Is SRFax HIPAA compliant?
Yes if you buy from SRFax's Healthcare Solutions range and request the agreement — the cheaper Standard Solutions plans are sold for general small business use, not healthcare.
Applies to SRFax Healthcare Solutions plans. Last reviewed against SRFax's own documentation. Next review December 26, 2026.
Reviewed by Carlos Mendez — IT Security Manager, regional healthcare network.
What you must do
- Choose a plan from the Healthcare Solutions range, which SRFax describes as fully HIPAA compliant.
- Request the agreement through SRFax's contact form — it is not issued automatically.
- Execute it before faxing any patient information.
- US practices should confirm they receive the HIPAA agreement rather than the Canadian PHIPA arrangement SRFax also offers.
- Decide whether to enable optional PGP encryption — SRFax describes it as optional, so it is off unless you ask.
- Ensure the mailbox receiving fax-to-email deliveries is itself covered by an agreement with that provider.
Does SRFax sign a business associate agreement?
Yes. SRFax offers one. Healthcare Solutions plans. SRFax does not describe its Standard Solutions plans as HIPAA compliant. Use the 'Request a BAA' link on SRFax's healthcare plans page or their contact form.
What this means in practice
SRFax splits its catalogue in two, and the split is the whole decision. Healthcare Solutions plans are the ones SRFax describes as fully HIPAA compliant. Standard Solutions plans are pitched at small businesses, sole practitioners and home users. They cost less and look similar, which is exactly why practices end up on the wrong one.
Nothing executes itself. SRFax offers a request route through its contact form, so the agreement is something you actively ask for and get signed before the first patient fax goes out.
Two practical details are easy to miss. PGP encryption is described as optional, meaning it is not on by default. And SRFax serves Canada as well as the US, so a US practice should confirm the document it receives is the HIPAA business associate agreement and not the Canadian equivalent.
How organizations get this wrong
The specific mistakes we see with SRFax, not generic advice.
- Signing up on a Standard Solutions plan to save a few dollars a month, then discovering it is not the healthcare-compliant product line.
- Treating the plan purchase as the agreement. SRFax requires a separate request through its contact form before anything is signed.
- Delivering inbound faxes to a personal email address, so patient records sit in a mailbox with no agreement behind it.
- Leaving optional PGP encryption switched off while assuming it was part of the healthcare package by default.
What the agreement does not cover
- SRFax's Standard Solutions plans, positioned for small businesses, sole practitioners and home users rather than healthcare.
- The email inbox or device where inbound faxes are delivered.
- PGP encryption unless you specifically request it.
- SRFax publishes no exclusions list, so treat any add-on or integration as unconfirmed.
Signing the agreement is step one. Proving it is step two.
Once you have the agreement with SRFax, someone has to know it exists, where the copy is, when it needs revisiting and who owns it. That register is what a client's security questionnaire is actually asking about, and it is the section of an evidence pack most organizations cannot produce on request.
$79/month, 14-day free trial, no credit card. The checker itself stays free and needs no account.
Sources
Every statement above comes from SRFax’s own published documentation, read on the date shown.
- HIPAA Compliance — SRFax. No publication date given. Read July 29, 2026.
- HIPAA Compliant Fax Service — Healthcare Solutions plans — SRFax. No publication date given. Read July 29, 2026.
Change history
- — First published.
This page is information, not certification and not legal advice. It reflects SRFax’s published documentation as read on July 29, 2026; vendors change their terms without notice, so confirm anything you rely on directly with the vendor. Whether your own use is compliant depends on your configuration, your executed agreement and how your staff actually work. No company can be “HIPAA certified” — no such designation exists.
Think something here is wrong or out of date? Tell us at support@hipaacompliancesoftware.org — corrections are published with a dated note in the change history above, never silently. See our editorial standards for how entries are researched and re-verified.