Important notice
There is no official “HIPAA certified” or government-issued HIPAA compliance seal. HHS does not certify vendors as “HIPAA compliant.” Statements on this page describe SingleFax’s role as a Business Associate, the safeguards we implement for HIPAA-mode services, and how compliance is shared between parties under the HIPAA Rules (45 C.F.R. Parts 160 and 164).
This page is an informational overview, not legal advice. Your organization remains responsible for its own Privacy Rule, Security Rule, and Breach Notification obligations. Have counsel review our BAA and product terms before relying on them in production or disputes.
1. Our role under HIPAA
When a Covered Entity (CE) or upstream Business Associate (BA) engages SingleFax to transmit documents that include PHI/ePHI, SingleFax acts as a Business Associate (or subcontractor BA) under 45 C.F.R. § 160.103. We create, receive, maintain, or transmit PHI solely to perform the Services described in our Terms and BAA—primarily fax transmission, temporary processing storage, delivery status, receipts, and compliance recordkeeping.
- We do
Transmit Customer-submitted documents; apply HIPAA-mode technical controls; execute and retain BAA records; purge PHI media per retention policy.
- We do not
Practice medicine; decide treatment; sell PHI; use PHI for our marketing; or replace your Notice of Privacy Practices or workforce training.
2. When to use HIPAA mode
Use HIPAA mode whenever the document contains PHI/ePHI and you are a CE or BA transmitting on behalf of a CE. Standard pay-per-fax is for non-PHI business documents (and for individuals sending their own records—patients are not Covered Entities and cannot bind a clinic’s BAA).
| Scenario | Recommended path |
|---|---|
| Clinic / BA sending medical records, labs, prior auths, claims with clinical detail | HIPAA mode + BAA |
| Patient or caregiver sending their own records | Standard send (no CE BAA) |
| Court filings, FOIA, non-health paperwork | Standard send |
HIPAA mode is never inferred from file contents. You must explicitly enable it and accept the BAA.
3. Business Associate Agreement
Before any PHI upload in HIPAA mode, an authorized signer for your legal entity must electronically accept our Business Associate Agreement. Acceptance is organization-scoped, versioned, and recorded with document digests and attestation checkboxes (authority to bind; minimum necessary).
- Aligned to 45 C.F.R. § 164.504(e) required elements (permitted uses, safeguards, subcontractors, breach reporting, HHS access, return/destruction, termination).
- Executed copy available for download after acceptance (PDF).
- New versions supersede prior acceptances; re-acceptance may be required when terms change.
4. Administrative, physical & technical safeguards
For HIPAA-mode ePHI, SingleFax implements safeguards reasonably and appropriately designed to meet the Security Rule (45 C.F.R. Part 164, Subpart C). Representative controls include:
Administrative
- Workforce access limited to roles needed to operate and support the Services (least privilege).
- Documented incident response and breach assessment procedures under our BAA timelines.
- Vendor / subcontractor due diligence and written downstream agreements where PHI is involved.
- Separation of HIPAA-mode product path from standard retail fax (explicit opt-in; no silent inference).
- Audit logging of BAA acceptance, privileged document access, and media purge events.
Physical
- Production systems hosted in professionally managed data-center facilities with facility access controls.
- No local workstation storage of Customer PHI as part of the designed HIPAA send path.
- Media handling for backups and disks subject to provider controls and our retention/destruction practices.
Technical
- Encryption in transit (TLS) between your browser/API clients and our services; TLS for database connections where configured.
- Encryption at rest for object storage used for document media (provider SSE) and disk-level protections on compute.
- Authentication & authorization for HIPAA send (signed-in user; organization membership; active BAA gate before upload).
- Isolated PHI storage prefix for HIPAA-mode media; signed, time-limited access for retrieval when needed.
- Payload minimization in workflow orchestration (identifiers rather than document bytes in queue messages).
- Fax provider preview storage disabled for HIPAA-mode transmissions where the API supports it.
- Payment metadata scrubbing—checkout uses opaque order identifiers and generic product naming (no clinical content).
- Conversion / processing services authenticated; not publicly writable without credentials.
5. PHI data lifecycle
- 1Ingest
Upload only after BAA acceptance. Document converted as needed for fax transmission.
- 2Process & transmit
Temporary storage under dedicated controls; transmission via fax carrier APIs; retries as configured.
- 3Status & receipts
We retain delivery status, timestamps, and compliance metadata needed for receipts and audit—not clinical free-text in payment systems.
- 4Secure deletion
HIPAA-mode document media is subject to a short operational retention window and automated purge with deletion evidence. BAA acceptances, executed PDFs, and required compliance records are retained for at least six (6) years as contemplated by the HIPAA documentation requirements.
6. Subcontractors & service providers
SingleFax uses carefully selected subprocessors to deliver the Services (for example: object storage, telecommunications / fax termination, payment processing, email delivery, and infrastructure hosting). Where a subprocessor creates, receives, maintains, or transmits PHI on our behalf, we obtain written assurances consistent with 45 C.F.R. § 164.502(e) and § 164.308(b)—typically a BAA or equivalent contractual safeguards—or we architect the flow so that provider does not receive PHI (e.g., payment processors receive only opaque order identifiers).
A current list of material subprocessors is available on request to Covered Entity customers with an active BAA, subject to reasonable confidentiality.
7. Breach notification & security incidents
Under our BAA, SingleFax will report to Customer, without unreasonable delay and in no case later than sixty (60) calendar days after Discovery (or sooner if Required by Law):
- Uses or disclosures of PHI not permitted by the BAA of which we become aware;
- Security Incidents of which we become aware (successful unauthorized access, use, disclosure, modification, or destruction, or interference with system operations); and
- Breaches of Unsecured PHI, including information required by 45 C.F.R. § 164.410.
Routine unsuccessful probes and scans may be logged and reported in aggregate upon request. Customer remains responsible for any downstream notifications to individuals, HHS, or the media when required of a Covered Entity.
8. Your obligations as Customer
HIPAA compliance is shared. By using HIPAA mode and accepting the BAA, you represent and agree that:
- 01You are a Covered Entity or a Business Associate engaging SingleFax as a subcontractor BA—not an individual patient binding a clinic.
- 02The signer has legal authority to bind the named entity.
- 03You will transmit only the minimum necessary PHI for the intended purpose (45 C.F.R. § 164.502(b)).
- 04You will not request uses or disclosures that would be impermissible if performed by you directly (except as the HIPAA Rules expressly allow for BAs).
- 05You maintain your own policies, workforce training, access controls, and patient rights processes required of a CE or BA.
- 06You use HIPAA mode for PHI and standard send only when appropriate—misclassification does not create a BAA for standard traffic.
9. Access, accounting & HHS
To the extent SingleFax maintains PHI in a Designated Record Set, we will make PHI available to Customer as needed for access (45 C.F.R. § 164.524), amendment (§ 164.526), and accounting of disclosures (§ 164.528), within a reasonable time through support channels. We will make our internal practices, books, and records relating to PHI available to the Secretary of HHS for determining compliance with the HIPAA Rules (45 C.F.R. § 164.504(e)(2)(ii)(I)).
Operational fax media is typically short-lived; compliance artifacts (BAA, acceptance logs, deletion evidence) are retained longer. Plan your own recordkeeping for clinical content you need beyond our media TTL.
10. Contact & privacy
For BAA questions, security incidents involving SingleFax, or compliance documentation requests:
Monocube LLC
30 N Gould St Ste R
Sheridan, WY 82801, USA
Ready to send PHI?
Accept the electronic BAA for your organization, then send with HIPAA-mode pricing and controls.
SingleFax does not claim HHS certification. Compliance depends on both parties meeting their obligations under the HIPAA Rules and our BAA.