HIPAA Compliance

What you need to do

Follow these steps to make your account totally HIPAA compliant:

  1. Head over to the Fax Settings section of your account and uncheck both boxes in the “Storage” section. This will prevent storage of any of your transmitted documents on Phaxio’s servers.
  2. Enable Two-Factor Authentication in your user profile.
  3. Use HTTPS for all webhook URLs you provide to us.
  4. Let us know that you need to sign a BAA by emailing us at compliance@phaxio.com with the userID of your account.
  5. Use the latest version of the API for the most up-to-date security features.
  6. Rotate your API keys on a regular basis.

What we already do for you

Here are just a few of the steps that we take to ensure that your protected health information (PHI) documents are secure:

  1. Our secure API URL (https://api.phaxio.com) enforces TLS 1.2.
  2. Your faxes are not stored (when the boxes in Storage Preference are unchecked). This means that Phaxio cannot view, alter, delete or otherwise tamper with your files.
  3. Callbacks are logged so that you know whether or not you received confirmation that a fax was sent or received and at what time the transmission occurred.
  4. Phaxio is hosted on Amazon’s AWS which has achieved ISO 27001 certification and has successfully completed multiple SOC 2 Type II audits. You can read more about their security precautions here.