controls Role-based access, unique accounts
Transmission Security TLS 1.2/1.3 or secure fax gateway
Audit Trail Capture IP, timestamp, and result

Technical and integration considerations

Confirm integration and platform requirements before signing so the agreement aligns with existing systems.

  • Integrations: Salesforce, Microsoft 365, NetSuite, Google Workspace
  • File Formats: PDF, DOCX, TIFF supported
  • Authentication: SAML/SSO and multi-factor options

Essential clauses to include in a Healthcare Fax Agreement

A comprehensive agreement balances operational detail with legal protections; include clauses that directly address PHI transmission and incident response.

Purpose and Scope

Define permitted types of PHI, departments involved, and whether the agreement covers only fax or additional transmission methods including secure gateways.

PHI Handling

Specify the minimum necessary standard, permitted data elements, redaction requirements, and procedures for de‑identification where appropriate.

Transmission Security

Detail required technical controls such as encrypted fax gateways, TLS 1.2/1.3, access controls, and delivery confirmation procedures.

Audit and Logging

Require retention of transmission logs, delivery receipts, and access records sufficient to support incident investigations and compliance audits.

Breach Notification

Assign breach reporting timelines, responsibilities and required content; include OCR notification obligations under HIPAA and contractual notice to affected parties.

Liability and Indemnity

Allocate responsibility for negligent transmissions, define limits on damages, and include indemnity for third‑party claims arising from PHI disclosures.

Security and compliance controls to reference

Encryption in Transit: TLS 1.2/1.3
Encryption at Rest: AES-256
BAA Requirement: BAA required for PHI
Audit Trail: Detailed transmission logs
Access Controls: Role-based permissions
Regulatory Standards: HIPAA, ESIGN, UETA

Potential penalties and legal risks

HIPAA Fines: Civil monetary penalties
OCR Enforcement: Corrective action plans
State Privacy Liability: Additional statutory fines
Contract Damages: Breach of contract claims
Reputational Harm: Patient trust loss
Criminal Exposure: Intentional misuse risks

Common drafting and operational mistakes to avoid

  • Failing to obtain written patient or organizational authorization for PHI transfers, leaving parties exposed to enforcement actions.
  • Sending PHI to an incorrect fax number due to lack of phone verification or outdated contact lists.
  • Omitting a secure cover sheet and minimum‑necessary instructions, increasing risk of unauthorized disclosure at the receiving fax machine.
  • Not retaining transmission logs or failing to document corrective steps after a misdirected fax, complicating breach response.

Key timelines and regulatory deadlines to include

Set explicit timing obligations in the agreement so parties understand response, retention, and notice windows required by federal standards.

Effective Date and Term:

State when the agreement takes effect and renewal or termination notice period.

Change Notice Period:

Provide at least 30 days' written notice for material changes to procedures or terms.

Breach Notification Deadline:

Report breaches to responsible parties and OCR within HIPAA-required timelines (OCR guidance expects prompt notification).

Retention of Logs:

Maintain transmission and audit logs for HIPAA retention (see 45 CFR §164.530(j)).

Revocation Response:

Acknowledge and act on consent revocation within a defined operational window, typically 30 days.

eSignature vendor comparison for Healthcare Fax Agreement execution

Compare basic pricing and core capabilities relevant to PHI-handling agreements; signNow is listed first per the comparison format.

signNow DocuSign Adobe Sign PandaDoc HelloSign
Starting Price $8/user/mo $15/user/mo $14/user/mo $19/user/mo $15/user/mo
Free Trial 7-day free trial Trial available Trial available Trial available Trial available
Bulk Send Yes Yes Yes Yes No
Audit Trail Yes Yes Yes Yes Yes
HIPAA Compliant Yes Yes Yes No No
Envelope Cap No cap 100 envelopes/user/year Varies by plan Varies by plan Varies by plan

Frequently asked questions about Healthcare Fax Agreements

Answers to common legal and operational questions can clarify enforceability, PHI handling, consent, and incident response obligations.


Need help? Contact support

be ready to get more
Join over 28 million airSlate SignNow users